Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Malware: Citadel (https://www.trojaner-board.de/134730-malware-citadel.html)

rico89 10.05.2013 01:43

Malware: Citadel
 
Hallo,
Ich habe kürzlich von dem Programm „Secure Banking“ einen Hinweis bekommen, dass eine Malware gefunden wurde. Siehe Ereignisse!


========================================
[10.05.2013 - 00:24:02] Malware gefunden!
----------------------------------------
Malware: Citadel
----------------------------------------
Infizierter Prozess: iexplore.exe
----------------------------------------
Infizierte Funktionen:
HttpSendRequestW: RET 0x00070662
HttpSendRequestA: RET 0x000706B7
InternetReadFile: RET 0x00070949
InternetQueryDataAvailable: RET 0x00070A50
========================================
Unter Status steht, dass fünf Bedrohungen erkannt wurden!
Ich hatte auch vor einer Woche ein Flugticket gebucht und ein paar Daten bezüglich meines Kontos angegeben, aber kein direktes online Banking gemacht. Sollte ich da jetzt auch drauf reagieren?

cosinus 10.05.2013 01:57

Hallo und :hallo:

Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die jemals fündig geworden?
Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs posten!

Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

rico89 10.05.2013 12:02

Ja okay, hab auch gestern mal mit einem kostenlosen Programm "spy Hunter" mein Rechner durchchecken lassen und und es wurden 255 infizierte Daten gefunden, dass ist schon echt hart gewesen als ich das gesehen habe. Egal ein Schritt nacheinander ich stell jetzt erstmal
ein Logfile von MBAM rein.

Code:

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org


Datenbank Version: v2012.09.29.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Ali :: ALI-PC [Administrator]

10.05.2013 12:50:08
mbam-log-2013-05-10 (12-50-08).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 206989
Laufzeit: 2 Minute(n), 19 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 10.05.2013 19:23

Finger weg von Spyhunter! Das ist ein Fakescanner!

Gab es jemals Funde mit anderen Scannern wie Malwarebytes oder zB AnitVir?

rico89 10.05.2013 19:32

Achso okay dann lösche ich dieses Programm!
Ja davor hatte ich mal diesen Trojaner Zeus/ZBot aber den konnten ich damals durch Hilfe von trojaner-board entfernen.

cosinus 10.05.2013 19:48

Bevor wir uns an die Arbeit machen, möchte ich dich bitten, folgende Punkte vollständig und aufmerksam zu lesen.
  • Lies dir meine Anleitungen, die ich im Laufe dieses Strangs hier posten werde, aufmerksam durch. Frag umgehend nach, wenn dir irgendetwas unklar sein sollte, bevor du anfängst meine Anleitungen umzusetzen.

  • Solltest du bei einem Schritt Probleme haben, stoppe dort und beschreib mir das Problem so gut du kannst. Manchmal erfordert ein Schritt den vorhergehenden.

  • Bitte nur Scans durchführen zu denen du von einem Helfer aufgefordert wurdest! Installiere / Deinstalliere keine Software ohne Aufforderung!

  • Poste die Logfiles direkt in deinen Thread (bitte in CODE-Tags) und nicht als Anhang, ausser du wurdest dazu aufgefordert. Logs in Anhängen erschweren mir das Auswerten!

  • Die Logs der aufgegebenen Tools wie zB Malwarebytes sind immer zu posten - egal ob ein Fund dabei war oder nicht!

  • Beachte bitte auch => Löschen von Logfiles und andere Anfragen

Note:
Sollte ich drei Tage nichts von mir hören lassen, so melde dich bitte in diesem Strang => Erinnerung an meinem Thread.
Nervige "Wann geht es weiter" Nachrichten enden mit Schließung deines Themas. Auch ich habe ein Leben abseits des Trojaner-Boards.


Erstmal eine Kontrolle mit OTL bitte:
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in CODE-Tags in den Thread.

rico89 10.05.2013 20:04

Logfile 1
OTL Logfile:
Code:

OTL logfile created on: 10.05.2013 20:54:22 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Ali\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,48 Gb Total Physical Memory | 2,01 Gb Available Physical Memory | 57,74% Memory free
6,95 Gb Paging File | 4,94 Gb Available in Paging File | 70,98% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 880,41 Gb Total Space | 814,98 Gb Free Space | 92,57% Space Free | Partition Type: NTFS
Drive D: | 50,00 Gb Total Space | 27,01 Gb Free Space | 54,03% Space Free | Partition Type: NTFS
Drive E: | 7,05 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive I: | 298,01 Gb Total Space | 174,39 Gb Free Space | 58,52% Space Free | Partition Type: FAT32
 
Computer Name: ALI-PC | User Name: Ali | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Ali\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
PRC - C:\Users\Ali\AppData\Roaming\Ywiha\neick.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Secure Banking\SecureBanking.exe (Secure Banking)
PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe (CyberLink)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe (CyberLink)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe (CyberLink)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ffmpegsumo.dll ()
MOD - C:\Users\Ali\AppData\Roaming\Ywiha\neick.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Flexera Software, Inc.)
SRV:64bit: - (CoordinatorServiceHost) -- C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe (Dassault Systèmes SolidWorks Corp.)
SRV:64bit: - (Remote Solver for Flow Simulation 2012) -- C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe (Mentor Graphics Corporation)
SRV:64bit: - (AMD FUEL Service) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software, Inc.)
SRV - (SolidWorks Licensing Service) -- C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (watchmi) -- C:\Program Files (x86)\watchmi\TvdService.exe ()
SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (MemeoBackgroundService) -- C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe (Memeo)
SRV - (vpnagent) -- C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (CyberLink PowerDVD 10 MS Service) -- C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe (CyberLink)
SRV - (CyberLink PowerDVD 10 MS Monitor Service) -- C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe (CyberLink)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (esgiguard) -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys File not found
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (usbfilter) -- C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (amd_sata) -- C:\Windows\SysNative\drivers\amd_sata.sys (Advanced Micro Devices)
DRV:64bit: - (amd_xata) -- C:\Windows\SysNative\drivers\amd_xata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxhc) -- C:\Windows\SysNative\drivers\amdxhc.sys (Advanced Micro Devices, INC.)
DRV:64bit: - (amdhub30) -- C:\Windows\SysNative\drivers\amdhub30.sys (Advanced Micro Devices, INC.)
DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (vpnva) -- C:\Windows\SysNative\drivers\vpnva64.sys (Cisco Systems, Inc.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (RTL8192su) -- C:\Windows\SysNative\drivers\RTL8192su.sys (Realtek Semiconductor Corporation                          )
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (wsvd) -- C:\Windows\SysNative\drivers\wsvd.sys (CyberLink)
DRV:64bit: - (amdiox64) -- C:\Windows\SysNative\drivers\amdiox64.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (BrSerIb) -- C:\Windows\SysNative\drivers\BrSerIb.sys (Brother Industries Ltd.)
DRV:64bit: - (BrUsbSIb) -- C:\Windows\SysNative\drivers\BrUsbSIb.sys (Brother Industries Ltd.)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-732902274-989681646-235948354-1002\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-732902274-989681646-235948354-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/
IE - HKU\S-1-5-21-732902274-989681646-235948354-1002\..\SearchScopes,DefaultScope = {2EE7A148-AF2C-4C37-8D9A-FA99F8A50C86}
IE - HKU\S-1-5-21-732902274-989681646-235948354-1002\..\SearchScopes\{2EE7A148-AF2C-4C37-8D9A-FA99F8A50C86}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MDNE_enDE393DE497
IE - HKU\S-1-5-21-732902274-989681646-235948354-1002\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-732902274-989681646-235948354-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Ali\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 
 
