Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Laptop plötzlich langsam geworden (https://www.trojaner-board.de/126318-laptop-ploetzlich-langsam-geworden.html)

VHSK 30.10.2012 21:25

Laptop plötzlich langsam geworden
 
Nachdem ich vor einiger Zeit auf unbekannten Internetseiten mit Firefox unterwegs war (kann schon ein Monat her sein, hab mich seit dem noch nicht weiter drum gekümmert), ist mein Laptop plötzlich total langsam geworden. Habs dann erst mal mit einem Neustart durch gedrückt-halten der POWER-taste versucht, danach konnte ich ihn ein paar mal nicht hochfahren, weil er bei dem "Willkommen"-Bildschirm hängen geblieben ist. Beim dritten mal hats dann seitdem geklappt, allerdings ist er immer noch total langsam geblieben... (Braucht Minuten um kleinste Programme zu öffnen, hängt dir Programme oft auf, wenn man auf eine Schaltfläche drückt etc.)
WLAN funktioniert meistens.
Habe dann die Virussoftware von Windows heruntergeladen (ka wie ich das noch geschafft habe - ne menge Geduld ;))
Hatte vorher die kostenlose Version von AVG.
AVG kann ich weder deinstallieren noch aktualisieren (ist noch die 2012er Version..)

Hilfe?

DANKE,
VHSK

ryder 31.10.2012 11:30

:hallo:

Ich habe dein Thema in Arbeit und melde mich so schnell als möglich mit weiteren Anweisungen.

Bitte beachte, dass alle meine Antworten zuerst von einem Ausbilder freigegeben werden müssen, bevor ich diese hier posten darf. Dies garantiert, dass Du Hilfe von einem ausgebildeten Helfer bekommst.

Ich bedanke mich für deine Geduld :)

ryder 01.11.2012 09:49

:hallo:

Ich werde dir bei deinem Problem helfen. Eine Bereinigung ist mitunter mit viel Arbeit für Dich (und mich) verbunden. Bevor es los geht, habe ich etwas Lesestoff für dich.
Zitat:

Lesestoff:
Regeln für die Bereinigung
Damit die Bereinigung funktioniert bitte ich dich, die folgenden Punkte aufmerksam zu lesen:
  • Bitte arbeite alle Schritte der Reihe nach ab. Gib mir bitte zu jedem Schritt Rückmeldung (Logfile oder Antwort).
  • Nur Scanns durchführen zu denen Du von einem Helfer aufgefordert wirst.
  • Bitte kein Crossposting (posten in mehreren Foren).
  • Installiere oder Deinstalliere während der Bereinigung keine Software, ausser Du wurdest dazu aufgefordert.
  • Lese Dir die Anleitung zuerst vollständig durch. Sollte etwas unklar sein, frage bevor Du beginnst.
  • Poste die Logfiles direkt in deinen Thread (möglichst in Code-Tags). Nicht anhängen ausser ich fordere Dich dazu auf. Erschwert mir nämlich das auswerten.
  • Mache deinen Namen nur dann unkenntlich, wenn es unbedingt sein muss.
  • Sollte ich nicht nach 3 Tagen geantwortet haben, dann (und nur dann) schicke mir bitte eine PM.
  • Eine Bitte: Mache bitte solange mit, bis ich oder ein anderer Helfer dir mitteilt, dass du "sauber" bist. Das gebietet alleine schon die Höflichkeit und ein Verschwinden der Symptome bedeutet nicht, dass die Schädlinge auch wirklich alle entfernt wurden.
  • Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist meist der Schnellere und immer der sicherste Weg.
Wenn du das alles gelesen und verstanden hast, kannst du loslegen! :kloppen:


Schritt 1:
Laufwerksemulationen abschalten mit Defogger
Downloade Dir bitte defogger von jpshortstuff auf Deinem Desktop und starte es:
  • Klicke nun auf den Disable Button, um die Treiber gewisser Emulatoren zu deaktivieren.
  • Defogger wird dich fragen "Defogger will forcefully ... Continue?" bestätige dies mit Ja.
  • Wenn der Scan beendet wurde (Finished), klicke auf OK.
  • Defogger fordert gegebenfalls zum Neustart auf. Bestätige dies mit OK.
Poste bitte die defogger_disable.txt von deinem Desktop.
Klicke den Re-enable Button nicht ohne Anweisung.
Schritt 2:
Customscan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

activex
netsvcs
msconfig
drivers32
safebootminimal
safebootnetwork
%SYSTEMDRIVE%\*.
%SYSTEMDRIVE%\*.*
%PROGRAMFILES%\*.exe
%PROGRAMFILES(X86)%\*.exe
%systemroot%\*. /mp /s
%windir%\installer\*. /10
%appdata%\*.
%appdata%\*.*
%appdata%\*.exe /s
%localappdata%\*.
%localappdata%\*.*
%localappdata%\*.exe /s
%allusersprofile%\*.
%allusersprofile%\*.*
%allusersprofile%\*.exe /s
CREATERESTOREPOINT

  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Kopiere nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread (möglichst in CODE-Tags)
Schritt 3:
Scan mit dem TDSS-Killer

Lese bitte folgende Anweisungen genau. Wir wollen hier noch nichts "fixen" sondern nur einen Scan Report sehen.

Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe
  • Klicke auf Change parameters, setze einen Haken bei Detect TDLFS file system und bestätige mit OK.
  • Drücke Start Scan
  • Warnung:
    Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und speichere das Logfile.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern ( Meistens C:\ )
    Als Beispiel: C:\TDSSKiller.<version_date_time>log.txt
Poste den Inhalt bitte hier in deinen Thread.

VHSK 01.11.2012 12:40

Vielen Dank schonmal für die Hilfe, das ist echt ein toller Service! Bevor ich jedoch unnötigen Aufwand verursache: Was passiert bei der Formatierung mit meinen a) Daten b) istallierten Programmen c) Einstellungen bzw. welche Möglichkeiten gibt es, sie wieder herzustellen? (Wo liegt der unterschied zur Systemwiederherstellung?)

Die beschriebene Anleitung gestaltet sich nämlich schon jetzt sehr schwierig, da ich nicht einmal einen Browser geöffnet bekomme... :(

ryder 01.11.2012 13:44

Tag.

Formatierung ... ganz einfach - ALLES futsch.
Systemwiederherstellung setzt dich auf einen alten Zustand zurück, allerdings nur, wenn auch ein Wiederherstellungpunkt da ist. Das macht auch nur Sinn, wenn dieser frühere Zeitpunkt schädlingsfrei ist.

Wenn du Neuaufsetzen willst, dann sollltest du vorher alle Daten sichern. Danach kannst du deine Programme alle wieder installieren und deine Einstellungen vornehmen.

Wir haben aber gute Chancen, deinen Rechner auch ohne das sauber zu bekommen. Es liegt an dir :)

VHSK 01.11.2012 16:33

Nun gut, dann versuch ich das wohl mal :)

VHSK 02.11.2012 00:30

Mit ewiger Geduld: Die Datei des ersten Schrittes...

ryder 02.11.2012 09:56

Hier ein paar Tipps zwischendurch, die dir vielleicht helfen:
  • Wenn es zeitlich am Herunterladen deiner Daten liegt, dann lade dir die Tools in der Nachbarschaft auf einen USB-Stick.
  • Ich habe es oft erlebt, dass so ein Laptop auch einfach nur gestreikt hat, weil er einfach verdreckt war. Staubsauger nehmen, auf geringste Stufe schalten und mal die Lüftungsschlitze vorsichtig ansaugen. Gelegentlich hilft das.
Zitat:

Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

VHSK 03.11.2012 01:37

Hmm, hört sich komisch an (mit dem verdrecken) aber ich probiers mal... Lohnt sich ein oberflächliches auseinanderschrauben?

War das log-file aus Schritt 1 denn jetzt in Ordnung oder soll ich es nochmal als Code-Tag posten? (Außerdem hat es mich gewundert, dass der scan als log-file ausgespuckt wurde und nicht wie oben beschrieben als txt.. und nach einem Neustart wurde ich ebenfalls nicht gefragt)

Beim Quick-Scan des zweiten Schrittes trat nun zum zweiten mal das Problem auf, dass sich das Programm (nach längerer Wartezeit; bin zwischendurch weggegangen) aufgehängt hat. In der Statusleiste stand dann glaube ich immer, dass es nach der OTL-Datei sucht..

LG

OK,Schritt 2 hat nun auch funktioniert (zwischendurch hat sich nur leider AVG kurz geöffnet, falls das ein Problem ist).

Code:

OTL Extras logfile created on: 11/3/2012 8:48:42 AM - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Vincent\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.80 Gb Total Physical Memory | 2.43 Gb Available Physical Memory | 63.87% Memory free
7.60 Gb Paging File | 6.04 Gb Available in Paging File | 79.43% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 296.09 Gb Total Space | 223.05 Gb Free Space | 75.33% Space Free | Partition Type: NTFS
 
Computer Name: LIFEBOOK-A530 | User Name: Vincent | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- Reg Error: Key error. File not found
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- Reg Error: Key error.
htmlfile [opennew] -- Reg Error: Key error.
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L"
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error.
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- Reg Error: Key error.
htmlfile [opennew] -- Reg Error: Key error.
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L"
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06517A4C-6C62-401A-8E91-D41A09061C6F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{0D4D04C0-CA38-490E-90F6-32FBA94A1686}" = rport=445 | protocol=6 | dir=out | app=system |
"{189D8DB0-7017-48F0-828B-06E4AEF97ACC}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{1A6DA632-8932-4D8E-821D-B4D1D0EB9B30}" = lport=2869 | protocol=6 | dir=in | app=system |
"{2132BBD5-4FA7-42DE-BF76-E44921B89E4D}" = lport=137 | protocol=17 | dir=in | app=system |
"{27E3F124-2E6B-43EA-9F07-74B0C6E348B6}" = lport=139 | protocol=6 | dir=in | app=system |
"{40F719D8-2B6F-4BB2-B0C4-08337FF9C32E}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{4433C892-845A-49DA-A4DF-FD0322FEAEC8}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{5DA860F1-C8EE-47AD-A6C3-911BEBEF3C4F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{611A57EC-60D8-4D91-926B-C6595C84A21F}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{6698C6A4-F783-4EB3-B106-7D9E79112799}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7439BCE0-9A22-4CB7-BBA2-851354B7EC62}" = rport=2869 | protocol=6 | dir=out | app=system |
"{874C2793-B1C9-47B3-BF3C-5B41C02251D7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8980F0A2-DBBA-4D81-9C72-9FD722019A6D}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{9F9CEE7C-26A8-4BA0-95CF-B26724FA62B4}" = rport=137 | protocol=17 | dir=out | app=system |
"{A295289A-E42B-4C33-B829-9961676B8BF0}" = rport=139 | protocol=6 | dir=out | app=system |
"{A81510E5-5DD8-40B1-9BAE-F4D7CF24EAF2}" = rport=138 | protocol=17 | dir=out | app=system |
"{C3C1F8C7-38F2-419A-8E37-2D59974BA88F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{C78DC077-C570-45EC-8146-C4684D13D2C8}" = lport=445 | protocol=6 | dir=in | app=system |
"{CA21798B-A6AF-4730-B5F1-8D4358946E63}" = lport=138 | protocol=17 | dir=in | app=system |
"{DA5B0E84-A825-4EB9-9E13-DB7FE1F59065}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{EABC39CB-4550-41E8-A471-C5DFBCCD9C31}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{EDC4FD74-D797-49B5-A34B-692B957DB9D7}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03C1C032-0883-446A-8BCF-DF462821DC55}" = protocol=6 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\tvtvsetup\tvtv_wizard.exe |
"{0AD0DCDB-819A-4947-8262-64EF4F99846D}" = protocol=6 | dir=in | app=c:\users\vincent\desktop\sweetimsetup.exe |
"{0B5802DD-886F-45E7-A341-BCFF65F6441D}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{1093DFD5-CC11-47D4-8CAD-5CDBEF232F34}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{13215DB6-A62F-4B08-8931-6FF5B2BB68A6}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{159ABDEF-7F19-44DD-8A33-9E292C437AC1}" = protocol=17 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\cinergydvr.exe |
"{2026BF00-D9A4-402C-938D-D4BFB905E9AE}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{20D62634-1E32-4E0A-BF4C-1E5FF5ED234D}" = protocol=17 | dir=in | app=%systemroot%\ehome\ehrecvr.exe |
"{27260019-4DD6-47AE-ABEE-99BFEE347202}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{35976CAF-E766-43A6-8395-9FD8A9D9E0DF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{36338240-1977-4088-B359-0F67656D1B0F}" = protocol=6 | dir=in | app=c:\users\vincent\appdata\local\temp\{647c2ccb-a717-4603-947e-039f2a08da37}\{63b9bab5-f36a-4a3b-9e5c-68a7f212bfb9}\insttool.exe |
"{3664ACE6-E3FA-4DC3-9C07-30892047C849}" = protocol=6 | dir=in | app=c:\users\vincent\appdata\local\temp\{d1158f1a-5eb4-4501-89a6-438fb21a8372}\{63b9bab5-f36a-4a3b-9e5c-68a7f212bfb9}\insttool.exe |
"{3C75CD9B-81A5-42C7-8530-6C7BDD40C89D}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{3CF68B69-038F-481D-97D7-FEFC2FD12128}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{46646A5B-D64E-4A76-9827-4C7D64531597}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{497F90FA-611D-4026-9AA8-E0C9EEF31A84}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{49CC37CD-3C21-4A54-A5FA-0CE27C40483D}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{52D66D02-F132-4A57-ACC9-4FF2A650FBAA}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{5765022D-2F79-4A84-B8D6-8F596988475D}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{57A47E5E-09FF-4929-A9A3-ECA7B3584D71}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{57D089F5-3FC8-4A10-9020-D3A91D09D9F0}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{59F45786-0DEA-4AE5-AD45-F2B84050AB75}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{622D4B97-D6CD-482B-A2C1-AFD0F64A7D22}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{69C1A01D-3523-4C35-8D2C-431957FF2CE4}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{6ED1C449-E0F2-4DD4-B0E3-A257549483AF}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{7176E071-36B3-47C9-9945-8307B085985E}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{73B42F76-F65E-4472-A072-8A54223CC8F5}" = protocol=17 | dir=in | app=c:\users\vincent\appdata\local\temp\{647c2ccb-a717-4603-947e-039f2a08da37}\{63b9bab5-f36a-4a3b-9e5c-68a7f212bfb9}\insttool.exe |
"{7A19A85D-8BBA-4861-97F3-617AA6100071}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{7A393B44-49A2-4876-ADD9-E8A3C9CB02F9}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{82E08060-38E9-4053-BF81-F660A2872D2E}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{89F245F0-1458-42B7-98C7-D977D96CF217}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{8A659294-1FBB-4C69-97C3-80A912101611}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{8AA5E584-1D4B-4E0C-B79D-18F07618A9A3}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{93F1003D-20A4-4FBD-B2C3-E667DE002A4B}" = protocol=17 | dir=in | app=c:\users\vincent\appdata\local\temp\{d1158f1a-5eb4-4501-89a6-438fb21a8372}\{63b9bab5-f36a-4a3b-9e5c-68a7f212bfb9}\insttool.exe |
"{9B53B5C5-5AA8-4423-A15E-FB8C36236F41}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{9F42DAC9-660E-4563-866C-0370D542CC18}" = protocol=17 | dir=in | app=c:\users\vincent\desktop\sweetimsetup.exe |
"{A3D41685-6C58-4B81-AD45-2CD4CFF59C90}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{A61DA92F-7831-4C50-8034-58CBB3A80C12}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{A6850111-69D5-4520-92CA-389305178939}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{A9891DC5-F5F6-43EF-9B27-3517B586E14B}" = protocol=17 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\tvtvsetup\tvtv_wizard.exe |
"{AD235DBC-005A-492E-BEEF-E1E93E0A1825}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{AF81C081-5377-4412-9512-06EDB30FEFB8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B177303D-FBB6-4F93-BB13-D186F19A77EE}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{B4322779-792A-4F88-AC80-71E399150963}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{B6FA54D5-8687-44DE-BEEC-5F1517C48961}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{B7401956-407C-45AC-8C65-B35F81B13860}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C5509975-6EFF-4191-854E-45B9589DD647}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{C90FD16F-3F11-4C19-80C1-6448E520E3F0}" = protocol=6 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\cinergydvr.exe |
"{CEBE9BA4-CA4E-4C78-9EE8-8E3A9DFD6EC4}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{D7648C10-E760-4C08-B372-996F65B7D1F0}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{EFC094D4-E472-44A0-ACA3-614D15B99A6E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FAABA204-DAB7-45D1-96DA-F482DE35F973}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{FDAD937D-9C91-4C70-944A-4FB24FCB7D78}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FDD1009F-1850-43BF-922A-BB8CE182A292}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"TCP Query User{13B5036F-F339-42A0-A6EE-4C986598335A}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe" = protocol=6 | dir=in | app=c:\program files (x86)\myphoneexplorer\myphoneexplorer.exe |
"TCP Query User{26F06863-0D0D-455A-85D7-F32B4759C23E}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"TCP Query User{280F676B-F521-4BF6-ACD3-DF2E2DBB8A76}C:\program files (x86)\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tmnationsforever\tmforever.exe |
"TCP Query User{45C08922-DA64-414F-A827-50A42D9D9B5E}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{54505BE6-0981-41DA-9D07-FD75AA6CDC85}C:\program files (x86)\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tmnationsforever\tmforever.exe |
"TCP Query User{773E7A3D-6CFB-469F-97A7-B733EC864A5B}C:\program files (x86)\terratec\terratec home cinema\cinergydvr.exe" = protocol=6 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\cinergydvr.exe |
"TCP Query User{A579DA36-5929-4E81-A5C5-0AAB898A1AD0}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{AC9EB357-C78C-47A5-8645-16AE16CDC51D}C:\program files (x86)\remote pc server 1.0.3\remote pc server.exe" = protocol=6 | dir=in | app=c:\program files (x86)\remote pc server 1.0.3\remote pc server.exe |
"TCP Query User{D49802FF-FE1E-432B-B951-0BA81A47C257}C:\users\vincent\desktop\teeworlds-b122-r50edfd37-win32\teeworlds_srv.exe" = protocol=6 | dir=in | app=c:\users\vincent\desktop\teeworlds-b122-r50edfd37-win32\teeworlds_srv.exe |
"TCP Query User{ED168340-BD23-47B1-BE6F-A30E263ED341}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe" = protocol=6 | dir=in | app=c:\program files (x86)\myphoneexplorer\myphoneexplorer.exe |
"UDP Query User{0162079E-1312-47B3-BB03-C6F8265E21E7}C:\program files (x86)\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tmnationsforever\tmforever.exe |
"UDP Query User{25041549-4572-496B-9D19-91E6A7657ABB}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"UDP Query User{5B781ED9-127D-4D52-9666-E59A1FF480DE}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe" = protocol=17 | dir=in | app=c:\program files (x86)\myphoneexplorer\myphoneexplorer.exe |
"UDP Query User{6652DC9F-93CA-45B9-AE98-6249763374C5}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{67EE5049-946F-49AD-9637-4310DA1C49A7}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{74677C3C-0E30-48A6-9BD4-8B6CE8D47555}C:\program files (x86)\terratec\terratec home cinema\cinergydvr.exe" = protocol=17 | dir=in | app=c:\program files (x86)\terratec\terratec home cinema\cinergydvr.exe |
"UDP Query User{7D32C4C9-1F24-421E-8624-9D2AEB7E2EA5}C:\program files (x86)\remote pc server 1.0.3\remote pc server.exe" = protocol=17 | dir=in | app=c:\program files (x86)\remote pc server 1.0.3\remote pc server.exe |
"UDP Query User{D4A3252C-A317-40B2-97D0-9501B2741358}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe" = protocol=17 | dir=in | app=c:\program files (x86)\myphoneexplorer\myphoneexplorer.exe |
"UDP Query User{E17C3877-9178-494F-87CC-2AA065AAC87E}C:\users\vincent\desktop\teeworlds-b122-r50edfd37-win32\teeworlds_srv.exe" = protocol=17 | dir=in | app=c:\users\vincent\desktop\teeworlds-b122-r50edfd37-win32\teeworlds_srv.exe |
"UDP Query User{E281E767-EC38-4D82-AE29-E130A0F4929D}C:\program files (x86)\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tmnationsforever\tmforever.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}" = iTunes
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86416030FF}" = Java(TM) 6 Update 30 (64-bit)
"{344C0D46-2EF4-4BC8-AE03-3DACDA9B9485}" = AVG 2012
"{4108974B-DE87-4AD4-9167-930C62C45691}" = Fujitsu Display Manager
"{41B19F41-8A6F-4422-AD69-CF3B408F382C}" = AVG 2012
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6226477E-444F-4DFE-BA19-9F4F7D4565BC}" = LifeBook Application Panel
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7254349B-460B-488F-B4DB-A96100C5C48B}" = Power Saving Utility
"{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}" = Apple Mobile Device Support
"{7BA64D21-EE46-4a9a-8145-52B0175C3F86}" = Plugfree NETWORK
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2F4C332-2359-4ADE-AF0C-C631768BBB89}" = Bluetooth Feature Pack 5.0
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{B7C6A943-83E0-4E7F-A79A-C5CBAA60B0F5}" = Plugfree NETWORK
"{BF46C84D-1AC3-4CC3-A45C-EF6257B80984}" = AVG 2012
"{C78D3032-9DFD-41D0-9DE9-58EAE750CBA4}" = Microsoft Security Client
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E8A5B78F-4456-4511-AB3D-E7BFFB974A7A}" = Fujitsu System Extension Utility
"{EC314CDF-3521-482B-A21C-65AC95664814}" = Fujitsu MobilityCenter Extension Utility
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"AVG" = AVG 2012
"GIMP-2_is1" = GIMP 2.8.2
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"PanoramaStudio2SE" = PanoramaStudio 2.3 SE ((deinstallieren))
"SynTPDeinstKey" = Synaptics Pointing Device Driver
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation(R)Store
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0EDBEB2B-7C8D-42E6-8312-0F84394A3223}" = Windows Media Center Add-in for Silverlight
"{147DFAD8-34C3-4DE1-9FCA-ACEFDE9EF810}" = Synaptics Gesture Suite featuring SYNAPTICS | Scrybe
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 35
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{63B9BAB5-F36A-4A3B-9E5C-68A7F212BFB9}" = TerraTec Home Cinema
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7FA1DAFD-AF55-E915-FD92-F269443A2ADF}" = Media Go Video Playback Engine 1.88.114.12060
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 3.5.3
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{8ABEEC21-B23C-4610-B57A-BE94345D4096}" = Audials
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0407-1000-0000000FF1CE}_HOMESTUDENTR_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet-TV für Windows Media Center
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation(R)Network Downloader
"{BA0CC975-682B-4678-A35C-05E607F36387}" = Fujitsu Hotkey Utility
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C656142F-EFE1-44CD-BFAD-6CBC6DCB9860}" = Vodafone Mobile Connect Lite
"{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DBF1AE39-DA30-4B89-A7EB-3BDA675C5D9E}" = Media Go
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F9000000-0015-0000-0000-074957833700}" = ABBYY Screenshot Reader
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Ashampoo Photo Commander 9_is1" = Ashampoo Photo Commander 9 v.9.4.3
"DeskUpdate_is1" = DeskUpdate 4.13
"EyeTV DTT Deluxe (2009) v2.00.02.8754" = EyeTV DTT Deluxe (2009) v2.00.02.8754
"EyeTV Netstream Service" = EyeTV Netstream for Windows Media Center
"Graph_is1" = Graph 4.3
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{4108974B-DE87-4AD4-9167-930C62C45691}" = Fujitsu Display Manager
"InstallShield_{6226477E-444F-4DFE-BA19-9F4F7D4565BC}" = LifeBook Application Panel
"InstallShield_{7254349B-460B-488F-B4DB-A96100C5C48B}" = Power Saving Utility
"InstallShield_{BA0CC975-682B-4678-A35C-05E607F36387}" = Fujitsu Hotkey Utility
"InstallShield_{E8A5B78F-4456-4511-AB3D-E7BFFB974A7A}" = Fujitsu System Extension Utility
"InstallShield_{EC314CDF-3521-482B-A21C-65AC95664814}" = Fujitsu MobilityCenter Extension Utility
"Lion_is1" = Lion 3.1.0
"Mozilla Firefox 15.0 (x86 de)" = Mozilla Firefox 15.0 (x86 de)
"Mozilla Thunderbird 15.0.1 (x86 de)" = Mozilla Thunderbird 15.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MPE" = MyPhoneExplorer
"Opera 11.62.1347" = Opera 11.62
"TmNationsForever_is1" = TmNationsForever
"VLC media player" = VLC media player 2.0.2
"WinLiveSuite" = Windows Live Essentials
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Mozilla Firefox 15.0.1 (x86 de)" = Mozilla Firefox 15.0.1 (x86 de)
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 10/5/2012 2:04:59 PM | Computer Name = Lifebook-A530 | Source = Application Hang | ID = 1002
Description = Programm explorer.exe, Version 6.1.7601.17567 kann nicht mehr unter
 Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf
in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem
 zu suchen.    Prozess-ID: 17b0    Startzeit: 01cda308dabb3e0d    Endzeit: 16    Anwendungspfad:
 C:\Windows\explorer.exe    Berichts-ID: fa3e62b3-0f16-11e2-8118-e0ca945063e8 
 
Error - 10/5/2012 2:17:09 PM | Computer Name = Lifebook-A530 | Source = WinMgmt | ID = 10
Description =
 
Error - 10/8/2012 6:38:27 AM | Computer Name = Lifebook-A530 | Source = WinMgmt | ID = 10
Description =
 
Error - 10/8/2012 9:36:02 AM | Computer Name = Lifebook-A530 | Source = Application Hang | ID = 1002
Description = Programm Explorer.EXE, Version 6.1.7601.17567 kann nicht mehr unter
 Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf
in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem
 zu suchen.    Prozess-ID: 87c    Startzeit: 01cda4dd16c4f825    Endzeit: 31    Anwendungspfad:
C:\Windows\Explorer.EXE    Berichts-ID: 5cfcd00f-114b-11e2-be67-e0ca945063e8 
 
Error - 10/8/2012 11:37:16 AM | Computer Name = Lifebook-A530 | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: fixcfg.exe, Version: 12.0.0.2111,
 Zeitstempel: 0x4f39b817  Name des fehlerhaften Moduls: avgsysx.dll, Version: 12.0.0.2111,
 Zeitstempel: 0x4f39da45  Ausnahmecode: 0xc0000006  Fehleroffset: 0x00022474  ID des fehlerhaften
 Prozesses: 0xed8  Startzeit der fehlerhaften Anwendung: 0x01cda556c25fed63  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\AVG\AVG2012\fixcfg.exe  Pfad des fehlerhaften
 Moduls: C:\Program Files (x86)\AVG\AVG2012\avgsysx.dll  Berichtskennung: 09923cb0-115e-11e2-be67-e0ca945063e8
 
Error - 10/8/2012 11:37:17 AM | Computer Name = Lifebook-A530 | Source = Application Error | ID = 1005
Description = Aus einem der folgenden Gründe kann nicht auf die Datei "C:\ProgramData\AVG2012\Cfg\update.cfg"
 zugegriffen werden:  Es besteht ein Problem mit der Netzwerkverbindung, dem Datenträger
 mit der gespeicherten Datei bzw. den auf dem Computer installierten  Speichertreibern,
 oder der Datenträger fehlt.  Das Programm AVG Configuration Repair Tool wurde wegen
 dieses Fehlers geschlossen.    Programm: AVG Configuration Repair Tool  Datei: C:\ProgramData\AVG2012\Cfg\update.cfg

Der
 Fehlerwert ist im Abschnitt "Zusätzliche Dateien" aufgelistet.  Benutzeraktion  1.
Öffnen Sie die Datei erneut.  Diese Situation ist eventuell ein temporäres Problem,
 das selbstständig behoben wird, wenn das Programm erneut ausgeführt wird.  2.  Wenn
 Sie weiterhin nicht auf die Datei zugreifen können und  - diese sich im Netzwerk
befindet,  dann sollte der Netzwerkadministrator überprüfen, dass kein Netzwerkproblem
 besteht und dass eine Verbindung mit dem Server hergestellt werden kann.  - diese
 sich auf einem Wechseldatenträger, wie z. B. einer Diskette oder einer CD, befindet,
 überprüfen Sie, ob der Datenträger richtig in den Computer eingelegt ist.  3. Überprüfen
 und reparieren Sie das Dateisystem, indem Sie CHKDSK ausführen. Klicken Sie dazu
 im Menü "Start" auf "Ausführen", geben Sie CMD ein, und klicken Sie auf "OK". Geben
 Sie an der Eingabeaufforderung CHKDSK /F ein, und drücken Sie die EINGABETASTE.
4.
 Stellen Sie die Datei von einer Sicherungskopie wieder her, wenn das Problem weiterhin
 besteht.  5. Überprüfen Sie, ob andere Dateien auf demselben Datenträger geöffnet
 werden können. Falls dies nicht möglich ist, ist der Datenträger eventuell beschädigt.
  Wenden Sie sich an den Administrator oder den Hersteller der Computerhardware,
um weitere Unterstützung zu erhalten, wenn es sich um eine Festplatte handelt.    Zusätzliche
 Daten  Fehlerwert: C0000185  Datenträgertyp: 3
 
Error - 10/14/2012 5:26:42 AM | Computer Name = Lifebook-A530 | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: fixcfg.exe, Version: 12.0.0.2111,
 Zeitstempel: 0x4f39b817  Name des fehlerhaften Moduls: avgsysx.dll, Version: 12.0.0.2111,
 Zeitstempel: 0x4f39da45  Ausnahmecode: 0xc0000006  Fehleroffset: 0x00022474  ID des fehlerhaften
 Prozesses: 0x88c  Startzeit der fehlerhaften Anwendung: 0x01cda5727f1cdc53  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\AVG\AVG2012\fixcfg.exe  Pfad des fehlerhaften
 Moduls: C:\Program Files (x86)\AVG\AVG2012\avgsysx.dll  Berichtskennung: 43507ee0-15e1-11e2-be67-e0ca945063e8
 
Error - 10/14/2012 5:26:42 AM | Computer Name = Lifebook-A530 | Source = Application Error | ID = 1005
Description = Aus einem der folgenden Gründe kann nicht auf die Datei "C:\ProgramData\AVG2012\Cfg\update.cfg"
 zugegriffen werden:  Es besteht ein Problem mit der Netzwerkverbindung, dem Datenträger
 mit der gespeicherten Datei bzw. den auf dem Computer installierten  Speichertreibern,
 oder der Datenträger fehlt.  Das Programm AVG Configuration Repair Tool wurde wegen
 dieses Fehlers geschlossen.    Programm: AVG Configuration Repair Tool  Datei: C:\ProgramData\AVG2012\Cfg\update.cfg

Der
 Fehlerwert ist im Abschnitt "Zusätzliche Dateien" aufgelistet.  Benutzeraktion  1.
Öffnen Sie die Datei erneut.  Diese Situation ist eventuell ein temporäres Problem,
 das selbstständig behoben wird, wenn das Programm erneut ausgeführt wird.  2.  Wenn
 Sie weiterhin nicht auf die Datei zugreifen können und  - diese sich im Netzwerk
befindet,  dann sollte der Netzwerkadministrator überprüfen, dass kein Netzwerkproblem
 besteht und dass eine Verbindung mit dem Server hergestellt werden kann.  - diese
 sich auf einem Wechseldatenträger, wie z. B. einer Diskette oder einer CD, befindet,
 überprüfen Sie, ob der Datenträger richtig in den Computer eingelegt ist.  3. Überprüfen
 und reparieren Sie das Dateisystem, indem Sie CHKDSK ausführen. Klicken Sie dazu
 im Menü "Start" auf "Ausführen", geben Sie CMD ein, und klicken Sie auf "OK". Geben
 Sie an der Eingabeaufforderung CHKDSK /F ein, und drücken Sie die EINGABETASTE.
4.
 Stellen Sie die Datei von einer Sicherungskopie wieder her, wenn das Problem weiterhin
 besteht.  5. Überprüfen Sie, ob andere Dateien auf demselben Datenträger geöffnet
 werden können. Falls dies nicht möglich ist, ist der Datenträger eventuell beschädigt.
  Wenden Sie sich an den Administrator oder den Hersteller der Computerhardware,
um weitere Unterstützung zu erhalten, wenn es sich um eine Festplatte handelt.    Zusätzliche
 Daten  Fehlerwert: C0000185  Datenträgertyp: 3
 
Error - 10/14/2012 10:28:01 AM | Computer Name = Lifebook-A530 | Source = System Restore | ID = 8193
Description =
 
Error - 10/14/2012 11:49:15 AM | Computer Name = Lifebook-A530 | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567,
 Zeitstempel: 0x4d672ee4  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
 Zeitstempel: 0x4ec4aa8e  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000000000004e4b4
ID
 des fehlerhaften Prozesses: 0x11ac  Startzeit der fehlerhaften Anwendung: 0x01cda9ea752a6f07
Pfad
 der fehlerhaften Anwendung: C:\Windows\explorer.exe  Pfad des fehlerhaften Moduls:
 C:\Windows\SYSTEM32\ntdll.dll  Berichtskennung: b4648361-1616-11e2-be67-e0ca945063e8
 
[ Media Center Events ]
Error - 1/29/2012 11:08:18 AM | Computer Name = Lifebook-A530 | Source = MCUpdate | ID = 0
Description = 16:08:09 - Fehler beim Herstellen der Internetverbindung.  16:08:09
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 1/30/2012 1:55:44 PM | Computer Name = Lifebook-A530 | Source = MCUpdate | ID = 0
Description = 18:55:43 - Directory konnte nicht abgerufen werden (Fehler: Timeout
 für Vorgang überschritten) 
 
Error - 4/4/2012 8:25:19 AM | Computer Name = Lifebook-A530 | Source = MCUpdate | ID = 0
Description = 14:25:17 - Fehler beim Herstellen der Internetverbindung.  14:25:18
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 4/4/2012 9:25:24 AM | Computer Name = Lifebook-A530 | Source = MCUpdate | ID = 0
Description = 15:25:23 - Fehler beim Herstellen der Internetverbindung.  15:25:23
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 4/4/2012 10:25:28 AM | Computer Name = Lifebook-A530 | Source = MCUpdate | ID = 0
Description = 16:25:28 - Fehler beim Herstellen der Internetverbindung.  16:25:28
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 4/4/2012 5:07:40 PM | Computer Name = Lifebook-A530 | Source = MCUpdate | ID = 0
Description = 23:07:40 - Fehler beim Herstellen der Internetverbindung.  23:07:40
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 7/20/2012 12:16:58 AM | Computer Name = Lifebook-A530 | Source = MCUpdate | ID = 0
Description = 06:16:58 - Fehler beim Herstellen der Internetverbindung.  06:16:58
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 7/20/2012 12:17:23 AM | Computer Name = Lifebook-A530 | Source = MCUpdate | ID = 0
Description = 06:17:23 - Fehler beim Herstellen der Internetverbindung.  06:17:23
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 7/20/2012 12:17:31 AM | Computer Name = Lifebook-A530 | Source = MCUpdate | ID = 0
Description = 06:17:28 - Fehler beim Herstellen der Internetverbindung.  06:17:28
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 7/22/2012 8:17:12 PM | Computer Name = Lifebook-A530 | Source = MCUpdate | ID = 0
Description = 02:17:12 - Fehler beim Herstellen der Internetverbindung.  02:17:12
-    Serververbindung konnte nicht hergestellt werden.. 
 
