Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Mystart.incredibar entfernen (https://www.trojaner-board.de/118793-mystart-incredibar-entfernen.html)

maeusuruh 07.07.2012 15:31

Mystart.incredibar entfernen
 
Hallo Leute!

Leider hab ich mir, wie anscheinend mehrere, dieses blöde incredibar runtergeladen und weiß nicht wie ichs losbekomme!
Ich kenn mich leider auch nicht soooo gut mit Computern aus. Also das übliche schon, aber was drüber hinausgeht, .... ähäm!!!
Aber ich geb mein Bestes!!

Habe den Malwarebytes runtergeladen und durchgeführt und kopiert:

Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.07.07.05

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Frank :: ADMIN-PC [Administrator]

Schutz: Aktiviert

07.07.2012 16:07:12
mbam-log-2012-07-07 (16-07-12).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 212098
Laufzeit: 2 Minute(n), 36 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 1
HKCU\Software\UBC5AB1IDP (Malware.Trace) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 1
C:\Users\Frank\AppData\Roaming\7910.org\Ticker (Trojan.DDOS) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateien: 6
C:\Users\Frank\Downloads\SoftonicDownloader_fuer_inkscape.exe (PUP.ToolbarDownloader) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Frank\Downloads\SoftonicDownloader_fuer_nw-docx-converter(1).exe (PUP.ToolbarDownloader) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Frank\Downloads\SoftonicDownloader_fuer_nw-docx-converter.exe (PUP.ToolbarDownloader) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Frank\AppData\Roaming\7910.org\Ticker\an1cHrs0cr60002MDAwODk1b3wwMDAwNTU0ZGF8QmFsZCBmYWhyZW4gd2lyISEhISBOb2No.gif (Trojan.DDOS) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Frank\AppData\Roaming\7910.org\Ticker\an1cHrsVM1P0002MDAwMTUwbHwwMDAwNTU0ZGF8QmFsZCBmYWhyZW4gd2lyISEhISBOb2No.gif (Trojan.DDOS) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Habe auch den defogger gemacht, er hat sich neu gestartet, war aber nix da zum kopieren!??

Dann hab ich OTL ausgeführt:OTL Logfile:
Code:

OTL logfile created on: 07.07.2012 16:44:55 - Run 1
OTL by OldTimer - Version 3.2.53.1    Folder = C:\Users\Frank\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
8,00 Gb Total Physical Memory | 6,13 Gb Available Physical Memory | 76,69% Memory free
16,05 Gb Paging File | 14,00 Gb Available in Paging File | 87,25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,51 Gb Total Space | 488,81 Gb Free Space | 52,48% Space Free | Partition Type: NTFS
 
Computer Name: ADMIN-PC | User Name: Frank | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.07.07 16:43:57 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Frank\Downloads\OTL.exe
PRC - [2012.06.13 12:25:11 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2012.05.08 22:15:04 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.08 22:14:59 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.05.08 22:14:59 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.08 15:15:02 | 000,185,856 | ---- | M] () -- C:\Programme\Web Assistant\ExtensionUpdaterService.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.01.23 06:43:08 | 000,092,592 | ---- | M] (TomTom) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2012.01.05 21:35:16 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2011.09.15 13:06:04 | 000,088,576 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2009.04.11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\conime.exe
PRC - [2009.03.23 13:12:44 | 000,327,680 | ---- | M] (PixArt Imaging Incorporation) -- C:\Windows\Pixart\Pac7302\PACTray.exe
PRC - [2007.12.10 15:55:26 | 000,323,584 | ---- | M] (PixArt Imaging Incorporation) -- C:\Windows\Pixart\Pac7302\Monitor.exe
 
 
========== Modules (No Company Name) ==========
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2012.04.06 04:16:02 | 000,236,544 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2007.10.19 05:10:30 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\AEADISRV.EXE -- (AEADIFilters)
SRV - [2012.06.23 19:29:08 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.06.20 17:18:50 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.05.08 22:15:04 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.08 22:14:59 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.05.08 15:15:02 | 000,185,856 | ---- | M] () [Auto | Running] -- C:\Programme\Web Assistant\ExtensionUpdaterService.exe -- (Web Assistant Updater)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.01.23 06:43:08 | 000,092,592 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2012.01.05 21:35:16 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2011.12.26 13:23:34 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Users\Frank\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe -- (SearchAnonymizer)
SRV - [2011.09.15 13:06:04 | 000,088,576 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.03.21 13:21:24 | 000,632,832 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.03.30 06:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.05.08 22:15:05 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.05.08 22:15:05 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\DRIVERS\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012.04.06 07:22:40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2012.04.06 07:22:40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.04.06 03:10:44 | 000,343,040 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.04.04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012.02.29 15:52:46 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.02.23 14:31:50 | 000,092,176 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdLH6.sys -- (AtiHDAudioService)
DRV:64bit: - [2011.09.16 17:08:07 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2010.12.02 15:14:26 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltjx64.sys -- (UsbserFilt)
DRV:64bit: - [2010.12.02 15:14:24 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64.sys -- (upperdev)
DRV:64bit: - [2010.12.02 15:14:22 | 000,027,136 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdc)
DRV:64bit: - [2010.12.02 15:14:18 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd)
DRV:64bit: - [2010.12.02 13:36:42 | 000,171,008 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nmwcdnsux64.sys -- (nmwcdnsux64)
DRV:64bit: - [2010.12.02 13:36:40 | 000,012,800 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nmwcdnsucx64.sys -- (nmwcdnsucx64)
DRV:64bit: - [2010.06.25 16:08:56 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\htcnprot.sys -- (htcnprot)
DRV:64bit: - [2009.12.02 18:57:48 | 000,868,848 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\Drivers\sptd.sys -- (sptd)
DRV:64bit: - [2009.10.01 02:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:64bit: - [2009.06.17 18:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2009.06.17 18:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2009.06.17 18:53:34 | 000,030,736 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\L8042Kbd.sys -- (L8042Kbd)
DRV:64bit: - [2009.06.10 00:46:06 | 000,031,744 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\ANDROIDUSB.sys -- (HTCAND64)
DRV:64bit: - [2009.04.11 07:43:06 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2009.04.11 07:39:37 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\usbser.sys -- (usbser)
DRV:64bit: - [2008.11.19 17:09:14 | 000,033,792 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\lgx64modem.sys -- (USBModem)
DRV:64bit: - [2008.11.19 17:09:12 | 000,027,136 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\lgx64diag.sys -- (UsbDiag)
DRV:64bit: - [2008.11.19 17:09:12 | 000,017,920 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\lgx64bus.sys -- (usbbus)
DRV:64bit: - [2008.11.10 13:17:40 | 000,531,968 | ---- | M] (PixArt Imaging Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\PAC7302.SYS -- (PAC7302)
DRV:64bit: - [2008.08.28 12:44:42 | 000,025,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys -- (pccsmcfd)
DRV:64bit: - [2008.03.20 02:44:34 | 000,467,456 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV:64bit: - [2007.12.06 09:51:00 | 000,391,680 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\yk60x64.sys -- (yukonx64)
DRV:64bit: - [2007.02.08 09:48:04 | 000,051,600 | ---- | M] (Thesycon GmbH, Germany) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\dsiarhwprog_x64.sys -- (usbio)
DRV:64bit: - [2006.10.31 17:23:42 | 000,015,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2006.09.19 14:43:54 | 000,018,224 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2008.01.18 14:21:38 | 000,013,312 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\LG Soft India\forteManager\bin\PII2CDriver.sys -- (LGII2CDevice)
DRV - [2008.01.18 14:21:36 | 000,014,336 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\LG Soft India\forteManager\bin\I2CDriver.sys -- (LGDDCDevice)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://start.facemoods.com/?a=dpg&s={searchTerms}&f=4
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = hxxp://start.facemoods.com/?a=dpg&s={searchTerms}&f=4&hl={language}&src=chrm
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2582601
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://mystart.incredibar.com/mb165?a=6R8vQpBcfa&i=26
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E62696E672E636F6D2F7365617263683F713D7B7365617263685465726D737D267372633D49452D536561726368426F7826464F524D3D494538535243&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&k=0
IE - HKCU\..\SearchScopes\{08F95AC0-1D40-443E-ADA3-9A0EAD1745C8}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = hxxp://start.facemoods.com.anonymize-me.de/?anonymto=687474703A2F2F73746172742E666163656D6F6F64732E636F6D2F3F613D64706726733D7B7365617263685465726D737D26663D34&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&k=0
IE - HKCU\..\SearchScopes\{5033262E-1290-45AD-8B2C-CB2FD2E65299}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{5CFDB435-86A1-48E5-ADE8-7F43EB9EAA8F}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://www.icq.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E6963712E636F6D2F7365617263682F726573756C74732E7068703F713D7B7365617263685465726D737D2663685F69643D6F7364&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&k=0
IE - HKCU\..\SearchScopes\{6FE52790-D24A-4B46-B535-7A88C2D86152}: "URL" = [String data over 1000 bytes]
IE - HKCU\..\SearchScopes\{9148E46A-4B18-4B31-8B70-A8114CF989BD}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E636F6E647569742E636F6D2F526573756C74734578742E617370783F713D7B7365617263685465726D737D26536561726368536F757263653D3426637469643D435432353832363031&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&k=0
IE - HKCU\..\SearchScopes\{B357C1CA-69CF-4B2E-A69A-9BDC10F2F8AC}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = hxxp://mystart.incredibar.com/mb165/?search={searchTerms}&loc=IB_DS&a=6R8vQpBcfa&i=26
IE - HKCU\..\SearchScopes\{D7ABBE17-5AC2-4E34-8B5F-7FAFB01B9751}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKCU\..\SearchScopes\Plasmoo: "URL" = hxxp://plasmoo.com.anonymize-me.de/?anonymto=687474703A2F2F706C61736D6F6F2E636F6D2F726573756C742E68746D3F713D7B7365617263685465726D737D265365617263684D617368696E653D74727565&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&k=0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.defaultthis.engineName: "pc gear de Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2582601&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://Mystart.incredibar.com/mb124"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.01
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {2ea04d33-5259-40b9-b79b-cb037d4824e7}:3.3.3.2
FF - prefs.js..extensions.enabledItems: codiprog@fbplus.plugin:1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.51
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7280
FF - prefs.js..extensions.enabledItems: engine@plasmoo.com:1.0.0.32
FF - prefs.js..keyword.URL: "hxxp://mystart.incredibar.com/mb165/?loc=IB_DS&a=6R8vQpBcfa&&i=26&search="
FF - prefs.js..network.proxy.http: "190.66.17.53"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.type: 0
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.110.0: C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.118.0: C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.122.0: C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Frank\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
 
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX [2012.06.13 07:33:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011.05.31 22:55:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.06.13 12:25:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.06.13 12:25:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.20 17:18:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.06.13 12:26:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012.05.16 10:24:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011.05.31 22:55:38 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.06.20 17:18:50 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.06.13 12:26:04 | 000,000,000 | ---D | M]
 
[2010.09.15 12:51:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\mozilla\Extensions
[2010.09.15 12:51:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.02.11 12:30:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2012.07.04 21:38:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\mozilla\Firefox\Profiles\8ghejrb4.default\extensions
[2010.04.28 06:15:21 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Frank\AppData\Roaming\mozilla\Firefox\Profiles\8ghejrb4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.07.20 19:59:08 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Frank\AppData\Roaming\mozilla\Firefox\Profiles\8ghejrb4.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.14 22:27:01 | 000,000,000 | ---D | M] ("FRITZ!Box AddOn") -- C:\Users\Frank\AppData\Roaming\mozilla\Firefox\Profiles\8ghejrb4.default\extensions\fb_add_on@avm.de
[2012.06.13 07:33:53 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Users\Frank\AppData\Roaming\mozilla\Firefox\Profiles\8ghejrb4.default\extensions\ffxtlbr@incredibar.com
[2012.06.01 23:34:29 | 000,000,000 | ---D | M] (softonic.com) -- C:\Users\Frank\AppData\Roaming\mozilla\Firefox\Profiles\8ghejrb4.default\extensions\ffxtlbra@softonic.com
[2012.05.18 13:38:38 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Frank\AppData\Roaming\mozilla\Firefox\Profiles\8ghejrb4.default\extensions\ich@maltegoetz.de
[2011.12.26 13:23:36 | 000,002,820 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\askcom.xml
[2011.12.26 13:23:36 | 000,001,129 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\conduit.xml
[2011.12.26 13:23:36 | 000,001,091 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\icqplugin.xml
[2012.06.13 07:33:25 | 000,002,203 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\MyStart Search.xml
[2011.12.26 13:23:37 | 000,002,188 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\{254DA591-C16D-4FB6-9062-4C050FA0B1BD}.xml
[2011.12.26 13:23:37 | 000,001,870 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\{6332F0FF-685E-4193-9E72-D96AEE055E73}.xml
[2011.12.26 13:23:37 | 000,002,077 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\{7D01AA1A-5AB3-4D3E-ACAE-79CACC0E28AC}.xml
[2012.03.22 12:00:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2009.06.23 21:00:33 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.12.13 23:06:06 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.06.06 22:18:50 | 000,061,219 | ---- | M] () (No name found) -- C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\EXTENSIONS\{9AA46F4F-4DC7-4C06-97AF-5035170634FE}.XPI
[2012.07.04 21:38:52 | 000,743,290 | ---- | M] () (No name found) -- C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012.06.20 17:18:50 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2009.09.08 16:02:46 | 000,188,416 | ---- | M] (The cURL library, hxxp://curl.haxx.se/) -- C:\Program Files (x86)\mozilla firefox\plugins\libcurl.dll
[2012.03.08 13:25:54 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2009.10.29 16:57:40 | 001,359,872 | ---- | M] (Fraunhofer IIS) -- C:\Program Files (x86)\mozilla firefox\plugins\npmmtaplayer.dll
[2012.06.13 12:25:21 | 000,129,144 | ---- | M] (RealPlayer) -- C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll
[2012.06.20 17:18:49 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.20 17:18:49 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.20 17:18:49 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.12.26 13:23:36 | 000,001,611 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrchDpg.xml
[2012.06.20 17:18:49 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.20 17:18:49 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.20 17:18:49 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 23:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2:64bit: - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Programme\Web Assistant\Extension64.dll ()
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Programme\Web Assistant\Extension32.dll ()
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\Frank\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS)
O4:64bit: - HKLM..\Run: [PAC7302_Monitor] C:\Windows\Pixart\Pac7302\Monitor.exe (PixArt Imaging Incorporation)
O4:64bit: - HKLM..\Run: [PACTray] C:\Windows\Pixart\Pac7302\PACTray.exe (PixArt Imaging Incorporation)
O4:64bit: - HKLM..\Run: [UpdateUSB] C:\Windows\inf\UpdateUSB.exe (AsusTek Inc.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: []  File not found
O4 - HKCU..\Run: [LDM] C:\Programme\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Frank\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Frank\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Spiele\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Spiele\PartyGaming\PartyPoker\RunApp.exe ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3EF2AE26-FF8E-4427-A3DD-D1BE409D82E6}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{841DA7EE-789D-4B01-B5BF-E1D0CF08E86C}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B94D2724-8C73-4AE6-A359-2099ABA3E767}: DhcpNameServer = 192.168.42.129
O18:64bit: - Protocol\Handler\bw+0 - No CLSID value found
O18:64bit: - Protocol\Handler\bw+0s - No CLSID value found
O18:64bit: - Protocol\Handler\bw-0 - No CLSID value found
O18:64bit: - Protocol\Handler\bw00 - No CLSID value found
O18:64bit: - Protocol\Handler\bw00s - No CLSID value found
O18:64bit: - Protocol\Handler\bw-0s - No CLSID value found
O18:64bit: - Protocol\Handler\bw10 - No CLSID value found
O18:64bit: - Protocol\Handler\bw10s - No CLSID value found
O18:64bit: - Protocol\Handler\bw20 - No CLSID value found
O18:64bit: - Protocol\Handler\bw20s - No CLSID value found
O18:64bit: - Protocol\Handler\bw30 - No CLSID value found
O18:64bit: - Protocol\Handler\bw30s - No CLSID value found
O18:64bit: - Protocol\Handler\bw40 - No CLSID value found
O18:64bit: - Protocol\Handler\bw40s - No CLSID value found
O18:64bit: - Protocol\Handler\bw50 - No CLSID value found
O18:64bit: - Protocol\Handler\bw50s - No CLSID value found
O18:64bit: - Protocol\Handler\bw60 - No CLSID value found
O18:64bit: - Protocol\Handler\bw60s - No CLSID value found
O18:64bit: - Protocol\Handler\bw70 - No CLSID value found
O18:64bit: - Protocol\Handler\bw70s - No CLSID value found
O18:64bit: - Protocol\Handler\bw80 - No CLSID value found
O18:64bit: - Protocol\Handler\bw80s - No CLSID value found
O18:64bit: - Protocol\Handler\bw90 - No CLSID value found
O18:64bit: - Protocol\Handler\bw90s - No CLSID value found
O18:64bit: - Protocol\Handler\bwa0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwa0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwb0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwb0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwc0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwc0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwd0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwd0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwe0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwe0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwf0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwf0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwfile-8876480 - No CLSID value found
O18:64bit: - Protocol\Handler\bwg0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwg0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwh0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwh0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwi0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwi0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwj0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwj0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwk0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwk0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwl0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwl0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwm0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwm0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwn0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwn0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwo0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwo0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwp0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwp0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwq0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwq0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwr0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwr0s - No CLSID value found
O18:64bit: - Protocol\Handler\bws0 - No CLSID value found
O18:64bit: - Protocol\Handler\bws0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwt0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwt0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwu0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwu0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwv0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwv0s - No CLSID value found
O18:64bit: - Protocol\Handler\bww0 - No CLSID value found
O18:64bit: - Protocol\Handler\bww0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwx0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwx0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwy0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwy0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwz0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwz0s - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\offline-8876480 - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\bw+0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw+0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw-0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw00 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw00s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw-0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw10 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw10s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw20 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw20s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw30 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw30s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw40 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw40s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw50 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw50s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw60 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw60s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw70 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw70s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw80 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw80s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw90 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw90s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwa0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwa0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwb0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwb0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwc0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwc0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwd0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwd0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwe0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwe0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwf0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwf0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwg0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwg0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwh0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwh0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwi0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwi0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwj0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwj0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwk0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwk0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwl0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwl0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwm0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwm0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwn0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwn0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwo0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwo0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwp0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwp0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwq0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwq0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwr0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwr0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bws0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bws0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwt0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwt0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwu0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwu0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwv0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwv0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bww0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bww0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwx0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwx0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwy0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwy0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwz0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwz0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\offline-8876480 {3FDB282B-B33E-4500-B6C2-484BBA806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Frank\Pictures\2010-09-06 Urlaub Sep.2010, Kroatien Premantura\Urlaub Sep.2010, Kroatien Premantura 012.JPG
O24 - Desktop BackupWallPaper: C:\Users\Frank\Pictures\2010-09-06 Urlaub Sep.2010, Kroatien Premantura\Urlaub Sep.2010, Kroatien Premantura 012.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{2ae806f2-a2a0-11df-9537-0022156014a3}\Shell - "" = AutoRun
O33 - MountPoints2\{2ae806f2-a2a0-11df-9537-0022156014a3}\Shell\AutoRun\command - "" = J:\LGAutoRun.exe
O33 - MountPoints2\{86f40ed1-a9b5-11df-8350-0022156014a3}\Shell - "" = AutoRun
O33 - MountPoints2\{86f40ed1-a9b5-11df-8350-0022156014a3}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\Start.hta
O33 - MountPoints2\{de9b2b23-df64-11de-b799-0022156014a3}\Shell - "" = AutoRun
O33 - MountPoints2\{de9b2b23-df64-11de-b799-0022156014a3}\Shell\AutoRun\command - "" = I:\Autorun.exe
O33 - MountPoints2\{f7e9ea89-702b-11e1-a539-0022156014a3}\Shell - "" = AutoRun
O33 - MountPoints2\{f7e9ea89-702b-11e1-a539-0022156014a3}\Shell\AutoRun\command - "" = J:\NokiaPCIA_Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.07 16:06:26 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Malwarebytes
[2012.07.07 16:06:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.07 16:06:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.07 16:06:11 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.07.07 16:06:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.06.14 14:21:48 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Local\Macromedia
[2012.06.13 12:25:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared
[2012.06.13 12:25:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
[2012.06.13 07:52:10 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\NwDocx
[2012.06.13 07:50:40 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Docx2Rtf
[2012.06.13 07:33:32 | 000,000,000 | ---D | C] -- C:\Program Files\Web Assistant
[2012.06.09 11:03:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nokia PC-Internetzugang
[2012.06.09 11:03:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Installations
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.07 16:39:52 | 001,445,546 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.07.07 16:39:52 | 000,628,742 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.07.07 16:39:52 | 000,596,036 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.07.07 16:39:52 | 000,126,486 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.07.07 16:39:52 | 000,104,110 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.07.07 16:33:29 | 000,003,712 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.07 16:33:29 | 000,003,712 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.07 16:33:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.07 16:30:09 | 000,000,020 | ---- | M] () -- C:\Users\Frank\defogger_reenable
[2012.07.07 16:29:15 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.07 16:06:12 | 000,000,948 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.06 22:16:53 | 000,283,304 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2012.07.06 22:16:53 | 000,283,304 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.07.06 22:16:29 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2012.07.05 11:31:16 | 000,001,950 | ---- | M] () -- C:\Users\Frank\Desktop\Windows Photo Gallery.lnk
[2012.07.05 11:24:27 | 000,000,218 | ---- | M] () -- C:\Users\Frank\.recently-used.xbel
[2012.06.15 21:33:45 | 000,271,176 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.06.14 23:20:55 | 000,182,784 | ---- | M] () -- C:\Users\Frank\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.06.13 12:26:00 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2012.06.13 12:25:18 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2012.06.13 07:33:54 | 000,000,614 | ---- | M] () -- C:\user.js
[2012.06.09 11:03:35 | 000,002,011 | ---- | M] () -- C:\Users\Public\Desktop\Nokia PC-Internetzugang.lnk
 
========== Files Created - No Company Name ==========
 
[2012.07.07 16:30:09 | 000,000,020 | ---- | C] () -- C:\Users\Frank\defogger_reenable
[2012.07.07 16:06:12 | 000,000,948 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.05 11:31:16 | 000,001,950 | ---- | C] () -- C:\Users\Frank\Desktop\Windows Photo Gallery.lnk
[2012.07.05 11:24:27 | 000,000,218 | ---- | C] () -- C:\Users\Frank\.recently-used.xbel
[2012.06.13 12:26:00 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2012.06.09 11:03:35 | 000,002,011 | ---- | C] () -- C:\Users\Public\Desktop\Nokia PC-Internetzugang.lnk
[2011.12.26 13:23:35 | 000,338,432 | ---- | C] () -- C:\Windows\SysWow64\sqlite36_engine.dll
[2011.11.06 01:09:44 | 011,980,353 | ---- | C] () -- C:\Windows\SysWow64\meinfotoalbum_meinfotoalbum_uninstaller.exe
[2011.10.28 19:57:38 | 000,001,356 | ---- | C] () -- C:\Users\Frank\AppData\Local\d3d9caps.dat
[2011.10.25 22:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011.10.01 17:29:47 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2011.09.17 14:55:57 | 001,418,240 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfserv.dll
[2011.09.17 14:55:57 | 001,099,776 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfusb1.dll
[2011.09.17 14:55:57 | 000,568,832 | ---- | C] () -- C:\Windows\SysWow64\lxbfutil.dll
[2011.09.17 14:55:57 | 000,488,448 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbflmpm.dll
[2011.09.17 14:55:57 | 000,410,112 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfpmui.dll
[2011.09.17 14:55:57 | 000,305,664 | ---- | C] ( ) -- C:\Windows\SysWow64\LXBFhcp.dll
[2011.09.17 14:55:57 | 000,238,592 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfinpa.dll
[2011.09.17 14:55:57 | 000,226,816 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfiesc.dll
[2011.09.17 14:55:57 | 000,194,048 | ---- | C] () -- C:\Windows\SysWow64\LXBFinst.dll
[2011.09.17 14:55:57 | 000,035,328 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfprox.dll
[2011.09.17 14:55:57 | 000,010,752 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfpplc.dll
[2011.09.17 14:55:56 | 000,696,320 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfcomc.dll
[2011.09.17 14:55:56 | 000,660,480 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfhbn3.dll
[2011.09.17 14:55:56 | 000,566,704 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfcoms.exe
[2011.09.17 14:55:56 | 000,249,856 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfcomm.dll
[2011.09.17 14:55:56 | 000,236,464 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfcfg.exe
[2011.09.17 14:55:56 | 000,233,392 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfih.exe
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.04.25 22:35:11 | 000,000,862 | ---- | C] () -- C:\Windows\SysWow64\SP7302.INI
[2011.03.28 20:54:49 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.08.27 17:11:17 | 000,097,344 | ---- | C] () -- C:\Users\Frank\slowenien.htm
[2010.07.29 11:50:19 | 000,000,000 | ---- | C] () -- C:\Users\Frank\jagex__preferences3.dat
[2010.07.29 11:45:26 | 000,000,099 | ---- | C] () -- C:\Users\Frank\jagex_runescape_preferences2.dat
[2010.07.29 11:44:24 | 000,000,046 | ---- | C] () -- C:\Users\Frank\jagex_runescape_preferences.dat
[2009.10.21 21:33:45 | 000,001,024 | ---- | C] () -- C:\Users\Frank\.rnd
[2009.06.23 16:54:02 | 000,182,784 | ---- | C] () -- C:\Users\Frank\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.06.23 12:29:59 | 000,001,164 | ---- | C] () -- C:\Users\Frank\AppData\Local\9A5FF4EA.il
[2009.06.23 12:29:59 | 000,000,280 | ---- | C] () -- C:\Users\Frank\AppData\Local\IndexIE_9A5FF4EA.il
[2009.06.23 11:32:45 | 000,000,732 | ---- | C] () -- C:\Users\Frank\AppData\Local\d3d9caps64.dat
 
========== LOP Check ==========
 
[2012.07.07 16:13:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\7910.org
[2012.06.02 01:16:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Amazon
[2011.08.04 13:44:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Auslogics
[2009.10.21 09:05:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Blitware
[2009.12.02 18:57:12 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DAEMON Tools
[2011.12.26 13:27:14 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DesktopIconForAmazon
[2012.06.13 07:53:19 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Docx2Rtf
[2012.01.01 15:01:34 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DVDVideoSoft
[2011.02.10 13:41:41 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.06.21 13:01:48 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Facebook
[2010.12.16 13:09:44 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Fraunhofer
[2012.01.19 18:35:30 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\HTC
[2011.05.11 15:07:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2012.06.01 11:47:59 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\inkscape
[2011.12.26 13:25:03 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\IrfanView
[2009.12.30 21:10:19 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Leadertech
[2012.01.31 00:03:17 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MyPhoneExplorer
[2011.05.23 13:48:57 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Nokia
[2011.05.23 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Nokia Ovi Suite
[2012.06.13 07:54:15 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\NwDocx
[2011.12.26 13:23:33 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\OCS
[2011.11.07 23:24:53 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\OpenCandy
[2011.12.26 13:23:37 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Opera
[2011.10.28 16:35:18 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Origin
[2011.05.06 21:27:51 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PC Suite
[2009.10.21 22:02:25 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Simple Star
[2010.04.29 20:34:38 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\temp
[2010.09.15 12:51:00 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Thunderbird
[2010.02.11 12:30:23 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TomTom
[2011.12.09 19:58:10 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Visan
[2010.12.16 16:29:37 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\XMedia Recode
[2009.10.21 21:37:38 | 000,000,390 | ---- | M] () -- C:\Windows\Tasks\File Helper.job
[2012.07.07 16:32:05 | 000,032,628 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 

< End of report >

--- --- ---
OTL Logfile:
Code:

OTL Extras logfile created on: 07.07.2012 16:44:55 - Run 1
OTL by OldTimer - Version 3.2.53.1    Folder = C:\Users\Frank\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
8,00 Gb Total Physical Memory | 6,13 Gb Available Physical Memory | 76,69% Memory free
16,05 Gb Paging File | 14,00 Gb Available in Paging File | 87,25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,51 Gb Total Space | 488,81 Gb Free Space | 52,48% Space Free | Partition Type: NTFS
 
Computer Name: ADMIN-PC | User Name: Frank | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01  [binary data]
"VistaSp2" = 5B 13 47 FB 45 C7 CA 01  [binary data]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{013B5350-FB9C-475F-93BD-F8AFD47FEC97}" = lport=445 | protocol=6 | dir=in | app=system |
"{0F596B15-C9E7-4B0E-AD1E-55DADAD8C737}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{106809ED-BB4D-4F2D-A442-73C9C603982C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{153206BB-EB69-4ACE-A031-4F2ABD726C86}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{1952039F-B91B-47AC-BB66-3B0EA6B75444}" = rport=10243 | protocol=6 | dir=out | app=system |
"{24164A48-CD12-45B8-87D4-BEE0BDB65BAF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3D76B166-C755-4491-A799-AB441E930ACF}" = lport=138 | protocol=17 | dir=in | app=system |
"{40D03767-E5D6-48BD-8CC4-AE5F49BB8DD5}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{4A1C92EC-40EE-4647-BC2E-95090A24A33E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4D70E9C2-06CA-455D-B74A-1C6D1F64E3DB}" = lport=10243 | protocol=6 | dir=in | app=system |
"{5A4EA7DB-3916-483F-8FF2-89427A8D743E}" = rport=2869 | protocol=6 | dir=out | app=system |
"{5A90CEED-5A54-4C8E-9359-6A72B4E423AC}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{684912DE-8747-4DEC-ACC1-3D69075C0436}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{68A773E8-E59C-4D05-9178-C9D81E025F51}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7AE5BB6F-DD54-4D41-A8B4-445C5AB07B06}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8534B09D-BA6C-4E68-8EF8-121E7D6A82C1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{86E99F5A-53FE-4B05-866B-972103A02B2B}" = rport=445 | protocol=6 | dir=out | app=system |
"{88149C5B-7077-421B-8BB5-49BC05DDD31D}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{884C79CF-08A3-4164-B522-AA75AE086DEA}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8EEBF4F1-7CA9-49F7-B126-6D9750133FB6}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9266E6D0-1FD0-4495-94B9-FACCEAD2942B}" = rport=137 | protocol=17 | dir=out | app=system |
"{96F0450A-5146-4EBF-B558-98C0E049A2BD}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{9C48E224-F2EB-4990-8A20-00C704CF3743}" = lport=137 | protocol=17 | dir=in | app=system |
"{9C6E5602-279C-4B87-9308-5FA881B7E225}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{B0458E22-DCCF-48A8-A60B-1B380FE8DADE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B3B32355-E48E-4AB9-A744-F7BFE2338E76}" = rport=139 | protocol=6 | dir=out | app=system |
"{B3D407C2-0C7F-49D6-8CA2-A21680ECDDD8}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{BB22E027-0FDF-4B51-9149-592FEB5A9237}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C76042BC-91F1-4037-BC38-7C7D3AC0DF38}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{CFFF1E65-D4BC-4973-B64E-948290342501}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D2ECB7E9-5950-4AC0-A42C-EF76DBBB9C76}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D5E76075-5D6A-46B1-A8AF-03A061A41D73}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{DD83E013-1B4B-42B9-B874-BA2382F6D323}" = rport=138 | protocol=17 | dir=out | app=system |
"{F442F423-F230-4212-A3BD-7A56EC0F8D8D}" = lport=139 | protocol=6 | dir=in | app=system |
"{FD66E814-E56B-448E-8875-AAEBAFE56E1D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{08448839-3E20-407A-8627-E25ED022199C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{11358582-780A-436F-B4F4-D3330DE32EC8}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{12C316C5-8DA8-490A-A9DB-D727D063CF21}" = protocol=6 | dir=in | app=c:\windows\syswow64\lxbfcoms.exe |
"{1CB55B50-2131-4F43-9E56-7B9A3D79483A}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{1F7AFAF5-41A2-4946-A6D3-7C988469AF90}" = protocol=6 | dir=in | app=c:\windows\system32\lxbfcoms.exe |
"{2174DBCA-1891-4769-A1E2-A2EA2325F1F7}" = protocol=17 | dir=in | app=c:\windows\syswow64\lxbfcoms.exe |
"{299DCF7F-3109-49B8-AFE0-187820101276}" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{2D919362-D108-4BB0-8164-0539EA00B129}" = protocol=6 | dir=in | app=c:\program files (x86)\bf3\battlefield 3\bf3.exe |
"{2F61F813-BAAA-417D-BE49-4B284E439612}" = protocol=6 | dir=in | app=c:\program files (x86)\bf3\battlefield 3\bf3.exe |
"{2FDF33A2-0CE1-4DFB-BB08-EDDB5F243EF1}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{36D9C825-C493-4F97-86DD-2E52B5AAB5CA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{3B639335-EAF2-40A3-B152-0BE2068FAFFB}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{3F45E21F-77F8-4F12-A35D-25733C84B347}" = protocol=6 | dir=in | app=d:\fsetup.exe |
"{4BF48DAF-E88E-4B0E-B32B-8C1DC8641EC9}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{4CA58B40-3EC6-4C2B-A66A-9716270A3CA2}" = protocol=17 | dir=in | app=c:\windows\system32\lxbfcoms.exe |
"{4DBEF5D3-107F-4D19-823A-3316143ED6DD}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{4F5E14DD-AA7A-4F72-9250-1A87B698BD4D}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{5287390A-8090-4B72-9DDD-DEFD45970805}" = protocol=17 | dir=in | app=c:\program files (x86)\bf3\battlefield 3\bf3.exe |
"{58B64600-5E26-44AD-B4A5-F1F5A4439F73}" = dir=in | app=c:\program files\hp\hp deskjet 3070 b611 series\bin\devicesetup.exe |
"{5FF55B6F-CFA5-42E9-A6DF-07D112FBA2F2}" = protocol=6 | dir=in | app=c:\program files (x86)\codemasters\of dragon rising\ofdr.exe |
"{60B8C299-EB73-4493-AAB9-2E77529077F5}" = protocol=17 | dir=in | app=c:\windows\system32\lxbfcoms.exe |
"{6A427348-1396-48F4-A7FB-9D165BE0202F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{76837BE6-6420-4924-A997-B7E805541A69}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{76B77A97-A080-48C6-8466-DF3E318F52B9}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{76C6E039-4C70-4CDB-9966-26F91CC521FD}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{78F9ECC8-FD43-4717-AB81-B3E5B1C12C59}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7CBB4109-A228-4256-BABC-B3FE6CC434E5}" = protocol=17 | dir=in | app=c:\program files (x86)\codemasters\of dragon rising\ofdr.exe |
"{82AA9E7B-679D-4AD3-BE4A-C2A6473B55B1}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{896E222E-8BEB-4380-B403-C755ED6F47E5}" = protocol=17 | dir=in | app=c:\program files (x86)\bf3\battlefield 3\bf3.exe |
"{8D6AC94D-77D1-4275-B8A5-41094D648F15}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{8F49BBE2-9D61-4D09-8347-B6F64DDF854F}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{934C4178-5EED-42EE-AD0C-B683BAD31214}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{946F01DC-CA9B-407C-8035-9335DE765979}" = protocol=6 | dir=in | app=c:\program files (x86)\codemasters\of dragon rising\ofdr.exe |
"{95568745-09ED-4F5A-9808-CC1481E28A76}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{9AD78029-34C6-463A-9237-AEA94E803D14}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{9B58DEAE-403D-49C5-A0CC-6F4A103FA650}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{9E7753C6-4B7B-4A0F-91C9-2DBA68FC0D59}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9FEA9F84-FF75-455F-B250-E273E22E5D45}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A3AD89C6-D56B-4E9D-88F6-63772FEB29F5}" = protocol=17 | dir=in | app=d:\fsetup.exe |
"{AB8FF451-60A6-4B92-B5BD-5D0B17005AA9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{AFEDD44F-D00C-457D-8791-F37DE1E94F43}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B09DAAEB-2AD5-4AD8-925B-F28BE8244BC6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B5EDDC26-D41F-42E8-B168-4F7EC08423FA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B735CC72-CDAB-4351-AD72-5D6AE5F32797}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{B7A4F85F-9990-4522-97BA-82A817100BE9}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{BB8657DD-4FC3-4D1C-B226-97C40B298C45}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BCD3BBAF-30D0-428E-86BF-176F930A25A9}" = dir=in | app=c:\program files\hp\hp deskjet 3070 b611 series\bin\hpnetworkcommunicator.exe |
"{CB737821-224A-442B-ACDB-3477609D1934}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CDB2A66C-E55E-41D7-91D8-3EE74FAAD081}" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{CFD5B692-2106-466F-B1D0-9646A1F60D3C}" = protocol=17 | dir=in | app=c:\program files (x86)\codemasters\of dragon rising\ofdr.exe |
"{D275E3F0-1AF0-4EF6-88F2-9BBB46ED3E87}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{D3332FD8-5C56-4B73-8CD7-85D49674446B}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D63ABC67-8E00-496D-AD94-B3F78F221DBC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DBFAFB3C-4B61-4B06-B3DC-9586BA818DD9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{DC1DF673-D402-4927-BE3D-D3477EAB802F}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E26ADFEE-3BFB-4AA0-96FC-CFB25752E634}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E6FDB3C2-70A6-439B-B408-0E8F86E73447}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{E7C63A00-5B5B-4ECA-98F0-2B2D249F6CE8}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{EE0BB81D-E351-4CA1-93B0-EE20EB3B5F43}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{F4A2622F-3EAB-457D-A5E1-26F1BF7AE77F}" = protocol=6 | dir=out | app=system |
"{F66CC220-A734-4F30-9280-08F279766F5C}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{FAE1869D-39BA-4BC5-82EE-17C6DD65CB3B}" = protocol=17 | dir=in | app=c:\windows\syswow64\lxbfcoms.exe |
"{FBC68AAE-CCB6-4582-88BF-9AFD229893FC}" = protocol=6 | dir=in | app=c:\windows\syswow64\lxbfcoms.exe |
"{FE827845-5923-493A-98FA-879536DB25EA}" = protocol=6 | dir=in | app=c:\windows\system32\lxbfcoms.exe |
"TCP Query User{09197238-8542-440E-919E-4B443CE97764}C:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=6 | dir=in | app=c:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe |
"TCP Query User{0C5DEF60-44BD-44AE-AA7E-67205FEE9FEE}C:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=6 | dir=in | app=c:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe |
"TCP Query User{0D0511E2-73A1-4DCF-9963-8AB03CAB2CA2}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"TCP Query User{21B37AD3-14C7-412E-9FAC-7A72345A2416}C:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe" = protocol=6 | dir=in | app=c:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe |
"TCP Query User{365D0F19-C201-47D9-AA5F-01B791CF004A}C:\program files\windows sidebar\sidebar.exe" = protocol=6 | dir=in | app=c:\program files\windows sidebar\sidebar.exe |
"TCP Query User{3E44E4A8-E491-4BFD-A64E-0310F8D1BBA9}C:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe |
"TCP Query User{9AF6ADBE-AC6A-4284-A2B2-BF9536EC1A26}C:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe |
"TCP Query User{9BF5522C-507A-4D90-8109-7FA2D477A3A7}C:\users\frank\downloads\maestia-downloader(1).exe" = protocol=6 | dir=in | app=c:\users\frank\downloads\maestia-downloader(1).exe |
"TCP Query User{D36A002D-11ED-4DCC-92D0-866FEA435BA1}C:\program files\windows sidebar\sidebar.exe" = protocol=6 | dir=in | app=c:\program files\windows sidebar\sidebar.exe |
"TCP Query User{DB9F5B3A-3D20-459F-9C71-4583C2C80C65}C:\users\frank\downloads\maestia-downloader.exe" = protocol=6 | dir=in | app=c:\users\frank\downloads\maestia-downloader.exe |
"TCP Query User{EC73549D-CF8A-4A10-80E7-FD4217DA2930}C:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe" = protocol=6 | dir=in | app=c:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe |
"TCP Query User{EEE1D85D-6AA3-4941-B078-A17063113583}D:\d-link.exe" = protocol=6 | dir=in | app=d:\d-link.exe |
"UDP Query User{44C7A380-E6C1-43AB-A61F-C001CB880F18}C:\users\frank\downloads\maestia-downloader.exe" = protocol=17 | dir=in | app=c:\users\frank\downloads\maestia-downloader.exe |
"UDP Query User{591D3E77-D290-4345-86AF-90391012DF48}C:\users\frank\downloads\maestia-downloader(1).exe" = protocol=17 | dir=in | app=c:\users\frank\downloads\maestia-downloader(1).exe |
"UDP Query User{7B51892A-DD7D-4694-A7BA-8BB1E06135BF}C:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe" = protocol=17 | dir=in | app=c:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe |
"UDP Query User{7B7DF927-7D6F-4262-95CB-463077739C45}C:\program files\windows sidebar\sidebar.exe" = protocol=17 | dir=in | app=c:\program files\windows sidebar\sidebar.exe |
"UDP Query User{993AD3F8-6681-4CC8-AD46-4D949F688F12}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"UDP Query User{9A99AA8C-DC7E-43AB-A0A7-56C4D98F9EE8}C:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=17 | dir=in | app=c:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe |
"UDP Query User{A85102DB-78CE-4983-B85E-4ABAB1766CE2}C:\program files\windows sidebar\sidebar.exe" = protocol=17 | dir=in | app=c:\program files\windows sidebar\sidebar.exe |
"UDP Query User{C508D110-21B6-476B-A660-5834D9254E16}D:\d-link.exe" = protocol=17 | dir=in | app=d:\d-link.exe |
"UDP Query User{C567A00E-2FF7-406C-BFE3-A82AC26E2F00}C:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe |
"UDP Query User{DE3CB284-7450-47DF-9406-B683B3F00219}C:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=17 | dir=in | app=c:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe |
"UDP Query User{E412DA07-514C-445A-9B79-260C72B89A38}C:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe |
"UDP Query User{F83908CB-674C-4AC9-AEC1-E997D6CB02C1}C:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe" = protocol=17 | dir=in | app=c:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F86416030FF}" = Java(TM) 6 Update 30 (64-bit)
"{2E8D6204-D656-8355-1ED3-2988AC52EB0F}" = ccc-utility64
"{336D0C35-8A85-403a-B9D2-65C292C39087}_is1" = Web Assistant 2.0.0.442
"{479B309B-E6B4-4947-8B83-472CF4272582}" = HP Deskjet 3070 B611 series - Grundlegende Software für das Gerät
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{50CBBEC7-1010-41C5-8718-A1A6FEDD9C3A}" = GEAR driver installer for AMD64 and Intel EM64T
"{5831C6D6-309D-DBB5-14F7-FEE57086CEE7}" = AMD Catalyst Install Manager
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B48E1FFD-A85D-45DB-9070-C06CDF6BD427}" = User's Guides
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D3120436-1358-4253-9EB2-257FFE8CE1D9}" = Logitech SetPoint 5.20
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D" = Windows-Treiberpaket - Nokia pccsmcfd  (08/22/2008 7.0.0.0)
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"SearchAnonymizer" = SearchAnonymizer
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{03D4C700-2BFE-43E0-A0B4-9512B43C5B9F}" = Catalyst Control Center - Branding
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{19D614EB-D62A-AEE7-2391-E74126601D59}" = CCC Help Italian
"{1A4052AB-BA77-44F7-8EE7-9F9131BFD7A6}" = OF Dragon Rising
"{1C373820-B9C8-0F7F-8F84-FC1B76A85F27}" = CCC Help Portuguese
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{25CFEF55-A945-41FC-86ED-76469F31DF37}" = Nokia Connectivity Cable Driver
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2B7E302B-9360-4A45-9A21-472D26A1EC47}" = DHP-302
"{2D35BC33-7D08-D529-DF91-8A15FBF2600E}" = CCC Help Polish
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{337788D1-43D1-9A0F-9787-DD00DB512D41}" = Catalyst Control Center Localization All
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3DE96337-68D2-48E0-A863-6E4A5CD3BC25}" = PC Connectivity Solution
"{4725833D-4325-5C34-57D4-1FE23E5AE578}" = CCC Help Chinese Standard
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B271648-43CB-DD31-FF24-E7B06D3EE72A}" = Catalyst Control Center InstallProxy
"{4CA10D13-F83A-487E-9B30-CC979FEF7A70}" = OviMPlatform
"{4DC37F33-7AEC-A4CB-56B1-69A402828763}" = CCC Help Japanese
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5710DAC2-8F2A-503C-CFC2-A973ADE0EA4C}" = CCC Help Czech
"{5C763682-4C40-86DA-9C46-31924D7D2C34}" = CCC Help Thai
"{5FCCD531-1B38-4A94-924C-127F722F1031}" = Nero 8
"{60E5022D-FA4B-C6A2-1E80-B46EC39096F3}" = CCC Help Chinese Traditional
"{60F34FDF-267C-408F-290E-EC90D841C8CB}" = CCC Help German
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6339663B-F26F-4FE3-B813-0E1DEC4ED976}" = Nokia Ovi Suite
"{66B79AE1-C6E2-B958-689C-D0812DE86BAB}" = CCC Help Greek
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B39BE0F-0F5E-A8FA-33E4-8481AE39D96C}" = CCC Help Russian
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7B1E8FA3-32BB-4902-AF7E-B9D9DAD6A675}" = Trust Webcam 16175
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E19F2AF-7145-51DE-E395-7729A9374973}" = Catalyst Control Center Graphics Previews Common
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90280407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional mit FrontPage
"{91CB5B8B-4EC8-DBA1-A88D-99FD480567B0}" = CCC Help English
"{924FBAC4-60D2-7981-3C3E-979DF9CBB346}" = CCC Help Finnish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DC939DC-B7A4-D0E2-C582-A442DF1B3EBE}" = CCC Help Spanish
"{9F20CE56-3828-432D-A3C5-3EC6A2ED93C6}" = HP Deskjet 3070 B611 series Hilfe
"{9F5FD796-86F0-4360-85F8-D54C0F5411EB}" = Steuer-Spar-Erklärung 2011
"{A1BD938B-F006-6E6D-70B2-47E1DD56F7DE}" = CCC Help Swedish
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A8F7FCEF-3CA6-4CE9-8FEA-8BB18F8686F0}" = Nokia Ovi Suite Software Updater
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AB77DFDE-9949-4AEF-B180-BE322C3E65D0}" = HTC Sync
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.1) - Deutsch
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B82157D3-6D31-4650-93B4-FC39BB08D6CE}" = AAVUpdateManager
"{BABF7852-C2DD-6A8A-9956-101720C715C7}" = CCC Help Turkish
"{BB7C2A56-9706-43B8-5A8C-210AF5816106}" = CCC Help French
"{BEF7FC5C-0182-4DDE-BDDD-F7D132AB833D}" = Ovi Desktop Sync Engine
"{CFC2CB60-5654-05A7-4D30-C661800A3A92}" = CCC Help Korean
"{D04CE005-D1D2-80F3-84C8-B3524FCD39C3}" = CCC Help Norwegian
"{D544AE4C-4152-225B-A897-6756C8986B14}" = Catalyst Control Center
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D81E9069-3CCC-4405-3751-71E4AFEACC52}" = CCC Help Hungarian
"{D8E1DFEE-622B-46BA-AEFF-AB7E541C0B21}" = Steuer-Spar-Erklärung 2010
"{DA6FAB8D-E87A-4E8E-A3D3-B7B9F479C725}" = forteManager
"{DB7AE42C-695D-4D36-A8FA-31A1C6454436}" = Nokia PC-Internetzugang
"{DDD5104F-1C44-49EB-9E6B-29EC5D27658B}" = HP Update
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E1640DA5-89B4-4F52-B15D-5DA3D14F29D4}" = LG USB Modem Drivers
"{E93FF166-DF14-2537-8FB4-96BB5810A96C}" = CCC Help Danish
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"{FA9827E1-8A8E-C176-4923-0840A67ED4DE}" = CCC Help Dutch
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9
"Audacity_is1" = Audacity 1.2.6
"Avira AntiVir Desktop" = Avira Free Antivirus
"AVMFBox" = AVM FRITZ!Box Dokumentation
"AVMFBoxPrinter" = AVM FRITZ!Box Druckeranschluss
"Battlelog Web Plugins" = Battlelog Web Plugins
"ESN Sonar-0.70.4" = ESN Sonar
"GameSpy Arcade" = GameSpy Arcade
"Host OpenAL (ADI)" = Host OpenAL (ADI)
"Inkscape" = Inkscape 0.48.2
"InstallShield_{2B7E302B-9360-4A45-9A21-472D26A1EC47}" = DHP-302
"InstallShield_{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"IrfanView" = IrfanView (remove only)
"LG Internet Kit" = LG Internet Kit
"lgx4.lgx.server" = G DATA Logox4 Speechengine
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400
"mmssetup_is1" = MixMeister Studio Demo 7.3.2
"Mozilla Firefox 13.0.1 (x86 de)" = Mozilla Firefox 13.0.1 (x86 de)
"Mozilla Thunderbird 12.0.1 (x86 de)" = Mozilla Thunderbird 12.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MPE" = MyPhoneExplorer
"Nokia Ovi Suite" = Nokia Ovi Suite
"Nokia PC Internet Access" = Nokia PC-Internetzugang
"Origin" = Origin
"PartyPoker" = PartyPoker
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 15.0" = RealPlayer
"TomTom HOME" = TomTom HOME 2.8.3.2499
"VLC media player" = VLC media player 1.1.11
"WinRAR archiver" = WinRAR Archivierer
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 27.10.2011 00:05:34 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 28.10.2011 00:06:27 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 28.10.2011 10:26:54 | Computer Name = Admin-PC | Source = Windows Installer 3.1 | ID = 921877
Description =
 