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U10 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Ali\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll
CHR - plugin: Java Deployment Toolkit 7.0.100.18 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\Ali\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Ali\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Ali\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\Ali\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Mail = C:\Users\Ali\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2012.12.23 15:46:18 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll File not found
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKU\S-1-5-21-732902274-989681646-235948354-1002\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-732902274-989681646-235948354-1002\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKU\S-1-5-21-732902274-989681646-235948354-1002\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O4:64bit: - HKLM..\Run: [MedionReminder] C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe (CyberLink)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-732902274-989681646-235948354-1002..\Run: [Facebook Update] C:\Users\Ali\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-732902274-989681646-235948354-1002..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O4 - HKU\S-1-5-21-732902274-989681646-235948354-1002..\Run: [SecureBanking] C:\Program Files (x86)\Secure Banking\SecureBanking.exe (Secure Banking)
O4 - HKU\S-1-5-21-732902274-989681646-235948354-1002..\Run: [Suuse] C:\Users\Ali\AppData\Roaming\Ywiha\neick.exe ()
O4:64bit: - HKLM..\RunOnce: [MedionReminder] C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe (CyberLink)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-732902274-989681646-235948354-1002\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-732902274-989681646-235948354-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:64bit: - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O9:64bit: - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{72B8E66E-4DBE-4DD5-A9B2-435B47A7B3E9}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8AAD6D8A-0CD9-4833-8080-E9547C00E9E4}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013.05.10 01:30:45 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010.05.25 06:16:57 | 000,000,046 | -H-- | M] () - E:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.05.10 20:36:56 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013.05.10 13:06:27 | 000,000,000 | ---D | C] -- C:\Users\Ali\Desktop\Neuer Ordner (2)
[2013.05.10 12:49:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.05.10 12:49:08 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.05.10 12:49:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.05.10 01:30:31 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2013.05.10 01:29:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2013.05.09 20:52:53 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\Ywiha
[2013.05.09 20:52:53 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\Ykma
[2013.05.09 20:52:53 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\Idmol
[2013.05.09 14:38:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
[2013.05.09 12:39:43 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\{FF286E22-4084-431F-99A0-C79951C819B6}
[2013.05.08 19:15:34 | 000,000,000 | ---D | C] -- C:\Users\Ali\Desktop\Zeichnungen
[2013.05.08 19:07:27 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\TempSWBackupDirectory
[2013.05.08 19:06:17 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\SolidWorks
[2013.05.08 19:04:59 | 000,000,000 | ---D | C] -- C:\ProgramData\SolidWorks Flow Simulation
[2013.05.08 19:04:29 | 000,000,000 | ---D | C] -- C:\Users\Ali\Documents\SolidWorks Visual Studio Tools for Applications
[2013.05.08 19:01:20 | 000,000,000 | ---D | C] -- C:\Program Files\SolidWorks Corp
[2013.05.08 19:01:20 | 000,000,000 | ---D | C] -- C:\ProgramData\SolidWorks
[2013.05.08 19:01:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2013.05.08 19:01:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Macrovision Shared
[2013.05.08 19:00:42 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2013.05.08 19:00:31 | 000,000,000 | ---D | C] -- C:\Users\Ali\Documents\Visual Studio 2005
[2013.05.08 19:00:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005
[2013.05.08 19:00:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2013.05.08 18:59:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache
[2013.05.08 18:59:32 | 000,000,000 | ---D | C] -- C:\SolidWorks Data
[2013.05.08 18:48:42 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\help_images_otherUI
[2013.05.08 10:11:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2013.05.07 21:46:58 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\DassaultSystemes
[2013.05.07 21:46:58 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\DassaultSystemes
[2013.05.07 21:46:58 | 000,000,000 | ---D | C] -- C:\ProgramData\DassaultSystemes
[2013.05.07 21:46:29 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\EDrawings
[2013.05.07 21:44:31 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2013.05.07 21:43:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared
[2013.05.07 21:42:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SolidWorks Shared
[2013.05.07 21:42:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SolidWorks Shared
[2013.05.07 21:42:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SolidWorks Corp
[2013.05.07 21:42:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2012
[2013.05.07 21:29:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks Installations-Manager
[2013.05.07 21:29:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SolidWorks Installations-Manager
[2013.05.07 21:27:16 | 000,000,000 | ---D | C] -- C:\Users\Ali\Documents\SolidWorks Downloads
[2013.05.07 21:27:16 | 000,000,000 | ---D | C] -- C:\Windows\SolidWorks
[2013.05.07 21:27:15 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\SolidWorks
[2013.05.07 15:48:38 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\Apple Computer
[2013.05.07 15:48:38 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\Apple Computer
[2013.05.07 15:48:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013.05.07 15:48:19 | 000,033,240 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2013.05.07 15:48:11 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013.05.07 15:48:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2013.05.07 15:48:11 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013.05.07 15:48:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2013.05.07 15:48:11 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013.05.07 15:47:21 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\Apple
[2013.05.07 15:47:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2013.05.07 15:47:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2013.05.07 15:47:03 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2013.05.07 15:47:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2013.05.07 15:47:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2013.05.07 15:47:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2013.05.07 14:54:57 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\redsn0w
[2013.05.07 13:36:07 | 000,000,000 | ---D | C] -- C:\Users\Ali\Desktop\ipod jailbreak
[2013.05.06 17:57:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure Banking
[2013.05.06 17:57:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Secure Banking
[2013.05.06 11:11:38 | 000,083,160 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avnetflt.sys
[2013.05.05 12:30:45 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\PDF24
[2013.05.05 12:27:37 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\Cisco
[2013.05.05 12:26:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco
[2013.05.05 12:26:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Cisco
[2013.05.05 12:26:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cisco
[2013.05.03 17:25:58 | 000,000,000 | ---D | C] -- C:\Users\Ali\Desktop\Alis Daten
[2013.05.03 16:53:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
[2013.05.03 16:53:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PDF24
[2013.05.03 16:52:48 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\Programs
[2013.05.02 14:41:40 | 000,000,000 | ---D | C] -- C:\Users\Ali\Desktop\Thrpiztrum
[2013.05.02 13:30:08 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\{2A230A30-EC0A-4F9D-BBC2-5FF4EDAF4CAE}
[2013.05.02 13:23:17 | 000,000,000 | R--D | C] -- C:\Users\Ali\Documents\Scanned Documents
[2013.05.02 13:23:17 | 000,000,000 | ---D | C] -- C:\Users\Ali\Documents\Fax
[2013.05.01 20:48:52 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\{522AD0D7-90EB-4C59-AEF2-6BCDDBE526D8}
[2013.05.01 20:48:35 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\{20E34768-5806-48C5-9DBF-F3FB8B296E44}
[2013.04.29 08:00:11 | 000,000,000 | ---D | C] -- C:\Users\Ali\4.0
[2013.04.29 08:00:10 | 000,000,000 | ---D | C] -- C:\Users\Ali\.tfo4
[2013.04.22 10:11:21 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\Apps
[2013.04.21 22:27:11 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\{B1A39E47-3000-4230-93C3-9CFB6076E7B6}
[2013.04.10 23:40:49 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013.04.10 23:40:49 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013.04.10 23:40:48 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013.04.10 23:40:48 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013.04.10 23:40:48 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013.04.10 23:40:48 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013.04.10 23:40:48 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013.04.10 23:40:48 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.04.10 23:40:48 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013.04.10 23:40:48 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013.04.10 23:40:47 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013.04.10 23:40:47 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013.04.10 23:40:46 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013.04.10 23:40:46 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.04.10 23:40:46 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.05.10 20:45:29 | 000,016,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.05.10 20:45:29 | 000,016,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.05.10 20:42:24 | 001,500,358 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.05.10 20:42:24 | 000,654,602 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.05.10 20:42:24 | 000,616,484 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.05.10 20:42:24 | 000,130,216 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.05.10 20:42:24 | 000,106,606 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.05.10 20:38:44 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.05.10 20:38:08 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.05.10 20:38:01 | 2800,545,792 | -HS- | M] () -- C:\hiberfil.sys
[2013.05.10 20:06:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.05.10 20:02:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.05.10 13:07:01 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-732902274-989681646-235948354-1002UA.job
[2013.05.10 12:49:09 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.05.10 01:30:45 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
[2013.05.09 22:07:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-732902274-989681646-235948354-1002Core.job
[2013.05.09 17:21:38 | 000,000,000 | ---- | M] () -- C:\Users\Ali\AppData\Local\Temptable.xml
[2013.05.08 20:56:43 | 000,309,488 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.05.08 19:03:01 | 000,002,785 | ---- | M] () -- C:\Users\Public\Desktop\SolidWorks 2012 x64 Edition.lnk
[2013.05.08 18:50:01 | 000,002,119 | ---- | M] () -- C:\Users\Public\Desktop\SolidWorks eDrawings 2012.lnk
[2013.05.08 18:48:46 | 000,000,000 | ---- | M] () -- C:\Windows\eDrawingOfficeAutomator.INI
[2013.05.08 18:48:42 | 000,002,089 | ---- | M] () -- C:\Users\Public\Desktop\SolidWorks eDrawings 2012 x64 Edition.lnk
[2013.05.07 15:48:35 | 000,001,787 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013.05.07 12:45:54 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2013.05.06 11:11:28 | 000,083,160 | ---- | M] (Avira GmbH) -- C:\Windows\SysNative\drivers\avnetflt.sys
[2013.05.03 17:21:59 | 000,182,529 | ---- | M] () -- C:\Users\Ali\Desktop\002.jpg
[2013.05.03 16:44:28 | 000,005,829 | ---- | M] () -- C:\Users\Ali\Documents\LANXESSAli Isle1.odt
[2013.05.03 16:27:50 | 000,005,675 | ---- | M] () -- C:\Users\Ali\Documents\CURRENTAAli Islek.odt
[2013.05.03 16:13:53 | 000,005,896 | ---- | M] () -- C:\Users\Ali\Documents\LANXESSAli Islek.odt
[2013.05.03 14:08:24 | 000,043,626 | -HS- | M] () -- C:\Users\Ali\Desktop\Folder.jpg
[2013.05.03 14:08:24 | 000,043,626 | -HS- | M] () -- C:\Users\Ali\Desktop\AlbumArt_{BFC6AF81-D8F9-4040-835B-5D022FB48B1F}_Large.jpg
[2013.05.03 14:08:24 | 000,008,788 | -HS- | M] () -- C:\Users\Ali\Desktop\AlbumArtSmall.jpg
[2013.05.03 14:08:24 | 000,008,788 | -HS- | M] () -- C:\Users\Ali\Desktop\AlbumArt_{BFC6AF81-D8F9-4040-835B-5D022FB48B1F}_Small.jpg
[2013.05.02 14:43:20 | 000,000,432 | ---- | M] () -- C:\Windows\BRWMARK.INI
[2013.04.12 20:20:45 | 000,000,367 | ---- | M] () -- C:\Users\Ali\Heimnetzgruppe - Verknüpfung.lnk
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.05.10 12:49:09 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.05.10 01:30:45 | 000,000,000 | ---- | C] () -- C:\autoexec.bat
[2013.05.08 19:15:51 | 000,000,000 | ---- | C] () -- C:\Users\Ali\AppData\Local\Temptable.xml
[2013.05.08 19:03:01 | 000,002,785 | ---- | C] () -- C:\Users\Public\Desktop\SolidWorks 2012 x64 Edition.lnk
[2013.05.08 18:48:46 | 000,000,000 | ---- | C] () -- C:\Windows\eDrawingOfficeAutomator.INI
[2013.05.08 18:48:42 | 000,002,089 | ---- | C] () -- C:\Users\Public\Desktop\SolidWorks eDrawings 2012 x64 Edition.lnk
[2013.05.07 21:42:55 | 000,002,119 | ---- | C] () -- C:\Users\Public\Desktop\SolidWorks eDrawings 2012.lnk
[2013.05.07 15:48:35 | 000,001,787 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013.05.07 15:47:20 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013.05.07 12:45:54 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2013.05.03 17:21:59 | 000,182,529 | ---- | C] () -- C:\Users\Ali\Desktop\002.jpg
[2013.05.03 16:33:46 | 000,005,829 | ---- | C] () -- C:\Users\Ali\Documents\LANXESSAli Isle1.odt
[2013.05.03 16:27:48 | 000,005,675 | ---- | C] () -- C:\Users\Ali\Documents\CURRENTAAli Islek.odt
[2013.05.03 16:13:51 | 000,005,896 | ---- | C] () -- C:\Users\Ali\Documents\LANXESSAli Islek.odt
[2013.05.03 14:08:17 | 000,043,626 | -HS- | C] () -- C:\Users\Ali\Desktop\Folder.jpg
[2013.05.03 14:08:17 | 000,043,626 | -HS- | C] () -- C:\Users\Ali\Desktop\AlbumArt_{BFC6AF81-D8F9-4040-835B-5D022FB48B1F}_Large.jpg
[2013.05.03 14:08:17 | 000,008,788 | -HS- | C] () -- C:\Users\Ali\Desktop\AlbumArtSmall.jpg
[2013.05.03 14:08:17 | 000,008,788 | -HS- | C] () -- C:\Users\Ali\Desktop\AlbumArt_{BFC6AF81-D8F9-4040-835B-5D022FB48B1F}_Small.jpg
[2013.04.12 20:20:45 | 000,000,367 | ---- | C] () -- C:\Users\Ali\Heimnetzgruppe - Verknüpfung.lnk
[2013.02.24 21:56:56 | 000,121,359 | ---- | C] () -- C:\Users\Ali\541019_10151490385920622_923617879_n.jpg
[2013.02.10 21:53:52 | 000,022,147 | ---- | C] () -- C:\Users\Ali\burpees-exercise.jpg
[2013.02.06 00:28:11 | 000,006,875 | ---- | C] () -- C:\Users\Ali\lebenslauif2.odt
[2013.02.05 23:48:40 | 000,008,234 | ---- | C] () -- C:\Users\Ali\phsio2.odt
[2012.12.23 01:03:04 | 000,000,000 | ---- | C] () -- C:\Users\Ali\defogger_reenable
[2012.12.09 22:02:52 | 001,841,122 | ---- | C] () -- C:\Users\Ali\MOV00165.3gp
[2012.09.03 11:03:44 | 000,000,432 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012.09.03 11:03:44 | 000,000,034 | ---- | C] () -- C:\Windows\SysWow64\BD7320.DAT
[2012.08.15 18:45:23 | 000,017,408 | ---- | C] () -- C:\Users\Ali\AppData\Local\WebpageIcons.db
[2012.08.14 12:57:37 | 000,000,017 | ---- | C] () -- C:\Windows\SysWow64\shortcut_ex.dat
[2012.08.14 12:49:49 | 011,027,660 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.04.25 21:49:04 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.04.25 20:29:27 | 000,204,960 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.04.25 20:29:27 | 000,157,152 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.04.25 20:29:26 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2012.03.29 09:22:32 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2012.03.03 01:33:26 | 000,023,040 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >

--- --- ---

[/CODE]

Logfile 2 (OTL)
OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 10.05.2013 20:54:22 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Ali\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,48 Gb Total Physical Memory | 2,01 Gb Available Physical Memory | 57,74% Memory free
6,95 Gb Paging File | 4,94 Gb Available in Paging File | 70,98% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 880,41 Gb Total Space | 814,98 Gb Free Space | 92,57% Space Free | Partition Type: NTFS
Drive D: | 50,00 Gb Total Space | 27,01 Gb Free Space | 54,03% Space Free | Partition Type: NTFS
Drive E: | 7,05 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive I: | 298,01 Gb Total Space | 174,39 Gb Free Space | 58,52% Space Free | Partition Type: FAT32
 