[ System Events ]
Error - 10/22/2012 3:13:10 AM | Computer Name = Lifebook-A530 | Source = DCOM | ID = 10010
Description =
 
Error - 10/22/2012 3:24:49 AM | Computer Name = Lifebook-A530 | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst avgwd erreicht.
 
Error - 10/22/2012 3:24:50 AM | Computer Name = Lifebook-A530 | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
 Windows-Fehlerberichterstattungsdienst erreicht.
 
Error - 10/22/2012 3:26:15 AM | Computer Name = Lifebook-A530 | Source = iaStor | ID = 262153
Description = Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht
 geantwortet.
 
Error - 10/22/2012 3:54:16 AM | Computer Name = Lifebook-A530 | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst avgwd erreicht.
 
Error - 10/22/2012 3:55:23 AM | Computer Name = Lifebook-A530 | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst MsMpSvc erreicht.
 
Error - 10/22/2012 4:00:56 AM | Computer Name = Lifebook-A530 | Source = Microsoft Antimalware | ID = 2001
Description = Beim Aktualisieren der Signaturen wurde von %%860 ein Fehler festgestellt.

        Neue
 Signaturversion:      Vorherige Signaturversion: 1.137.1929.0    Aktualisierungsquelle:
%%859    Aktualisierungsphase: %%852    Quellpfad: hxxp://www.microsoft.com    Signaturtyp:
%%800    Aktualisierungstyp: %%803    Benutzer: NT-AUTORITÄT\SYSTEM    Aktuelle Modulversion:
      Vorherige Modulversion: 1.1.8800.0    Fehlercode: 0x8024402c    Fehlerbeschreibung: Unerwartetes
 Problem bei der Überprüfung auf Updates. Informationen zum Installieren von Updates
 oder zur Problembehandlung finden Sie unter "Hilfe und Support".
 
Error - 10/22/2012 4:04:20 AM | Computer Name = Lifebook-A530 | Source = Microsoft Antimalware | ID = 2001
Description = Beim Aktualisieren der Signaturen wurde von %%860 ein Fehler festgestellt.

        Neue
 Signaturversion:      Vorherige Signaturversion: 1.137.1929.0    Aktualisierungsquelle:
%%859    Aktualisierungsphase: %%852    Quellpfad: hxxp://www.microsoft.com    Signaturtyp:
%%800    Aktualisierungstyp: %%803    Benutzer: NT-AUTORITÄT\SYSTEM    Aktuelle Modulversion:
      Vorherige Modulversion: 1.1.8800.0    Fehlercode: 0x8024402c    Fehlerbeschreibung: Unerwartetes
 Problem bei der Überprüfung auf Updates. Informationen zum Installieren von Updates
 oder zur Problembehandlung finden Sie unter "Hilfe und Support".
 
Error - 10/22/2012 4:15:22 AM | Computer Name = Lifebook-A530 | Source = iaStor | ID = 262153
Description = Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht
 geantwortet.
 
Error - 10/22/2012 10:16:07 PM | Computer Name = Lifebook-A530 | Source = ipnathlp | ID = 31004
Description =
 
 
< End of report >

Teil 2 folgt

Bis hier hin alles in Ordnung?

VHSK 03.11.2012 11:24

Code:

OTL logfile created on: 11/3/2012 8:48:42 AM - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Vincent\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.80 Gb Total Physical Memory | 2.43 Gb Available Physical Memory | 63.87% Memory free
7.60 Gb Paging File | 6.04 Gb Available in Paging File | 79.43% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 296.09 Gb Total Space | 223.05 Gb Free Space | 75.33% Space Free | Partition Type: NTFS
 
Computer Name: LIFEBOOK-A530 | User Name: Vincent | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012/11/01 23:38:59 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Vincent\Desktop\OTL.exe
PRC - [2012/09/10 20:26:59 | 006,035,064 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
PRC - [2012/08/24 14:44:42 | 000,878,712 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgcmgr.exe
PRC - [2012/08/07 02:39:46 | 004,370,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgui.exe
PRC - [2012/07/31 02:37:02 | 002,596,984 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
PRC - [2012/07/27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/25 10:28:02 | 000,101,288 | ---- | M] (Fujitsu Technology Solutions) -- C:\Program Files (x86)\Fujitsu\DeskUpdate\DeskUpdateNotifier.exe
PRC - [2012/02/14 03:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/11/24 16:31:18 | 001,837,568 | ---- | M] (TerraTec Electronic GmbH) -- C:\Program Files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe
PRC - [2011/09/15 12:06:04 | 000,088,576 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2009/11/01 17:04:48 | 002,314,240 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009/11/01 17:04:42 | 000,262,144 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009/10/09 21:06:50 | 000,047,976 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
PRC - [2009/10/08 20:44:54 | 000,036,712 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012/09/15 09:49:38 | 000,766,976 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\log4net\ca507030bb77d2c58f5cebca8b4de7f0\log4net.ni.dll
MOD - [2012/09/15 09:49:38 | 000,117,248 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\DeskUpdateNotifier\82cf810ac24ee22f99a0a1a7a752947c\DeskUpdateNotifier.ni.exe
MOD - [2012/06/15 20:27:06 | 013,198,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\3971e166cf827b6726e142f344061dc9\System.Windows.Forms.ni.dll
MOD - [2012/06/15 20:26:56 | 001,666,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\8c40f40ef36622109793788049fbe9ab\System.Drawing.ni.dll
MOD - [2012/05/15 17:06:10 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll
MOD - [2012/05/15 17:06:06 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\623d2a0f11dd82bb9bc13d1cb981b239\System.Configuration.ni.dll
MOD - [2012/05/15 17:06:04 | 009,091,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll
MOD - [2012/05/15 17:05:59 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2012/09/12 20:21:48 | 000,368,896 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2012/09/12 20:21:48 | 000,022,072 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/06/23 17:14:38 | 000,330,240 | ---- | M] (FUJITSU LIMITED) [On_Demand | Stopped] -- C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe -- (PFNService)
SRV:64bit: - [2009/12/24 12:43:40 | 000,145,840 | ---- | M] (CSR, plc) [Auto | Running] -- C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe -- (VFPRadioSupportService)
SRV:64bit: - [2009/07/30 10:43:00 | 000,063,336 | ---- | M] (FUJITSU LIMITED) [Auto | Running] -- C:\Program Files\Fujitsu\PSUtility\PSUService.exe -- (PowerSavingUtilityService)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/10/14 13:24:08 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/07 00:13:37 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/08/13 02:24:48 | 005,167,736 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2012/07/27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/06/07 18:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/02/14 03:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2011/09/15 12:06:04 | 000,088,576 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2011/05/27 15:23:00 | 001,300,264 | ---- | M] (Synaptics, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe -- (ScrybeUpdater)
SRV - [2010/09/13 12:58:24 | 000,399,944 | ---- | M] (Elgato Systems GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\Elgato\EyeTV Netstream\EyeTVNetstreamSvc.exe -- (EyeTV Netstream)
SRV - [2010/03/18 21:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/11/01 17:04:48 | 002,314,240 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009/11/01 17:04:42 | 000,262,144 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/10/16 16:18:17 | 000,759,072 | ---- | M] (ABBYY (BIT Software)) [Disabled | Stopped] -- C:\Program Files (x86)\ABBYY Screenshot Reader\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.ScreenshotReader.9.0)
SRV - [2008/07/04 11:52:18 | 000,014,336 | ---- | M] (Vodafone) [Disabled | Stopped] -- C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012/08/30 21:03:48 | 000,128,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/08/24 14:43:16 | 000,384,352 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2012/08/21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/07/26 02:21:28 | 000,291,680 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2012/07/09 12:42:54 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/04/19 03:50:26 | 000,028,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/01/31 03:46:48 | 000,036,944 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2012/01/03 16:28:54 | 000,047,208 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tbhsd.sys -- (tbhsd)
DRV:64bit: - [2012/01/03 16:28:47 | 000,037,480 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rrnetcap.sys -- (RRNetCapMP)
DRV:64bit: - [2012/01/03 16:28:47 | 000,037,480 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rrnetcap.sys -- (RRNetCap)
DRV:64bit: - [2011/12/23 12:32:14 | 000,047,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2011/12/23 12:32:04 | 000,029,776 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\avgidsfiltera.sys -- (AVGIDSFilter)
DRV:64bit: - [2011/12/23 12:31:58 | 000,124,496 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2011/08/02 15:38:44 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
DRV:64bit: - [2011/03/31 18:32:00 | 001,424,944 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 04:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/06/25 16:08:10 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
DRV:64bit: - [2010/06/08 09:33:14 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010/04/12 08:09:08 | 000,131,144 | ---- | M] (ABILIS Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AbilisBdaTuner.sys -- (AbilisT)
DRV:64bit: - [2010/03/04 21:43:00 | 000,346,144 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/12/18 11:38:56 | 008,038,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/11/27 05:15:00 | 000,244,736 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2009/11/06 12:56:06 | 001,550,848 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009/11/02 18:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
DRV:64bit: - [2009/11/01 17:04:42 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009/10/26 12:39:44 | 000,151,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 01:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2009/07/14 01:00:13 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Dot4Scan.sys -- (Dot4Scan)
DRV:64bit: - [2009/07/14 00:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008/03/17 10:06:14 | 000,115,328 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV:64bit: - [2006/11/01 17:59:24 | 000,007,296 | ---- | M] (FUJITSU LIMITED) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\fuj02e3.sys -- (FUJ02E3)
DRV:64bit: - [2006/11/01 17:20:28 | 000,007,808 | ---- | M] (FUJITSU LIMITED) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\fuj02b1.sys -- (FUJ02B1)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {916F2051-FF46-4C6C-B0CC-5621E68CBCFE}
IE:64bit: - HKLM\..\SearchScopes\{916F2051-FF46-4C6C-B0CC-5621E68CBCFE}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7FTSG
IE - HKLM\..\SearchScopes,DefaultScope = {916F2051-FF46-4C6C-B0CC-5621E68CBCFE}
IE - HKLM\..\SearchScopes\{916F2051-FF46-4C6C-B0CC-5621E68CBCFE}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7FTSG
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ts.fujitsu.com
IE - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.google.com/ig/redirectd [Binary data over 200 bytes]
IE - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=FTSG&bmod=FTSG
IE - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\..\SearchScopes,DefaultScope = {916F2051-FF46-4C6C-B0CC-5621E68CBCFE}
IE - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\..\SearchScopes\{72C07153-7FE4-4370-A10E-899B5605130B}: "URL" = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
IE - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=937811&ilc=12"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: {F53C93F1-07D5-430c-86D4-C9531B27DFAF}:12.0.0.2189
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}:6.0.33
FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Vincent\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Vincent\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/09/10 20:30:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/07/03 14:56:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/07 00:13:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012/08/29 20:08:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\avgthb@avg.com: C:\Program Files (x86)\AVG\AVG2012\Thunderbird\
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/07 00:13:38 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2011/12/25 22:02:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Vincent\AppData\Roaming\mozilla\Extensions
[2012/11/01 16:19:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Vincent\AppData\Roaming\mozilla\Firefox\Profiles\9u0eqmus.default\extensions
[2012/11/01 16:19:41 | 000,048,118 | ---- | M] () (No name found) -- C:\Users\Vincent\AppData\Roaming\mozilla\firefox\profiles\9u0eqmus.default\extensions\GlassMyFox@ArisT2_Noia4dev.xpi
[2012/02/20 10:55:37 | 000,003,915 | ---- | M] () -- C:\Users\Vincent\AppData\Roaming\mozilla\firefox\profiles\9u0eqmus.default\searchplugins\sweetim.xml
[2012/09/12 22:52:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012/09/07 00:13:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/09/12 22:52:25 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/07/03 14:56:25 | 000,000,000 | ---D | M] (AVG Do Not Track) -- C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX\DONOTTRACK
[2012/09/07 00:13:38 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/09/06 22:34:59 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/09/06 22:34:59 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/09/06 22:34:59 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012/09/06 22:34:59 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/09/06 22:34:59 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/09/06 22:34:59 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Vincent\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2210_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U35 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.350.10 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: Media Go Detector (Enabled) = C:\Program Files (x86)\Sony\Media Go\npmediago.dll
CHR - plugin: PlayStation(R)Network Downloader Check Plug-in (Enabled) = C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Wetter (Erweiterung) = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\beapnbfmjmjhhfpaoajfhjbbfnnlfpnc\0.9.0.0_0\
CHR - Extension: Adblock Plus (Beta) = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Grooveshark Germany unlocker = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\docdgimmdejoiemdafcgeodchlbllgac\2.3.4_0\
CHR - Extension: Grooveshark Germany unlocker = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\docdgimmdejoiemdafcgeodchlbllgac\2.3.4_0\.orig
CHR - Extension: Regentropfen(Non-Aero) = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpagcfbbmlebfnkeogkigellbgmfkjfg\1.0.0.2_0\
CHR - Extension: AdBlock = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.45_0\
CHR - Extension: AVG Safe Search = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2210_0\
CHR - Extension: Smooth Scrollerator = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmicgfcegednlkdhgbhgickcgndjeeig\1.1.1_0\
CHR - Extension: AVG Do Not Track = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
 
O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll File not found
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll File not found
O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\PROGRA~2\TerraTec\TERRAT~1\THCDES~1.DLL (TerraTec Electronic GmbH)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [BthSyncServ] "C:\Program Files\CSR\Bluetooth Feature Pack 5.0\bthsyncserv.exe" File not found
O4:64bit: - HKLM..\Run: [ConMgr] C:\Program Files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe (CSR, plc)
O4:64bit: - HKLM..\Run: [CSRBIP] C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRBipPushResponder.exe (CSR, plc)
O4:64bit: - HKLM..\Run: [CSRFTP] C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRBthFtpServer.exe (CSR, plc)
O4:64bit: - HKLM..\Run: [CSRSkype] C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRSkype.exe (CSR, plc)
O4:64bit: - HKLM..\Run: [FDM7] C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PSUTility] C:\Program Files\Fujitsu\PSUtility\TrayManager.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DeskUpdateNotifier] C:\Program Files (x86)\Fujitsu\DeskUpdate\DeskUpdateNotifier.exe (Fujitsu Technology Solutions)
O4 - HKLM..\Run: [IndicatorUtility] C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [LoadFUJ02E3] C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1655660024-2649062184-858687661-1000..\Run: [ABBYY Screenshot Reader Retail]  File not found
O4 - HKU\S-1-5-21-1655660024-2649062184-858687661-1000..\Run: [Remote Control Editor] C:\Program Files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe (TerraTec Electronic GmbH)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutoHotkey.ahk - Verknüpfung.lnk = C:\Users\Vincent\Documents\Library\AutoHotkey.ahk ()
O4 - Startup: C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SynTPEnh.exe (Synaptics Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0F44BEA7-67FF-46D6-A274-D71A7952D06B}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F70A030-AB0A-40A3-848F-93F0CB9B9048}: DhcpNameServer = 10.129.32.1 10.111.81.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E9B66E02-0BE1-4EBD-AA23-CCB8CBC5B727}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{8ec7cabf-2f68-11e1-83af-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{8ec7cabf-2f68-11e1-83af-806e6f6e6963}\Shell\AutoRun\command - "" = F:\tools\shelexec.exe html\index.htm
O33 - MountPoints2\{aca35bed-ee1f-11e1-9d8d-e0ca945063e8}\Shell - "" = AutoRun
O33 - MountPoints2\{aca35bed-ee1f-11e1-9d8d-e0ca945063e8}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{aca35bf4-ee1f-11e1-9d8d-e0ca945063e8}\Shell - "" = AutoRun
O33 - MountPoints2\{aca35bf4-ee1f-11e1-9d8d-e0ca945063e8}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
 
MsConfig:64bit - StartUpReg: ABBYY Screenshot Reader Retail - hkey= - key= - C:\Program Files (x86)\ABBYY Screenshot Reader\ScreenShotReader.exe (ABBYY Software Ltd)
MsConfig:64bit - StartUpReg: APSDaemon - hkey= - key= - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: DeskUpdateNotifier - hkey= - key= - C:\Program Files (x86)\Fujitsu\DeskUpdate\DeskUpdateNotifier.exe (Fujitsu Technology Solutions)
MsConfig:64bit - StartUpReg: FILSHtray - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: Google Update - hkey= - key= - C:\Users\Vincent\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
MsConfig:64bit - StartUpReg: HTC Sync Loader - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: MobileConnect - hkey= - key= - C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
MsConfig:64bit - StartUpReg: PDFPrint - hkey= - key= - C:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: Remote Control Editor - hkey= - key= - C:\Program Files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe (TerraTec Electronic GmbH)
MsConfig:64bit - StartUpReg: UCam_Menu - hkey= - key= - C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: YouCam Mirror Tray icon - hkey= - key= - C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe (CyberLink Corp.)
MsConfig:64bit - State: "bootini" - Reg Error: Key error.
MsConfig:64bit - State: "startup" - Reg Error: Key error.
MsConfig:64bit - State: "services" - Reg Error: Key error.
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: MsMpSvc - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: MsMpSvc - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/11/03 08:33:55 | 000,000,000 | ---D | C] -- C:\Users\Vincent\Desktop\126318-laptop-ploetzlich-langsam-geworden-post948325-Dateien
[2012/11/03 00:50:18 | 000,208,216 | ---- | C] (Kaspersky Lab, GERT) -- C:\Windows\SysNative\drivers\79859503.sys
[2012/11/01 23:53:05 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Vincent\Desktop\tdsskiller.exe
[2012/11/01 23:36:51 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Vincent\Desktop\OTL.exe
[2012/10/04 22:32:56 | 000,000,000 | ---D | C] -- C:\Users\Vincent\Desktop\Bank
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012/11/03 10:33:00 | 000,001,128 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1655660024-2649062184-858687661-1000UA.job
[2012/11/03 10:04:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/03 09:43:50 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/03 09:43:00 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/03 08:39:42 | 000,142,943 | ---- | M] () -- C:\Users\Vincent\Desktop\126318-laptop-ploetzlich-langsam-geworden-post948325.html
[2012/11/03 08:15:07 | 000,001,076 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1655660024-2649062184-858687661-1000Core.job
[2012/11/03 08:00:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/11/03 02:28:25 | 3061,227,520 | -HS- | M] () -- C:\hiberfil.sys
[2012/11/03 01:39:57 | 000,013,833 | ---- | M] () -- C:\Users\Vincent\Desktop\fatal.JPG
[2012/11/03 00:50:47 | 000,208,216 | ---- | M] (Kaspersky Lab, GERT) -- C:\Windows\SysNative\drivers\79859503.sys
[2012/11/02 00:10:26 | 000,082,214 | ---- | M] () -- C:\Users\Vincent\Desktop\forum-anleitung.JPG
[2012/11/01 23:53:23 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Vincent\Desktop\tdsskiller.exe
[2012/11/01 23:38:59 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Vincent\Desktop\OTL.exe
[2012/11/01 23:38:07 | 000,000,000 | ---- | M] () -- C:\Users\Vincent\defogger_reenable
[2012/11/01 23:09:20 | 000,050,477 | ---- | M] () -- C:\Users\Vincent\Desktop\Defogger.exe
[2012/11/01 15:20:35 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/01 15:20:30 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/01 15:00:50 | 000,696,870 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012/11/01 15:00:50 | 000,652,148 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/11/01 15:00:50 | 000,121,080 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/11/01 15:00:45 | 000,148,134 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012/11/01 15:00:13 | 001,612,484 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012/11/03 08:35:43 | 000,142,943 | ---- | C] () -- C:\Users\Vincent\Desktop\126318-laptop-ploetzlich-langsam-geworden-post948325.html
[2012/11/03 01:37:59 | 000,013,833 | ---- | C] () -- C:\Users\Vincent\Desktop\fatal.JPG
[2012/11/02 00:10:25 | 000,082,214 | ---- | C] () -- C:\Users\Vincent\Desktop\forum-anleitung.JPG
[2012/11/01 23:38:07 | 000,000,000 | ---- | C] () -- C:\Users\Vincent\defogger_reenable
[2012/11/01 23:04:57 | 000,050,477 | ---- | C] () -- C:\Users\Vincent\Desktop\Defogger.exe
[2012/09/16 19:53:35 | 000,010,045 | ---- | C] () -- C:\Users\Vincent\AppData\Local\recently-used.xbel
[2012/05/23 18:28:04 | 006,607,360 | ---- | C] () -- C:\Program Files\LuPO_NRW_SV.exe
[2012/03/03 20:13:33 | 000,006,656 | ---- | C] () -- C:\Users\Vincent\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/20 00:00:48 | 000,007,606 | ---- | C] () -- C:\Users\Vincent\AppData\Local\Resmon.ResmonCfg
[2012/01/07 05:55:32 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011/11/03 09:57:42 | 000,870,544 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2011/11/03 09:57:42 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2011/11/03 09:57:42 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2011/11/03 09:57:42 | 000,051,068 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2011/11/03 09:57:41 | 000,127,896 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2011/04/15 06:37:26 | 001,641,654 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2008/06/23 12:02:02 | 000,097,410 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2008/05/23 16:48:50 | 000,020,270 | ---- | C] () -- C:\ProgramData\DeviceInstaller.xml
 
========== ZeroAccess Check ==========
 
[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2012/03/20 19:52:10 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\ACD Systems
[2012/09/14 21:40:50 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Ashampoo
[2012/01/08 22:28:23 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\AVG2012
[2012/01/26 21:59:37 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Babylon
[2012/02/05 20:07:54 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\DVDVideoSoft
[2012/02/05 20:07:14 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/12/25 20:22:10 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Fujitsu
[2012/07/18 07:35:48 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\gtk-2.0
[2012/01/26 23:06:01 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\HTC
[2012/02/06 23:26:38 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Music Liberator 10.5 Release 1.1
[2012/08/24 19:46:24 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\MyPhoneExplorer
[2012/02/20 12:51:46 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Need for Speed World
[2012/04/14 15:16:08 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Opera
[2012/09/16 18:50:01 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\PanoramaStudio2
[2012/01/22 12:30:19 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Remote PC Server
[2012/01/10 21:53:16 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\SoftGrid Client
[2012/05/07 09:18:17 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Sony
[2012/01/07 07:36:25 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Synaptics
[2012/09/11 15:23:33 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Teeworlds
[2012/06/24 09:06:20 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\TerraTec
[2012/01/08 16:36:51 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Thunderbird
[2011/12/25 23:44:51 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\TP
[2012/09/10 20:20:11 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Vodafone
[2012/01/31 21:42:43 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Windows Live Writer
[2012/02/19 20:17:21 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Windows SideBar
[2012/02/07 00:14:53 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\WindSolutions
[2012/09/15 12:27:29 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Zoner
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %SYSTEMDRIVE%\*. >
[2012/05/31 19:13:41 | 000,000,000 | -H-D | M] -- C:\$AVG
[2012/01/16 02:47:07 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2011/02/11 15:33:09 | 000,000,000 | -HSD | M] -- C:\Boot
[2009/07/14 06:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2011/11/03 09:56:51 | 000,000,000 | ---D | M] -- C:\Drivers
[2012/09/29 16:42:08 | 000,000,000 | -HSD | M] -- C:\found.000
[2011/12/25 20:18:41 | 000,000,000 | ---D | M] -- C:\Fujitsu
[2011/12/26 03:25:53 | 000,000,000 | ---D | M] -- C:\Intel
[2012/01/10 20:53:16 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2012/09/30 14:35:36 | 000,000,000 | R--D | M] -- C:\Program Files
[2012/09/30 14:46:51 | 000,000,000 | R--D | M] -- C:\Program Files (x86)
[2012/09/15 21:08:19 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2011/02/11 15:39:58 | 000,000,000 | -HSD | M] -- C:\Recovery
[2012/11/03 09:57:08 | 000,000,000 | ---D | M] -- C:\System Volume Information
[2012/09/14 19:16:52 | 000,000,000 | ---D | M] -- C:\Temp
[2011/12/25 20:13:51 | 000,000,000 | R--D | M] -- C:\Users
[2012/03/09 17:31:44 | 000,000,000 | ---D | M] -- C:\Vimeo
[2012/10/03 18:31:45 | 000,000,000 | ---D | M] -- C:\Windows
 
< %SYSTEMDRIVE%\*.* >
[2010/11/21 04:23:51 | 000,383,786 | RHS- | M] () -- C:\bootmgr
[2011/02/11 15:33:10 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2012/11/03 02:28:25 | 3061,227,520 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/25 20:13:28 | 000,007,430 | ---- | M] () -- C:\lang.txt
[2006/12/01 23:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
[2012/11/03 02:28:20 | 4081,639,424 | -HS- | M] () -- C:\pagefile.sys
[2011/12/25 20:09:48 | 000,002,208 | ---- | M] () -- C:\RHDSetup.log
[2012/11/03 01:53:28 | 000,003,558 | ---- | M] () -- C:\TDSSKiller.2.8.15.0_03.11.2012_00.50.16_log.txt
[2012/01/26 21:59:50 | 000,000,237 | ---- | M] () -- C:\user.js
 
< %PROGRAMFILES%\*.exe >
 
< %PROGRAMFILES(X86)%\*.exe >
 
< %systemroot%\*. /mp /s >
 
< %windir%\installer\*. /10 >
 
< %appdata%\*.  >
[2012/03/20 19:52:10 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\ACD Systems
[2012/01/18 21:50:07 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Adobe
[2012/05/07 07:32:42 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Apple Computer
[2012/09/14 21:40:50 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Ashampoo
[2012/01/08 22:28:23 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\AVG2012
[2012/01/26 21:59:37 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Babylon
[2011/12/25 20:27:17 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\CyberLink
[2012/07/20 08:01:58 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\dvdcss
[2012/02/05 20:07:54 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\DVDVideoSoft
[2012/02/05 20:07:14 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/12/25 20:22:10 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Fujitsu
[2012/07/18 07:35:48 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\gtk-2.0
[2012/01/26 23:06:01 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\HTC
[2011/12/25 20:21:17 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Identities
[2011/12/25 22:09:54 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Macromedia
[2010/11/21 08:16:58 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Media Center Programs
[2012/04/17 04:59:31 | 000,000,000 | --SD | M] -- C:\Users\Vincent\AppData\Roaming\Microsoft
[2011/12/25 22:02:36 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Mozilla
[2012/02/06 23:26:38 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Music Liberator 10.5 Release 1.1
[2012/08/24 19:46:24 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\MyPhoneExplorer
[2012/02/20 12:51:46 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Need for Speed World
[2012/04/14 15:16:08 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Opera
[2012/09/16 18:50:01 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\PanoramaStudio2
[2012/01/22 12:30:19 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Remote PC Server
[2012/09/29 09:56:09 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Skype
[2012/01/10 21:53:16 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\SoftGrid Client
[2012/05/07 09:18:17 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Sony
[2012/01/07 07:36:25 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Synaptics
[2012/09/11 15:23:33 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Teeworlds
[2012/06/24 09:06:20 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\TerraTec
[2012/01/08 16:36:51 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Thunderbird
[2011/12/25 23:44:51 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\TP
[2012/09/22 23:04:03 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\vlc
[2012/09/10 20:20:11 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Vodafone
[2012/01/31 21:42:43 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Windows Live Writer
[2012/02/19 20:17:21 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Windows SideBar
[2012/02/07 00:14:53 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\WindSolutions
[2012/09/15 12:27:29 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Zoner
 
< %appdata%\*.*  >
 
< %appdata%\*.exe /s >
[2012/01/18 21:57:04 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Vincent\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2012/01/09 18:48:25 | 001,082,680 | ---- | M] () -- C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FTSDeskUpdate.exe
[2011/03/31 18:29:28 | 002,735,400 | ---- | M] (Synaptics Incorporated) -- C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SynTPEnh.exe
 