Error - 28.10.2011 10:30:39 | Computer Name = Admin-PC | Source = Windows Installer 3.1 | ID = 921877
Description =
 
Error - 28.10.2011 11:43:55 | Computer Name = Admin-PC | Source = System Restore | ID = 8193
Description =
 
Error - 28.10.2011 11:49:29 | Computer Name = Admin-PC | Source = System Restore | ID = 8193
Description =
 
Error - 28.10.2011 13:10:20 | Computer Name = Admin-PC | Source = Application Hang | ID = 1002
Description = Programm bf3.exe, Version 1.0.0.0 arbeitet nicht mehr mit Windows
zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen
 für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem
 zu suchen.  Prozess-ID: cc0  Anfangszeit: 01cc9592d87a4f80  Zeitpunkt der Beendigung:
 218
 
Error - 28.10.2011 13:30:17 | Computer Name = Admin-PC | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\Nero\Nero8\Nero Toolkit\DiscSpeed.exe". Fehler in Manifest- oder Richtliniendatei
 "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt
 mit einer anderen bereits aktiven Komponentenversion.  Die widersprüchlichen Komponenten
 sind:  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.
 
Error - 28.10.2011 13:30:18 | Computer Name = Admin-PC | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Program Files
 (x86)\Nero\Nero8\Nero Toolkit\DiscSpeed.exe". Fehler in Manifest- oder Richtliniendatei
 "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt
 mit einer anderen bereits aktiven Komponentenversion.  Die widersprüchlichen Komponenten
 sind:  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.
 
Error - 28.10.2011 13:31:32 | Computer Name = Admin-PC | Source = WinMgmt | ID = 10
Description =
 
[ System Events ]
Error - 06.07.2012 02:25:26 | Computer Name = Admin-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
 
Error - 06.07.2012 02:25:50 | Computer Name = Admin-PC | Source = Print | ID = 19
Description = Der Druckspooler konnte den Drucker HP Deskjet 3070 B611 series nicht
 unter dem Namen HP Deskjet 3070 B611 series freigeben. Fehler: 2114. Der Drucker
 kann nicht von anderen Benutzern im Netzwerk verwendet werden.
 
Error - 06.07.2012 02:26:22 | Computer Name = Admin-PC | Source = ipnathlp | ID = 31004
Description = 0 Bytes Speicher konnten durch den DNS-Proxy-Agenten nicht zugeordnet
 werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner
Fehler ist im Speicher-Manager aufgetreten.
 
Error - 06.07.2012 14:23:48 | Computer Name = Admin-PC | Source = ipnathlp | ID = 31004
Description = 0 Bytes Speicher konnten durch den DNS-Proxy-Agenten nicht zugeordnet
 werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner
Fehler ist im Speicher-Manager aufgetreten.
 
Error - 06.07.2012 14:24:51 | Computer Name = Admin-PC | Source = ipnathlp | ID = 31004
Description = 0 Bytes Speicher konnten durch den DNS-Proxy-Agenten nicht zugeordnet
 werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner
Fehler ist im Speicher-Manager aufgetreten.
 
Error - 07.07.2012 06:55:33 | Computer Name = Admin-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
 
Error - 07.07.2012 06:55:33 | Computer Name = Admin-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
 
Error - 07.07.2012 09:58:58 | Computer Name = Admin-PC | Source = ipnathlp | ID = 31004
Description = 0 Bytes Speicher konnten durch den DNS-Proxy-Agenten nicht zugeordnet
 werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner
Fehler ist im Speicher-Manager aufgetreten.
 
Error - 07.07.2012 10:32:58 | Computer Name = Admin-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
 
Error - 07.07.2012 10:32:59 | Computer Name = Admin-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
 
 
< End of report >

--- --- ---



So, weiter weiß ich nicht mehr! Hoffe ihr könnt mir helfen!

LG - Claudia

cosinus 11.07.2012 21:13

Bitte erstmal routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

maeusuruh 16.07.2012 20:40

Hallo Arne,

ich habe jetzt den Malewarebytes im Vollscan durchgeführt und er hat nichts gefunden!! Den Quickscan hatte ich ja vorher gemacht, da hatte er ja was gefunden (s.o.).

Dann habe ich den ESET Online Scanner laufen lassen: hier die log.txt

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=3eb40ff41bb27545ae6a5870f64334b3
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-07-16 07:05:49
# local_time=2012-07-16 09:05:49 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 11084397 11084397 0 0
# compatibility_mode=4096 16777215 100 0 0 0 0 0
# compatibility_mode=5892 16776573 100 56 297235 179981374 0 0
# compatibility_mode=8192 67108863 100 0 192 192 0 0
# scanned=326747
# found=0
# cleaned=0
# scan_time=8081

Was mach ich nun weiter???

Schöne Grüße

Claudia

cosinus 17.07.2012 11:08

Zitat:

ich habe jetzt den Malewarebytes im Vollscan durchgeführt und er hat nichts gefunden!!
Trotzdem bitte alle Logs davon posten
Die Logs enthalten ein paar mehr Infos als nur Fund oder kein Fund.

Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

maeusuruh 17.07.2012 21:34

Ok, hier der Vollscan:

Code:

Malwarebytes Anti-Malware (Test) 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.07.17.12

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Frank :: ADMIN-PC [Administrator]

Schutz: Deaktiviert

17.07.2012 20:40:41
mbam-log-2012-07-17 (20-40-41).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 491451
Laufzeit: 1 Stunde(n), 45 Minute(n), 35 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Gruß Claudia

cosinus 18.07.2012 16:02

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

maeusuruh 18.07.2012 16:44

Hier der adwcleaner:

Code:

# AdwCleaner v1.702 - Logfile created 07/18/2012 at 17:41:48
# Updated 13/07/2012 by Xplode
# Operating system : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# User : Frank - ADMIN-PC
# Running from : C:\Users\Frank\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****

Found : Web Assistant Updater

***** [Files / Folders] *****

Folder Found : C:\Users\Frank\AppData\Local\OpenCandy
Folder Found : C:\Users\Frank\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Frank\AppData\LocalLow\Conduit
Folder Found : C:\Users\Frank\AppData\LocalLow\facemoods.com
Folder Found : C:\Users\Frank\AppData\Roaming\OpenCandy
Folder Found : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\Conduit
Folder Found : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\ConduitEngine
Folder Found : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\extensions\ffxtlbra@softonic.com
Folder Found : C:\ProgramData\Ask
Folder Found : C:\Program Files\Web Assistant
Folder Found : C:\Program Files (x86)\Ask.com
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
File Found : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\Askcom.xml
File Found : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\Conduit.xml
File Found : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\MyStart Search.xml

***** [Registry] *****

Key Found : HKCU\Software\APN
Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\Ask.com
Key Found : HKCU\Software\IM
Key Found : HKCU\Software\ImInstaller
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Found : HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\APN
Key Found : HKLM\SOFTWARE\AskToolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Found : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
Key Found : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\DT Soft
Key Found : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Found : HKLM\SOFTWARE\Software
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
[x64] Key Found : HKCU\Software\APN
[x64] Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
[x64] Key Found : HKCU\Software\AppDataLow\Software\Conduit
[x64] Key Found : HKCU\Software\Ask.com
[x64] Key Found : HKCU\Software\IM
[x64] Key Found : HKCU\Software\ImInstaller
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
[x64] Key Found : HKCU\Software\Softonic
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
[x64] Key Found : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
[x64] Key Found : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
[x64] Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
[x64] Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
[x64] Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
[x64] Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
[x64] Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
[x64] Key Found : HKLM\SOFTWARE\Software
[x64] Key Found : HKLM\SOFTWARE\Web Assistant
[x64] Value Found : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Found : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Found : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403a-B9D2-65C292C39087}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
[x64] Key Found : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
[x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
[x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
[x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
[x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403a-B9D2-65C292C39087}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
[x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
[x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://mystart.incredibar.com/mb165?a=6R8vQpBcfa&i=26
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://start.facemoods.com/?a=dpg&s={searchTerms}&f=4

-\\ Mozilla Firefox v13.0.1 (de)

Profile name : default
File : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\prefs.js

Found : user_pref("CT2582601..clientLogIsEnabled", true);
Found : user_pref("CT2582601..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT2582601..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT2582601.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2582601.CTID", "CT2582601");
Found : user_pref("CT2582601.CurrentServerDate", "1-5-2011");
Found : user_pref("CT2582601.DialogsAlignMode", "LTR");
Found : user_pref("CT2582601.DialogsGetterLastCheckTime", "Sun May 01 2011 11:40:18 GMT+0200");
Found : user_pref("CT2582601.DownloadReferralCookieData", "");
Found : user_pref("CT2582601.EMailNotifierPollDate", "Sun Nov 21 2010 13:34:27 GMT+0100");
Found : user_pref("CT2582601.FeedLastCount203199574394042224", 477);
Found : user_pref("CT2582601.FeedPollDate129255010797257841", "Sun Nov 21 2010 13:23:47 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257847", "Sun Nov 21 2010 13:23:47 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257853", "Sun Nov 21 2010 13:23:47 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257859", "Sun Nov 21 2010 13:23:47 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257865", "Sun Nov 21 2010 13:23:47 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257871", "Sun Nov 21 2010 13:23:47 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257877", "Sun Nov 21 2010 13:23:47 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257883", "Sun Nov 21 2010 13:23:47 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257889", "Sun Nov 21 2010 13:23:47 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257895", "Sun Nov 21 2010 13:23:47 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257901", "Sun Nov 21 2010 13:23:48 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257907", "Sun Nov 21 2010 13:23:48 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257913", "Sun Nov 21 2010 13:23:48 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257919", "Sun Nov 21 2010 13:23:48 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257925", "Sun Nov 21 2010 13:23:48 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257931", "Sun Nov 21 2010 13:23:48 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257937", "Sun Nov 21 2010 13:23:48 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257943", "Sun Nov 21 2010 13:23:49 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257949", "Sun Nov 21 2010 13:23:49 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257955", "Sun Nov 21 2010 13:23:51 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257961", "Sun Nov 21 2010 13:23:51 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257967", "Sun Nov 21 2010 13:23:51 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257973", "Sun Nov 21 2010 13:23:51 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257979", "Sun Nov 21 2010 13:23:51 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257985", "Sun Nov 21 2010 13:23:51 GMT+0100");
Found : user_pref("CT2582601.FeedPollDate129255010797257991", "Sun Nov 21 2010 13:23:51 GMT+0100");
Found : user_pref("CT2582601.FeedTTL129255010797257853", 5);
Found : user_pref("CT2582601.FeedTTL129255010797257859", 5);
Found : user_pref("CT2582601.FeedTTL129255010797257889", 2);
Found : user_pref("CT2582601.FeedTTL129255010797257919", 5);
Found : user_pref("CT2582601.FeedTTL129255010797257931", 30);
Found : user_pref("CT2582601.FirstServerDate", "21-11-2010");
Found : user_pref("CT2582601.FirstTime", true);
Found : user_pref("CT2582601.FirstTimeFF3", true);
Found : user_pref("CT2582601.FirstTimeSettingsDone", true);
Found : user_pref("CT2582601.FixPageNotFoundErrors", true);
Found : user_pref("CT2582601.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2582601.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2582601.HasUserGlobalKeys", true);
Found : user_pref("CT2582601.Initialize", true);
Found : user_pref("CT2582601.InitializeCommonPrefs", true);
Found : user_pref("CT2582601.InstallationAndCookieDataSentCount", 2);
Found : user_pref("CT2582601.InstallationId", "np_0033");
Found : user_pref("CT2582601.InstallationType", "ExternalIntegration");
Found : user_pref("CT2582601.InstalledDate", "Sun Nov 21 2010 13:23:47 GMT+0100");
Found : user_pref("CT2582601.InvalidateCache", false);
Found : user_pref("CT2582601.IsGrouping", false);
Found : user_pref("CT2582601.IsMulticommunity", false);
Found : user_pref("CT2582601.IsOpenThankYouPage", false);
Found : user_pref("CT2582601.IsOpenUninstallPage", true);
Found : user_pref("CT2582601.LanguagePackLastCheckTime", "Sun May 01 2011 11:40:18 GMT+0200");
Found : user_pref("CT2582601.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2582601.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2582601.LastLogin_2.7.1.3", "Sun Nov 21 2010 13:23:47 GMT+0100");
Found : user_pref("CT2582601.LastLogin_3.3.3.2", "Sun May 01 2011 11:40:19 GMT+0200");
Found : user_pref("CT2582601.LatestVersion", "3.2.5.2");
Found : user_pref("CT2582601.Locale", "de");
Found : user_pref("CT2582601.LoginCache", 4);
Found : user_pref("CT2582601.MCDetectTooltipHeight", "83");
Found : user_pref("CT2582601.MCDetectTooltipShow", false);
Found : user_pref("CT2582601.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2582601.MCDetectTooltipWidth", "295");
Found : user_pref("CT2582601.PublisherContainerWidth", 1360);
Found : user_pref("CT2582601.RadioIsPodcast", false);
Found : user_pref("CT2582601.RadioLastCheckTime", "Sun Nov 21 2010 13:23:47 GMT+0100");
Found : user_pref("CT2582601.RadioLastUpdateIPServer", "3");
Found : user_pref("CT2582601.RadioLastUpdateServer", "3");
Found : user_pref("CT2582601.RadioMediaID", "9951");
Found : user_pref("CT2582601.RadioMediaType", "Media Player");
Found : user_pref("CT2582601.RadioMenuSelectedID", "EBRadioMenu_CT2582601_RECENT9951");
Found : user_pref("CT2582601.RadioShrinked", "expanded");
Found : user_pref("CT2582601.RadioStationName", "Rap");
Found : user_pref("CT2582601.RadioStationURL", "hxxp://www.defjay.com/listen.asx");
Found : user_pref("CT2582601.RadioVolume", "34");
Found : user_pref("CT2582601.SavedHomepage", "hxxp://www.die-staemme.de/");
Found : user_pref("CT2582601.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Found : user_pref("CT2582601.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2582601.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT258[...]
Found : user_pref("CT2582601.SearchInNewTabEnabled", true);
Found : user_pref("CT2582601.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2582601.SearchInNewTabLastCheckTime", "Sun May 01 2011 11:40:19 GMT+0200");
Found : user_pref("CT2582601.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2582601.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Found : user_pref("CT2582601.SearchInNewTabUserEnabled", false);
Found : user_pref("CT2582601.ServiceMapLastCheckTime", "Sun May 01 2011 11:40:18 GMT+0200");
Found : user_pref("CT2582601.SettingsCheckIntervalMin", 120);
Found : user_pref("CT2582601.SettingsLastCheckTime", "Sun May 01 2011 11:40:18 GMT+0200");
Found : user_pref("CT2582601.SettingsLastUpdate", "1299524390");
Found : user_pref("CT2582601.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2582601.ThirdPartyComponentsLastCheck", "Sun May 01 2011 11:40:18 GMT+0200");
Found : user_pref("CT2582601.ThirdPartyComponentsLastUpdate", "1255348257");
Found : user_pref("CT2582601.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2582601");
Found : user_pref("CT2582601.Uninstall", true);
Found : user_pref("CT2582601.UserID", "UN95689624456545820");
Found : user_pref("CT2582601.ValidationData_Toolbar", 2);
Found : user_pref("CT2582601.WeatherNetwork", "");
Found : user_pref("CT2582601.WeatherPollDate", "Sun Nov 21 2010 14:05:48 GMT+0100");
Found : user_pref("CT2582601.WeatherUnit", "C");
Found : user_pref("CT2582601.alertChannelId", "975434");
Found : user_pref("CT2582601.backendstorage.facebbok_user_id", "313030303030323036353534383937");
Found : user_pref("CT2582601.backendstorage.facebook_login_status", "31");
Found : user_pref("CT2582601.backendstorage.facebook_lust_recievegadet", "");
Found : user_pref("CT2582601.backendstorage.facebook_mode", "32");
Found : user_pref("CT2582601.backendstorage.facebook_user_name", "3078303034332C3078303036432C3078303036312C[...]
Found : user_pref("CT2582601.backendstorage.facebook_user_token", "3230393834353033353330347C656166363136356[...]
Found : user_pref("CT2582601.backendstorage.facebooknotifications", "31");
Found : user_pref("CT2582601.backendstorage.hxxp://cmg1_conduit-widgets_com/pitsi.state", "434C4F5345");
Found : user_pref("CT2582601.backendstorage.hxxp://facebook_conduitapps_com/v308.facebook_friendsuploadstab_[...]
Found : user_pref("CT2582601.backendstorage.hxxp://facebook_conduitapps_com/v308.facebook_last_visit_tab", "[...]
Found : user_pref("CT2582601.backendstorage.hxxp://facebook_conduitapps_com/v308.facebook_myuploadstab_pos",[...]
Found : user_pref("CT2582601.clientLogIsEnabled", true);
Found : user_pref("CT2582601.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Found : user_pref("CT2582601.components.1000034", false);
Found : user_pref("CT2582601.components.1003", true);
Found : user_pref("CT2582601.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
Found : user_pref("CT2582601.globalFirstTimeInfoLastCheckTime", "Sun May 01 2011 11:40:19 GMT+0200");
Found : user_pref("CT2582601.isAppTrackingManagerOn", true);
Found : user_pref("CT2582601.myStuffEnabled", true);
Found : user_pref("CT2582601.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2582601.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2582601.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2582601.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2582601.oldAppsList", "129144940768357001,129144940768669502,129144940770700906,1000082[...]
Found : user_pref("CT2582601.testingCtid", "");
Found : user_pref("CT2582601.toolbarAppMetaDataLastCheckTime", "Sun May 01 2011 11:40:18 GMT+0200");
Found : user_pref("CT2582601.toolbarContextMenuLastCheckTime", "Sun May 01 2011 11:40:18 GMT+0200");
Found : user_pref("CT2582601.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Found : user_pref("CommunityToolbar.CantToolbarBeEngineOwner", "CT2582601");
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"")[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2582601", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.2[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2582601",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2582601/CT2582601[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"634[...]
Found : user_pref("CommunityToolbar.EngineHiddenByUser", true);
Found : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
Found : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com");
Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
Found : user_pref("CommunityToolbar.IsEngineShown", false);
Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Found : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://cdn.triplegames.com/shared/apps/gamearcade/ar[...]
Found : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://plasmoo.com/result.htm?q=");
Found : user_pref("CommunityToolbar.ToolbarsList", "CT2582601,ConduitEngine");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2582601");
Found : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon Mar 21 2011 16:58:47 GMT+01[...]
Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun May 01 2011 01:17:33 GMT+0200");
Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.alert.locale", "en");
Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sun May 01 2011 01:17:25 GMT+0200");
Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1303303927");
Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.alert.userId", "d28878a8-54b1-44ff-893f-1689174313cc");
Found : user_pref("CommunityToolbar.facebook.sessionKey", "eaf6165a52ee896139383624-100000206554897");
Found : user_pref("CommunityToolbar.facebook.sessionSecret", "dc74e0df59a52ac607c385084305d878");
Found : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sun Nov 21 2010 13:23:47 GMT+0100");
Found : user_pref("CommunityToolbar.facebook.userId", "100000206554897");
Found : user_pref("CommunityToolbar.globalUserId", "a32c2896-5c8e-4535-8786-732ccbb427df");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2582601");
Found : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Wed Apr 20 2011 22:52:14 GMT+0200");
Found : user_pref("ConduitEngine.BrowserCompStateIsOpen_1627818309137728572", true);
Found : user_pref("ConduitEngine.CTID", "ConduitEngine");
Found : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Sun May 01 2011 11:36:31 GMT+0200");
Found : user_pref("ConduitEngine.FirstServerDate", "03/21/2011 17");
Found : user_pref("ConduitEngine.FirstTime", true);
Found : user_pref("ConduitEngine.FirstTimeFF3", true);
Found : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Found : user_pref("ConduitEngine.Initialize", true);
Found : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Found : user_pref("ConduitEngine.InstalledDate", "Mon Mar 21 2011 16:58:48 GMT+0100");
Found : user_pref("ConduitEngine.IsMulticommunity", false);
Found : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Found : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Found : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Sun May 01 2011 11:36:31 GMT+0200");
Found : user_pref("ConduitEngine.LastLogin_3.3.2.1", "Tue Mar 22 2011 12:04:32 GMT+0100");
Found : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Sun May 01 2011 11:36:32 GMT+0200");
Found : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Found : user_pref("ConduitEngine.SettingsLastCheckTime", "Sun May 01 2011 11:36:31 GMT+0200");
Found : user_pref("ConduitEngine.UserID", "UN91039505358548577");
Found : user_pref("ConduitEngine.apps1627818309137728572", false);
Found : user_pref("ConduitEngine.componentAlertEnabled", false);
Found : user_pref("ConduitEngine.engineLocale", "de");
Found : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Sun May 01 2011 11:36:32 GMT+0200");
Found : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Sun May 01 2011 11:36:31 GMT+0200");
Found : user_pref("ConduitEngine.initDone", true);
Found : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Found : user_pref("ConduitEngine.usagesFlag", 2);
Found : user_pref("browser.search.defaultengine", "Ask.com");
Found : user_pref("browser.search.defaultenginename", "Ask.com");
Found : user_pref("browser.search.defaultthis.engineName", "pc gear de Customized Web Search");
Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2582601&Sea[...]
Found : user_pref("browser.search.order.1", "Ask.com");
Found : user_pref("extensions.Softonic.admin", false);
Found : user_pref("extensions.Softonic.aflt", "orgnl");
Found : user_pref("extensions.Softonic.autoRvrt", "false");
Found : user_pref("extensions.Softonic.cntry", "DE");
Found : user_pref("extensions.Softonic.dfltLng", "");
Found : user_pref("extensions.Softonic.dfltlng", "en");
Found : user_pref("extensions.Softonic.dfltsrch", "false");
Found : user_pref("extensions.Softonic.envrmnt", "production");
Found : user_pref("extensions.Softonic.excTlbr", false);
Found : user_pref("extensions.Softonic.hdrMd5", "C6870FEE33F57EE46463A55EBC1E8B72");
Found : user_pref("extensions.Softonic.hmpg", false);
Found : user_pref("extensions.Softonic.hrdid", "8c0dac64000000000000002215600bad");
Found : user_pref("extensions.Softonic.id", "8c0dac64000000000000002215600bad");
Found : user_pref("extensions.Softonic.instlDay", "15492");
Found : user_pref("extensions.Softonic.instlRef", "MON00001");
Found : user_pref("extensions.Softonic.instlday", "15492");
Found : user_pref("extensions.Softonic.instlref", "MON00001");
Found : user_pref("extensions.Softonic.isDcmntCmplt", true);
Found : user_pref("extensions.Softonic.isdcmntcmplt", "false");
Found : user_pref("extensions.Softonic.keywordurl", "");
Found : user_pref("extensions.Softonic.lastVrsnTs", "1.5.24.323:34:20");
Found : user_pref("extensions.Softonic.mntrvrsn", "1.3.0");
Found : user_pref("extensions.Softonic.newTab", false);
Found : user_pref("extensions.Softonic.newtab", "false");
Found : user_pref("extensions.Softonic.newtaburl", "");
Found : user_pref("extensions.Softonic.prdct", "Softonic");
Found : user_pref("extensions.Softonic.prtnrId", "softonic");
Found : user_pref("extensions.Softonic.prtnrid", "softonic");
Found : user_pref("extensions.Softonic.rvrtMsg", "Click Yes to keep current home page and default search set[...]
Found : user_pref("extensions.Softonic.savedVrsnTs", "1");
Found : user_pref("extensions.Softonic.sg", "az");
Found : user_pref("extensions.Softonic.similarsitesstorage-pid2", "8489e505aeab360d");
Found : user_pref("extensions.Softonic.smplGrp", "none");
Found : user_pref("extensions.Softonic.smplgrp", "none");
Found : user_pref("extensions.Softonic.srch", "");
Found : user_pref("extensions.Softonic.srchprvdr", "");
Found : user_pref("extensions.Softonic.tlbrId", "base");
Found : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MON00001/tb_v1?SearchSource[...]
Found : user_pref("extensions.Softonic.tlbrid", "base");
Found : user_pref("extensions.Softonic.tlbrsrchurl", "hxxp://search.softonic.com/MON00001/tb_v1?SearchSource[...]
Found : user_pref("extensions.Softonic.vrsn", "1.5.24.3");
Found : user_pref("extensions.Softonic.vrsnTs", "1.5.24.323:34:20");
Found : user_pref("extensions.Softonic.vrsni", "1.5.24.3");
Found : user_pref("extensions.Softonic.vrsnts", "1.5.24.323:34:20");
Found : user_pref("extensions.Softonic_i.newTab", false);
Found : user_pref("extensions.Softonic_i.smplGrp", "none");
Found : user_pref("extensions.Softonic_i.vrsnTs", "1.5.24.323:34:20");
Found : user_pref("extensions.asktb.abar-war-regex", "conduit\\.com");
Found : user_pref("extensions.asktb.autofill-competitor-query-enabled", true);
Found : user_pref("extensions.asktb.cbid", "U3");
Found : user_pref("extensions.asktb.config-updated", false);
Found : user_pref("extensions.asktb.crumb", "2012.07.08+00.08.16-toolbar003iad-DE-QmVybGluLEdlcm1hbnk%3D");
Found : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.ask.com/web?q={query}&qsrc={qsrc}&[...]
Found : user_pref("extensions.asktb.displaybehavior", "");
Found : user_pref("extensions.asktb.displaytext", "");
Found : user_pref("extensions.asktb.dtid", "YYYYYYYYDE");
Found : user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false);
Found : user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "GMXX0007");
Found : user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "C");
Found : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://mystart.incredibar.com/mb165/?loc=IB_D[...]
Found : user_pref("extensions.asktb.first-restart-after-config-update", true);
Found : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com[...]
Found : user_pref("extensions.asktb.l", "dis");
Found : user_pref("extensions.asktb.last-config-req", "1341850132200");
Found : user_pref("extensions.asktb.last-v", "3.14.1.100013");
Found : user_pref("extensions.asktb.locale", "de_DE");
Found : user_pref("extensions.asktb.location", "Berlin,Germany");
Found : user_pref("extensions.asktb.lstation", "");
Found : user_pref("extensions.asktb.news-native-on", true);
Found : user_pref("extensions.asktb.o", "100000027");
Found : user_pref("extensions.asktb.pstate", "");
Found : user_pref("extensions.asktb.qsrc", "2871");
Found : user_pref("extensions.asktb.search-suggestions-enabled", true);
Found : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false);
Found : user_pref("extensions.asktb.socialmini-first", true);
Found : user_pref("extensions.asktb.socialmini-interval", "1200000");
Found : user_pref("extensions.asktb.socialmini-max-char-ticker", "33");
Found : user_pref("extensions.asktb.socialmini-max-items", "30");
Found : user_pref("extensions.asktb.socialmini-native-on", true);
Found : user_pref("extensions.asktb.socialmini-speed", "10000");
Found : user_pref("extensions.asktb.socialmini-transition-first-open", false);
Found : user_pref("extensions.asktb.to", "");
Found : user_pref("extensions.enabledAddons", "fb_add_on@avm.de:1.6.3,ich@maltegoetz.de:1.4.2,ffxtlbra@softo[...]
Found : user_pref("extensions.facemoods.aflt", "_#dpg");
Found : user_pref("extensions.facemoods.firstRun", false);
Found : user_pref("extensions.facemoods.lastActv", "6");
Found : user_pref("extensions.incredibar.actvtyRptTime", "1341467344666");
Found : user_pref("extensions.incredibar.admin", false);
Found : user_pref("extensions.incredibar.aflt", "orgnl");
Found : user_pref("extensions.incredibar.afterInstallRpt", "sent");
Found : user_pref("extensions.incredibar.cntry", "DE");
Found : user_pref("extensions.incredibar.dfltLng", "EN");
Found : user_pref("extensions.incredibar.dfltSrch", false);
Found : user_pref("extensions.incredibar.dfltlng", "EN");
Found : user_pref("extensions.incredibar.dfltsrch", "false");
Found : user_pref("extensions.incredibar.did", "10665");
Found : user_pref("extensions.incredibar.envrmnt", "production");
Found : user_pref("extensions.incredibar.excTlbr", false);
Found : user_pref("extensions.incredibar.hdrMd5", "D2BF7951FBB008229551AA1ADAAAA037");
Found : user_pref("extensions.incredibar.hmpg", false);
Found : user_pref("extensions.incredibar.hrdid", "0");
Found : user_pref("extensions.incredibar.id", "8c0dac64000000000000002215600bad");
Found : user_pref("extensions.incredibar.installerproductid", "26");
Found : user_pref("extensions.incredibar.instlDay", "15504");
Found : user_pref("extensions.incredibar.instlRef", "");
Found : user_pref("extensions.incredibar.instlday", "15504");
Found : user_pref("extensions.incredibar.instlref", "");
Found : user_pref("extensions.incredibar.isDcmntCmplt", false);
Found : user_pref("extensions.incredibar.isdcmntcmplt", "false");
Found : user_pref("extensions.incredibar.keywordurl", "");
Found : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.147:33:53");
Found : user_pref("extensions.incredibar.logicsMngrDailyReportTime", "05-07-2012");
Found : user_pref("extensions.incredibar.mntrvrsn", "1.2.0");
Found : user_pref("extensions.incredibar.newTab", false);
Found : user_pref("extensions.incredibar.newtab", "false");
Found : user_pref("extensions.incredibar.newtaburl", "");
Found : user_pref("extensions.incredibar.noFFXTlbr", false);
Found : user_pref("extensions.incredibar.ppd", "");
Found : user_pref("extensions.incredibar.prdct", "incredibar");
Found : user_pref("extensions.incredibar.productid", "26");
Found : user_pref("extensions.incredibar.propectorlck", 80068214);
Found : user_pref("extensions.incredibar.prtkHmpg", 1);
Found : user_pref("extensions.incredibar.prtnrId", "Incredibar");
Found : user_pref("extensions.incredibar.prtnrid", "Incredibar");
Found : user_pref("extensions.incredibar.sg", "none");
Found : user_pref("extensions.incredibar.smplGrp", "none");
Found : user_pref("extensions.incredibar.smplgrp", "none");
Found : user_pref("extensions.incredibar.srch", "");
Found : user_pref("extensions.incredibar.srchprvdr", "");
Found : user_pref("extensions.incredibar.tlbrId", "base");
Found : user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8vQpBcfa&loc=IB_T[...]
Found : user_pref("extensions.incredibar.tlbrid", "base");
Found : user_pref("extensions.incredibar.tlbrsrchurl", "hxxp://mystart.Incredibar.com/?a=6R8vQpBcfa&loc=IB_T[...]
Found : user_pref("extensions.incredibar.upn2", "6R8vQpBcfa");
Found : user_pref("extensions.incredibar.upn2n", "92824526614914436");
Found : user_pref("extensions.incredibar.vrsn", "1.5.11.14");
Found : user_pref("extensions.incredibar.vrsnTs", "1.5.11.147:33:53");
Found : user_pref("extensions.incredibar.vrsni", "1.5.11.14");
Found : user_pref("extensions.incredibar.vrsnts", "1.5.11.147:33:53");
Found : user_pref("extensions.incredibar_i.aflt", "orgnl");
Found : user_pref("extensions.incredibar_i.dfltLng", "");
Found : user_pref("extensions.incredibar_i.did", "10665");
Found : user_pref("extensions.incredibar_i.excTlbr", false);
Found : user_pref("extensions.incredibar_i.id", "8c0dac64000000000000002215600bad");
Found : user_pref("extensions.incredibar_i.installerproductid", "26");
Found : user_pref("extensions.incredibar_i.instlDay", "15504");
Found : user_pref("extensions.incredibar_i.instlRef", "");
Found : user_pref("extensions.incredibar_i.ms_url_id", "");
Found : user_pref("extensions.incredibar_i.newTab", false);
Found : user_pref("extensions.incredibar_i.ppd", "");
Found : user_pref("extensions.incredibar_i.prdct", "incredibar");
Found : user_pref("extensions.incredibar_i.productid", "26");
Found : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
Found : user_pref("extensions.incredibar_i.smplGrp", "none");
Found : user_pref("extensions.incredibar_i.tlbrId", "base");
Found : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8vQpBcfa&loc=IB[...]
Found : user_pref("extensions.incredibar_i.upn2", "6R8vQpBcfa");
Found : user_pref("extensions.incredibar_i.upn2n", "92824526614914436");
Found : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14");
Found : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.147:33:53");
Found : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14");
Found : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ORJ&o=100000027&loca[...]
Found : user_pref("plasmoo.search.engine.prevkeywordurl", "hxxp://start.facemoods.com/results.php?f=5&a=dpg&[...]
Found : user_pref("plasmoo.search.engine.prevsearchdefaultthisenginename", "pc gear de Customized Web Search[...]
Found : user_pref("plasmoo.search.engine.prevsearchdefaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?c[...]

*************************

AdwCleaner[R1].txt - [41164 octets] - [18/07/2012 17:41:48]

########## EOF - C:\AdwCleaner[R1].txt - [41293 octets] ##########


cosinus 18.07.2012 21:23

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

maeusuruh 19.07.2012 11:11

adwCleaner - Delete:

Code:

# AdwCleaner v1.702 - Logfile created 07/19/2012 at 12:04:31
# Updated 13/07/2012 by Xplode
# Operating system : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# User : Frank - ADMIN-PC
# Running from : C:\Users\Frank\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****

Stopped & Deleted : Web Assistant Updater

***** [Files / Folders] *****

Deleted on reboot : C:\Users\Frank\AppData\Local\OpenCandy
Deleted on reboot : C:\Users\Frank\AppData\LocalLow\AskToolbar
Deleted on reboot : C:\Users\Frank\AppData\LocalLow\Conduit
Deleted on reboot : C:\Users\Frank\AppData\LocalLow\facemoods.com
Deleted on reboot : C:\Users\Frank\AppData\Roaming\OpenCandy
Deleted on reboot : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\Conduit
Deleted on reboot : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\ConduitEngine
Deleted on reboot : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\extensions\ffxtlbra@softonic.com
Deleted on reboot : C:\ProgramData\Ask
Deleted on reboot : C:\Program Files\Web Assistant
Deleted on reboot : C:\Program Files (x86)\Ask.com
Deleted on reboot : C:\Program Files (x86)\Conduit
Deleted on reboot : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
File Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\Askcom.xml
File Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\Conduit.xml
File Deleted : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\MyStart Search.xml

***** [Registry] *****

Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\APN
Key Deleted : HKLM\SOFTWARE\AskToolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\DT Soft
Key Deleted : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Software
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
[x64] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
[x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
[x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
[x64] Key Deleted : HKLM\SOFTWARE\Software
[x64] Key Deleted : HKLM\SOFTWARE\Web Assistant

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403a-B9D2-65C292C39087}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
[x64] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}
[x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://mystart.incredibar.com/mb165?a=6R8vQpBcfa&i=26 --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://start.facemoods.com/?a=dpg&s={searchTerms}&f=4 --> hxxp://www.google.com

-\\ Mozilla Firefox v14.0.1 (de)

Profile name : default
File : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\prefs.js

C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\user.js ... Deleted !