Computer Name: ALI-PC | User Name: Ali | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_USERS\.DEFAULT\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
[HKEY_USERS\S-1-5-18\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0774D1BB-E6E8-40D3-9A0B-CD57A9A257ED}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{2BD0024B-6D91-4A74-9DA5-68C19B3E59BE}" = lport=138 | protocol=17 | dir=in | app=system |
"{36113B42-7EC1-4750-8638-0C9A96D01453}" = rport=137 | protocol=17 | dir=out | app=system |
"{3F0CB73A-4640-4B7B-A0AC-524E66E23823}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{4476A2B0-7F93-40C5-998E-BAFFE700ACA4}" = lport=445 | protocol=6 | dir=in | app=system |
"{4C07DFBD-F627-4B7E-A0C5-EF38CF1D4034}" = lport=139 | protocol=6 | dir=in | app=system |
"{4DDFA5A7-A8A5-4A0D-A8EF-4EA135C48B2F}" = rport=445 | protocol=6 | dir=out | app=system |
"{65EB329D-853A-4943-BC9C-9C210E7A8F88}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{667EF413-20AF-4DDF-B102-FF5C9D914F2A}" = lport=137 | protocol=17 | dir=in | app=system |
"{6A282FE4-1BBF-4260-8073-E378920A85BB}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6BCF59DD-B385-43EA-A868-B429B2DEA58F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6D4F4FB5-861F-4D98-9623-2AC411758738}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7DF0A5E1-FB3F-4C57-9160-75ACD456A83C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8074BDE0-C96D-440E-B6C7-27916FCA8BF6}" = rport=10243 | protocol=6 | dir=out | app=system |
"{894EEC85-8AFC-49B5-9B65-476C45F7B38F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{92094879-792D-4269-B874-4939B91FD6EC}" = lport=10243 | protocol=6 | dir=in | app=system |
"{936A2009-D4A5-4235-B77F-AC5DEC9F360E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{939D0EBE-CBCF-4222-ACF5-87F38622D7D5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A5BDFFE6-CE54-4C03-8944-0E88F100B2B8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B5DB872C-50F5-4068-B549-6A545DFBC13D}" = rport=138 | protocol=17 | dir=out | app=system |
"{D63C74F5-9DCE-4F49-A501-D838905BB8A3}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{D75C27AF-EFC3-4E5C-BA44-4034665B172E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DE64A96F-9795-48EF-A4AE-40D42183AC37}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{E4E56A61-41F3-48CD-8EA9-20D759C9A27C}" = rport=139 | protocol=6 | dir=out | app=system |
"{F832B972-40E5-4703-873C-B56D8FC78882}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{004DB218-5A19-45CC-ADB5-5032CD9F1965}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{02330FA4-307A-4636-BDA1-6A7B55E057C2}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{02F0F56F-0393-4251-B512-ACFE1D0E0D45}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{03538BEE-00E0-491A-8B1C-228B12A8613A}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{0E9032EA-8E2E-4997-8C78-F66A8D214033}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{11B2DEAD-2EE3-4029-A36C-3086A88654E3}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{15217B96-427B-443B-9D52-2983ABA3418C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1BAFF021-C922-4F97-B8CA-39A54A5837A0}" = protocol=6 | dir=in | app=c:\program files\solidworks corp\solidworks\photoview\photoview360.exe |
"{221AD45E-B25B-4120-824B-4D7BE640655C}" = protocol=17 | dir=in | app=c:\program files\solidworks corp\solidworks\swscheduler\dtscoordinatorservice.exe |
"{2A043408-F0BD-48E7-9151-30D8BEC7D6FD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2D29762C-0B26-4E4F-8291-30A578F7F741}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3309DD24-7F35-46CC-A50F-846E8D90FBE2}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{448502A3-CADB-4B15-B212-1A8E0BB9273C}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |
"{46B9E9F3-40E8-4B98-850E-CA053880467D}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{4976E994-DF8A-4DC0-B692-B91218F8E7CD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4B053FE4-111E-45A6-B2C2-DDCEE1C123AC}" = protocol=6 | dir=out | app=system |
"{551F50F7-F999-40EA-98C2-91928BB5670C}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{5AF8B07E-06C7-431E-8350-F5B83E73B00C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7A86A8B9-7899-4C34-A619-3C940322E37E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{85832019-5E10-4687-9BE8-ECC6260C4DFB}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{8A77CE6C-EEA1-4271-9510-BC6C3D138DCA}" = protocol=6 | dir=in | app=c:\program files\solidworks corp\solidworks\swscheduler\dtscoordinatorservice.exe |
"{96B5A17E-16E4-46FA-8B27-FD6DB1503F0D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{9BD35360-411E-4672-AF94-210EB3B7865C}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |
"{9FF5C3FE-78B7-467F-91F7-FAA3B3917E4B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A61367A7-E653-4885-8E59-833F8F86E119}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{B0E43F6F-BD35-4366-8125-13A6DC499B5D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{B2530575-C097-460F-835A-A332D2E992BC}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B2DC6B51-35A6-4FB3-9AB2-CD7C3CE8C0B4}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{B575D541-B8B4-41AB-A7CB-52FD9909F1C2}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd cinema\powerdvdcinema10.exe |
"{B8A79B27-9B9D-4434-B82B-3B736B2C9063}" = protocol=17 | dir=in | app=c:\program files\solidworks corp\solidworks\photoview\photoview360.exe |
"{BE06C39B-BED4-4112-A9CA-97F8749E748F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{C0B4056E-B896-435C-BBE5-FF8029F17959}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{C5B8384C-F5B9-4AF0-8809-49EDDAA22E60}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C9D56DC8-8175-49B5-AA47-279A5731C1BD}" = protocol=17 | dir=in | app=c:\program files\solidworks corp\solidworks\photoview\photoview360_cl.exe |
"{CAF729A1-76AD-486F-B0AC-2F4C9416FAA5}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{CB0D8099-3334-4CC9-ABDA-C1B9AC479B71}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CB2332EA-77AC-41DE-AD54-8B1B22BDC0F9}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{CF7B8919-428C-405D-A724-C505B59E1B70}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\pdvd10serv.exe |
"{D0DFD85B-0AD1-44A4-B65E-F00137AD9A71}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{D13CE2C1-E40A-4013-B336-35D8A04E9164}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{D3159457-6735-4773-9245-DDF1EEB77A96}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe |
"{D551DB91-B43A-4233-A2B1-1689FF7A5879}" = dir=in | app=c:\users\ali\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{E2F5A9C4-B310-48C1-8369-F8771F20D61D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{E4640980-D148-45F4-852E-D26C491FAD38}" = protocol=6 | dir=in | app=c:\program files\solidworks corp\solidworks\photoview\photoview360_cl.exe |
"{E9B0EAEB-C76F-411E-8379-6920E029A5A4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F434872A-64ED-4BF9-8C76-D8A5585960F2}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\device\mediaserver\clmsserver.exe |
"{F44A7D16-3489-4AB8-A678-34C644507995}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{F614609F-25C6-4327-A7D7-402DC4B76C86}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{FD7E9231-09A4-4605-8E05-F48B706755D7}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{FD911185-B75B-48C0-B32F-6B46731EC876}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{08049A1D-919A-437D-8BF0-E86DF08FAD27}C:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe |
"TCP Query User{263F1609-5E17-435A-9A5D-A12B79F2AE4F}C:\program files (x86)\starcraft ii\versions\base24944\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base24944\sc2.exe |
"UDP Query User{8328C114-FDD9-4469-A316-1F2E755B7AE6}C:\program files (x86)\starcraft ii\versions\base24944\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base24944\sc2.exe |
"UDP Query User{86E9DE54-29FE-4747-BCFA-F1CAAFB0BA50}C:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0225AD21-F3E2-4916-BFF3-65D3F9052582}" = iTunes
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1685AE50-97ED-485B-80F6-145071EE14B0}" = Windows Live Remote Service Resources
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{19F09425-3C20-4730-9E2A-FC2E17C9F362}" = Windows Live Remote Service Resources
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1EB2CFC3-E1C5-4FC4-B1F8-549DD6242C67}" = Windows Live Remote Service Resources
"{2426E29F-9E8C-4C0B-97FC-0DB690C1ED98}" = Windows Live Remote Client Resources
"{2486F47D-848C-4C46-ADD5-060984AAEE34}" = SolidWorks eDrawings 2012 x64 Edition SP04
"{2A2FECF6-C701-6C8A-6B1D-B491CB0A58BD}" = AMD Accelerated Video Transcoding
"{2C1A6191-9804-4FDC-AB01-6F9183C91A13}" = Windows Live Remote Client Resources
"{2F304EF4-0C31-47F4-8557-0641AAE4197C}" = Windows Live Remote Client Resources
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{456FB9B5-AFBC-4761-BBDC-BA6BAFBB818F}" = Windows Live Remote Client Resources
"{46F7226B-C813-8686-4745-1B547E49119B}" = AMD Fuel
"{480F28F0-8BCE-404A-A52E-0DBB7D1CE2EF}" = Windows Live Remote Service Resources
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4C2E49C0-9276-4324-841D-774CCCE5DB48}" = Windows Live Remote Client Resources
"{4C66F076-D3AB-49C8-85D4-BAA6D82FCAE2}" = SolidWorks 2012 x64 Edition SP04
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5151E2DB-0748-4FD1-86A2-72E2F94F8BE7}" = Windows Live Remote Service Resources
"{542DDF04-9F91-4F36-B2F4-2638B788A4C8}" = Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
"{57F2BD1C-14A3-4785-8E48-2075B96EB2DF}" = Windows Live Remote Service Resources
"{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{5FEAD3E5-A158-4B66-B92B-0C959D7CF838}" = Windows Live Remote Service Resources
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{65DDB7D8-5E04-45DF-B60E-89557ED37ED2}" = SolidWorks Explorer 2012 SP04 x64 Edition
"{692CCE55-9EAE-4F57-A834-092882E7FE0B}" = Windows Live Remote Client Resources
"{6C9D3F1D-DBBE-46F9-96A0-726CC72935AF}" = Windows Live Remote Service Resources
"{6CBFDC3C-CF21-4C02-A6DC-A5A2707FAF55}" = Windows Live Remote Service Resources
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7AEC844D-448A-455E-A34E-E1032196BBCD}" = Windows Live Remote Service Resources
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{850B8072-2EA7-4EDC-B930-7FE569495E76}" = Windows Live Remote Client Resources
"{8970AE69-40BE-4058-9916-0ACB1B974A3D}" = Windows Live Remote Client Resources
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8EB588BD-D398-40D0-ADF7-BE1CEEF7C116}" = Windows Live Remote Client Resources
"{90140000-006D-0407-1000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A060182D-CDBE-4AD6-B9B4-860B435D6CBD}" = Windows Live Remote Client Resources
"{A343E874-9218-9F30-428E-7DCBDF444591}" = AMD Media Foundation Decoders
"{A679FBE4-BA2D-4514-8834-030982C8B31A}" = Windows Live Remote Service Resources
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C9F05151-95A9-4B9B-B534-1760E2D014A5}" = Windows Live Remote Client Resources
"{CBD31BA9-DCAA-555F-65D1-9117BF9F6A16}" = ccc-utility64
"{D1C1556C-7FF3-48A3-A5D6-7126F0FAFB66}" = Windows Live Remote Client Resources
"{D3E4F422-7E0F-49C7-8B00-F42490D7A385}" = Windows Live Remote Service Resources
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DBEDAF67-C5A3-4C91-951D-31F3FE63AF3F}" = Windows Live Remote Client Resources
"{DCAEC601-735C-41AE-B84F-D792F09FB7D1}" = WOT for Internet Explorer
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E07F5C48-19FD-0ADD-EABB-D7940E3B7967}" = AMD Drag and Drop Transcoding
"{EB9400D5-6289-4F9F-9B79-B3528101C0C7}" = SolidWorks Flow Simulation 2012 SP04 x64 Edition
"{F11C146C-580C-7594-B7BB-4F610202E7C3}" = AMD Catalyst Install Manager
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6CB2C5F-B2C1-4DF1-BF44-39D0DC06FE6F}" = Windows Live Remote Service Resources
"{FC6DA3C3-FAFE-568A-7CD2-D1A31BD81481}" = AMD AVIVO64 Codecs
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU" = Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
"WinRAR archiver" = WinRAR 4.20 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00884F14-05BD-4D8E-90E5-1ABF78948CA4}" = Windows Live Mesh
"{02C6615A-A8FF-4175-8B25-9DADCE1D02B7}_is1" = Secure Banking Version 1.4.6
"{04668DF2-D32F-4555-9C7E-35523DCD6544}" = Control ActiveX de Windows Live Mesh para conexiones remotas
"{05E379CC-F626-4E7D-8354-463865B303BF}" = Windows Live UX Platform Language Pack
"{062E4D94-8306-46D5-81B6-45E6AD09C799}" = Windows Live Messenger
"{0654EA5D-308A-4196-882B-5C09744A5D81}" = Windows Live Photo Common
"{066751D5-77C0-DB40-AAC5-DA8696263A49}" = CCC Help Finnish
"{09922FFE-D153-44AE-8B60-EA3CB8088F93}" = Windows Live UX Platform Language Pack
"{09B7C7EB-3140-4B5E-842F-9C79A7137139}" = Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C1931EB-8339-4837-8BEC-75029BF42734}" = Windows Live UX Platform Language Pack
"{0C975FCC-A06E-4CB6-8F54-A9B52CF37781}" = Windows Liven sähköposti
"{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail
"{0EC0B576-90F9-43C3-8FAD-A4902DF4B8F4}" = Galeria de Fotografias do Windows Live
"{10186F1A-6A14-43DF-A404-F0105D09BB07}" = Windows Live Mail
"{110668B7-54C6-47C9-BAC4-1CE77F156AF5}" = Windows Live Mesh
"{11417707-1F72-4279-95A3-01E0B898BBF5}" = Windows Live Mesh
"{1203DC60-D9BD-44F9-B372-2B8F227E6094}" = Windows Live Temel Parçalar
"{133D9D67-D475-4407-AC3C-D558087B2453}" = Windows Live Movie Maker
"{14B441B7-774D-4170-98EA-A13667AE6218}" = Windows Live Writer Resources
"{17F99FCE-8F03-4439-860A-25C5A5434E18}" = Windows Live Essentials
"{191473E4-9958-BB64-37BF-0A59964B993C}" = CCC Help Japanese
"{198EA334-8A3F-4CB2-9D61-6C10B8168A6F}" = Windows Live Writer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1A72337E-D126-4BAF-AC89-E6122DB71866}" = Windows Liven valokuvavalikoima
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1D6C2068-807F-4B76-A0C2-62ED05656593}" = Windows Live Writer
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema
"{1FC83EAE-74C8-4C72-8400-2D8E40A017DE}" = Windows Live Writer
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{220C7F8C-929D-4F71-9DC7-F7A6823B38E4}" = Windows Live UX Platform Language Pack
"{24DF33E0-F924-4D0D-9B96-11F28F0D602D}" = Windows Live UX Platform Language Pack
"{25A381E1-0AB9-4E7A-ACCE-BA49D519CF4E}" = Windows Live Mail
"{25CD4B12-8CC5-433E-B723-C9CB41FA8C5A}" = Windows Live Writer
"{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 10