< %localappdata%\*.  >
[2012/09/14 19:22:41 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\ABBYY
[2012/02/05 20:47:35 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Abelssoft
[2012/03/20 19:59:46 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\ACD Systems
[2012/01/18 21:50:06 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Adobe
[2011/12/25 20:13:51 | 000,000,000 | -HSD | M] -- C:\Users\Vincent\AppData\Local\Anwendungsdaten
[2011/12/26 01:28:54 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Apple
[2011/12/30 17:06:07 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Apple Computer
[2012/09/14 21:35:01 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\ashampoo
[2012/01/26 21:59:39 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Babylon
[2012/10/14 16:53:44 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\CrashDumps
[2012/02/06 01:20:33 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\CrashRpt
[2012/08/24 17:27:15 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\CUSTPDF Writer
[2011/12/25 20:26:56 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\CyberLink
[2012/11/03 04:09:48 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Diagnostics
[2012/05/07 07:32:10 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Downloaded Installations
[2012/02/19 20:16:33 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Electronic_Arts_Inc
[2012/11/03 04:09:48 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\ElevatedDiagnostics
[2012/09/16 18:36:00 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\fontconfig
[2012/09/16 18:35:58 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\gegl-0.2
[2012/09/15 12:26:07 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Google
[2012/09/16 20:11:40 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Innovative Solutions
[2012/06/16 17:30:13 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Macromedia
[2012/09/15 20:23:34 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Microsoft
[2012/04/12 18:08:11 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Microsoft Help
[2011/12/25 22:02:27 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Mozilla
[2012/04/14 15:16:08 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Opera
[2011/12/30 17:24:49 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\PackageAware
[2012/09/16 18:44:02 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Paint.NET
[2012/01/26 09:42:57 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\PDF24
[2012/09/10 20:19:50 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Programs
[2012/02/06 01:18:26 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\RapidSolution
[2011/12/25 23:44:46 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\SoftGrid Client
[2012/05/07 09:14:48 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Sony
[2012/11/03 10:35:18 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Temp
[2011/12/25 20:13:51 | 000,000,000 | -HSD | M] -- C:\Users\Vincent\AppData\Local\Temporary Internet Files
[2012/01/27 17:10:11 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Thunderbird
[2011/12/25 20:13:51 | 000,000,000 | -HSD | M] -- C:\Users\Vincent\AppData\Local\Verlauf
[2012/01/17 20:28:48 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\VirtualStore
[2012/04/19 00:51:47 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Windows Live
[2012/01/07 08:56:12 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Windows Live Writer
[2012/09/14 15:55:54 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\Zoner
[2012/03/20 13:26:34 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{0558CE5D-7DF7-4EC7-B65B-1EEE9DD3B733}
[2012/04/19 00:55:10 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{14AAD8A1-0137-41B4-97CE-112A4B125E0F}
[2012/04/18 22:28:24 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{1C20213A-F652-4E6F-8318-3C46AE3CDDAB}
[2011/12/28 18:06:00 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{234D422A-0115-490C-818E-E12FEABB57D7}
[2012/02/04 10:35:23 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{26E35703-C3D8-476A-A203-E503F2AE10C1}
[2012/02/04 10:35:13 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{358F4FF3-4BF3-4BC1-977E-0E4FC7E11286}
[2012/03/20 13:26:25 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{39E6C2DB-6CE1-4DE2-8307-91998A647A0F}
[2012/01/07 09:38:04 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{3C4941B5-C0DF-4C37-B83A-9E723F086ED7}
[2012/04/19 00:54:30 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{3F5D0D7A-53A4-4F12-9B9A-4A0471E6EDC5}
[2012/08/06 14:05:41 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{40318A0E-2742-4FE2-8ED6-88AA79843768}
[2012/01/31 21:39:38 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{43A1999F-9FFD-4260-A8D4-0766C41ED606}
[2012/02/24 16:19:21 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{4A516C56-B15A-4B77-990A-C84D7D54421C}
[2012/02/05 12:14:31 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{53FF4C9B-631B-49DE-8480-061C6E1CE42C}
[2012/08/22 23:02:13 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{56F87D58-F02F-403D-BBEA-B4F1F0D05F37}
[2012/02/02 20:59:40 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{59BB865D-282F-4153-B933-11B15D1BB216}
[2012/02/03 19:31:55 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{5A88A158-DC4D-49A4-B8DD-BDF5FC1CA97E}
[2012/01/11 20:36:12 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{60604835-8AE0-433F-924D-0C38B2CF7C33}
[2011/12/27 21:52:26 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{670D4D52-C428-4109-83A1-79ADDD26A261}
[2012/02/08 20:23:43 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{73D4DE1D-526E-47C4-A584-60EA2CBED061}
[2011/12/27 21:44:55 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{753E0ACD-651A-4E2E-AB5B-FE3FB2C50D91}
[2012/04/19 00:55:00 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{77385AFF-DA6C-4C54-A0D6-E17DAE92667D}
[2012/02/08 20:23:32 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{7E5FE671-3AB5-435A-A34A-7F736935609F}
[2012/02/02 20:59:51 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{800AB4D3-8B4E-4253-8223-9B10B1D4FD5B}
[2012/02/03 19:31:45 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{82AADD77-FBF5-41FB-B3FD-B3103B2AE7E2}
[2012/09/16 20:54:02 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{86F4CC6F-6464-4A1F-8232-7C26250121B6}
[2012/01/07 09:38:15 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{8C24A39C-7931-48C0-A006-1C2298DE3A85}
[2012/01/07 08:56:34 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{9370E490-A01F-4A01-AFB3-624742D4308A}
[2012/02/22 20:05:36 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{99A162DB-96CB-43D1-BCB7-673D5DFB7058}
[2012/02/01 19:43:47 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{9C0EA8AD-4A30-4BE1-9B21-8DE059B05307}
[2012/01/07 08:56:33 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{A0386D85-8D85-49EA-A8AE-961829EF7F70}
[2012/04/19 00:52:19 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{A598B9A5-54CC-4A5B-BA1E-12F4E9584FC1}
[2012/02/05 13:29:27 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{A874B693-9139-47BC-B6BB-CE99D62CFA81}
[2012/01/11 20:36:12 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{AA7A7DA6-05CB-4A96-B5FA-C290B87440B5}
[2012/02/05 00:14:17 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{B4B05CE3-E1F5-4F93-92A1-CA8E840B3676}
[2012/04/19 00:52:09 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{B6C07F63-D89B-4D73-A9DD-79DBF5836FB6}
[2012/01/08 20:16:28 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{BA39FF43-6FB9-422B-989C-C21232064472}
[2012/02/22 20:05:36 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{BAC5232B-6C01-4146-AB2F-DC2C53777FA2}
[2012/01/22 11:40:38 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{C29C53EC-F7D9-4B7A-B462-EB6B4CFE8792}
[2012/01/08 20:16:39 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{C46F3243-26E0-4FD9-95F5-45DD5BB3C541}
[2012/01/22 11:40:50 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{C7BF4215-C8F9-443C-B7DA-706C5A8DB623}
[2012/08/06 14:05:56 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{C7C70502-59D1-4A07-8BBA-34A2A16C9D92}
[2011/12/27 21:19:27 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{C90F1E95-7DAC-422D-80BA-7B8737E0EE5C}
[2012/02/24 16:19:31 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{CD042312-3AE6-4AF1-952E-9043ECC76383}
[2012/02/05 13:29:38 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{D50E0ACF-35C1-4C50-8FF7-8FAAF51B51DB}
[2012/09/10 20:18:42 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{D53238E8-3427-491E-A57E-097FA966AAC1}
[2012/01/31 21:39:27 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{D7A6B357-EE5F-4C3D-8B70-673DA74C9150}
[2012/02/20 12:25:04 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{DE5DA50E-4EC1-4957-9F34-A5150681F0B2}
[2012/02/05 00:14:28 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Local\{FBB913BC-E638-4AC9-B4B2-C8D60108FC10}
 
< %localappdata%\*.* >
[2012/03/03 20:15:30 | 000,006,656 | ---- | M] () -- C:\Users\Vincent\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/11 18:54:44 | 000,067,872 | ---- | M] () -- C:\Users\Vincent\AppData\Local\GDIPFONTCACHEV1.DAT
[2012/11/03 02:01:33 | 001,514,355 | -H-- | M] () -- C:\Users\Vincent\AppData\Local\IconCache.db
[2012/09/16 19:53:35 | 000,010,045 | ---- | M] () -- C:\Users\Vincent\AppData\Local\recently-used.xbel
[2012/10/03 14:42:55 | 000,007,606 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Resmon.ResmonCfg
 
< %localappdata%\*.exe /s >
[2011/12/01 16:49:13 | 001,789,040 | ---- | M] (Babylon Ltd.) -- C:\Users\Vincent\AppData\Local\Babylon\Setup\Setup.exe
[2012/10/10 11:06:17 | 001,239,064 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\chrome.exe
[2012/08/30 03:57:20 | 000,081,432 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\21.0.1180.89\chrome_frame_helper.exe
[2012/08/30 03:57:21 | 000,084,504 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\21.0.1180.89\chrome_launcher.exe
[2012/08/30 03:57:23 | 000,200,216 | ---- | M] (TODO: <Company name>) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\21.0.1180.89\delegate_execute.exe
[2012/08/30 02:50:45 | 000,696,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\21.0.1180.89\flashplayerapp.exe
[2012/08/30 03:58:39 | 000,914,968 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\21.0.1180.89\nacl64.exe
[2012/09/12 08:02:23 | 001,541,144 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\21.0.1180.89\Installer\setup.exe
[2012/09/25 10:41:32 | 000,081,432 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.79\chrome_frame_helper.exe
[2012/09/25 10:41:34 | 000,084,504 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.79\chrome_launcher.exe
[2012/09/25 10:41:35 | 000,219,672 | ---- | M] (TODO: <Company name>) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.79\delegate_execute.exe
[2012/09/25 10:42:52 | 000,986,136 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.79\nacl64.exe
[2012/09/27 20:33:54 | 001,578,520 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.79\Installer\setup.exe
[2012/10/10 11:04:50 | 000,081,432 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.94\chrome_frame_helper.exe
[2012/10/10 11:04:51 | 000,084,504 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.94\chrome_launcher.exe
[2012/10/10 11:04:52 | 000,219,672 | ---- | M] (TODO: <Company name>) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.94\delegate_execute.exe
[2012/10/10 11:06:09 | 000,986,136 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.94\nacl64.exe
[2012/10/14 10:46:49 | 001,578,520 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.94\Installer\setup.exe
[2012/07/18 07:12:41 | 000,116,648 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Update\GoogleUpdate.exe
[2012/09/17 06:28:41 | 000,212,432 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler.exe
[2012/09/17 06:28:41 | 000,279,504 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler64.exe
[2012/09/17 06:28:41 | 000,116,648 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Update\1.3.21.123\GoogleUpdate.exe
[2012/09/17 06:28:41 | 000,059,344 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Update\1.3.21.123\GoogleUpdateBroker.exe
[2012/09/17 06:28:41 | 000,059,344 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Update\1.3.21.123\GoogleUpdateOnDemand.exe
[2012/08/22 22:34:00 | 000,763,232 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Update\1.3.21.123\GoogleUpdateSetup.exe
[2012/08/22 22:34:00 | 000,763,232 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.123\GoogleUpdateSetup.exe
[2012/10/10 16:31:00 | 001,204,136 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\22.0.1229.94\22.0.1229.94_22.0.1229.79_chrome_updater.exe
[2012/04/18 22:28:49 | 001,287,528 | ---- | M] (Microsoft Corporation) -- C:\Users\Vincent\AppData\Local\Microsoft\Windows Live\Installer\Catalog\wlsetup.exe
[2012/02/19 20:17:36 | 000,005,632 | ---- | M] (Microsoft Corporation) -- C:\Users\Vincent\AppData\Local\Microsoft\Windows Sidebar\Gadgets\alarmClock.gadget\Sibbl.Gadget.AlarmClock.AlertApp.exe
[2012/02/19 20:17:25 | 000,020,480 | ---- | M] (Microsoft) -- C:\Users\Vincent\AppData\Local\Microsoft\Windows Sidebar\Gadgets\GermanyRain.gadget\RegisterHost.exe
[2012/02/19 20:17:16 | 000,032,768 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Q_driveinfo_1_2.gadget\CDR.exe
[2012/02/19 20:17:15 | 000,065,536 | ---- | M] (Uwe Sieber - www.uwe-sieber.de) -- C:\Users\Vincent\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Q_driveinfo_1_2.gadget\rd.exe
[2012/08/21 10:46:19 | 001,262,924 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AQXL7HNK\MyPhoneExplorer_v2_5185[1].exe
[153 C:\Users\Vincent\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AQXL7HNK\*.tmp files -> C:\Users\Vincent\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AQXL7HNK\*.tmp -> ]
[2012/09/15 21:04:19 | 000,073,624 | ---- | M] (Apple Inc.) -- C:\Users\Vincent\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D6WAZON7\SetupAdmin[1].exe
[115 C:\Users\Vincent\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D6WAZON7\*.tmp files -> C:\Users\Vincent\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D6WAZON7\*.tmp -> ]
[2011/12/25 20:58:32 | 015,134,848 | ---- | M] (Mozilla) -- C:\Users\Vincent\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\96L6T4Q9\Firefox%20Setup%209.0.1[1].exe
[2012/08/22 22:34:00 | 000,763,232 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Temp\GoogleUpdateSetup.exe1e329d7
[2012/10/02 23:12:45 | 067,176,016 | ---- | M] (Microsoft Corporation) -- C:\Users\Vincent\AppData\Local\Temp\mpam-c42fae57.exe
[2009/10/07 09:37:48 | 000,667,485 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Temp\setup.exe
[321 C:\Users\Vincent\AppData\Local\Temp\*.tmp files -> C:\Users\Vincent\AppData\Local\Temp\*.tmp -> ]
[2012/04/14 10:43:23 | 001,207,296 | ---- | M] (Google) -- C:\Users\Vincent\AppData\Local\Temp\._msige61\GoogleEarth.exe
[2012/04/05 02:01:28 | 000,050,688 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\earthflashsol.exe
[2012/04/14 10:22:15 | 000,071,680 | ---- | M] (Google) -- C:\Users\Vincent\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\googleearth.exe
[2012/03/12 10:43:03 | 000,293,888 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\gpsbabel.exe
[2012/04/14 10:22:15 | 000,071,680 | ---- | M] (Google) -- C:\Users\Vincent\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\geplugin.exe
[2012/01/09 18:51:52 | 000,117,560 | ---- | M] (Acresso Software Inc.) -- C:\Users\Vincent\AppData\Local\Temp\{166F6C55-4391-4B83-826E-6E286269CB0B}\ISBEW64.exe
[2012/01/18 21:57:01 | 015,160,720 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Vincent\AppData\Local\Temp\{228F068E-3A8D-45FB-9001-00C969162E5C}\{06C3E79F-FB43-405B-9BA8-DF726B4C18EC}\AdobeAIRInstaller.exe
[2012/01/18 21:57:11 | 014,132,192 | ---- | M] (HTC Corporation                                              ) -- C:\Users\Vincent\AppData\Local\Temp\{228F068E-3A8D-45FB-9001-00C969162E5C}\{26ECEF94-14F8-461F-97D6-11DCE98CEDD4}\HTCDriver.exe
[2012/09/15 12:43:17 | 000,117,560 | ---- | M] (Acresso Software Inc.) -- C:\Users\Vincent\AppData\Local\Temp\{A9C8FF76-9801-4429-BB75-F7F65762CAD4}\ISBEW64.exe
[2012/07/18 07:12:41 | 000,186,832 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Temp\{D05B88EB-53B5-4AF8-94A7-638CD8B0CDF7}\GoogleCrashHandler.exe
[2012/07/18 07:12:41 | 000,244,176 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Temp\{D05B88EB-53B5-4AF8-94A7-638CD8B0CDF7}\GoogleCrashHandler64.exe
[2012/07/18 07:12:41 | 000,116,648 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Temp\{D05B88EB-53B5-4AF8-94A7-638CD8B0CDF7}\GoogleUpdate.exe
[2012/07/18 07:12:41 | 000,059,344 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Temp\{D05B88EB-53B5-4AF8-94A7-638CD8B0CDF7}\GoogleUpdateBroker.exe
[2012/07/18 07:12:41 | 000,059,344 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Temp\{D05B88EB-53B5-4AF8-94A7-638CD8B0CDF7}\GoogleUpdateOnDemand.exe
[2012/06/05 23:57:00 | 000,746,336 | ---- | M] (Google Inc.) -- C:\Users\Vincent\AppData\Local\Temp\{D05B88EB-53B5-4AF8-94A7-638CD8B0CDF7}\GoogleUpdateSetup.exe
[2012/01/09 18:51:23 | 000,117,560 | ---- | M] (Acresso Software Inc.) -- C:\Users\Vincent\AppData\Local\Temp\{D9805C26-7450-4B39-8F2B-430810EAA27C}\ISBEW64.exe
[2012/04/10 21:22:56 | 008,738,464 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\Vincent\AppData\Local\Temp\2617.dir\InstallFlashPlayer.exe
[2012/03/20 19:22:19 | 000,584,072 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Temp\30203883.Uninstall\Uninstall.exe
[2011/11/27 13:49:44 | 001,362,728 | ---- | M] (BabylonToolbar) -- C:\Users\Vincent\AppData\Local\Temp\770A9343-BAB0-7891-BFEF-DEF75B19080A\MyBabylonTB.exe
[2011/12/01 16:49:13 | 001,789,040 | ---- | M] (Babylon Ltd.) -- C:\Users\Vincent\AppData\Local\Temp\770A9343-BAB0-7891-BFEF-DEF75B19080A\Setup.exe
[2012/01/22 14:37:30 | 008,197,280 | ---- | M] (Adobe Systems, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\846E.dir\InstallFlashPlayer.exe
[2012/09/14 21:39:30 | 151,225,144 | ---- | M] (Ashampoo GmbH & Co. KG                                      ) -- C:\Users\Vincent\AppData\Local\Temp\ainetB714607F\ashampoo_photo_commander_10_10.1.3_10509.exe
[2012/01/23 13:11:52 | 000,949,104 | ---- | M] (Opera Software) -- C:\Users\Vincent\AppData\Local\Temp\CProgram Files (x86)Opera\opera.exe
[2012/02/22 16:22:07 | 000,949,104 | ---- | M] (Opera Software) -- C:\Users\Vincent\AppData\Local\Temp\CProgram Files (x86)Opera\OperaUpgrader.exe
[2012/02/22 16:22:07 | 010,625,624 | ---- | M] (Opera Software ASA) -- C:\Users\Vincent\AppData\Local\Temp\CProgram Files (x86)Opera\Opera_11.61_int_Setup.exe
[2012/01/23 09:55:28 | 000,018,944 | ---- | M] (Opera Software) -- C:\Users\Vincent\AppData\Local\Temp\CProgram Files (x86)Opera\program\netscape.exe
[2012/06/03 13:33:24 | 010,620,872 | ---- | M] (Opera Software ASA) -- C:\Users\Vincent\AppData\Local\Temp\CUsersVincentAppDataLocalTempCProgram Files (x86)Opera\Opera-11.64-1403.i386.autoupdate.exe
[2012/05/04 17:13:29 | 000,949,104 | ---- | M] (Opera Software) -- C:\Users\Vincent\AppData\Local\Temp\CUsersVincentAppDataLocalTempCProgram Files (x86)Opera\opera.exe
[2012/06/03 13:33:24 | 000,949,104 | ---- | M] (Opera Software) -- C:\Users\Vincent\AppData\Local\Temp\CUsersVincentAppDataLocalTempCProgram Files (x86)Opera\OperaUpgrader.exe
[2012/05/04 11:55:10 | 000,018,944 | ---- | M] (Opera Software) -- C:\Users\Vincent\AppData\Local\Temp\CUsersVincentAppDataLocalTempCProgram Files (x86)Opera\program\netscape.exe
[2012/01/22 14:36:47 | 008,197,280 | ---- | M] (Adobe Systems, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\DE8F.dir\InstallFlashPlayer.exe
[2011/11/10 12:34:40 | 000,623,384 | ---- | M] (Fujitsu Technology Solutions) -- C:\Users\Vincent\AppData\Local\Temp\DeskUpdate\DeskUpdate.exe
[2011/11/10 12:34:40 | 000,365,848 | ---- | M] (Fujitsu Technology Solutions) -- C:\Users\Vincent\AppData\Local\Temp\DeskUpdate\ducmd.exe
[2011/11/10 12:34:40 | 000,075,544 | ---- | M] (Microsoft Corporation) -- C:\Users\Vincent\AppData\Local\Temp\DeskUpdate\infinst64.exe
[2012/01/22 18:53:11 | 001,255,464 | ---- | M] (Fujitsu Technology Solutions                                ) -- C:\Users\Vincent\AppData\Local\Temp\DeskUpdate2d587e59\ftsdeskupdatesetup.exe
[2012/09/15 09:49:07 | 001,998,648 | ---- | M] (Fujitsu Technology Solutions                                ) -- C:\Users\Vincent\AppData\Local\Temp\DeskUpdate7b7e3374\ftsdeskupdatesetup.exe
[2012/05/09 16:33:20 | 000,506,056 | ---- | M] (DealPly) -- C:\Users\Vincent\AppData\Local\Temp\is1373634743\dp.exe
[2012/03/22 08:39:42 | 001,418,152 | ---- | M] (Alactro LLC) -- C:\Users\Vincent\AppData\Local\Temp\is1373634743\ezLookerSilent_DDD_FTT_BG_BD_BVD.exe
[2012/08/15 13:41:36 | 000,899,224 | ---- | M] (Babylon Ltd.) -- C:\Users\Vincent\AppData\Local\Temp\is1373634743\MyBabylonTB.exe
[2012/03/16 15:49:30 | 000,197,120 | ---- | M] (Setup ©                      ) -- C:\Users\Vincent\AppData\Local\Temp\is1373634743\PKExecuter.exe
[2012/09/06 22:34:59 | 000,270,304 | ---- | M] (Mozilla Foundation) -- C:\Users\Vincent\AppData\Local\Temp\MozUpdater\updater.exe
[2012/02/23 20:37:45 | 000,019,968 | ---- | M] (1am Studios) -- C:\Users\Vincent\AppData\Local\Temp\SharePodLib\bin\SharePodHelper.exe
[2012/02/20 10:55:13 | 000,459,568 | ---- | M] (SweetIM Technologies, Ltd.) -- C:\Users\Vincent\AppData\Local\Temp\SweetIMReinstall\SweetImSetup.exe
[2011/04/07 20:58:14 | 004,669,288 | ---- | M] (Bullzip                                                    ) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_BullzipPDFPrinter_7_2_0_1304.zip\BullzipPDFPrinter_7_2_0_1304.exe
[2012/01/20 18:36:02 | 007,745,728 | ---- | M] (WindSolutions) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_CopyTransDEv4.821.zip\CopyTrans.exe
[2012/01/09 18:51:19 | 003,973,184 | ---- | M] (FUJITSU LIMITED                                              ) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_FTS_FujitsuHotkeyUtility_3601_1042670.zip\Fujitsu_HotkeyUtility_3.60.1.0\setup.exe
[2011/10/07 16:06:24 | 003,756,544 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Temp\Temp1_paint.net.3.5.10.zip\Paint.NET.3.5.10.Install.exe
[2008/01/18 11:30:56 | 000,142,336 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinNT5\x64\InstNT.exe
[2006/02/07 09:34:46 | 000,174,080 | ---- | M] (InstallShield Software Corporation) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinNT5\x64\setup.exe
[2008/01/18 10:54:30 | 000,156,160 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinNT5\x64\SynAcer.exe
[2008/01/18 10:53:04 | 000,233,472 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinNT5\x64\SynMood.exe
[2008/01/18 11:04:56 | 001,214,976 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinNT5\x64\SynTPEnh.exe
[2008/01/18 10:53:56 | 000,241,664 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinNT5\x64\SynZMetr.exe
[2008/01/18 11:10:36 | 000,327,680 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinNT5\x64\Tutorial.exe
[2008/01/18 11:30:50 | 000,118,784 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinNT5\x86\InstNT.exe
[2006/02/07 09:34:46 | 000,174,080 | ---- | M] (InstallShield Software Corporation) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinNT5\x86\setup.exe
[2008/01/18 10:54:26 | 000,139,264 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinNT5\x86\SynAcer.exe
[2008/01/18 10:53:04 | 000,233,472 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinNT5\x86\SynMood.exe
[2008/01/18 11:04:08 | 001,028,096 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinNT5\x86\SynTPEnh.exe
[2008/01/18 10:53:56 | 000,241,664 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinNT5\x86\SynZMetr.exe
[2008/01/18 11:10:36 | 000,327,680 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinNT5\x86\Tutorial.exe
[2006/10/12 17:25:02 | 000,929,248 | ---- | M] (Microsoft Corporation) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x64\dpinst.exe
[2008/01/18 11:31:30 | 000,147,752 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x64\InstNT.exe
[2008/01/18 11:31:28 | 000,161,064 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x64\setup.exe
[2008/01/18 10:54:30 | 000,156,160 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x64\SynAcer.exe
[2008/01/18 10:53:04 | 000,233,472 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x64\SynMood.exe
[2008/01/18 11:31:28 | 001,220,392 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x64\SynTPEnh.exe
[2008/01/18 11:31:32 | 000,119,080 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x64\SynTPHelper.exe
[2008/01/18 10:53:56 | 000,241,664 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x64\SynZMetr.exe
[2008/01/18 11:10:36 | 000,327,680 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x64\Tutorial.exe
[2006/10/12 17:25:02 | 000,794,080 | ---- | M] (Microsoft Corporation) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x86\dpinst.exe
[2008/01/18 11:31:24 | 000,124,200 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x86\InstNT.exe
[2008/01/18 11:31:22 | 000,161,064 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x86\setup.exe
[2008/01/18 10:54:26 | 000,139,264 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x86\SynAcer.exe
[2008/01/18 10:53:04 | 000,233,472 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x86\SynMood.exe
[2008/01/18 11:31:22 | 001,033,512 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x86\SynTPEnh.exe
[2008/01/18 11:31:32 | 000,095,528 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x86\SynTPHelper.exe
[2008/01/18 10:53:56 | 000,241,664 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x86\SynZMetr.exe
[2008/01/18 11:10:36 | 000,327,680 | ---- | M] (Synaptics, Inc.) -- C:\Users\Vincent\AppData\Local\Temp\Temp1_Touchpad_Synaptics_v10.2.4_Vistax32x64_XPx32x64_modded_build2.zip\WinWDF\x86\Tutorial.exe
[2008/12/28 17:47:48 | 016,410,637 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Temp\Temp1_yam-win_1.8.zip\YamiPod.exe
[2008/12/28 17:47:48 | 016,410,637 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Temp\Temp2_yam-win_1.8.zip\YamiPod.exe
[2011/07/16 13:55:30 | 021,073,936 | ---- | M] () -- C:\Users\Vincent\AppData\Local\Temp\VideoLAN\vlc-1.1.11-win32.exe
 
< %allusersprofile%\*.  >
[2012/09/15 21:09:05 | 000,000,000 | ---D | M] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2012/09/14 19:21:03 | 000,000,000 | ---D | M] -- C:\ProgramData\ABBYY
[2012/03/21 12:46:24 | 000,000,000 | ---D | M] -- C:\ProgramData\ACD Systems
[2012/08/24 20:21:44 | 000,000,000 | ---D | M] -- C:\ProgramData\Adobe
[2011/12/26 01:28:49 | 000,000,000 | ---D | M] -- C:\ProgramData\Apple
[2012/01/22 19:21:20 | 000,000,000 | ---D | M] -- C:\ProgramData\Apple Computer
[2009/07/14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2012/09/14 21:35:01 | 000,000,000 | ---D | M] -- C:\ProgramData\ashampoo
[2012/01/08 22:29:00 | 000,000,000 | ---D | M] -- C:\ProgramData\AVG2012
[2012/01/26 21:59:37 | 000,000,000 | ---D | M] -- C:\ProgramData\Babylon
[2012/01/08 22:19:21 | 000,000,000 | -H-D | M] -- C:\ProgramData\Common Files
[2011/12/26 00:40:53 | 000,000,000 | ---D | M] -- C:\ProgramData\CyberLink
[2009/07/14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2009/07/14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2012/01/08 17:13:03 | 000,000,000 | ---D | M] -- C:\ProgramData\Easy Driver Pro
[2009/07/14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2012/01/09 03:18:06 | 000,000,000 | ---D | M] -- C:\ProgramData\Fujitsu
[2011/12/25 21:11:02 | 000,000,000 | ---D | M] -- C:\ProgramData\Google
[2012/09/10 20:20:09 | 000,000,000 | ---D | M] -- C:\ProgramData\InstallShield
[2012/10/03 18:19:01 | 000,000,000 | ---D | M] -- C:\ProgramData\MFAData
[2012/01/16 02:07:00 | 000,000,000 | --SD | M] -- C:\ProgramData\Microsoft
[2012/10/15 17:27:20 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft Help
[2012/05/07 08:57:39 | 000,000,000 | ---D | M] -- C:\ProgramData\Mozilla
[2011/12/25 22:36:35 | 000,000,000 | ---D | M] -- C:\ProgramData\Norton
[2011/12/25 20:19:25 | 000,000,000 | ---D | M] -- C:\ProgramData\NortonInstaller
[2011/12/25 22:36:34 | 000,000,000 | ---D | M] -- C:\ProgramData\Partner
[2012/02/06 01:20:07 | 000,000,000 | ---D | M] -- C:\ProgramData\RapidSolution
[2012/09/11 15:31:33 | 000,000,000 | ---D | M] -- C:\ProgramData\Skype
[2012/05/07 07:33:00 | 000,000,000 | ---D | M] -- C:\ProgramData\Sony Corporation
[2009/07/14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2012/01/22 12:28:02 | 000,000,000 | ---D | M] -- C:\ProgramData\Sun
[2012/01/07 07:42:15 | 000,000,000 | ---D | M] -- C:\ProgramData\Synaptics
[2012/08/24 18:58:26 | 000,000,000 | ---D | M] -- C:\ProgramData\Tarma Installer
[2012/01/22 14:38:04 | 000,000,000 | ---D | M] -- C:\ProgramData\Temp
[2009/07/14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2012/06/21 20:13:45 | 000,000,000 | ---D | M] -- C:\ProgramData\TerraTec
[2012/07/22 21:58:05 | 000,000,000 | ---D | M] -- C:\ProgramData\TrackMania
[2011/12/26 03:28:05 | 000,000,000 | ---D | M] -- C:\ProgramData\VirtualizedApplications
[2012/09/10 20:19:38 | 000,000,000 | ---D | M] -- C:\ProgramData\Vodafone
[2012/02/07 00:10:49 | 000,000,000 | ---D | M] -- C:\ProgramData\WindSolutions
[2011/12/26 01:31:53 | 000,000,000 | ---D | M] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
 
< %allusersprofile%\*.* >
[2008/05/23 16:48:50 | 000,020,270 | ---- | M] () -- C:\ProgramData\DeviceInstaller.xml
[2008/06/23 12:02:02 | 000,097,410 | R--- | M] () -- C:\ProgramData\DeviceManager.xml.rc4
 
< %allusersprofile%\*.exe /s >
[2012/08/21 12:01:28 | 001,977,816 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69\GEARDIFx.exe
[2012/08/21 12:01:20 | 000,131,544 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\DifXInst64.exe
[2012/01/03 08:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\Reader\9.4\ARM\5513\AcrobatUpdater.exe
[2012/01/03 08:37:53 | 000,843,712 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\Reader\9.4\ARM\5513\AdobeARM.exe
[2012/01/03 08:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\Reader\9.4\ARM\5513\AdobeARMHelper.exe
[2012/01/03 08:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\Reader\9.4\ARM\5513\ReaderUpdater.exe
[2012/01/03 18:46:15 | 000,345,520 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1031-7B44-A95000000001}\Setup.exe
[2012/01/03 18:44:25 | 000,342,984 | ---- | M] (Adobe Systems Incorporated) -- C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1031-7B44-AA1000000001}\setup.exe
[2012/09/15 21:04:19 | 000,073,624 | ---- | M] (Apple Inc.) -- C:\ProgramData\Apple Computer\Installer Cache\iTunes 10.7.0.21\SetupAdmin.exe
[2011/12/26 03:42:57 | 000,073,584 | ---- | M] (Apple Inc.) -- C:\ProgramData\Apple Computer\Installer Cache\Safari 5.34.52.7\SetupAdmin.exe
[2012/03/08 17:18:22 | 000,073,584 | ---- | M] (Apple Inc.) -- C:\ProgramData\Apple Computer\Installer Cache\Safari 5.34.54.16\SetupAdmin.exe
[2012/04/10 20:53:32 | 000,073,584 | ---- | M] (Apple Inc.) -- C:\ProgramData\Apple Computer\Installer Cache\Safari 5.34.55.3\SetupAdmin.exe
[2012/07/04 06:10:27 | 000,073,584 | ---- | M] (Apple Inc.) -- C:\ProgramData\Apple Computer\Installer Cache\Safari 5.34.57.2\SetupAdmin.exe
[2009/10/09 13:51:22 | 003,973,184 | ---- | M] (FUJITSU LIMITED                                              ) -- C:\ProgramData\Fujitsu\DeskUpdate\1042670\setup.exe
[2009/12/24 12:46:40 | 016,024,872 | ---- | M] (CSR Plc.                                                    ) -- C:\ProgramData\Fujitsu\DeskUpdate\1046746\setup.exe
[2010/06/23 17:20:32 | 000,283,024 | ---- | M] (FUJITSU LIMITED) -- C:\ProgramData\Fujitsu\DeskUpdate\1052689\Setup.exe
[2012/01/09 03:19:26 | 003,715,072 | ---- | M] () -- C:\ProgramData\Fujitsu\DeskUpdate\download\files\1042670_fujitsu_3_60_1.exe
[2012/01/09 03:19:55 | 015,872,000 | ---- | M] () -- C:\ProgramData\Fujitsu\DeskUpdate\download\files\1046746_csr_5_0_14.exe
[2012/01/09 03:19:42 | 019,275,776 | ---- | M] () -- C:\ProgramData\Fujitsu\DeskUpdate\download\files\1052689_fujitsu_5_3_0_1.exe
[2010/03/12 04:50:30 | 001,100,664 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\OEMOffice14\Office14\setup.exe
[2010/03/24 01:51:52 | 000,838,536 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\OEMOffice14\Office14\Office.de-de\DW20.EXE
[2010/03/24 01:51:58 | 000,519,584 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\OEMOffice14\Office14\Office.de-de\dwtrig20.exe
[2010/03/16 10:34:53 | 000,149,352 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\OEMOffice14\Office14\SingleImage.WW\ose.exe
[2010/02/28 10:33:12 | 005,336,456 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\OEMOffice14\OStarter\de-de\Office.exe
[2010/03/31 02:20:14 | 001,629,584 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\OEMOffice14\OStarter\de-de\SetupConsumerC2R.exe
[2010/03/31 02:20:14 | 001,629,584 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\OEMOffice14\OStarter\de-de\SetupConsumerC2ROLW.exe
[2011/11/16 00:16:48 | 005,590,528 | ---- | M] (Jeffrey Harris) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePod.exe
[2011/03/11 04:29:12 | 000,227,984 | R-S- | M] (Tarma Software Research Pty Ltd) -- C:\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\Setup.exe
[2011/12/25 20:09:51 | 000,036,864 | ---- | M] ( ) -- C:\ProgramData\Temp\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\PostBuild.exe
 
<          >
[2009/07/14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009/07/14 06:08:49 | 000,031,622 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/04/19 21:52:04 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012/05/17 17:32:45 | 000,001,108 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012/05/17 17:32:45 | 000,001,112 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012/09/12 07:55:31 | 000,001,076 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1655660024-2649062184-858687661-1000Core.job
[2012/09/12 07:55:31 | 000,001,128 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1655660024-2649062184-858687661-1000UA.job
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:DBC416F8

< End of report >


VHSK 03.11.2012 11:25

ja sry für das durcheinander, habe das erste ausversehen im alten beitrag eingefügt als edit und das andere 2 mal gepostet... jetzt müsste es stimmen (?)

ryder 03.11.2012 11:31

Morgen! Du hast mir zweimal die OTL.txt gepostet. Ich bräuchte noch die extras.txt bevor es losgeht.