Deleted : user_pref("CT2582601..clientLogIsEnabled", true);
Deleted : user_pref("CT2582601..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2582601..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2582601.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2582601.CTID", "CT2582601");
Deleted : user_pref("CT2582601.CurrentServerDate", "1-5-2011");
Deleted : user_pref("CT2582601.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2582601.DialogsGetterLastCheckTime", "Sun May 01 2011 11:40:18 GMT+0200");
Deleted : user_pref("CT2582601.DownloadReferralCookieData", "");
Deleted : user_pref("CT2582601.EMailNotifierPollDate", "Sun Nov 21 2010 13:34:27 GMT+0100");
Deleted : user_pref("CT2582601.FeedLastCount203199574394042224", 477);
Deleted : user_pref("CT2582601.FeedPollDate129255010797257841", "Sun Nov 21 2010 13:23:47 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257847", "Sun Nov 21 2010 13:23:47 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257853", "Sun Nov 21 2010 13:23:47 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257859", "Sun Nov 21 2010 13:23:47 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257865", "Sun Nov 21 2010 13:23:47 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257871", "Sun Nov 21 2010 13:23:47 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257877", "Sun Nov 21 2010 13:23:47 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257883", "Sun Nov 21 2010 13:23:47 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257889", "Sun Nov 21 2010 13:23:47 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257895", "Sun Nov 21 2010 13:23:47 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257901", "Sun Nov 21 2010 13:23:48 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257907", "Sun Nov 21 2010 13:23:48 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257913", "Sun Nov 21 2010 13:23:48 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257919", "Sun Nov 21 2010 13:23:48 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257925", "Sun Nov 21 2010 13:23:48 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257931", "Sun Nov 21 2010 13:23:48 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257937", "Sun Nov 21 2010 13:23:48 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257943", "Sun Nov 21 2010 13:23:49 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257949", "Sun Nov 21 2010 13:23:49 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257955", "Sun Nov 21 2010 13:23:51 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257961", "Sun Nov 21 2010 13:23:51 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257967", "Sun Nov 21 2010 13:23:51 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257973", "Sun Nov 21 2010 13:23:51 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257979", "Sun Nov 21 2010 13:23:51 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257985", "Sun Nov 21 2010 13:23:51 GMT+0100");
Deleted : user_pref("CT2582601.FeedPollDate129255010797257991", "Sun Nov 21 2010 13:23:51 GMT+0100");
Deleted : user_pref("CT2582601.FeedTTL129255010797257853", 5);
Deleted : user_pref("CT2582601.FeedTTL129255010797257859", 5);
Deleted : user_pref("CT2582601.FeedTTL129255010797257889", 2);
Deleted : user_pref("CT2582601.FeedTTL129255010797257919", 5);
Deleted : user_pref("CT2582601.FeedTTL129255010797257931", 30);
Deleted : user_pref("CT2582601.FirstServerDate", "21-11-2010");
Deleted : user_pref("CT2582601.FirstTime", true);
Deleted : user_pref("CT2582601.FirstTimeFF3", true);
Deleted : user_pref("CT2582601.FirstTimeSettingsDone", true);
Deleted : user_pref("CT2582601.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2582601.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2582601.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2582601.HasUserGlobalKeys", true);
Deleted : user_pref("CT2582601.Initialize", true);
Deleted : user_pref("CT2582601.InitializeCommonPrefs", true);
Deleted : user_pref("CT2582601.InstallationAndCookieDataSentCount", 2);
Deleted : user_pref("CT2582601.InstallationId", "np_0033");
Deleted : user_pref("CT2582601.InstallationType", "ExternalIntegration");
Deleted : user_pref("CT2582601.InstalledDate", "Sun Nov 21 2010 13:23:47 GMT+0100");
Deleted : user_pref("CT2582601.InvalidateCache", false);
Deleted : user_pref("CT2582601.IsGrouping", false);
Deleted : user_pref("CT2582601.IsMulticommunity", false);
Deleted : user_pref("CT2582601.IsOpenThankYouPage", false);
Deleted : user_pref("CT2582601.IsOpenUninstallPage", true);
Deleted : user_pref("CT2582601.LanguagePackLastCheckTime", "Sun May 01 2011 11:40:18 GMT+0200");
Deleted : user_pref("CT2582601.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2582601.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2582601.LastLogin_2.7.1.3", "Sun Nov 21 2010 13:23:47 GMT+0100");
Deleted : user_pref("CT2582601.LastLogin_3.3.3.2", "Sun May 01 2011 11:40:19 GMT+0200");
Deleted : user_pref("CT2582601.LatestVersion", "3.2.5.2");
Deleted : user_pref("CT2582601.Locale", "de");
Deleted : user_pref("CT2582601.LoginCache", 4);
Deleted : user_pref("CT2582601.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2582601.MCDetectTooltipShow", false);
Deleted : user_pref("CT2582601.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2582601.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2582601.PublisherContainerWidth", 1360);
Deleted : user_pref("CT2582601.RadioIsPodcast", false);
Deleted : user_pref("CT2582601.RadioLastCheckTime", "Sun Nov 21 2010 13:23:47 GMT+0100");
Deleted : user_pref("CT2582601.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2582601.RadioLastUpdateServer", "3");
Deleted : user_pref("CT2582601.RadioMediaID", "9951");
Deleted : user_pref("CT2582601.RadioMediaType", "Media Player");
Deleted : user_pref("CT2582601.RadioMenuSelectedID", "EBRadioMenu_CT2582601_RECENT9951");
Deleted : user_pref("CT2582601.RadioShrinked", "expanded");
Deleted : user_pref("CT2582601.RadioStationName", "Rap");
Deleted : user_pref("CT2582601.RadioStationURL", "hxxp://www.defjay.com/listen.asx");
Deleted : user_pref("CT2582601.RadioVolume", "34");
Deleted : user_pref("CT2582601.SavedHomepage", "hxxp://www.die-staemme.de/");
Deleted : user_pref("CT2582601.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Deleted : user_pref("CT2582601.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2582601.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT258[...]
Deleted : user_pref("CT2582601.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2582601.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2582601.SearchInNewTabLastCheckTime", "Sun May 01 2011 11:40:19 GMT+0200");
Deleted : user_pref("CT2582601.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2582601.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2582601.SearchInNewTabUserEnabled", false);
Deleted : user_pref("CT2582601.ServiceMapLastCheckTime", "Sun May 01 2011 11:40:18 GMT+0200");
Deleted : user_pref("CT2582601.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2582601.SettingsLastCheckTime", "Sun May 01 2011 11:40:18 GMT+0200");
Deleted : user_pref("CT2582601.SettingsLastUpdate", "1299524390");
Deleted : user_pref("CT2582601.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2582601.ThirdPartyComponentsLastCheck", "Sun May 01 2011 11:40:18 GMT+0200");
Deleted : user_pref("CT2582601.ThirdPartyComponentsLastUpdate", "1255348257");
Deleted : user_pref("CT2582601.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2582601");
Deleted : user_pref("CT2582601.Uninstall", true);
Deleted : user_pref("CT2582601.UserID", "UN95689624456545820");
Deleted : user_pref("CT2582601.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2582601.WeatherNetwork", "");
Deleted : user_pref("CT2582601.WeatherPollDate", "Sun Nov 21 2010 14:05:48 GMT+0100");
Deleted : user_pref("CT2582601.WeatherUnit", "C");
Deleted : user_pref("CT2582601.alertChannelId", "975434");
Deleted : user_pref("CT2582601.backendstorage.facebbok_user_id", "313030303030323036353534383937");
Deleted : user_pref("CT2582601.backendstorage.facebook_login_status", "31");
Deleted : user_pref("CT2582601.backendstorage.facebook_lust_recievegadet", "");
Deleted : user_pref("CT2582601.backendstorage.facebook_mode", "32");
Deleted : user_pref("CT2582601.backendstorage.facebook_user_name", "3078303034332C3078303036432C3078303036312C[...]
Deleted : user_pref("CT2582601.backendstorage.facebook_user_token", "3230393834353033353330347C656166363136356[...]
Deleted : user_pref("CT2582601.backendstorage.facebooknotifications", "31");
Deleted : user_pref("CT2582601.backendstorage.hxxp://cmg1_conduit-widgets_com/pitsi.state", "434C4F5345");
Deleted : user_pref("CT2582601.backendstorage.hxxp://facebook_conduitapps_com/v308.facebook_friendsuploadstab_[...]
Deleted : user_pref("CT2582601.backendstorage.hxxp://facebook_conduitapps_com/v308.facebook_last_visit_tab", "[...]
Deleted : user_pref("CT2582601.backendstorage.hxxp://facebook_conduitapps_com/v308.facebook_myuploadstab_pos",[...]
Deleted : user_pref("CT2582601.clientLogIsEnabled", true);
Deleted : user_pref("CT2582601.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Deleted : user_pref("CT2582601.components.1000034", false);
Deleted : user_pref("CT2582601.components.1003", true);
Deleted : user_pref("CT2582601.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
Deleted : user_pref("CT2582601.globalFirstTimeInfoLastCheckTime", "Sun May 01 2011 11:40:19 GMT+0200");
Deleted : user_pref("CT2582601.isAppTrackingManagerOn", true);
Deleted : user_pref("CT2582601.myStuffEnabled", true);
Deleted : user_pref("CT2582601.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2582601.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2582601.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2582601.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2582601.oldAppsList", "129144940768357001,129144940768669502,129144940770700906,1000082[...]
Deleted : user_pref("CT2582601.testingCtid", "");
Deleted : user_pref("CT2582601.toolbarAppMetaDataLastCheckTime", "Sun May 01 2011 11:40:18 GMT+0200");
Deleted : user_pref("CT2582601.toolbarContextMenuLastCheckTime", "Sun May 01 2011 11:40:18 GMT+0200");
Deleted : user_pref("CT2582601.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Deleted : user_pref("CommunityToolbar.CantToolbarBeEngineOwner", "CT2582601");
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2582601", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.2[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2582601",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2582601/CT2582601[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"634[...]
Deleted : user_pref("CommunityToolbar.EngineHiddenByUser", true);
Deleted : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com");
Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
Deleted : user_pref("CommunityToolbar.IsEngineShown", false);
Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://cdn.triplegames.com/shared/apps/gamearcade/ar[...]
Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://plasmoo.com/result.htm?q=");
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2582601,ConduitEngine");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2582601");
Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon Mar 21 2011 16:58:47 GMT+01[...]
Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun May 01 2011 01:17:33 GMT+0200");
Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sun May 01 2011 01:17:25 GMT+0200");
Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1303303927");
Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.alert.userId", "d28878a8-54b1-44ff-893f-1689174313cc");
Deleted : user_pref("CommunityToolbar.facebook.sessionKey", "eaf6165a52ee896139383624-100000206554897");
Deleted : user_pref("CommunityToolbar.facebook.sessionSecret", "dc74e0df59a52ac607c385084305d878");
Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sun Nov 21 2010 13:23:47 GMT+0100");
Deleted : user_pref("CommunityToolbar.facebook.userId", "100000206554897");
Deleted : user_pref("CommunityToolbar.globalUserId", "a32c2896-5c8e-4535-8786-732ccbb427df");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2582601");
Deleted : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Wed Apr 20 2011 22:52:14 GMT+0200");
Deleted : user_pref("ConduitEngine.BrowserCompStateIsOpen_1627818309137728572", true);
Deleted : user_pref("ConduitEngine.CTID", "ConduitEngine");
Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Sun May 01 2011 11:36:31 GMT+0200");
Deleted : user_pref("ConduitEngine.FirstServerDate", "03/21/2011 17");
Deleted : user_pref("ConduitEngine.FirstTime", true);
Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Deleted : user_pref("ConduitEngine.Initialize", true);
Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Deleted : user_pref("ConduitEngine.InstalledDate", "Mon Mar 21 2011 16:58:48 GMT+0100");
Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Sun May 01 2011 11:36:31 GMT+0200");
Deleted : user_pref("ConduitEngine.LastLogin_3.3.2.1", "Tue Mar 22 2011 12:04:32 GMT+0100");
Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Sun May 01 2011 11:36:32 GMT+0200");
Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Sun May 01 2011 11:36:31 GMT+0200");
Deleted : user_pref("ConduitEngine.UserID", "UN91039505358548577");
Deleted : user_pref("ConduitEngine.apps1627818309137728572", false);
Deleted : user_pref("ConduitEngine.componentAlertEnabled", false);
Deleted : user_pref("ConduitEngine.engineLocale", "de");
Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Sun May 01 2011 11:36:32 GMT+0200");
Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Sun May 01 2011 11:36:31 GMT+0200");
Deleted : user_pref("ConduitEngine.initDone", true);
Deleted : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Deleted : user_pref("ConduitEngine.usagesFlag", 2);
Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Deleted : user_pref("browser.search.defaultenginename", "Ask.com");
Deleted : user_pref("browser.search.defaultthis.engineName", "pc gear de Customized Web Search");
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2582601&Sea[...]
Deleted : user_pref("browser.search.order.1", "Ask.com");
Deleted : user_pref("extensions.Softonic.admin", false);
Deleted : user_pref("extensions.Softonic.aflt", "orgnl");
Deleted : user_pref("extensions.Softonic.autoRvrt", "false");
Deleted : user_pref("extensions.Softonic.cntry", "DE");
Deleted : user_pref("extensions.Softonic.dfltLng", "");
Deleted : user_pref("extensions.Softonic.dfltlng", "en");
Deleted : user_pref("extensions.Softonic.dfltsrch", "false");
Deleted : user_pref("extensions.Softonic.envrmnt", "production");
Deleted : user_pref("extensions.Softonic.excTlbr", false);
Deleted : user_pref("extensions.Softonic.hdrMd5", "C6870FEE33F57EE46463A55EBC1E8B72");
Deleted : user_pref("extensions.Softonic.hmpg", false);
Deleted : user_pref("extensions.Softonic.hrdid", "8c0dac64000000000000002215600bad");
Deleted : user_pref("extensions.Softonic.id", "8c0dac64000000000000002215600bad");
Deleted : user_pref("extensions.Softonic.instlDay", "15492");
Deleted : user_pref("extensions.Softonic.instlRef", "MON00001");
Deleted : user_pref("extensions.Softonic.instlday", "15492");
Deleted : user_pref("extensions.Softonic.instlref", "MON00001");
Deleted : user_pref("extensions.Softonic.isDcmntCmplt", true);
Deleted : user_pref("extensions.Softonic.isdcmntcmplt", "false");
Deleted : user_pref("extensions.Softonic.keywordurl", "");
Deleted : user_pref("extensions.Softonic.lastVrsnTs", "1.5.24.323:34:20");
Deleted : user_pref("extensions.Softonic.mntrvrsn", "1.3.0");
Deleted : user_pref("extensions.Softonic.newTab", false);
Deleted : user_pref("extensions.Softonic.newtab", "false");
Deleted : user_pref("extensions.Softonic.newtaburl", "");
Deleted : user_pref("extensions.Softonic.prdct", "Softonic");
Deleted : user_pref("extensions.Softonic.prtnrId", "softonic");
Deleted : user_pref("extensions.Softonic.prtnrid", "softonic");
Deleted : user_pref("extensions.Softonic.rvrtMsg", "Click Yes to keep current home page and default search set[...]
Deleted : user_pref("extensions.Softonic.savedVrsnTs", "1");
Deleted : user_pref("extensions.Softonic.sg", "az");
Deleted : user_pref("extensions.Softonic.similarsitesstorage-pid2", "8489e505aeab360d");
Deleted : user_pref("extensions.Softonic.smplGrp", "none");
Deleted : user_pref("extensions.Softonic.smplgrp", "none");
Deleted : user_pref("extensions.Softonic.srch", "");
Deleted : user_pref("extensions.Softonic.srchprvdr", "");
Deleted : user_pref("extensions.Softonic.tlbrId", "base");
Deleted : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MON00001/tb_v1?SearchSource[...]
Deleted : user_pref("extensions.Softonic.tlbrid", "base");
Deleted : user_pref("extensions.Softonic.tlbrsrchurl", "hxxp://search.softonic.com/MON00001/tb_v1?SearchSource[...]
Deleted : user_pref("extensions.Softonic.vrsn", "1.5.24.3");
Deleted : user_pref("extensions.Softonic.vrsnTs", "1.5.24.323:34:20");
Deleted : user_pref("extensions.Softonic.vrsni", "1.5.24.3");
Deleted : user_pref("extensions.Softonic.vrsnts", "1.5.24.323:34:20");
Deleted : user_pref("extensions.Softonic_i.newTab", false);
Deleted : user_pref("extensions.Softonic_i.smplGrp", "none");
Deleted : user_pref("extensions.Softonic_i.vrsnTs", "1.5.24.323:34:20");
Deleted : user_pref("extensions.asktb.abar-war-regex", "conduit\\.com");
Deleted : user_pref("extensions.asktb.autofill-competitor-query-enabled", true);
Deleted : user_pref("extensions.asktb.cbid", "U3");
Deleted : user_pref("extensions.asktb.config-updated", false);
Deleted : user_pref("extensions.asktb.crumb", "2012.07.08+00.08.16-toolbar003iad-DE-QmVybGluLEdlcm1hbnk%3D");
Deleted : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.ask.com/web?q={query}&qsrc={qsrc}&[...]
Deleted : user_pref("extensions.asktb.displaybehavior", "");
Deleted : user_pref("extensions.asktb.displaytext", "");
Deleted : user_pref("extensions.asktb.dtid", "YYYYYYYYDE");
Deleted : user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false);
Deleted : user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "GMXX0007");
Deleted : user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "C");
Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://mystart.incredibar.com/mb165/?loc=IB_D[...]
Deleted : user_pref("extensions.asktb.first-restart-after-config-update", true);
Deleted : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com[...]
Deleted : user_pref("extensions.asktb.l", "dis");
Deleted : user_pref("extensions.asktb.last-config-req", "1341850132200");
Deleted : user_pref("extensions.asktb.last-v", "3.14.1.100013");
Deleted : user_pref("extensions.asktb.locale", "de_DE");
Deleted : user_pref("extensions.asktb.location", "Berlin,Germany");
Deleted : user_pref("extensions.asktb.lstation", "");
Deleted : user_pref("extensions.asktb.news-native-on", true);
Deleted : user_pref("extensions.asktb.o", "100000027");
Deleted : user_pref("extensions.asktb.pstate", "");
Deleted : user_pref("extensions.asktb.qsrc", "2871");
Deleted : user_pref("extensions.asktb.search-suggestions-enabled", true);
Deleted : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false);
Deleted : user_pref("extensions.asktb.socialmini-first", true);
Deleted : user_pref("extensions.asktb.socialmini-interval", "1200000");
Deleted : user_pref("extensions.asktb.socialmini-max-char-ticker", "33");
Deleted : user_pref("extensions.asktb.socialmini-max-items", "30");
Deleted : user_pref("extensions.asktb.socialmini-native-on", true);
Deleted : user_pref("extensions.asktb.socialmini-speed", "10000");
Deleted : user_pref("extensions.asktb.socialmini-transition-first-open", false);
Deleted : user_pref("extensions.asktb.to", "");
Deleted : user_pref("extensions.enabledAddons", "fb_add_on@avm.de:1.6.3,ich@maltegoetz.de:1.4.2,ffxtlbra@softo[...]
Deleted : user_pref("extensions.facemoods.aflt", "_#dpg");
Deleted : user_pref("extensions.facemoods.firstRun", false);
Deleted : user_pref("extensions.facemoods.lastActv", "6");
Deleted : user_pref("extensions.incredibar.actvtyRptTime", "1341467344666");
Deleted : user_pref("extensions.incredibar.admin", false);
Deleted : user_pref("extensions.incredibar.aflt", "orgnl");
Deleted : user_pref("extensions.incredibar.afterInstallRpt", "sent");
Deleted : user_pref("extensions.incredibar.cntry", "DE");
Deleted : user_pref("extensions.incredibar.dfltLng", "EN");
Deleted : user_pref("extensions.incredibar.dfltSrch", false);
Deleted : user_pref("extensions.incredibar.dfltlng", "EN");
Deleted : user_pref("extensions.incredibar.dfltsrch", "false");
Deleted : user_pref("extensions.incredibar.did", "10665");
Deleted : user_pref("extensions.incredibar.envrmnt", "production");
Deleted : user_pref("extensions.incredibar.excTlbr", false);
Deleted : user_pref("extensions.incredibar.hdrMd5", "D2BF7951FBB008229551AA1ADAAAA037");
Deleted : user_pref("extensions.incredibar.hmpg", false);
Deleted : user_pref("extensions.incredibar.hrdid", "0");
Deleted : user_pref("extensions.incredibar.id", "8c0dac64000000000000002215600bad");
Deleted : user_pref("extensions.incredibar.installerproductid", "26");
Deleted : user_pref("extensions.incredibar.instlDay", "15504");
Deleted : user_pref("extensions.incredibar.instlRef", "");
Deleted : user_pref("extensions.incredibar.instlday", "15504");
Deleted : user_pref("extensions.incredibar.instlref", "");
Deleted : user_pref("extensions.incredibar.isDcmntCmplt", false);
Deleted : user_pref("extensions.incredibar.isdcmntcmplt", "false");
Deleted : user_pref("extensions.incredibar.keywordurl", "");
Deleted : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.147:33:53");
Deleted : user_pref("extensions.incredibar.logicsMngrDailyReportTime", "05-07-2012");
Deleted : user_pref("extensions.incredibar.mntrvrsn", "1.2.0");
Deleted : user_pref("extensions.incredibar.newTab", false);
Deleted : user_pref("extensions.incredibar.newtab", "false");
Deleted : user_pref("extensions.incredibar.newtaburl", "");
Deleted : user_pref("extensions.incredibar.noFFXTlbr", false);
Deleted : user_pref("extensions.incredibar.ppd", "");
Deleted : user_pref("extensions.incredibar.prdct", "incredibar");
Deleted : user_pref("extensions.incredibar.productid", "26");
Deleted : user_pref("extensions.incredibar.propectorlck", 80068214);
Deleted : user_pref("extensions.incredibar.prtkHmpg", 1);
Deleted : user_pref("extensions.incredibar.prtnrId", "Incredibar");
Deleted : user_pref("extensions.incredibar.prtnrid", "Incredibar");
Deleted : user_pref("extensions.incredibar.sg", "none");
Deleted : user_pref("extensions.incredibar.smplGrp", "none");
Deleted : user_pref("extensions.incredibar.smplgrp", "none");
Deleted : user_pref("extensions.incredibar.srch", "");
Deleted : user_pref("extensions.incredibar.srchprvdr", "");
Deleted : user_pref("extensions.incredibar.tlbrId", "base");
Deleted : user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8vQpBcfa&loc=IB_T[...]
Deleted : user_pref("extensions.incredibar.tlbrid", "base");
Deleted : user_pref("extensions.incredibar.tlbrsrchurl", "hxxp://mystart.Incredibar.com/?a=6R8vQpBcfa&loc=IB_T[...]
Deleted : user_pref("extensions.incredibar.upn2", "6R8vQpBcfa");
Deleted : user_pref("extensions.incredibar.upn2n", "92824526614914436");
Deleted : user_pref("extensions.incredibar.vrsn", "1.5.11.14");
Deleted : user_pref("extensions.incredibar.vrsnTs", "1.5.11.147:33:53");
Deleted : user_pref("extensions.incredibar.vrsni", "1.5.11.14");
Deleted : user_pref("extensions.incredibar.vrsnts", "1.5.11.147:33:53");
Deleted : user_pref("extensions.incredibar_i.aflt", "orgnl");
Deleted : user_pref("extensions.incredibar_i.dfltLng", "");
Deleted : user_pref("extensions.incredibar_i.did", "10665");
Deleted : user_pref("extensions.incredibar_i.excTlbr", false);
Deleted : user_pref("extensions.incredibar_i.id", "8c0dac64000000000000002215600bad");
Deleted : user_pref("extensions.incredibar_i.installerproductid", "26");
Deleted : user_pref("extensions.incredibar_i.instlDay", "15504");
Deleted : user_pref("extensions.incredibar_i.instlRef", "");
Deleted : user_pref("extensions.incredibar_i.ms_url_id", "");
Deleted : user_pref("extensions.incredibar_i.newTab", false);
Deleted : user_pref("extensions.incredibar_i.ppd", "");
Deleted : user_pref("extensions.incredibar_i.prdct", "incredibar");
Deleted : user_pref("extensions.incredibar_i.productid", "26");
Deleted : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
Deleted : user_pref("extensions.incredibar_i.smplGrp", "none");
Deleted : user_pref("extensions.incredibar_i.tlbrId", "base");
Deleted : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8vQpBcfa&loc=IB[...]
Deleted : user_pref("extensions.incredibar_i.upn2", "6R8vQpBcfa");
Deleted : user_pref("extensions.incredibar_i.upn2n", "92824526614914436");
Deleted : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14");
Deleted : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.147:33:53");
Deleted : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14");
Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ORJ&o=100000027&loca[...]
Deleted : user_pref("plasmoo.search.engine.prevkeywordurl", "hxxp://start.facemoods.com/results.php?f=5&a=dpg&[...]
Deleted : user_pref("plasmoo.search.engine.prevsearchdefaultthisenginename", "pc gear de Customized Web Search[...]
Deleted : user_pref("plasmoo.search.engine.prevsearchdefaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?c[...]

*************************

AdwCleaner[R1].txt - [41193 octets] - [18/07/2012 17:41:48]
AdwCleaner[S1].txt - [38806 octets] - [19/07/2012 12:04:31]

########## EOF - C:\AdwCleaner[S1].txt - [38935 octets] ##########


Übrigens: seit ich den ersten Quickscan mit Malwarebytes gemacht habe, taucht die incredibar, die sich ja immer wieder in meine Startseite von Firefox geladen hat, nicht mehr auf!! :)

cosinus 19.07.2012 19:04

Hätte da mal drei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?
3.) Die Toolbar bzw. Weiterleitung nun weg?

maeusuruh 24.07.2012 21:45

Also:
1. Windows war nie eingeschränkt und läuft wie immer ganz normal (wobei es mir vorkommt, als ob es etwas langsamer läuft)
2. Vermisse bis jetzt nichts im Startmenü, habe auch keine leeren Ordner gefunden.
3. Die Weiterleitung, meinst damit zu incredibar oder, die ist weg. Habe Facebook in meinem Startmenü von Firefox drinnen, und die wird aufgerufen, wenn ich firefox starte. Vorher hat sich ja da incredibar immer wieder draufgelegt, wenn ich den Compi neu gestartet habe!!
LG Claudia

cosinus 24.07.2012 22:21

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


maeusuruh 01.08.2012 12:40

Sorry, war die letzten Tage nicht da!!
Jetzt die OTL:

OTL Logfile:
Code:

OTL logfile created on: 01.08.2012 13:23:39 - Run 2
OTL by OldTimer - Version 3.2.55.0    Folder = C:\Users\Frank\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
8,00 Gb Total Physical Memory | 6,21 Gb Available Physical Memory | 77,67% Memory free
16,21 Gb Paging File | 14,21 Gb Available in Paging File | 87,66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,51 Gb Total Space | 481,76 Gb Free Space | 51,72% Space Free | Partition Type: NTFS
 
Computer Name: ADMIN-PC | User Name: Frank | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.08.01 12:37:14 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\Frank\Desktop\OTL(1).exe
PRC - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.06.13 12:25:11 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2012.05.08 22:15:04 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.08 22:14:59 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.05.08 22:14:59 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.01.23 06:43:08 | 000,247,728 | ---- | M] (TomTom) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2012.01.23 06:43:08 | 000,092,592 | ---- | M] (TomTom) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2012.01.05 21:35:16 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2011.09.15 13:06:04 | 000,088,576 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2009.03.23 13:12:44 | 000,327,680 | ---- | M] (PixArt Imaging Incorporation) -- C:\Windows\Pixart\Pac7302\PACTray.exe
PRC - [2007.12.10 15:55:26 | 000,323,584 | ---- | M] (PixArt Imaging Incorporation) -- C:\Windows\Pixart\Pac7302\Monitor.exe
 
 
========== Modules (No Company Name) ==========
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2012.04.06 04:16:02 | 000,236,544 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2007.10.19 05:10:30 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\AEADISRV.EXE -- (AEADIFilters)
SRV - [2012.07.26 23:29:09 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.07.03 13:19:28 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.05.08 22:15:04 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.08 22:14:59 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.01.23 06:43:08 | 000,092,592 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2012.01.05 21:35:16 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2011.12.26 13:23:34 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Users\Frank\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe -- (SearchAnonymizer)
SRV - [2011.09.15 13:06:04 | 000,088,576 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.03.21 13:21:24 | 000,632,832 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.03.30 06:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.07.03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012.05.08 22:15:05 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.05.08 22:15:05 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\DRIVERS\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012.04.06 07:22:40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2012.04.06 07:22:40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.04.06 03:10:44 | 000,343,040 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.02.29 15:52:46 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.02.23 14:31:50 | 000,092,176 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdLH6.sys -- (AtiHDAudioService)
DRV:64bit: - [2011.09.16 17:08:07 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011.02.11 23:23:34 | 000,035,344 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf)
DRV:64bit: - [2010.12.02 15:14:26 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltjx64.sys -- (UsbserFilt)
DRV:64bit: - [2010.12.02 15:14:24 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64.sys -- (upperdev)
DRV:64bit: - [2010.12.02 15:14:22 | 000,027,136 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdc)
DRV:64bit: - [2010.12.02 15:14:18 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd)
DRV:64bit: - [2010.12.02 13:36:42 | 000,171,008 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nmwcdnsux64.sys -- (nmwcdnsux64)
DRV:64bit: - [2010.12.02 13:36:40 | 000,012,800 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nmwcdnsucx64.sys -- (nmwcdnsucx64)
DRV:64bit: - [2010.06.25 16:08:56 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\htcnprot.sys -- (htcnprot)
DRV:64bit: - [2009.12.02 18:57:48 | 000,868,848 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\Drivers\sptd.sys -- (sptd)
DRV:64bit: - [2009.10.01 02:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:64bit: - [2009.06.17 18:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2009.06.17 18:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2009.06.17 18:53:34 | 000,030,736 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\L8042Kbd.sys -- (L8042Kbd)
DRV:64bit: - [2009.06.10 00:46:06 | 000,031,744 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\ANDROIDUSB.sys -- (HTCAND64)
DRV:64bit: - [2009.04.11 07:43:06 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2009.04.11 07:39:37 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\usbser.sys -- (usbser)
DRV:64bit: - [2008.11.19 17:09:14 | 000,033,792 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\lgx64modem.sys -- (USBModem)
DRV:64bit: - [2008.11.19 17:09:12 | 000,027,136 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\lgx64diag.sys -- (UsbDiag)
DRV:64bit: - [2008.11.19 17:09:12 | 000,017,920 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\lgx64bus.sys -- (usbbus)
DRV:64bit: - [2008.11.10 13:17:40 | 000,531,968 | ---- | M] (PixArt Imaging Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\PAC7302.SYS -- (PAC7302)
DRV:64bit: - [2008.08.28 12:44:42 | 000,025,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys -- (pccsmcfd)
DRV:64bit: - [2008.03.20 02:44:34 | 000,467,456 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV:64bit: - [2007.12.06 09:51:00 | 000,391,680 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\yk60x64.sys -- (yukonx64)
DRV:64bit: - [2007.02.08 09:48:04 | 000,051,600 | ---- | M] (Thesycon GmbH, Germany) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\dsiarhwprog_x64.sys -- (usbio)
DRV:64bit: - [2006.10.31 17:23:42 | 000,015,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2006.09.19 14:43:54 | 000,018,224 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2008.01.18 14:21:38 | 000,013,312 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\LG Soft India\forteManager\bin\PII2CDriver.sys -- (LGII2CDevice)
DRV - [2008.01.18 14:21:36 | 000,014,336 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\LG Soft India\forteManager\bin\I2CDriver.sys -- (LGDDCDevice)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes,DefaultScope = Plasmoo
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E62696E672E636F6D2F7365617263683F713D7B7365617263685465726D737D267372633D49452D536561726368426F7826464F524D3D494538535243&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{08F95AC0-1D40-443E-ADA3-9A0EAD1745C8}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{5033262E-1290-45AD-8B2C-CB2FD2E65299}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{5CFDB435-86A1-48E5-ADE8-7F43EB9EAA8F}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://www.icq.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E6963712E636F6D2F7365617263682F726573756C74732E7068703F713D7B7365617263685465726D737D2663685F69643D6F7364&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{6FE52790-D24A-4B46-B535-7A88C2D86152}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=YYYYYYYYDE&apn_uid=F501E56B-5C15-4F3D-A955-EF8ABECD821C&apn_sauid=44DED72A-4D64-4297-8CDC-9A6F16CB5830
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{9148E46A-4B18-4B31-8B70-A8114CF989BD}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{B357C1CA-69CF-4B2E-A69A-9BDC10F2F8AC}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{D7ABBE17-5AC2-4E34-8B5F-7FAFB01B9751}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\Plasmoo: "URL" = hxxp://plasmoo.com.anonymize-me.de/?anonymto=687474703A2F2F706C61736D6F6F2E636F6D2F726573756C742E68746D3F713D7B7365617263685465726D737D265365617263684D617368696E653D74727565&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.facebook.com/index.php?lh=b5f1416c11cd4baa3a997c8bfe9cb4b1&eu=IfFOcEYGRYwiAU8TS6GVAw"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.16
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: codiprog@fbplus.plugin:1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.7
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..extensions.enabledItems: engine@plasmoo.com:1.0.0.32
FF - prefs.js..extensions.enabledItems: fb_add_on@avm.de:1.6.3
FF - prefs.js..extensions.enabledItems: ffxtlbra@softonic.com:1.5.0
FF - prefs.js..network.proxy.http: "190.66.17.53"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.110.0: C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.118.0: C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.122.0: C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Frank\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
 
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011.05.31 22:55:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.06.13 12:25:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.06.13 12:25:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.07.19 10:49:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.07.07 22:44:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012.07.12 13:15:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011.05.31 22:55:38 | 000,000,000 | ---D | M]
 
[2010.09.15 12:51:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\mozilla\Extensions
[2010.09.15 12:51:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.02.11 12:30:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2012.07.25 19:52:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Frank\AppData\Roaming\mozilla\Firefox\Profiles\8ghejrb4.default\extensions
[2010.04.28 06:15:21 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Frank\AppData\Roaming\mozilla\Firefox\Profiles\8ghejrb4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.07.20 19:59:08 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Frank\AppData\Roaming\mozilla\Firefox\Profiles\8ghejrb4.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.14 22:27:01 | 000,000,000 | ---D | M] ("FRITZ!Box AddOn") -- C:\Users\Frank\AppData\Roaming\mozilla\Firefox\Profiles\8ghejrb4.default\extensions\fb_add_on@avm.de
[2012.05.18 13:38:38 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Frank\AppData\Roaming\mozilla\Firefox\Profiles\8ghejrb4.default\extensions\ich@maltegoetz.de
[2011.12.26 13:23:36 | 000,001,091 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\icqplugin.xml
[2011.12.26 13:23:37 | 000,002,188 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\{254DA591-C16D-4FB6-9062-4C050FA0B1BD}.xml
[2011.12.26 13:23:37 | 000,001,870 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\{6332F0FF-685E-4193-9E72-D96AEE055E73}.xml
[2011.12.26 13:23:37 | 000,002,077 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\{7D01AA1A-5AB3-4D3E-ACAE-79CACC0E28AC}.xml
[2012.07.07 22:45:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2009.06.23 21:00:33 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.12.13 23:06:06 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.07.07 22:45:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012.07.11 15:39:43 | 000,061,228 | ---- | M] () (No name found) -- C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\EXTENSIONS\{9AA46F4F-4DC7-4C06-97AF-5035170634FE}.XPI
[2012.07.19 10:49:48 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2009.09.08 16:02:46 | 000,188,416 | ---- | M] (The cURL library, hxxp://curl.haxx.se/) -- C:\Program Files (x86)\mozilla firefox\plugins\libcurl.dll
[2009.10.29 16:57:40 | 001,359,872 | ---- | M] (Fraunhofer IIS) -- C:\Program Files (x86)\mozilla firefox\plugins\npmmtaplayer.dll
[2012.06.13 12:25:21 | 000,129,144 | ---- | M] (RealPlayer) -- C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll
[2012.07.07 21:43:38 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.07.07 21:43:38 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.07.07 21:43:38 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.12.26 13:23:36 | 000,001,611 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrchDpg.xml
[2012.07.07 21:43:38 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.07 21:43:38 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.07.07 21:43:38 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 23:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\Frank\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS)
O4:64bit: - HKLM..\Run: [PAC7302_Monitor] C:\Windows\Pixart\Pac7302\Monitor.exe (PixArt Imaging Incorporation)
O4:64bit: - HKLM..\Run: [PACTray] C:\Windows\Pixart\Pac7302\PACTray.exe (PixArt Imaging Incorporation)
O4:64bit: - HKLM..\Run: [UpdateUSB] C:\Windows\inf\UpdateUSB.exe (AsusTek Inc.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000..\Run: []  File not found
O4 - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000..\Run: [LDM] C:\Programme\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech)
O4 - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000..\Run: [TomTomHOME.exe] C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Frank\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Frank\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Spiele\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Spiele\PartyGaming\PartyPoker\RunApp.exe ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3EF2AE26-FF8E-4427-A3DD-D1BE409D82E6}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{841DA7EE-789D-4B01-B5BF-E1D0CF08E86C}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B94D2724-8C73-4AE6-A359-2099ABA3E767}: DhcpNameServer = 192.168.42.129
O18:64bit: - Protocol\Handler\bw+0 - No CLSID value found
O18:64bit: - Protocol\Handler\bw+0s - No CLSID value found
O18:64bit: - Protocol\Handler\bw-0 - No CLSID value found
O18:64bit: - Protocol\Handler\bw00 - No CLSID value found
O18:64bit: - Protocol\Handler\bw00s - No CLSID value found
O18:64bit: - Protocol\Handler\bw-0s - No CLSID value found
O18:64bit: - Protocol\Handler\bw10 - No CLSID value found
O18:64bit: - Protocol\Handler\bw10s - No CLSID value found
O18:64bit: - Protocol\Handler\bw20 - No CLSID value found
O18:64bit: - Protocol\Handler\bw20s - No CLSID value found
O18:64bit: - Protocol\Handler\bw30 - No CLSID value found
O18:64bit: - Protocol\Handler\bw30s - No CLSID value found
O18:64bit: - Protocol\Handler\bw40 - No CLSID value found
O18:64bit: - Protocol\Handler\bw40s - No CLSID value found
O18:64bit: - Protocol\Handler\bw50 - No CLSID value found
O18:64bit: - Protocol\Handler\bw50s - No CLSID value found
O18:64bit: - Protocol\Handler\bw60 - No CLSID value found
O18:64bit: - Protocol\Handler\bw60s - No CLSID value found
O18:64bit: - Protocol\Handler\bw70 - No CLSID value found
O18:64bit: - Protocol\Handler\bw70s - No CLSID value found
O18:64bit: - Protocol\Handler\bw80 - No CLSID value found
O18:64bit: - Protocol\Handler\bw80s - No CLSID value found
O18:64bit: - Protocol\Handler\bw90 - No CLSID value found
O18:64bit: - Protocol\Handler\bw90s - No CLSID value found
O18:64bit: - Protocol\Handler\bwa0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwa0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwb0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwb0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwc0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwc0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwd0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwd0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwe0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwe0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwf0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwf0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwfile-8876480 - No CLSID value found
O18:64bit: - Protocol\Handler\bwg0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwg0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwh0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwh0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwi0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwi0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwj0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwj0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwk0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwk0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwl0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwl0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwm0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwm0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwn0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwn0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwo0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwo0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwp0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwp0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwq0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwq0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwr0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwr0s - No CLSID value found
O18:64bit: - Protocol\Handler\bws0 - No CLSID value found
O18:64bit: - Protocol\Handler\bws0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwt0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwt0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwu0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwu0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwv0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwv0s - No CLSID value found
O18:64bit: - Protocol\Handler\bww0 - No CLSID value found
O18:64bit: - Protocol\Handler\bww0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwx0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwx0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwy0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwy0s - No CLSID value found
O18:64bit: - Protocol\Handler\bwz0 - No CLSID value found
O18:64bit: - Protocol\Handler\bwz0s - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\offline-8876480 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\bw+0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw+0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw-0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw00 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw00s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw-0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw10 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw10s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw20 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw20s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw30 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw30s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw40 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw40s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw50 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw50s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw60 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw60s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw70 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw70s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw80 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw80s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw90 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bw90s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwa0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwa0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwb0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwb0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwc0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwc0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwd0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwd0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwe0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwe0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwf0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwf0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwg0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwg0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwh0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwh0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwi0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwi0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwj0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwj0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwk0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwk0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwl0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwl0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwm0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwm0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwn0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwn0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwo0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwo0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwp0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwp0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwq0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwq0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwr0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwr0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bws0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bws0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwt0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwt0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwu0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwu0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwv0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwv0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bww0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bww0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwx0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwx0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwy0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwy0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwz0 {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\bwz0s {3fdb282b-b33e-4500-b6c2-484bba806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\offline-8876480 {3FDB282B-B33E-4500-B6C2-484BBA806116} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc.                        )
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Frank\Pictures\2010-09-06 Urlaub Sep.2010, Kroatien Premantura\Urlaub Sep.2010, Kroatien Premantura 012.JPG
O24 - Desktop BackupWallPaper: C:\Users\Frank\Pictures\2010-09-06 Urlaub Sep.2010, Kroatien Premantura\Urlaub Sep.2010, Kroatien Premantura 012.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{2ae806f2-a2a0-11df-9537-0022156014a3}\Shell - "" = AutoRun
O33 - MountPoints2\{2ae806f2-a2a0-11df-9537-0022156014a3}\Shell\AutoRun\command - "" = J:\LGAutoRun.exe
O33 - MountPoints2\{86f40ed1-a9b5-11df-8350-0022156014a3}\Shell - "" = AutoRun
O33 - MountPoints2\{86f40ed1-a9b5-11df-8350-0022156014a3}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\Start.hta
O33 - MountPoints2\{de9b2b23-df64-11de-b799-0022156014a3}\Shell - "" = AutoRun
O33 - MountPoints2\{de9b2b23-df64-11de-b799-0022156014a3}\Shell\AutoRun\command - "" = I:\Autorun.exe
O33 - MountPoints2\{f7e9ea89-702b-11e1-a539-0022156014a3}\Shell - "" = AutoRun
O33 - MountPoints2\{f7e9ea89-702b-11e1-a539-0022156014a3}\Shell\AutoRun\command - "" = J:\NokiaPCIA_Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
 