"{26E3C07C-7FF7-4362-9E99-9E49E383CF16}" = Windows Live Writer Resources
"{28B9D2D8-4304-483F-AD71-51890A063A74}" = Windows Live Photo Common
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A07C35B-8384-4DA4-9A95-442B6C89A073}" = Windows Live Essentials
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2E50E321-4747-4EB5-9ECB-BBC6C3AC0F31}" = Windows Live Writer Resources
"{2F54E453-8C93-4B3B-936A-233C909E6CAC}" = Windows Live Messenger
"{3125D9DE-8D7A-4987-95F3-8A42389833D8}" = Windows Live Writer Resources
"{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}" = CyberLink WaveEditor
"{331DD203-AD0A-881A-878D-0779EEDB2E76}" = CCC Help Swedish
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{370F888E-42A7-4911-9E34-7D74632E17EB}" = Windows Live Photo Common
"{376D59B1-42D9-4FA2-B6CC-E346B6BE14F5}" = ActiveX-kontroll för fjärranslutningar för Windows Live Mesh
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{39F95B0B-A0B7-4FA7-BB6C-197DA2546468}" = Windows Live Mesh
"{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer
"{3F4143A1-9C21-4011-8679-3BC1014C6886}" = Windows Live Mesh
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{40BFD84C-64CD-42CC-9909-8734C50429C6}" = Windows Live UX Platform Language Pack
"{410DF0AA-882D-450D-9E1B-F5397ACFFA80}" = Windows Live Essentials
"{419FCF7D-D678-D4DC-FC27-2330D0D7281E}" = CCC Help Spanish
"{429DF1A0-3610-4E9E-8ACE-3C8AC1BA8FCA}" = Windows Live Photo Gallery
"{443B561F-DE1B-4DEF-ADD9-484B684653C7}" = Windows Live Messenger
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = CyberLink PowerRecover
"{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}" = Apple Application Support
"{46872828-6453-4138-BE1C-CE35FBF67978}" = Windows Live Mesh
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR
"{48294D95-EE9A-4377-8213-44FC4265FB27}" = Windows Live Messenger
"{4862344A-A39C-4897-ACD4-A1BED5163C5A}" = CyberLink PhotoDirector 2011
"{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live
"{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A04DB63-8F81-4EF4-9D09-61A2057EF419}" = Windows Live Essentials
"{4B28D47A-5FF0-45F8-8745-11DC2A1C9D0F}" = Windows Live Writer
"{4B744C85-DBB1-4038-B989-4721EB22C582}" = Windows Live Messenger
"{4CF6F287-5121-483C-A5A2-07BDE19D8B4E}" = Windows Live Meshin etäyhteyksien ActiveX-komponentti
"{4D141929-141B-4605-95D6-2B8650C1C6DA}" = Windows Live UX Platform Language Pack
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{506FC723-8E6C-4417-9CFF-351F99130425}" = Windows Live UX Platform Language Pack
"{523DF2BB-3A85-4047-9898-29DC8AEB7E69}" = Windows Live UX Platform Language Pack
"{526FCE48-BF57-0B12-4145-814CBA86C080}" = CCC Help German
"{5275D81E-83AD-4DE4-BC2B-6E6BA3A33244}" = Windows Live Writer Resources
"{55D003F4-9599-44BF-BA9E-95D060730DD3}" = Contrôle ActiveX Windows Live Mesh pour connexions à distance
"{56C3465B-74D0-F971-7B2D-104B5D26D07A}" = CCC Help Danish
"{57220148-3B2B-412A-A2E0-82B9DF423696}" = Windows Live Mesh ActiveX-objekt til fjernforbindelser
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5C2F5C1B-9732-4F81-8FBF-6711627DC508}" = Windows Live Fotogalleri
"{5CF5B1A5-CBC3-42F0-8533-5A5090665862}" = Windows Live Mesh
"{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker
"{60C3C026-DB53-4DAB-8B97-7C1241F9A847}" = Windows Live Movie Maker
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources
"{634C6E88-A2C3-F328-0EA8-8A727216EFCF}" = Catalyst Control Center InstallProxy
"{63CF7D0C-B6E7-4EE9-8253-816B613CC437}" = Windows Live Mail
"{640798A0-A4FB-4C52-AC72-755134767F1E}" = Windows Live Movie Maker
"{64376910-1860-4CEF-8B34-AA5D205FC5F1}" = Poczta usługi Windows Live
"{677AAD91-1790-4FC5-B285-0E6A9D65F7DC}" = Windows Live Mail
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69CAC24D-B1DC-4B97-A1BE-FE21843108FE}" = Windows Live Writer Resources
"{6A67578E-095B-4661-88F7-0B199CEC3371}" = Windows Live Messenger
"{6ABE832B-A5C7-44C1-B697-3E123B7B4D5B}" = Windows Live Mesh
"{6B556C37-8919-4991-AC34-93D018B9EA49}" = Windows Live Photo Common
"{6B66E31D-18FD-F71E-A1D1-40BD4CFD5307}" = CCC Help Norwegian
"{6D17F8CA-07BD-285C-3F9B-F2426F815ABA}" = CCC Help French
"{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker
"{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}" = Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz
"{6E8AFC13-F7B8-41D8-88AB-F1D0CFC56305}" = Windows Live Messenger
"{6EF2BE2C-3121-48B7-B7A6-C56046B3A588}" = Windows Live Movie Maker
"{6FAB23A6-D55E-C402-00A1-73E07ED45B68}" = AMD VISION Engine Control Center
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71A81378-79D5-40CC-9BDC-380642D1A87F}" = Windows Live Writer
"{71C95134-F6A9-45E7-B7B3-07CA6012BF2A}" = Windows Live Mesh
"{7272F232-A7E0-4B2B-A5D2-71B7C5E2379C}" = Windows Live Fotótár
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{734104DE-C2BF-412F-BB97-FCCE1EC94229}" = Windows Live Writer Resources
"{73FC3510-6421-40F7-9503-EDAE4D0CF70D}" = Windows Live Photo Common
"{7496FD31-E5CB-4AE4-82D3-31099558BF6A}" = Windows Live Mesh
"{74E8A7F6-575D-42C7-9178-E87D1B3BEFE8}" = Windows Live UX Platform Language Pack
"{77477AEA-5757-47D8-8B33-939F43D82218}" = Windows Live UX Platform Language Pack
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78DAE910-CA72-450E-AD22-772CB1A00678}" = Windows Live Mesh
"{7A9D47BA-6D50-4087-866F-0800D8B89383}" = Podstawowe programy Windows Live
"{7ADFA72D-2A9F-4DEC-80A5-2FAA27E23F0F}" = Windows Live Photo Common
"{7BA19818-F717-4DFB-BC11-FAF17B2B8AEE}" = Pošta Windows Live
"{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials
"{7E017923-16F8-4E32-94EF-0A150BD196FE}" = Windows Live Writer
"{7E90B133-FF47-48BB-91B8-36FC5A548FE9}" = Windows Live Writer Resources
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 5.4.0
"{827D3E4A-0186-48B7-9801-7D1E9DD40C07}" = Windows Live Essentials
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh
"{84267681-BF16-40B6-9564-27BC57D7D71C}" = Windows Live Photo Common
"{85373DA7-834E-4850-8AF5-1D99F7526857}" = Windows Live Photo Common
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{885F1BCD-C344-4758-85BD-09640CF449A5}" = Windows Live Photo Gallery
"{8909CFA8-97BF-4077-AC0F-6925243FFE08}" = Windows Liven asennustyökalu
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8CF5D47D-27B7-49D6-A14F-10550B92749D}" = Windows Live UX Platform Language Pack
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E666407-AC41-46a2-9692-6C7BFCBFDD37}" = Memeo Instant Backup
"{8FF3891F-01B5-4A71-BFCD-20761890471C}" = Windows Live Messenger
"{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components
"{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch
"{90E1836C-11B8-880F-0BB2-7FD1C2641161}" = CCC Help English
"{924B4D82-1B97-48EB-8F1E-55C4353C22DB}" = Windows Live Mail
"{9268B41D-6045-4F5F-A14E-3F8E51CD2666}" = Secure Download Manager
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{93E464B3-D075-4989-87FD-A828B5C308B1}" = Windows Live Writer Resources
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BD262D0-B788-4546-A0A5-F4F56EC3834B}" = Windows Live Photo Common
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A101F637-2E56-42C0-8E08-F1E9086BFAF3}" = Windows Live Movie Maker
"{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common
"{A44D21A9-713C-1578-90F2-D66EFB633ECD}" = CCC Help Dutch
"{A60B3BF0-954B-42AF-B8D8-2C1D34B613AA}" = Windows Live Photo Gallery
"{A7056D45-C63A-4FE4-A69D-FB54EF9B21BB}" = Windows Live Messenger
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9A76D94-166A-4DA8-BCDD-30CE751C330A}_is1" = YouProxy Version 1.1
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA7FA5FA-5580-BD13-C457-9DCBFA266B01}" = CCC Help Italian
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB61A2E9-37D3-485D-9085-19FBDF8CEF4A}" = Windows Live Messenger
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.02) - Deutsch
"{AC76BA86-7AD7-5464-3428-A00000000004}" = Spelling Dictionaries Support For Adobe Reader X
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{ADE85655-8D1E-4E4B-BF88-5E312FB2C74F}" = Windows Live Mail
"{ADFE4AED-7F8E-4658-8D6E-742B15B9F120}" = Windows Live Photo Common
"{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}" = Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B2E90616-C50D-4B89-A40D-92377AC669E5}" = Windows Live Messenger
"{B571687A-1AE6-4C32-9B5B-678BECB556BE}" = Cisco AnyConnect VPN Client
"{B618C3BF-5142-4630-81DD-F96864F97C7E}" = Windows Live Essentials
"{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling 1.2.0.287
"{BD695C2F-3EA0-4DA4-92D5-154072468721}" = Windows Live Fotoğraf Galerisi
"{BF022D76-9F72-4203-B8FA-6522DC66DFDA}" = Windows Live Movie Maker
"{BF35168D-F6F9-4202-BA87-86B5E3C9BF7A}" = Windows Live Mesh
"{BFC47A0B-D487-4DF0-889E-D6D392DF31E0}" = Windows Live Messenger
"{C00C2A91-6CB3-483F-80B3-2958E29468F1}" = Συλλογή φωτογραφιών του Windows Live
"{C29FC15D-E84B-4EEC-8505-4DED94414C59}" = Windows Live Writer Resources
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C32CE55C-12BA-4951-8797-0967FDEF556F}" = Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}" = Windows Live Mesh ActiveX Control for Remote Connections
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C8421D85-CA0E-4E93-A9A9-B826C4FB88EA}" = Windows Live Mail
"{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common
"{CA227A9D-09BE-4BFB-9764-48FED2DA5454}" = Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave
"{CB3F59BB-7858-41A1-A7EA-4B8A6FC7D431}" = Galeria fotografii usługi Windows Live
"{CB7224D9-6DCA-43F1-8F83-6B1E39A00F92}" = Windows Live Movie Maker
"{CD442136-9115-4236-9C14-278F6A9DCB3F}" = Windows Live Movie Maker
"{CD7CB1E6-267A-408F-877D-B532AD2C882E}" = Windows Live Photo Common
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF671BFE-6BA3-44E7-98C1-500D9C51D947}" = Windows Live Photo Gallery
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D31169F2-CD71-4337-B783-3E53F29F4CAD}" = Windows Live Mail
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D481EA96-2313-4A7C-98EE-710D1AF884AC}" = Microsoft Visual Studio 2005 Tools for Applications - ENU
"{D588365A-AE39-4F27-BDAE-B4E72C8E900C}" = Windows Live Mail
"{D6F25CF9-4E87-43EB-B324-C12BE9CDD668}" = Windows Live UX Platform Language Pack
"{DA29F644-2420-4448-8128-1331BE588999}" = Windows Live Writer
"{DAEF48AD-89C8-4A93-B1DD-45B7E4FB6071}" = Windows Live Movie Maker
"{DB1208F4-B2FE-44E9-BFE6-8824DBD7891B}" = Windows Live Movie Maker
"{DCAB6BA7-6533-44BF-9235-E5BF33B7431C}" = Windows Live Writer
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE7C13A6-E4EA-4296-B0D5-5D7E8AD69501}" = Windows Live Writer
"{DE8F99FD-2FC7-4C98-AA67-2729FDE1F040}" = Windows Live Writer Resources
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DEF91E0F-D266-453D-B6F2-1BA002B40CB6}" = Windows Live Essentials
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso
"{E3D04529-6EDB-11D8-A372-0050BAE317E1}" = CyberLink PowerDVD Copy
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}" = Controlo ActiveX do Windows Live Mesh para Ligações Remotas
"{E55E0C35-AC3C-4683-BA2F-834348577B80}" = Windows Live Writer
"{E59969EA-3B5B-4B24-8B94-43842A7FBFE9}" = Fotogalerija Windows Live
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E5DD4723-FE0B-436E-A815-DC23CF902A0B}" = Windows Live UX Platform Language Pack
"{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources
"{E8524B28-3BBB-4763-AC83-0E83FE31C350}" = Windows Live Writer
"{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live
"{E9AD2143-26D5-4201-BED1-19DCC03B407D}" = Windows Live Messenger
"{E9D98402-21AB-4E9F-BF6B-47AF36EF7E97}" = Windows Live Writer Resources
"{ED16B700-D91F-44B0-867C-7EB5253CA38D}" = Raccolta foto di Windows Live
"{F0559C5E-7912-4391-B1A0-6B975F0E5064}" = watchmi
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0F9505B-3ACF-4158-9311-D0285136AA00}" = Windows Live Essentials
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F80E5450-3EF3-4270-B26C-6AC53BEC5E76}" = Windows Live Movie Maker
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FAAC9596-EFF3-11ED-1A98-90ED59732CD1}" = Catalyst Control Center Localization All
"{FCDE76CB-989D-4E32-9739-6A272D2B0ED7}" = Windows Live Mesh
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FEEF7F78-5876-438B-B554-C4CC426A4302}" = Windows Live Essentials
"{FF3DFA01-1E98-46B4-A065-DA8AD47C9598}" = Windows Live Movie Maker
"{FFFA0584-8E3D-4195-8283-CCA3AD73C746}" = Windows Live Messenger
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Ashampoo Burning Studio_is1" = Ashampoo Burning Studio
"Ashampoo Photo Commander_is1" = Ashampoo Photo Commander
"Ashampoo Photo Optimizer_is1" = Ashampoo Photo Optimizer
"Ashampoo Snap_is1" = Ashampoo Snap
"Avira AntiVir Desktop" = Avira Free Antivirus
"Foxit Reader_is1" = Foxit Reader
"Free PDF to Word Doc Converter_is1" = Free PDF to Word Doc Converter v1.1
"Google Chrome" = Google Chrome
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Medion Home Cinema
"InstallShield_{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}" = CyberLink WaveEditor
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = CyberLink PowerRecover
"InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}" = CyberLink PhotoDirector 2011
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso
"InstallShield_{E3D04529-6EDB-11D8-A372-0050BAE317E1}" = CyberLink PowerDVD Copy
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.65.1.1000
"Microsoft Visual Studio 2005 Tools for Applications - ENU" = Microsoft Visual Studio 2005 Tools for Applications - ENU
"Office14.Click2Run" = Microsoft Office Klick-und-Los 2010
"PC-Kids Mathematik 2_is1" = PC-Kids Mathematik 2
"PCSUITE_SHREDDER_PRO_is1" = PCSUITE SHREDDER
"SolidWorks Installation Manager 20120-40400-1100-100" = SolidWorks 2012 x64 Edition SP04
"StarCraft II" = StarCraft II
"VLC media player" = VLC media player 2.0.4
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.00 (32-bit)
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 09.05.2013 14:44:16 | Computer Name = Ali-PC | Source = MemeoBackgroundService | ID = 0
Description = Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException:
 Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException:
 Manche oder alle Identitätsverweise konnten nicht übersetzt werden.    bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object
 data)    bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary
 properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)