VHSK 03.11.2012 11:34

[QUOTE=VHSK;949744]ja sry für das durcheinander, habe das erste ausversehen im alten beitrag eingefügt als edit und das andere 2 mal gepostet... jetzt müsste es stimmen (?)

ryder 03.11.2012 11:35

Alles klar, dann noch tdsskiller-log und dann gehts los :)

VHSK 03.11.2012 11:38

Liste der Anhänge anzeigen (Anzahl: 1)
keine datei ausgeworfen
laptop ist iwie wieder normal schnell im moment :D

ryder 03.11.2012 11:41

In Ordnung, wir räumen aber trotzdem noch ein wenig Müll auf und machen einen Rundumcheck :)

Schritt 1:
AdwCleaner: Werbeprogramme suchen und löschen

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Löschen.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.
Schritt 2:
Quick-Scan mit Malwarebytes

Downloade Dir bitte Malwarebytes
  • Installiere das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung --> Suche nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere Quickscan durchführen und drücke auf Scannen.
  • Wenn der Scan beendet ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.
Schritt 3:
ESET Online Scanner

Zitat:

Wichtig:
Bitte während der Online-Scans evtl. vorhandene externe Festplatten einschalten!
Bitte während der Scans alle Hintergrundwächter (Anti-Virus-Programm, Firewall, Skriptblocking und ähnliches) abstellen und nicht vergessen, alles hinterher wieder einzuschalten.

Wenn der Scan beendet wurdeBitte poste die ESET.txt hier oder teile mir mit, dass nichts gefunden wurde.

Schritt 4:
Kontrollscan mit OTL
  • Starte bitte OTL.exe
  • Stelle sicher, dass "Alle Benuzter Scannen" angehakt ist!
  • Drücke den Quick Scan Button.
  • Poste die OTL.txt hier in deinen Thread.

VHSK 03.11.2012 12:30

Edit: gibt wohl eine datei für schritt 3 (wie beschrieben unter c:, hab ich übersehen), poste ich wenn ich wieder am laptop bin..

Was bedeutet eigentlich registry und was kann man aus den ganzen scan berichten so lesen *neugier*? :)

Und wie funktionieren eig die cleaner, habe mal gelesen sie können auch große Probleme verursachen (weil si u.U. ausversehen wichtige dateien mitlöschen)?

PS: laptop hakt übrigens doch noch, ebenso immernoch sehr langsames runterfahren (habe ich iwann abgebrochen) und hochfahren wenn er bereits den normalen hintergrund anzeigt (also zb beim starten von den minianwendungen etc) danach gehts einigermaßen. Sind also doch noch nicht am Ziel.. also - fortsetzung folgt, sobald ich wieder am laptop bin.

ryder 03.11.2012 12:32

Ganz einfach gesprochen, wenn wir Registry-Cleaner sehen sagen wir das ...

Warnung: Registry-Cleaner
Zitat:

Lesestoff:
Registry-Cleaner und temporäre Dateien
Aus deinen Logfiles geht hervor, dass du eines dieser Programme benutzt. Wir empfehlen solche Programme nicht zu benutzen. Die Registrierung ist ein zentraler Bestandteil des Betriebssystems. Löscht ein Registry-Cleaner die falschen Zeilen kann das im schlimmsten Fall dazu führen, dass dein Computer unbootbar wird. Einige verwaiste Registryeinträge sind nicht weiter tragisch und auch die höhere Geschwindigkeit beim Booten ist normalerweise nicht merklich. Das Risiko, dass das Programm dein System "zerstört" ist einfach zu hoch. Ich empfehle dir also dringend, das Programm zu deinstallieren.

Beispielsweise bei CCleaner wird auch eine Funktion angeboten die temporären Dateien zu löschen. Wenn du von der Registrybereinigung die Finger läßt ist gegen den Einsatz von CCleaner nichts zu sagen. Ein alternatives Programm dafür möchte ich dir gerne noch empfehlen: TFC - einfach als Administrator starten und zurücklehnen.
Brauchst du mehr Infos? :)

VHSK 03.11.2012 12:45

Gerne :) Was ist die registry? Und was genau erfährt man aus meinen geposteten berichten?

ryder 03.11.2012 12:48

Registrierungsdatenbank :Boogie:

Wir erfahren eine Menge über dein System - was genau, lernst du bei uns an der Akademie.

VHSK 03.11.2012 17:52

der nachtrag zu schritt 3:

teil 2 folgt

VHSK 03.11.2012 18:01

Liste der Anhänge anzeigen (Anzahl: 1)
das andere .txt war zu groß um als datei hochgeladen zu werden...

Code:

11:35:20.0394 42416  TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
11:35:20.0503 42416  ============================================================
11:35:20.0503 42416  Current date / time: 2012/11/03 11:35:20.0503
11:35:20.0503 42416  SystemInfo:
11:35:20.0503 42416 
11:35:20.0503 42416  OS Version: 6.1.7601 ServicePack: 1.0
11:35:20.0503 42416  Product type: Workstation
11:35:20.0503 42416  ComputerName: LIFEBOOK-A530
11:35:20.0503 42416  UserName: Vincent
11:35:20.0503 42416  Windows directory: C:\Windows
11:35:20.0503 42416  System windows directory: C:\Windows
11:35:20.0503 42416  Running under WOW64
11:35:20.0503 42416  Processor architecture: Intel x64
11:35:20.0503 42416  Number of processors: 4
11:35:20.0503 42416  Page size: 0x1000
11:35:20.0503 42416  Boot type: Normal boot
11:35:20.0503 42416  ============================================================
11:35:21.0611 42416  Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:35:21.0611 42416  ============================================================
11:35:21.0611 42416  \Device\Harddisk0\DR0:
11:35:21.0611 42416  MBR partitions:
11:35:21.0611 42416  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x401000, BlocksNum 0x2502D2B0
11:35:21.0611 42416  ============================================================
11:35:21.0657 42416  C: <-> \Device\Harddisk0\DR0\Partition1
11:35:21.0657 42416  ============================================================
11:35:21.0657 42416  Initialize success
11:35:21.0657 42416  ============================================================
11:35:48.0928 43128  ============================================================
11:35:48.0928 43128  Scan started
11:35:48.0928 43128  Mode: Manual; TDLFS;
11:35:48.0928 43128  ============================================================
11:35:49.0287 43128  ================ Scan system memory ========================
11:35:49.0287 43128  System memory - ok
11:35:49.0287 43128  ================ Scan services =============================
11:35:49.0443 43128  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
11:35:49.0459 43128  1394ohci - ok
11:35:49.0583 43128  [ F9C202597DD9340260DF2482500DFCF9 ] ABBYY.Licensing.FineReader.ScreenshotReader.9.0 C:\Program Files (x86)\ABBYY Screenshot Reader\NetworkLicenseServer.exe
11:35:49.0615 43128  ABBYY.Licensing.FineReader.ScreenshotReader.9.0 - ok
11:35:49.0677 43128  [ 6C1437F6CB5889605BF3016D0DB316A8 ] AbilisT        C:\Windows\system32\DRIVERS\AbilisBdaTuner.sys
11:35:49.0693 43128  AbilisT - ok
11:35:49.0739 43128  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
11:35:49.0739 43128  ACPI - ok
11:35:49.0755 43128  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi        C:\Windows\system32\drivers\acpipmi.sys
11:35:49.0755 43128  AcpiPmi - ok
11:35:49.0833 43128  [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
11:35:49.0833 43128  AdobeARMservice - ok
11:35:49.0973 43128  [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
11:35:49.0989 43128  AdobeFlashPlayerUpdateSvc - ok
11:35:50.0036 43128  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
11:35:50.0051 43128  adp94xx - ok
11:35:50.0067 43128  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci        C:\Windows\system32\drivers\adpahci.sys
11:35:50.0083 43128  adpahci - ok
11:35:50.0114 43128  [ E109549C90F62FB570B9540C4B148E54 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
11:35:50.0114 43128  adpu320 - ok
11:35:50.0145 43128  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
11:35:50.0145 43128  AeLookupSvc - ok
11:35:50.0223 43128  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD            C:\Windows\system32\drivers\afd.sys
11:35:50.0239 43128  AFD - ok
11:35:50.0254 43128  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\Windows\system32\drivers\agp440.sys
11:35:50.0254 43128  agp440 - ok
11:35:50.0285 43128  [ 3290D6946B5E30E70414990574883DDB ] ALG            C:\Windows\System32\alg.exe
11:35:50.0285 43128  ALG - ok
11:35:50.0301 43128  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\Windows\system32\drivers\aliide.sys
11:35:50.0301 43128  aliide - ok
11:35:50.0317 43128  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\Windows\system32\drivers\amdide.sys
11:35:50.0332 43128  amdide - ok
11:35:50.0332 43128  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
11:35:50.0348 43128  AmdK8 - ok
11:35:50.0363 43128  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\Windows\system32\drivers\amdppm.sys
11:35:50.0363 43128  AmdPPM - ok
11:35:50.0379 43128  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata        C:\Windows\system32\drivers\amdsata.sys
11:35:50.0395 43128  amdsata - ok
11:35:50.0410 43128  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
11:35:50.0410 43128  amdsbs - ok
11:35:50.0426 43128  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata        C:\Windows\system32\drivers\amdxata.sys
11:35:50.0426 43128  amdxata - ok
11:35:50.0457 43128  [ 89A69C3F2F319B43379399547526D952 ] AppID          C:\Windows\system32\drivers\appid.sys
11:35:50.0473 43128  AppID - ok
11:35:50.0488 43128  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
11:35:50.0488 43128  AppIDSvc - ok
11:35:50.0504 43128  [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo        C:\Windows\System32\appinfo.dll
11:35:50.0504 43128  Appinfo - ok
11:35:50.0613 43128  [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
11:35:50.0613 43128  Apple Mobile Device - ok
11:35:50.0644 43128  [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt        C:\Windows\System32\appmgmts.dll
11:35:50.0644 43128  AppMgmt - ok
11:35:50.0675 43128  [ C484F8CEB1717C540242531DB7845C4E ] arc            C:\Windows\system32\drivers\arc.sys
11:35:50.0675 43128  arc - ok
11:35:50.0707 43128  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\Windows\system32\drivers\arcsas.sys
11:35:50.0707 43128  arcsas - ok
11:35:50.0816 43128  [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
11:35:50.0816 43128  aspnet_state - ok
11:35:50.0863 43128  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
11:35:50.0863 43128  AsyncMac - ok
11:35:50.0878 43128  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi          C:\Windows\system32\drivers\atapi.sys
11:35:50.0878 43128  atapi - ok
11:35:50.0972 43128  [ D6CAD7E5B05055BB8226BDCB1644DA27 ] athr            C:\Windows\system32\DRIVERS\athrx.sys
11:35:51.0050 43128  athr - ok
11:35:51.0097 43128  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
11:35:51.0112 43128  AudioEndpointBuilder - ok
11:35:51.0143 43128  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
11:35:51.0143 43128  AudioSrv - ok
11:35:51.0830 43128  [ F6A528DE535396C2FB1A4E3C6F00CEC4 ] AVGIDSAgent    C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
11:35:52.0298 43128  AVGIDSAgent - ok
11:35:52.0345 43128  [ 1B2E9FCDC26DC7C81D4131430E2DC936 ] AVGIDSDriver    C:\Windows\system32\DRIVERS\avgidsdrivera.sys
11:35:52.0345 43128  AVGIDSDriver - ok
11:35:52.0391 43128  [ 0F293406F64B48D5D2F0D3A1117F3A83 ] AVGIDSFilter    C:\Windows\system32\DRIVERS\avgidsfiltera.sys
11:35:52.0391 43128  AVGIDSFilter - ok
11:35:52.0438 43128  [ CFFC3A4A638F462E0561CB368B9A7A3A ] AVGIDSHA        C:\Windows\system32\DRIVERS\avgidsha.sys
11:35:52.0438 43128  AVGIDSHA - ok
11:35:52.0485 43128  [ 221FEBAB02D6C97C95558348CC354A85 ] Avgldx64        C:\Windows\system32\DRIVERS\avgldx64.sys
11:35:52.0485 43128  Avgldx64 - ok
11:35:52.0516 43128  [ A6AEC362AAE5E2DDA7445E7690CB0F33 ] Avgmfx64        C:\Windows\system32\DRIVERS\avgmfx64.sys
11:35:52.0516 43128  Avgmfx64 - ok
11:35:52.0547 43128  [ 645C7F0A0E39758A0024A9B1748273C0 ] Avgrkx64        C:\Windows\system32\DRIVERS\avgrkx64.sys
11:35:52.0547 43128  Avgrkx64 - ok
11:35:52.0579 43128  [ F8C3C7ED612A41B05C66358FC9786BFD ] Avgtdia        C:\Windows\system32\DRIVERS\avgtdia.sys
11:35:52.0579 43128  Avgtdia - ok
11:35:52.0610 43128  [ EA1145DEBCD508FD25BD1E95C4346929 ] avgwd          C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
11:35:52.0610 43128  avgwd - ok
11:35:52.0641 43128  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\Windows\System32\AxInstSV.dll
11:35:52.0641 43128  AxInstSV - ok
11:35:52.0672 43128  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv        C:\Windows\system32\drivers\bxvbda.sys
11:35:52.0688 43128  b06bdrv - ok
11:35:52.0719 43128  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
11:35:52.0719 43128  b57nd60a - ok
11:35:52.0735 43128  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\Windows\System32\bdesvc.dll
11:35:52.0750 43128  BDESVC - ok
11:35:52.0766 43128  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\Windows\system32\drivers\Beep.sys
11:35:52.0766 43128  Beep - ok
11:35:52.0797 43128  [ 82974D6A2FD19445CC5171FC378668A4 ] BFE            C:\Windows\System32\bfe.dll
11:35:52.0828 43128  BFE - ok
11:35:52.0875 43128  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\Windows\System32\qmgr.dll
11:35:52.0906 43128  BITS - ok
11:35:52.0953 43128  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
11:35:52.0953 43128  blbdrive - ok
11:35:53.0047 43128  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
11:35:53.0047 43128  Bonjour Service - ok
11:35:53.0109 43128  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
11:35:53.0109 43128  bowser - ok
11:35:53.0140 43128  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
11:35:53.0140 43128  BrFiltLo - ok
11:35:53.0156 43128  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
11:35:53.0156 43128  BrFiltUp - ok
11:35:53.0187 43128  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser        C:\Windows\System32\browser.dll
11:35:53.0187 43128  Browser - ok
11:35:53.0218 43128  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
11:35:53.0234 43128  Brserid - ok
11:35:53.0249 43128  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
11:35:53.0249 43128  BrSerWdm - ok
11:35:53.0265 43128  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
11:35:53.0265 43128  BrUsbMdm - ok
11:35:53.0281 43128  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
11:35:53.0296 43128  BrUsbSer - ok
11:35:53.0343 43128  [ CF98190A94F62E405C8CB255018B2315 ] BthEnum        C:\Windows\system32\drivers\BthEnum.sys
11:35:53.0343 43128  BthEnum - ok
11:35:53.0374 43128  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
11:35:53.0390 43128  BTHMODEM - ok
11:35:53.0421 43128  [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan          C:\Windows\system32\DRIVERS\bthpan.sys
11:35:53.0421 43128  BthPan - ok
11:35:53.0452 43128  [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT        C:\Windows\System32\Drivers\BTHport.sys
11:35:53.0468 43128  BTHPORT - ok
11:35:53.0499 43128  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv        C:\Windows\system32\bthserv.dll
11:35:53.0499 43128  bthserv - ok
11:35:53.0530 43128  [ F188B7394D81010767B6DF3178519A37 ] BTHUSB          C:\Windows\System32\Drivers\BTHUSB.sys
11:35:53.0530 43128  BTHUSB - ok
11:35:53.0577 43128  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
11:35:53.0577 43128  cdfs - ok
11:35:53.0593 43128  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
11:35:53.0593 43128  cdrom - ok
11:35:53.0624 43128  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc    C:\Windows\System32\certprop.dll
11:35:53.0624 43128  CertPropSvc - ok
11:35:53.0639 43128  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\Windows\system32\drivers\circlass.sys
11:35:53.0639 43128  circlass - ok
11:35:53.0671 43128  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\Windows\system32\CLFS.sys
11:35:53.0671 43128  CLFS - ok
11:35:53.0749 43128  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:35:53.0749 43128  clr_optimization_v2.0.50727_32 - ok
11:35:53.0795 43128  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
11:35:53.0795 43128  clr_optimization_v2.0.50727_64 - ok
11:35:53.0858 43128  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
11:35:53.0858 43128  clr_optimization_v4.0.30319_32 - ok
11:35:53.0889 43128  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
11:35:53.0889 43128  clr_optimization_v4.0.30319_64 - ok
11:35:53.0920 43128  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
11:35:53.0920 43128  CmBatt - ok
11:35:53.0951 43128  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\Windows\system32\drivers\cmdide.sys
11:35:53.0951 43128  cmdide - ok
11:35:54.0014 43128  [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG            C:\Windows\system32\Drivers\cng.sys
11:35:54.0014 43128  CNG - ok
11:35:54.0045 43128  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
11:35:54.0045 43128  Compbatt - ok
11:35:54.0045 43128  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
11:35:54.0061 43128  CompositeBus - ok
11:35:54.0061 43128  COMSysApp - ok
11:35:54.0092 43128  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
11:35:54.0092 43128  crcdisk - ok
11:35:54.0139 43128  [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc        C:\Windows\system32\cryptsvc.dll
11:35:54.0139 43128  CryptSvc - ok
11:35:54.0185 43128  [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC            C:\Windows\system32\drivers\csc.sys
11:35:54.0201 43128  CSC - ok
11:35:54.0232 43128  [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService      C:\Windows\System32\cscsvc.dll
11:35:54.0263 43128  CscService - ok
11:35:54.0310 43128  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\Windows\system32\rpcss.dll
11:35:54.0326 43128  DcomLaunch - ok
11:35:54.0357 43128  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc      C:\Windows\System32\defragsvc.dll
11:35:54.0357 43128  defragsvc - ok
11:35:54.0388 43128  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
11:35:54.0388 43128  DfsC - ok
11:35:54.0404 43128  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\Windows\system32\dhcpcore.dll
11:35:54.0419 43128  Dhcp - ok
11:35:54.0419 43128  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\Windows\system32\drivers\discache.sys
11:35:54.0419 43128  discache - ok
11:35:54.0466 43128  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\Windows\system32\drivers\disk.sys
11:35:54.0466 43128  Disk - ok
11:35:54.0482 43128  [ 5DB085A8A6600BE6401F2B24EECB5415 ] dmvsc          C:\Windows\system32\drivers\dmvsc.sys
11:35:54.0482 43128  dmvsc - ok
11:35:54.0513 43128  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
11:35:54.0529 43128  Dnscache - ok
11:35:54.0560 43128  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc        C:\Windows\System32\dot3svc.dll
11:35:54.0560 43128  dot3svc - ok
11:35:54.0607 43128  [ B42ED0320C6E41102FDE0005154849BB ] Dot4            C:\Windows\system32\DRIVERS\Dot4.sys
11:35:54.0607 43128  Dot4 - ok
11:35:54.0638 43128  [ E9F5969233C5D89F3C35E3A66A52A361 ] Dot4Print      C:\Windows\system32\DRIVERS\Dot4Prt.sys
11:35:54.0638 43128  Dot4Print - ok
11:35:54.0638 43128  [ 488669CD1CD3BDCFDD9A5FDA72209069 ] Dot4Scan        C:\Windows\system32\DRIVERS\Dot4Scan.sys
11:35:54.0653 43128  Dot4Scan - ok
11:35:54.0685 43128  [ FD05A02B0370BC3000F402E543CA5814 ] dot4usb        C:\Windows\system32\DRIVERS\dot4usb.sys
11:35:54.0685 43128  dot4usb - ok
11:35:54.0700 43128  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS            C:\Windows\system32\dps.dll
11:35:54.0700 43128  DPS - ok
11:35:54.0731 43128  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
11:35:54.0731 43128  drmkaud - ok
11:35:54.0778 43128  [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
11:35:54.0825 43128  DXGKrnl - ok
11:35:54.0841 43128  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost        C:\Windows\System32\eapsvc.dll
11:35:54.0841 43128  EapHost - ok
11:35:54.0950 43128  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv          C:\Windows\system32\drivers\evbda.sys
11:35:55.0043 43128  ebdrv - ok
11:35:55.0075 43128  [ C118A82CD78818C29AB228366EBF81C3 ] EFS            C:\Windows\System32\lsass.exe
11:35:55.0075 43128  EFS - ok
11:35:55.0137 43128  [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
11:35:55.0168 43128  ehRecvr - ok
11:35:55.0184 43128  [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched        C:\Windows\ehome\ehsched.exe
11:35:55.0184 43128  ehSched - ok
11:35:55.0215 43128  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
11:35:55.0215 43128  elxstor - ok
11:35:55.0246 43128  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\Windows\system32\drivers\errdev.sys
11:35:55.0246 43128  ErrDev - ok
11:35:55.0309 43128  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem    C:\Windows\system32\es.dll
11:35:55.0324 43128  EventSystem - ok
11:35:55.0340 43128  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat          C:\Windows\system32\drivers\exfat.sys
11:35:55.0340 43128  exfat - ok
11:35:55.0418 43128  [ E343DFEA029DB97418237DE5AD457FD3 ] EyeTV Netstream C:\Program Files (x86)\Elgato\EyeTV Netstream\EyeTVNetstreamSvc.exe
11:35:55.0418 43128  EyeTV Netstream - ok
11:35:55.0449 43128  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat        C:\Windows\system32\drivers\fastfat.sys
11:35:55.0465 43128  fastfat - ok
11:35:55.0496 43128  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax            C:\Windows\system32\fxssvc.exe
11:35:55.0527 43128  Fax - ok
11:35:55.0543 43128  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc            C:\Windows\system32\drivers\fdc.sys
11:35:55.0543 43128  fdc - ok
11:35:55.0574 43128  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost        C:\Windows\system32\fdPHost.dll
11:35:55.0574 43128  fdPHost - ok
11:35:55.0589 43128  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\Windows\system32\fdrespub.dll
11:35:55.0589 43128  FDResPub - ok
11:35:55.0605 43128  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
11:35:55.0605 43128  FileInfo - ok
11:35:55.0621 43128  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
11:35:55.0621 43128  Filetrace - ok
11:35:55.0652 43128  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
11:35:55.0652 43128  flpydisk - ok
11:35:55.0683 43128  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
11:35:55.0683 43128  FltMgr - ok
11:35:55.0730 43128  [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache      C:\Windows\system32\FntCache.dll
11:35:55.0777 43128  FontCache - ok
11:35:55.0823 43128  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
11:35:55.0823 43128  FontCache3.0.0.0 - ok
11:35:55.0839 43128  [ D43703496149971890703B4B1B723EAC ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
11:35:55.0839 43128  FsDepends - ok
11:35:55.0855 43128  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
11:35:55.0870 43128  Fs_Rec - ok
11:35:55.0917 43128  [ BA0C1FFDA496D8BCBCAC63F8D98D20E3 ] FUJ02B1        C:\Windows\system32\DRIVERS\FUJ02B1.sys
11:35:55.0933 43128  FUJ02B1 - ok
11:35:55.0933 43128  [ 7135030CBF87D724B6037BB023923730 ] FUJ02E3        C:\Windows\system32\DRIVERS\FUJ02E3.sys
11:35:55.0933 43128  FUJ02E3 - ok
11:35:55.0979 43128  [ 1F7B25B858FA27015169FE95E54108ED ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
11:35:55.0979 43128  fvevol - ok
11:35:56.0011 43128  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
11:35:56.0011 43128  gagp30kx - ok
11:35:56.0042 43128  [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
11:35:56.0042 43128  GEARAspiWDM - ok
11:35:56.0151 43128  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc          C:\Windows\System32\gpsvc.dll
11:35:56.0167 43128  gpsvc - ok
11:35:56.0260 43128  [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:35:56.0260 43128  gupdate - ok
11:35:56.0276 43128  [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:35:56.0276 43128  gupdatem - ok
11:35:56.0307 43128  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
11:35:56.0307 43128  hcw85cir - ok
11:35:56.0354 43128  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
11:35:56.0354 43128  HdAudAddService - ok
11:35:56.0369 43128  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
11:35:56.0369 43128  HDAudBus - ok
11:35:56.0401 43128  [ B6AC71AAA2B10848F57FC49D55A651AF ] HECIx64        C:\Windows\system32\DRIVERS\HECIx64.sys
11:35:56.0401 43128  HECIx64 - ok
11:35:56.0416 43128  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt        C:\Windows\system32\drivers\HidBatt.sys
11:35:56.0432 43128  HidBatt - ok
11:35:56.0447 43128  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\Windows\system32\drivers\hidbth.sys
11:35:56.0447 43128  HidBth - ok
11:35:56.0463 43128  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr          C:\Windows\system32\drivers\hidir.sys
11:35:56.0463 43128  HidIr - ok
11:35:56.0494 43128  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv        C:\Windows\system32\hidserv.dll
11:35:56.0494 43128  hidserv - ok
11:35:56.0510 43128  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
11:35:56.0510 43128  HidUsb - ok
11:35:56.0541 43128  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\Windows\system32\kmsvc.dll
11:35:56.0541 43128  hkmsvc - ok
11:35:56.0557 43128  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
11:35:56.0557 43128  HomeGroupListener - ok
11:35:56.0588 43128  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
11:35:56.0603 43128  HomeGroupProvider - ok
11:35:56.0635 43128  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
11:35:56.0635 43128  HpSAMD - ok
11:35:56.0666 43128  [ F47CEC45FB85791D4AB237563AD0FA8F ] HTCAND64        C:\Windows\system32\Drivers\ANDROIDUSB.sys
11:35:56.0666 43128  HTCAND64 - ok
11:35:56.0697 43128  [ B8B1B284362E1D8135112573395D5DA5 ] htcnprot        C:\Windows\system32\DRIVERS\htcnprot.sys
11:35:56.0697 43128  htcnprot - ok
11:35:56.0837 43128  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
11:35:56.0915 43128  HTTP - ok
11:35:56.0962 43128  [ C8F3119AD72A507D12EF389DF4C266EF ] hwdatacard      C:\Windows\system32\DRIVERS\ewusbmdm.sys
11:35:56.0962 43128  hwdatacard - ok
11:35:56.0993 43128  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
11:35:56.0993 43128  hwpolicy - ok
11:35:57.0025 43128  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
11:35:57.0025 43128  i8042prt - ok
11:35:57.0056 43128  [ 2064090C9FAAD92C090D77E50E735B2E ] iaStor          C:\Windows\system32\drivers\iaStor.sys
11:35:57.0056 43128  iaStor - ok
11:35:57.0103 43128  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
11:35:57.0103 43128  iaStorV - ok
11:35:57.0165 43128  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
11:35:57.0181 43128  idsvc - ok
11:35:57.0399 43128  [ 8E509DE232CFA4F8A5B34F01802F500E ] igfx            C:\Windows\system32\DRIVERS\igdkmd64.sys
11:35:57.0617 43128  igfx - ok
11:35:57.0649 43128  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
11:35:57.0649 43128  iirsp - ok
11:35:57.0789 43128  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\Windows\System32\ikeext.dll
11:35:57.0914 43128  IKEEXT - ok
11:35:57.0945 43128  [ 36FDF367A1DABFF903E2214023D71368 ] Impcd          C:\Windows\system32\DRIVERS\Impcd.sys
11:35:57.0945 43128  Impcd - ok
11:35:58.0023 43128  [ 42943BB3AB7A405B30EFF7C8283CC129 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
11:35:58.0101 43128  IntcAzAudAddService - ok
11:35:58.0210 43128  [ D248AAE81C156C0D47A77CD61BC24CD4 ] IntcDAud        C:\Windows\system32\DRIVERS\IntcDAud.sys
11:35:58.0210 43128  IntcDAud - ok
11:35:58.0241 43128  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\Windows\system32\drivers\intelide.sys
11:35:58.0257 43128  intelide - ok
11:35:58.0288 43128  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
11:35:58.0288 43128  intelppm - ok
11:35:58.0319 43128  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
11:35:58.0319 43128  IPBusEnum - ok
11:35:58.0335 43128  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:35:58.0335 43128  IpFilterDriver - ok
11:35:58.0366 43128  [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
11:35:58.0366 43128  iphlpsvc - ok
11:35:58.0397 43128  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV        C:\Windows\system32\drivers\IPMIDrv.sys
11:35:58.0397 43128  IPMIDRV - ok
11:35:58.0429 43128  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
11:35:58.0429 43128  IPNAT - ok
11:35:58.0491 43128  [ 6E50CFA46527B39015B750AAD161C5CC ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
11:35:58.0522 43128  iPod Service - ok
11:35:58.0538 43128  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
11:35:58.0538 43128  IRENUM - ok
11:35:58.0569 43128  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
11:35:58.0569 43128  isapnp - ok
11:35:58.0600 43128  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
11:35:58.0600 43128  iScsiPrt - ok
11:35:58.0631 43128  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
11:35:58.0631 43128  kbdclass - ok
11:35:58.0647 43128  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\Windows\system32\drivers\kbdhid.sys
11:35:58.0647 43128  kbdhid - ok
11:35:58.0663 43128  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\Windows\system32\lsass.exe
11:35:58.0663 43128  KeyIso - ok
11:35:58.0709 43128  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
11:35:58.0709 43128  KSecDD - ok
11:35:58.0741 43128  [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
11:35:58.0741 43128  KSecPkg - ok
11:35:58.0772 43128  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
11:35:58.0787 43128  ksthunk - ok
11:35:58.0819 43128  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm          C:\Windows\system32\msdtckrm.dll
11:35:58.0819 43128  KtmRm - ok
11:35:58.0850 43128  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\Windows\system32\srvsvc.dll
11:35:58.0865 43128  LanmanServer - ok
11:35:58.0865 43128  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
11:35:58.0881 43128  LanmanWorkstation - ok
11:35:58.0897 43128  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
11:35:58.0897 43128  lltdio - ok
11:35:58.0928 43128  [ C1185803384AB3FEED115F79F109427F ] lltdsvc        C:\Windows\System32\lltdsvc.dll
11:35:58.0928 43128  lltdsvc - ok
11:35:58.0943 43128  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts        C:\Windows\System32\lmhsvc.dll
11:35:58.0959 43128  lmhosts - ok
11:35:59.0037 43128  [ A1C148801B4AF64847AEB9F3AD9594EF ] LMS            C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
11:35:59.0037 43128  LMS - ok
11:35:59.0068 43128  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
11:35:59.0068 43128  LSI_FC - ok
11:35:59.0084 43128  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
11:35:59.0084 43128  LSI_SAS - ok
11:35:59.0115 43128  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
11:35:59.0115 43128  LSI_SAS2 - ok
11:35:59.0131 43128  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
11:35:59.0131 43128  LSI_SCSI - ok
11:35:59.0162 43128  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv          C:\Windows\system32\drivers\luafv.sys
11:35:59.0177 43128  luafv - ok
11:35:59.0193 43128  [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
11:35:59.0209 43128  Mcx2Svc - ok
11:35:59.0240 43128  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas        C:\Windows\system32\drivers\megasas.sys
11:35:59.0240 43128  megasas - ok
11:35:59.0271 43128  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
11:35:59.0287 43128  MegaSR - ok
11:35:59.0302 43128  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS          C:\Windows\system32\mmcss.dll
11:35:59.0302 43128  MMCSS - ok
11:35:59.0333 43128  [ 800BA92F7010378B09F9ED9270F07137 ] Modem          C:\Windows\system32\drivers\modem.sys
11:35:59.0333 43128  Modem - ok
11:35:59.0365 43128  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
11:35:59.0365 43128  monitor - ok
11:35:59.0411 43128  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
11:35:59.0411 43128  mouclass - ok
11:35:59.0427 43128  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
11:35:59.0427 43128  mouhid - ok
11:35:59.0443 43128  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
11:35:59.0443 43128  mountmgr - ok
11:35:59.0489 43128  [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
11:35:59.0489 43128  MozillaMaintenance - ok
11:35:59.0536 43128  [ 05BF204EC0E82CC4A054DB189C8A3D84 ] MpFilter        C:\Windows\system32\DRIVERS\MpFilter.sys
11:35:59.0536 43128  MpFilter - ok
11:35:59.0567 43128  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\Windows\system32\drivers\mpio.sys
11:35:59.0583 43128  mpio - ok
11:35:59.0614 43128  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
11:35:59.0614 43128  mpsdrv - ok
11:35:59.0661 43128  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc          C:\Windows\system32\mpssvc.dll
11:35:59.0692 43128  MpsSvc - ok
11:35:59.0708 43128  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
11:35:59.0723 43128  MRxDAV - ok
11:35:59.0770 43128  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
11:35:59.0770 43128  mrxsmb - ok
11:35:59.0801 43128  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:35:59.0817 43128  mrxsmb10 - ok
11:35:59.0833 43128  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:35:59.0833 43128  mrxsmb20 - ok
11:35:59.0864 43128  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\Windows\system32\drivers\msahci.sys
11:35:59.0864 43128  msahci - ok
11:35:59.0879 43128  [ DB801A638D011B9633829EB6F663C900 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
11:35:59.0879 43128  msdsm - ok
11:35:59.0911 43128  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC          C:\Windows\System32\msdtc.exe
11:35:59.0911 43128  MSDTC - ok
11:35:59.0957 43128  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
11:35:59.0957 43128  Msfs - ok
11:35:59.0957 43128  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
11:35:59.0973 43128  mshidkmdf - ok
11:35:59.0989 43128  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
11:35:59.0989 43128  msisadrv - ok
11:36:00.0004 43128  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
11:36:00.0004 43128  MSiSCSI - ok
11:36:00.0020 43128  msiserver - ok
11:36:00.0035 43128  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
11:36:00.0035 43128  MSKSSRV - ok
11:36:00.0113 43128  [ CC8E4F72F21340A4D3A3D4DB50313EF5 ] MsMpSvc        c:\Program Files\Microsoft Security Client\MsMpEng.exe
11:36:00.0113 43128  MsMpSvc - ok
11:36:00.0145 43128  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
11:36:00.0145 43128  MSPCLOCK - ok
11:36:00.0160 43128  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
11:36:00.0160 43128  MSPQM - ok
11:36:00.0191 43128  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
11:36:00.0191 43128  MsRPC - ok
11:36:00.0223 43128  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
11:36:00.0223 43128  mssmbios - ok
11:36:00.0223 43128  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
11:36:00.0223 43128  MSTEE - ok
11:36:00.0254 43128  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
11:36:00.0254 43128  MTConfig - ok
11:36:00.0254 43128  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup            C:\Windows\system32\Drivers\mup.sys
11:36:00.0254 43128  Mup - ok
11:36:00.0285 43128  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\Windows\system32\qagentRT.dll
11:36:00.0301 43128  napagent - ok
11:36:00.0332 43128  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
11:36:00.0332 43128  NativeWifiP - ok
11:36:00.0379 43128  [ 760E38053BF56E501D562B70AD796B88 ] NDIS            C:\Windows\system32\drivers\ndis.sys
11:36:00.0410 43128  NDIS - ok
11:36:00.0441 43128  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
11:36:00.0441 43128  NdisCap - ok
11:36:00.0457 43128  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
11:36:00.0457 43128  NdisTapi - ok
11:36:00.0488 43128  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
11:36:00.0488 43128  Ndisuio - ok
11:36:00.0503 43128  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
11:36:00.0503 43128  NdisWan - ok
11:36:00.0550 43128  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
11:36:00.0550 43128  NDProxy - ok
11:36:00.0581 43128  [ 6F4607E2333FE21E9E3FF8133A88B35B ] Netaapl        C:\Windows\system32\DRIVERS\netaapl64.sys
11:36:00.0581 43128  Netaapl - ok
11:36:00.0613 43128  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
11:36:00.0613 43128  NetBIOS - ok
11:36:00.0737 43128  [ 09594D1089C523423B32A4229263F068 ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
11:36:00.0753 43128  NetBT - ok
11:36:00.0769 43128  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\Windows\system32\lsass.exe
11:36:00.0769 43128  Netlogon - ok
11:36:00.0800 43128  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\Windows\System32\netman.dll
11:36:00.0815 43128  Netman - ok
11:36:00.0862 43128  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:36:00.0862 43128  NetMsmqActivator - ok
11:36:00.0862 43128  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:36:00.0878 43128  NetPipeActivator - ok
11:36:00.0909 43128  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\Windows\System32\netprofm.dll
11:36:00.0925 43128  netprofm - ok
11:36:00.0925 43128  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:36:00.0925 43128  NetTcpActivator - ok
11:36:00.0940 43128  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:36:00.0940 43128  NetTcpPortSharing - ok
11:36:00.0956 43128  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
11:36:00.0956 43128  nfrd960 - ok
11:36:01.0003 43128  [ 5FF89F20317309D28AC1EDEB0CD1BA72 ] NisDrv          C:\Windows\system32\DRIVERS\NisDrvWFP.sys
11:36:01.0003 43128  NisDrv - ok
11:36:01.0049 43128  [ 79E80B10FE8F6662E0C9162A68C43444 ] NisSrv          c:\Program Files\Microsoft Security Client\NisSrv.exe
11:36:01.0049 43128  NisSrv - ok
11:36:01.0065 43128  [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc          C:\Windows\System32\nlasvc.dll
11:36:01.0081 43128  NlaSvc - ok
11:36:01.0112 43128  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
11:36:01.0112 43128  Npfs - ok
11:36:01.0127 43128  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi            C:\Windows\system32\nsisvc.dll
11:36:01.0127 43128  nsi - ok
11:36:01.0159 43128  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
11:36:01.0159 43128  nsiproxy - ok
11:36:01.0237 43128  [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
11:36:01.0315 43128  Ntfs - ok
11:36:01.0346 43128  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\Windows\system32\drivers\Null.sys
11:36:01.0346 43128  Null - ok
11:36:01.0377 43128  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\Windows\system32\drivers\nvraid.sys
11:36:01.0377 43128  nvraid - ok
11:36:01.0408 43128  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\Windows\system32\drivers\nvstor.sys
11:36:01.0408 43128  nvstor - ok
11:36:01.0424 43128  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
11:36:01.0424 43128  nv_agp - ok
11:36:01.0533 43128  [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv          C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
11:36:01.0549 43128  odserv - ok
11:36:01.0564 43128  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
11:36:01.0564 43128  ohci1394 - ok
11:36:01.0611 43128  [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:36:01.0611 43128  ose - ok
11:36:01.0658 43128  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
11:36:01.0658 43128  p2pimsvc - ok
11:36:01.0673 43128  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\Windows\system32\p2psvc.dll
11:36:01.0689 43128  p2psvc - ok
11:36:01.0705 43128  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport        C:\Windows\system32\drivers\parport.sys
11:36:01.0705 43128  Parport - ok
11:36:01.0736 43128  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr        C:\Windows\system32\drivers\partmgr.sys
11:36:01.0736 43128  partmgr - ok
11:36:01.0783 43128  [ 39B9DCD7040654C2E57D7396736C718E ] PassThru Service C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
11:36:01.0783 43128  PassThru Service - ok
11:36:01.0798 43128  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\Windows\System32\pcasvc.dll
11:36:01.0814 43128  PcaSvc - ok
11:36:01.0845 43128  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci            C:\Windows\system32\drivers\pci.sys
11:36:01.0845 43128  pci - ok
11:36:01.0861 43128  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\Windows\system32\drivers\pciide.sys
11:36:01.0861 43128  pciide - ok
11:36:01.0892 43128  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
11:36:01.0907 43128  pcmcia - ok
11:36:01.0923 43128  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw            C:\Windows\system32\drivers\pcw.sys
11:36:01.0939 43128  pcw - ok
11:36:01.0954 43128  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
11:36:01.0970 43128  PEAUTH - ok
11:36:02.0048 43128  [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc    C:\Windows\system32\peerdistsvc.dll
11:36:02.0095 43128  PeerDistSvc - ok
11:36:02.0157 43128  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
11:36:02.0173 43128  PerfHost - ok
11:36:02.0251 43128  [ C0F1CFCEE7E8AFF3AE0A7F54A7D3D6BE ] PFNService      C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe
11:36:02.0266 43128  PFNService - ok
11:36:02.0329 43128  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla            C:\Windows\system32\pla.dll
11:36:02.0391 43128  pla - ok
11:36:02.0531 43128  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
11:36:02.0609 43128  PlugPlay - ok
11:36:02.0687 43128  [ F485770EEC8959684CC4C4786B63C06C ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
11:36:02.0687 43128  Pml Driver HPZ12 - ok
11:36:02.0734 43128  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
11:36:02.0734 43128  PNRPAutoReg - ok
11:36:02.0750 43128  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
11:36:02.0750 43128  PNRPsvc - ok
11:36:02.0781 43128  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
11:36:02.0797 43128  PolicyAgent - ok
11:36:02.0906 43128  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power          C:\Windows\system32\umpo.dll
11:36:02.0968 43128  Power - ok
11:36:03.0015 43128  [ 843BA5F09A391D52AC1F8486C5FC3D4F ] PowerSavingUtilityService C:\Program Files\Fujitsu\PSUtility\PSUService.exe
11:36:03.0031 43128  PowerSavingUtilityService - ok
11:36:03.0046 43128  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
11:36:03.0062 43128  PptpMiniport - ok
11:36:03.0077 43128  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor      C:\Windows\system32\drivers\processr.sys
11:36:03.0077 43128  Processor - ok
11:36:03.0109 43128  [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc        C:\Windows\system32\profsvc.dll
11:36:03.0124 43128  ProfSvc - ok
11:36:03.0140 43128  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
11:36:03.0140 43128  ProtectedStorage - ok
11:36:03.0155 43128  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
11:36:03.0155 43128  Psched - ok
11:36:03.0202 43128  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
11:36:03.0265 43128  ql2300 - ok
11:36:03.0296 43128  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
11:36:03.0296 43128  ql40xx - ok
11:36:03.0327 43128  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE          C:\Windows\system32\qwave.dll
11:36:03.0327 43128  QWAVE - ok
11:36:03.0343 43128  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
11:36:03.0343 43128  QWAVEdrv - ok
11:36:03.0358 43128  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
11:36:03.0358 43128  RasAcd - ok
11:36:03.0374 43128  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
11:36:03.0374 43128  RasAgileVpn - ok
11:36:03.0389 43128  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto        C:\Windows\System32\rasauto.dll
11:36:03.0405 43128  RasAuto - ok
11:36:03.0436 43128  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
11:36:03.0436 43128  Rasl2tp - ok
11:36:03.0452 43128  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\Windows\System32\rasmans.dll
11:36:03.0467 43128  RasMan - ok
11:36:03.0483 43128  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
11:36:03.0483 43128  RasPppoe - ok
11:36:03.0499 43128  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
11:36:03.0499 43128  RasSstp - ok
11:36:03.0514 43128  [ 77F665941019A1594D887A74F301FA2F ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
11:36:03.0514 43128  rdbss - ok
11:36:03.0545 43128  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
11:36:03.0545 43128  rdpbus - ok
11:36:03.0577 43128  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
11:36:03.0577 43128  RDPCDD - ok
11:36:03.0608 43128  [ 1B6163C503398B23FF8B939C67747683 ] RDPDR          C:\Windows\system32\drivers\rdpdr.sys
11:36:03.0608 43128  RDPDR - ok
11:36:03.0623 43128  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
11:36:03.0623 43128  RDPENCDD - ok
11:36:03.0639 43128  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
11:36:03.0639 43128  RDPREFMP - ok
11:36:03.0670 43128  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
11:36:03.0670 43128  RDPWD - ok
11:36:03.0701 43128  [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
11:36:03.0717 43128  rdyboost - ok
11:36:03.0748 43128  [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess    C:\Windows\System32\mprdim.dll
11:36:03.0748 43128  RemoteAccess - ok
11:36:03.0779 43128  [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
11:36:03.0779 43128  RemoteRegistry - ok
11:36:03.0904 43128  [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM          C:\Windows\system32\DRIVERS\rfcomm.sys
11:36:03.0904 43128  RFCOMM - ok
11:36:03.0920 43128  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
11:36:03.0935 43128  RpcEptMapper - ok
11:36:03.0951 43128  [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator      C:\Windows\system32\locator.exe
11:36:03.0951 43128  RpcLocator - ok
11:36:03.0967 43128  [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs          C:\Windows\system32\rpcss.dll
11:36:03.0982 43128  RpcSs - ok
11:36:03.0998 43128  [ 2ABD2B3BA2EF0C3BA82284C2A5E28675 ] RRNetCap        C:\Windows\system32\DRIVERS\rrnetcap.sys
11:36:03.0998 43128  RRNetCap - ok
11:36:04.0013 43128  [ 2ABD2B3BA2EF0C3BA82284C2A5E28675 ] RRNetCapMP      C:\Windows\system32\DRIVERS\rrnetcap.sys
11:36:04.0013 43128  RRNetCapMP - ok
11:36:04.0045 43128  [ DDC86E4F8E7456261E637E3552E804FF ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
11:36:04.0045 43128  rspndr - ok
11:36:04.0060 43128  RSUSBSTOR - ok
11:36:04.0091 43128  [ 7EA8D2EB9BBFD2AB8A3117A1E96D3B3A ] RTL8167        C:\Windows\system32\DRIVERS\Rt64win7.sys
11:36:04.0107 43128  RTL8167 - ok
11:36:04.0107 43128  RtsUIR - ok
11:36:04.0123 43128  [ E60C0A09F997826C7627B244195AB581 ] s3cap          C:\Windows\system32\drivers\vms3cap.sys
11:36:04.0123 43128  s3cap - ok
11:36:04.0138 43128  [ C118A82CD78818C29AB228366EBF81C3 ] SamSs          C:\Windows\system32\lsass.exe
11:36:04.0138 43128  SamSs - ok
11:36:04.0169 43128  [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
11:36:04.0169 43128  sbp2port - ok
11:36:04.0201 43128  [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr        C:\Windows\System32\SCardSvr.dll
11:36:04.0201 43128  SCardSvr - ok
11:36:04.0232 43128  [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
11:36:04.0247 43128  scfilter - ok
11:36:04.0279 43128  [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule        C:\Windows\system32\schedsvc.dll
11:36:04.0310 43128  Schedule - ok
11:36:04.0341 43128  [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc    C:\Windows\System32\certprop.dll
11:36:04.0341 43128  SCPolicySvc - ok
11:36:04.0419 43128  [ B60E9769655DDEE8368E3ABB6668E076 ] ScrybeUpdater  C:\Program Files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe
11:36:04.0450 43128  ScrybeUpdater - ok
11:36:04.0481 43128  [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
11:36:04.0481 43128  SDRSVC - ok
11:36:04.0513 43128  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
11:36:04.0513 43128  secdrv - ok
11:36:04.0528 43128  [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon        C:\Windows\system32\seclogon.dll
11:36:04.0544 43128  seclogon - ok
11:36:04.0544 43128  [ C32AB8FA018EF34C0F113BD501436D21 ] SENS            C:\Windows\System32\sens.dll
11:36:04.0559 43128  SENS - ok
11:36:04.0575 43128  [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
11:36:04.0575 43128  SensrSvc - ok
11:36:04.0606 43128  [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum        C:\Windows\system32\drivers\serenum.sys
11:36:04.0606 43128  Serenum - ok
11:36:04.0622 43128  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial          C:\Windows\system32\drivers\serial.sys
11:36:04.0622 43128  Serial - ok
11:36:04.0637 43128  [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse        C:\Windows\system32\drivers\sermouse.sys
11:36:04.0637 43128  sermouse - ok
11:36:04.0669 43128  [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv      C:\Windows\system32\sessenv.dll
11:36:04.0669 43128  SessionEnv - ok
11:36:04.0700 43128  [ A554811BCD09279536440C964AE35BBF ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
11:36:04.0700 43128  sffdisk - ok
11:36:04.0731 43128  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
11:36:04.0731 43128  sffp_mmc - ok
11:36:04.0731 43128  [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
11:36:04.0747 43128  sffp_sd - ok
11:36:04.0747 43128  [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
11:36:04.0762 43128  sfloppy - ok
11:36:04.0871 43128  [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess    C:\Windows\System32\ipnathlp.dll
11:36:04.0887 43128  SharedAccess - ok
11:36:04.0918 43128  [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
11:36:04.0934 43128  ShellHWDetection - ok
11:36:04.0949 43128  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
11:36:04.0949 43128  SiSRaid2 - ok
11:36:04.0981 43128  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
11:36:04.0981 43128  SiSRaid4 - ok
11:36:05.0043 43128  [ DDAA5F4A6B958FC313EBD02DD925752F ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
11:36:05.0043 43128  SkypeUpdate - ok
11:36:05.0074 43128  [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
11:36:05.0074 43128  Smb - ok
11:36:05.0105 43128  [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
11:36:05.0105 43128  SNMPTRAP - ok
11:36:05.0121 43128  [ B9E31E5CACDFE584F34F730A677803F9 ] spldr          C:\Windows\system32\drivers\spldr.sys
11:36:05.0121 43128  spldr - ok
11:36:05.0152 43128  [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler        C:\Windows\System32\spoolsv.exe
11:36:05.0168 43128  Spooler - ok
11:36:05.0480 43128  [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc          C:\Windows\system32\sppsvc.exe
11:36:05.0776 43128  sppsvc - ok
11:36:05.0792 43128  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify    C:\Windows\system32\sppuinotify.dll
11:36:05.0792 43128  sppuinotify - ok
11:36:05.0917 43128  [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv            C:\Windows\system32\DRIVERS\srv.sys
11:36:05.0932 43128  srv - ok
11:36:05.0948 43128  [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
11:36:05.0948 43128  srv2 - ok
11:36:05.0979 43128  [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
11:36:05.0979 43128  srvnet - ok
11:36:06.0010 43128  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
11:36:06.0010 43128  SSDPSRV - ok
11:36:06.0026 43128  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc        C:\Windows\system32\sstpsvc.dll
11:36:06.0026 43128  SstpSvc - ok
11:36:06.0057 43128  [ F3817967ED533D08327DC73BC4D5542A ] stexstor        C:\Windows\system32\drivers\stexstor.sys
11:36:06.0057 43128  stexstor - ok
11:36:06.0104 43128  [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc          C:\Windows\System32\wiaservc.dll
11:36:06.0104 43128  stisvc - ok
11:36:06.0151 43128  [ 7785DC213270D2FC066538DAF94087E7 ] storflt        C:\Windows\system32\drivers\vmstorfl.sys
11:36:06.0151 43128  storflt - ok
11:36:06.0182 43128  [ C40841817EF57D491F22EB103DA587CC ] StorSvc        C:\Windows\system32\storsvc.dll
11:36:06.0182 43128  StorSvc - ok
11:36:06.0213 43128  [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc        C:\Windows\system32\drivers\storvsc.sys
11:36:06.0213 43128  storvsc - ok
11:36:06.0229 43128  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
11:36:06.0229 43128  swenum - ok
11:36:06.0338 43128  [ E08E46FDD841B7184194011CA1955A0B ] swprv          C:\Windows\System32\swprv.dll
11:36:06.0431 43128  swprv - ok
11:36:06.0494 43128  [ 8DF6C536ECE3B538978B53C223AB905D ] SynTP          C:\Windows\system32\DRIVERS\SynTP.sys
11:36:06.0541 43128  SynTP - ok
11:36:06.0775 43128  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain        C:\Windows\system32\sysmain.dll
11:36:06.0977 43128  SysMain - ok
11:36:06.0993 43128  [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
11:36:07.0009 43128  TabletInputService - ok
11:36:07.0087 43128  [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv        C:\Windows\System32\tapisrv.dll
11:36:07.0102 43128  TapiSrv - ok
11:36:07.0133 43128  [ 4430E9B4C60AAB672D16E801BAD0555E ] tbhsd          C:\Windows\system32\drivers\tbhsd.sys
11:36:07.0133 43128  tbhsd - ok
11:36:07.0149 43128  [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS            C:\Windows\System32\tbssvc.dll
11:36:07.0149 43128  TBS - ok
11:36:07.0367 43128  [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
11:36:07.0555 43128  Tcpip - ok
11:36:07.0757 43128  [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
11:36:07.0757 43128  TCPIP6 - ok
11:36:07.0820 43128  [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
11:36:07.0820 43128  tcpipreg - ok
11:36:07.0835 43128  [ 3371D21011695B16333A3934340C4E7C ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
11:36:07.0851 43128  TDPIPE - ok
11:36:07.0867 43128  [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
11:36:07.0867 43128  TDTCP - ok
11:36:07.0882 43128  [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
11:36:07.0882 43128  tdx - ok
11:36:07.0898 43128  [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
11:36:07.0898 43128  TermDD - ok
11:36:08.0023 43128  [ 2E648163254233755035B46DD7B89123 ] TermService    C:\Windows\System32\termsrv.dll
11:36:08.0132 43128  TermService - ok
11:36:08.0147 43128  [ F0344071948D1A1FA732231785A0664C ] Themes          C:\Windows\system32\themeservice.dll
11:36:08.0147 43128  Themes - ok
11:36:08.0179 43128  [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER    C:\Windows\system32\mmcss.dll
11:36:08.0179 43128  THREADORDER - ok
11:36:08.0194 43128  [ DBCC20C02E8A3E43B03C304A4E40A84F ] TPM            C:\Windows\system32\drivers\tpm.sys
11:36:08.0210 43128  TPM - ok
11:36:08.0225 43128  [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks          C:\Windows\System32\trkwks.dll
11:36:08.0225 43128  TrkWks - ok
11:36:08.0272 43128  [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
11:36:08.0272 43128  TrustedInstaller - ok
11:36:08.0303 43128  [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
11:36:08.0303 43128  tssecsrv - ok
11:36:08.0319 43128  [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
11:36:08.0319 43128  TsUsbFlt - ok
11:36:08.0350 43128  [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD        C:\Windows\system32\drivers\TsUsbGD.sys
11:36:08.0350 43128  TsUsbGD - ok
11:36:08.0366 43128  [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
11:36:08.0366 43128  tunnel - ok
11:36:08.0381 43128  [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
11:36:08.0397 43128  uagp35 - ok
11:36:08.0428 43128  [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
11:36:08.0444 43128  udfs - ok
11:36:08.0459 43128  [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
11:36:08.0475 43128  UI0Detect - ok
11:36:08.0491 43128  [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
11:36:08.0491 43128  uliagpkx - ok
11:36:08.0506 43128  [ DC54A574663A895C8763AF0FA1FF7561 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
11:36:08.0506 43128  umbus - ok
11:36:08.0522 43128  [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass          C:\Windows\system32\drivers\umpass.sys
11:36:08.0522 43128  UmPass - ok
11:36:08.0553 43128  [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService    C:\Windows\System32\umrdp.dll
11:36:08.0553 43128  UmRdpService - ok
11:36:08.0678 43128  [ 41118D920B2B268C0ADC36421248CDCF ] UNS            C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
11:36:08.0756 43128  UNS - ok
11:36:08.0787 43128  [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost        C:\Windows\System32\upnphost.dll
11:36:08.0803 43128  upnphost - ok
11:36:08.0834 43128  [ AF1B9474D67897D0C2CFF58E0ACEACCC ] USBAAPL64      C:\Windows\system32\Drivers\usbaapl64.sys
11:36:08.0834 43128  USBAAPL64 - ok
11:36:08.0849 43128  [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
11:36:08.0849 43128  usbccgp - ok
11:36:08.0865 43128  USBCCID - ok
11:36:08.0881 43128  [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
11:36:08.0881 43128  usbcir - ok
11:36:08.0912 43128  [ C025055FE7B87701EB042095DF1A2D7B ] usbehci        C:\Windows\system32\drivers\usbehci.sys
11:36:08.0912 43128  usbehci - ok
11:36:08.0927 43128  [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
11:36:08.0943 43128  usbhub - ok
11:36:08.0959 43128  [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
11:36:08.0974 43128  usbohci - ok
11:36:08.0990 43128  [ 73188F58FB384E75C4063D29413CEE3D ] usbprint        C:\Windows\system32\drivers\usbprint.sys
11:36:08.0990 43128  usbprint - ok
11:36:09.0005 43128  [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:36:09.0005 43128  USBSTOR - ok
11:36:09.0021 43128  [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci        C:\Windows\system32\drivers\usbuhci.sys
11:36:09.0021 43128  usbuhci - ok
11:36:09.0052 43128  [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
11:36:09.0052 43128  usbvideo - ok
11:36:09.0099 43128  [ 70D05EE263568A742D14E1876DF80532 ] usb_rndisx      C:\Windows\system32\drivers\usb8023x.sys
11:36:09.0099 43128  usb_rndisx - ok
11:36:09.0130 43128  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms          C:\Windows\System32\uxsms.dll
11:36:09.0130 43128  UxSms - ok
11:36:09.0146 43128  [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc        C:\Windows\system32\lsass.exe
11:36:09.0146 43128  VaultSvc - ok
11:36:09.0161 43128  [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
11:36:09.0161 43128  vdrvroot - ok
11:36:09.0193 43128  [ 8D6B481601D01A456E75C3210F1830BE ] vds            C:\Windows\System32\vds.exe
11:36:09.0193 43128  vds - ok
11:36:09.0239 43128  [ D9656445499625B0ED88C0B203F3C16F ] VFPRadioSupportService C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe
11:36:09.0239 43128  VFPRadioSupportService - ok
11:36:09.0271 43128  [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
11:36:09.0271 43128  vga - ok
11:36:09.0286 43128  [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave        C:\Windows\System32\drivers\vga.sys
11:36:09.0286 43128  VgaSave - ok
11:36:09.0317 43128  [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp          C:\Windows\system32\drivers\vhdmp.sys
11:36:09.0317 43128  vhdmp - ok
11:36:09.0349 43128  [ E5689D93FFE4E5D66C0178761240DD54 ] viaide          C:\Windows\system32\drivers\viaide.sys
11:36:09.0349 43128  viaide - ok
11:36:09.0380 43128  [ 86EA3E79AE350FEA5331A1303054005F ] vmbus          C:\Windows\system32\drivers\vmbus.sys
11:36:09.0380 43128  vmbus - ok
11:36:09.0411 43128  [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
11:36:09.0411 43128  VMBusHID - ok
11:36:09.0473 43128  [ 6E021D6DA429AD7288FE8322E2BBA96B ] VMCService      C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
11:36:09.0473 43128  VMCService - ok
11:36:09.0489 43128  [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
11:36:09.0505 43128  volmgr - ok
11:36:09.0614 43128  [ A255814907C89BE58B79EF2F189B843B ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
11:36:09.0629 43128  volmgrx - ok
11:36:09.0645 43128  [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
11:36:09.0645 43128  volsnap - ok
11:36:09.0661 43128  [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
11:36:09.0661 43128  vsmraid - ok
11:36:09.0723 43128  [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS            C:\Windows\system32\vssvc.exe
11:36:09.0785 43128  VSS - ok
11:36:09.0817 43128  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
11:36:09.0817 43128  vwifibus - ok
11:36:09.0848 43128  [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
11:36:09.0848 43128  vwififlt - ok
11:36:09.0863 43128  [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp        C:\Windows\system32\DRIVERS\vwifimp.sys
11:36:09.0863 43128  vwifimp - ok
11:36:09.0879 43128  [ 1C9D80CC3849B3788048078C26486E1A ] W32Time        C:\Windows\system32\w32time.dll
11:36:09.0895 43128  W32Time - ok
11:36:09.0926 43128  [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
11:36:09.0926 43128  WacomPen - ok
11:36:09.0926 43128  [ 356AFD78A6ED4457169241AC3965230C ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
11:36:09.0941 43128  WANARP - ok
11:36:09.0957 43128  [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
11:36:09.0957 43128  Wanarpv6 - ok
11:36:10.0019 43128  [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc    C:\Windows\system32\Wat\WatAdminSvc.exe
11:36:10.0066 43128  WatAdminSvc - ok
11:36:10.0144 43128  [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine        C:\Windows\system32\wbengine.exe
11:36:10.0175 43128  wbengine - ok
11:36:10.0191 43128  [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
11:36:10.0191 43128  WbioSrvc - ok
11:36:10.0222 43128  [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc        C:\Windows\System32\wcncsvc.dll
11:36:10.0238 43128  wcncsvc - ok
11:36:10.0238 43128  [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
11:36:10.0253 43128  WcsPlugInService - ok
11:36:10.0269 43128  [ 72889E16FF12BA0F235467D6091B17DC ] Wd              C:\Windows\system32\drivers\wd.sys
11:36:10.0269 43128  Wd - ok
11:36:10.0316 43128  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
11:36:10.0331 43128  Wdf01000 - ok
11:36:10.0347 43128  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost  C:\Windows\system32\wdi.dll
11:36:10.0363 43128  WdiServiceHost - ok
11:36:10.0363 43128  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost  C:\Windows\system32\wdi.dll
11:36:10.0378 43128  WdiSystemHost - ok
11:36:10.0394 43128  [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient      C:\Windows\System32\webclnt.dll
11:36:10.0394 43128  WebClient - ok
11:36:10.0425 43128  [ C749025A679C5103E575E3B48E092C43 ] Wecsvc          C:\Windows\system32\wecsvc.dll
11:36:10.0425 43128  Wecsvc - ok
11:36:10.0441 43128  [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
11:36:10.0456 43128  wercplsupport - ok
11:36:10.0456 43128  [ 6D137963730144698CBD10F202E9F251 ] WerSvc          C:\Windows\System32\WerSvc.dll
11:36:10.0456 43128  WerSvc - ok
11:36:10.0472 43128  [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
11:36:10.0487 43128  WfpLwf - ok
11:36:10.0503 43128  [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
11:36:10.0519 43128  WIMMount - ok
11:36:10.0534 43128  WinDefend - ok
11:36:10.0550 43128  WinHttpAutoProxySvc - ok
11:36:10.0612 43128  [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
11:36:10.0612 43128  Winmgmt - ok
11:36:10.0690 43128  [ BCB1310604AA415C4508708975B3931E ] WinRM          C:\Windows\system32\WsmSvc.dll
11:36:10.0753 43128  WinRM - ok
11:36:10.0799 43128  [ FE88B288356E7B47B74B13372ADD906D ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
11:36:10.0799 43128  WinUsb - ok
11:36:10.0846 43128  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc        C:\Windows\System32\wlansvc.dll
11:36:10.0877 43128  Wlansvc - ok
11:36:10.0924 43128  [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc        C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
11:36:10.0924 43128  wlcrasvc - ok
11:36:11.0065 43128  [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
11:36:11.0127 43128  wlidsvc - ok
11:36:11.0158 43128  [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
11:36:11.0158 43128  WmiAcpi - ok
11:36:11.0189 43128  [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
11:36:11.0189 43128  wmiApSrv - ok
11:36:11.0205 43128  WMPNetworkSvc - ok
11:36:11.0221 43128  [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
11:36:11.0221 43128  WPCSvc - ok
11:36:11.0236 43128  [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
11:36:11.0236 43128  WPDBusEnum - ok
11:36:11.0252 43128  [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
11:36:11.0252 43128  ws2ifsl - ok
11:36:11.0267 43128  [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc          C:\Windows\System32\wscsvc.dll
11:36:11.0283 43128  wscsvc - ok
11:36:11.0283 43128  WSearch - ok
11:36:11.0377 43128  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
11:36:11.0455 43128  wuauserv - ok
11:36:11.0486 43128  [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
11:36:11.0501 43128  WudfPf - ok
11:36:11.0517 43128  [ CF8D590BE3373029D57AF80914190682 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
11:36:11.0517 43128  WUDFRd - ok
11:36:11.0548 43128  [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
11:36:11.0548 43128  wudfsvc - ok
11:36:11.0564 43128  [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc        C:\Windows\System32\wwansvc.dll
11:36:11.0579 43128  WwanSvc - ok
11:36:11.0611 43128  ================ Scan global ===============================
11:36:11.0642 43128  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
11:36:11.0689 43128  [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
11:36:11.0704 43128  [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
11:36:11.0735 43128  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
11:36:11.0767 43128  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
11:36:11.0767 43128  [Global] - ok
11:36:11.0767 43128  ================ Scan MBR ==================================
11:36:11.0782 43128  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
11:36:12.0437 43128  \Device\Harddisk0\DR0 - ok
11:36:12.0437 43128  ================ Scan VBR ==================================
11:36:12.0469 43128  [ 288515C5B57C8690FD2A3C784D2C9C89 ] \Device\Harddisk0\DR0\Partition1
11:36:12.0469 43128  \Device\Harddisk0\DR0\Partition1 - ok
11:36:12.0484 43128  ============================================================
11:36:12.0484 43128  Scan finished
11:36:12.0484 43128  ============================================================
11:36:12.0500 43120  Detected object count: 0
11:36:12.0500 43120  Actual detected object count: 0
11:37:16.0912 42412  Deinitialize success