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^forteManager.lnk - C:\PROGRA~2\LGSOFT~1\FORTEM~1\bin\Monitor.exe - ()
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk - C:\PROGRA~2\MICROS~1\Office10\OSA.EXE - (Microsoft Corporation)
MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
MsConfig:64bit - StartUpReg: ehTray.exe - hkey= - key= - C:\Windows\ehome\ehtray.exe (Microsoft Corporation)
MsConfig:64bit - StartUpReg: HP Software Update - hkey= - key= - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
MsConfig:64bit - StartUpReg: HTC Sync Loader - hkey= - key= - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
MsConfig:64bit - StartUpReg: hxxp://ticker.7910.org/an1cHrs0cr60002MDAwODk1b3wwMDAwNTU0ZGF8QmFsZCBmYWhyZW4gd2lyISEhISBOb2No - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: hxxp://ticker.7910.org/an1cHrsVM1P0002MDAwMTUwbHwwMDAwNTU0ZGF8QmFsZCBmYWhyZW4gd2lyISEhISBOb2No - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - hkey= - key= - C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
MsConfig:64bit - StartUpReg: ISUSPM Startup - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: ISUSScheduler - hkey= - key= - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
MsConfig:64bit - StartUpReg: LDM - hkey= - key= - C:\Programme\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech)
MsConfig:64bit - StartUpReg: NBKeyScan - hkey= - key= - C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
MsConfig:64bit - StartUpReg: NokiaMServer - hkey= - key= - C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
MsConfig:64bit - StartUpReg: NokiaOviSuite2 - hkey= - key= - C:\Program Files (x86)\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe (Nokia)
MsConfig:64bit - StartUpReg: NokiaPCInternetAccess - hkey= - key= - C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe (Nokia)
MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: Skype - hkey= - key= - C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig:64bit - StartUpReg: SoundMAXPnP - hkey= - key= - C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
MsConfig:64bit - StartUpReg: SoundTray - hkey= - key= - C:\Program Files (x86)\Analog Devices\SoundMAX\SoundTray.exe (Sonic Focus, Inc.)
MsConfig:64bit - StartUpReg: StartCCC - hkey= - key= - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
MsConfig:64bit - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
MsConfig:64bit - StartUpReg: TkBellExe - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: TomTomHOME.exe - hkey= - key= - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
MsConfig:64bit - StartUpReg: WinampAgent - hkey= - key= -  File not found
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: WudfPf - Driver
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX:64bit: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Macromedia Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.iac2 - C:\Windows\SysWOW64\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.IV41 - C:\Windows\SysWow64\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.08.01 12:37:13 | 000,597,504 | ---- | C] (OldTimer Tools) -- C:\Users\Frank\Desktop\OTL(1).exe
[2012.07.29 23:10:03 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Audacity
[2012.07.29 23:09:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audacity
[2012.07.26 16:47:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2012.07.16 18:47:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.07.16 18:47:21 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Frank\Desktop\esetsmartinstaller_enu.exe
[2012.07.09 00:38:52 | 000,000,000 | ---D | C] -- C:\Program Files\WinPcap
[2012.07.09 00:38:23 | 000,000,000 | ---D | C] -- C:\Users\Frank\Documents\Freemake
[2012.07.09 00:38:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Freemake
[2012.07.09 00:38:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Freemake
[2012.07.08 22:30:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012.07.08 22:30:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012.07.07 16:06:26 | 000,000,000 | ---D | C] -- C:\Users\Frank\AppData\Roaming\Malwarebytes
[2012.07.07 16:06:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.07 16:06:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.07 16:06:11 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.07.07 16:06:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
 
========== Files - Modified Within 30 Days ==========
 
[2012.08.01 12:37:14 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\Frank\Desktop\OTL(1).exe
[2012.08.01 12:29:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.08.01 12:08:33 | 001,445,546 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.08.01 12:08:33 | 000,628,742 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.08.01 12:08:33 | 000,596,036 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.08.01 12:08:33 | 000,126,486 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.08.01 12:08:33 | 000,104,110 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.08.01 12:02:39 | 000,003,712 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.08.01 12:02:39 | 000,003,712 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.08.01 12:02:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.31 21:22:24 | 000,283,304 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2012.07.31 21:22:24 | 000,283,304 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.07.31 21:22:19 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2012.07.29 23:09:18 | 000,000,846 | ---- | M] () -- C:\Users\Frank\Desktop\Audacity.lnk
[2012.07.18 17:40:46 | 000,624,883 | ---- | M] () -- C:\Users\Frank\Desktop\adwcleaner.exe
[2012.07.16 18:47:23 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Frank\Desktop\esetsmartinstaller_enu.exe
[2012.07.16 16:45:20 | 000,000,948 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.12 18:03:59 | 000,271,176 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.07.08 22:30:29 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2012.07.07 21:31:30 | 000,001,778 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.07.07 20:40:40 | 000,097,473 | ---- | M] () -- C:\Users\Frank\Desktop\bookmarks-2012-07-07.json
[2012.07.07 16:30:09 | 000,000,020 | ---- | M] () -- C:\Users\Frank\defogger_reenable
[2012.07.05 11:31:16 | 000,001,950 | ---- | M] () -- C:\Users\Frank\Desktop\Windows Photo Gallery.lnk
[2012.07.05 11:24:27 | 000,000,218 | ---- | M] () -- C:\Users\Frank\.recently-used.xbel
[2012.07.03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
 
========== Files Created - No Company Name ==========
 
[2012.07.29 23:09:18 | 000,000,858 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2012.07.29 23:09:18 | 000,000,846 | ---- | C] () -- C:\Users\Frank\Desktop\Audacity.lnk
[2012.07.18 17:40:42 | 000,624,883 | ---- | C] () -- C:\Users\Frank\Desktop\adwcleaner.exe
[2012.07.07 21:43:40 | 000,000,900 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.07.07 21:31:30 | 000,001,778 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.07.07 20:40:40 | 000,097,473 | ---- | C] () -- C:\Users\Frank\Desktop\bookmarks-2012-07-07.json
[2012.07.07 16:30:09 | 000,000,020 | ---- | C] () -- C:\Users\Frank\defogger_reenable
[2012.07.07 16:06:12 | 000,000,948 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.05 11:31:16 | 000,001,950 | ---- | C] () -- C:\Users\Frank\Desktop\Windows Photo Gallery.lnk
[2012.07.05 11:24:27 | 000,000,218 | ---- | C] () -- C:\Users\Frank\.recently-used.xbel
[2011.12.26 13:23:35 | 000,338,432 | ---- | C] () -- C:\Windows\SysWow64\sqlite36_engine.dll
[2011.11.06 01:09:44 | 011,980,353 | ---- | C] () -- C:\Windows\SysWow64\meinfotoalbum_meinfotoalbum_uninstaller.exe
[2011.10.28 19:57:38 | 000,001,356 | ---- | C] () -- C:\Users\Frank\AppData\Local\d3d9caps.dat
[2011.10.25 22:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011.10.01 17:29:47 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2011.09.17 14:55:57 | 001,418,240 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfserv.dll
[2011.09.17 14:55:57 | 001,099,776 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfusb1.dll
[2011.09.17 14:55:57 | 000,568,832 | ---- | C] () -- C:\Windows\SysWow64\lxbfutil.dll
[2011.09.17 14:55:57 | 000,488,448 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbflmpm.dll
[2011.09.17 14:55:57 | 000,410,112 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfpmui.dll
[2011.09.17 14:55:57 | 000,305,664 | ---- | C] ( ) -- C:\Windows\SysWow64\LXBFhcp.dll
[2011.09.17 14:55:57 | 000,238,592 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfinpa.dll
[2011.09.17 14:55:57 | 000,226,816 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfiesc.dll
[2011.09.17 14:55:57 | 000,194,048 | ---- | C] () -- C:\Windows\SysWow64\LXBFinst.dll
[2011.09.17 14:55:57 | 000,035,328 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfprox.dll
[2011.09.17 14:55:57 | 000,010,752 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfpplc.dll
[2011.09.17 14:55:56 | 000,696,320 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfcomc.dll
[2011.09.17 14:55:56 | 000,660,480 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfhbn3.dll
[2011.09.17 14:55:56 | 000,566,704 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfcoms.exe
[2011.09.17 14:55:56 | 000,249,856 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfcomm.dll
[2011.09.17 14:55:56 | 000,236,464 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfcfg.exe
[2011.09.17 14:55:56 | 000,233,392 | ---- | C] ( ) -- C:\Windows\SysWow64\lxbfih.exe
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.04.25 22:35:11 | 000,000,862 | ---- | C] () -- C:\Windows\SysWow64\SP7302.INI
[2011.03.28 20:54:49 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.02.11 23:23:34 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
[2010.08.27 17:11:17 | 000,097,344 | ---- | C] () -- C:\Users\Frank\slowenien.htm
[2010.07.29 11:50:19 | 000,000,000 | ---- | C] () -- C:\Users\Frank\jagex__preferences3.dat
[2010.07.29 11:45:26 | 000,000,099 | ---- | C] () -- C:\Users\Frank\jagex_runescape_preferences2.dat
[2010.07.29 11:44:24 | 000,000,046 | ---- | C] () -- C:\Users\Frank\jagex_runescape_preferences.dat
[2009.10.21 21:33:45 | 000,001,024 | ---- | C] () -- C:\Users\Frank\.rnd
[2009.06.23 16:54:02 | 000,182,784 | ---- | C] () -- C:\Users\Frank\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.06.23 12:29:59 | 000,001,164 | ---- | C] () -- C:\Users\Frank\AppData\Local\9A5FF4EA.il
[2009.06.23 12:29:59 | 000,000,280 | ---- | C] () -- C:\Users\Frank\AppData\Local\IndexIE_9A5FF4EA.il
[2009.06.23 11:32:45 | 000,000,732 | ---- | C] () -- C:\Users\Frank\AppData\Local\d3d9caps64.dat
 
========== LOP Check ==========
 
[2012.07.07 16:13:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\7910.org
[2012.06.02 01:16:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Amazon
[2012.07.29 23:37:55 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Audacity
[2011.08.04 13:44:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Auslogics
[2009.10.21 09:05:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Blitware
[2009.12.02 18:57:12 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DAEMON Tools
[2011.12.26 13:27:14 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DesktopIconForAmazon
[2012.06.13 07:53:19 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Docx2Rtf
[2012.07.09 00:53:13 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DVDVideoSoft
[2010.06.21 13:01:48 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Facebook
[2010.12.16 13:09:44 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Fraunhofer
[2012.01.19 18:35:30 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\HTC
[2011.05.11 15:07:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2012.06.01 11:47:59 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\inkscape
[2011.12.26 13:25:03 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\IrfanView
[2009.12.30 21:10:19 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Leadertech
[2012.01.31 00:03:17 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MyPhoneExplorer
[2011.05.23 13:48:57 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Nokia
[2011.05.23 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Nokia Ovi Suite
[2012.06.13 07:54:15 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\NwDocx
[2011.12.26 13:23:33 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\OCS
[2011.12.26 13:23:37 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Opera
[2011.10.28 16:35:18 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Origin
[2011.05.06 21:27:51 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PC Suite
[2009.10.21 22:02:25 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Simple Star
[2010.04.29 20:34:38 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\temp
[2010.09.15 12:51:00 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Thunderbird
[2010.02.11 12:30:23 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TomTom
[2011.12.09 19:58:10 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Visan
[2010.12.16 16:29:37 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\XMedia Recode
[2009.10.21 21:37:38 | 000,000,390 | ---- | M] () -- C:\Windows\Tasks\File Helper.job
[2012.07.31 23:15:10 | 000,032,628 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.07.07 16:13:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\7910.org
[2011.05.11 09:09:35 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Adobe
[2009.12.18 09:27:07 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Ahead
[2012.06.02 01:16:20 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Amazon
[2011.11.03 07:31:54 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Apple Computer
[2009.06.23 11:44:15 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\ATI
[2012.07.29 23:37:55 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Audacity
[2011.08.04 13:44:06 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Auslogics
[2012.03.10 12:52:39 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Avira
[2009.10.21 09:05:29 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Blitware
[2009.12.02 18:57:12 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DAEMON Tools
[2011.12.26 13:27:14 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DesktopIconForAmazon
[2012.06.13 07:53:19 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Docx2Rtf
[2012.04.22 00:55:13 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\dvdcss
[2012.07.09 00:53:13 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\DVDVideoSoft
[2010.06.21 13:01:48 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Facebook
[2010.12.16 13:09:44 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Fraunhofer
[2011.10.08 17:44:23 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\HpUpdate
[2012.01.19 18:35:30 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\HTC
[2011.05.11 15:07:22 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2009.06.23 11:32:49 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Identities
[2012.06.01 11:47:59 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\inkscape
[2009.06.23 12:15:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\InstallShield
[2011.12.26 13:25:03 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\IrfanView
[2009.12.30 21:10:19 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Leadertech
[2009.06.23 20:13:45 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Macromedia
[2012.07.07 16:06:26 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Malwarebytes
[2006.11.02 17:07:25 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Media Center Programs
[2012.06.02 00:14:52 | 000,000,000 | --SD | M] -- C:\Users\Frank\AppData\Roaming\Microsoft
[2012.06.02 00:15:03 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MixMeister Technology
[2009.10.01 19:52:00 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Mozilla
[2010.07.31 20:17:43 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Mozilla-Cache
[2012.01.31 00:03:17 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\MyPhoneExplorer
[2009.10.21 21:34:11 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Nero
[2009.12.06 21:48:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\NeroDigital™
[2011.05.23 13:48:57 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Nokia
[2011.05.23 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Nokia Ovi Suite
[2012.06.13 07:54:15 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\NwDocx
[2011.12.26 13:23:33 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\OCS
[2011.12.26 13:23:37 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Opera
[2011.10.28 16:35:18 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Origin
[2011.05.06 21:27:51 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\PC Suite
[2012.02.11 11:26:57 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Real
[2012.01.23 18:25:45 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\RealNetworks
[2009.10.01 19:51:15 | 000,000,000 | RH-D | M] -- C:\Users\Frank\AppData\Roaming\SecuROM
[2009.10.21 22:02:25 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Simple Star
[2012.07.09 00:50:36 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Skype
[2011.08.05 21:14:42 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\skypePM
[2009.08.24 11:57:02 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Talkback
[2010.04.29 20:34:38 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\temp
[2010.09.15 12:51:00 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Thunderbird
[2010.02.11 12:30:23 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\TomTom
[2011.12.09 19:58:10 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\Visan
[2012.02.10 18:32:00 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\vlc
[2010.12.16 16:29:37 | 000,000,000 | ---D | M] -- C:\Users\Frank\AppData\Roaming\XMedia Recode
 
< %APPDATA%\*.exe /s >
[2011.12.26 13:27:13 | 000,753,664 | ---- | M] (Microsoft) -- C:\Users\Frank\AppData\Roaming\DesktopIconForAmazon\IconForAmazon.exe
[2010.06.21 13:01:48 | 000,050,354 | ---- | M] (Facebook, Inc.) -- C:\Users\Frank\AppData\Roaming\Facebook\uninstall.exe
[2011.12.26 10:06:05 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Frank\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2012.06.02 00:14:52 | 000,000,766 | R--- | M] () -- C:\Users\Frank\AppData\Roaming\Microsoft\Installer\{50CBBEC7-1010-41C5-8718-A1A6FEDD9C3A}\ARPPRODUCTICON.exe
[2011.12.26 13:23:33 | 000,106,496 | ---- | M] (OCS) -- C:\Users\Frank\AppData\Roaming\OCS\SM\SearchAnonymizer.exe
[2011.12.26 13:23:34 | 000,040,960 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
[2012.02.27 13:42:45 | 000,591,480 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Frank\AppData\Roaming\Real\RealPlayer\setup\AU_setup20120216.exe
[2009.12.05 20:00:39 | 000,439,816 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Frank\AppData\Roaming\Real\Update\setup3.09\setup.exe
[2009.12.06 11:44:42 | 000,079,368 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Frank\AppData\Roaming\Real\Update\setup3.09\RUP\vista.exe
[2012.06.09 23:12:22 | 000,317,080 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Frank\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\9.11\rnupgagent.exe
[2012.06.10 11:00:59 | 028,087,744 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Frank\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\9.11\stub_data\RealPlayer_de.exe
[2012.06.10 11:00:13 | 000,693,504 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Frank\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\9.11\stub_exe\RealPlayer_de.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2008.01.21 04:32:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows.old\Windows\System32\drivers\AGP440.sys
[2008.01.21 04:32:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.21 04:32:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.21 04:32:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows.old\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.21 04:32:22 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows.old\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
[2008.01.21 04:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\SysNative\drivers\AGP440.sys
[2008.01.21 04:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008.01.21 04:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.01.21 04:46:50 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows.old\Windows\System32\drivers\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows.old\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.21 04:32:21 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.21 04:32:21 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows.old\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2009.04.11 09:15:00 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\SysNative\drivers\atapi.sys
[2009.04.11 09:15:00 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\SysNative\cngaudit.dll
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows.old\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 04:46:59 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2008.01.21 04:46:59 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
[2008.01.21 04:32:49 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows.old\Windows\System32\drivers\iaStorV.sys
[2008.01.21 04:32:49 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.21 04:32:49 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows.old\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2008.01.21 04:51:03 | 000,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows.old\Windows\System32\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SysWOW64\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009.04.11 09:11:16 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\SysNative\netlogon.dll
[2009.04.11 09:11:16 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008.01.21 04:33:41 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
[2008.01.21 04:48:28 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.21 04:32:47 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows.old\Windows\System32\drivers\nvstor.sys
[2008.01.21 04:32:47 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows.old\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.21 04:32:47 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows.old\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
[2008.01.21 04:46:54 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\SysNative\drivers\nvstor.sys
[2008.01.21 04:46:54 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 04:34:39 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2008.01.21 04:50:28 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008.01.21 04:49:49 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows.old\Windows\System32\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SysWOW64\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009.04.11 09:11:23 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\SysNative\scecli.dll
[2009.04.11 09:11:23 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
 
< MD5 for: USER32.DLL  >
[2008.01.21 04:48:29 | 000,820,224 | ---- | M] (Microsoft Corporation) MD5=32B87D215905F648EBE36A621978442C -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_295707c525b9f068\user32.dll
[2008.01.21 04:49:14 | 000,648,192 | ---- | M] (Microsoft Corporation) MD5=3D691030DBD3BD75DE1501BE54F0D425 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_33abb2175a1ab263\user32.dll
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\Windows.old\Windows\System32\user32.dll
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
[2008.01.21 04:34:02 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2009.04.11 08:26:45 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\SysWOW64\user32.dll
[2009.04.11 08:26:45 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_35972b23573c7daf\user32.dll
[2009.04.11 09:11:27 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysNative\user32.dll
[2009.04.11 09:11:27 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_2b4280d122dbbbb4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 04:34:37 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows.old\Windows\System32\userinit.exe
[2008.01.21 04:34:37 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2008.01.21 04:50:36 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\SysWOW64\userinit.exe
[2008.01.21 04:50:36 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2008.01.21 04:49:46 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\SysNative\userinit.exe
[2008.01.21 04:49:46 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.21 04:33:13 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows.old\Windows\System32\wininit.exe
[2008.01.21 04:33:13 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2008.01.21 04:48:04 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\SysWOW64\wininit.exe
[2008.01.21 04:48:04 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2008.01.21 04:50:23 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\SysNative\wininit.exe
[2008.01.21 04:50:23 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_8d115452bcae17d8\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.04.11 09:11:08 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\SysNative\winlogon.exe
[2009.04.11 09:11:08 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008.01.21 04:49:47 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows.old\Windows\System32\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SysWOW64\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2012.07.03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.01.21 04:34:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
[2008.01.21 04:50:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 04:49:42 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2008.01.21 04:49:42 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_aba53c58802b1777\ws2ifsl.sys
[2008.01.21 04:34:35 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows.old\Windows\System32\drivers\ws2ifsl.sys
[2008.01.21 04:34:35 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows.old\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

--- --- ---
[/code]

cosinus 02.08.2012 11:52

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes,DefaultScope = Plasmoo
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{08F95AC0-1D40-443E-ADA3-9A0EAD1745C8}: "URL" = http://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{5033262E-1290-45AD-8B2C-CB2FD2E65299}: "URL" = http://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{5CFDB435-86A1-48E5-ADE8-7F43EB9EAA8F}: "URL" = http://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://www.icq.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E6963712E636F6D2F7365617263682F726573756C74732E7068703F713D7B7365617263685465726D737D2663685F69643D6F7364&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{6FE52790-D24A-4B46-B535-7A88C2D86152}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=YYYYYYYYDE&apn_uid=F501E56B-5C15-4F3D-A955-EF8ABECD821C&apn_sauid=44DED72A-4D64-4297-8CDC-9A6F16CB5830
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{9148E46A-4B18-4B31-8B70-A8114CF989BD}: "URL" = http://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\{B357C1CA-69CF-4B2E-A69A-9BDC10F2F8AC}: "URL" = http://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\..\SearchScopes\Plasmoo: "URL" = http://plasmoo.com.anonymize-me.de/?anonymto=687474703A2F2F706C61736D6F6F2E636F6D2F726573756C742E68746D3F713D7B7365617263685465726D737D265365617263684D617368696E653D74727565&st={searchTerms}&clid=193bf99a-6e40-4d77-90b6-a2d438483d05&pid=freewarede&k=0
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2
FF - prefs.js..extensions.enabledItems: engine@plasmoo.com:1.0.0.32
FF - prefs.js..network.proxy.http: "190.66.17.53"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..extensions.enabledItems: ffxtlbra@softonic.com:1.5.0
FF - user.js - File not found
[2011.12.26 13:23:36 | 000,001,091 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\icqplugin.xml
[2011.12.26 13:23:37 | 000,002,188 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\{254DA591-C16D-4FB6-9062-4C050FA0B1BD}.xml
[2011.12.26 13:23:37 | 000,001,870 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\{6332F0FF-685E-4193-9E72-D96AEE055E73}.xml
[2011.12.26 13:23:37 | 000,002,077 | ---- | M] () -- C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\{7D01AA1A-5AB3-4D3E-ACAE-79CACC0E28AC}.xml
[2009.06.23 21:00:33 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.12.26 13:23:36 | 000,001,611 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrchDpg.xml
O4 - HKLM..\Run: []  File not found
O4 - HKU\S-1-5-21-1827684769-3620193026-1381853637-1000..\Run: []  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{2ae806f2-a2a0-11df-9537-0022156014a3}\Shell - "" = AutoRun
O33 - MountPoints2\{2ae806f2-a2a0-11df-9537-0022156014a3}\Shell\AutoRun\command - "" = J:\LGAutoRun.exe
O33 - MountPoints2\{86f40ed1-a9b5-11df-8350-0022156014a3}\Shell - "" = AutoRun
O33 - MountPoints2\{86f40ed1-a9b5-11df-8350-0022156014a3}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\Start.hta
O33 - MountPoints2\{de9b2b23-df64-11de-b799-0022156014a3}\Shell - "" = AutoRun
O33 - MountPoints2\{de9b2b23-df64-11de-b799-0022156014a3}\Shell\AutoRun\command - "" = I:\Autorun.exe
O33 - MountPoints2\{f7e9ea89-702b-11e1-a539-0022156014a3}\Shell - "" = AutoRun
O33 - MountPoints2\{f7e9ea89-702b-11e1-a539-0022156014a3}\Shell\AutoRun\command - "" = J:\NokiaPCIA_Autorun.exe
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

maeusuruh 08.08.2012 22:10

Hallo Arne!

Hier die OTL Fix:

Code:

All processes killed
========== OTL ==========
HKU\S-1-5-21-1827684769-3620193026-1381853637-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\StartPageCache| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-1827684769-3620193026-1381853637-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
HKEY_USERS\S-1-5-21-1827684769-3620193026-1381853637-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-1827684769-3620193026-1381853637-1000\Software\Microsoft\Internet Explorer\SearchScopes\{08F95AC0-1D40-443E-ADA3-9A0EAD1745C8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08F95AC0-1D40-443E-ADA3-9A0EAD1745C8}\ not found.
Registry key HKEY_USERS\S-1-5-21-1827684769-3620193026-1381853637-1000\Software\Microsoft\Internet Explorer\SearchScopes\{5033262E-1290-45AD-8B2C-CB2FD2E65299}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5033262E-1290-45AD-8B2C-CB2FD2E65299}\ not found.
Registry key HKEY_USERS\S-1-5-21-1827684769-3620193026-1381853637-1000\Software\Microsoft\Internet Explorer\SearchScopes\{5CFDB435-86A1-48E5-ADE8-7F43EB9EAA8F}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5CFDB435-86A1-48E5-ADE8-7F43EB9EAA8F}\ not found.
Registry key HKEY_USERS\S-1-5-21-1827684769-3620193026-1381853637-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found.
Registry key HKEY_USERS\S-1-5-21-1827684769-3620193026-1381853637-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6FE52790-D24A-4B46-B535-7A88C2D86152}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6FE52790-D24A-4B46-B535-7A88C2D86152}\ not found.
Registry key HKEY_USERS\S-1-5-21-1827684769-3620193026-1381853637-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9148E46A-4B18-4B31-8B70-A8114CF989BD}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9148E46A-4B18-4B31-8B70-A8114CF989BD}\ not found.
Registry key HKEY_USERS\S-1-5-21-1827684769-3620193026-1381853637-1000\Software\Microsoft\Internet Explorer\SearchScopes\{B357C1CA-69CF-4B2E-A69A-9BDC10F2F8AC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B357C1CA-69CF-4B2E-A69A-9BDC10F2F8AC}\ not found.
Registry key HKEY_USERS\S-1-5-21-1827684769-3620193026-1381853637-1000\Software\Microsoft\Internet Explorer\SearchScopes\{searchTerms}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{searchTerms}\ not found.
Prefs.js: engine@conduit.com:3.3.3.2 removed from extensions.enabledItems
Prefs.js: engine@plasmoo.com:1.0.0.32 removed from extensions.enabledItems
Prefs.js: "190.66.17.53" removed from network.proxy.http
Prefs.js: 3128 removed from network.proxy.http_port
Prefs.js: ffxtlbra@softonic.com:1.5.0 removed from extensions.enabledItems
C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\icqplugin.xml moved successfully.
C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\{254DA591-C16D-4FB6-9062-4C050FA0B1BD}.xml moved successfully.
C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\{6332F0FF-685E-4193-9E72-D96AEE055E73}.xml moved successfully.
C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\searchplugins\{7D01AA1A-5AB3-4D3E-ACAE-79CACC0E28AC}.xml moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} folder moved successfully.
C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrchDpg.xml moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1827684769-3620193026-1381853637-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2ae806f2-a2a0-11df-9537-0022156014a3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2ae806f2-a2a0-11df-9537-0022156014a3}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2ae806f2-a2a0-11df-9537-0022156014a3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2ae806f2-a2a0-11df-9537-0022156014a3}\ not found.
File J:\LGAutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{86f40ed1-a9b5-11df-8350-0022156014a3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{86f40ed1-a9b5-11df-8350-0022156014a3}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{86f40ed1-a9b5-11df-8350-0022156014a3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{86f40ed1-a9b5-11df-8350-0022156014a3}\ not found.
File C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\Start.hta not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{de9b2b23-df64-11de-b799-0022156014a3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{de9b2b23-df64-11de-b799-0022156014a3}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{de9b2b23-df64-11de-b799-0022156014a3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{de9b2b23-df64-11de-b799-0022156014a3}\ not found.
File I:\Autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7e9ea89-702b-11e1-a539-0022156014a3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f7e9ea89-702b-11e1-a539-0022156014a3}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7e9ea89-702b-11e1-a539-0022156014a3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f7e9ea89-702b-11e1-a539-0022156014a3}\ not found.
File J:\NokiaPCIA_Autorun.exe not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56466 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Frank
->Temp folder emptied: 305168630 bytes
->Temporary Internet Files folder emptied: 453556188 bytes
->Java cache emptied: 48675673 bytes
->FireFox cache emptied: 1157775869 bytes
->Flash cache emptied: 68063 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 401569 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 749 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 1.875,00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
->Flash cache emptied: 0 bytes
 
User: Default User
->Flash cache emptied: 0 bytes
 
User: Frank
->Flash cache emptied: 0 bytes
 
User: Public
 
Total Flash Files Cleaned = 0,00 mb
 
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.56.0 log created on 08082012_225916

Files\Folders moved on Reboot...
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.

PendingFileRenameOperations files...
[2012.08.08 23:03:16 | 000,000,098 | ---- | M] () C:\Windows\System32\drivers\etc\Hosts : MD5=F9C056369E96130CEAD3623A430D925F

Registry entries deleted on Reboot...


Gruß Claudia

cosinus 09.08.2012 15:49

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

maeusuruh 11.08.2012 18:41

Teil 1
Code:

19:28:34.0020 2612        TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32
19:28:34.0085 2612        ============================================================
19:28:34.0085 2612        Current date / time: 2012/08/11 19:28:34.0085
19:28:34.0085 2612        SystemInfo:
19:28:34.0085 2612       
19:28:34.0085 2612        OS Version: 6.0.6002 ServicePack: 2.0
19:28:34.0085 2612        Product type: Workstation
19:28:34.0085 2612        ComputerName: ADMIN-PC
19:28:34.0086 2612        UserName: Frank
19:28:34.0086 2612        Windows directory: C:\Windows
19:28:34.0086 2612        System windows directory: C:\Windows
19:28:34.0086 2612        Running under WOW64
19:28:34.0086 2612        Processor architecture: Intel x64
19:28:34.0086 2612        Number of processors: 2
19:28:34.0086 2612        Page size: 0x1000
19:28:34.0086 2612        Boot type: Normal boot
19:28:34.0086 2612        ============================================================
19:28:35.0154 2612        Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:28:35.0166 2612        ============================================================
19:28:35.0166 2612        \Device\Harddisk0\DR0:
19:28:35.0166 2612        MBR partitions:
19:28:35.0166 2612        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x74705800
19:28:35.0166 2612        ============================================================
19:28:35.0202 2612        C: <-> \Device\Harddisk0\DR0\Partition0
19:28:35.0203 2612        ============================================================
19:28:35.0203 2612        Initialize success
19:28:35.0203 2612        ============================================================
19:28:44.0796 5628        ============================================================
19:28:44.0796 5628        Scan started
19:28:44.0796 5628        Mode: Manual; SigCheck; TDLFS;
19:28:44.0796 5628        ============================================================
19:28:47.0336 5628        ACPI            (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys
19:28:47.0399 5628        ACPI - ok
19:28:47.0455 5628        ADIHdAudAddService (4a30fa79f8253134d398251db614e3c9) C:\Windows\system32\drivers\ADIHdAud.sys
19:28:47.0482 5628        ADIHdAudAddService - ok
19:28:47.0581 5628        AdobeARMservice (11a52cf7b265631deeb24c6149309eff) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
19:28:47.0588 5628        AdobeARMservice - ok
19:28:48.0077 5628        AdobeFlashPlayerUpdateSvc (f19c98ad81d2c0e1bbfd8153d2c80ee8) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
19:28:48.0086 5628        AdobeFlashPlayerUpdateSvc - ok
19:28:48.0993 5628        adp94xx        (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
19:28:49.0023 5628        adp94xx - ok
19:28:49.0064 5628        adpahci        (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
19:28:49.0078 5628        adpahci - ok
19:28:49.0105 5628        adpu160m        (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
19:28:49.0114 5628        adpu160m - ok
19:28:49.0138 5628        adpu320        (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
19:28:49.0148 5628        adpu320 - ok
19:28:49.0189 5628        AEADIFilters    (28c0b0a6cb61bdd1fef877d4d0f69fbf) C:\Windows\system32\AEADISRV.EXE
19:28:49.0203 5628        AEADIFilters - ok
19:28:49.0237 5628        AeLookupSvc    (0f421175574bfe0bf2f4d8e910a253bb) C:\Windows\System32\aelupsvc.dll
19:28:49.0253 5628        AeLookupSvc - ok
19:28:49.0331 5628        AFD            (c4f6ce6087760ad70960c9eb130e7943) C:\Windows\system32\drivers\afd.sys
19:28:49.0367 5628        AFD - ok
19:28:49.0407 5628        agp440          (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
19:28:49.0416 5628        agp440 - ok
19:28:49.0442 5628        aic78xx        (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
19:28:49.0453 5628        aic78xx - ok
19:28:49.0468 5628        ALG            (5922f4f59b7868f3d74bbbbeb7b825a3) C:\Windows\System32\alg.exe
19:28:49.0507 5628        ALG - ok
19:28:49.0532 5628        aliide          (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys
19:28:49.0540 5628        aliide - ok
19:28:49.0713 5628        AMD External Events Utility (20c8a3e435a47f0408a1ea674afa6194) C:\Windows\system32\atiesrxx.exe
19:28:49.0734 5628        AMD External Events Utility - ok
19:28:49.0743 5628        amdide          (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys
19:28:49.0751 5628        amdide - ok
19:28:49.0794 5628        AmdK8          (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
19:28:49.0816 5628        AmdK8 - ok
19:28:50.0132 5628        amdkmdag        (0b45c18b0f3ee996d25baa4e74884b83) C:\Windows\system32\DRIVERS\atikmdag.sys
19:28:50.0426 5628        amdkmdag - ok
19:28:50.0581 5628        amdkmdap        (0e57258e5cc4cc7a9a9a877afdf0cec6) C:\Windows\system32\DRIVERS\atikmpag.sys
19:28:50.0602 5628        amdkmdap - ok
19:28:50.0710 5628        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
19:28:50.0718 5628        AntiVirSchedulerService - ok
19:28:50.0752 5628        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
19:28:50.0759 5628        AntiVirService - ok
19:28:50.0828 5628        Appinfo        (9c37b3fd5615477cb9a0cd116cf43f5c) C:\Windows\System32\appinfo.dll
19:28:50.0842 5628        Appinfo - ok
19:28:50.0878 5628        arc            (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
19:28:50.0886 5628        arc - ok
19:28:50.0936 5628        arcsas          (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
19:28:50.0946 5628        arcsas - ok
19:28:50.0985 5628        AsyncMac        (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
19:28:51.0013 5628        AsyncMac - ok
19:28:51.0048 5628        atapi          (e68d9b3a3905619732f7fe039466a623) C:\Windows\system32\drivers\atapi.sys
19:28:51.0056 5628        atapi - ok
19:28:51.0140 5628        AtiHDAudioService (917692cdf8e1ce00d9752fa40615338b) C:\Windows\system32\drivers\AtihdLH6.sys
19:28:51.0150 5628        AtiHDAudioService - ok
19:28:51.0152 5628        AtiHdmiService - ok
19:28:51.0620 5628        atikmdag        (0b45c18b0f3ee996d25baa4e74884b83) C:\Windows\system32\DRIVERS\atikmdag.sys
19:28:51.0800 5628        atikmdag - ok
19:28:51.0965 5628        AudioEndpointBuilder (79318c744693ec983d20e9337a2f8196) C:\Windows\System32\Audiosrv.dll
19:28:51.0998 5628        AudioEndpointBuilder - ok
19:28:52.0001 5628        AudioSrv        (79318c744693ec983d20e9337a2f8196) C:\Windows\System32\Audiosrv.dll
19:28:52.0021 5628        AudioSrv - ok
19:28:52.0078 5628        avgntflt        (26e38b5a58c6c55fafbc563eeddb0867) C:\Windows\system32\DRIVERS\avgntflt.sys
19:28:52.0086 5628        avgntflt - ok
19:28:52.0099 5628        avipbb          (9d1f00beff84cbbf46d7f052bc7e0565) C:\Windows\system32\DRIVERS\avipbb.sys
19:28:52.0107 5628        avipbb - ok
19:28:52.0127 5628        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
19:28:52.0134 5628        avkmgr - ok
19:28:52.0188 5628        BFE            (ffb96c2589ffa60473ead78b39fbde29) C:\Windows\System32\bfe.dll
19:28:52.0217 5628        BFE - ok
19:28:52.0286 5628        BITS            (6d316f4859634071cc25c4fd4589ad2c) C:\Windows\System32\qmgr.dll
19:28:52.0331 5628        BITS - ok
19:28:52.0380 5628        blbdrive        (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
19:28:52.0410 5628        blbdrive - ok
19:28:52.0444 5628        bowser          (2348447a80920b2493a9b582a23e81e1) C:\Windows\system32\DRIVERS\bowser.sys
19:28:52.0464 5628        bowser - ok
19:28:52.0485 5628        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
19:28:52.0500 5628        BrFiltLo - ok
19:28:52.0515 5628        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
19:28:52.0536 5628        BrFiltUp - ok
19:28:52.0573 5628        Browser        (a1b39de453433b115b4ea69ee0343816) C:\Windows\System32\browser.dll
19:28:52.0603 5628        Browser - ok
19:28:52.0647 5628        Brserid        (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
19:28:52.0687 5628        Brserid - ok
19:28:52.0705 5628        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
19:28:52.0751 5628        BrSerWdm - ok
19:28:52.0760 5628        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
19:28:52.0803 5628        BrUsbMdm - ok
19:28:52.0818 5628        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
19:28:52.0856 5628        BrUsbSer - ok
19:28:52.0870 5628        BTHMODEM        (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
19:28:52.0909 5628        BTHMODEM - ok
19:28:52.0934 5628        cdfs            (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
19:28:52.0962 5628        cdfs - ok
19:28:53.0001 5628        cdrom          (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys
19:28:53.0028 5628        cdrom - ok
19:28:53.0061 5628        CertPropSvc    (5a268127633c7ee2a7fb87f39d748d56) C:\Windows\System32\certprop.dll
19:28:53.0082 5628        CertPropSvc - ok
19:28:53.0110 5628        circlass        (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys
19:28:53.0131 5628        circlass - ok
19:28:53.0177 5628        CLFS            (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys
19:28:53.0191 5628        CLFS - ok
19:28:53.0287 5628        clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:28:53.0295 5628        clr_optimization_v2.0.50727_32 - ok
19:28:53.0361 5628        clr_optimization_v2.0.50727_64 (ce07a466201096f021cd09d631b21540) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
19:28:53.0369 5628        clr_optimization_v2.0.50727_64 - ok
19:28:53.0449 5628        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:28:53.0457 5628        clr_optimization_v4.0.30319_32 - ok
19:28:53.0480 5628        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
19:28:53.0487 5628        clr_optimization_v4.0.30319_64 - ok
19:28:53.0525 5628        cmdide          (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys
19:28:53.0532 5628        cmdide - ok
19:28:53.0543 5628        Compbatt        (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\drivers\compbatt.sys
19:28:53.0551 5628        Compbatt - ok
19:28:53.0553 5628        COMSysApp - ok
19:28:53.0624 5628        cpuz132 - ok
19:28:53.0634 5628        crcdisk        (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
19:28:53.0641 5628        crcdisk - ok
19:28:53.0690 5628        CryptSvc        (62740b9d2a137e8ced41a9e4239a7a31) C:\Windows\system32\cryptsvc.dll
19:28:53.0707 5628        CryptSvc - ok
19:28:53.0766 5628        DcomLaunch      (cf8b9a3a5e7dc57724a89d0c3e8cf9ef) C:\Windows\system32\rpcss.dll
19:28:53.0791 5628        DcomLaunch - ok
19:28:53.0838 5628        DfsC            (8b722ba35205c71e7951cdc4cdbade19) C:\Windows\system32\Drivers\dfsc.sys
19:28:53.0855 5628        DfsC - ok
19:28:53.0952 5628        DFSR            (c647f468f7de343df8c143655c5557d4) C:\Windows\system32\DFSR.exe
19:28:54.0021 5628        DFSR - ok
19:28:54.0164 5628        Dhcp            (3ed0321127ce70acdaabbf77e157c2a7) C:\Windows\System32\dhcpcsvc.dll
19:28:54.0181 5628        Dhcp - ok
19:28:54.0242 5628        disk            (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys
19:28:54.0251 5628        disk - ok
19:28:54.0295 5628        Dnscache        (06230f1b721494a6df8d47fd395bb1b0) C:\Windows\System32\dnsrslvr.dll
19:28:54.0312 5628        Dnscache - ok
19:28:54.0351 5628        dot3svc        (1a7156dd1e850e9914e5e991e3225b94) C:\Windows\System32\dot3svc.dll
19:28:54.0368 5628        dot3svc - ok
19:28:54.0401 5628        DPS            (1583b39790db3eaec7edb0cb0140c708) C:\Windows\system32\dps.dll
19:28:54.0434 5628        DPS - ok
19:28:54.0480 5628        drmkaud        (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
19:28:54.0513 5628        drmkaud - ok
19:28:54.0566 5628        DXGKrnl        (b8e554e502d5123bc111f99d6a2181b4) C:\Windows\System32\drivers\dxgkrnl.sys
19:28:54.0585 5628        DXGKrnl - ok
19:28:54.0621 5628        E1G60          (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
19:28:54.0654 5628        E1G60 - ok
19:28:54.0665 5628        EagleX64 - ok
19:28:54.0698 5628        EapHost        (c2303883fd9be49dc36a6400643002ea) C:\Windows\System32\eapsvc.dll
19:28:54.0735 5628        EapHost - ok
19:28:54.0783 5628        Ecache          (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys
19:28:54.0793 5628        Ecache - ok
19:28:54.0828 5628        ehRecvr        (14ce384d2e27b64c256bda4dc39c312d) C:\Windows\ehome\ehRecvr.exe
19:28:54.0864 5628        ehRecvr - ok
19:28:54.0883 5628        ehSched        (b93159c1313d66fdfbbe876f5189cd52) C:\Windows\ehome\ehsched.exe
19:28:54.0891 5628        ehSched - ok
19:28:54.0901 5628        ehstart        (f5ee2527d74449868e3c3227a59bcd28) C:\Windows\ehome\ehstart.dll
19:28:54.0915 5628        ehstart - ok
19:28:54.0948 5628        elxstor        (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
19:28:54.0963 5628        elxstor - ok
19:28:55.0009 5628        EMDMgmt        (a9b18b63a4fd6baab83326706d857fab) C:\Windows\system32\emdmgmt.dll
19:28:55.0046 5628        EMDMgmt - ok
19:28:55.0069 5628        ErrDev          (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys
19:28:55.0100 5628        ErrDev - ok
19:28:55.0148 5628        EventSystem    (e12f22b73f153dece721cd45ec05b4af) C:\Windows\system32\es.dll
19:28:55.0194 5628        EventSystem - ok
19:28:55.0228 5628        exfat          (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys
19:28:55.0244 5628        exfat - ok
19:28:55.0286 5628        fastfat        (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys
19:28:55.0319 5628        fastfat - ok
19:28:55.0352 5628        fdc            (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
19:28:55.0373 5628        fdc - ok
19:28:55.0405 5628        fdPHost        (bb9267acacd8b7533dd936c34a0cba5e) C:\Windows\system32\fdPHost.dll
19:28:55.0435 5628        fdPHost - ok
19:28:55.0448 5628        FDResPub        (300c80931eabbe1db7591c516efe8d0f) C:\Windows\system32\fdrespub.dll
19:28:55.0484 5628        FDResPub - ok
19:28:55.0494 5628        FileInfo        (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
19:28:55.0503 5628        FileInfo - ok
19:28:55.0517 5628        Filetrace      (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
19:28:55.0538 5628        Filetrace - ok
19:28:55.0548 5628        flpydisk        (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
19:28:55.0570 5628        flpydisk - ok
19:28:55.0615 5628        FltMgr          (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys
19:28:55.0625 5628        FltMgr - ok
19:28:55.0688 5628        FontCache      (be1c5bd1ca7ed015bc6fa1ae67e592c8) C:\Windows\system32\FntCache.dll
19:28:55.0725 5628        FontCache - ok
19:28:55.0794 5628        FontCache3.0.0.0 (bc5b0be5af3510b0fd8c140ee42c6d3e) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
19:28:55.0801 5628        FontCache3.0.0.0 - ok
19:28:55.0892 5628        FreemakeVideoCapture - ok
19:28:55.0935 5628        Fs_Rec          (5779b86cd8b32519fbecb136394d946a) C:\Windows\system32\drivers\Fs_Rec.sys
19:28:55.0947 5628        Fs_Rec - ok
19:28:55.0971 5628        gagp30kx        (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
19:28:55.0980 5628        gagp30kx - ok
19:28:56.0022 5628        GEARAspiWDM    (58e581a98a85587e9f5a297d4ad44cc0) C:\Windows\system32\Drivers\GEARAspiWDM.sys
19:28:56.0029 5628        GEARAspiWDM - ok
19:28:56.0077 5628        gpsvc          (a0e1b575ba8f504968cd40c0faeb2384) C:\Windows\System32\gpsvc.dll
19:28:56.0101 5628        gpsvc - ok
19:28:56.0151 5628        HdAudAddService (68e732382b32417ff61fd663259b4b09) C:\Windows\system32\drivers\HdAudio.sys
19:28:56.0162 5628        HdAudAddService - ok
19:28:56.0223 5628        HDAudBus        (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys
19:28:56.0262 5628        HDAudBus - ok
19:28:56.0295 5628        HidBth          (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
19:28:56.0338 5628        HidBth - ok
19:28:56.0344 5628        HidIr          (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
19:28:56.0386 5628        HidIr - ok
19:28:56.0419 5628        hidserv        (59361d38a297755d46a540e450202b2a) C:\Windows\system32\hidserv.dll
19:28:56.0435 5628        hidserv - ok
19:28:56.0476 5628        HidUsb          (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys
19:28:56.0498 5628        HidUsb - ok
19:28:56.0532 5628        hkmsvc          (b12f367ea39c0795fd57e31242ce1a5a) C:\Windows\system32\kmsvc.dll
19:28:56.0554 5628        hkmsvc - ok
19:28:56.0594 5628        HpCISSs        (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
19:28:56.0603 5628        HpCISSs - ok
19:28:56.0644 5628        HTCAND64        (894a75a3d6bfd97d73bf60d3022b567a) C:\Windows\system32\Drivers\ANDROIDUSB.sys
19:28:56.0662 5628        HTCAND64 - ok
19:28:56.0707 5628        htcnprot        (4f6c3122817049997cd696d4a38bfacb) C:\Windows\system32\DRIVERS\htcnprot.sys
19:28:56.0714 5628        htcnprot - ok
19:28:56.0760 5628        HTTP            (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys
19:28:56.0810 5628        HTTP - ok
19:28:56.0839 5628        i2omp          (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
19:28:56.0847 5628        i2omp - ok
19:28:56.0869 5628        i8042prt        (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
19:28:56.0892 5628        i8042prt - ok
19:28:56.0912 5628        iaStorV        (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
19:28:56.0923 5628        iaStorV - ok
19:28:57.0015 5628        IDriverT        (6f95324909b502e2651442c1548ab12f) C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
19:28:57.0035 5628        IDriverT ( UnsignedFile.Multi.Generic ) - warning
19:28:57.0035 5628        IDriverT - detected UnsignedFile.Multi.Generic (1)
19:28:57.0160 5628        idsvc          (749f5f8cedca70f2a512945325fc489d) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
19:28:57.0182 5628        idsvc - ok
19:28:57.0194 5628        iirsp          (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
19:28:57.0202 5628        iirsp - ok
19:28:57.0241 5628        IKEEXT          (0c9ea6e654e7b0471741e343a6c671af) C:\Windows\System32\ikeext.dll
19:28:57.0263 5628        IKEEXT - ok
19:28:57.0310 5628        intelide        (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys
19:28:57.0318 5628        intelide - ok
19:28:57.0334 5628        intelppm        (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
19:28:57.0355 5628        intelppm - ok
19:28:57.0384 5628        IPBusEnum      (5624bc1bc5eeb49c0ab76a8114f05ea3) C:\Windows\system32\ipbusenum.dll
19:28:57.0406 5628        IPBusEnum - ok
19:28:57.0444 5628        IpFilterDriver  (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:28:57.0473 5628        IpFilterDriver - ok
19:28:57.0497 5628        iphlpsvc        (bf0dbfa9792c5c14fa00f61c75116c1b) C:\Windows\System32\iphlpsvc.dll
19:28:57.0512 5628        iphlpsvc - ok
19:28:57.0514 5628        IpInIp - ok
19:28:57.0532 5628        IPMIDRV        (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
19:28:57.0553 5628        IPMIDRV - ok
19:28:57.0568 5628        IPNAT          (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
19:28:57.0598 5628        IPNAT - ok
19:28:57.0626 5628        IRENUM          (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
19:28:57.0656 5628        IRENUM - ok
19:28:57.0678 5628        isapnp          (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
19:28:57.0686 5628        isapnp - ok
19:28:57.0726 5628        iScsiPrt        (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys
19:28:57.0736 5628        iScsiPrt - ok
19:28:57.0749 5628        iteatapi        (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
19:28:57.0756 5628        iteatapi - ok
19:28:57.0780 5628        iteraid        (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
19:28:57.0788 5628        iteraid - ok
19:28:57.0795 5628        kbdclass        (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
19:28:57.0803 5628        kbdclass - ok
19:28:57.0829 5628        kbdhid          (dbdf75d51464fbc47d0104ec3d572c05) C:\Windows\system32\DRIVERS\kbdhid.sys
19:28:57.0850 5628        kbdhid - ok
19:28:57.0871 5628        KeyIso          (260bf9c43ee12c6898a9f5aab0fb0e5d) C:\Windows\system32\lsass.exe
19:28:57.0895 5628        KeyIso - ok
19:28:57.0941 5628        KSecDD          (88956ad9fa510848ad176777a6c6c1f5) C:\Windows\system32\Drivers\ksecdd.sys
19:28:57.0955 5628        KSecDD - ok
19:28:57.0987 5628        ksthunk        (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
19:28:58.0017 5628        ksthunk - ok
19:28:58.0064 5628        KtmRm          (1faf6926f3416d3da05c5b265491bdae) C:\Windows\system32\msdtckrm.dll
19:28:58.0108 5628        KtmRm - ok
19:28:58.0148 5628        L8042Kbd        (f33c5d79d3273530e1892a0922283a7b) C:\Windows\system32\DRIVERS\L8042Kbd.sys
19:28:58.0154 5628        L8042Kbd - ok
19:28:58.0191 5628        LanmanServer    (50c7a3cb427e9bb5ed0708a669956ab5) C:\Windows\system32\srvsvc.dll
19:28:58.0207 5628        LanmanServer - ok
19:28:58.0257 5628        LanmanWorkstation (caf86fc1388be1e470f1a7b43e348adb) C:\Windows\System32\wkssvc.dll
19:28:58.0278 5628        LanmanWorkstation - ok
19:28:58.0336 5628        LGDDCDevice    (094c41ab6fbb0ec205989e92e257aebf) C:\Program Files (x86)\LG Soft India\forteManager\bin\I2CDriver.sys
19:28:58.0352 5628        LGDDCDevice ( UnsignedFile.Multi.Generic ) - warning
19:28:58.0352 5628        LGDDCDevice - detected UnsignedFile.Multi.Generic (1)
19:28:58.0368 5628        LGII2CDevice    (8409a28e641136caf114120c7387d072) C:\Program Files (x86)\LG Soft India\forteManager\bin\PII2CDriver.sys
19:28:58.0382 5628        LGII2CDevice ( UnsignedFile.Multi.Generic ) - warning
19:28:58.0382 5628        LGII2CDevice - detected UnsignedFile.Multi.Generic (1)
19:28:58.0423 5628        LHidFilt        (b6552d382ff070b4ed34cbd6737277c0) C:\Windows\system32\DRIVERS\LHidFilt.Sys
19:28:58.0429 5628        LHidFilt - ok
19:28:58.0457 5628        lltdio          (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
19:28:58.0484 5628        lltdio - ok
19:28:58.0522 5628        lltdsvc        (961ccbd0b1ccb5675d64976fae37d092) C:\Windows\System32\lltdsvc.dll
19:28:58.0552 5628        lltdsvc - ok
19:28:58.0563 5628        lmhosts        (a47f8080cacc23c91fe823ad19aa5612) C:\Windows\System32\lmhsvc.dll
19:28:58.0585 5628        lmhosts - ok
19:28:58.0597 5628        LMouFilt        (73c1f563ab73d459dffe682d66476558) C:\Windows\system32\DRIVERS\LMouFilt.Sys
19:28:58.0603 5628        LMouFilt - ok
19:28:58.0616 5628        LSI_FC          (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
19:28:58.0626 5628        LSI_FC - ok
19:28:58.0656 5628        LSI_SAS        (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
19:28:58.0665 5628        LSI_SAS - ok
19:28:58.0695 5628        LSI_SCSI        (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
19:28:58.0705 5628        LSI_SCSI - ok
19:28:58.0720 5628        luafv          (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
19:28:58.0745 5628        luafv - ok
19:28:58.0772 5628        MBAMProtector  (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys
19:28:58.0780 5628        MBAMProtector - ok
19:28:58.0830 5628        MBAMService    (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
19:28:58.0857 5628        MBAMService - ok
19:28:58.0888 5628        Mcx2Svc        (76a58df02bd4ea29f189b82d0bef17f8) C:\Windows\system32\Mcx2Svc.dll
19:28:58.0897 5628        Mcx2Svc - ok
19:28:58.0988 5628        megasas        (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
19:28:58.0996 5628        megasas - ok
19:28:59.0028 5628        MegaSR          (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
19:28:59.0043 5628        MegaSR - ok
19:28:59.0075 5628        MMCSS          (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll
19:28:59.0104 5628        MMCSS - ok
19:28:59.0113 5628        Modem          (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
19:28:59.0144 5628        Modem - ok
19:28:59.0151 5628        monitor        (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
19:28:59.0179 5628        monitor - ok
19:28:59.0209 5628        mouclass        (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
19:28:59.0217 5628        mouclass - ok
19:28:59.0236 5628        mouhid          (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
19:28:59.0257 5628        mouhid - ok
19:28:59.0268 5628        MountMgr        (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
19:28:59.0276 5628        MountMgr - ok
19:28:59.0302 5628        mpio            (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
19:28:59.0311 5628        mpio - ok
19:28:59.0321 5628        mpsdrv          (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
19:28:59.0342 5628        mpsdrv - ok
19:28:59.0396 5628        MpsSvc          (897e3baf68ba406a61682ae39c83900c) C:\Windows\system32\mpssvc.dll
19:28:59.0420 5628        MpsSvc - ok
19:28:59.0432 5628        Mraid35x        (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
19:28:59.0440 5628        Mraid35x - ok
19:28:59.0475 5628        MRxDAV          (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys
19:28:59.0494 5628        MRxDAV - ok
19:28:59.0530 5628        mrxsmb          (1485811b320ff8c7edad1caebb1c6c2b) C:\Windows\system32\DRIVERS\mrxsmb.sys
19:28:59.0539 5628        mrxsmb - ok
19:28:59.0582 5628        mrxsmb10        (3b929a60c833fc615fd97fba82bc7632) C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:28:59.0602 5628        mrxsmb10 - ok
19:28:59.0606 5628        mrxsmb20        (c64ab3e1f53b4f5b5bb6d796b2d7bec3) C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:28:59.0615 5628        mrxsmb20 - ok
19:28:59.0645 5628        msahci          (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys
19:28:59.0653 5628        msahci - ok
19:28:59.0669 5628        msdsm          (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
19:28:59.0678 5628        msdsm - ok
19:28:59.0711 5628        MSDTC          (7ec02ce772f068ed0beafa3da341a9bc) C:\Windows\System32\msdtc.exe
19:28:59.0733 5628        MSDTC - ok
19:28:59.0751 5628        Msfs            (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
19:28:59.0797 5628        Msfs - ok
19:28:59.0879 5628        msisadrv        (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
19:28:59.0887 5628        msisadrv - ok
19:28:59.0925 5628        MSiSCSI        (366b0c1f4478b519c181e37d43dcda32) C:\Windows\system32\iscsiexe.dll
19:28:59.0948 5628        MSiSCSI - ok
19:28:59.0950 5628        msiserver - ok
19:28:59.0960 5628        MSKSSRV        (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
19:28:59.0992 5628        MSKSSRV - ok
19:29:00.0013 5628        MSPCLOCK        (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
19:29:00.0035 5628        MSPCLOCK - ok
19:29:00.0070 5628        MSPQM          (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
19:29:00.0102 5628        MSPQM - ok
19:29:00.0143 5628        MsRPC          (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys
19:29:00.0154 5628        MsRPC - ok
19:29:00.0163 5628        mssmbios        (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
19:29:00.0171 5628        mssmbios - ok
19:29:00.0174 5628        MSTEE          (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
19:29:00.0195 5628        MSTEE - ok
19:29:00.0229 5628        MTsensor        (6936198f2cc25b39cf5262436c80df46) C:\Windows\system32\DRIVERS\ASACPI.sys
19:29:00.0235 5628        MTsensor - ok
19:29:00.0242 5628        Mup            (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys
19:29:00.0250 5628        Mup - ok
19:29:00.0302 5628        napagent        (a5b10c845e7538c60c0f5d87a57cb3f5) C:\Windows\system32\qagentRT.dll
19:29:00.0335 5628        napagent - ok
19:29:00.0387 5628        NativeWifiP    (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys
19:29:00.0404 5628        NativeWifiP - ok
19:29:00.0464 5628        NDIS            (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys
19:29:00.0483 5628        NDIS - ok
19:29:00.0521 5628        NdisTapi        (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
19:29:00.0542 5628        NdisTapi - ok
19:29:00.0555 5628        Ndisuio        (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
19:29:00.0587 5628        Ndisuio - ok
19:29:00.0629 5628        NdisWan        (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys
19:29:00.0651 5628        NdisWan - ok
19:29:00.0666 5628        NDProxy        (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
19:29:00.0689 5628        NDProxy - ok
19:29:00.0819 5628        Nero BackItUp Scheduler 3 (c5052fb77aa42ed440f9f6b4e37145a9) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
19:29:00.0837 5628        Nero BackItUp Scheduler 3 - ok
19:29:00.0865 5628        NetBIOS        (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
19:29:00.0886 5628        NetBIOS - ok
19:29:00.0935 5628        netbt          (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys
19:29:00.0957 5628        netbt - ok
19:29:00.0995 5628        Netlogon        (260bf9c43ee12c6898a9f5aab0fb0e5d) C:\Windows\system32\lsass.exe
19:29:01.0003 5628        Netlogon - ok
19:29:01.0045 5628        Netman          (9b63b29defc0f3115a559d2597bf5d75) C:\Windows\System32\netman.dll
19:29:01.0086 5628        Netman - ok
19:29:01.0107 5628        netprofm        (7846d0136cc2b264926a73047ba7688a) C:\Windows\System32\netprofm.dll
19:29:01.0135 5628        netprofm - ok
19:29:01.0243 5628        NetTcpPortSharing (74751dda198165947fd7454d83f49825) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
19:29:01.0252 5628        NetTcpPortSharing - ok
19:29:01.0280 5628        nfrd960        (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
19:29:01.0288 5628        nfrd960 - ok
19:29:01.0322 5628        NlaSvc          (f145bf4c4668e7e312069f81ef847cfc) C:\Windows\System32\nlasvc.dll
19:29:01.0353 5628        NlaSvc - ok
19:29:01.0459 5628        NMIndexingService (74149bcf0307bb76d68c0f8912df731c) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
19:29:01.0472 5628        NMIndexingService - ok
19:29:01.0524 5628        nmwcd          (903681bab213d5f84717c0fc42afb28a) C:\Windows\system32\drivers\ccdcmbx64.sys
19:29:01.0547 5628        nmwcd - ok
19:29:01.0584 5628        nmwcdc          (ec4c5ebd003e0395bf4ea5a2efd13ce6) C:\Windows\system32\drivers\ccdcmbox64.sys
19:29:01.0611 5628        nmwcdc - ok
19:29:01.0648 5628        nmwcdnsucx64    (863aa6c58ac85a22355ae943c605e44b) C:\Windows\system32\drivers\nmwcdnsucx64.sys
19:29:01.0670 5628        nmwcdnsucx64 - ok
19:29:01.0684 5628        nmwcdnsux64    (7983d9201788407c4d1fc4d0baa04e32) C:\Windows\system32\drivers\nmwcdnsux64.sys
19:29:01.0714 5628        nmwcdnsux64 - ok
19:29:01.0750 5628        npf            (351533acc2a069b94e80bbfc177e8fdf) C:\Windows\system32\drivers\npf.sys
19:29:01.0757 5628        npf - ok
19:29:01.0792 5628        Npfs            (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys
19:29:01.0813 5628        Npfs - ok
19:29:01.0841 5628        nsi            (acb62baa1c319b17752553df3026eeeb) C:\Windows\system32\nsisvc.dll
19:29:01.0868 5628        nsi - ok
19:29:01.0905 5628        nsiproxy        (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
19:29:01.0930 5628        nsiproxy - ok
19:29:02.0003 5628        Ntfs            (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys
19:29:02.0036 5628        Ntfs - ok
19:29:02.0147 5628        Null            (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
19:29:02.0172 5628        Null - ok
19:29:02.0203 5628        nvraid          (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys
19:29:02.0213 5628        nvraid - ok
19:29:02.0227 5628        nvstor          (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys
19:29:02.0235 5628        nvstor - ok
19:29:02.0249 5628        nv_agp          (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys
19:29:02.0259 5628        nv_agp - ok
19:29:02.0260 5628        NwlnkFlt - ok
19:29:02.0263 5628        NwlnkFwd - ok
19:29:02.0307 5628        ohci1394        (b5b1ce65ac15bbd11c0619e3ef7cfc28) C:\Windows\system32\DRIVERS\ohci1394.sys
19:29:02.0331 5628        ohci1394 - ok
19:29:02.0385 5628        p2pimsvc        (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll
19:29:02.0426 5628        p2pimsvc - ok
19:29:02.0431 5628        p2psvc          (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll
19:29:02.0448 5628        p2psvc - ok
19:29:02.0526 5628        PAC7302        (4729a9729eda69a018796a7a48a9a846) C:\Windows\system32\DRIVERS\PAC7302.SYS
19:29:02.0586 5628        PAC7302 - ok
19:29:02.0617 5628        Parport        (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys
19:29:02.0651 5628        Parport - ok
19:29:02.0687 5628        partmgr        (b43751085e2abe389da466bc62a4b987) C:\Windows\system32\drivers\partmgr.sys
19:29:02.0695 5628        partmgr - ok
19:29:02.0781 5628        PassThru Service (39b9dcd7040654c2e57d7396736c718e) C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
19:29:02.0791 5628        PassThru Service ( UnsignedFile.Multi.Generic ) - warning
19:29:02.0791 5628        PassThru Service - detected UnsignedFile.Multi.Generic (1)
19:29:02.0816 5628        PcaSvc          (9ab157b374192ff276c1628fbdba2b0e) C:\Windows\System32\pcasvc.dll
19:29:02.0826 5628        PcaSvc - ok
19:29:02.0892 5628        pccsmcfd        (bc0018c2d29f655188a0ed3fa94fdb24) C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
19:29:02.0899 5628        pccsmcfd - ok
19:29:02.0947 5628        pci            (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys
19:29:02.0957 5628        pci - ok
19:29:02.0975 5628        pciide          (2657f6c0b78c36d95034be109336e382) C:\Windows\system32\drivers\pciide.sys
19:29:02.0983 5628        pciide - ok
19:29:03.0021 5628        pcmcia          (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys
19:29:03.0031 5628        pcmcia - ok
19:29:03.0061 5628        PEAUTH          (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
19:29:03.0114 5628        PEAUTH - ok
19:29:03.0181 5628        PerfHost        (0ed8727ea0172860f47258456c06caea) C:\Windows\SysWow64\perfhost.exe
19:29:03.0208 5628        PerfHost - ok
19:29:03.0289 5628        pla            (e9e68c1a0f25cf4a7ac966eea74ee89e) C:\Windows\system32\pla.dll
19:29:03.0354 5628        pla - ok
19:29:03.0400 5628        PlugPlay        (fe6b0f59215c9fd9f9d26539c58c8b82) C:\Windows\system32\umpnpmgr.dll
19:29:03.0418 5628        PlugPlay - ok
19:29:03.0420 5628        PnkBstrA - ok
19:29:03.0477 5628        PNRPAutoReg    (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll
19:29:03.0493 5628        PNRPAutoReg - ok
19:29:03.0498 5628        PNRPsvc        (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll
19:29:03.0517 5628        PNRPsvc - ok
19:29:03.0547 5628        PolicyAgent    (89a5560671c2d8b4a4b51f3e1aa069d8) C:\Windows\System32\ipsecsvc.dll
19:29:03.0591 5628        PolicyAgent - ok
19:29:03.0665 5628        PptpMiniport    (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys
19:29:03.0688 5628        PptpMiniport - ok
19:29:03.0721 5628        Processor      (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys
19:29:03.0742 5628        Processor - ok
19:29:03.0780 5628        ProfSvc        (e058ce4fc2449d8bfa14739c83b7ff2a) C:\Windows\system32\profsvc.dll
19:29:03.0801 5628        ProfSvc - ok
19:29:03.0836 5628        ProtectedStorage (260bf9c43ee12c6898a9f5aab0fb0e5d) C:\Windows\system32\lsass.exe
19:29:03.0844 5628        ProtectedStorage - ok
19:29:03.0883 5628        PSched          (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys
19:29:03.0898 5628        PSched - ok
19:29:03.0940 5628        ql2300          (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys
19:29:03.0970 5628        ql2300 - ok
19:29:03.0991 5628        ql40xx          (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
19:29:03.0999 5628        ql40xx - ok
19:29:04.0038 5628        QWAVE          (90574842c3da781e279061a3eff91f07) C:\Windows\system32\qwave.dll
19:29:04.0056 5628        QWAVE - ok
19:29:04.0069 5628        QWAVEdrv        (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
19:29:04.0078 5628        QWAVEdrv - ok
19:29:04.0111 5628        RasAcd          (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
19:29:04.0135 5628        RasAcd - ok
19:29:04.0150 5628        RasAuto        (b2ae18f847d07f0044404ddf7cb04497) C:\Windows\System32\rasauto.dll
19:29:04.0172 5628        RasAuto - ok
19:29:04.0214 5628        Rasl2tp        (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys
19:29:04.0240 5628        Rasl2tp - ok
19:29:04.0260 5628        RasMan          (3ad83e4046c43be510de681588acb8af) C:\Windows\System32\rasmans.dll
19:29:04.0278 5628        RasMan - ok
19:29:04.0316 5628        RasPppoe        (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys
19:29:04.0340 5628        RasPppoe - ok
19:29:04.0374 5628        RasSstp        (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys
19:29:04.0383 5628        RasSstp - ok
19:29:04.0424 5628        rdbss          (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys
19:29:04.0442 5628        rdbss - ok
19:29:04.0477 5628        RDPCDD          (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
19:29:04.0498 5628        RDPCDD - ok
19:29:04.0520 5628        rdpdr          (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys
19:29:04.0557 5628        rdpdr - ok
19:29:04.0560 5628        RDPENCDD        (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
19:29:04.0581 5628        RDPENCDD - ok
19:29:04.0612 5628        RDPWD          (ae4bd9e1c33d351d8e607fc81f15160c) C:\Windows\system32\drivers\RDPWD.sys
19:29:04.0622 5628        RDPWD - ok
19:29:04.0658 5628        RemoteAccess    (c612b9557da73f70d41f8a6fbc8e5344) C:\Windows\System32\mprdim.dll
19:29:04.0685 5628        RemoteAccess - ok
19:29:04.0723 5628        RemoteRegistry  (44b9d8ec2f3ef3a0efb00857af70d861) C:\Windows\system32\regsvc.dll
19:29:04.0751 5628        RemoteRegistry - ok
19:29:04.0779 5628        RpcLocator      (f46c457840d4b7a4daafee739ce04102) C:\Windows\system32\locator.exe
19:29:04.0787 5628        RpcLocator - ok
19:29:04.0839 5628        RpcSs          (cf8b9a3a5e7dc57724a89d0c3e8cf9ef) C:\Windows\system32\rpcss.dll
19:29:04.0862 5628        RpcSs - ok
19:29:04.0914 5628        rspndr          (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
19:29:04.0935 5628        rspndr - ok
19:29:04.0952 5628        SamSs          (260bf9c43ee12c6898a9f5aab0fb0e5d) C:\Windows\system32\lsass.exe
19:29:04.0961 5628        SamSs - ok
19:29:04.0980 5628        sbp2port        (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys
19:29:04.0988 5628        sbp2port - ok