  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties,
 IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)

  --- Ende der internen Ausnahmestapelüberwachung ---    bei System.RuntimeMethodHandle._InvokeConstructor(Object[]
 args, SignatureStruct& signature, IntPtr declaringType)    bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags
 invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)    bei System.RuntimeType.CreateInstanceImpl(BindingFlags
 bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)

  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry
 entry)    bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)    bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)    bei System.Runtime.Remoting.RemotingConfiguration.Configure(String
 filename, Boolean ensureSecurity)    bei RemoteServerService.MemeoBackgroundService.OnStart(String[]
 args)
 
Error - 09.05.2013 18:04:49 | Computer Name = Ali-PC | Source = MemeoBackgroundService | ID = 0
Description = Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException:
 Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException:
 Manche oder alle Identitätsverweise konnten nicht übersetzt werden.    bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object
 data)    bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary
 properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)

  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties,
 IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)

  --- Ende der internen Ausnahmestapelüberwachung ---    bei System.RuntimeMethodHandle._InvokeConstructor(Object[]
 args, SignatureStruct& signature, IntPtr declaringType)    bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags
 invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)    bei System.RuntimeType.CreateInstanceImpl(BindingFlags
 bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)

  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry
 entry)    bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)    bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)    bei System.Runtime.Remoting.RemotingConfiguration.Configure(String
 filename, Boolean ensureSecurity)    bei RemoteServerService.MemeoBackgroundService.OnStart(String[]
 args)
 
Error - 09.05.2013 18:36:24 | Computer Name = Ali-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: sbservice.exe, Version: 0.0.0.0,
Zeitstempel: 0x4f26b499  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
 Zeitstempel: 0x4ec49b8f  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0002e41b  ID des fehlerhaften
 Prozesses: 0x1190  Startzeit der fehlerhaften Anwendung: 0x01ce4d015df0dd34  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\Secure Banking\sbservice.exe  Pfad
 des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll  Berichtskennung: e06d5320-b8f8-11e2-ba7a-8c89a5e200c4
 
Error - 10.05.2013 06:35:51 | Computer Name = Ali-PC | Source = MemeoBackgroundService | ID = 0
Description = Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException:
 Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException:
 Manche oder alle Identitätsverweise konnten nicht übersetzt werden.    bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object
 data)    bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary
 properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)

  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties,
 IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)

  --- Ende der internen Ausnahmestapelüberwachung ---    bei System.RuntimeMethodHandle._InvokeConstructor(Object[]
 args, SignatureStruct& signature, IntPtr declaringType)    bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags
 invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)    bei System.RuntimeType.CreateInstanceImpl(BindingFlags
 bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)

  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry
 entry)    bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)    bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)    bei System.Runtime.Remoting.RemotingConfiguration.Configure(String
 filename, Boolean ensureSecurity)    bei RemoteServerService.MemeoBackgroundService.OnStart(String[]
 args)
 
Error - 10.05.2013 06:47:04 | Computer Name = Ali-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: sbservice.exe, Version: 0.0.0.0,
Zeitstempel: 0x4f26b499  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
 Zeitstempel: 0x4ec49b8f  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0002e41b  ID des fehlerhaften
 Prozesses: 0xdec  Startzeit der fehlerhaften Anwendung: 0x01ce4d6a5d2bd174  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\Secure Banking\sbservice.exe  Pfad
 des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll  Berichtskennung: f3709a35-b95e-11e2-92c4-8c89a5e200c4
 