mir ist außerdem noch aufgefallen, dass folgendes unten rechts auf meinem bildschirm (quasi auf das hintergrundbild aufgedruckt):

ryder 03.11.2012 18:10

Jetzt muss ich dich logischerweise fragen: Hast du eine echte Windowskopie?

VHSK 03.11.2012 18:51

Definitiv. Habe den Laptop von einem seriösen Internethändler gekauft (habe ja auch eine Rechnung und auf der Rückseite den product-key)!
Verzweifle gerade: Habe den neuen Schritt 1 mit dem adwcleaner durchgeführt, auf ok gedrückt, computer fährt runter und wieder hoch, ich vertippe mich beim kennwort, möchte es noch einmal eingeben: fehlgeschlagen weil er in dem moment einfriert. zwinge ihn zum neustart, gebe das passwort ein und nun hängt er im willkommen bildschirm fest... versuche es jetzt nochmal...

ryder 03.11.2012 18:55

Gut, lass es mal gut sein, wir müssen da nochmal ganz anders ran fürchte ich. Melde mich gleich.

ryder 03.11.2012 19:00

Scan mit Farbar's Recovery Scan Tool (FRST 64bit)

Downloade dir bitte Farbar Recovery Scan Tool 64-Bit und speichere diese auf einen USB Stick.

Schließe den USB Stick an das infizierte System an

Du musst das System nun in die System Reparatur Option booten.

Über den Boot Manager
  • Starte den Rechner neu auf.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".

Mit Windows CD/DVD
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu auf und starte von der CD
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !!
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".


Wähle in den Reparaturoptionen Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument: Datei > Speichern unter... und wähle Computer
    Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein.
    e:\frst64.exe
    Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Yes und klicke Scan
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier.

VHSK 04.11.2012 11:53

Liste der Anhänge anzeigen (Anzahl: 1)
Nochmal kurz zum Thema angebliche Softwarefälschung bevor ich #26 versuche: Es hat sich folgendes Fenster geöffnet, das auf diesen link verweist:

Genuine Microsoft Software
hxxp://www.microsoft.com/genuine/validate/DownloadValidationSupport.aspx?displaylang=de&sGuid=25deebb0-fd9d-4e73-842c-48a0dcff8ffd&OSV=6.1.7601.2.00010100.1.0.048.09.1031&LS=0&LegitCheckError=00000052&GenuineInfo=00000000&Channel=8&ErrCode=00000000

adwcleaner protokoll kann ja nicht schaden.

außerdem habe ich bemerktl, dass ich zwei dokumente auf dem desktop mit dem namen desktop.ini habe. sind versteckt...

in ihnen steht
Code:

[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21799
[LocalizedFileNames]
Norton Internet Security.lnk=@C:\PROGRA~2\NORTON~2\Branding\muis.dll,-102

und
Code:

[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
IconResource=%SystemRoot%\system32\imageres.dll,-183

wenn man so viel über die systeme herausfinden kann über all die sachen, die man postet, ist es dann nicht etwas fraglich wegen datenschutz sie alle öffentlich zu posten?

ryder 04.11.2012 12:10

Wenn wir fertig sind, dann kannst du dein Windows einfach wieder aktivieren, kein Problem.

Wegen deiner anderen Frage haben wir hier u.a. einen Wichtig-Thema, das man vor der Bereinigung lesen sollte: http://www.trojaner-board.de/108422-...-anfragen.html

Man weiß hier durchaus viel über deinen Computer, aber nicht soooo viel über dich. Mache bitte erstmal mit FRST weiter.

VHSK 04.11.2012 16:11

ok. kann man ja in kauf nehmen..

das mit der softwarefälschung scheint geklärt..

mache jetzt den usb frst start.

was sind denn diese versteckten desktop.ini dateien?

ryder 04.11.2012 16:27

Die gehören normalerweise zu Windows, keine Sorge.

VHSK 04.11.2012 17:10

Et voilá...

ryder 04.11.2012 19:04

Das sieht aber eigentlich sauber aus.
Jetzt kreisen wir das Problem weiter ein:
Was passiert denn, wenn du versuchst AVG zu entfernen?
Hast du versucht AVG im abgesicherten Modus zu entfernen?

VHSK 04.11.2012 20:21

der avg deinstallierer öffnet sich, hängt sich aber irgendwie auf... versuche es mal im abgesicherten modus.

hier ist eine liste der zuletzt abgerufenen Internet-seiten (Chrome-Verlauf), bevor der computer ins koma gefallen ist (ich glaube zumindest, dass sie es waren)... vielleicht kommt ja von dort der trojaner, bzw vielleicht hilft ja das datum...

Code:



Samstag, 29. September 2012


11:19
Showtime movies - I am live - ilive.to - better live streaming platform
www.ilive.to

11:18
AdF.ly - shrink your URLs and get paid!
adf.ly

11:18
adf.ly - shrink your URLs and get paid!
adf.ly

11:18
Watch Showtime Movies Live Stream | PHSTREAM
www.phstream.com

11:17
Watch Showtime Movies Live Stream | PHSTREAM
www.google.de

11:17
LiveTvCafe.net - Watch Live Tv Channels Online Free - Showtime (Powered by FreeTvAll)
livetvcafe.net

11:17
FreeTvAll.com - Watch Free All Live Tv Channels Online Anywhere - Showtime (Powered by FreeTvAll)
freetvall.com

11:16
Californication (TV Series 2007) - IMDb
www.imdb.com

11:16
IMDb - Movies, TV and Celebrities
www.imdb.com

11:15
showtime live stream dexter - Google-Suche
www.google.de

11:15
Google
www.google.de

11:15
SHOWTIME Live Stream | USA Television
www.stream2watch.me

11:14
Google
www.google.de

11:14
Where can I watch Dexter live online for free.? - Yahoo! Answers
answers.yahoo.com


ryder 04.11.2012 21:21

Die Daten oben helfen leider nicht.

Hast du es jetzt im abgesicherten Modus probiert?

Hast du schon den richtigen Remover probiert?

Link Suche dir bitte das richtige raus - ich vermute mal es wird AVG2012 64bit remover sein.

Probier ob du es damit gekillt bekommst und berichte mir.

VHSK 05.11.2012 06:55

Liste der Anhänge anzeigen (Anzahl: 2)
So, im abgesicherten Modus dachte ich, es hätte geklappt, dann sehe ich aber, als ich ihn normal neu gestartet habe, dass es doch noch drauf ist. Also probier ich es nochmal (im normalen modus) und diesmal bleibt er nicht hängen (computer war diesmal auch von vornherein viel schneller). Es öffnete sich eine Internetseite (anhang) und am Ende erschien eine Fehlermeldung (anhang).
Bei der internetseite find ich einfach nur interessant zu sehen, dass als erste Option Verlangsamung aufgeführt wird, ich scheine also nicht der einzige zu sein...

Hier die Protokolle vom Deinstallationsfehler:
(insg. 7 folgen)

VHSK 05.11.2012 07:17

Ehrlich gesagt weiß ich nicht wie ich sie posten soll, sie sind alle über 97 kb groß... und als code hat das eine auch nicht funktioniert.. ?

Jedenfalls hab ich danach noch mal mit dem remover probiert:
Code:

"Running zap for product code {41B19F41-8A6F-4422-AD69-CF3B408F382C}:05.11.2012  6:52:30,87"

D:\>C:\Users\Vincent\AppData\Local\Temp\avg-69c32039-7b8d-4d36-9c1d-ae5857c0bf10.exe TW! {41B19F41-8A6F-4422-AD69-CF3B408F382C} /nologo


***** Zapping data for user S-1-5-18 for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} *****
MsiZapInfo: Performing operations for user S-1-5-18
Searching for the product {41B19F41-8A6F-4422-AD69-CF3B408F382C} cached package. . .
  Removed file: C:\Windows\Installer\7da7eca.msi
Searching for install property data for product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
  Removed  \14F91B14F6A82244DA96FCB304F883C2\InstallProperties
Searching for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data in the HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall key. . .
  Removed  \{41B19F41-8A6F-4422-AD69-CF3B408F382C}
Searching user's global config location for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes...
  Removed upgrade code '14F91B14F6A82244DA96FCB304F883C2' at HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Removed  \Features
  Removed  \Patches
  Removed  \Usage
  Removed  \Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\14F91B14F6A82244DA96FCB304F883C2
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching per-machine global config location for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching old global config location for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Microsoft\Windows\CurrentVersion\Installer\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching per-machine location for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Classes\Installer\UpgradeCodes...
  Removed upgrade code '14F91B14F6A82244DA96FCB304F883C2' at HKLM\Software\Classes\Installer\UpgradeCodes
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Classes\Installer\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Classes\Installer\Components for published component data for the product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
  Searching HKLM\Software\Classes\Installer\Assemblies for .Net assembly data for the product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
  Searching HKLM\Software\Classes\Installer\Win32Assemblies for Win32 assembly data for the product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
  Searching HKLM\Software\Classes\Installer\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Removed  \Media
  Removed  \Net
  Removed  \SourceList
  Removed  \Software\Classes\Installer\Products\14F91B14F6A82244DA96FCB304F883C2
  Searching HKLM\Software\Classes\Installer\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
  Removed  \Software\Classes\Installer\Features\14F91B14F6A82244DA96FCB304F883C2
Searching for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} in per-user managed location. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching for shared DLL counts for components tied to the product 14F91B14F6A82244DA96FCB304F883C2. . .
  HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Components key is not present.
Searching for shared DLL counts for components tied to the product 14F91B14F6A82244DA96FCB304F883C2. . .
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\sc.dat
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\HtmLayout.dll
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\sb.dat
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\avgatupd.stp
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\avgupdx.dll
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\avgatend.stp
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\sb.dat.xcd
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\js.dat
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\awacs\rules.cat
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\dfncfg.dat
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\awacs\rules.js
  Reduced shared DLL count to 999 for: C:\ProgramData\AVG2012\IDS\config\internalList.zip
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\avgmfarx.dll
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\cf.dat
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\sb2.dat
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\sc.dat.xcd
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\ph.dat
  Reduced shared DLL count to 999 for: C:\Program Files (x86)\AVG\AVG2012\avgupd.sig
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 client info data. . .
  Removed client of component 00FB2164D4C9EF64E96205401125F844
  Removed client of component 02AD614616FB1364ABCE294CCDB95629
  Removed client of component 03417262F87C7FE4AAD0D2FBFC7CB9F3
  Removed client of component 07CE8F8306921AF42913F56E54DC7413
  Removed client of component 0821F183D66E67D4A9649309B1067635
  Removed client of component 08DB6088F9C4056418835141AD119791
  Removed client of component 09215B2FA3729F847A6DC2511E60575F
  Removed client of component 09F2282E0658E444784FD26E7E3B5FF3
  Removed client of component 0A1D4D6BBE0F207409B178F74BE460D7
  Removed client of component 0B38EF98AB1581443AD249C5C90AA6EA
  Removed client of component 0BF9C5167FECCDF4E939E29821860CBD
  Removed client of component 0C147B9CA63DE654493881ED171092DE
  Removed client of component 0CDB03255FAA29D43A726311EE9B39AF
  Removed client of component 0DE2D1B6F75A35E48857357C5EA46A30
  Removed client of component 0E6682D66C458F9478A0C1EE51131927
  Removed client of component 0F6C8A71566ED1C409B6F2442C2CE6E6
  Removed client of component 10DC689E3D5C9E04E956C34BB9DA72FC
  Removed client of component 115C55E4B299C9746B953DCF0F1C0498
  Removed client of component 11DE9CEFE7D23224E82D4F60D277B03D
  Removed client of component 1203663EA1581DC40801EB20CD813A69
  Removed client of component 121A520F1B8E3C24F9636D8ACE286485
  Removed client of component 12EA08C024899B0418292DEE7024C6E3
  Removed client of component 148EF1ED58C99B4429282C1CF4322243
  Removed client of component 1497D8EA46597E649ADA96A94F10BCB8
  Removed client of component 14F579201201E2C428B6A2406E05F571
  Removed client of component 15C4F60261D177A4D822789C4F3088AC
  Removed client of component 1662F5426903BEE4792329B714BA4962
  Removed client of component 16B9439A9B6F09441924A8B28B421AF6
  Removed client of component 1741A9E1E8A32C0488F1BE21E8AD42F9
  Removed client of component 1888CBFD4D7EFBC428B2BE5BC4473322
  Removed client of component 1AD80ED741F46F446997319B1985292B
  Removed client of component 1D1F9947603921C488D8BB5DA1332053
  Removed client of component 1D37CBEDE1A9A5844B092474FCDACDB0
  Removed client of component 1D6A32B776F45E44F8BC652F38790B72
  Removed client of component 1E9A06E17F2CBFC42908A7AD66EF5401
  Removed client of component 1EED469A4C5F7C745827D50BBB8C1761
  Removed client of component 1F13D34635D3E9644A9F79DE7DD15BB5
  Removed client of component 1FA006F2081767D44B10AA2BE4A3080A
  Removed client of component 1FE27B552F13FD14DAA834D775074A1A
  Removed client of component 20258851324DE6248912A1D161CC9E1E
  Removed client of component 209B86F6EA1A22D4CB6594EA4A18F6A2
  Removed client of component 21885EF92FD91A740833A822F2C0B764
  Removed client of component 219F767E8BB90164696322370C445571
  Removed client of component 21C9AA2100231834DAB660767EB6DA28
  Removed client of component 23321D2744275A94FAB6E858B432CC92
  Removed client of component 24C4B793138411F4EA0FAEBD5F54CAE4
  Removed client of component 25585AAE2D9E5C34C9C766C9BFA16652
  Removed client of component 262DEC570D5E8684483BE95DDA53E376
  Removed client of component 26433751F7DE54E43818C88786A3874C
  Removed client of component 2714DC615D53E6C4C86D2E300D8BF9BA
  Removed client of component 274FD6D88AE9D6B42A6EB295F153EA50
  Removed client of component 276B0AEEF5496BF45A7EC616C2498B09
  Removed client of component 289FAF5C09777004F8CC38C673AFB580
  Removed client of component 29D64A3EC8128F74D8BDBFE31FB7EB1A
  Removed client of component 2A2017D405FF9D54C8BDB5B2DC29C084
  Removed client of component 2A69AB43A7F78014AA8A9459CA47DEF3
  Removed client of component 2BA0382DE34CA844E981D04A6081C2D8
  Removed client of component 2BF2207A456F58B47A19FE0FA93DDB2B
  Removed client of component 2C7FAF9742A3D5049BA5E463E6019EEF
  Removed client of component 2D56CCBB52263F141A29BD9F3755DA87
  Removed client of component 2DEE2ED50096FB346A9E531D24B28336
  Removed client of component 2E27E9A619A76BB4B99F42D2DF921A9E
  Removed client of component 2E73953AFC387D045A6333EF2164BFC4
  Removed client of component 2EF2BE8D0D3E0684393AFD5FA2B94CD5
  Removed client of component 2F391EB72F3A0F44798692F96613B5A0
  Removed client of component 2FE417FA6A399D9419D61D1F330B1286
  Removed client of component 3284BC44EA4F61F4A8E619DD6234CF8E
  Removed client of component 32BF6E9B62140814AA76BD323D3CE4A0
  Removed client of component 332B9B84ED6857845A093CA461B64AAB
  Removed client of component 33C46B3013C4D2C4BACC7F32A99F271F
  Removed client of component 35134CB9D14722C46A34A57A68CD647C
  Removed client of component 359ECDCCD3B03434DABDD3C9B108D6EA
  Removed client of component 35FEB4B81DAE148419059119525359D2
  Removed client of component 361C254CFBC214D418730C8805F52801
  Removed client of component 3629EB64CCA6C464796EA6C4DDCBB43F
  Removed client of component 37DD841F8FA18154BB25FDCF9DB27243
  Removed client of component 380B39FF82221C041BE2ECDA2D982C09
  Removed client of component 384BF1A9E63DD6D4FB3D4C9B35875889
  Removed client of component 38D8E24252DD37F45B5698BC3C078DE2
  Removed client of component 394161B2A1C20964E80259487AFC3936
  Removed client of component 3CB9A374886ED3A4B817E5D16761CE91
  Removed client of component 3CE94E96BD39D0E43A6DF1CB6A6A1649
  Removed client of component 3F556399007B345478CBC58CFA411D60
  Removed client of component 3FE89B386F54AD2429446EE2A1137750
  Removed client of component 3FEDF976F5D0D7C4E979FBAE976F1552
  Removed client of component 402F35A3489E5B644986A7D64AFA2F5E
  Removed client of component 405A397C9FCBDC24CBFCEAD25B8E3706
  Removed client of component 413B72E1505931D4AB8BC921148F7CC5
  Removed client of component 41802A8770B2683428FB5EE35B3B269E
  Removed client of component 41BA0F7DB7E9C5D418B7996C5735D37F
  Removed client of component 41ED20A6906033F43860CECF0824F36F
  Removed client of component 425C9CCBFC9B0134FABF2D69D5739792
  Removed client of component 42880575DF40D6342B4D6C02576F4287
  Removed client of component 43D9C93C7646D3C42B404B86C43108D6
  Removed client of component 459698D21314E98439782135FF08F092
  Removed client of component 4611225D7FCC9E844B2BFB9BC814C8FF
  Removed client of component 46C2D78ADEC65254580D82C6F4F0B78D
  Removed client of component 47267D11CB256E640ADFDCA61B72D247
  Removed client of component 48A5A8E6552A6F64D807824201D768B2
  Removed client of component 48C98A705FC92794A96FA37B77B5A0A8
  Removed client of component 4ACD1363AD02ECD448DF9F76CFA51166
  Removed client of component 4CC657C6C8A669C42B42CC5AB2D0A504
  Removed client of component 4D993D550A7310F44AE0F52C79DE37BD
  Removed client of component 4E8D3C51ED202E04CA884A731359977E
  Removed client of component 4EDDFD314B6538744B43B77B3D101812
  Removed client of component 511E1388C85CF06498FF6BDF2F0D60D5
  Removed client of component 52354C62716F2254F86F43DC3CDF632A
  Removed client of component 527B10DD57CA4094BB0A5433F4E18A65
  Removed client of component 5438510F6DD36AD47AC992410BE5BE09
  Removed client of component 549FC47537CCFC14B95101FE728BDCE0
  Removed client of component 54B29B682E4733D4CA8A84B05913AFDE
  Removed client of component 54F221F94B0A52845A61BFE5AE13458D
  Removed client of component 550D8EF204542CF47A1444F7F82C896C
  Removed client of component 5522F383C5285CC459238472161300DA
  Removed client of component 56A11469197931347B2EF54F3C912959
  Removed client of component 57D6D738457BD5D40B4E69BDFD8686DF
  Removed client of component 5811995C26A8252449FD6C7ABC319EB8
  Removed client of component 583CA4CF0AC7F8843A84E5D8130C367A
  Removed client of component 584BA253081CE6D4093008A3EB917631
  Removed client of component 588AD543883CC79409BBD79F21B599A4
  Removed client of component 58BF3FBBE4EAA904F867E97E8EF73499
  Removed client of component 58DE44FAC5064B9499C41C742720988E
  Removed client of component 591A6CDCB390CD848B5D47ED1E3879FC
  Removed client of component 5A164D82FA44BE540A6368B96DDFFDBB
  Removed client of component 5B0FA21D31C5FBB438F2152432E8B9E4
  Removed client of component 5BC04B484C8B06F469C1F053A437F39B
  Removed client of component 5BE80BB925727C940A6CC44335537CC1
  Removed client of component 5D70FD512AFFB5C459F4EB79441AB0CA
  Removed client of component 5E1B2F759E7C1574D8A4E5F5C412EEF1
  Removed client of component 5EA8BCD3F5B513B4FAF5770FF33F9C28
  Removed client of component 60C68AE8C906D55429FC04F241915288
  Removed client of component 6105B82D03B14774E8B6F59DD0B8F6A7
  Removed client of component 6199430737C0E3E48A204C870714C0E6
  Removed client of component 62297EFB1EAD1374A8BE37951773392E
  Removed client of component 6240EB65F43EB9E46918722AA9A690F3
  Removed client of component 624BB461518C0F94CB88FFBA9572EEC0
  Removed client of component 654FD6FD7F74FF047BBF46A837C689F5
  Removed client of component 659AFF1C9FB73FA428D29FBDFF2CEADC
  Removed client of component 6610574CDE09E664DB24D0BBD59F94A8
  Removed client of component 66791AB3105772941AAF175F0A6CBD84
  Removed client of component 6692140C420A7034BB32511EEF6A4046
  Removed client of component 6744005AEAA90224F9B2577B50A49AEB
  Removed client of component 681EE1FDB0838BC4DAB9A1A93335CA91
  Removed client of component 687E351671D8BC14280980A68E785258
  Removed client of component 693D14B7DCD6098408467DD114548893
  Removed client of component 6981AB81A4738804691A6209577B632B
  Removed client of component 698AAC0801AEC994B909F8BA01702155
  Removed client of component 69A6F144A153F364499AD9E627047D55
  Removed client of component 6A93A02ADE963AB4EA3963505708CD0D
  Removed client of component 6B73052A1DF4DEC4F82474ABD9C86A1D
  Removed client of component 6BF3878AE2AA11F408E1A39F51D957BD
  Removed client of component 6C3DEC6E1282CE749B91A1F90C3ADBE6
  Removed client of component 6EA0D887B9A94764AA0152EC3E308725
  Removed client of component 6FF641D575ACB6942AE7FF90ACC0201F
  Removed client of component 707EAD4321AA99541B459CD6A88E6F9C
  Removed client of component 7121893414A1B8B4BA6033E95AD2F70C
  Removed client of component 714CF90045B6EF74B8455FFC5AC00F25
  Removed client of component 723C2A1E41455784EB3E7504A5001051
  Removed client of component 733C87EE6B7ECAF4A8DA17E45C881131
  Removed client of component 7391F3C90835FB848957E90B18365F19
  Removed client of component 74416286FE81BBE4882ECC9746CBF7BD
  Removed client of component 749369BC0D2AAA14ABFA36894681D87F
  Removed client of component 74D38C06420EEC94AAA13DD9EC0E0096
  Removed client of component 76113BD4CDB4CDD42B914765E5971681
  Removed client of component 768C888C1F369C94EA721FCEE3930603
  Removed client of component 76A63CD6BDF1430468269ED964B57273
  Removed client of component 770E95C8DE80B324499FFC89718EA6AA
  Removed client of component 77B1698BE23CB0D40ADF0D5C841A5B3F
  Removed client of component 7807090397DF2BE4785478B73671B0FB
  Removed client of component 780BCF6A96755FA40A0C1970B8C39541
  Removed client of component 792EAE80B02653045A0688B229664084
  Removed client of component 7A8D8B33104478F4B89E2D816396013A
  Removed client of component 7AE8A4C6FA6F1144EB0A7F8EDC02E54C
  Removed client of component 7B9D1CBE18CC60241A55D03838468C56
  Removed client of component 7C615F9D79C89CE4DA7FD8F6178C5978
  Removed client of component 7C9EEBB866FA8854297217E0C91407EF
  Removed client of component 7F165CCEE2D6A754CBF1A33B3690B35D
  Removed client of component 7F6A9E3A59E21424383B679FA8B12056
  Removed client of component 8064306BD59432B4BA00AF9AFDB3E00D
  Removed client of component 80982D461CE8DFD4AAC4E11EC5A69794
  Removed client of component 8108A82209BEC1044AE571A90EA62CC4
  Removed client of component 81F0D4C6159E8064F9CBE6CD6BB15963
  Removed client of component 8387317AED1A0D64C8F39A05D3E5ADE2
  Removed client of component 839749C7DE6C0FB4D92038E653899CEB
  Removed client of component 84A020F387925634F9769E7BFE004F20
  Removed client of component 85078668E396D1B4199D13221660DCF5
  Removed client of component 85CCEB323E53F5E4FBC9850ED9532E70
  Removed client of component 85EC1D8B7BE494A4A9DE14D2271176C6
  Removed client of component 85F0B0B76FD63E9429923C033DF8F498
  Removed client of component 879764956D4F84346A5BD47A168A5173
  Removed client of component 8B3876962B20F634B894D96B6E6F5B3E
  Removed client of component 8B5BC1C170CABFA4D85081BEEA06E6A9
  Removed client of component 8BA53390B6D77D14FACBC84BD234C32C
  Removed client of component 8BD6E5805034D7A4E86B315BA3C5454A
  Removed client of component 8BE35A0BBF201A24EA4DB8197F34134B
  Removed client of component 8D1E989ED0C81B44B8BE9B0BE8C58EC5
  Removed client of component 8D28B2E7EC7B56B468FC62AD25220867
  Removed client of component 8D9E99A44477C6648A00D7F548844749
  Removed client of component 8F3EDF98BC3E58941A7473BC41B43F5F
  Removed client of component 8FBFB03FE5F2E9549BE954CE52B78FB9
  Removed client of component 902357776D756434099161F48CB7EB99
  Removed client of component 92312A030BCF97341979ACF99F2C15D2
  Removed client of component 9238717B266ADD643AD39013EA460A97
  Removed client of component 9294A456131736745852BDD8BDC475E1
  Removed client of component 934CE06719A1AF642959CEF8686B15C5
  Removed client of component 9368A939062BF934199093B2E6403F9F
  Removed client of component 936B3CE721A634E48846EA0BB0842EFB
  Removed client of component 94BC40A46E5A5144788CC24648AEC8BC
  Removed client of component 964A33E77500CC34B8D3F5DEAD6212A6
  Removed client of component 9665D78DA1469094383ECF47A9D8D84C
  Removed client of component 9799070EAD4A1524C88683DB56D1584E
  Removed client of component 97BAE971E7A56FA47BA1118B0F8B6747
  Removed client of component 97EDF8697F32F24439BF8526C9E8BD68
  Removed client of component 97FBC35B48854B347BFB2DBEF203CBAF
  Removed client of component 9825CB7F5ACA03142B83118BDD627D7F
  Removed client of component 99CC2F1A7F8FC3F448D74BDC23AB8E68
  Removed client of component 9AC0785E3BC2A5D44BCAA40E283576B7
  Removed client of component 9ADDD90BBDEDE824C807D5DB9B992F66
  Removed client of component 9B656E919AA389B4CBCF0C57D33E1E29
  Removed client of component 9B90AA0CAE1D3E147BEF2CF6797EFA1E
  Removed client of component 9BDF2516394B58A4D9C6C12CC9E099BB
  Removed client of component 9C7780973C9B9BC448B7FA598B68AD4E
  Removed client of component 9CBF7FC1F7873ED49862F04CA10B8FDE
  Removed client of component 9D14327F34F93E64480FD3DC6E97131C
  Removed client of component 9D92789C51EDF8F4EB3FB8325179F2FB
  Removed client of component 9D9F23382CA2E684A89A5BFC1D227137
  Removed client of component 9DDDC04E1C3AF3B438EE7F7FDA6461ED
  Removed client of component 9E444D35BC85EFF41BBA156CC0E491B2
  Removed client of component 9EE57B10911F35A438636C79A6DE2033
  Removed client of component 9FAA3A8AA9064C94BAFDA0B4BA6ADCB8
  Removed client of component A0066271D79C6F24F8728D6D2EF36308
  Removed client of component A0513AEF7C219284DA9518167EE77082
  Removed client of component A1134359B7955984A9B6A1FC0EEB7EBE
  Removed client of component A18413103C8272F4D8E50C5C1A599BC7
  Removed client of component A1C0147BB35C38246A6BED808A6048BC
  Removed client of component A20C63B2F09022B42BD78DB6F97EDC19
  Removed client of component A29CCD0EF2F170C4A820E901B1D05C94
  Removed client of component A2DCC9330C5A5B343B4A9178986A421A
  Removed client of component A32CD0EC4A8FBA1478BD2CB031145A85
  Removed client of component A349FB85ED23A94429528A9DE2707EBD
  Removed client of component A3512A90D4B94F44E8CBD76F01988E13
  Removed client of component A356DB03D439C944BA8E4936AF9FA85C
  Removed client of component A4DF15DF1AEF0BC4194959FAC3C8D515
  Removed client of component A5640AD18AA0ADB46B742389583CC79A
  Removed client of component A692E78D59122C34BA02F3029493BADD
  Removed client of component A754AE0AE1C52EC498470B0914896271
  Removed client of component A82D93DE5E568404E98115D545346EC6
  Removed client of component A866FECCC2EDFAB4081ED457B0F19F21
  Removed client of component AABE34F4E0B29BE4E99FABF43E3EFDC5
  Removed client of component AC0F0309298BE894EA35BF369DCC9049
  Removed client of component AC5CF863E3B0F8044BE4AE5ECF29A8AE
  Removed client of component AC7A2A3DB8930B84DAA78C1B6DE74526
  Removed client of component AD995495EC471EA4AB014AA2F1A81080
  Removed client of component AEA16B55A833DBE4784A89E373C82EF0
  Removed client of component AEC4428EA000C324181FE263620DA9F7
  Removed client of component B180763B6DDA19E46AA65D1F707172AB
  Removed client of component B2D2DF1A281EEF74F8C86A47D02A1959
  Removed client of component B2D4B1005E2356142A5D234551CD547B
  Removed client of component B39B28FC21842DD4793DB5C281490DF7
  Removed client of component B5967C94AD2608E4BA9ABBAD47838116
  Removed client of component B6240439242E4BC4E8F83A199AC2AEE2
  Removed client of component B6D0804A314D9794CB2DC1CA9447CC87
  Removed client of component B6D7DD87E66F85440920466D71991278
  Removed client of component B6DC47FEE7E55504C8A108B06F6BD2BB
  Removed client of component B7F49CBF0544C7C4D9030FDD1C8477C8
  Removed client of component B8B0C5D47B9497C4291ADB123BCE0EB9
  Removed client of component B9F995C22DB895E46A259E9A0561EF65
  Removed client of component BBD32FBAD07C36442BCF603DFF0C3D75
  Removed client of component BC79836E536DA7A41809ECBCF974116B
  Removed client of component BD1B0C29845DCE94B9B1D6F759947C16
  Removed client of component BDD8855D45FB10646861C79AFEBF86C5
  Removed client of component BE3DDB414A5C2D04D925C0BF406D6710
  Removed client of component BF85F3119F70FE94D8DD866825A8C6A9
  Removed client of component BFB0077CB3DD6D74BBBDEF827EC83942
  Removed client of component C105182B53D91C940A0777CE3399CE17
  Removed client of component C23101620A7410C448718DE31C4D5A35
  Removed client of component C31468550121A4A40BEBE793CE231D3E
  Removed client of component C3FE241C5BF96A94D885409117ECBABB
  Removed client of component C4CB18365C8AF1045B7D4B7F9A0C006B
  Removed client of component C4CCD9C1528D29C4BBF611EFFE3B6D08
  Removed client of component C4CFB718387E9EB45B407A8E4B14264A
  Removed client of component C4EC6DD7180AC9840AFA49EE52C3C4F0
  Removed client of component C60211C610823404FB10F01F02ABCB9B
  Removed client of component C66BDDF209F3AD645AB634C50DE7F7ED
  Removed client of component C67820A22FB21F649A904D85ECF3EDF7
  Removed client of component C6DBD13D059CC794E83445EFD03AE076
  Removed client of component C70B0D249FA09DC42B111492CFD6BBBB
  Removed client of component C7EE74E5D2941974BAA3E1A37B8C55C9
  Removed client of component C886527D8FC6F67409CC1785EAD83508
  Removed client of component C8F648C5E8F27B6488CEEED1CF683B8B
  Removed client of component C9416FA855A98BF4792271554BFDAABB
  Removed client of component CAEE8C192FDFB13479C32862C650F4D6
  Removed client of component CAEF0206AA1A04A43AE31A5CC20C5444
  Removed client of component CBBE5F8AE6A8DE247A8A775E67E44B3C
  Removed client of component CBD102EF66D93CB4A8C6AA14FD2335B3
  Removed client of component CC1D0B74289CF904BA9F1CBE306F7354
  Removed client of component CC970BF39E3E738478706ACF972F52AE
  Removed client of component CD1C323D312570945A884F5D7DCEFEBB
  Removed client of component CD2FFF4DC65728149A096E258856F692
  Removed client of component CD43BEA39CA1DB64490673C012F18BFE
  Removed client of component CDBC84CC8E7CC8F4AB4F381572014A94
  Removed client of component CDD48CDF1DAE2384C968BF53CC3B8B4C
  Removed client of component CE45FE7787028E24D8D4066125F6B64C
  Removed client of component CE6D544924D09E84F8042BAD38A60F78
  Removed client of component CE79C231997464846920C2A6994F757B
  Removed client of component CEA9A6D8B5FDFB34B875367D1065891A
  Removed client of component CFA46696AFCE1CB4AAE0B3D8E3B65217
  Removed client of component D074E81EF0C5EEF48AB9E05FE98AF421
  Removed client of component D0DF41036523CEE4C9C4116142AB5939
  Removed client of component D0F185BFF8CCDA14AA98CB4961AABE45
  Removed client of component D41591240BFD6E34589254139C8E0177
  Removed client of component D47DF81D063677C4386D5C3A38D9ECC5
  Removed client of component D511310E193FB924691EE8E4899281E7
  Removed client of component D55441B1479F59740AFBE9FDD2740122
  Removed client of component D62BA8D870EDB2B40B2ED662BBD084C1
  Removed client of component D729A26097AD7FB4DBADCB4B54B996A3
  Removed client of component D75A3BC0A55667A488F4DF8B37461E87
  Removed client of component D866A5DABB6C36B438BE5CF5BA28B211
  Removed client of component D86F5EDBB77274E4A92AD98FCA215919
  Removed client of component D88DEAD01DF0D8C4082F327D910AA736
  Removed client of component D9BBD8AF64DB9DF4EB40EF79BC7C4E81
  Removed client of component DB21340018319B0438D1FC0DF8C7776B
  Removed client of component DB23D2363BF5F754B9AAD07ED74C14F5
  Removed client of component DBB119042F602E149A1828A6C50B517D
  Removed client of component DC1A862FADBE0874DA7DB986505EA7B0
  Removed client of component DC548F66804580044BA742BF5DEF7E9A
  Removed client of component DC6F9B8AB0594174DB1A8418F5D31D10
  Removed client of component DCE7FD9ADD3FE4C43A0B0BDBB5FF3A9D
  Removed client of component DD4C58965EE9CD74097AE4D52BC38174
  Removed client of component DD8AA62319076AD469EA56D4E2CB2EC9
  Removed client of component DEDA8A433CD021642BE1DD3AE45EC550
  Removed client of component DEE4BD0922B59024AB720BF0B16A00B6
  Removed client of component DF7426EFFD9735C458D348B69EEE0542
  Removed client of component E1AE7BF52C8D76444B4750ACAA8D255B
  Removed client of component E2A454327BA2AE245BF287EA51DED8EC
  Removed client of component E36DD787A29FC5B4FB3983B7881B81FB
  Removed client of component E41B494CC536D2140A47BF7060989593
  Removed client of component E433AA04A91C4F34F859AD4629343519
  Removed client of component E4353913FE8BD564EAF1B7F4DA9F2528
  Removed client of component E44FA2B654640724596D61083C5FD4A4
  Removed client of component E583759B13F5D054B801210C67780086
  Removed client of component E8461EE0E9D58394FBA5BDBCDAD0F722
  Removed client of component EB06BD404D6EB77448B48C83D896EEAE
  Removed client of component EB66A40157026C34FB66DEAF92622EBF
  Removed client of component ECF0C86740A17A242981A461D7A40328
  Removed client of component ECFF7FD6E6A8EFC4AA259E9173B34B94
  Removed client of component ED90795236E27C24CB18D231731F1FB2
  Removed client of component EE362632BDE7F53468931017C9FE9F58
  Removed client of component EEEAB3C9702367644B8F522093D5B83C
  Removed client of component EEF4F7070057EFC44BCD0A4ECA1D63A6
  Removed client of component EF8141EDBC3732A4AA5CF0443DA8C6BF
  Removed client of component EFFE8EEEBDB6CC34FB81DD7C7DB2FF15
  Removed client of component F061708F3225D9D4D906120730B2AC2D
  Removed client of component F0839BF88786D904D842E3A12C0E09FD
  Removed client of component F0BD53C72928ED34596E716A52B8BBC0
  Removed client of component F17FC484AAB8919449542D896C9BCB4F
  Removed client of component F1C570715109D3A4A99BE27ED26855D8
  Removed client of component F2A8FCE0C74359D4093F67EC7D6E1500
  Removed client of component F325D7BB7989D8F4D876651E5811E2A6
  Removed client of component F330C824EC6536D4DB1652975923033F
  Removed client of component F37F0F0B9EB84E34F8C7B8CAC4467074
  Removed client of component F3D629045F6B8E347B0846334E5D3D92
  Removed client of component F48C37897CBAF324483D3A82EB1ECE9D
  Removed client of component F4DCC2F4D1D87034C8DE335A424D092B
  Removed client of component F549D72EB97BFC34DBFE85252BE316DB
  Removed client of component F5762A04D23DFDF409B143E6F80B36E0
  Removed client of component F59EFE50136030B4E87919A92806215B
  Removed client of component F5E1BB41968CC1B4788EAF61AA9B07D4
  Removed client of component F6904A4EC8AA6824AA98B30B170A1B7A
  Removed client of component F74CF95EF80320246A95AC7A43EEBAE9
  Removed client of component F757A89A2E3212C4EBD744B8D6F0A3CC
  Removed client of component F762B380CA9EA734F9DDC58C6F2F3ACB
  Removed client of component F77A4F94E03B00F429651D643688C183
  Removed client of component F7AF2723EF90BA64D9B9E2C7C0A24D21
  Removed client of component F8168FD8729B88343B63BBB823EB8CE0
  Removed client of component F86CE24379AECA5439A24CF0FCB467B1
  Removed client of component F8E8B4C854C050D4B8D12A8CDA1340C8
  Removed client of component F915FD4BFE14BD84E8D6CF7EA80B9D4F
  Removed client of component F94CEB5132A64074B8AB5E041D59BD43
  Removed client of component F9D680E815490724A9868C09AB5057E9
  Removed client of component FA116E182F95B5B49896E51E3DDEF167
  Removed client of component FA28C090436E045469BD279915C49FB4
  Removed client of component FADA742E8571AEB48BEF171FE7BDCBCC
  Removed client of component FBD5E45BC65F74F4A954A75074B73E72
  Removed client of component FC1A52BFAAA60D54BB9F3B852AAA5F9D
  Removed client of component FC359DF5AC8E6F9468823167B72DCDE6
  Removed client of component FCF7479C6905AA0459397D1D1F6827CB
  Removed client of component FCFA7ABAD5FCFE646BBA4CDCA19C3633
  Removed client of component FE69A3AD1FFCBFF40AE3F850520FB704
  Removed client of component FE6B425CFD173B84EBF82724F0EF5FCD
  Removed client of component FEE91B250D6F8EC4A9DB588DF789E9E8
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 client info data. . .
Searching for Installer files and folders associated with the product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
  Searching for files and folders in the user's profile. . .
  Searching for files and folders in the %WINDIR%\Installer folder
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgabout.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgamnot.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgapia.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgapix.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgapps.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgcclia.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgcclix.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgcerta.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgcertx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgcfga.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgcfgex.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgcfgx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgchcla.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgchclx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgchjwa.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgclita.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgclitx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgcmgr.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgcsla.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgcslx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgcsrva.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgcsrvx.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgdecider.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgdiagex.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgdumpa.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgdumpx.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgemca.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgidpmx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgidpsdkx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\AVGIDSAgent.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgld.cat
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgld.inf
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgldx64.sys
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgldx86.sys
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avglnga.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avglngx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgloga.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avglogx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avglscanx.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgmf.cat
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgmf.inf
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgmfx64.sys
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgmfx86.sys
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgmvfla.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgmvflx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgnsa.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgntdumpa.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgntdumpx.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgntopenssla.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgntopensslx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgntsqlitea.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgntsqlitex.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgopenssla.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgopensslx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgpostinstx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgpp.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgppa.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgresf.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgrk.cat
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgrk.inf
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgrkta.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgrkx64.sys
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgrkx86.sys
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgrsa.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgscana.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgscana.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgscanx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgscanx.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgsched.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgse.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgsea.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgsrma.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgsrmaa.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgsrmax.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgsrmx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgssff5.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgssff6.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgssff7.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgssff8.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgssff9.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgssie.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgssiea.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgsysa.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgsysx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\AVGTBInstall.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgtdi.cat
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgtdi.inf
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgtdia.sys
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgtdix.sys
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgtray.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgui.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avguiadv.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avguires.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgutila.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgutilx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgvva.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgvvx.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgwd.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgwdsvc.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgwdwsc.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgwebui.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgwsc.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgxpl.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\avgxpla.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\AxBrowsers.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\axioo.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\DiskCleanerHelper.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\DiskDefragHelper.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\fixcfg.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\helper.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\localizer.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\MicroScanner.exe
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\MicroScannerElevation.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\RegistryCleanerHelper.dll
  Removed file: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901\RescueCenterHelper.dll
  Removed folder: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2\12.0.1901
  Removed folder: C:\Windows\Installer\$PatchCache$\Managed\14F91B14F6A82244DA96FCB304F883C2