19:29:05.0025 5628        SCardSvr        (fd1cdcf108d5ef3366f00d18b70fb89b) C:\Windows\System32\SCardSvr.dll
19:29:05.0046 5628        SCardSvr - ok
19:29:05.0101 5628        Schedule        (0f838c811ad295d2a4489b9993096c63) C:\Windows\system32\schedsvc.dll
19:29:05.0170 5628        Schedule - ok
19:29:05.0217 5628        SCPolicySvc    (5a268127633c7ee2a7fb87f39d748d56) C:\Windows\System32\certprop.dll
19:29:05.0232 5628        SCPolicySvc - ok
19:29:05.0266 5628        SDRSVC          (4ff71b076a7760fe75ea5ae2d0ee0018) C:\Windows\System32\SDRSVC.dll
19:29:05.0283 5628        SDRSVC - ok
19:29:05.0399 5628        SearchAnonymizer (0f4a80438e7286a0e623582f5f2395bd) C:\Users\Frank\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
19:29:05.0407 5628        SearchAnonymizer ( UnsignedFile.Multi.Generic ) - warning
19:29:05.0407 5628        SearchAnonymizer - detected UnsignedFile.Multi.Generic (1)
19:29:05.0464 5628        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
19:29:05.0508 5628        secdrv - ok
19:29:05.0535 5628        seclogon        (5acdcbc67fcf894a1815b9f96d704490) C:\Windows\system32\seclogon.dll
19:29:05.0562 5628        seclogon - ok
19:29:05.0575 5628        SENS            (90973a64b96cd647ff81c79443618eed) C:\Windows\System32\sens.dll
19:29:05.0603 5628        SENS - ok
19:29:05.0620 5628        Serenum        (2449316316411d65bd2c761a6ffb2ce2) C:\Windows\system32\DRIVERS\serenum.sys
19:29:05.0661 5628        Serenum - ok
19:29:05.0685 5628        Serial          (4b438170be2fc8e0bd35ee87a960f84f) C:\Windows\system32\DRIVERS\serial.sys
19:29:05.0711 5628        Serial - ok
19:29:05.0737 5628        sermouse        (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
19:29:05.0776 5628        sermouse - ok
19:29:05.0882 5628        ServiceLayer    (12b41d84a4d058adc60853c365dbfcca) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
19:29:05.0891 5628        ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
19:29:05.0891 5628        ServiceLayer - detected UnsignedFile.Multi.Generic (1)
19:29:05.0931 5628        SessionEnv      (a8e4a4407a09f35dccc3771af590b0c4) C:\Windows\system32\sessenv.dll
19:29:05.0954 5628        SessionEnv - ok
19:29:05.0969 5628        sffdisk        (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys
19:29:05.0998 5628        sffdisk - ok
19:29:06.0013 5628        sffp_mmc        (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys
19:29:06.0045 5628        sffp_mmc - ok
19:29:06.0077 5628        sffp_sd        (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys
19:29:06.0106 5628        sffp_sd - ok
19:29:06.0114 5628        sfloppy        (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys
19:29:06.0146 5628        sfloppy - ok
19:29:06.0182 5628        SharedAccess    (4c5aee179da7e1ee9a9ccb9da289af34) C:\Windows\System32\ipnathlp.dll
19:29:06.0219 5628        SharedAccess - ok
19:29:06.0262 5628        ShellHWDetection (56793271ecdedd350c5add305603e963) C:\Windows\System32\shsvcs.dll
19:29:06.0280 5628        ShellHWDetection - ok
19:29:06.0289 5628        SiSRaid2        (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys
19:29:06.0297 5628        SiSRaid2 - ok
19:29:06.0326 5628        SiSRaid4        (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys
19:29:06.0334 5628        SiSRaid4 - ok
19:29:06.0413 5628        SkypeUpdate    (ea396139541706b4b433641d62ea53ce) C:\Program Files (x86)\Skype\Updater\Updater.exe
19:29:06.0420 5628        SkypeUpdate - ok
19:29:06.0527 5628        slsvc          (a9a27a8e257b45a604fdad4f26fe7241) C:\Windows\system32\SLsvc.exe
19:29:06.0619 5628        slsvc - ok
19:29:06.0739 5628        SLUINotify      (fd74b4b7c2088e390a30c85a896fc3af) C:\Windows\system32\SLUINotify.dll
19:29:06.0761 5628        SLUINotify - ok
19:29:06.0823 5628        Smb            (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys
19:29:06.0850 5628        Smb - ok
19:29:06.0881 5628        SNMPTRAP        (f8f47f38909823b1af28d60b96340cff) C:\Windows\System32\snmptrap.exe
19:29:06.0897 5628        SNMPTRAP - ok
19:29:06.0935 5628        spldr          (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys
19:29:06.0943 5628        spldr - ok
19:29:06.0978 5628        Spooler        (f66ff751e7efc816d266977939ef5dc3) C:\Windows\System32\spoolsv.exe
19:29:06.0992 5628        Spooler - ok
19:29:07.0059 5628        sptd            (9ab59cf736981ed1f83c6ab5faa8ba5c) C:\Windows\System32\Drivers\sptd.sys
19:29:07.0106 5628        sptd - ok
19:29:07.0139 5628        srv            (880a57fccb571ebd063d4dd50e93e46d) C:\Windows\system32\DRIVERS\srv.sys
19:29:07.0176 5628        srv - ok
19:29:07.0219 5628        srv2            (a1ad14a6d7a37891fffeca35ebbb0730) C:\Windows\system32\DRIVERS\srv2.sys
19:29:07.0253 5628        srv2 - ok
19:29:07.0272 5628        srvnet          (4bed62f4fa4d8300973f1151f4c4d8a7) C:\Windows\system32\DRIVERS\srvnet.sys
19:29:07.0286 5628        srvnet - ok
19:29:07.0315 5628        SSDPSRV        (192c74646ec5725aef3f80d19ff75f6a) C:\Windows\System32\ssdpsrv.dll
19:29:07.0347 5628        SSDPSRV - ok
19:29:07.0391 5628        SstpSvc        (2ee3fa0308e6185ba64a9a7f2e74332b) C:\Windows\system32\sstpsvc.dll
19:29:07.0408 5628        SstpSvc - ok
19:29:07.0454 5628        stisvc          (15825c1fbfb8779992cb65087f316af5) C:\Windows\System32\wiaservc.dll
19:29:07.0470 5628        stisvc - ok
19:29:07.0498 5628        swenum          (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
19:29:07.0506 5628        swenum - ok
19:29:07.0552 5628        swprv          (6de37f4de19d4efd9c48c43addbc949a) C:\Windows\System32\swprv.dll
19:29:07.0575 5628        swprv - ok
19:29:07.0591 5628        Symc8xx        (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
19:29:07.0598 5628        Symc8xx - ok
19:29:07.0606 5628        Sym_hi          (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
19:29:07.0614 5628        Sym_hi - ok
19:29:07.0622 5628        Sym_u3          (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
19:29:07.0630 5628        Sym_u3 - ok
19:29:07.0702 5628        SysMain        (92d7a8b0f87b036f17d25885937897a6) C:\Windows\system32\sysmain.dll
19:29:07.0731 5628        SysMain - ok
19:29:07.0764 5628        TabletInputService (005ce42567f9113a3bccb3b20073b029) C:\Windows\System32\TabSvc.dll
19:29:07.0787 5628        TabletInputService - ok
19:29:07.0832 5628        TapiSrv        (cc2562b4d55e0b6a4758c65407f63b79) C:\Windows\System32\tapisrv.dll
19:29:07.0850 5628        TapiSrv - ok
19:29:07.0860 5628        TBS            (cdbe8d7c1e201b911cdc346d06617fb5) C:\Windows\System32\tbssvc.dll
19:29:07.0881 5628        TBS - ok
19:29:07.0979 5628        Tcpip          (46d448e9117464e4d3bbf36d7e3fa48e) C:\Windows\system32\drivers\tcpip.sys
19:29:08.0010 5628        Tcpip - ok
19:29:08.0094 5628        Tcpip6          (46d448e9117464e4d3bbf36d7e3fa48e) C:\Windows\system32\DRIVERS\tcpip.sys
19:29:08.0148 5628        Tcpip6 - ok
19:29:08.0190 5628        tcpipreg        (c7e72a4071ee0200e3c075dacfb2b334) C:\Windows\system32\drivers\tcpipreg.sys
19:29:08.0202 5628        tcpipreg - ok
19:29:08.0235 5628        TDPIPE          (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
19:29:08.0256 5628        TDPIPE - ok
19:29:08.0268 5628        TDTCP          (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
19:29:08.0296 5628        TDTCP - ok
19:29:08.0334 5628        tdx            (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys
19:29:08.0360 5628        tdx - ok
19:29:08.0400 5628        TermDD          (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys
19:29:08.0408 5628        TermDD - ok
19:29:08.0462 5628        TermService    (5cdd30bc217082dac71a9878d9bfd566) C:\Windows\System32\termsrv.dll
19:29:08.0512 5628        TermService - ok
19:29:08.0553 5628        Themes          (56793271ecdedd350c5add305603e963) C:\Windows\system32\shsvcs.dll
19:29:08.0564 5628        Themes - ok
19:29:08.0598 5628        THREADORDER    (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll
19:29:08.0620 5628        THREADORDER - ok
19:29:08.0694 5628        TomTomHOMEService (3199a477f0f06eede41bd55179f8eb05) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
19:29:08.0701 5628        TomTomHOMEService - ok
19:29:08.0739 5628        TrkWks          (f4689f05af472a651a7b1b7b02d200e7) C:\Windows\System32\trkwks.dll
19:29:08.0761 5628        TrkWks - ok
19:29:08.0817 5628        TrustedInstaller (66328b08ef5a9305d8ede36b93930369) C:\Windows\servicing\TrustedInstaller.exe
19:29:08.0844 5628        TrustedInstaller - ok
19:29:08.0879 5628        tssecsrv        (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
19:29:08.0908 5628        tssecsrv - ok
19:29:08.0920 5628        tunmp          (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
19:29:08.0939 5628        tunmp - ok
19:29:08.0964 5628        tunnel          (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys
19:29:08.0983 5628        tunnel - ok
19:29:08.0997 5628        uagp35          (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys
19:29:09.0005 5628        uagp35 - ok
19:29:09.0044 5628        udfs            (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys
19:29:09.0074 5628        udfs - ok
19:29:09.0110 5628        UI0Detect      (060507c4113391394478f6953a79eedc) C:\Windows\system32\UI0Detect.exe
19:29:09.0131 5628        UI0Detect - ok
19:29:09.0161 5628        uliagpkx        (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys
19:29:09.0170 5628        uliagpkx - ok
19:29:09.0185 5628        uliahci        (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys
19:29:09.0196 5628        uliahci - ok
19:29:09.0208 5628        UlSata          (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
19:29:09.0217 5628        UlSata - ok
19:29:09.0233 5628        ulsata2        (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
19:29:09.0242 5628        ulsata2 - ok
19:29:09.0255 5628        umbus          (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
19:29:09.0276 5628        umbus - ok
19:29:09.0295 5628        upnphost        (7093799ff80e9deca0680d2e3535be60) C:\Windows\System32\upnphost.dll
19:29:09.0332 5628        upnphost - ok
19:29:09.0373 5628        upperdev        (7168819f30fe9622284ea19bde7f8ab4) C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
19:29:09.0389 5628        upperdev - ok
19:29:09.0436 5628        usbaudio        (c6ba890de6e41857fbe84175519cae7d) C:\Windows\system32\drivers\usbaudio.sys
19:29:09.0464 5628        usbaudio - ok
19:29:09.0504 5628        usbbus          (5fcc71487888589a9244af54cfefab29) C:\Windows\system32\DRIVERS\lgx64bus.sys
19:29:09.0522 5628        usbbus - ok
19:29:09.0558 5628        usbccgp        (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys
19:29:09.0575 5628        usbccgp - ok
19:29:09.0606 5628        usbcir          (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys
19:29:09.0650 5628        usbcir - ok
19:29:09.0682 5628        UsbDiag        (3fb6e423f7567c92c32ea786f5fd0c69) C:\Windows\system32\DRIVERS\lgx64diag.sys
19:29:09.0699 5628        UsbDiag - ok
19:29:09.0709 5628        usbehci        (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys
19:29:09.0736 5628        usbehci - ok
19:29:09.0778 5628        usbhub          (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys
19:29:09.0796 5628        usbhub - ok
19:29:09.0845 5628        usbio          (5c4219c10b5887dff85e1d2779aed55b) C:\Windows\system32\Drivers\dsiarhwprog_x64.sys
19:29:09.0860 5628        usbio ( UnsignedFile.Multi.Generic ) - warning
19:29:09.0860 5628        usbio - detected UnsignedFile.Multi.Generic (1)
19:29:09.0895 5628        USBModem        (78d551f5b93488b4666f5fc8dd4815f3) C:\Windows\system32\DRIVERS\lgx64modem.sys
19:29:09.0902 5628        USBModem - ok
19:29:09.0955 5628        usbohci        (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys
19:29:10.0013 5628        usbohci - ok
19:29:10.0093 5628        usbprint        (28b693b6d31e7b9332c1bdcefef228c1) C:\Windows\system32\DRIVERS\usbprint.sys
19:29:10.0115 5628        usbprint - ok
19:29:10.0151 5628        usbscan        (ea0bf666868964fbe8cb10e50c97b9f1) C:\Windows\system32\DRIVERS\usbscan.sys
19:29:10.0177 5628        usbscan - ok
19:29:10.0216 5628        usbser          (f7386007fb19e7685fc7b298560aa81f) C:\Windows\system32\DRIVERS\usbser.sys
19:29:10.0240 5628        usbser - ok
19:29:10.0280 5628        UsbserFilt      (66c25cb20b2974e0c0cfdab49fb72a02) C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys
19:29:10.0305 5628        UsbserFilt - ok
19:29:10.0338 5628        USBSTOR        (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:29:10.0361 5628        USBSTOR - ok
19:29:10.0396 5628        usbuhci        (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys
19:29:10.0411 5628        usbuhci - ok
19:29:10.0464 5628        usb_rndisx      (1e36bb1a3c5aaf2aa9fa9a126df8c16c) C:\Windows\system32\DRIVERS\usb8023x.sys
19:29:10.0492 5628        usb_rndisx - ok
19:29:10.0534 5628        UxSms          (d76e231e4850bb3f88a3d9a78df191e3) C:\Windows\System32\uxsms.dll
19:29:10.0551 5628        UxSms - ok
19:29:10.0592 5628        vds            (294945381dfa7ce58cecf0a9896af327) C:\Windows\System32\vds.exe
19:29:10.0614 5628        vds - ok
19:29:10.0628 5628        vga            (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys
19:29:10.0659 5628        vga - ok
19:29:10.0671 5628        VgaSave        (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
19:29:10.0691 5628        VgaSave - ok
19:29:10.0724 5628        viaide          (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys
19:29:10.0731 5628        viaide - ok
19:29:10.0768 5628        volmgr          (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys
19:29:10.0776 5628        volmgr - ok
19:29:10.0819 5628        volmgrx        (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys
19:29:10.0833 5628        volmgrx - ok
19:29:10.0879 5628        volsnap        (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys
19:29:10.0890 5628        volsnap - ok
19:29:10.0906 5628        vsmraid        (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys
19:29:10.0916 5628        vsmraid - ok
19:29:10.0985 5628        VSS            (b75232dad33bfd95bf6f0a3e6bff51e1) C:\Windows\system32\vssvc.exe
19:29:11.0042 5628        VSS - ok
19:29:11.0168 5628        W32Time        (f14a7de2ea41883e250892e1e5230a9a) C:\Windows\system32\w32time.dll
19:29:11.0202 5628        W32Time - ok
19:29:11.0254 5628        WacomPen        (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
19:29:11.0298 5628        WacomPen - ok
19:29:11.0334 5628        Wanarp          (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
19:29:11.0361 5628        Wanarp - ok
19:29:11.0363 5628        Wanarpv6        (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
19:29:11.0379 5628        Wanarpv6 - ok
19:29:11.0436 5628        wcncsvc        (b4e4c37d0aa6100090a53213ee2bf1c1) C:\Windows\System32\wcncsvc.dll
19:29:11.0467 5628        wcncsvc - ok
19:29:11.0497 5628        WcsPlugInService (ea4b369560e986f19d93f45a881484ac) C:\Windows\System32\WcsPlugInService.dll
19:29:11.0515 5628        WcsPlugInService - ok
19:29:11.0525 5628        Wd              (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys
19:29:11.0533 5628        Wd - ok
19:29:11.0585 5628        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
19:29:11.0603 5628        Wdf01000 - ok
19:29:11.0613 5628        WdiServiceHost  (c5efda73ebfca8b02a094898de0a9276) C:\Windows\system32\wdi.dll
19:29:11.0646 5628        WdiServiceHost - ok
19:29:11.0648 5628        WdiSystemHost  (c5efda73ebfca8b02a094898de0a9276) C:\Windows\system32\wdi.dll
19:29:11.0670 5628        WdiSystemHost - ok
19:29:11.0718 5628        WebClient      (3e6d05381cf35f75ebb055544a8ed9ac) C:\Windows\System32\webclnt.dll
19:29:11.0729 5628        WebClient - ok
19:29:11.0765 5628        Wecsvc          (8d40bc587993f876658bf9fb0f7d3462) C:\Windows\system32\wecsvc.dll
19:29:11.0786 5628        Wecsvc - ok
19:29:11.0818 5628        wercplsupport  (9c980351d7e96288ea0c23ae232bd065) C:\Windows\System32\wercplsupport.dll
19:29:11.0835 5628        wercplsupport - ok
19:29:11.0846 5628        WerSvc          (66b9ecebc46683f47edc06333c075fef) C:\Windows\System32\WerSvc.dll
19:29:11.0868 5628        WerSvc - ok
19:29:11.0901 5628        WinDefend - ok
19:29:11.0904 5628        WinHttpAutoProxySvc - ok
19:29:11.0979 5628        Winmgmt        (d2e7296ed1bd26d8db2799770c077a02) C:\Windows\system32\wbem\WMIsvc.dll
19:29:11.0995 5628        Winmgmt - ok
19:29:12.0081 5628        WinRM          (6cbb0c68f13b9c2ec1b16f5fa5e7c869) C:\Windows\system32\WsmSvc.dll
19:29:12.0136 5628        WinRM - ok
19:29:12.0264 5628        Wlansvc        (ec339c8115e91baed835957e9a677f16) C:\Windows\System32\wlansvc.dll
19:29:12.0343 5628        Wlansvc - ok
19:29:12.0411 5628        WmiAcpi        (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\drivers\wmiacpi.sys
19:29:12.0434 5628        WmiAcpi - ok
19:29:12.0519 5628        wmiApSrv        (21fa389e65a852698b6a1341f36ee02d) C:\Windows\system32\wbem\WmiApSrv.exe
19:29:12.0536 5628        wmiApSrv - ok
19:29:12.0576 5628        WMPNetworkSvc - ok
19:29:12.0617 5628        WPCSvc          (cbc156c913f099e6680d1df9307db7a8) C:\Windows\System32\wpcsvc.dll
19:29:12.0633 5628        WPCSvc - ok
19:29:12.0665 5628        WPDBusEnum      (490a18b4e4d53dc10879deaa8e8b70d9) C:\Windows\system32\wpdbusenum.dll
19:29:12.0689 5628        WPDBusEnum - ok
19:29:12.0727 5628        WpdUsb          (5e2401b3fc1089c90e081291357371a9) C:\Windows\system32\DRIVERS\wpdusb.sys
19:29:12.0744 5628        WpdUsb - ok
19:29:12.0916 5628        WPFFontCache_v0400 (991e2c2cf3bc204c2bb2ee1476149e4e) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
19:29:12.0938 5628        WPFFontCache_v0400 - ok
19:29:12.0973 5628        ws2ifsl        (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
19:29:13.0003 5628        ws2ifsl - ok
19:29:13.0042 5628        wscsvc          (9ea3e6d0ef7a5c2b9181961052a4b01a) C:\Windows\System32\wscsvc.dll
19:29:13.0052 5628        wscsvc - ok
19:29:13.0054 5628        WSearch - ok
19:29:13.0144 5628        wuauserv        (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
19:29:13.0196 5628        wuauserv - ok
19:29:13.0354 5628        WUDFRd          (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys
19:29:13.0376 5628        WUDFRd - ok
19:29:13.0409 5628        wudfsvc        (6cbd51ff913c851d56ed9dc7f2a27dde) C:\Windows\System32\WUDFSvc.dll
19:29:13.0432 5628        wudfsvc - ok
19:29:13.0480 5628        yukonx64        (2ae06b41b36549fabf0886b2af89a599) C:\Windows\system32\DRIVERS\yk60x64.sys
19:29:13.0513 5628        yukonx64 - ok
19:29:13.0537 5628        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
19:29:13.0703 5628        \Device\Harddisk0\DR0 - ok
19:29:13.0704 5628        Boot (0x1200)  (2b6a0507950261eed5cb2e60e63274bb) \Device\Harddisk0\DR0\Partition0
19:29:13.0705 5628        \Device\Harddisk0\DR0\Partition0 - ok
19:29:13.0706 5628        ============================================================
19:29:13.0706 5628        Scan finished
19:29:13.0706 5628        ============================================================
19:29:13.0711 1092        Detected object count: 7
19:29:13.0711 1092        Actual detected object count: 7
19:30:03.0459 1092        IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
19:30:03.0459 1092        IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:30:03.0459 1092        LGDDCDevice ( UnsignedFile.Multi.Generic ) - skipped by user
19:30:03.0459 1092        LGDDCDevice ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:30:03.0460 1092        LGII2CDevice ( UnsignedFile.Multi.Generic ) - skipped by user
19:30:03.0460 1092        LGII2CDevice ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:30:03.0461 1092        PassThru Service ( UnsignedFile.Multi.Generic ) - skipped by user
19:30:03.0461 1092        PassThru Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:30:03.0462 1092        SearchAnonymizer ( UnsignedFile.Multi.Generic ) - skipped by user
19:30:03.0462 1092        SearchAnonymizer ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:30:03.0462 1092        ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
19:30:03.0462 1092        ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:30:03.0463 1092        usbio ( UnsignedFile.Multi.Generic ) - skipped by user
19:30:03.0463 1092        usbio ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:30:08.0519 3844        ============================================================
19:30:08.0519 3844        Scan started
19:30:08.0519 3844        Mode: Manual; SigCheck; TDLFS;
19:30:08.0519 3844        ============================================================
19:30:08.0748 3844        ACPI            (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys
19:30:08.0765 3844        ACPI - ok
19:30:08.0811 3844        ADIHdAudAddService (4a30fa79f8253134d398251db614e3c9) C:\Windows\system32\drivers\ADIHdAud.sys
19:30:08.0823 3844        ADIHdAudAddService - ok
19:30:08.0904 3844        AdobeARMservice (11a52cf7b265631deeb24c6149309eff) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
19:30:08.0911 3844        AdobeARMservice - ok
19:30:09.0019 3844        AdobeFlashPlayerUpdateSvc (f19c98ad81d2c0e1bbfd8153d2c80ee8) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
19:30:09.0027 3844        AdobeFlashPlayerUpdateSvc - ok
19:30:09.0131 3844        adp94xx        (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
19:30:09.0145 3844        adp94xx - ok
19:30:09.0163 3844        adpahci        (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
19:30:09.0175 3844        adpahci - ok
19:30:09.0195 3844        adpu160m        (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
19:30:09.0203 3844        adpu160m - ok
19:30:09.0220 3844        adpu320        (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
19:30:09.0230 3844        adpu320 - ok
19:30:09.0262 3844        AEADIFilters    (28c0b0a6cb61bdd1fef877d4d0f69fbf) C:\Windows\system32\AEADISRV.EXE
19:30:09.0269 3844        AEADIFilters - ok
19:30:09.0302 3844        AeLookupSvc    (0f421175574bfe0bf2f4d8e910a253bb) C:\Windows\System32\aelupsvc.dll
19:30:09.0318 3844        AeLookupSvc - ok
19:30:09.0364 3844        AFD            (c4f6ce6087760ad70960c9eb130e7943) C:\Windows\system32\drivers\afd.sys
19:30:09.0376 3844        AFD - ok
19:30:09.0406 3844        agp440          (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
19:30:09.0414 3844        agp440 - ok
19:30:09.0449 3844        aic78xx        (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
19:30:09.0457 3844        aic78xx - ok
19:30:09.0467 3844        ALG            (5922f4f59b7868f3d74bbbbeb7b825a3) C:\Windows\System32\alg.exe
19:30:09.0488 3844        ALG - ok
19:30:09.0497 3844        aliide          (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys
19:30:09.0506 3844        aliide - ok
19:30:09.0546 3844        AMD External Events Utility (20c8a3e435a47f0408a1ea674afa6194) C:\Windows\system32\atiesrxx.exe
19:30:09.0558 3844        AMD External Events Utility - ok
19:30:09.0567 3844        amdide          (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys
19:30:09.0574 3844        amdide - ok
19:30:09.0584 3844        AmdK8          (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
19:30:09.0606 3844        AmdK8 - ok
19:30:09.0915 3844        amdkmdag        (0b45c18b0f3ee996d25baa4e74884b83) C:\Windows\system32\DRIVERS\atikmdag.sys
19:30:10.0067 3844        amdkmdag - ok
19:30:10.0238 3844        amdkmdap        (0e57258e5cc4cc7a9a9a877afdf0cec6) C:\Windows\system32\DRIVERS\atikmpag.sys
19:30:10.0251 3844        amdkmdap - ok
19:30:10.0342 3844        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
19:30:10.0349 3844        AntiVirSchedulerService - ok
19:30:10.0375 3844        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
19:30:10.0382 3844        AntiVirService - ok
19:30:10.0410 3844        Appinfo        (9c37b3fd5615477cb9a0cd116cf43f5c) C:\Windows\System32\appinfo.dll
19:30:10.0418 3844        Appinfo - ok
19:30:10.0451 3844        arc            (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
19:30:10.0460 3844        arc - ok
19:30:10.0468 3844        arcsas          (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
19:30:10.0476 3844        arcsas - ok
19:30:10.0492 3844        AsyncMac        (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
19:30:10.0514 3844        AsyncMac - ok
19:30:10.0555 3844        atapi          (e68d9b3a3905619732f7fe039466a623) C:\Windows\system32\drivers\atapi.sys
19:30:10.0563 3844        atapi - ok
19:30:10.0606 3844        AtiHDAudioService (917692cdf8e1ce00d9752fa40615338b) C:\Windows\system32\drivers\AtihdLH6.sys
19:30:10.0612 3844        AtiHDAudioService - ok
19:30:10.0614 3844        AtiHdmiService - ok
19:30:10.0933 3844        atikmdag        (0b45c18b0f3ee996d25baa4e74884b83) C:\Windows\system32\DRIVERS\atikmdag.sys
19:30:11.0074 3844        atikmdag - ok
19:30:11.0213 3844        AudioEndpointBuilder (79318c744693ec983d20e9337a2f8196) C:\Windows\System32\Audiosrv.dll
19:30:11.0233 3844        AudioEndpointBuilder - ok
19:30:11.0237 3844        AudioSrv        (79318c744693ec983d20e9337a2f8196) C:\Windows\System32\Audiosrv.dll
19:30:11.0257 3844        AudioSrv - ok
19:30:11.0319 3844        avgntflt        (26e38b5a58c6c55fafbc563eeddb0867) C:\Windows\system32\DRIVERS\avgntflt.sys
19:30:11.0326 3844        avgntflt - ok
19:30:11.0339 3844        avipbb          (9d1f00beff84cbbf46d7f052bc7e0565) C:\Windows\system32\DRIVERS\avipbb.sys
19:30:11.0347 3844        avipbb - ok
19:30:11.0359 3844        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
19:30:11.0366 3844        avkmgr - ok
19:30:11.0412 3844        BFE            (ffb96c2589ffa60473ead78b39fbde29) C:\Windows\System32\bfe.dll
19:30:11.0432 3844        BFE - ok
19:30:11.0468 3844        BITS            (6d316f4859634071cc25c4fd4589ad2c) C:\Windows\System32\qmgr.dll
19:30:11.0495 3844        BITS - ok
19:30:11.0520 3844        blbdrive        (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
19:30:11.0541 3844        blbdrive - ok
19:30:11.0568 3844        bowser          (2348447a80920b2493a9b582a23e81e1) C:\Windows\system32\DRIVERS\bowser.sys
19:30:11.0576 3844        bowser - ok
19:30:11.0592 3844        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
19:30:11.0607 3844        BrFiltLo - ok
19:30:11.0622 3844        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
19:30:11.0637 3844        BrFiltUp - ok
19:30:11.0672 3844        Browser        (a1b39de453433b115b4ea69ee0343816) C:\Windows\System32\browser.dll
19:30:11.0693 3844        Browser - ok
19:30:11.0703 3844        Brserid        (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
19:30:11.0735 3844        Brserid - ok
19:30:11.0746 3844        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
19:30:11.0778 3844        BrSerWdm - ok
19:30:11.0792 3844        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
19:30:11.0824 3844        BrUsbMdm - ok
19:30:11.0859 3844        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
19:30:11.0891 3844        BrUsbSer - ok
19:30:11.0902 3844        BTHMODEM        (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
19:30:11.0935 3844        BTHMODEM - ok
19:30:11.0949 3844        cdfs            (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
19:30:11.0971 3844        cdfs - ok
19:30:12.0008 3844        cdrom          (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys
19:30:12.0024 3844        cdrom - ok
19:30:12.0060 3844        CertPropSvc    (5a268127633c7ee2a7fb87f39d748d56) C:\Windows\System32\certprop.dll
19:30:12.0075 3844        CertPropSvc - ok
19:30:12.0092 3844        circlass        (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys
19:30:12.0114 3844        circlass - ok
19:30:12.0159 3844        CLFS            (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys
19:30:12.0172 3844        CLFS - ok
19:30:12.0236 3844        clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:30:12.0243 3844        clr_optimization_v2.0.50727_32 - ok
19:30:12.0310 3844        clr_optimization_v2.0.50727_64 (ce07a466201096f021cd09d631b21540) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
19:30:12.0317 3844        clr_optimization_v2.0.50727_64 - ok
19:30:12.0382 3844        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:30:12.0389 3844        clr_optimization_v4.0.30319_32 - ok
19:30:12.0420 3844        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
19:30:12.0427 3844        clr_optimization_v4.0.30319_64 - ok
19:30:12.0465 3844        cmdide          (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys
19:30:12.0472 3844        cmdide - ok
19:30:12.0483 3844        Compbatt        (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\drivers\compbatt.sys
19:30:12.0491 3844        Compbatt - ok
19:30:12.0493 3844        COMSysApp - ok
19:30:12.0556 3844        cpuz132 - ok
19:30:12.0566 3844        crcdisk        (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
19:30:12.0574 3844        crcdisk - ok
19:30:12.0614 3844        CryptSvc        (62740b9d2a137e8ced41a9e4239a7a31) C:\Windows\system32\cryptsvc.dll
19:30:12.0624 3844        CryptSvc - ok
19:30:12.0673 3844        DcomLaunch      (cf8b9a3a5e7dc57724a89d0c3e8cf9ef) C:\Windows\system32\rpcss.dll
19:30:12.0697 3844        DcomLaunch - ok
19:30:12.0737 3844        DfsC            (8b722ba35205c71e7951cdc4cdbade19) C:\Windows\system32\Drivers\dfsc.sys
19:30:12.0746 3844        DfsC - ok
19:30:12.0867 3844        DFSR            (c647f468f7de343df8c143655c5557d4) C:\Windows\system32\DFSR.exe
19:30:12.0913 3844        DFSR - ok
19:30:13.0046 3844        Dhcp            (3ed0321127ce70acdaabbf77e157c2a7) C:\Windows\System32\dhcpcsvc.dll
19:30:13.0063 3844        Dhcp - ok
19:30:13.0124 3844        disk            (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys
19:30:13.0133 3844        disk - ok
19:30:13.0169 3844        Dnscache        (06230f1b721494a6df8d47fd395bb1b0) C:\Windows\System32\dnsrslvr.dll
19:30:13.0178 3844        Dnscache - ok
19:30:13.0216 3844        dot3svc        (1a7156dd1e850e9914e5e991e3225b94) C:\Windows\System32\dot3svc.dll
19:30:13.0234 3844        dot3svc - ok
19:30:13.0267 3844        DPS            (1583b39790db3eaec7edb0cb0140c708) C:\Windows\system32\dps.dll
19:30:13.0290 3844        DPS - ok
19:30:13.0320 3844        drmkaud        (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
19:30:13.0336 3844        drmkaud - ok
19:30:13.0390 3844        DXGKrnl        (b8e554e502d5123bc111f99d6a2181b4) C:\Windows\System32\drivers\dxgkrnl.sys
19:30:13.0410 3844        DXGKrnl - ok
19:30:13.0445 3844        E1G60          (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
19:30:13.0466 3844        E1G60 - ok
19:30:13.0470 3844        EagleX64 - ok
19:30:13.0480 3844        EapHost        (c2303883fd9be49dc36a6400643002ea) C:\Windows\System32\eapsvc.dll
19:30:13.0496 3844        EapHost - ok
19:30:13.0532 3844        Ecache          (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys
19:30:13.0542 3844        Ecache - ok
19:30:13.0585 3844        ehRecvr        (14ce384d2e27b64c256bda4dc39c312d) C:\Windows\ehome\ehRecvr.exe
19:30:13.0596 3844        ehRecvr - ok
19:30:13.0615 3844        ehSched        (b93159c1313d66fdfbbe876f5189cd52) C:\Windows\ehome\ehsched.exe
19:30:13.0624 3844        ehSched - ok
19:30:13.0633 3844        ehstart        (f5ee2527d74449868e3c3227a59bcd28) C:\Windows\ehome\ehstart.dll
19:30:13.0641 3844        ehstart - ok
19:30:13.0664 3844        elxstor        (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
19:30:13.0676 3844        elxstor - ok
19:30:13.0725 3844        EMDMgmt        (a9b18b63a4fd6baab83326706d857fab) C:\Windows\system32\emdmgmt.dll
19:30:13.0738 3844        EMDMgmt - ok
19:30:13.0777 3844        ErrDev          (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys
19:30:13.0797 3844        ErrDev - ok
19:30:13.0847 3844        EventSystem    (e12f22b73f153dece721cd45ec05b4af) C:\Windows\system32\es.dll
19:30:13.0866 3844        EventSystem - ok
19:30:13.0902 3844        exfat          (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys
19:30:13.0912 3844        exfat - ok
19:30:13.0952 3844        fastfat        (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys
19:30:13.0968 3844        fastfat - ok
19:30:13.0976 3844        fdc            (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
19:30:13.0997 3844        fdc - ok
19:30:14.0029 3844        fdPHost        (bb9267acacd8b7533dd936c34a0cba5e) C:\Windows\system32\fdPHost.dll
19:30:14.0050 3844        fdPHost - ok
19:30:14.0055 3844        FDResPub        (300c80931eabbe1db7591c516efe8d0f) C:\Windows\system32\fdrespub.dll
19:30:14.0088 3844        FDResPub - ok
19:30:14.0118 3844        FileInfo        (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
19:30:14.0126 3844        FileInfo - ok
19:30:14.0141 3844        Filetrace      (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
19:30:14.0162 3844        Filetrace - ok
19:30:14.0172 3844        flpydisk        (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
19:30:14.0193 3844        flpydisk - ok
19:30:14.0239 3844        FltMgr          (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys
19:30:14.0249 3844        FltMgr - ok
19:30:14.0312 3844        FontCache      (be1c5bd1ca7ed015bc6fa1ae67e592c8) C:\Windows\system32\FntCache.dll
19:30:14.0333 3844        FontCache - ok
19:30:14.0376 3844        FontCache3.0.0.0 (bc5b0be5af3510b0fd8c140ee42c6d3e) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
19:30:14.0383 3844        FontCache3.0.0.0 - ok
19:30:14.0466 3844        FreemakeVideoCapture - ok
19:30:14.0509 3844        Fs_Rec          (5779b86cd8b32519fbecb136394d946a) C:\Windows\system32\drivers\Fs_Rec.sys
19:30:14.0517 3844        Fs_Rec - ok
19:30:14.0545 3844        gagp30kx        (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
19:30:14.0553 3844        gagp30kx - ok
19:30:14.0588 3844        GEARAspiWDM    (58e581a98a85587e9f5a297d4ad44cc0) C:\Windows\system32\Drivers\GEARAspiWDM.sys
19:30:14.0594 3844        GEARAspiWDM - ok
19:30:14.0642 3844        gpsvc          (a0e1b575ba8f504968cd40c0faeb2384) C:\Windows\System32\gpsvc.dll
19:30:14.0665 3844        gpsvc - ok
19:30:14.0700 3844        HdAudAddService (68e732382b32417ff61fd663259b4b09) C:\Windows\system32\drivers\HdAudio.sys
19:30:14.0710 3844        HdAudAddService - ok
19:30:14.0763 3844        HDAudBus        (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys
19:30:14.0789 3844        HDAudBus - ok
19:30:14.0803 3844        HidBth          (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
19:30:14.0835 3844        HidBth - ok
19:30:14.0843 3844        HidIr          (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
19:30:14.0875 3844        HidIr - ok
19:30:14.0895 3844        hidserv        (59361d38a297755d46a540e450202b2a) C:\Windows\system32\hidserv.dll
19:30:14.0912 3844        hidserv - ok
19:30:14.0933 3844        HidUsb          (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys
19:30:14.0949 3844        HidUsb - ok
19:30:14.0981 3844        hkmsvc          (b12f367ea39c0795fd57e31242ce1a5a) C:\Windows\system32\kmsvc.dll
19:30:15.0004 3844        hkmsvc - ok
19:30:15.0035 3844        HpCISSs        (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
19:30:15.0043 3844        HpCISSs - ok
19:30:15.0076 3844        HTCAND64        (894a75a3d6bfd97d73bf60d3022b567a) C:\Windows\system32\Drivers\ANDROIDUSB.sys
19:30:15.0085 3844        HTCAND64 - ok
19:30:15.0114 3844        htcnprot        (4f6c3122817049997cd696d4a38bfacb) C:\Windows\system32\DRIVERS\htcnprot.sys
19:30:15.0121 3844        htcnprot - ok
19:30:15.0167 3844        HTTP            (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys
19:30:15.0182 3844        HTTP - ok
19:30:15.0213 3844        i2omp          (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
19:30:15.0221 3844        i2omp - ok
19:30:15.0234 3844        i8042prt        (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
19:30:15.0249 3844        i8042prt - ok
19:30:15.0269 3844        iaStorV        (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
19:30:15.0280 3844        iaStorV - ok
19:30:15.0373 3844        IDriverT        (6f95324909b502e2651442c1548ab12f) C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
19:30:15.0375 3844        IDriverT ( UnsignedFile.Multi.Generic ) - warning
19:30:15.0375 3844        IDriverT - detected UnsignedFile.Multi.Generic (1)
19:30:15.0493 3844        idsvc          (749f5f8cedca70f2a512945325fc489d) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
19:30:15.0512 3844        idsvc - ok
19:30:15.0526 3844        iirsp          (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
19:30:15.0534 3844        iirsp - ok
19:30:15.0573 3844        IKEEXT          (0c9ea6e654e7b0471741e343a6c671af) C:\Windows\System32\ikeext.dll
19:30:15.0594 3844        IKEEXT - ok
19:30:15.0626 3844        intelide        (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys
19:30:15.0634 3844        intelide - ok
19:30:15.0649 3844        intelppm        (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
19:30:15.0671 3844        intelppm - ok
19:30:15.0700 3844        IPBusEnum      (5624bc1bc5eeb49c0ab76a8114f05ea3) C:\Windows\system32\ipbusenum.dll
19:30:15.0721 3844        IPBusEnum - ok
19:30:15.0760 3844        IpFilterDriver  (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:30:15.0776 3844        IpFilterDriver - ok
19:30:15.0936 3844        iphlpsvc        (bf0dbfa9792c5c14fa00f61c75116c1b) C:\Windows\System32\iphlpsvc.dll
19:30:15.0945 3844        iphlpsvc - ok
19:30:15.0947 3844        IpInIp - ok
19:30:15.0964 3844        IPMIDRV        (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
19:30:15.0985 3844        IPMIDRV - ok
19:30:16.0000 3844        IPNAT          (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
19:30:16.0022 3844        IPNAT - ok
19:30:16.0050 3844        IRENUM          (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
19:30:16.0071 3844        IRENUM - ok
19:30:16.0085 3844        isapnp          (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
19:30:16.0093 3844        isapnp - ok
19:30:16.0133 3844        iScsiPrt        (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys
19:30:16.0143 3844        iScsiPrt - ok
19:30:16.0156 3844        iteatapi        (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
19:30:16.0163 3844        iteatapi - ok
19:30:16.0179 3844        iteraid        (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
19:30:16.0186 3844        iteraid - ok
19:30:16.0194 3844        kbdclass        (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys


maeusuruh 11.08.2012 18:42

Teil 2:

Code:

19:30:16.0202 3844        kbdclass - ok
19:30:16.0228 3844        kbdhid          (dbdf75d51464fbc47d0104ec3d572c05) C:\Windows\system32\DRIVERS\kbdhid.sys
19:30:16.0243 3844        kbdhid - ok
19:30:16.0261 3844        KeyIso          (260bf9c43ee12c6898a9f5aab0fb0e5d) C:\Windows\system32\lsass.exe
19:30:16.0270 3844        KeyIso - ok
19:30:16.0306 3844        KSecDD          (88956ad9fa510848ad176777a6c6c1f5) C:\Windows\system32\Drivers\ksecdd.sys
19:30:16.0320 3844        KSecDD - ok
19:30:16.0335 3844        ksthunk        (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
19:30:16.0357 3844        ksthunk - ok
19:30:16.0388 3844        KtmRm          (1faf6926f3416d3da05c5b265491bdae) C:\Windows\system32\msdtckrm.dll
19:30:16.0414 3844        KtmRm - ok
19:30:16.0447 3844        L8042Kbd        (f33c5d79d3273530e1892a0922283a7b) C:\Windows\system32\DRIVERS\L8042Kbd.sys
19:30:16.0453 3844        L8042Kbd - ok
19:30:16.0490 3844        LanmanServer    (50c7a3cb427e9bb5ed0708a669956ab5) C:\Windows\system32\srvsvc.dll
19:30:16.0499 3844        LanmanServer - ok
19:30:16.0531 3844        LanmanWorkstation (caf86fc1388be1e470f1a7b43e348adb) C:\Windows\System32\wkssvc.dll
19:30:16.0541 3844        LanmanWorkstation - ok
19:30:16.0593 3844        LGDDCDevice    (094c41ab6fbb0ec205989e92e257aebf) C:\Program Files (x86)\LG Soft India\forteManager\bin\I2CDriver.sys
19:30:16.0595 3844        LGDDCDevice ( UnsignedFile.Multi.Generic ) - warning
19:30:16.0595 3844        LGDDCDevice - detected UnsignedFile.Multi.Generic (1)
19:30:16.0601 3844        LGII2CDevice    (8409a28e641136caf114120c7387d072) C:\Program Files (x86)\LG Soft India\forteManager\bin\PII2CDriver.sys
19:30:16.0603 3844        LGII2CDevice ( UnsignedFile.Multi.Generic ) - warning
19:30:16.0603 3844        LGII2CDevice - detected UnsignedFile.Multi.Generic (1)
19:30:16.0614 3844        LHidFilt        (b6552d382ff070b4ed34cbd6737277c0) C:\Windows\system32\DRIVERS\LHidFilt.Sys
19:30:16.0620 3844        LHidFilt - ok
19:30:16.0648 3844        lltdio          (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
19:30:16.0669 3844        lltdio - ok
19:30:16.0704 3844        lltdsvc        (961ccbd0b1ccb5675d64976fae37d092) C:\Windows\System32\lltdsvc.dll
19:30:16.0727 3844        lltdsvc - ok
19:30:16.0737 3844        lmhosts        (a47f8080cacc23c91fe823ad19aa5612) C:\Windows\System32\lmhsvc.dll
19:30:16.0759 3844        lmhosts - ok
19:30:16.0796 3844        LMouFilt        (73c1f563ab73d459dffe682d66476558) C:\Windows\system32\DRIVERS\LMouFilt.Sys
19:30:16.0802 3844        LMouFilt - ok
19:30:16.0815 3844        LSI_FC          (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
19:30:16.0825 3844        LSI_FC - ok
19:30:16.0838 3844        LSI_SAS        (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
19:30:16.0847 3844        LSI_SAS - ok
19:30:16.0861 3844        LSI_SCSI        (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
19:30:16.0870 3844        LSI_SCSI - ok
19:30:16.0885 3844        luafv          (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
19:30:16.0907 3844        luafv - ok
19:30:16.0921 3844        MBAMProtector  (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys
19:30:16.0929 3844        MBAMProtector - ok
19:30:16.0979 3844        MBAMService    (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
19:30:16.0993 3844        MBAMService - ok
19:30:17.0029 3844        Mcx2Svc        (76a58df02bd4ea29f189b82d0bef17f8) C:\Windows\system32\Mcx2Svc.dll
19:30:17.0037 3844        Mcx2Svc - ok
19:30:17.0062 3844        megasas        (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
19:30:17.0070 3844        megasas - ok
19:30:17.0094 3844        MegaSR          (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
19:30:17.0106 3844        MegaSR - ok
19:30:17.0141 3844        MMCSS          (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll
19:30:17.0162 3844        MMCSS - ok
19:30:17.0171 3844        Modem          (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
19:30:17.0191 3844        Modem - ok
19:30:17.0200 3844        monitor        (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
19:30:17.0221 3844        monitor - ok
19:30:17.0233 3844        mouclass        (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
19:30:17.0241 3844        mouclass - ok
19:30:17.0252 3844        mouhid          (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
19:30:17.0272 3844        mouhid - ok
19:30:17.0284 3844        MountMgr        (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
19:30:17.0292 3844        MountMgr - ok
19:30:17.0326 3844        mpio            (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
19:30:17.0334 3844        mpio - ok
19:30:17.0345 3844        mpsdrv          (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
19:30:17.0362 3844        mpsdrv - ok
19:30:17.0414 3844        MpsSvc          (897e3baf68ba406a61682ae39c83900c) C:\Windows\system32\mpssvc.dll
19:30:17.0436 3844        MpsSvc - ok
19:30:17.0448 3844        Mraid35x        (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
19:30:17.0455 3844        Mraid35x - ok
19:30:17.0460 3844        MRxDAV          (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys
19:30:17.0469 3844        MRxDAV - ok
19:30:17.0506 3844        mrxsmb          (1485811b320ff8c7edad1caebb1c6c2b) C:\Windows\system32\DRIVERS\mrxsmb.sys
19:30:17.0515 3844        mrxsmb - ok
19:30:17.0556 3844        mrxsmb10        (3b929a60c833fc615fd97fba82bc7632) C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:30:17.0565 3844        mrxsmb10 - ok
19:30:17.0569 3844        mrxsmb20        (c64ab3e1f53b4f5b5bb6d796b2d7bec3) C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:30:17.0577 3844        mrxsmb20 - ok
19:30:17.0611 3844        msahci          (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys
19:30:17.0619 3844        msahci - ok
19:30:17.0634 3844        msdsm          (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
19:30:17.0643 3844        msdsm - ok
19:30:17.0676 3844        MSDTC          (7ec02ce772f068ed0beafa3da341a9bc) C:\Windows\System32\msdtc.exe
19:30:17.0698 3844        MSDTC - ok
19:30:17.0708 3844        Msfs            (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
19:30:17.0728 3844        Msfs - ok
19:30:17.0745 3844        msisadrv        (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
19:30:17.0753 3844        msisadrv - ok
19:30:17.0790 3844        MSiSCSI        (366b0c1f4478b519c181e37d43dcda32) C:\Windows\system32\iscsiexe.dll
19:30:17.0812 3844        MSiSCSI - ok
19:30:17.0814 3844        msiserver - ok
19:30:17.0826 3844        MSKSSRV        (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
19:30:17.0846 3844        MSKSSRV - ok
19:30:17.0854 3844        MSPCLOCK        (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
19:30:17.0874 3844        MSPCLOCK - ok
19:30:17.0910 3844        MSPQM          (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
19:30:17.0932 3844        MSPQM - ok
19:30:17.0975 3844        MsRPC          (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys
19:30:17.0986 3844        MsRPC - ok
19:30:17.0996 3844        mssmbios        (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
19:30:18.0004 3844        mssmbios - ok
19:30:18.0006 3844        MSTEE          (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
19:30:18.0027 3844        MSTEE - ok
19:30:18.0053 3844        MTsensor        (6936198f2cc25b39cf5262436c80df46) C:\Windows\system32\DRIVERS\ASACPI.sys
19:30:18.0059 3844        MTsensor - ok
19:30:18.0066 3844        Mup            (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys
19:30:18.0074 3844        Mup - ok
19:30:18.0126 3844        napagent        (a5b10c845e7538c60c0f5d87a57cb3f5) C:\Windows\system32\qagentRT.dll
19:30:18.0146 3844        napagent - ok
19:30:18.0186 3844        NativeWifiP    (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys
19:30:18.0196 3844        NativeWifiP - ok
19:30:18.0246 3844        NDIS            (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys
19:30:18.0264 3844        NDIS - ok
19:30:18.0295 3844        NdisTapi        (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
19:30:18.0310 3844        NdisTapi - ok
19:30:18.0321 3844        Ndisuio        (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
19:30:18.0342 3844        Ndisuio - ok
19:30:18.0379 3844        NdisWan        (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys
19:30:18.0395 3844        NdisWan - ok
19:30:18.0407 3844        NDProxy        (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
19:30:18.0422 3844        NDProxy - ok
19:30:18.0535 3844        Nero BackItUp Scheduler 3 (c5052fb77aa42ed440f9f6b4e37145a9) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
19:30:18.0553 3844        Nero BackItUp Scheduler 3 - ok
19:30:18.0581 3844        NetBIOS        (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
19:30:18.0603 3844        NetBIOS - ok
19:30:18.0650 3844        netbt          (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys
19:30:18.0667 3844        netbt - ok
19:30:18.0702 3844        Netlogon        (260bf9c43ee12c6898a9f5aab0fb0e5d) C:\Windows\system32\lsass.exe
19:30:18.0711 3844        Netlogon - ok
19:30:18.0752 3844        Netman          (9b63b29defc0f3115a559d2597bf5d75) C:\Windows\System32\netman.dll
19:30:18.0778 3844        Netman - ok
19:30:18.0797 3844        netprofm        (7846d0136cc2b264926a73047ba7688a) C:\Windows\System32\netprofm.dll
19:30:18.0821 3844        netprofm - ok
19:30:18.0934 3844        NetTcpPortSharing (74751dda198165947fd7454d83f49825) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
19:30:18.0941 3844        NetTcpPortSharing - ok
19:30:18.0962 3844        nfrd960        (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
19:30:18.0970 3844        nfrd960 - ok
19:30:18.0988 3844        NlaSvc          (f145bf4c4668e7e312069f81ef847cfc) C:\Windows\System32\nlasvc.dll
19:30:19.0010 3844        NlaSvc - ok
19:30:19.0108 3844        NMIndexingService (74149bcf0307bb76d68c0f8912df731c) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
19:30:19.0119 3844        NMIndexingService - ok
19:30:19.0148 3844        nmwcd          (903681bab213d5f84717c0fc42afb28a) C:\Windows\system32\drivers\ccdcmbx64.sys
19:30:19.0164 3844        nmwcd - ok
19:30:19.0191 3844        nmwcdc          (ec4c5ebd003e0395bf4ea5a2efd13ce6) C:\Windows\system32\drivers\ccdcmbox64.sys
19:30:19.0207 3844        nmwcdc - ok
19:30:19.0230 3844        nmwcdnsucx64    (863aa6c58ac85a22355ae943c605e44b) C:\Windows\system32\drivers\nmwcdnsucx64.sys
19:30:19.0246 3844        nmwcdnsucx64 - ok
19:30:19.0258 3844        nmwcdnsux64    (7983d9201788407c4d1fc4d0baa04e32) C:\Windows\system32\drivers\nmwcdnsux64.sys
19:30:19.0274 3844        nmwcdnsux64 - ok
19:30:19.0300 3844        npf            (351533acc2a069b94e80bbfc177e8fdf) C:\Windows\system32\drivers\npf.sys
19:30:19.0306 3844        npf - ok
19:30:19.0307 3844        Scan interrupted by user!
19:30:19.0307 3844        Scan interrupted by user!
19:30:19.0307 3844        Scan interrupted by user!
19:30:19.0307 3844        ============================================================
19:30:19.0307 3844        Scan finished
19:30:19.0307 3844        ============================================================
19:30:19.0310 5388        Detected object count: 3
19:30:19.0310 5388        Actual detected object count: 3
19:30:21.0837 5388        IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
19:30:21.0837 5388        IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:30:21.0838 5388        LGDDCDevice ( UnsignedFile.Multi.Generic ) - skipped by user
19:30:21.0838 5388        LGDDCDevice ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:30:21.0838 5388        LGII2CDevice ( UnsignedFile.Multi.Generic ) - skipped by user
19:30:21.0838 5388        LGII2CDevice ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:30:42.0917 5272        ============================================================
19:30:42.0917 5272        Scan started
19:30:42.0917 5272        Mode: Manual; SigCheck; TDLFS;
19:30:42.0917 5272        ============================================================
19:30:43.0257 5272        ACPI            (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys
19:30:43.0268 5272        ACPI - ok
19:30:43.0312 5272        ADIHdAudAddService (4a30fa79f8253134d398251db614e3c9) C:\Windows\system32\drivers\ADIHdAud.sys
19:30:43.0323 5272        ADIHdAudAddService - ok
19:30:43.0405 5272        AdobeARMservice (11a52cf7b265631deeb24c6149309eff) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
19:30:43.0410 5272        AdobeARMservice - ok
19:30:43.0519 5272        AdobeFlashPlayerUpdateSvc (f19c98ad81d2c0e1bbfd8153d2c80ee8) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
19:30:43.0527 5272        AdobeFlashPlayerUpdateSvc - ok
19:30:43.0631 5272        adp94xx        (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
19:30:43.0645 5272        adp94xx - ok
19:30:43.0664 5272        adpahci        (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
19:30:43.0676 5272        adpahci - ok
19:30:43.0695 5272        adpu160m        (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
19:30:43.0704 5272        adpu160m - ok
19:30:43.0721 5272        adpu320        (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
19:30:43.0730 5272        adpu320 - ok
19:30:43.0763 5272        AEADIFilters    (28c0b0a6cb61bdd1fef877d4d0f69fbf) C:\Windows\system32\AEADISRV.EXE
19:30:43.0770 5272        AEADIFilters - ok
19:30:43.0803 5272        AeLookupSvc    (0f421175574bfe0bf2f4d8e910a253bb) C:\Windows\System32\aelupsvc.dll
19:30:43.0819 5272        AeLookupSvc - ok
19:30:43.0864 5272        AFD            (c4f6ce6087760ad70960c9eb130e7943) C:\Windows\system32\drivers\afd.sys
19:30:43.0876 5272        AFD - ok
19:30:43.0906 5272        agp440          (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
19:30:43.0914 5272        agp440 - ok
19:30:43.0941 5272        aic78xx        (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
19:30:43.0949 5272        aic78xx - ok
19:30:43.0959 5272        ALG            (5922f4f59b7868f3d74bbbbeb7b825a3) C:\Windows\System32\alg.exe
19:30:43.0980 5272        ALG - ok
19:30:43.0989 5272        aliide          (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys
19:30:43.0997 5272        aliide - ok
19:30:44.0038 5272        AMD External Events Utility (20c8a3e435a47f0408a1ea674afa6194) C:\Windows\system32\atiesrxx.exe
19:30:44.0049 5272        AMD External Events Utility - ok
19:30:44.0059 5272        amdide          (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys
19:30:44.0066 5272        amdide - ok
19:30:44.0077 5272        AmdK8          (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
19:30:44.0098 5272        AmdK8 - ok
19:30:44.0417 5272        amdkmdag        (0b45c18b0f3ee996d25baa4e74884b83) C:\Windows\system32\DRIVERS\atikmdag.sys
19:30:44.0567 5272        amdkmdag - ok
19:30:44.0739 5272        amdkmdap        (0e57258e5cc4cc7a9a9a877afdf0cec6) C:\Windows\system32\DRIVERS\atikmpag.sys
19:30:44.0752 5272        amdkmdap - ok
19:30:44.0842 5272        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
19:30:44.0849 5272        AntiVirSchedulerService - ok
19:30:44.0876 5272        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
19:30:44.0883 5272        AntiVirService - ok
19:30:44.0910 5272        Appinfo        (9c37b3fd5615477cb9a0cd116cf43f5c) C:\Windows\System32\appinfo.dll
19:30:44.0918 5272        Appinfo - ok
19:30:44.0952 5272        arc            (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
19:30:44.0960 5272        arc - ok
19:30:44.0969 5272        arcsas          (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
19:30:44.0977 5272        arcsas - ok
19:30:44.0992 5272        AsyncMac        (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
19:30:45.0014 5272        AsyncMac - ok
19:30:45.0056 5272        atapi          (e68d9b3a3905619732f7fe039466a623) C:\Windows\system32\drivers\atapi.sys
19:30:45.0064 5272        atapi - ok
19:30:45.0106 5272        AtiHDAudioService (917692cdf8e1ce00d9752fa40615338b) C:\Windows\system32\drivers\AtihdLH6.sys
19:30:45.0113 5272        AtiHDAudioService - ok
19:30:45.0114 5272        AtiHdmiService - ok
19:30:45.0421 5272        atikmdag        (0b45c18b0f3ee996d25baa4e74884b83) C:\Windows\system32\DRIVERS\atikmdag.sys
19:30:45.0566 5272        atikmdag - ok
19:30:45.0706 5272        AudioEndpointBuilder (79318c744693ec983d20e9337a2f8196) C:\Windows\System32\Audiosrv.dll
19:30:45.0725 5272        AudioEndpointBuilder - ok
19:30:45.0729 5272        AudioSrv        (79318c744693ec983d20e9337a2f8196) C:\Windows\System32\Audiosrv.dll
19:30:45.0748 5272        AudioSrv - ok
19:30:45.0803 5272        avgntflt        (26e38b5a58c6c55fafbc563eeddb0867) C:\Windows\system32\DRIVERS\avgntflt.sys
19:30:45.0810 5272        avgntflt - ok
19:30:45.0823 5272        avipbb          (9d1f00beff84cbbf46d7f052bc7e0565) C:\Windows\system32\DRIVERS\avipbb.sys
19:30:45.0831 5272        avipbb - ok
19:30:45.0843 5272        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
19:30:45.0850 5272        avkmgr - ok
19:30:45.0896 5272        BFE            (ffb96c2589ffa60473ead78b39fbde29) C:\Windows\System32\bfe.dll
19:30:45.0915 5272        BFE - ok
19:30:45.0952 5272        BITS            (6d316f4859634071cc25c4fd4589ad2c) C:\Windows\System32\qmgr.dll
19:30:45.0979 5272        BITS - ok
19:30:46.0004 5272        blbdrive        (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
19:30:46.0025 5272        blbdrive - ok
19:30:46.0060 5272        bowser          (2348447a80920b2493a9b582a23e81e1) C:\Windows\system32\DRIVERS\bowser.sys
19:30:46.0068 5272        bowser - ok
19:30:46.0076 5272        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
19:30:46.0091 5272        BrFiltLo - ok
19:30:46.0105 5272        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
19:30:46.0121 5272        BrFiltUp - ok
19:30:46.0156 5272        Browser        (a1b39de453433b115b4ea69ee0343816) C:\Windows\System32\browser.dll
19:30:46.0178 5272        Browser - ok
19:30:46.0258 5272        Brserid        (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
19:30:46.0290 5272        Brserid - ok
19:30:46.0329 5272        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
19:30:46.0361 5272        BrSerWdm - ok
19:30:46.0376 5272        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
19:30:46.0408 5272        BrUsbMdm - ok
19:30:46.0417 5272        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
19:30:46.0449 5272        BrUsbSer - ok
19:30:46.0486 5272        BTHMODEM        (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
19:30:46.0519 5272        BTHMODEM - ok
19:30:46.0533 5272        cdfs            (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
19:30:46.0555 5272        cdfs - ok
19:30:46.0592 5272        cdrom          (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys
19:30:46.0607 5272        cdrom - ok
19:30:46.0644 5272        CertPropSvc    (5a268127633c7ee2a7fb87f39d748d56) C:\Windows\System32\certprop.dll
19:30:46.0659 5272        CertPropSvc - ok
19:30:46.0676 5272        circlass        (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys
19:30:46.0697 5272        circlass - ok
19:30:46.0735 5272        CLFS            (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys
19:30:46.0748 5272        CLFS - ok
19:30:46.0811 5272        clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:30:46.0818 5272        clr_optimization_v2.0.50727_32 - ok
19:30:46.0886 5272        clr_optimization_v2.0.50727_64 (ce07a466201096f021cd09d631b21540) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
19:30:46.0893 5272        clr_optimization_v2.0.50727_64 - ok
19:30:46.0957 5272        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:30:46.0964 5272        clr_optimization_v4.0.30319_32 - ok
19:30:46.0987 5272        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
19:30:46.0994 5272        clr_optimization_v4.0.30319_64 - ok
19:30:47.0024 5272        cmdide          (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys
19:30:47.0031 5272        cmdide - ok
19:30:47.0042 5272        Compbatt        (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\drivers\compbatt.sys
19:30:47.0050 5272        Compbatt - ok
19:30:47.0052 5272        COMSysApp - ok
19:30:47.0115 5272        cpuz132 - ok
19:30:47.0125 5272        crcdisk        (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
19:30:47.0132 5272        crcdisk - ok
19:30:47.0173 5272        CryptSvc        (62740b9d2a137e8ced41a9e4239a7a31) C:\Windows\system32\cryptsvc.dll
19:30:47.0182 5272        CryptSvc - ok
19:30:47.0232 5272        DcomLaunch      (cf8b9a3a5e7dc57724a89d0c3e8cf9ef) C:\Windows\system32\rpcss.dll
19:30:47.0256 5272        DcomLaunch - ok
19:30:47.0288 5272        DfsC            (8b722ba35205c71e7951cdc4cdbade19) C:\Windows\system32\Drivers\dfsc.sys
19:30:47.0296 5272        DfsC - ok
19:30:47.0385 5272        DFSR            (c647f468f7de343df8c143655c5557d4) C:\Windows\system32\DFSR.exe
19:30:47.0431 5272        DFSR - ok
19:30:47.0563 5272        Dhcp            (3ed0321127ce70acdaabbf77e157c2a7) C:\Windows\System32\dhcpcsvc.dll
19:30:47.0580 5272        Dhcp - ok
19:30:47.0642 5272        disk            (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys
19:30:47.0650 5272        disk - ok
19:30:47.0686 5272        Dnscache        (06230f1b721494a6df8d47fd395bb1b0) C:\Windows\System32\dnsrslvr.dll
19:30:47.0695 5272        Dnscache - ok
19:30:47.0734 5272        dot3svc        (1a7156dd1e850e9914e5e991e3225b94) C:\Windows\System32\dot3svc.dll
19:30:47.0750 5272        dot3svc - ok
19:30:47.0792 5272        DPS            (1583b39790db3eaec7edb0cb0140c708) C:\Windows\system32\dps.dll
19:30:47.0814 5272        DPS - ok
19:30:47.0846 5272        drmkaud        (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
19:30:47.0861 5272        drmkaud - ok
19:30:47.0915 5272        DXGKrnl        (b8e554e502d5123bc111f99d6a2181b4) C:\Windows\System32\drivers\dxgkrnl.sys
19:30:47.0935 5272        DXGKrnl - ok
19:30:47.0970 5272        E1G60          (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
19:30:47.0992 5272        E1G60 - ok
19:30:47.0994 5272        EagleX64 - ok
19:30:48.0006 5272        EapHost        (c2303883fd9be49dc36a6400643002ea) C:\Windows\System32\eapsvc.dll
19:30:48.0022 5272        EapHost - ok
19:30:48.0058 5272        Ecache          (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys
19:30:48.0067 5272        Ecache - ok
19:30:48.0111 5272        ehRecvr        (14ce384d2e27b64c256bda4dc39c312d) C:\Windows\ehome\ehRecvr.exe
19:30:48.0121 5272        ehRecvr - ok
19:30:48.0141 5272        ehSched        (b93159c1313d66fdfbbe876f5189cd52) C:\Windows\ehome\ehsched.exe
19:30:48.0149 5272        ehSched - ok
19:30:48.0159 5272        ehstart        (f5ee2527d74449868e3c3227a59bcd28) C:\Windows\ehome\ehstart.dll
19:30:48.0166 5272        ehstart - ok
19:30:48.0190 5272        elxstor        (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
19:30:48.0202 5272        elxstor - ok
19:30:48.0250 5272        EMDMgmt        (a9b18b63a4fd6baab83326706d857fab) C:\Windows\system32\emdmgmt.dll
19:30:48.0264 5272        EMDMgmt - ok
19:30:48.0302 5272        ErrDev          (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys
19:30:48.0322 5272        ErrDev - ok
19:30:48.0373 5272        EventSystem    (e12f22b73f153dece721cd45ec05b4af) C:\Windows\system32\es.dll
19:30:48.0392 5272        EventSystem - ok
19:30:48.0444 5272        exfat          (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys
19:30:48.0453 5272        exfat - ok
19:30:48.0494 5272        fastfat        (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys
19:30:48.0511 5272        fastfat - ok
19:30:48.0518 5272        fdc            (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
19:30:48.0539 5272        fdc - ok
19:30:48.0571 5272        fdPHost        (bb9267acacd8b7533dd936c34a0cba5e) C:\Windows\system32\fdPHost.dll
19:30:48.0592 5272        fdPHost - ok
19:30:48.0597 5272        FDResPub        (300c80931eabbe1db7591c516efe8d0f) C:\Windows\system32\fdrespub.dll
19:30:48.0629 5272        FDResPub - ok
19:30:48.0661 5272        FileInfo        (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
19:30:48.0669 5272        FileInfo - ok
19:30:48.0683 5272        Filetrace      (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
19:30:48.0704 5272        Filetrace - ok
19:30:48.0715 5272        flpydisk        (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
19:30:48.0735 5272        flpydisk - ok
19:30:48.0781 5272        FltMgr          (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys
19:30:48.0791 5272        FltMgr - ok
19:30:48.0854 5272        FontCache      (be1c5bd1ca7ed015bc6fa1ae67e592c8) C:\Windows\system32\FntCache.dll
19:30:48.0875 5272        FontCache - ok
19:30:48.0918 5272        FontCache3.0.0.0 (bc5b0be5af3510b0fd8c140ee42c6d3e) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
19:30:48.0926 5272        FontCache3.0.0.0 - ok
19:30:49.0008 5272        FreemakeVideoCapture - ok
19:30:49.0051 5272        Fs_Rec          (5779b86cd8b32519fbecb136394d946a) C:\Windows\system32\drivers\Fs_Rec.sys
19:30:49.0059 5272        Fs_Rec - ok
19:30:49.0087 5272        gagp30kx        (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
19:30:49.0096 5272        gagp30kx - ok
19:30:49.0130 5272        GEARAspiWDM    (58e581a98a85587e9f5a297d4ad44cc0) C:\Windows\system32\Drivers\GEARAspiWDM.sys
19:30:49.0136 5272        GEARAspiWDM - ok
19:30:49.0184 5272        gpsvc          (a0e1b575ba8f504968cd40c0faeb2384) C:\Windows\System32\gpsvc.dll
19:30:49.0207 5272        gpsvc - ok
19:30:49.0242 5272        HdAudAddService (68e732382b32417ff61fd663259b4b09) C:\Windows\system32\drivers\HdAudio.sys
19:30:49.0252 5272        HdAudAddService - ok
19:30:49.0306 5272        HDAudBus        (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys
19:30:49.0332 5272        HDAudBus - ok
19:30:49.0345 5272        HidBth          (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
19:30:49.0377 5272        HidBth - ok
19:30:49.0393 5272        HidIr          (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
19:30:49.0426 5272        HidIr - ok
19:30:49.0446 5272        hidserv        (59361d38a297755d46a540e450202b2a) C:\Windows\system32\hidserv.dll
19:30:49.0462 5272        hidserv - ok
19:30:49.0484 5272        HidUsb          (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys
19:30:49.0499 5272        HidUsb - ok
19:30:49.0532 5272        hkmsvc          (b12f367ea39c0795fd57e31242ce1a5a) C:\Windows\system32\kmsvc.dll
19:30:49.0553 5272        hkmsvc - ok
19:30:49.0585 5272        HpCISSs        (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
19:30:49.0593 5272        HpCISSs - ok
19:30:49.0627 5272        HTCAND64        (894a75a3d6bfd97d73bf60d3022b567a) C:\Windows\system32\Drivers\ANDROIDUSB.sys
19:30:49.0634 5272        HTCAND64 - ok
19:30:49.0665 5272        htcnprot        (4f6c3122817049997cd696d4a38bfacb) C:\Windows\system32\DRIVERS\htcnprot.sys
19:30:49.0671 5272        htcnprot - ok
19:30:49.0718 5272        HTTP            (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys
19:30:49.0733 5272        HTTP - ok
19:30:49.0764 5272        i2omp          (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
19:30:49.0771 5272        i2omp - ok
19:30:49.0785 5272        i8042prt        (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
19:30:49.0800 5272        i8042prt - ok
19:30:49.0820 5272        iaStorV        (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
19:30:49.0829 5272        iaStorV - ok
19:30:49.0932 5272        IDriverT        (6f95324909b502e2651442c1548ab12f) C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
19:30:49.0934 5272        IDriverT ( UnsignedFile.Multi.Generic ) - warning
19:30:49.0934 5272        IDriverT - detected UnsignedFile.Multi.Generic (1)
19:30:50.0052 5272        idsvc          (749f5f8cedca70f2a512945325fc489d) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
19:30:50.0069 5272        idsvc - ok
19:30:50.0085 5272        iirsp          (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
19:30:50.0092 5272        iirsp - ok
19:30:50.0132 5272        IKEEXT          (0c9ea6e654e7b0471741e343a6c671af) C:\Windows\System32\ikeext.dll
19:30:50.0152 5272        IKEEXT - ok
19:30:50.0184 5272        intelide        (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys
19:30:50.0192 5272        intelide - ok
19:30:50.0208 5272        intelppm        (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
19:30:50.0229 5272        intelppm - ok
19:30:50.0259 5272        IPBusEnum      (5624bc1bc5eeb49c0ab76a8114f05ea3) C:\Windows\system32\ipbusenum.dll
19:30:50.0280 5272        IPBusEnum - ok
19:30:50.0319 5272        IpFilterDriver  (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:30:50.0334 5272        IpFilterDriver - ok
19:30:50.0355 5272        iphlpsvc        (bf0dbfa9792c5c14fa00f61c75116c1b) C:\Windows\System32\iphlpsvc.dll
19:30:50.0365 5272        iphlpsvc - ok
19:30:50.0366 5272        IpInIp - ok
19:30:50.0381 5272        IPMIDRV        (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
19:30:50.0402 5272        IPMIDRV - ok
19:30:50.0417 5272        IPNAT          (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
19:30:50.0439 5272        IPNAT - ok
19:30:50.0451 5272        IRENUM          (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
19:30:50.0472 5272        IRENUM - ok
19:30:50.0503 5272        isapnp          (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
19:30:50.0511 5272        isapnp - ok
19:30:50.0551 5272        iScsiPrt        (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys
19:30:50.0560 5272        iScsiPrt - ok
19:30:50.0573 5272        iteatapi        (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
19:30:50.0580 5272        iteatapi - ok
19:30:50.0596 5272        iteraid        (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
19:30:50.0603 5272        iteraid - ok
19:30:50.0611 5272        kbdclass        (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
19:30:50.0619 5272        kbdclass - ok
19:30:50.0645 5272        kbdhid          (dbdf75d51464fbc47d0104ec3d572c05) C:\Windows\system32\DRIVERS\kbdhid.sys
19:30:50.0660 5272        kbdhid - ok
19:30:50.0679 5272        KeyIso          (260bf9c43ee12c6898a9f5aab0fb0e5d) C:\Windows\system32\lsass.exe
19:30:50.0687 5272        KeyIso - ok
19:30:50.0723 5272        KSecDD          (88956ad9fa510848ad176777a6c6c1f5) C:\Windows\system32\Drivers\ksecdd.sys
19:30:50.0737 5272        KSecDD - ok
19:30:50.0770 5272        ksthunk        (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
19:30:50.0790 5272        ksthunk - ok
19:30:50.0831 5272        KtmRm          (1faf6926f3416d3da05c5b265491bdae) C:\Windows\system32\msdtckrm.dll
19:30:50.0855 5272        KtmRm - ok
19:30:50.0889 5272        L8042Kbd        (f33c5d79d3273530e1892a0922283a7b) C:\Windows\system32\DRIVERS\L8042Kbd.sys
19:30:50.0895 5272        L8042Kbd - ok
19:30:50.0932 5272        LanmanServer    (50c7a3cb427e9bb5ed0708a669956ab5) C:\Windows\system32\srvsvc.dll
19:30:50.0942 5272        LanmanServer - ok
19:30:50.0981 5272        LanmanWorkstation (caf86fc1388be1e470f1a7b43e348adb) C:\Windows\System32\wkssvc.dll
19:30:50.0991 5272        LanmanWorkstation - ok
19:30:51.0044 5272        LGDDCDevice    (094c41ab6fbb0ec205989e92e257aebf) C:\Program Files (x86)\LG Soft India\forteManager\bin\I2CDriver.sys
19:30:51.0046 5272        LGDDCDevice ( UnsignedFile.Multi.Generic ) - warning
19:30:51.0046 5272        LGDDCDevice - detected UnsignedFile.Multi.Generic (1)
19:30:51.0060 5272        LGII2CDevice    (8409a28e641136caf114120c7387d072) C:\Program Files (x86)\LG Soft India\forteManager\bin\PII2CDriver.sys
19:30:51.0062 5272        LGII2CDevice ( UnsignedFile.Multi.Generic ) - warning
19:30:51.0062 5272        LGII2CDevice - detected UnsignedFile.Multi.Generic (1)
19:30:51.0073 5272        LHidFilt        (b6552d382ff070b4ed34cbd6737277c0) C:\Windows\system32\DRIVERS\LHidFilt.Sys
19:30:51.0079 5272        LHidFilt - ok
19:30:51.0107 5272        lltdio          (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
19:30:51.0128 5272        lltdio - ok
19:30:51.0163 5272        lltdsvc        (961ccbd0b1ccb5675d64976fae37d092) C:\Windows\System32\lltdsvc.dll
19:30:51.0186 5272        lltdsvc - ok
19:30:51.0196 5272        lmhosts        (a47f8080cacc23c91fe823ad19aa5612) C:\Windows\System32\lmhsvc.dll
19:30:51.0217 5272        lmhosts - ok
19:30:51.0255 5272        LMouFilt        (73c1f563ab73d459dffe682d66476558) C:\Windows\system32\DRIVERS\LMouFilt.Sys
19:30:51.0261 5272        LMouFilt - ok
19:30:51.0274 5272        LSI_FC          (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
19:30:51.0283 5272        LSI_FC - ok
19:30:51.0297 5272        LSI_SAS        (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
19:30:51.0306 5272        LSI_SAS - ok
19:30:51.0320 5272        LSI_SCSI        (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
19:30:51.0328 5272        LSI_SCSI - ok
19:30:51.0361 5272        luafv          (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
19:30:51.0382 5272        luafv - ok
19:30:51.0398 5272        MBAMProtector  (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys
19:30:51.0404 5272        MBAMProtector - ok
19:30:51.0454 5272        MBAMService    (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
19:30:51.0469 5272        MBAMService - ok
19:30:51.0504 5272        Mcx2Svc        (76a58df02bd4ea29f189b82d0bef17f8) C:\Windows\system32\Mcx2Svc.dll
19:30:51.0513 5272        Mcx2Svc - ok
19:30:51.0538 5272        megasas        (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
19:30:51.0546 5272        megasas - ok
19:30:51.0569 5272        MegaSR          (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
19:30:51.0582 5272        MegaSR - ok
19:30:51.0617 5272        MMCSS          (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll
19:30:51.0638 5272        MMCSS - ok
19:30:51.0646 5272        Modem          (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
19:30:51.0667 5272        Modem - ok
19:30:51.0675 5272        monitor        (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
19:30:51.0697 5272        monitor - ok
19:30:51.0708 5272        mouclass        (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
19:30:51.0716 5272        mouclass - ok
19:30:51.0727 5272        mouhid          (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
19:30:51.0748 5272        mouhid - ok
19:30:51.0759 5272        MountMgr        (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
19:30:51.0767 5272        MountMgr - ok
19:30:51.0801 5272        mpio            (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
19:30:51.0810 5272        mpio - ok
19:30:51.0821 5272        mpsdrv          (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
19:30:51.0837 5272        mpsdrv - ok
19:30:51.0889 5272        MpsSvc          (897e3baf68ba406a61682ae39c83900c) C:\Windows\system32\mpssvc.dll
19:30:51.0911 5272        MpsSvc - ok
19:30:51.0923 5272        Mraid35x        (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
19:30:51.0931 5272        Mraid35x - ok
19:30:51.0936 5272        MRxDAV          (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys
19:30:51.0945 5272        MRxDAV - ok
19:30:51.0980 5272        mrxsmb          (1485811b320ff8c7edad1caebb1c6c2b) C:\Windows\system32\DRIVERS\mrxsmb.sys
19:30:51.0989 5272        mrxsmb - ok
19:30:52.0031 5272        mrxsmb10        (3b929a60c833fc615fd97fba82bc7632) C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:30:52.0041 5272        mrxsmb10 - ok
19:30:52.0045 5272        mrxsmb20        (c64ab3e1f53b4f5b5bb6d796b2d7bec3) C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:30:52.0053 5272        mrxsmb20 - ok
19:30:52.0087 5272        msahci          (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys
19:30:52.0094 5272        msahci - ok
19:30:52.0110 5272        msdsm          (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
19:30:52.0118 5272        msdsm - ok
19:30:52.0152 5272        MSDTC          (7ec02ce772f068ed0beafa3da341a9bc) C:\Windows\System32\msdtc.exe
19:30:52.0174 5272        MSDTC - ok
19:30:52.0191 5272        Msfs            (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
19:30:52.0212 5272        Msfs - ok
19:30:52.0221 5272        msisadrv        (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
19:30:52.0229 5272        msisadrv - ok
19:30:52.0266 5272        MSiSCSI        (366b0c1f4478b519c181e37d43dcda32) C:\Windows\system32\iscsiexe.dll
19:30:52.0288 5272        MSiSCSI - ok
19:30:52.0290 5272        msiserver - ok
19:30:52.0301 5272        MSKSSRV        (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
19:30:52.0322 5272        MSKSSRV - ok
19:30:52.0329 5272        MSPCLOCK        (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
19:30:52.0350 5272        MSPCLOCK - ok
19:30:52.0386 5272        MSPQM          (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
19:30:52.0407 5272        MSPQM - ok
19:30:52.0451 5272        MsRPC          (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys
19:30:52.0461 5272        MsRPC - ok
19:30:52.0471 5272        mssmbios        (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
19:30:52.0479 5272        mssmbios - ok
19:30:52.0481 5272        MSTEE          (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
19:30:52.0503 5272        MSTEE - ok
19:30:52.0528 5272        MTsensor        (6936198f2cc25b39cf5262436c80df46) C:\Windows\system32\DRIVERS\ASACPI.sys
19:30:52.0534 5272        MTsensor - ok
19:30:52.0541 5272        Mup            (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys
19:30:52.0550 5272        Mup - ok
19:30:52.0602 5272        napagent        (a5b10c845e7538c60c0f5d87a57cb3f5) C:\Windows\system32\qagentRT.dll
19:30:52.0622 5272        napagent - ok
19:30:52.0661 5272        NativeWifiP    (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys
19:30:52.0671 5272        NativeWifiP - ok
19:30:52.0722 5272        NDIS            (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys
19:30:52.0739 5272        NDIS - ok
19:30:52.0779 5272        NdisTapi        (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
19:30:52.0794 5272        NdisTapi - ok
19:30:52.0813 5272        Ndisuio        (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
19:30:52.0834 5272        Ndisuio - ok
19:30:52.0871 5272        NdisWan        (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys
19:30:52.0887 5272        NdisWan - ok
19:30:52.0899 5272        NDProxy        (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
19:30:52.0915 5272        NDProxy - ok
19:30:53.0027 5272        Nero BackItUp Scheduler 3 (c5052fb77aa42ed440f9f6b4e37145a9) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
19:30:53.0044 5272        Nero BackItUp Scheduler 3 - ok
19:30:53.0073 5272        NetBIOS        (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
19:30:53.0094 5272        NetBIOS - ok
19:30:53.0142 5272        netbt          (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys
19:30:53.0159 5272        netbt - ok
19:30:53.0195 5272        Netlogon        (260bf9c43ee12c6898a9f5aab0fb0e5d) C:\Windows\system32\lsass.exe
19:30:53.0203 5272        Netlogon - ok
19:30:53.0244 5272        Netman          (9b63b29defc0f3115a559d2597bf5d75) C:\Windows\System32\netman.dll
19:30:53.0269 5272        Netman - ok
19:30:53.0289 5272        netprofm        (7846d0136cc2b264926a73047ba7688a) C:\Windows\System32\netprofm.dll
19:30:53.0312 5272        netprofm - ok
19:30:53.0410 5272        NetTcpPortSharing (74751dda198165947fd7454d83f49825) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
19:30:53.0417 5272        NetTcpPortSharing - ok
19:30:53.0446 5272        nfrd960        (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
19:30:53.0453 5272        nfrd960 - ok
19:30:53.0472 5272        NlaSvc          (f145bf4c4668e7e312069f81ef847cfc) C:\Windows\System32\nlasvc.dll
19:30:53.0494 5272        NlaSvc - ok
19:30:53.0592 5272        NMIndexingService (74149bcf0307bb76d68c0f8912df731c) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
19:30:53.0603 5272        NMIndexingService - ok
19:30:53.0640 5272        nmwcd          (903681bab213d5f84717c0fc42afb28a) C:\Windows\system32\drivers\ccdcmbx64.sys
19:30:53.0656 5272        nmwcd - ok
19:30:53.0683 5272        nmwcdc          (ec4c5ebd003e0395bf4ea5a2efd13ce6) C:\Windows\system32\drivers\ccdcmbox64.sys
19:30:53.0699 5272        nmwcdc - ok
19:30:53.0722 5272        nmwcdnsucx64    (863aa6c58ac85a22355ae943c605e44b) C:\Windows\system32\drivers\nmwcdnsucx64.sys
19:30:53.0738 5272        nmwcdnsucx64 - ok
19:30:53.0750 5272        nmwcdnsux64    (7983d9201788407c4d1fc4d0baa04e32) C:\Windows\system32\drivers\nmwcdnsux64.sys
19:30:53.0767 5272        nmwcdnsux64 - ok
19:30:53.0792 5272        npf            (351533acc2a069b94e80bbfc177e8fdf) C:\Windows\system32\drivers\npf.sys
19:30:53.0798 5272        npf - ok
19:30:53.0833 5272        Npfs            (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys
19:30:53.0848 5272        Npfs - ok
19:30:53.0874 5272        nsi            (acb62baa1c319b17752553df3026eeeb) C:\Windows\system32\nsisvc.dll
19:30:53.0896 5272        nsi - ok
19:30:53.0929 5272        nsiproxy        (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
19:30:53.0950 5272        nsiproxy - ok
19:30:54.0019 5272        Ntfs            (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys
19:30:54.0047 5272        Ntfs - ok
19:30:54.0164 5272        Null            (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
19:30:54.0185 5272        Null - ok
19:30:54.0195 5272        nvraid          (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys
19:30:54.0203 5272        nvraid - ok
19:30:54.0235 5272        nvstor          (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys
19:30:54.0243 5272        nvstor - ok
19:30:54.0257 5272        nv_agp          (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys
19:30:54.0266 5272        nv_agp - ok
19:30:54.0268 5272        NwlnkFlt - ok
19:30:54.0270 5272        NwlnkFwd - ok
19:30:54.0307 5272        ohci1394        (b5b1ce65ac15bbd11c0619e3ef7cfc28) C:\Windows\system32\DRIVERS\ohci1394.sys
19:30:54.0322 5272        ohci1394 - ok
19:30:54.0377 5272        p2pimsvc        (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll
19:30:54.0393 5272        p2pimsvc - ok
19:30:54.0398 5272        p2psvc          (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll
19:30:54.0415 5272        p2psvc - ok
19:30:54.0467 5272        PAC7302        (4729a9729eda69a018796a7a48a9a846) C:\Windows\system32\DRIVERS\PAC7302.SYS
19:30:54.0478 5272        PAC7302 - ok
19:30:54.0492 5272        Parport        (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys
19:30:54.0526 5272        Parport - ok
19:30:54.0561 5272        partmgr        (b43751085e2abe389da466bc62a4b987) C:\Windows\system32\drivers\partmgr.sys
19:30:54.0570 5272        partmgr - ok
19:30:54.0647 5272        PassThru Service (39b9dcd7040654c2e57d7396736c718e) C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
19:30:54.0650 5272        PassThru Service ( UnsignedFile.Multi.Generic ) - warning
19:30:54.0650 5272        PassThru Service - detected UnsignedFile.Multi.Generic (1)
19:30:54.0674 5272        PcaSvc          (9ab157b374192ff276c1628fbdba2b0e) C:\Windows\System32\pcasvc.dll
19:30:54.0684 5272        PcaSvc - ok
19:30:54.0717 5272        pccsmcfd        (bc0018c2d29f655188a0ed3fa94fdb24) C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
19:30:54.0723 5272        pccsmcfd - ok
19:30:54.0764 5272        pci            (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys
19:30:54.0773 5272        pci - ok
19:30:54.0783 5272        pciide          (2657f6c0b78c36d95034be109336e382) C:\Windows\system32\drivers\pciide.sys
19:30:54.0791 5272        pciide - ok
19:30:54.0829 5272        pcmcia          (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys
19:30:54.0838 5272        pcmcia - ok
19:30:54.0870 5272        PEAUTH          (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
19:30:54.0908 5272        PEAUTH - ok
19:30:54.0969 5272        PerfHost        (0ed8727ea0172860f47258456c06caea) C:\Windows\SysWow64\perfhost.exe
19:30:54.0990 5272        PerfHost - ok
19:30:55.0056 5272        pla            (e9e68c1a0f25cf4a7ac966eea74ee89e) C:\Windows\system32\pla.dll
19:30:55.0086 5272        pla - ok
19:30:55.0133 5272        PlugPlay        (fe6b0f59215c9fd9f9d26539c58c8b82) C:\Windows\system32\umpnpmgr.dll
19:30:55.0151 5272        PlugPlay - ok
19:30:55.0153 5272        PnkBstrA - ok
19:30:55.0210 5272        PNRPAutoReg    (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll
19:30:55.0227 5272        PNRPAutoReg - ok
19:30:55.0232 5272        PNRPsvc        (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll
19:30:55.0248 5272        PNRPsvc - ok
19:30:55.0271 5272        PolicyAgent    (89a5560671c2d8b4a4b51f3e1aa069d8) C:\Windows\System32\ipsecsvc.dll
19:30:55.0292 5272        PolicyAgent - ok
19:30:55.0365 5272        PptpMiniport    (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys
19:30:55.0380 5272        PptpMiniport - ok
19:30:55.0412 5272        Processor      (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys
19:30:55.0433 5272        Processor - ok
19:30:55.0472 5272        ProfSvc        (e058ce4fc2449d8bfa14739c83b7ff2a) C:\Windows\system32\profsvc.dll
19:30:55.0489 5272        ProfSvc - ok
19:30:55.0519 5272        ProtectedStorage (260bf9c43ee12c6898a9f5aab0fb0e5d) C:\Windows\system32\lsass.exe
19:30:55.0528 5272        ProtectedStorage - ok
19:30:55.0566 5272        PSched          (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys
19:30:55.0581 5272        PSched - ok
19:30:55.0623 5272        ql2300          (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys
19:30:55.0646 5272        ql2300 - ok
19:30:55.0674 5272        ql40xx          (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
19:30:55.0682 5272        ql40xx - ok
19:30:55.0721 5272        QWAVE          (90574842c3da781e279061a3eff91f07) C:\Windows\system32\qwave.dll
19:30:55.0732 5272        QWAVE - ok
19:30:55.0744 5272        QWAVEdrv        (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
19:30:55.0752 5272        QWAVEdrv - ok
19:30:55.0786 5272        RasAcd          (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
19:30:55.0807 5272        RasAcd - ok
19:30:55.0817 5272        RasAuto        (b2ae18f847d07f0044404ddf7cb04497) C:\Windows\System32\rasauto.dll
19:30:55.0839 5272        RasAuto - ok
19:30:55.0881 5272        Rasl2tp        (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys
19:30:55.0897 5272        Rasl2tp - ok
19:30:55.0909 5272        RasMan          (3ad83e4046c43be510de681588acb8af) C:\Windows\System32\rasmans.dll
19:30:55.0927 5272        RasMan - ok
19:30:55.0966 5272        RasPppoe        (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys
19:30:55.0981 5272        RasPppoe - ok
19:30:56.0016 5272        RasSstp        (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys
19:30:56.0024 5272        RasSstp - ok
19:30:56.0065 5272        rdbss          (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys
19:30:56.0082 5272        rdbss - ok
19:30:56.0118 5272        RDPCDD          (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
19:30:56.0139 5272        RDPCDD - ok
19:30:56.0161 5272        rdpdr          (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys
19:30:56.0184 5272        rdpdr - ok
19:30:56.0186 5272        RDPENCDD        (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
19:30:56.0207 5272        RDPENCDD - ok
19:30:56.0245 5272        RDPWD          (ae4bd9e1c33d351d8e607fc81f15160c) C:\Windows\system32\drivers\RDPWD.sys
19:30:56.0255 5272        RDPWD - ok
19:30:56.0283 5272        RemoteAccess    (c612b9557da73f70d41f8a6fbc8e5344) C:\Windows\System32\mprdim.dll
19:30:56.0305 5272        RemoteAccess - ok
19:30:56.0348 5272        RemoteRegistry  (44b9d8ec2f3ef3a0efb00857af70d861) C:\Windows\system32\regsvc.dll
19:30:56.0365 5272        RemoteRegistry - ok
19:30:56.0404 5272        RpcLocator      (f46c457840d4b7a4daafee739ce04102) C:\Windows\system32\locator.exe
19:30:56.0412 5272        RpcLocator - ok
19:30:56.0563 5272        RpcSs          (cf8b9a3a5e7dc57724a89d0c3e8cf9ef) C:\Windows\system32\rpcss.dll
19:30:56.0586 5272        RpcSs - ok
19:30:56.0614 5272        rspndr          (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
19:30:56.0635 5272        rspndr - ok
19:30:56.0652 5272        SamSs          (260bf9c43ee12c6898a9f5aab0fb0e5d) C:\Windows\system32\lsass.exe
19:30:56.0660 5272        SamSs - ok
19:30:56.0680 5272        sbp2port        (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys
19:30:56.0687 5272        sbp2port - ok
19:30:56.0725 5272        SCardSvr        (fd1cdcf108d5ef3366f00d18b70fb89b) C:\Windows\System32\SCardSvr.dll
19:30:56.0741 5272        SCardSvr - ok
19:30:56.0801 5272        Schedule        (0f838c811ad295d2a4489b9993096c63) C:\Windows\system32\schedsvc.dll
19:30:56.0819 5272        Schedule - ok
19:30:56.0850 5272        SCPolicySvc    (5a268127633c7ee2a7fb87f39d748d56) C:\Windows\System32\certprop.dll
19:30:56.0865 5272        SCPolicySvc - ok
19:30:56.0899 5272        SDRSVC          (4ff71b076a7760fe75ea5ae2d0ee0018) C:\Windows\System32\SDRSVC.dll
19:30:56.0908 5272        SDRSVC - ok
19:30:57.0015 5272        SearchAnonymizer (0f4a80438e7286a0e623582f5f2395bd) C:\Users\Frank\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
19:30:57.0018 5272        SearchAnonymizer ( UnsignedFile.Multi.Generic ) - warning
19:30:57.0018 5272        SearchAnonymizer - detected UnsignedFile.Multi.Generic (1)
19:30:57.0073 5272        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
19:30:57.0104 5272        secdrv - ok
19:30:57.0110 5272        seclogon        (5acdcbc67fcf894a1815b9f96d704490) C:\Windows\system32\seclogon.dll
19:30:57.0131 5272        seclogon - ok
19:30:57.0141 5272        SENS            (90973a64b96cd647ff81c79443618eed) C:\Windows\System32\sens.dll
19:30:57.0163 5272        SENS - ok
19:30:57.0178 5272        Serenum        (2449316316411d65bd2c761a6ffb2ce2) C:\Windows\system32\DRIVERS\serenum.sys
19:30:57.0199 5272        Serenum - ok
19:30:57.0218 5272        Serial          (4b438170be2fc8e0bd35ee87a960f84f) C:\Windows\system32\DRIVERS\serial.sys
19:30:57.0239 5272        Serial - ok
19:30:57.0254 5272        sermouse        (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
19:30:57.0275 5272        sermouse - ok
19:30:57.0373 5272        ServiceLayer    (12b41d84a4d058adc60853c365dbfcca) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
19:30:57.0383 5272        ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
19:30:57.0383 5272        ServiceLayer - detected UnsignedFile.Multi.Generic (1)
19:30:57.0423 5272        SessionEnv      (a8e4a4407a09f35dccc3771af590b0c4) C:\Windows\system32\sessenv.dll
19:30:57.0445 5272        SessionEnv - ok
19:30:57.0461 5272        sffdisk        (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys
19:30:57.0481 5272        sffdisk - ok
19:30:57.0505 5272        sffp_mmc        (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys
19:30:57.0526 5272        sffp_mmc - ok
19:30:57.0535 5272        sffp_sd        (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys
19:30:57.0556 5272        sffp_sd - ok
19:30:57.0563 5272        sfloppy        (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys
19:30:57.0595 5272        sfloppy - ok
19:30:57.0632 5272        SharedAccess    (4c5aee179da7e1ee9a9ccb9da289af34) C:\Windows\System32\ipnathlp.dll
19:30:57.0656 5272        SharedAccess - ok
19:30:57.0704 5272        ShellHWDetection (56793271ecdedd350c5add305603e963) C:\Windows\System32\shsvcs.dll
19:30:57.0714 5272        ShellHWDetection - ok
19:30:57.0731 5272        SiSRaid2        (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys
19:30:57.0739 5272        SiSRaid2 - ok
19:30:57.0759 5272        SiSRaid4        (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys
19:30:57.0767 5272        SiSRaid4 - ok
19:30:57.0846 5272        SkypeUpdate    (ea396139541706b4b433641d62ea53ce) C:\Program Files (x86)\Skype\Updater\Updater.exe
19:30:57.0854 5272        SkypeUpdate - ok
19:30:57.0951 5272        slsvc          (a9a27a8e257b45a604fdad4f26fe7241) C:\Windows\system32\SLsvc.exe
19:30:57.0995 5272        slsvc - ok
19:30:58.0122 5272        SLUINotify      (fd74b4b7c2088e390a30c85a896fc3af) C:\Windows\system32\SLUINotify.dll
19:30:58.0138 5272        SLUINotify - ok
19:30:58.0206 5272        Smb            (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys
19:30:58.0222 5272        Smb - ok
19:30:58.0256 5272        SNMPTRAP        (f8f47f38909823b1af28d60b96340cff) C:\Windows\System32\snmptrap.exe
19:30:58.0264 5272        SNMPTRAP - ok
19:30:58.0301 5272        spldr          (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys
19:30:58.0309 5272        spldr - ok
19:30:58.0345 5272        Spooler        (f66ff751e7efc816d266977939ef5dc3) C:\Windows\System32\spoolsv.exe
19:30:58.0355 5272        Spooler - ok
19:30:58.0417 5272        sptd            (9ab59cf736981ed1f83c6ab5faa8ba5c) C:\Windows\System32\Drivers\sptd.sys
19:30:58.0435 5272        sptd - ok
19:30:58.0472 5272        srv            (880a57fccb571ebd063d4dd50e93e46d) C:\Windows\system32\DRIVERS\srv.sys
19:30:58.0484 5272        srv - ok
19:30:58.0519 5272        srv2            (a1ad14a6d7a37891fffeca35ebbb0730) C:\Windows\system32\DRIVERS\srv2.sys
19:30:58.0528 5272        srv2 - ok
19:30:58.0539 5272        srvnet          (4bed62f4fa4d8300973f1151f4c4d8a7) C:\Windows\system32\DRIVERS\srvnet.sys
19:30:58.0547 5272        srvnet - ok
19:30:58.0582 5272        SSDPSRV        (192c74646ec5725aef3f80d19ff75f6a) C:\Windows\System32\ssdpsrv.dll
19:30:58.0604 5272        SSDPSRV - ok
19:30:58.0632 5272        SstpSvc        (2ee3fa0308e6185ba64a9a7f2e74332b) C:\Windows\system32\sstpsvc.dll
19:30:58.0642 5272        SstpSvc - ok
19:30:58.0687 5272        stisvc          (15825c1fbfb8779992cb65087f316af5) C:\Windows\System32\wiaservc.dll
19:30:58.0702 5272        stisvc - ok
19:30:58.0731 5272        swenum          (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
19:30:58.0738 5272        swenum - ok
19:30:58.0786 5272        swprv          (6de37f4de19d4efd9c48c43addbc949a) C:\Windows\System32\swprv.dll
19:30:58.0806 5272        swprv - ok
19:30:58.0815 5272        Symc8xx        (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
19:30:58.0823 5272        Symc8xx - ok
19:30:58.0831 5272        Sym_hi          (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
19:30:58.0839 5272        Sym_hi - ok
19:30:58.0847 5272        Sym_u3          (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
19:30:58.0855 5272        Sym_u3 - ok
19:30:58.0925 5272        SysMain        (92d7a8b0f87b036f17d25885937897a6) C:\Windows\system32\sysmain.dll
19:30:58.0951 5272        SysMain - ok
19:30:58.0980 5272        TabletInputService (005ce42567f9113a3bccb3b20073b029) C:\Windows\System32\TabSvc.dll
19:30:58.0990 5272        TabletInputService - ok
19:30:59.0032 5272        TapiSrv        (cc2562b4d55e0b6a4758c65407f63b79) C:\Windows\System32\tapisrv.dll
19:30:59.0050 5272        TapiSrv - ok
19:30:59.0059 5272        TBS            (cdbe8d7c1e201b911cdc346d06617fb5) C:\Windows\System32\tbssvc.dll
19:30:59.0082 5272        TBS - ok
19:30:59.0179 5272        Tcpip          (46d448e9117464e4d3bbf36d7e3fa48e) C:\Windows\system32\drivers\tcpip.sys
19:30:59.0207 5272        Tcpip - ok
19:30:59.0294 5272        Tcpip6          (46d448e9117464e4d3bbf36d7e3fa48e) C:\Windows\system32\DRIVERS\tcpip.sys
19:30:59.0321 5272        Tcpip6 - ok
19:30:59.0381 5272        tcpipreg        (c7e72a4071ee0200e3c075dacfb2b334) C:\Windows\system32\drivers\tcpipreg.sys
19:30:59.0389 5272        tcpipreg - ok
19:30:59.0435 5272        TDPIPE          (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
19:30:59.0456 5272        TDPIPE - ok
19:30:59.0468 5272        TDTCP          (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
19:30:59.0490 5272        TDTCP - ok
19:30:59.0526 5272        tdx            (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys
19:30:59.0542 5272        tdx - ok
19:30:59.0575 5272        TermDD          (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys
19:30:59.0583 5272        TermDD - ok
19:30:59.0637 5272        TermService    (5cdd30bc217082dac71a9878d9bfd566) C:\Windows\System32\termsrv.dll
19:30:59.0658 5272        TermService - ok
19:30:59.0703 5272        Themes          (56793271ecdedd350c5add305603e963) C:\Windows\system32\shsvcs.dll
19:30:59.0713 5272        Themes - ok
19:30:59.0748 5272        THREADORDER    (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll
19:30:59.0769 5272        THREADORDER - ok
19:30:59.0844 5272        TomTomHOMEService (3199a477f0f06eede41bd55179f8eb05) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
19:30:59.0851 5272        TomTomHOMEService - ok
19:30:59.0889 5272        TrkWks          (f4689f05af472a651a7b1b7b02d200e7) C:\Windows\System32\trkwks.dll
19:30:59.0911 5272        TrkWks - ok
19:30:59.0967 5272        TrustedInstaller (66328b08ef5a9305d8ede36b93930369) C:\Windows\servicing\TrustedInstaller.exe
19:30:59.0983 5272        TrustedInstaller - ok
19:31:00.0020 5272        tssecsrv        (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
19:31:00.0041 5272        tssecsrv - ok
19:31:00.0053 5272        tunmp          (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
19:31:00.0061 5272        tunmp - ok
19:31:00.0080 5272        tunnel          (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys
19:31:00.0088 5272        tunnel - ok
19:31:00.0105 5272        uagp35          (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys
19:31:00.0113 5272        uagp35 - ok
19:31:00.0153 5272        udfs            (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys
19:31:00.0169 5272        udfs - ok
19:31:00.0186 5272        UI0Detect      (060507c4113391394478f6953a79eedc) C:\Windows\system32\UI0Detect.exe
19:31:00.0207 5272        UI0Detect - ok
19:31:00.0227 5272        uliagpkx        (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys
19:31:00.0235 5272        uliagpkx - ok
19:31:00.0251 5272        uliahci        (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys
19:31:00.0261 5272        uliahci - ok
19:31:00.0274 5272        UlSata          (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
19:31:00.0282 5272        UlSata - ok
19:31:00.0308 5272        ulsata2        (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
19:31:00.0316 5272        ulsata2 - ok
19:31:00.0330 5272        umbus          (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
19:31:00.0352 5272        umbus - ok
19:31:00.0370 5272        upnphost        (7093799ff80e9deca0680d2e3535be60) C:\Windows\System32\upnphost.dll
19:31:00.0412 5272        upnphost - ok
19:31:00.0456 5272        upperdev        (7168819f30fe9622284ea19bde7f8ab4) C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
19:31:00.0471 5272        upperdev - ok
19:31:00.0511 5272        usbaudio        (c6ba890de6e41857fbe84175519cae7d) C:\Windows\system32\drivers\usbaudio.sys
19:31:00.0527 5272        usbaudio - ok
19:31:00.0554 5272        usbbus          (5fcc71487888589a9244af54cfefab29) C:\Windows\system32\DRIVERS\lgx64bus.sys
19:31:00.0560 5272        usbbus - ok
19:31:00.0592 5272        usbccgp        (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys
19:31:00.0607 5272        usbccgp - ok
19:31:00.0640 5272        usbcir          (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys
19:31:00.0672 5272        usbcir - ok
19:31:00.0707 5272        UsbDiag        (3fb6e423f7567c92c32ea786f5fd0c69) C:\Windows\system32\DRIVERS\lgx64diag.sys
19:31:00.0713 5272        UsbDiag - ok
19:31:00.0726 5272        usbehci        (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys
19:31:00.0741 5272        usbehci - ok
19:31:00.0786 5272        usbhub          (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys
19:31:00.0803 5272        usbhub - ok
19:31:00.0836 5272        usbio          (5c4219c10b5887dff85e1d2779aed55b) C:\Windows\system32\Drivers\dsiarhwprog_x64.sys
19:31:00.0840 5272        usbio ( UnsignedFile.Multi.Generic ) - warning
19:31:00.0840 5272        usbio - detected UnsignedFile.Multi.Generic (1)
19:31:00.0853 5272        USBModem        (78d551f5b93488b4666f5fc8dd4815f3) C:\Windows\system32\DRIVERS\lgx64modem.sys
19:31:00.0860 5272        USBModem - ok
19:31:00.0874 5272        usbohci        (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys
19:31:00.0907 5272        usbohci - ok
19:31:00.0935 5272        usbprint        (28b693b6d31e7b9332c1bdcefef228c1) C:\Windows\system32\DRIVERS\usbprint.sys
19:31:00.0956 5272        usbprint - ok
19:31:00.0992 5272        usbscan        (ea0bf666868964fbe8cb10e50c97b9f1) C:\Windows\system32\DRIVERS\usbscan.sys
19:31:01.0008 5272        usbscan - ok
19:31:01.0041 5272        usbser          (f7386007fb19e7685fc7b298560aa81f) C:\Windows\system32\DRIVERS\usbser.sys
19:31:01.0056 5272        usbser - ok
19:31:01.0088 5272        UsbserFilt      (66c25cb20b2974e0c0cfdab49fb72a02) C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys
19:31:01.0103 5272        UsbserFilt - ok
19:31:01.0138 5272        USBSTOR        (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:31:01.0154 5272        USBSTOR - ok
19:31:01.0187 5272        usbuhci        (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys
19:31:01.0203 5272        usbuhci - ok
19:31:01.0239 5272        usb_rndisx      (1e36bb1a3c5aaf2aa9fa9a126df8c16c) C:\Windows\system32\DRIVERS\usb8023x.sys
19:31:01.0254 5272        usb_rndisx - ok
19:31:01.0293 5272        UxSms          (d76e231e4850bb3f88a3d9a78df191e3) C:\Windows\System32\uxsms.dll
19:31:01.0309 5272        UxSms - ok
19:31:01.0350 5272        vds            (294945381dfa7ce58cecf0a9896af327) C:\Windows\System32\vds.exe
19:31:01.0370 5272        vds - ok
19:31:01.0386 5272        vga            (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys
19:31:01.0407 5272        vga - ok
19:31:01.0420 5272        VgaSave        (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
19:31:01.0441 5272        VgaSave - ok
19:31:01.0457 5272        viaide          (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys
19:31:01.0464 5272        viaide - ok
19:31:01.0501 5272        volmgr          (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys
19:31:01.0511 5272        volmgr - ok
19:31:01.0576 5272        volmgrx        (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys
19:31:01.0589 5272        volmgrx - ok
19:31:01.0637 5272        volsnap        (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys
19:31:01.0648 5272        volsnap - ok
19:31:01.0681 5272        vsmraid        (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys
19:31:01.0690 5272        vsmraid - ok
19:31:01.0760 5272        VSS            (b75232dad33bfd95bf6f0a3e6bff51e1) C:\Windows\system32\vssvc.exe
19:31:01.0791 5272        VSS - ok
19:31:01.0918 5272        W32Time        (f14a7de2ea41883e250892e1e5230a9a) C:\Windows\system32\w32time.dll
19:31:01.0939 5272        W32Time - ok
19:31:01.0996 5272        WacomPen        (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
19:31:02.0028 5272        WacomPen - ok
19:31:02.0058 5272        Wanarp          (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
19:31:02.0074 5272        Wanarp - ok
19:31:02.0076 5272        Wanarpv6        (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
19:31:02.0092 5272        Wanarpv6 - ok
19:31:02.0144 5272        wcncsvc        (b4e4c37d0aa6100090a53213ee2bf1c1) C:\Windows\System32\wcncsvc.dll
19:31:02.0158 5272        wcncsvc - ok
19:31:02.0189 5272        WcsPlugInService (ea4b369560e986f19d93f45a881484ac) C:\Windows\System32\WcsPlugInService.dll
19:31:02.0205 5272        WcsPlugInService - ok
19:31:02.0217 5272        Wd              (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys
19:31:02.0224 5272        Wd - ok
19:31:02.0268 5272        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
19:31:02.0285 5272        Wdf01000 - ok
19:31:02.0297 5272        WdiServiceHost  (c5efda73ebfca8b02a094898de0a9276) C:\Windows\system32\wdi.dll
19:31:02.0319 5272        WdiServiceHost - ok
19:31:02.0321 5272        WdiSystemHost  (c5efda73ebfca8b02a094898de0a9276) C:\Windows\system32\wdi.dll
19:31:02.0343 5272        WdiSystemHost - ok
19:31:02.0393 5272        WebClient      (3e6d05381cf35f75ebb055544a8ed9ac) C:\Windows\System32\webclnt.dll
19:31:02.0404 5272        WebClient - ok
19:31:02.0448 5272        Wecsvc          (8d40bc587993f876658bf9fb0f7d3462) C:\Windows\system32\wecsvc.dll
19:31:02.0458 5272        Wecsvc - ok
19:31:02.0468 5272        wercplsupport  (9c980351d7e96288ea0c23ae232bd065) C:\Windows\System32\wercplsupport.dll
19:31:02.0485 5272        wercplsupport - ok
19:31:02.0521 5272        WerSvc          (66b9ecebc46683f47edc06333c075fef) C:\Windows\System32\WerSvc.dll
19:31:02.0537 5272        WerSvc - ok
19:31:02.0568 5272        WinDefend - ok
19:31:02.0571 5272        WinHttpAutoProxySvc - ok
19:31:02.0646 5272        Winmgmt        (d2e7296ed1bd26d8db2799770c077a02) C:\Windows\system32\wbem\WMIsvc.dll
19:31:02.0662 5272        Winmgmt - ok
19:31:02.0748 5272        WinRM          (6cbb0c68f13b9c2ec1b16f5fa5e7c869) C:\Windows\system32\WsmSvc.dll
19:31:02.0779 5272        WinRM - ok
19:31:02.0914 5272        Wlansvc        (ec339c8115e91baed835957e9a677f16) C:\Windows\System32\wlansvc.dll
19:31:02.0929 5272        Wlansvc - ok
19:31:02.0994 5272        WmiAcpi        (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\drivers\wmiacpi.sys
19:31:03.0009 5272        WmiAcpi - ok
19:31:03.0078 5272        wmiApSrv        (21fa389e65a852698b6a1341f36ee02d) C:\Windows\system32\wbem\WmiApSrv.exe
19:31:03.0094 5272        wmiApSrv - ok
19:31:03.0126 5272        WMPNetworkSvc - ok
19:31:03.0167 5272        WPCSvc          (cbc156c913f099e6680d1df9307db7a8) C:\Windows\System32\wpcsvc.dll
19:31:03.0177 5272        WPCSvc - ok
19:31:03.0207 5272        WPDBusEnum      (490a18b4e4d53dc10879deaa8e8b70d9) C:\Windows\system32\wpdbusenum.dll
19:31:03.0216 5272        WPDBusEnum - ok
19:31:03.0252 5272        WpdUsb          (5e2401b3fc1089c90e081291357371a9) C:\Windows\system32\DRIVERS\wpdusb.sys
19:31:03.0261 5272        WpdUsb - ok
19:31:03.0434 5272        WPFFontCache_v0400 (991e2c2cf3bc204c2bb2ee1476149e4e) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
19:31:03.0454 5272        WPFFontCache_v0400 - ok
19:31:03.0481 5272        ws2ifsl        (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
19:31:03.0503 5272        ws2ifsl - ok
19:31:03.0542 5272        wscsvc          (9ea3e6d0ef7a5c2b9181961052a4b01a) C:\Windows\System32\wscsvc.dll
19:31:03.0552 5272        wscsvc - ok
19:31:03.0554 5272        WSearch - ok
19:31:03.0644 5272        wuauserv        (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
19:31:03.0686 5272        wuauserv - ok
19:31:03.0829 5272        WUDFRd          (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys
19:31:03.0851 5272        WUDFRd - ok
19:31:03.0892 5272        wudfsvc        (6cbd51ff913c851d56ed9dc7f2a27dde) C:\Windows\System32\WUDFSvc.dll
19:31:03.0914 5272        wudfsvc - ok
19:31:03.0963 5272        yukonx64        (2ae06b41b36549fabf0886b2af89a599) C:\Windows\system32\DRIVERS\yk60x64.sys
19:31:03.0976 5272        yukonx64 - ok
19:31:03.0995 5272        MBR (0x1B8)    (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
19:31:04.0161 5272        \Device\Harddisk0\DR0 - ok
19:31:04.0163 5272        Boot (0x1200)  (2b6a0507950261eed5cb2e60e63274bb) \Device\Harddisk0\DR0\Partition0
19:31:04.0164 5272        \Device\Harddisk0\DR0\Partition0 - ok
19:31:04.0164 5272        ============================================================
19:31:04.0164 5272        Scan finished
19:31:04.0164 5272        ============================================================
19:31:04.0167 5400        Detected object count: 7
19:31:04.0167 5400        Actual detected object count: 7
19:31:07.0235 5400        IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
19:31:07.0235 5400        IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:31:07.0235 5400        LGDDCDevice ( UnsignedFile.Multi.Generic ) - skipped by user
19:31:07.0235 5400        LGDDCDevice ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:31:07.0236 5400        LGII2CDevice ( UnsignedFile.Multi.Generic ) - skipped by user
19:31:07.0236 5400        LGII2CDevice ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:31:07.0236 5400        PassThru Service ( UnsignedFile.Multi.Generic ) - skipped by user
19:31:07.0236 5400        PassThru Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:31:07.0237 5400        SearchAnonymizer ( UnsignedFile.Multi.Generic ) - skipped by user
19:31:07.0237 5400        SearchAnonymizer ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:31:07.0237 5400        ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
19:31:07.0237 5400        ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:31:07.0238 5400        usbio ( UnsignedFile.Multi.Generic ) - skipped by user
19:31:07.0238 5400        usbio ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 11.08.2012 19:59