Error - 10.05.2013 09:49:48 | Computer Name = Ali-PC | Source = Application Hang | ID = 1002
Description = Programm iTunes.exe, Version 11.0.2.26 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 19e8    Startzeit:
 01ce4d850d5551cb    Endzeit: 15    Anwendungspfad: C:\Program Files (x86)\iTunes\iTunes.exe

Berichts-ID:
 
 
Error - 10.05.2013 13:37:32 | Computer Name = Ali-PC | Source = MemeoBackgroundService | ID = 0
Description = Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException:
 Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException:
 Manche oder alle Identitätsverweise konnten nicht übersetzt werden.    bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object
 data)    bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary
 properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)

  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties,
 IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)

  --- Ende der internen Ausnahmestapelüberwachung ---    bei System.RuntimeMethodHandle._InvokeConstructor(Object[]
 args, SignatureStruct& signature, IntPtr declaringType)    bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags
 invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)    bei System.RuntimeType.CreateInstanceImpl(BindingFlags
 bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)

  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry
 entry)    bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)    bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)    bei System.Runtime.Remoting.RemotingConfiguration.Configure(String
 filename, Boolean ensureSecurity)    bei RemoteServerService.MemeoBackgroundService.OnStart(String[]
 args)
 
Error - 10.05.2013 14:08:18 | Computer Name = Ali-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: sbservice.exe, Version: 0.0.0.0,
Zeitstempel: 0x4f26b499  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
 Zeitstempel: 0x4ec49b8f  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0002e41b  ID des fehlerhaften
 Prozesses: 0x4e8  Startzeit der fehlerhaften Anwendung: 0x01ce4da89a925d71  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\Secure Banking\sbservice.exe  Pfad
 des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll  Berichtskennung: 97293d01-b99c-11e2-8f43-8c89a5e200c4
 
Error - 10.05.2013 14:38:14 | Computer Name = Ali-PC | Source = MemeoBackgroundService | ID = 0
Description = Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException:
 Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException:
 Manche oder alle Identitätsverweise konnten nicht übersetzt werden.    bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object
 data)    bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary
 properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)

  bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties,
 IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)

  --- Ende der internen Ausnahmestapelüberwachung ---    bei System.RuntimeMethodHandle._InvokeConstructor(Object[]
 args, SignatureStruct& signature, IntPtr declaringType)    bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags
 invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)    bei System.RuntimeType.CreateInstanceImpl(BindingFlags
 bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)

  bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry
 entry)    bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)    bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)" bei der Remotekonfiguration.  bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData
 configData, Boolean ensureSecurity)    bei System.Runtime.Remoting.RemotingConfiguration.Configure(String
 filename, Boolean ensureSecurity)    bei RemoteServerService.MemeoBackgroundService.OnStart(String[]
 args)
 
Error - 10.05.2013 14:44:00 | Computer Name = Ali-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: sbservice.exe, Version: 0.0.0.0,
Zeitstempel: 0x4f26b499  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
 Zeitstempel: 0x4ec49b8f  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0002e41b  ID des fehlerhaften
 Prozesses: 0x1198  Startzeit der fehlerhaften Anwendung: 0x01ce4dad9342f441  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\Secure Banking\sbservice.exe  Pfad
 des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll  Berichtskennung: 93fadc36-b9a1-11e2-8632-8c89a5e200c4
 
[ Cisco AnyConnect VPN Client Events ]
Error - 08.05.2013 12:45:36 | Computer Name = Ali-PC | Source = vpndownloader | ID = 67108866
Description = Function: HostInitSettings::setAttribute File: ..\Api\HostInitSettings.cpp
Line:
 363 Invoked Function: HostInitSettings::setAttribute Return Code: -33554423 (0xFE000009)
Description:
 GLOBAL_ERROR_UNEXPECTED Invalid preference ID or not handling attributes for element
 ClearSmartcardPin
 
Error - 08.05.2013 12:45:36 | Computer Name = Ali-PC | Source = vpndownloader | ID = 67108866
Description = Function: MSSaxErrorHandlerImpl::fatalError File: ..\Common\Xml\MSSaxErrorHandlerImpl.cpp
Line:
 31 Invoked Function: CVCMSSaxParser Return Code: -1072897499 (0xC00CE225) Description:
 WINDOWS_ERROR_CODE XML Parser fatal error: Fehler bei der Überprüfung. 
 
Error - 08.05.2013 12:45:37 | Computer Name = Ali-PC | Source = vpndownloader | ID = 67108866
Description = Function: CManifest::GetManifest File: .\Manifest.cpp Line: 236 Invoked
 Function: CManifestInfo Return Code: 0 (0x00000000) Description: Failed to init CManifestInfo

 
Error - 08.05.2013 12:45:37 | Computer Name = Ali-PC | Source = vpndownloader | ID = 67108866
Description = Function: CHash::HashFile File: ..\CommonCrypt\Hash.cpp Line: 244 Invoked
 Function: std::ifstream::open Return Code: -30408690 (0xFE30000E) Description: HASH_ERROR_IO

 
Error - 08.05.2013 12:45:37 | Computer Name = Ali-PC | Source = vpndownloader | ID = 67108866
Description = Function: CManifestInfo::VersionIsNewer File: .\ManifestInfo.cpp Line:
 1818 Invoked Function: CHash::HashFile Return Code: -30408690 (0xFE30000E) Description:
 HASH_ERROR_IO
 
Error - 08.05.2013 12:45:57 | Computer Name = Ali-PC | Source = vpnagent | ID = 67110872
Description = Failed Route change:  Action: DelRoute  Destination: 192.168.2.255  Netmask:
 255.255.255.255  Gateway: 192.168.2.103  Interface: 192.168.2.103  Metric: 256
 
Error - 08.05.2013 12:45:57 | Computer Name = Ali-PC | Source = vpnagent | ID = 67108866
Description = Function: CChangeRouteHelper::SetRouteTable File: .\ChangeRouteHelper.cpp
Line:
 244 Invoked Function: AddRouteChange Return Code: -33095666 (0xFE07000E) Description:
 ROUTETABLE_ERROR_DELETEIPFORWARDENTRY_FAILED
 
Error - 08.05.2013 12:45:57 | Computer Name = Ali-PC | Source = vpnagent | ID = 67110872
Description = Failed Route change:  Action: DelRoute  Destination: 192.168.2.255  Netmask:
 255.255.255.255  Gateway: 192.168.2.105  Interface: 192.168.2.105  Metric: 256
 
Error - 08.05.2013 12:45:57 | Computer Name = Ali-PC | Source = vpnagent | ID = 67108866
Description = Function: CChangeRouteHelper::SetRouteTable File: .\ChangeRouteHelper.cpp
Line:
 244 Invoked Function: AddRouteChange Return Code: -33095666 (0xFE07000E) Description:
 ROUTETABLE_ERROR_DELETEIPFORWARDENTRY_FAILED
 
Error - 08.05.2013 12:45:57 | Computer Name = Ali-PC | Source = vpnagent | ID = 67108866
Description = Function: fileExists File: .\Utility\sysutils.cpp Line: 500 Invoked Function:
 _tstat Return Code: 2 (0x00000002) Description: Das System kann die angegebene Datei
 nicht finden.  File: C:\ProgramData\Cisco\Cisco AnyConnect VPN Client\InitialFirewallConfig.wfw
Error:
 No such file or directory
 
[ System Events ]
Error - 05.05.2013 09:03:49 | Computer Name = Ali-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "IPsec-Richtlinien-Agent" wurde aufgrund folgenden Fehlers
 nicht gestartet:  %%1069
 
Error - 05.05.2013 09:03:51 | Computer Name = Ali-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Computerbrowser" wurde mit folgendem Fehler beendet:  %%1115
 
Error - 05.05.2013 09:03:52 | Computer Name = Ali-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Server" wurde mit folgendem Fehler beendet:  %%1062
 
Error - 07.05.2013 11:08:08 | Computer Name = Ali-PC | Source = Schannel | ID = 36888
Description = Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus
 lautet: 10.
 
Error - 07.05.2013 11:08:08 | Computer Name = Ali-PC | Source = Schannel | ID = 36888
Description = Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus
 lautet: 10.
 
Error - 07.05.2013 11:08:09 | Computer Name = Ali-PC | Source = Schannel | ID = 36888
Description = Es wurde eine schwerwiegende Warnung generiert: 10. Der interne Fehlerstatus
 lautet: 10.
 
Error - 07.05.2013 14:41:01 | Computer Name = Ali-PC | Source = DCOM | ID = 10016
Description =
 
Error - 08.05.2013 13:11:43 | Computer Name = Ali-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk4\DR7 gefunden.
 
Error - 08.05.2013 13:11:45 | Computer Name = Ali-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk4\DR7 gefunden.
 
Error - 08.05.2013 13:11:45 | Computer Name = Ali-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk4\DR7 gefunden.
 
 
< End of report >

--- --- ---

[/CODE]

rico89 10.05.2013 20:07

So hab jetzt beide Logfiles reingestellt :)

cosinus 10.05.2013 20:28

Dann bitte jetzt Combofix ausführen:

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


rico89 10.05.2013 23:21

ComboFix Lofile ausgeführt!!

Code:

ComboFix 13-05-10.03 - Ali 11.05.2013  0:12.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3561.1953 [GMT 2:00]
ausgeführt von:: c:\users\Ali\Downloads\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Ali\4.0
c:\users\Ali\AppData\Roaming\Ywiha
c:\users\Ali\AppData\Roaming\Ywiha\neick.exe
c:\windows\Installer\{F0559C5E-7912-4391-B1A0-6B975F0E5064}\SHCT_TRAY_PROGRAMG_A10D8603999C4E9488776EF2533C58C9.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-04-10 bis 2013-05-10  ))))))))))))))))))))))))))))))
.
.
2013-05-10 22:17 . 2013-05-10 22:17        --------        d-----w-        c:\users\Public\AppData\Local\temp
2013-05-10 22:17 . 2013-05-10 22:17        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-05-10 10:49 . 2013-05-10 10:49        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2013-05-10 10:49 . 2012-09-29 17:54        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2013-05-09 23:30 . 2013-05-09 23:30        --------        d-----w-        c:\program files\Enigma Software Group
2013-05-09 23:29 . 2013-05-10 18:36        --------        d-----w-        c:\windows\6B6C4C461B7E4A419E70ACFBB22B1D81.TMP
2013-05-09 23:29 . 2013-05-09 23:29        --------        d-----w-        c:\program files (x86)\Common Files\Wise Installation Wizard
2013-05-09 18:52 . 2013-05-10 19:04        --------        d-----w-        c:\users\Ali\AppData\Roaming\Ykma
2013-05-09 18:52 . 2013-05-09 18:52        --------        d-----w-        c:\users\Ali\AppData\Roaming\Idmol
2013-05-09 12:38 . 2013-05-09 12:38        --------        d-----w-        c:\program files (x86)\Microsoft CAPICOM 2.1.0.2
2013-05-08 17:07 . 2013-05-09 16:37        --------        d-----w-        c:\users\Ali\AppData\Local\TempSWBackupDirectory
2013-05-08 17:06 . 2013-05-08 17:06        --------        d-----w-        c:\users\Ali\AppData\Local\SolidWorks
2013-05-08 17:04 . 2013-05-08 17:04        --------        d-----w-        c:\programdata\SolidWorks Flow Simulation
2013-05-08 17:01 . 2013-05-08 17:04        --------        d-----w-        c:\program files\SolidWorks Corp
2013-05-08 17:01 . 2013-05-08 17:01        --------        d-----w-        c:\programdata\SolidWorks
2013-05-08 17:01 . 2013-05-08 17:01        --------        d-----w-        c:\program files (x86)\NVIDIA Corporation
2013-05-08 17:01 . 2013-05-08 17:01        --------        d-----w-        c:\program files\Common Files\Macrovision Shared
2013-05-08 17:00 . 2013-05-08 17:00        --------        d-----w-        c:\program files\Microsoft Visual Studio 8
2013-05-08 17:00 . 2013-05-08 17:00        --------        d-----w-        c:\program files (x86)\Microsoft Visual Studio 8
2013-05-08 16:59 . 2013-05-08 16:59        --------        d-----w-        c:\program files (x86)\MSECache
2013-05-08 16:59 . 2013-05-08 17:04        --------        d-----w-        C:\SolidWorks Data
2013-05-08 16:48 . 2013-05-08 16:48        --------        d-----w-        c:\users\Ali\AppData\Roaming\help_images_otherUI
2013-05-08 08:11 . 2013-05-08 08:11        --------        d-----w-        c:\program files (x86)\MSXML 4.0
2013-05-07 19:46 . 2013-05-08 17:04        --------        d-----w-        c:\programdata\DassaultSystemes
2013-05-07 19:46 . 2013-05-07 19:46        --------        d-----w-        c:\users\Ali\AppData\Roaming\DassaultSystemes
2013-05-07 19:46 . 2013-05-07 19:46        --------        d-----w-        c:\users\Ali\AppData\Local\DassaultSystemes
2013-05-07 19:46 . 2013-05-07 19:46        --------        d-----w-        c:\users\Ali\AppData\Roaming\EDrawings
2013-05-07 19:44 . 2013-05-07 19:44        --------        d-----w-        c:\programdata\FLEXnet
2013-05-07 19:43 . 2013-05-07 19:43        --------        d-----w-        c:\program files (x86)\Common Files\Macrovision Shared
2013-05-07 19:42 . 2013-05-08 17:02        --------        d-----w-        c:\program files (x86)\Common Files\SolidWorks Shared
2013-05-07 19:42 . 2013-05-08 17:02        --------        d-----w-        c:\program files\Common Files\SolidWorks Shared
2013-05-07 19:42 . 2013-05-07 19:42        --------        d-----w-        c:\program files (x86)\SolidWorks Corp
2013-05-07 19:29 . 2013-05-08 16:48        --------        d-----w-        c:\program files (x86)\Common Files\SolidWorks Installations-Manager
2013-05-07 19:27 . 2013-05-08 16:50        --------        d-----w-        c:\windows\SolidWorks
2013-05-07 19:27 . 2013-05-09 16:37        --------        d-----w-        c:\users\Ali\AppData\Roaming\SolidWorks
2013-05-07 13:48 . 2013-05-07 16:18        --------        d-----w-        c:\users\Ali\AppData\Roaming\Apple Computer
2013-05-07 13:47 . 2013-05-07 13:47        --------        d-----w-        c:\programdata\Apple
2013-05-07 12:54 . 2013-05-07 12:54        --------        d-----w-        c:\users\Ali\AppData\Roaming\redsn0w
2013-05-06 15:57 . 2013-05-06 15:57        --------        d-----w-        c:\program files (x86)\Secure Banking
2013-05-06 09:11 . 2013-05-06 09:11        83160        ----a-w-        c:\windows\system32\drivers\avnetflt.sys
2013-05-05 10:30 . 2013-05-05 10:30        --------        d-----w-        c:\users\Ali\AppData\Local\PDF24
2013-05-05 10:27 . 2013-05-05 10:27        --------        d-----w-        c:\users\Ali\AppData\Local\Cisco
2013-05-05 10:26 . 2013-05-05 10:26        --------        d-----w-        c:\programdata\Cisco
2013-05-05 10:26 . 2013-05-05 10:26        --------        d-----w-        c:\program files (x86)\Cisco
2013-05-03 14:53 . 2013-05-03 14:53        --------        d-----w-        c:\program files (x86)\PDF24
2013-05-03 14:52 . 2013-05-03 14:52        --------        d-----w-        c:\users\Ali\AppData\Local\Programs
2013-04-29 06:00 . 2013-04-29 06:00        --------        d-----w-        c:\users\Ali\.tfo4
2013-04-24 08:13 . 2013-04-12 14:45        1656680        ----a-w-        c:\windows\system32\drivers\ntfs.sys
2013-04-22 08:11 . 2013-04-22 08:11        --------        d-----w-        c:\users\Ali\AppData\Local\Apps
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-10 21:41 . 2011-07-18 20:31        72702784        ----a-w-        c:\windows\system32\MRT.exe
2013-03-30 16:43 . 2013-03-30 16:43        28600        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2013-03-30 16:43 . 2013-03-30 16:43        130016        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2013-03-30 16:43 . 2013-03-30 16:43        100712        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2013-03-19 06:04 . 2013-04-10 15:09        5550424        ----a-w-        c:\windows\system32\ntoskrnl.exe
2013-03-19 05:46 . 2013-04-10 15:09        43520        ----a-w-        c:\windows\system32\csrsrv.dll
2013-03-19 05:04 . 2013-04-10 15:09        3968856        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04 . 2013-04-10 15:09        3913560        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47 . 2013-04-10 15:09        6656        ----a-w-        c:\windows\SysWow64\apisetschema.dll
2013-03-19 03:06 . 2013-04-10 15:09        112640        ----a-w-        c:\windows\system32\smss.exe
2013-03-12 21:11 . 2011-12-01 21:26        73432        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-12 21:11 . 2008-01-01 07:31        693976        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-01 03:36 . 2013-04-10 15:09        3153408        ----a-w-        c:\windows\system32\win32k.sys
2013-02-22 06:57 . 2013-04-10 21:40        17817088        ----a-w-        c:\windows\system32\mshtml.dll
2013-02-22 06:29 . 2013-04-10 21:40        10925568        ----a-w-        c:\windows\system32\ieframe.dll
2013-02-22 06:27 . 2013-04-10 21:40        2312704        ----a-w-        c:\windows\system32\jscript9.dll
2013-02-22 06:21 . 2013-04-10 21:40        1346560        ----a-w-        c:\windows\system32\urlmon.dll
2013-02-22 06:20 . 2013-04-10 21:40        1392128        ----a-w-        c:\windows\system32\wininet.dll
2013-02-22 06:19 . 2013-04-10 21:40        1494528        ----a-w-        c:\windows\system32\inetcpl.cpl
2013-02-22 06:18 . 2013-04-10 21:40        237056        ----a-w-        c:\windows\system32\url.dll
2013-02-22 06:17 . 2013-04-10 21:40        85504        ----a-w-        c:\windows\system32\jsproxy.dll
2013-02-22 06:15 . 2013-04-10 21:40        173056        ----a-w-        c:\windows\system32\ieUnatt.exe
2013-02-22 06:15 . 2013-04-10 21:40        599040        ----a-w-        c:\windows\system32\vbscript.dll
2013-02-22 06:15 . 2013-04-10 21:40        816640        ----a-w-        c:\windows\system32\jscript.dll
2013-02-22 06:14 . 2013-04-10 21:40        729088        ----a-w-        c:\windows\system32\msfeeds.dll
2013-02-22 06:13 . 2013-04-10 21:40        2147840        ----a-w-        c:\windows\system32\iertutil.dll
2013-02-22 06:13 . 2013-04-10 21:40        96768        ----a-w-        c:\windows\system32\mshtmled.dll
2013-02-22 06:12 . 2013-04-10 21:40        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2013-02-22 06:09 . 2013-04-10 21:40        248320        ----a-w-        c:\windows\system32\ieui.dll
2013-02-22 03:46 . 2013-04-10 21:40        1800704        ----a-w-        c:\windows\SysWow64\jscript9.dll
2013-02-22 03:38 . 2013-04-10 21:40        1129472        ----a-w-        c:\windows\SysWow64\wininet.dll
2013-02-22 03:37 . 2013-04-10 21:40        1427968        ----a-w-        c:\windows\SysWow64\inetcpl.cpl
2013-02-22 03:34 . 2013-04-10 21:40        142848        ----a-w-        c:\windows\SysWow64\ieUnatt.exe
2013-02-22 03:34 . 2013-04-10 21:40        420864        ----a-w-        c:\windows\SysWow64\vbscript.dll
2013-02-22 03:31 . 2013-04-10 21:40        2382848        ----a-w-        c:\windows\SysWow64\mshtml.tlb
2013-02-15 06:08 . 2013-04-10 15:09        44032        ----a-w-        c:\windows\system32\tsgqec.dll
2013-02-15 06:06 . 2013-04-10 15:09        3717632        ----a-w-        c:\windows\system32\mstscax.dll
2013-02-15 06:02 . 2013-04-10 15:09        158720        ----a-w-        c:\windows\system32\aaclient.dll
2013-02-15 04:37 . 2013-04-10 15:09        3217408        ----a-w-        c:\windows\SysWow64\mstscax.dll
2013-02-15 04:34 . 2013-04-10 15:09        131584        ----a-w-        c:\windows\SysWow64\aaclient.dll
2013-02-15 03:25 . 2013-04-10 15:09        36864        ----a-w-        c:\windows\SysWow64\tsgqec.dll
2013-02-12 05:45 . 2013-03-14 06:58        135168        ----a-w-        c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45 . 2013-03-14 06:58        350208        ----a-w-        c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45 . 2013-03-14 06:58        308736        ----a-w-        c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45 . 2013-03-14 06:58        111104        ----a-w-        c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48 . 2013-03-14 06:58        474112        ----a-w-        c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48 . 2013-03-14 06:58        2176512        ----a-w-        c:\windows\apppatch\AcGenral.dll
2013-02-12 04:12 . 2013-03-26 10:04        19968        ----a-w-        c:\windows\system32\drivers\usb8023.sys
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{bb4c50c9-d7f0-48ef-a67c-daf6a86830e4}]
2010-11-21 03:24        297808        ----a-w-        c:\windows\System32\mscoree.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"Facebook Update"="c:\users\Ali\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2013-02-05 138096]
"SecureBanking"="c:\program files (x86)\Secure Banking\SecureBanking.exe" [2012-05-23 364544]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-03-29 630912]
"RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2011-03-30 87336]
"CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2012-04-14 111080]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-05-06 345312]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"PDFPrint"="c:\program files (x86)\PDF24\pdf24.exe" [2013-03-20 162856]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
watchmi tray.lnk - c:\windows\Installer\{F0559C5E-7912-4391-B1A0-6B975F0E5064}\SHCT_TRAY_PROGRAMG_A10D8603999C4E9488776EF2533C58C9.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-29 676936]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-02-28 161384]
R3 BrSerIb;Brother MFC Serial Interface Driver(WDM);c:\windows\system32\DRIVERS\BrSerIb.sys [2009-07-14 281088]
R3 BrUsbSIb;Brother MFC Serial USB Driver(WDM);c:\windows\system32\DRIVERS\BrUsbSIb.sys [2009-06-10 15360]
R3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2012-06-08 89192]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2013-05-08 1431888]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-29 25928]
R3 Remote Solver for Flow Simulation 2012;Remote Solver for Flow Simulation 2012;c:\program files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2012-04-09 114824]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-12-13 54784]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2010-09-23 129008]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 amd_sata;amd_sata;c:\windows\system32\drivers\amd_sata.sys [2011-12-12 82048]
S0 amd_xata;amd_xata;c:\windows\system32\drivers\amd_xata.sys [2011-12-12 42624]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-03-30 28600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-03-29 235520]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-03-29 361984]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2013-03-30 86752]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 CyberLink PowerDVD 10 MS Monitor Service;CyberLink PowerDVD 10 MS Monitor Service;c:\program files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [2011-04-13 70952]
S2 CyberLink PowerDVD 10 MS Service;CyberLink PowerDVD 10 MS Service;c:\program files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [2011-04-13 312616]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-29 399432]
S2 MemeoBackgroundService;MemeoBackgroundService;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe [2011-09-28 25824]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe [2011-06-10 641464]
S2 watchmi;watchmi service;c:\program files (x86)\watchmi\TvdService.exe [2012-01-31 70144]
S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys [2011-10-26 102528]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys [2011-10-26 219776]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-02-16 676968]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-11-25 694888]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2012-01-13 56448]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-10 14:56        1642448        ----a-w-        c:\program files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-05-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2008-01-01 21:11]
.
2013-05-09 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-732902274-989681646-235948354-1002Core.job
- c:\users\Ali\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-05 21:02]
.
2013-05-10 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-732902274-989681646-235948354-1002UA.job
- c:\users\Ali\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-05 21:02]
.
2013-05-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-14 10:41]
.
2013-05-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-14 10:41]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-03-13 12452968]
"MedionReminder"="c:\program files (x86)\CyberLink\PowerRecover\Reminder.exe" [2011-05-25 443688]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"MedionReminder"="c:\program files (x86)\CyberLink\PowerRecover\Reminder.exe" [2011-05-25 443688]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - LocalService
FontCache
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4
TCP: DhcpNameServer = 192.168.2.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-Suuse - c:\users\Ali\AppData\Roaming\Ywiha\neick.exe
Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-05-11  00:19:20
ComboFix-quarantined-files.txt  2013-05-10 22:19
.
Vor Suchlauf: 8 Verzeichnis(se), 874.545.836.032 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 874.810.728.448 Bytes frei
.
- - End Of File - - DF16D1604232F260F7E3A051C0507A35