***** Zapping data for user S-1-5-18 for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} *****
MsiZapInfo: Performing operations for user S-1-5-18
Searching for the product {41B19F41-8A6F-4422-AD69-CF3B408F382C} cached package. . .
Searching for install property data for product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
Searching user's global config location for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching per-machine global config location for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching old global config location for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Microsoft\Windows\CurrentVersion\Installer\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching per-machine location for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Classes\Installer\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Classes\Installer\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Classes\Installer\Components for published component data for the product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
  Searching HKLM\Software\Classes\Installer\Assemblies for .Net assembly data for the product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
  Searching HKLM\Software\Classes\Installer\Win32Assemblies for Win32 assembly data for the product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
  Searching HKLM\Software\Classes\Installer\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKLM\Software\Classes\Installer\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} in per-user managed location. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-18\Installer\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching for shared DLL counts for components tied to the product 14F91B14F6A82244DA96FCB304F883C2. . .
  HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Components key is not present.
Searching for shared DLL counts for components tied to the product 14F91B14F6A82244DA96FCB304F883C2. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 client info data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 client info data. . .
Searching for Installer files and folders associated with the product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
  Searching for files and folders in the user's profile. . .
  Searching for files and folders in the %WINDIR%\Installer folder


***** Zapping data for user S-1-5-21-1655660024-2649062184-858687661-1000 for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} *****
MsiZapInfo: Performing operations for user S-1-5-21-1655660024-2649062184-858687661-1000
Searching for the product {41B19F41-8A6F-4422-AD69-CF3B408F382C} cached package. . .
Searching for install property data for product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
Searching user's global config location for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1655660024-2649062184-858687661-1000\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1655660024-2649062184-858687661-1000\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1655660024-2649062184-858687661-1000\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching per-machine global config location for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching old global config location for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Microsoft\Windows\CurrentVersion\Installer\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching per-machine location for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Classes\Installer\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Classes\Installer\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Classes\Installer\Components for published component data for the product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
  Searching HKLM\Software\Classes\Installer\Assemblies for .Net assembly data for the product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
  Searching HKLM\Software\Classes\Installer\Win32Assemblies for Win32 assembly data for the product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
  Searching HKLM\Software\Classes\Installer\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKLM\Software\Classes\Installer\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching old per-user location for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Classes\Installer\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Classes\Installer\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKCU\Software\Classes\Installer\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKCU\Software\Classes\Installer\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching per-user location for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Microsoft\Installer\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Microsoft\Installer\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKCU\Software\Microsoft\Installer\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKCU\Software\Microsoft\Installer\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching for product {41B19F41-8A6F-4422-AD69-CF3B408F382C} in per-user managed location. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 upgrade codes in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1655660024-2649062184-858687661-1000\Installer\UpgradeCodes...
  Searching for patches for product 14F91B14F6A82244DA96FCB304F883C2 in Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1655660024-2649062184-858687661-1000\Installer\Products\14F91B14F6A82244DA96FCB304F883C2\Patches
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1655660024-2649062184-858687661-1000\Installer\Products\14F91B14F6A82244DA96FCB304F883C2 for product data. . .
  Searching HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1655660024-2649062184-858687661-1000\Installer\Features\14F91B14F6A82244DA96FCB304F883C2 for product feature data. . .
Searching for shared DLL counts for components tied to the product 14F91B14F6A82244DA96FCB304F883C2. . .
  HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Components key is not present.
Searching for shared DLL counts for components tied to the product 14F91B14F6A82244DA96FCB304F883C2. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 client info data. . .
  Searching for product 14F91B14F6A82244DA96FCB304F883C2 client info data. . .
Searching for Installer files and folders associated with the product {41B19F41-8A6F-4422-AD69-CF3B408F382C}. . .
  Searching for files and folders in the user's profile. . .
  Searching for files and folders in the %WINDIR%\Installer folder

Es scheint also deinstalliert zu sein? Jedenfalls finde ich es bei "programme und funktionen" nicht mehr. Nur die Verlinkung auf dem desktop ist noch da ;)


Jetziger Stand:
(Nach 1. Versuch im abg. Modus 2. Versuch im normalen Modus 3. vermutlicher Erfolg im normalen Modus mit remover)

Computer wieder normal schnell, man kann wieder gut mit ihm arbeiten, jedoch hängt er ab und zu für kürzere Zeit manche Programme auf (z.B. sowohl Chrome als auch Firefox, sobald man versucht, den Verlauf anzugucken..).

Was mache ich jetzt mit micr security essentials? Drauf lassen oder anderes Virenprogramm (außer avg ;) ) installieren?
Weiteres Vorgehen?

ryder 06.11.2012 14:24

Ich perönlich kenne MSE nicht sondern nutze seit längerem Avast. Damit komme ich gut zurecht. Beobachte das jetzt bitte erstmal und mache in neues OTL-Log. Vielleicht sehen wir da ja noch ein paar Überreste, die wir entfernen müßten.

Kontrollscan mit OTL
  • Starte bitte OTL.exe
  • Stelle sicher, dass "Alle Benuzter Scannen" angehakt ist!
  • Drücke den Quick Scan Button.
  • Poste die OTL.txt hier in deinen Thread.

VHSK 07.11.2012 16:57

Mein word funktioniert irgendwie nicht mehr...

Gehts auch als code?

OTL Logfile:
Code:

OTL logfile created on: 11/7/2012 7:36:02 AM - Run 2
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Vincent\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.80 Gb Total Physical Memory | 2.45 Gb Available Physical Memory | 64.42% Memory free
7.60 Gb Paging File | 6.18 Gb Available in Paging File | 81.29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 296.09 Gb Total Space | 223.25 Gb Free Space | 75.40% Space Free | Partition Type: NTFS
 
Computer Name: LIFEBOOK-A530 | User Name: Vincent | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012/11/01 23:38:59 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Vincent\Desktop\OTL.exe
PRC - [2012/07/27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/25 10:28:02 | 000,101,288 | ---- | M] (Fujitsu Technology Solutions) -- C:\Program Files (x86)\Fujitsu\DeskUpdate\DeskUpdateNotifier.exe
PRC - [2011/11/24 16:31:18 | 001,837,568 | ---- | M] (TerraTec Electronic GmbH) -- C:\Program Files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe
PRC - [2011/09/15 12:06:04 | 000,088,576 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2010/04/14 16:40:00 | 000,235,579 | ---- | M] () -- C:\Program Files (x86)\Lion\Lion.exe
PRC - [2009/11/01 17:04:48 | 002,314,240 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009/11/01 17:04:42 | 000,262,144 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009/10/09 21:06:50 | 000,047,976 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
PRC - [2009/10/08 20:44:54 | 000,036,712 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012/09/15 09:49:38 | 000,766,976 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\log4net\ca507030bb77d2c58f5cebca8b4de7f0\log4net.ni.dll
MOD - [2012/09/15 09:49:38 | 000,117,248 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\DeskUpdateNotifier\82cf810ac24ee22f99a0a1a7a752947c\DeskUpdateNotifier.ni.exe
MOD - [2012/06/15 20:27:06 | 013,198,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\3971e166cf827b6726e142f344061dc9\System.Windows.Forms.ni.dll
MOD - [2012/06/15 20:26:56 | 001,666,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\8c40f40ef36622109793788049fbe9ab\System.Drawing.ni.dll
MOD - [2012/05/15 17:06:10 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll
MOD - [2012/05/15 17:06:06 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\623d2a0f11dd82bb9bc13d1cb981b239\System.Configuration.ni.dll
MOD - [2012/05/15 17:06:04 | 009,091,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll
MOD - [2012/05/15 17:05:59 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
MOD - [2010/04/14 16:40:00 | 000,235,579 | ---- | M] () -- C:\Program Files (x86)\Lion\Lion.exe
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2012/09/12 20:21:48 | 000,368,896 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2012/09/12 20:21:48 | 000,022,072 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/06/23 17:14:38 | 000,330,240 | ---- | M] (FUJITSU LIMITED) [On_Demand | Stopped] -- C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe -- (PFNService)
SRV:64bit: - [2009/12/24 12:43:40 | 000,145,840 | ---- | M] (CSR, plc) [Auto | Running] -- C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe -- (VFPRadioSupportService)
SRV:64bit: - [2009/07/30 10:43:00 | 000,063,336 | ---- | M] (FUJITSU LIMITED) [Auto | Running] -- C:\Program Files\Fujitsu\PSUtility\PSUService.exe -- (PowerSavingUtilityService)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/11/05 07:42:28 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/10/14 13:24:08 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/06/07 18:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011/09/15 12:06:04 | 000,088,576 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2011/05/27 15:23:00 | 001,300,264 | ---- | M] (Synaptics, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe -- (ScrybeUpdater)
SRV - [2010/09/13 12:58:24 | 000,399,944 | ---- | M] (Elgato Systems GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\Elgato\EyeTV Netstream\EyeTVNetstreamSvc.exe -- (EyeTV Netstream)
SRV - [2010/03/18 21:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/11/01 17:04:48 | 002,314,240 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009/11/01 17:04:42 | 000,262,144 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/10/16 16:18:17 | 000,759,072 | ---- | M] (ABBYY (BIT Software)) [Disabled | Stopped] -- C:\Program Files (x86)\ABBYY Screenshot Reader\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.ScreenshotReader.9.0)
SRV - [2008/07/04 11:52:18 | 000,014,336 | ---- | M] (Vodafone) [Disabled | Stopped] -- C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012/08/30 21:03:48 | 000,128,456 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/08/23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 15:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012/08/23 15:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012/08/21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/07/09 12:42:54 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/01/03 16:28:54 | 000,047,208 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tbhsd.sys -- (tbhsd)
DRV:64bit: - [2012/01/03 16:28:47 | 000,037,480 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rrnetcap.sys -- (RRNetCapMP)
DRV:64bit: - [2012/01/03 16:28:47 | 000,037,480 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rrnetcap.sys -- (RRNetCap)
DRV:64bit: - [2011/08/02 15:38:44 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
DRV:64bit: - [2011/03/31 18:32:00 | 001,424,944 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/21 04:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/06/25 16:08:10 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
DRV:64bit: - [2010/06/08 09:33:14 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010/04/12 08:09:08 | 000,131,144 | ---- | M] (ABILIS Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AbilisBdaTuner.sys -- (AbilisT)
DRV:64bit: - [2010/03/04 21:43:00 | 000,346,144 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/12/18 11:38:56 | 008,038,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/11/27 05:15:00 | 000,244,736 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2009/11/06 12:56:06 | 001,550,848 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009/11/02 18:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
DRV:64bit: - [2009/11/01 17:04:42 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009/10/26 12:39:44 | 000,151,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 01:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2009/07/14 01:00:13 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Dot4Scan.sys -- (Dot4Scan)
DRV:64bit: - [2009/07/14 00:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008/03/17 10:06:14 | 000,115,328 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV:64bit: - [2006/11/01 17:59:24 | 000,007,296 | ---- | M] (FUJITSU LIMITED) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\fuj02e3.sys -- (FUJ02E3)
DRV:64bit: - [2006/11/01 17:20:28 | 000,007,808 | ---- | M] (FUJITSU LIMITED) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\fuj02b1.sys -- (FUJ02B1)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{916F2051-FF46-4C6C-B0CC-5621E68CBCFE}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7FTSG
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{916F2051-FF46-4C6C-B0CC-5621E68CBCFE}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7FTSG
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ts.fujitsu.com
IE - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.google.com/ig/redirectd [Binary data over 200 bytes]
IE - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=FTSG&bmod=FTSG
IE - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\..\SearchScopes\{72C07153-7FE4-4370-A10E-899B5605130B}: "URL" = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}
IE - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=937811&ilc=12"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}:6.0.33
FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Vincent\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Vincent\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/07 00:13:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012/08/29 20:08:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\avgthb@avg.com: C:\Program Files (x86)\AVG\AVG2012\Thunderbird\
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/07 00:13:38 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2011/12/25 22:02:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Vincent\AppData\Roaming\mozilla\Extensions
[2012/11/01 16:19:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Vincent\AppData\Roaming\mozilla\Firefox\Profiles\9u0eqmus.default\extensions
[2012/11/01 16:19:41 | 000,048,118 | ---- | M] () (No name found) -- C:\Users\Vincent\AppData\Roaming\mozilla\firefox\profiles\9u0eqmus.default\extensions\GlassMyFox@ArisT2_Noia4dev.xpi
[2012/09/12 22:52:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012/09/07 00:13:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/09/12 22:52:25 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/11/03 16:57:41 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\updated\extensions
[2012/11/03 17:02:45 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\updated\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2012/11/03 16:57:41 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\updated\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/11/03 16:58:05 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\updated\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/09/07 00:13:38 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/09/06 22:34:59 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/09/06 22:34:59 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/09/06 22:34:59 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012/09/06 22:34:59 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/09/06 22:34:59 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/09/06 22:34:59 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Vincent\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Vincent\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2210_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U35 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.350.10 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: Media Go Detector (Enabled) = C:\Program Files (x86)\Sony\Media Go\npmediago.dll
CHR - plugin: PlayStation(R)Network Downloader Check Plug-in (Enabled) = C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Wetter (Erweiterung) = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\beapnbfmjmjhhfpaoajfhjbbfnnlfpnc\0.9.0.0_0\
CHR - Extension: Adblock Plus (Beta) = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Grooveshark Germany unlocker = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\docdgimmdejoiemdafcgeodchlbllgac\2.3.4_0\
CHR - Extension: Grooveshark Germany unlocker = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\docdgimmdejoiemdafcgeodchlbllgac\2.3.4_0\.orig
CHR - Extension: Regentropfen(Non-Aero) = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpagcfbbmlebfnkeogkigellbgmfkjfg\1.0.0.2_0\
CHR - Extension: AdBlock = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.45_0\
CHR - Extension: Smooth Scrollerator = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmicgfcegednlkdhgbhgickcgndjeeig\1.1.1_0\
 