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

maeusuruh 26.08.2012 14:06

So jetzt ComboFix:

Combofix Logfile:
Code:

ComboFix 12-08-25.04 - Frank 26.08.2012  14:46:09.1.2 - x64
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.8190.5964 [GMT 2:00]
ausgeführt von:: c:\users\Frank\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Frank\AppData\Roaming\7910.org
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\pthreadVC.dll
c:\windows\SysWow64\wpcap.dll
.
.
(((((((((((((((((((((((((((((((((((((((  Treiber/Dienste  )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_npf
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-07-26 bis 2012-08-26  ))))))))))))))))))))))))))))))
.
.
2012-08-25 13:05 . 2012-08-25 13:05        --------        d-----w-        c:\program files (x86)\AMD APP
2012-08-24 08:34 . 2012-08-01 22:58        9309624        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{A6E49A0C-66D8-4CB7-B6AD-51D4628C46FB}\mpengine.dll
2012-08-24 08:32 . 2012-08-24 08:32        --------        d-----w-        c:\programdata\McAfee Security Scan
2012-08-24 08:32 . 2012-08-24 08:32        --------        d-----w-        c:\program files (x86)\McAfee Security Scan
2012-08-16 19:09 . 2000-01-04 04:39        212992        ----a-w-        c:\program files (x86)\Common Files\InstallShield\engine\6\Intel 32\ILog.dll
2012-08-15 16:35 . 2012-05-11 16:34        788480        ----a-w-        c:\windows\system32\localspl.dll
2012-08-15 16:35 . 2012-05-11 15:57        623616        ----a-w-        c:\windows\SysWow64\localspl.dll
2012-08-15 16:35 . 2012-06-29 16:20        648192        ----a-w-        c:\windows\system32\netapi32.dll
2012-08-10 16:54 . 2012-08-10 16:54        --------        d-----w-        c:\users\Frank\AppData\Roaming\Party
2012-08-08 20:59 . 2012-08-08 20:59        --------        d-----w-        C:\_OTL
2012-07-29 21:10 . 2012-07-29 21:37        --------        d-----w-        c:\users\Frank\AppData\Roaming\Audacity
2012-07-29 21:09 . 2012-07-29 21:09        --------        d-----w-        c:\program files (x86)\Audacity
2012-07-27 20:47 . 2012-07-27 20:47        187392        ----a-w-        c:\windows\system32\clinfo.exe
2012-07-27 20:47 . 2012-07-27 20:47        75776        ----a-w-        c:\windows\system32\OpenVideo64.dll
2012-07-27 20:47 . 2012-07-27 20:47        65024        ----a-w-        c:\windows\SysWow64\OpenVideo.dll
2012-07-27 20:47 . 2012-07-27 20:47        63488        ----a-w-        c:\windows\system32\OVDecode64.dll
2012-07-27 20:47 . 2012-07-27 20:47        56320        ----a-w-        c:\windows\SysWow64\OVDecode.dll
2012-07-27 20:46 . 2012-07-27 20:46        16464896        ----a-w-        c:\windows\system32\amdocl64.dll
2012-07-27 20:46 . 2012-07-27 20:46        13013504        ----a-w-        c:\windows\SysWow64\amdocl.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-25 20:37 . 2009-07-11 14:13        283304        ----a-w-        c:\windows\SysWow64\PnkBstrB.exe
2012-08-25 20:37 . 2009-07-11 14:13        283304        ----a-w-        c:\windows\SysWow64\PnkBstrB.xtr
2012-08-25 20:36 . 2009-07-11 14:13        280904        ----a-w-        c:\windows\SysWow64\PnkBstrB.ex0
2012-08-24 08:32 . 2012-03-30 15:07        696520        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-24 08:32 . 2011-05-17 10:35        73416        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-15 20:59 . 2006-11-02 12:35        62134624        ----a-w-        c:\windows\system32\mrt.exe
2012-07-07 20:44 . 2012-07-07 20:44        476936        ----a-w-        c:\windows\SysWow64\npdeployJava1.dll
2012-07-07 20:44 . 2010-04-21 21:06        472840        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2012-07-07 11:06 . 2012-07-07 11:06        1207568        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2012-07-03 11:46 . 2012-07-07 14:06        24904        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-06-25 14:04 . 2012-06-25 14:04        1394248        ----a-w-        c:\windows\SysWow64\msxml4.dll
2012-06-13 10:25 . 2012-01-04 11:45        499712        ----a-w-        c:\windows\SysWow64\msvcp71.dll
2012-06-13 10:25 . 2012-01-04 11:45        348160        ----a-w-        c:\windows\SysWow64\msvcr71.dll
2012-06-08 17:59 . 2012-07-12 10:48        12899840        ----a-w-        c:\windows\system32\shell32.dll
2012-06-05 16:47 . 2012-07-12 10:48        1401856        ----a-w-        c:\windows\SysWow64\msxml6.dll
2012-06-05 16:47 . 2012-07-12 10:48        1248768        ----a-w-        c:\windows\SysWow64\msxml3.dll
2012-06-05 16:22 . 2012-07-12 10:48        1797120        ----a-w-        c:\windows\system32\msxml6.dll
2012-06-05 16:22 . 2012-07-12 10:48        1869824        ----a-w-        c:\windows\system32\msxml3.dll
2012-06-04 15:29 . 2012-07-12 10:48        516480        ----a-w-        c:\windows\system32\drivers\ksecdd.sys
2012-06-02 22:19 . 2012-06-22 14:57        38424        ----a-w-        c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-22 14:57        2428952        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-22 14:57        57880        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-22 14:57        44056        ----a-w-        c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-22 14:57        35864        ----a-w-        c:\windows\SysWow64\wups.dll
2012-06-02 22:19 . 2012-06-22 14:57        701976        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-22 14:57        577048        ----a-w-        c:\windows\SysWow64\wuapi.dll
2012-06-02 22:15 . 2012-06-22 14:57        2622464        ----a-w-        c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-22 14:57        99840        ----a-w-        c:\windows\system32\wudriver.dll
2012-06-02 22:12 . 2012-06-22 14:57        88576        ----a-w-        c:\windows\SysWow64\wudriver.dll
2012-06-02 13:19 . 2012-06-22 14:56        186752        ----a-w-        c:\windows\system32\wuwebv.dll
2012-06-02 13:19 . 2012-06-22 14:56        171904        ----a-w-        c:\windows\SysWow64\wuwebv.dll
2012-06-02 13:15 . 2012-06-22 14:56        36864        ----a-w-        c:\windows\system32\wuapp.exe
2012-06-02 13:12 . 2012-06-22 14:56        33792        ----a-w-        c:\windows\SysWow64\wuapp.exe
2012-06-02 00:22 . 2012-07-12 10:48        347136        ----a-w-        c:\windows\system32\schannel.dll
2012-06-02 00:22 . 2012-07-12 10:48        254464        ----a-w-        c:\windows\system32\ncrypt.dll
2012-06-02 00:05 . 2012-07-12 10:48        77312        ----a-w-        c:\windows\SysWow64\secur32.dll
2012-06-02 00:04 . 2012-07-12 10:48        278528        ----a-w-        c:\windows\SysWow64\schannel.dll
2012-06-02 00:03 . 2012-07-12 10:48        204288        ----a-w-        c:\windows\SysWow64\ncrypt.dll
2012-05-31 10:25 . 2009-10-03 07:56        279656        ------w-        c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2009-06-23 32768]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"TomTomHOME.exe"="c:\program files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [2012-01-23 247728]
"MsgCenterExe"="c:\program files (x86)\Real\RealPlayer\update\RealOneMessageCenter.exe" [2012-06-13 79008]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-04-05 641664]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-18 421888]
"TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2012-06-13 296056]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2009-6-23 450560]
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528]
SetPointII.lnk - c:\program files\Logitech\SetPoint II\SetPointII.exe [2009-7-21 815104]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-24 250568]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
Themes
.
Inhalt des "geplante Tasks" Ordners
.
2012-08-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 08:32]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateUSB"="c:\windows\inf\UpdateUSB.exe" [2006-06-23 30720]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2007-12-10 323584]
"PACTray"="c:\windows\Pixart\PAC7302\PACTray.exe" [2009-03-23 327680]
"Ocs_SM"="c:\users\Frank\AppData\Roaming\OCS\SM\SearchAnonymizer.exe" [2011-12-26 106496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Free YouTube to MP3 Converter - c:\users\Frank\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~1\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.178.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\8ghejrb4.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/index.php?lh=b5f1416c11cd4baa3a997c8bfe9cb4b1&eu=IfFOcEYGRYwiAU8TS6GVAw
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-WMPNSCFG - c:\program files (x86)\Windows Media Player\WMPNSCFG.exe
HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1827684769-3620193026-1381853637-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:19,cd,6f,4b,8a,ad,6c,11,28,5c,3f,5e,6e,8b,6a,d5,1c,45,5e,27,e2,c8,70,
  0b,30,5f,02,bf,1b,82,0a,63,8d,12,fc,06,dc,b0,73,f4,99,bc,11,7a,b6,ed,d0,8e,\
"??"=hex:e5,ad,92,d7,17,59,ff,7b,b2,3c,83,ad,21,1c,95,98
.
[HKEY_USERS\S-1-5-21-1827684769-3620193026-1381853637-1000\Software\SecuROM\License information*]
"datasecu"=hex:60,f4,00,a8,6e,dd,51,b5,0c,60,5b,44,ba,90,ac,c2,4f,95,23,cf,8c,
  20,5c,3f,70,11,8a,30,a4,c9,89,59,1c,00,ed,6b,0d,8e,7b,dd,62,73,5d,9c,02,9f,\
"rkeysecu"=hex:8d,a3,d1,e2,14,c0,a3,3b,df,1d,96,7f,f6,6c,2a,83
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\sched.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-08-26  14:58:41 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-08-26 12:58
.
Vor Suchlauf: 21 Verzeichnis(se), 516.805.058.560 Bytes frei
Nach Suchlauf: 24 Verzeichnis(se), 517.435.564.032 Bytes frei
.
- - End Of File - - 5790DEC2D74861571267E19E0533B4BF

--- --- ---


Bin jetzt auch nochmal im Urlaub, kann also etwas dauern, bis ich mich melde!

Schöne Grüße
Claudia

cosinus 30.08.2012 18:41

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

maeusuruh 25.09.2012 21:15

Hallo cosinus!

So jetzt machen wir es wieder zügiger, entschuldige das es so lang jetzt gedauert hat, hab grad etwas Probleme privat!

Also GMER ging:

GMER Logfile:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-09-22 20:20:53
Windows 6.0.6002 Service Pack 2
Running: y26fm7dr.exe


---- Registry - GMER 1.0.15 ----

Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                                   
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                  C:\Program Files (x86)\DAEMON Tools Lite\
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                  0
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                              0xE1 0xAC 0xF9 0x3C ...
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001                           
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                        0x20 0x01 0x00 0x00 ...
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                      0x64 0x6F 0x48 0xF7 ...
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40                     
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                0x9B 0x49 0xAB 0xAD ...
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)               
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                      C:\Program Files (x86)\DAEMON Tools Lite\
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                      0
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                  0xE1 0xAC 0xF9 0x3C ...
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)       
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                            0x20 0x01 0x00 0x00 ...
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                          0x64 0x6F 0x48 0xF7 ...
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) 
Reg  HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                    0x9B 0x49 0xAB 0xAD ...

---- EOF - GMER 1.0.15 ----

--- --- ---



OSAM hab ich ausgeführt wie in der Beschreibung, nur wenn ich zum Schluss auf Save log klicke, dann passiert nix mehr! Es geht kein weiteres Fenster auf!

Was soll ich machen?

LG Claudia

cosinus 26.09.2012 13:49

Du hast ein 64-Bit-Vista? Ich glaub da haut OSAM nicht hin, lass das einfach aus, also nur GMER und aswMBR machen :)

maeusuruh 26.09.2012 20:24

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-26 20:38:56
-----------------------------
20:38:56.460    OS Version: Windows x64 6.0.6002 Service Pack 2
20:38:56.460    Number of processors: 2 586 0x170A
20:38:56.460    ComputerName: ADMIN-PC  UserName: Frank
20:38:57.762    Initialize success
20:40:29.082    AVAST engine defs: 12092600
20:40:46.297    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-4
20:40:46.299    Disk 0 Vendor: Hitachi_HDT721010SLA360 ST6OA31B Size: 953869MB BusType: 3
20:40:46.308    Disk 0 MBR read successfully
20:40:46.309    Disk 0 MBR scan
20:40:46.323    Disk 0 Windows VISTA default MBR code
20:40:46.333    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS      953867 MB offset 2048
20:40:46.356    Disk 0 scanning C:\Windows\system32\drivers
20:40:57.578    Service scanning
20:41:24.200    Modules scanning
20:41:24.203    Disk 0 trace - called modules:
20:41:24.216    ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
20:41:24.218    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008e03520]
20:41:24.219    3 CLASSPNP.SYS[fffffa6000fd0c33] -> nt!IofCallDriver -> [0xfffffa80078e0520]
20:41:24.222    5 acpi.sys[fffffa60008c0fde] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-4[0xfffffa80078dd060]
20:41:25.629    AVAST engine scan C:\Windows
20:41:29.869    AVAST engine scan C:\Windows\system32
20:44:49.049    AVAST engine scan C:\Windows\system32\drivers
20:45:03.772    AVAST engine scan C:\Users\Frank
21:16:56.652    AVAST engine scan C:\ProgramData
21:18:34.859    Scan finished successfully
21:21:17.379    Disk 0 MBR has been saved successfully to "C:\Users\Frank\Desktop\MBR.dat"
21:21:17.382    The log file has been saved successfully to "C:\Users\Frank\Desktop\aswMBR.txt"

Wieviel müssen wir denn eigentlich noch machen?? Eigentlich funktioniert wieder alles wie früher!?? :)

cosinus 27.09.2012 15:30

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

maeusuruh 28.09.2012 17:28

Code:

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.28.03

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Frank :: ADMIN-PC [Administrator]

28.09.2012 10:30:39
mbam-log-2012-09-28 (10-30-39).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 501484
Laufzeit: 1 Stunde(n), 49 Minute(n), 11 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 09/28/2012 at 08:07 PM

Application Version : 5.5.1022

Core Rules Database Version : 9309
Trace Rules Database Version: 7121

Scan type      : Complete Scan
Total Scan Time : 01:27:05

Operating System Information
Windows Vista Home Premium 64-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Administrator

Memory items scanned      : 710
Memory threats detected  : 0
Registry items scanned    : 66836
Registry threats detected : 0
File items scanned        : 92589
File threats detected    : 89

Adware.Tracking Cookie
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\RTF9INOW.txt [ /zanox.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\Y5ZEWJH5.txt [ /2o7.net ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\3J7ULRIV.txt [ /fastclick.net ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\5A2ZM7JX.txt [ /atdmt.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\A8IQ1PXO.txt [ /apmebf.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\39JAFKM2.txt [ /mediaplex.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\WTF34L17.txt [ /c.atdmt.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\X7OY8HI0.txt [ /invitemedia.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\HKPJFTOX.txt [ /ad.zanox.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\XX340VMU.txt [ /ads.creative-serving.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\JA8QPVL6.txt [ /doubleclick.net ]
        C:\USERS\FRANK\AppData\Roaming\Microsoft\Windows\Cookies\Low\YF93YJOR.txt [ Cookie:frank@ad3.adfarm1.adition.com/ ]
        C:\USERS\FRANK\AppData\Roaming\Microsoft\Windows\Cookies\Low\7PSF31X3.txt [ Cookie:frank@doubleclick.net/ ]
        C:\USERS\FRANK\Cookies\RTF9INOW.txt [ Cookie:frank@zanox.com/ ]
        C:\USERS\FRANK\Cookies\Y5ZEWJH5.txt [ Cookie:frank@2o7.net/ ]
        C:\USERS\FRANK\Cookies\5A2ZM7JX.txt [ Cookie:frank@atdmt.com/ ]
        C:\USERS\FRANK\Cookies\39JAFKM2.txt [ Cookie:frank@mediaplex.com/ ]
        C:\USERS\FRANK\Cookies\WTF34L17.txt [ Cookie:frank@c.atdmt.com/ ]
        C:\USERS\FRANK\Cookies\X7OY8HI0.txt [ Cookie:frank@invitemedia.com/ ]
        C:\USERS\FRANK\Cookies\HKPJFTOX.txt [ Cookie:frank@ad.zanox.com/ ]
        C:\USERS\FRANK\Cookies\JA8QPVL6.txt [ Cookie:frank@doubleclick.net/ ]
        cdn1.static.youporn.phncdn.com [ C:\USERS\FRANK\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\955HJEDP ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@AD.YIELDMANAGER[1].TXT [ /AD.YIELDMANAGER ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@PARTYGAMING.122.2O7[1].TXT [ /PARTYGAMING.122.2O7 ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@PARTYPOKER[1].TXT [ /PARTYPOKER ]
        .2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .kabeldeutschland.122.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .partygaming.122.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .sevenoneintermedia.112.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .msnportal.112.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .aolde.122.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        eulge.acecounter.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .lgeeurope.122.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        eulge.acecounter.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .microsoftwindows.112.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        clicks.pangora.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        clicks.pangora.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        clicks.pangora.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        clicks.pangora.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .track.asus.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .track.asus.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        track.asus.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        eulge.acecounter.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        adserver.71i.de [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .paypal.112.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .doccheckag.122.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-Autorun[Swisyn]
        C:\PROGRAM FILES (X86)\ELABORATE BYTES\CLONEDVD2\KEYGEN.EXE




Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 09/28/2012 at 08:07 PM

Application Version : 5.5.1022

Core Rules Database Version : 9309
Trace Rules Database Version: 7121

Scan type      : Complete Scan
Total Scan Time : 01:27:05

Operating System Information
Windows Vista Home Premium 64-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Administrator

Memory items scanned      : 710
Memory threats detected  : 0
Registry items scanned    : 66836
Registry threats detected : 0
File items scanned        : 92589
File threats detected    : 89

Adware.Tracking Cookie
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\RTF9INOW.txt [ /zanox.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\Y5ZEWJH5.txt [ /2o7.net ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\3J7ULRIV.txt [ /fastclick.net ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\5A2ZM7JX.txt [ /atdmt.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\A8IQ1PXO.txt [ /apmebf.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\39JAFKM2.txt [ /mediaplex.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\WTF34L17.txt [ /c.atdmt.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\X7OY8HI0.txt [ /invitemedia.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\HKPJFTOX.txt [ /ad.zanox.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\XX340VMU.txt [ /ads.creative-serving.com ]
        C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Cookies\JA8QPVL6.txt [ /doubleclick.net ]
        C:\USERS\FRANK\AppData\Roaming\Microsoft\Windows\Cookies\Low\YF93YJOR.txt [ Cookie:frank@ad3.adfarm1.adition.com/ ]
        C:\USERS\FRANK\AppData\Roaming\Microsoft\Windows\Cookies\Low\7PSF31X3.txt [ Cookie:frank@doubleclick.net/ ]
        C:\USERS\FRANK\Cookies\RTF9INOW.txt [ Cookie:frank@zanox.com/ ]
        C:\USERS\FRANK\Cookies\Y5ZEWJH5.txt [ Cookie:frank@2o7.net/ ]
        C:\USERS\FRANK\Cookies\5A2ZM7JX.txt [ Cookie:frank@atdmt.com/ ]
        C:\USERS\FRANK\Cookies\39JAFKM2.txt [ Cookie:frank@mediaplex.com/ ]
        C:\USERS\FRANK\Cookies\WTF34L17.txt [ Cookie:frank@c.atdmt.com/ ]
        C:\USERS\FRANK\Cookies\X7OY8HI0.txt [ Cookie:frank@invitemedia.com/ ]
        C:\USERS\FRANK\Cookies\HKPJFTOX.txt [ Cookie:frank@ad.zanox.com/ ]
        C:\USERS\FRANK\Cookies\JA8QPVL6.txt [ Cookie:frank@doubleclick.net/ ]
        cdn1.static.youporn.phncdn.com [ C:\USERS\FRANK\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\955HJEDP ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@AD.YIELDMANAGER[1].TXT [ /AD.YIELDMANAGER ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@PARTYGAMING.122.2O7[1].TXT [ /PARTYGAMING.122.2O7 ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@PARTYPOKER[1].TXT [ /PARTYPOKER ]
        .2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .kabeldeutschland.122.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .partypoker.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .partygaming.122.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .sevenoneintermedia.112.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .msnportal.112.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .aolde.122.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        eulge.acecounter.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .lgeeurope.122.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        eulge.acecounter.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .microsoftwindows.112.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        clicks.pangora.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        clicks.pangora.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        clicks.pangora.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        clicks.pangora.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .track.asus.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .track.asus.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        track.asus.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        eulge.acecounter.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        adserver.71i.de [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .paypal.112.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .doccheckag.122.2o7.net [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XS25SKWJ.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-Autorun[Swisyn]
        C:\PROGRAM FILES (X86)\ELABORATE BYTES\CLONEDVD2\KEYGEN.EXE

Habe bei dem letzten SuperAntiSpyware leider vergessen die Häkchen bei ein paar Sachen rauszunehmen (bei der Scan-Kontrolle waren glaub ich 3 Häkchen zuviel drin).
Und zum Schluss hat er mich glaub ich gefragt, ob er die Funde in Quarantäne stecken soll, das hat er glaub ich auch gemacht. Aber bei rebooten ja oder später hab ich abgebrochen (mit x oben rechts)!
Sorry! Danach noch einmal SASpyware laufen lassen mit den richtigen Häkchen, da hat er nix mehr gefunden.
Hoffentlich haben wir es bald, sonst mach ich noch mehr kaputt als du reparieren kannst! :)
Gruß - Claudia

Sorry, es ist schon zu spät für mich! :stirn:
Der zweite Scan von SuperAntiSpyware läuft gerade und hat auch was gefunden!
Wenn er gleich fertig ist, dann schick ich ihn dir!
Claudia

So das ist der zweite Scan, er hat noch mehr gefunden. Hoffe ich mach nix falsch, wenn ich das in Quarantäne setz!??? Und er lässt mich nur auf Remove Threads drücken! Ahhhhhhh!



Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 09/29/2012 at 00:57 AM

Application Version : 5.5.1022

Core Rules Database Version : 9309
Trace Rules Database Version: 7121

Scan type      : Complete Scan
Total Scan Time : 04:31:24

Operating System Information
Windows Vista Home Premium 64-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Administrator

Memory items scanned      : 720
Memory threats detected  : 0
Registry items scanned    : 66836
Registry threats detected : 0
File items scanned        : 300841
File threats detected    : 115

Adware.Tracking Cookie
        .apmebf.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .unrulymedia.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        fr.sitestat.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        fr.sitestat.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        aa.adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        in.getclicky.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        www.youporn.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        de.youporn.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .tracker.vinsight.de [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        tracking.affiliates.de [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        tracking.affiliates.de [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        tracking.sim-technik.de [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        media.antenne-bayern.de [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .deutschepostag.112.2o7.net [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        de.youporn.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        track.zalando.de [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        stats.crsend.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        stats.crsend.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        stats.crsend.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .eaeacom.112.2o7.net [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\FRANK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8GHEJRB4.DEFAULT\COOKIES.SQLITE ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@SEVENONEINTERMEDIA.112.2O7[1].TXT [ /SEVENONEINTERMEDIA.112.2O7 ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@SECURE.PARTYACCOUNT[3].TXT [ /SECURE.PARTYACCOUNT ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@SECURE.PARTYACCOUNT[7].TXT [ /SECURE.PARTYACCOUNT ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@SECURE.PARTYACCOUNT[4].TXT [ /SECURE.PARTYACCOUNT ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@SECURE.PARTYACCOUNT[5].TXT [ /SECURE.PARTYACCOUNT ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@SECURE.PARTYACCOUNT[6].TXT [ /SECURE.PARTYACCOUNT ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@SECURE.PARTYACCOUNT[2].TXT [ /SECURE.PARTYACCOUNT ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@EARLYEXPERIENCE.PARTYACCOUNT[2].TXT [ /EARLYEXPERIENCE.PARTYACCOUNT ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\ADMIN@ATWOLA[1].TXT [ /ATWOLA ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ADMIN@DOUBLECLICK[1].TXT [ /DOUBLECLICK ]
        C:\WINDOWS.OLD\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ADMIN@ADTECH[2].TXT [ /ADTECH ]


maeusuruh 16.10.2012 15:23

Hallo Cosinus!

Wie schaut es aus, sind wir fertig? :taenzer:

Kann ich dann die ganzen Dateien auf meinem Desktop löschen?
Und den Malewarebytes muss ich deinstallieren oder?

Gruß Claudia

cosinus 17.10.2012 11:58

Code:

Trojan.Agent/Gen-Autorun[Swisyn]
        C:\PROGRAM FILES (X86)\ELABORATE BYTES\CLONEDVD2\KEYGEN.EXE

Eigentlich ist bei sowas hier Schluss!! :pfui:
Warum verwendest du so einen Dreck?

maeusuruh 17.10.2012 12:40

Sorry, hab dir ja schon gesagt, ich hab nicht so viel Ahnung von Computer und so. Das hatte ich mal runtergeladen anscheinend, nicht kapiert, gelassen, und jetzt ist es halt noch auf dem Compi!
Hab grad nachgeschaut: der Ordner ist leer und erstellt von Januar 2010.
Da wollt ich ne Aerobic-DVD von mir kopieren, aber das ging nicht und dann hab ich es lassen.

Also machen wir jetzt nichts mehr?

Gruß Claudia

cosinus 17.10.2012 12:56

Nein du hast Glück gehabt weil wir mit der Bereinigung durch sind und der keygen zum Schluss erst auffiel. Lösch den Kram und lass in Zukunft die Finger davon! :nono:


Sieht ansonsten ok aus, da wurden nur Cookies gefunden, die können alle weg.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

maeusuruh 17.10.2012 15:35

Der Keygen ist schon gelöscht!!!!!
Ansonsten macht mein System keinerlei Anstalten! Gott sei dank!

Vielen Dank für die Hilfe und danke nochmal für die Tipps mit den Cookies, ich werd sie mir mal anschauen!

Gruß Claudia

cosinus 17.10.2012 16:13

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 21:04 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131