O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\PROGRA~2\TerraTec\TERRAT~1\THCDES~1.DLL (TerraTec Electronic GmbH)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [BthSyncServ] "C:\Program Files\CSR\Bluetooth Feature Pack 5.0\bthsyncserv.exe" File not found
O4:64bit: - HKLM..\Run: [ConMgr] C:\Program Files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe (CSR, plc)
O4:64bit: - HKLM..\Run: [CSRBIP] C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRBipPushResponder.exe (CSR, plc)
O4:64bit: - HKLM..\Run: [CSRFTP] C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRBthFtpServer.exe (CSR, plc)
O4:64bit: - HKLM..\Run: [CSRSkype] C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRSkype.exe (CSR, plc)
O4:64bit: - HKLM..\Run: [FDM7] C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PSUTility] C:\Program Files\Fujitsu\PSUtility\TrayManager.exe (FUJITSU LIMITED)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [DeskUpdateNotifier] C:\Program Files (x86)\Fujitsu\DeskUpdate\DeskUpdateNotifier.exe (Fujitsu Technology Solutions)
O4 - HKLM..\Run: [IndicatorUtility] C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [LoadFUJ02E3] C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1655660024-2649062184-858687661-1000..\Run: [ABBYY Screenshot Reader Retail]  File not found
O4 - HKU\S-1-5-21-1655660024-2649062184-858687661-1000..\Run: [Remote Control Editor] C:\Program Files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe (TerraTec Electronic GmbH)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutoHotkey.ahk - Verknüpfung.lnk = C:\Users\Vincent\Documents\Library\AutoHotkey.ahk ()
O4 - Startup: C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Lion.lnk = C:\Program Files (x86)\Lion\Lion.exe ()
O4 - Startup: C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SynTPEnh.exe (Synaptics Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-1655660024-2649062184-858687661-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 10.9.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0F44BEA7-67FF-46D6-A274-D71A7952D06B}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F70A030-AB0A-40A3-848F-93F0CB9B9048}: DhcpNameServer = 10.129.32.1 10.111.81.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E9B66E02-0BE1-4EBD-AA23-CCB8CBC5B727}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{8ec7cabf-2f68-11e1-83af-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{8ec7cabf-2f68-11e1-83af-806e6f6e6963}\Shell\AutoRun\command - "" = F:\tools\shelexec.exe html\index.htm
O33 - MountPoints2\{aca35bed-ee1f-11e1-9d8d-e0ca945063e8}\Shell - "" = AutoRun
O33 - MountPoints2\{aca35bed-ee1f-11e1-9d8d-e0ca945063e8}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{aca35bf4-ee1f-11e1-9d8d-e0ca945063e8}\Shell - "" = AutoRun
O33 - MountPoints2\{aca35bf4-ee1f-11e1-9d8d-e0ca945063e8}\Shell\AutoRun\command - "" = E:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/11/05 06:41:48 | 000,000,000 | ---D | C] -- C:\Users\Vincent\Desktop\avg-protokoll
[2012/11/05 06:26:28 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Roaming\AVG2012
[2012/11/04 16:55:07 | 000,000,000 | ---D | C] -- C:\FRST
[2012/11/04 15:49:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012/11/04 14:09:37 | 000,000,000 | ---D | C] -- C:\Users\Vincent\Desktop\alt
[2012/11/03 00:50:18 | 000,208,216 | ---- | C] (Kaspersky Lab, GERT) -- C:\Windows\SysNative\drivers\79859503.sys
[2012/11/01 23:36:51 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Vincent\Desktop\OTL.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012/11/07 08:04:07 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/07 07:43:00 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/07 07:33:00 | 000,001,128 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1655660024-2649062184-858687661-1000UA.job
[2012/11/07 07:33:00 | 000,001,076 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1655660024-2649062184-858687661-1000Core.job
[2012/11/07 07:31:56 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/07 07:31:56 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/07 07:31:49 | 001,612,484 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/07 07:31:49 | 000,696,870 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012/11/07 07:31:49 | 000,652,148 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/11/07 07:31:49 | 000,148,134 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012/11/07 07:31:49 | 000,121,080 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/11/07 07:27:19 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/07 07:24:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/11/07 07:24:08 | 3061,227,520 | -HS- | M] () -- C:\hiberfil.sys
[2012/11/03 01:39:57 | 000,013,833 | ---- | M] () -- C:\Users\Vincent\Desktop\fatal.JPG
[2012/11/03 00:50:47 | 000,208,216 | ---- | M] (Kaspersky Lab, GERT) -- C:\Windows\SysNative\drivers\79859503.sys
[2012/11/01 23:38:59 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Vincent\Desktop\OTL.exe
[2012/11/01 23:38:07 | 000,000,000 | ---- | M] () -- C:\Users\Vincent\defogger_reenable
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012/11/03 01:37:59 | 000,013,833 | ---- | C] () -- C:\Users\Vincent\Desktop\fatal.JPG
[2012/11/01 23:38:07 | 000,000,000 | ---- | C] () -- C:\Users\Vincent\defogger_reenable
[2012/09/16 19:53:35 | 000,010,045 | ---- | C] () -- C:\Users\Vincent\AppData\Local\recently-used.xbel
[2012/05/23 18:28:04 | 006,607,360 | ---- | C] () -- C:\Program Files\LuPO_NRW_SV.exe
[2012/03/03 20:13:33 | 000,006,656 | ---- | C] () -- C:\Users\Vincent\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/20 00:00:48 | 000,007,606 | ---- | C] () -- C:\Users\Vincent\AppData\Local\Resmon.ResmonCfg
[2012/01/07 05:55:32 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011/11/03 09:57:42 | 000,870,544 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2011/11/03 09:57:42 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2011/11/03 09:57:42 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2011/11/03 09:57:42 | 000,051,068 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2011/11/03 09:57:41 | 000,127,896 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2011/04/15 06:37:26 | 001,641,654 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2008/06/23 12:02:02 | 000,097,410 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2008/05/23 16:48:50 | 000,020,270 | ---- | C] () -- C:\ProgramData\DeviceInstaller.xml
 
========== ZeroAccess Check ==========
 
[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2012/03/20 19:52:10 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\ACD Systems
[2012/09/14 21:40:50 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Ashampoo
[2012/11/05 06:26:28 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\AVG2012
[2012/02/05 20:07:54 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\DVDVideoSoft
[2012/02/05 20:07:14 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/12/25 20:22:10 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Fujitsu
[2012/07/18 07:35:48 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\gtk-2.0
[2012/01/26 23:06:01 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\HTC
[2012/02/06 23:26:38 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Music Liberator 10.5 Release 1.1
[2012/08/24 19:46:24 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\MyPhoneExplorer
[2012/02/20 12:51:46 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Need for Speed World
[2012/04/14 15:16:08 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Opera
[2012/09/16 18:50:01 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\PanoramaStudio2
[2012/01/22 12:30:19 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Remote PC Server
[2012/01/10 21:53:16 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\SoftGrid Client
[2012/05/07 09:18:17 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Sony
[2012/01/07 07:36:25 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Synaptics
[2012/09/11 15:23:33 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Teeworlds
[2012/06/24 09:06:20 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\TerraTec
[2012/01/08 16:36:51 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Thunderbird
[2011/12/25 23:44:51 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\TP
[2012/09/10 20:20:11 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Vodafone
[2012/01/31 21:42:43 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Windows Live Writer
[2012/02/19 20:17:21 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Windows SideBar
[2012/02/07 00:14:53 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\WindSolutions
[2012/09/15 12:27:29 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\Zoner
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:DBC416F8

< End of report >

--- --- ---

ryder 07.11.2012 17:03

Nein das sieht alles gut aus. Wir machen hier mal Schluss. Wenn du wieder Probleme hast, dann mache bitte ein neues Thema auf.

Prima! :daumenhoc

Damit wären wir fertig. Wir räumen jetzt noch ein wenig auf und dann habe ich am Ende etwas Lesestoff für dich.
Hinweis: Solltest du Defogger benutzt haben, kannst du jetzt re-enable drücken.

Schritt 1:
Systemwiederherstellungspunkte löschen mit OTL
  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die http://larusso.trojaner-board.de/Images/otlfix.jpg Textbox.
    Code:

    :OTL
    @Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:DBC416F8
    :Commands
    [CLEARALLRESTOREPOINTS]

  • Schliesse bitte nun alle Programme.
  • Klicke nun bitte auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
  • Nach dem Neustart findest Du ein Textdokument auf deinem Desktop.
    ( Auch zu finden unter C:\_OTL\MovedFiles\<time_date>.txt)
  • Kopiere nun den Inhalt hier in Deinen Thread.
Schritt 2:
Toolbereinigung mit OTL
  • Starte bitte OTL und klicke auf Bereinigung.
  • Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben.
  • Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.
Schritt 3:
AdwCleaner entfernen
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Uninstall.
  • Bestätige mit Ja.
Schritt 4:
ESET deinstallieren (Optional)

Ich empfehle dir dein System einmal pro Woche mit ESET zu scannen. Möchtest du ESET aber entfernen:
Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und kopiere folgenden Text in das Ausführen-Fenster und klicke OK.
Code:

"%ProgramFiles%\Eset\Eset Online Scanner\OnlineScannerUninstaller.exe"
Abschließend noch Tipps zu folgenden Themen:
  • Systemupdates
  • Softwareupdates
  • Sicherheitssoftware
  • Sicheres Surfen

Zitat:

Lesestoff:
Systemupdates
Man kann es gar nicht oft genug erwähnen, wie wichtig es ist, sein System aktuell zu halten. Dein Auto bringst du ja auch regelmässig zur Inspektion in die Werkstatt. Stelle also bitte sicher, dass die Systemupdates aktiviert sind:
  • Bitte überprüfe, ob dein System Windows Updates automatisch herunter lädt:
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.


Zitat:

Lesestoff:
Softwareupdates
Ebenso wichtig wie die Systemprogramme ist auch die Software, die du täglich nutzt. Die folgende Liste gibt dir einen kleinen Überblick mit Links zu den Updates, welche Programme dringend aktuell gehalten werden müssen (falls du sie überhaupt installiert hast und nutzt), weil durch deren Sicherheitslücken oft Malware auf die Computer gelangen kann:Auch nicht gelistete Programme sind natürlich wichtig. Ob es für diese eine neue Version gibt, kannst du auf deren Herstellerwebseite oder ganz bequem mit diesen Tools überprüfen:

Zitat:

Lesestoff:
Sicherheitssoftware
Würde dich jemand nackt auf dem Motorrad auf der Autobahn überholen würdest du auch den Kopf schütteln. Dein Computer braucht auch einen Schutz vor den täglichen kleinen Angriffen durch Schädlinge. Neben hervorragenden kommerziellen Anti-Viren-Lösungen gibt es auch durchaus gute Schutzprogramme, die kostenfrei mit reduziertem Funktionsumfang erhältlich sind. Aber vorsicht, hier gilt nicht "je mehr desto besser". Was du brauchst ist genau einen Virenscanner mit Hintergrundwächter. Nicht mehr und nicht weniger. Es gibt hier viele Produkte auf dem Markt, die einem gute Dienste leisten. Ich persönlich empfehle dir Avast Free Antivirus. Es bietet relativ guten Schutz, bei wenig nerviger Werbung und installiert dir ein Browserplugin, das dich vor gefährlichen Webseiten warnt.
  • Wenn du deine Antivirenlösung wechseln solltest, findest du hier Tools mit denen du die Überreste nach der Deinstallation deines alten Scanners entfernen kannst.
  • Installiere niemals mehr als einen Virenscanner. Deren Hintergrundwächter würden sich gegenseitig behindern und dein System ausbremsen.
  • Ein Browserplugin, das dich vor betrügerischen Webseiten schützt, kann dir gute Dienste leisten, wenn du dich nicht gut auskennst (siehe oben).
  • Sorge dafür, dass deine Sicherheitslösung ständig up-to-date ist und sich automatisch Updates besorgt. Wenn du auf manuelle Updates setzt bist du meistens zu spät, da die Virendatenbanken oft täglich sogar mehrfach erneuert werden.
  • Einen zusätzlichen Schutz (und dieser wäre auch erlaubt) bietet ein spezieller Malwarescanner. Hier empfehle ich dir dringend Malwarebytes und einmal wöchentlich damit zu scannen. In der kostenpflichtigen Version hat es sogar einen Hintergrundwächter. Hierfür haben wir eine Anleitung für dich.
Zuletzt empfehle ich dir deine Daten regelmässig (am besten automatisch) zu sichern. Dies kann eine professionelle Backuplösung, externe Festplatten, Brennen auf DVDs oder Überspielen auf ein Online-Laufwerk wie z.B. Dropbox sein. Erzeuge so viele Kopien wie möglich und halte sie aktuell. Nur so bist du auf den schlimmsten Fall vorbereitet, wenn dein Computer - wodurch auch immer - unbrauchbar werden sollte. Leider passiert das ja immer unangekündigt und immer dann wenn man ihn am Nötigsten braucht. Also sorge vor! :)

Zitat:

Lesestoff:
Sicheres Surfen
Zunächst muss man sagen, dass es üblicherweise immer der menschliche Faktor ist, der es Malware ermöglicht auf einen Computer zu gelangen. Kaufst du Leuten, die an deiner Haustür klingeln, auch sofort ohne nachzudenken irgendwelches Zeug ab? Gewöhne dir daher zunächst einige Verhaltensregeln beim Surfen im Internet an:
  • Klicke nicht irgendwo hin, nur weil es bunt ist und leuchtet, in einer Ecke aufpoppt oder so aussieht, als wäre es eine Systemmeldung.
  • Lade dir keine illegale Software, keine Cracks, keine Keygens, keine Gametrainer usw ... die Webseiten, die so etwas anbieten, sind meist nicht seriös und die angeblichen Helfer sind meist verseuchter als du es dir ausmalen würdest. Es spielt dabei keine Rolle, ob du diese Dateien über einen Browser oder Filesharingprogramme beziehst.
  • Öffne keine Emailanhänge von Leuten, die du nicht kennst, Emails mit seltsamen Rechtschreibfehlern oder starte Dateien, die dir eine Webseite anbietet, ohne dass du sie wolltest.
  • Lasse niemand an deinem Computer surfen, der diese Regeln nicht auch befolgt.
  • Verlasse dich nicht darauf, dass dein Virenscanner schon alles findet. Keine Sicherheitslösung ist 100% sicher!

Aber selbst bei der peinlichen Einhaltung dieser Regeln kann es dennoch zu einer sogenannten Drive-By-Infektion kommen, bei der ein Schädling aus dem Schutzmechanismus des Webbrowsers ausbricht. Um die Sicherheit noch weiter zu erhöhen gibt es spezielle Schutzsoftware, die deinen Browser noch weiter absichert.
  • WOT (Web of trust) Dieses Add-On warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst. Hinweis: Avast enthält ein solches Plugin bereits.
  • Sandboxie schafft eine zusätzliche isolierte Programmumgebung, damit dein Browser wie ein Kleinkind im Sandkasten sicher ist. (Anleitung: Sandboxie)
  • Securebanking ist ein Software, die Verbindungen untersucht und dir meldet, wenn jemand "mithört". Wie der Name sagt, wurde es entwickelt, damit Onlinebanking wirklich sicher ist. Mehr Infos auf der Homepage: Secure Banking

Zuletzt denke bitte über die Benutzung eines alternativen Browsers nach. Programme, die nicht so oft verwendet werden, sind auch nicht so sehr im Focus der "bösen Jungs". D.h. du bist mit einem exotischen Browser eher auf der sicheren Seite. Grundsätzlich bist du erst einmal deutlich sicherer, wenn du nicht den Internet Explorer benutzt.

Damit wünsche ich dir noch viel Spaß beim Surfen im Internet :daumenhoc

... und vielleicht möchtest du ja das Trojaner-Board unterstützen?

Eine Bitte: Gib mir eine kurze Rückmeldung, wenn alles erledigt ist und keine Fragen mehr vorhanden sind, damit ich diesen Thread aus meinen Abos löschen kann.

VHSK 07.11.2012 18:32

aber er ist doch noch gar nicht wieder normal..
jedenfalls zb firefox hat probleme mit mehreren tabs und videos.

ryder 07.11.2012 18:38

Was Malware angeht, sehe ich zumindest nichts mehr, was da Probleme machen könnte. Beschreib bitte die Probleme die du noch hast.

VHSK 07.11.2012 19:43

Microsoft Office funktioniert nicht (kann nicht gestartet werden).
Computer allgemein langsam.
Firefox hängt sich ungefähr jede Minute ein mal auf.
Z. T. merkwürdige Geräusche bei Musikwiedergabe.

ryder 07.11.2012 19:49

Wir können noch einen Scan machen um auszuschliessen, dass es sich um einen Schädling handelt und dann würde ich dich zu den Kollegen von der Hard- und Software überweisen :)

Scan mit Combofix
Zitat:

WARNUNG:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!
Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).

Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

VHSK 07.11.2012 21:54

Code:

ComboFix 12-11-06.03 - Vincent 07.11.2012  20:28:08.1.4 - x64
Microsoft Windows 7 Professional  6.1.7601.1.1252.49.1031.18.3893.1858 [GMT 1:00]
ausgeführt von:: c:\users\Vincent\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-10-07 bis 2012-11-07  ))))))))))))))))))))))))))))))
.
.
2012-11-07 19:47 . 2012-11-07 19:47        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-11-07 19:01 . 2012-10-12 07:19        9291768        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{45FA7450-3BE5-4F5F-B4A8-A3BE3851CE63}\mpengine.dll
2012-11-07 15:49 . 2012-10-12 07:19        9291768        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-06 16:12 . 2012-08-24 18:03        1448448        ----a-w-        c:\windows\system32\lsasrv.dll
2012-11-06 16:12 . 2012-08-24 16:57        22016        ----a-w-        c:\windows\SysWow64\secur32.dll
2012-11-06 16:12 . 2012-08-24 16:53        96768        ----a-w-        c:\windows\SysWow64\sspicli.dll
2012-11-05 05:26 . 2012-11-05 05:26        --------        d-----w-        c:\users\Vincent\AppData\Roaming\AVG2012
2012-11-04 15:55 . 2012-11-04 15:55        --------        d-----w-        C:\FRST
2012-11-04 14:49 . 2012-11-04 14:49        --------        d-----w-        c:\program files (x86)\Common Files\Java
2012-11-04 14:47 . 2012-11-04 14:47        95208        ----a-w-        c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-03 16:01 . 2012-09-06 21:35        770384        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\msvcr100.dll
2012-11-03 16:01 . 2012-09-06 21:35        421200        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\msvcp100.dll
2012-11-03 16:00 . 2012-11-03 16:02        816608        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\mozsqlite3.dll
2012-11-03 16:00 . 2012-11-03 16:02        2295264        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\mozjs.dll
2012-11-03 16:00 . 2012-11-03 16:02        124384        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\mozglue.dll
2012-11-03 16:00 . 2012-11-03 16:02        15840        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\mozalloc.dll
2012-11-03 16:00 . 2012-11-03 16:02        192600        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\maintenanceservice_installer.exe
2012-11-03 15:59 . 2012-11-03 16:02        115168        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\maintenanceservice.exe
2012-11-03 15:59 . 2012-11-03 16:02        416224        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\libGLESv2.dll
2012-11-03 15:59 . 2012-11-03 16:02        80864        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\libEGL.dll
2012-11-03 15:58 . 2012-11-03 16:02        2560480        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\gkmedias.dll
2012-11-03 15:58 . 2012-11-03 16:02        258528        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\freebl3.dll
2012-11-03 15:58 . 2012-11-03 16:02        917984        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\firefox.exe
2012-11-03 15:55 . 2012-09-06 21:35        1998168        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\d3dx9_43.dll
2012-11-03 15:55 . 2012-09-06 21:35        2106216        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\D3DCompiler_43.dll
2012-11-03 15:55 . 2012-11-03 16:02        116192        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\crashreporter.exe
2012-11-03 15:55 . 2012-11-03 16:02        261600        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\components\browsercomps.dll
2012-11-03 15:54 . 2012-11-03 16:02        73696        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\breakpadinjector.dll
2012-11-03 15:54 . 2012-11-03 16:02        18912        ----a-w-        c:\program files (x86)\Mozilla Firefox\updated\AccessibleMarshal.dll
2012-11-02 23:50 . 2012-11-02 23:50        208216        ----a-w-        c:\windows\system32\drivers\79859503.sys
2012-11-01 14:57 . 2012-10-03 15:10        972192        ------w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{956EE1EA-9CD4-466F-8C1B-59E41AEA4404}\gapaengine.dll
2012-10-14 17:13 . 2012-06-02 05:41        1464320        ----a-w-        c:\windows\system32\crypt32.dll
2012-10-14 17:13 . 2012-06-02 04:36        1159680        ----a-w-        c:\windows\SysWow64\crypt32.dll
2012-10-14 17:13 . 2012-06-02 05:41        184320        ----a-w-        c:\windows\system32\cryptsvc.dll
2012-10-14 17:13 . 2012-06-02 05:41        140288        ----a-w-        c:\windows\system32\cryptnet.dll
2012-10-14 17:13 . 2012-06-02 04:36        140288        ----a-w-        c:\windows\SysWow64\cryptsvc.dll
2012-10-14 17:13 . 2012-06-02 04:36        103936        ----a-w-        c:\windows\SysWow64\cryptnet.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-04 14:47 . 2012-07-19 21:20        821736        ----a-w-        c:\windows\SysWow64\npdeployJava1.dll
2012-11-04 14:47 . 2012-01-22 11:27        746984        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2012-10-15 17:03 . 2011-12-26 18:41        65309168        ----a-w-        c:\windows\system32\MRT.exe
2012-10-14 12:24 . 2012-04-19 20:51        696760        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-14 12:24 . 2011-12-25 21:09        73656        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-03 15:10 . 2012-10-02 22:55        972192        ------w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-08-30 20:03 . 2012-08-30 20:03        228768        ----a-w-        c:\windows\system32\drivers\MpFilter.sys
2012-08-30 20:03 . 2012-03-20 18:44        128456        ----a-w-        c:\windows\system32\drivers\NisDrvWFP.sys
2012-08-24 11:15 . 2012-09-22 09:08        17810944        ----a-w-        c:\windows\system32\mshtml.dll
2012-08-24 10:39 . 2012-09-22 09:08        10925568        ----a-w-        c:\windows\system32\ieframe.dll
2012-08-24 10:31 . 2012-09-22 09:09        2312704        ----a-w-        c:\windows\system32\jscript9.dll
2012-08-24 10:22 . 2012-09-22 09:09        1346048        ----a-w-        c:\windows\system32\urlmon.dll
2012-08-24 10:21 . 2012-09-22 09:09        1392128        ----a-w-        c:\windows\system32\wininet.dll
2012-08-24 10:20 . 2012-09-22 09:09        1494528        ----a-w-        c:\windows\system32\inetcpl.cpl
2012-08-24 10:18 . 2012-09-22 09:09        237056        ----a-w-        c:\windows\system32\url.dll
2012-08-24 10:17 . 2012-09-22 09:08        85504        ----a-w-        c:\windows\system32\jsproxy.dll
2012-08-24 10:14 . 2012-09-22 09:09        173056        ----a-w-        c:\windows\system32\ieUnatt.exe
2012-08-24 10:14 . 2012-09-22 09:08        816640        ----a-w-        c:\windows\system32\jscript.dll
2012-08-24 10:13 . 2012-09-22 09:08        599040        ----a-w-        c:\windows\system32\vbscript.dll
2012-08-24 10:12 . 2012-09-22 09:08        2144768        ----a-w-        c:\windows\system32\iertutil.dll
2012-08-24 10:11 . 2012-09-22 09:09        729088        ----a-w-        c:\windows\system32\msfeeds.dll
2012-08-24 10:10 . 2012-09-22 09:09        96768        ----a-w-        c:\windows\system32\mshtmled.dll
2012-08-24 10:09 . 2012-09-22 09:09        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2012-08-24 10:04 . 2012-09-22 09:09        248320        ----a-w-        c:\windows\system32\ieui.dll
2012-08-24 06:59 . 2012-09-22 09:08        1800704        ----a-w-        c:\windows\SysWow64\jscript9.dll
2012-08-24 06:51 . 2012-09-22 09:09        1129472        ----a-w-        c:\windows\SysWow64\wininet.dll
2012-08-24 06:51 . 2012-09-22 09:09        1427968        ----a-w-        c:\windows\SysWow64\inetcpl.cpl
2012-08-24 06:47 . 2012-09-22 09:09        142848        ----a-w-        c:\windows\SysWow64\ieUnatt.exe
2012-08-24 06:47 . 2012-09-22 09:09        420864        ----a-w-        c:\windows\SysWow64\vbscript.dll
2012-08-24 06:43 . 2012-09-22 09:09        2382848        ----a-w-        c:\windows\SysWow64\mshtml.tlb
2012-08-22 18:12 . 2012-09-12 09:21        1913200        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2012-08-22 18:12 . 2012-09-12 09:21        950128        ----a-w-        c:\windows\system32\drivers\ndis.sys
2012-08-22 18:12 . 2012-09-12 09:21        376688        ----a-w-        c:\windows\system32\drivers\netio.sys
2012-08-22 18:12 . 2012-09-12 09:21        288624        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2012-08-21 21:01 . 2012-09-25 18:58        245760        ----a-w-        c:\windows\system32\OxpsConverter.exe
2012-08-21 11:01 . 2012-09-15 20:09        33240        ----a-w-        c:\windows\system32\drivers\GEARAspiWDM.sys
2012-08-21 11:01 . 2011-12-26 00:31        125872        ----a-w-        c:\windows\system32\GEARAspi64.dll
2012-08-21 11:01 . 2011-12-26 00:31        106928        ----a-w-        c:\windows\SysWow64\GEARAspi.dll
2012-08-20 17:38 . 2012-10-14 17:14        44032        ----a-w-        c:\windows\apppatch\acwow64.dll
2012-05-23 17:28 . 2012-05-23 17:28        6607360        ----a-w-        c:\program files\LuPO_NRW_SV.exe
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"Remote Control Editor"="c:\program files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe" [2011-11-24 1837568]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"LoadFUJ02E3"="c:\program files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe" [2009-10-08 36712]
"IndicatorUtility"="c:\program files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2009-10-09 47976]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"DeskUpdateNotifier"="c:\program files (x86)\Fujitsu\DeskUpdate\DeskUpdateNotifier.exe" [2012-07-25 101288]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
AutoHotkey.ahk - Verknüpfung.lnk - c:\users\Vincent\Documents\Library\AutoHotkey.ahk [2012-1-23 1811]
Lion.lnk - c:\program files (x86)\Lion\Lion.exe [2012-1-11 235579]
SynTPEnh.exe [2011-3-31 2735400]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944]
R3 AbilisT;EyeTV DTT Deluxe (2009) Service;c:\windows\system32\DRIVERS\AbilisBdaTuner.sys [2010-04-12 131144]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-11-02 33736]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-25 36928]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2011-08-02 22528]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-30 128456]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-12 368896]
R3 PFNService;PFNService;c:\program files\Fujitsu\Plugfree NETWORK\PFNService.exe [2010-06-23 330240]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 RRNetCap;RRNetCap Service;c:\windows\system32\DRIVERS\rrnetcap.sys [2012-01-03 37480]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-30 1255736]
R4 ABBYY.Licensing.FineReader.ScreenshotReader.9.0;ABBYY.Licensing.FineReader.ScreenshotReader.9.0;c:\program files (x86)\ABBYY Screenshot Reader\NetworkLicenseServer.exe [2008-10-16 759072]
R4 EyeTV Netstream;EyeTV Netstream;c:\program files (x86)\Elgato\EyeTV Netstream\EyeTVNetstreamSvc.exe [2010-09-13 399944]
R4 ScrybeUpdater;Scrybe-Updateprogramm;c:\program files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe [2011-05-27 1300264]
R4 VMCService;Vodafone Mobile Connect Service;c:\program files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [2008-07-04 14336]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2011-09-15 88576]
S2 PowerSavingUtilityService;PowerSavingUtilityService;c:\program files\Fujitsu\PSUtility\PSUService.exe [2009-07-30 63336]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-01 2314240]
S2 VFPRadioSupportService;Unterstützung für Bluetooth-Funktionen;c:\program files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe [2009-12-24 145840]
S3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;c:\windows\system32\DRIVERS\FUJ02E3.sys [2006-11-01 7296]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-11-01 56344]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2009-10-26 151936]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2009-11-27 244736]
S3 RRNetCapMP;RRNetCapMP;c:\windows\system32\DRIVERS\rrnetcap.sys [2012-01-03 37480]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
.
.
Inhalt des "geplante Tasks" Ordners
.
2012-11-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-19 12:24]
.
2012-11-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-17 16:32]
.
2012-11-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-17 16:32]
.
2012-11-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1655660024-2649062184-858687661-1000Core.job
- c:\users\Vincent\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-12 06:12]
.
2012-11-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1655660024-2649062184-858687661-1000UA.job
- c:\users\Vincent\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-12 06:12]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-01-12 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-01-12 390680]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-01-12 410136]
"PSUTility"="c:\program files\Fujitsu\PSUtility\TrayManager.exe" [2009-07-30 188264]
"FDM7"="c:\program files\Fujitsu\FDM7\FdmDaemon.exe" [2009-11-26 164712]
"LoadFujitsuQuickTouch"="c:\program files\Fujitsu\Application Panel\QuickTouch.exe" [2009-10-15 157544]
"LoadBtnHnd"="c:\program files\Fujitsu\Application Panel\BtnHnd.exe" [2009-10-15 35176]
"ConMgr"="c:\program files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe" [2009-12-24 535440]
"CSRSkype"="c:\program files\CSR\Bluetooth Feature Pack 5.0\CSRSkype.exe" [2009-12-24 431504]
"CSRFTP"="c:\program files\CSR\Bluetooth Feature Pack 5.0\CSRBthFtpServer.exe" [2009-12-24 463264]
"CSRBIP"="c:\program files\CSR\Bluetooth Feature Pack 5.0\CSRBipPushResponder.exe" [2009-12-24 419752]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-28 8312352]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 1289704]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=FTSG&bmod=FTSG
uInternet Settings,ProxyOverride = *.local
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Vincent\AppData\Roaming\Mozilla\Firefox\Profiles\9u0eqmus.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - ExtSQL: 2012-09-12 23:52; {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}; c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-ABBYY Screenshot Reader Retail - (no file)
Toolbar-Locked - (no file)
HKLM-Run-BthSyncServ - c:\program files\CSR\Bluetooth Feature Pack 5.0\bthsyncserv.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP\UserChoice]
@Denied: (2) (S-1-5-21-1655660024-2649062184-858687661-1000)
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.bmp.15.4"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DIB\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.bmp.15.4"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (S-1-5-21-1655660024-2649062184-858687661-1000)
@Denied: (2) (LocalSystem)
"Progid"="ThunderbirdEML"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ICO\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.ico.15.4"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JFIF\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.jpg.15.4"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPE\UserChoice]
@Denied: (2) (S-1-5-21-1655660024-2649062184-858687661-1000)
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.jpg.15.4"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPEG\UserChoice]
@Denied: (2) (S-1-5-21-1655660024-2649062184-858687661-1000)
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.jpg.15.4"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPG\UserChoice]
@Denied: (2) (S-1-5-21-1655660024-2649062184-858687661-1000)
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.jpg.15.4"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.PNG\UserChoice]
@Denied: (2) (S-1-5-21-1655660024-2649062184-858687661-1000)
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.png.15.4"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TIF\UserChoice]
@Denied: (2) (S-1-5-21-1655660024-2649062184-858687661-1000)
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.tif.15.4"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TIFF\UserChoice]
@Denied: (2) (S-1-5-21-1655660024-2649062184-858687661-1000)
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.tif.15.4"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v14o\UserChoice]
@Denied: (2) (S-1-5-21-1655660024-2649062184-858687661-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.v14o"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v14p\UserChoice]
@Denied: (2) (S-1-5-21-1655660024-2649062184-858687661-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.v14p"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v14pf\UserChoice]
@Denied: (2) (S-1-5-21-1655660024-2649062184-858687661-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.v14pf"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WDP\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLive.PhotoGallery.wdp.15.4"
.
[HKEY_USERS\S-1-5-21-1655660024-2649062184-858687661-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (S-1-5-21-1655660024-2649062184-858687661-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 14.xmp"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-11-07  21:47:26
ComboFix-quarantined-files.txt  2012-11-07 20:47
.
Vor Suchlauf: 12 Verzeichnis(se), 254.070.628.352 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 254.977.937.408 Bytes frei
.
- - End Of File - - BF147D9A601DB606EB1F624E7A2E127C


ryder 07.11.2012 22:08

Nix.

Also wir haben jetzt Malwaremässig alles untersucht. Daran liegt es meiner Meinung nicht. Du solltest Combofix jetzt deinstallieren und dann einen Thread in der "Rund um Windows"-Ecke aufmachen, damit man dir dort weiter helfen kann.

Combofix deinstallieren
  • Bitte vor der folgenden Aktion wieder temporär Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren.
  • Drücke die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und kopiere den folgenden Text Ausführen-Fenster und klicke OK.
    Combofix /Uninstall
  • Aktiviere die zuvor deaktivierten Programme wieder.

ryder 09.11.2012 10:59

Dieses Thema scheint beendet und wurde aus meinen Abos gelöscht.

VHSK 10.11.2012 10:20

Haben wir denn nun irgendwas geändert, außer avg deinstalliert?

VHSK 11.11.2012 20:39

zu schritt 1 von #39:

Code:

========== OTL ==========
ADS C:\ProgramData\Temp:DBC416F8 deleted successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point
 
OTL by OldTimer - Version 3.2.69.0 log created on 11112012_203232

#39:
Schritt 2: zb was?
schritt 4: nicht mgl, existiert nicht...


Alle Zeitangaben in WEZ +1. Es ist jetzt 12:53 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131