--- --- ---

[/CODE]

cosinus 12.05.2013 19:42

Combofix-Skript
WARNUNG für die MITLESER:
Folgendes ComboFix Skript ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

  • Lösche die vorhandene Combofix.exe von deinem Desktop und lade das Programm von folgenden Download-Spiegel neu herunter: Link
  • Speichere es erneut auf dem Desktop (nicht woanders hin, das ist wichtig)!
  • Drücke die Windows + R Taste --> notepad (hinein schreiben) --> OK
  • Kopiere nun den Text aus der folgenden Codebox komplett in das leere Textdokument.
    Code:

    Folder::
    c:\users\Ali\AppData\Roaming\Ykma
    c:\users\Ali\AppData\Roaming\Idmol

    Solltest du deinen Benutzernamen z. B. durch "*****" unkenntlich gemacht haben, so füge an entsprechender Stelle deinen richtigen Benutzernamen ein. Andernfalls wird der Fix nicht funktionieren.
  • Speichere dies als CFScript.txt auf deinem Desktop.
  • Wichtig: Stelle deine Anti Viren Software temporär ab. Dies kann ComboFix nämlich bei der Arbeit behindern.
    Danach wieder anstellen nicht vergessen!
  • Schließe alle laufenden Programme damit ComboFix ungehindert arbeiten kann.
  • Ziehe CFScript.txt in die ComboFix.exe wie in diesem Bild:
  • Mache nichts am Computer, bewege nicht die Maus über das ComboFix-Fenster oder klicke in dieses hinein. Dies kann dazu führen, dass ComboFix sich aufhängt.
  • Wenn ComboFix fertig ist wird es ein Log erstellen: C:\ComboFix.txt
    Bitte füge es hier als Antwort (in CODE-Tags mit dem #-Button des Editors) ein.

Hinweis:
Suspect:: und Collect::
Falls im Skript diese Anweisungen enthalten sind, sollen Dateien zur Analyse eingeschickt werden. Es erscheint eine Message-Box, nachdem Combofix fertig ist. Klicke OK und folge den Aufforderungen/Anweisungen, um die Dateien hochzuladen. Teile mir unbedingt mit, ob der Upload geklappt hat!


rico89 14.05.2013 20:21

Ich hoffe so ist das richtig.


Code:

Combofix Logfile:

       
Code:

       
ComboFix 13-05-14.01 - Ali 14.05.2013  21:12:44.3.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.3561.1742 [GMT 2:00]
ausgeführt von:: c:\users\Ali\Downloads\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Ali\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Ali\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk
c:\users\Ali\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\rasphone.pbk
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-04-14 bis 2013-05-14  ))))))))))))))))))))))))))))))
.
.
2013-05-14 19:16 . 2013-05-14 19:16        --------        d-----w-        c:\users\Public\AppData\Local\temp
2013-05-14 19:16 . 2013-05-14 19:16        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-05-10 10:49 . 2013-05-10 10:49        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2013-05-10 10:49 . 2012-09-29 17:54        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2013-05-09 23:30 . 2013-05-09 23:30        --------        d-----w-        c:\program files\Enigma Software Group
2013-05-09 23:29 . 2013-05-10 18:36        --------        d-----w-        c:\windows\6B6C4C461B7E4A419E70ACFBB22B1D81.TMP
2013-05-09 23:29 . 2013-05-09 23:29        --------        d-----w-        c:\program files (x86)\Common Files\Wise Installation Wizard
2013-05-09 18:52 . 2013-05-10 19:04        --------        d-----w-        c:\users\Ali\AppData\Roaming\Ykma
2013-05-09 18:52 . 2013-05-09 18:52        --------        d-----w-        c:\users\Ali\AppData\Roaming\Idmol
2013-05-09 12:38 . 2013-05-09 12:38        --------        d-----w-        c:\program files (x86)\Microsoft CAPICOM 2.1.0.2
2013-05-08 17:07 . 2013-05-12 11:28        --------        d-----w-        c:\users\Ali\AppData\Local\TempSWBackupDirectory
2013-05-08 17:06 . 2013-05-08 17:06        --------        d-----w-        c:\users\Ali\AppData\Local\SolidWorks
2013-05-08 17:04 . 2013-05-08 17:04        --------        d-----w-        c:\programdata\SolidWorks Flow Simulation
2013-05-08 17:01 . 2013-05-08 17:04        --------        d-----w-        c:\program files\SolidWorks Corp
2013-05-08 17:01 . 2013-05-08 17:01        --------        d-----w-        c:\programdata\SolidWorks
2013-05-08 17:01 . 2013-05-08 17:01        --------        d-----w-        c:\program files (x86)\NVIDIA Corporation
2013-05-08 17:01 . 2013-05-08 17:01        --------        d-----w-        c:\program files\Common Files\Macrovision Shared
2013-05-08 17:00 . 2013-05-08 17:00        --------        d-----w-        c:\program files\Microsoft Visual Studio 8
2013-05-08 17:00 . 2013-05-08 17:00        --------        d-----w-        c:\program files (x86)\Microsoft Visual Studio 8
2013-05-08 16:59 . 2013-05-08 16:59        --------        d-----w-        c:\program files (x86)\MSECache
2013-05-08 16:59 . 2013-05-08 17:04        --------        d-----w-        C:\SolidWorks Data
2013-05-08 16:48 . 2013-05-08 16:48        --------        d-----w-        c:\users\Ali\AppData\Roaming\help_images_otherUI
2013-05-08 08:11 . 2013-05-08 08:11        --------        d-----w-        c:\program files (x86)\MSXML 4.0
2013-05-07 19:46 . 2013-05-08 17:04        --------        d-----w-        c:\programdata\DassaultSystemes
2013-05-07 19:46 . 2013-05-07 19:46        --------        d-----w-        c:\users\Ali\AppData\Roaming\DassaultSystemes
2013-05-07 19:46 . 2013-05-07 19:46        --------        d-----w-        c:\users\Ali\AppData\Local\DassaultSystemes
2013-05-07 19:46 . 2013-05-07 19:46        --------        d-----w-        c:\users\Ali\AppData\Roaming\EDrawings
2013-05-07 19:44 . 2013-05-07 19:44        --------        d-----w-        c:\programdata\FLEXnet
2013-05-07 19:43 . 2013-05-07 19:43        --------        d-----w-        c:\program files (x86)\Common Files\Macrovision Shared
2013-05-07 19:42 . 2013-05-08 17:02        --------        d-----w-        c:\program files (x86)\Common Files\SolidWorks Shared
2013-05-07 19:42 . 2013-05-08 17:02        --------        d-----w-        c:\program files\Common Files\SolidWorks Shared
2013-05-07 19:42 . 2013-05-07 19:42        --------        d-----w-        c:\program files (x86)\SolidWorks Corp
2013-05-07 19:29 . 2013-05-08 16:48        --------        d-----w-        c:\program files (x86)\Common Files\SolidWorks Installations-Manager
2013-05-07 19:27 . 2013-05-08 16:50        --------        d-----w-        c:\windows\SolidWorks
2013-05-07 19:27 . 2013-05-12 11:30        --------        d-----w-        c:\users\Ali\AppData\Roaming\SolidWorks
2013-05-07 13:48 . 2013-05-07 16:18        --------        d-----w-        c:\users\Ali\AppData\Roaming\Apple Computer
2013-05-07 13:47 . 2013-05-07 13:47        --------        d-----w-        c:\programdata\Apple
2013-05-07 12:54 . 2013-05-07 12:54        --------        d-----w-        c:\users\Ali\AppData\Roaming\redsn0w
2013-05-06 15:57 . 2013-05-06 15:57        --------        d-----w-        c:\program files (x86)\Secure Banking
2013-05-06 09:11 . 2013-05-06 09:11        83160        ----a-w-        c:\windows\system32\drivers\avnetflt.sys
2013-05-05 10:30 . 2013-05-05 10:30        --------        d-----w-        c:\users\Ali\AppData\Local\PDF24
2013-05-05 10:27 . 2013-05-05 10:27        --------        d-----w-        c:\users\Ali\AppData\Local\Cisco
2013-05-05 10:26 . 2013-05-05 10:26        --------        d-----w-        c:\programdata\Cisco
2013-05-05 10:26 . 2013-05-05 10:26        --------        d-----w-        c:\program files (x86)\Cisco
2013-05-03 14:53 . 2013-05-03 14:53        --------        d-----w-        c:\program files (x86)\PDF24
2013-05-03 14:52 . 2013-05-03 14:52        --------        d-----w-        c:\users\Ali\AppData\Local\Programs
2013-04-29 06:00 . 2013-04-29 06:00        --------        d-----w-        c:\users\Ali\.tfo4
2013-04-24 08:13 . 2013-04-12 14:45        1656680        ----a-w-        c:\windows\system32\drivers\ntfs.sys
2013-04-22 08:11 . 2013-04-22 08:11        --------        d-----w-        c:\users\Ali\AppData\Local\Apps
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-14 19:06 . 2011-12-01 21:26        71048        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-14 19:06 . 2008-01-01 07:31        692104        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2013-05-12 12:50 . 2011-03-29 01:36        22240        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-04-10 21:41 . 2011-07-18 20:31        72702784        ----a-w-        c:\windows\system32\MRT.exe
2013-03-30 16:43 . 2013-03-30 16:43        28600        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2013-03-30 16:43 . 2013-03-30 16:43        130016        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2013-03-30 16:43 . 2013-03-30 16:43        100712        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2013-03-19 06:04 . 2013-04-10 15:09        5550424        ----a-w-        c:\windows\system32\ntoskrnl.exe
2013-03-19 05:46 . 2013-04-10 15:09        43520        ----a-w-        c:\windows\system32\csrsrv.dll
2013-03-19 05:04 . 2013-04-10 15:09        3968856        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04 . 2013-04-10 15:09        3913560        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47 . 2013-04-10 15:09        6656        ----a-w-        c:\windows\SysWow64\apisetschema.dll
2013-03-19 03:06 . 2013-04-10 15:09        112640        ----a-w-        c:\windows\system32\smss.exe
2013-03-01 03:36 . 2013-04-10 15:09        3153408        ----a-w-        c:\windows\system32\win32k.sys
2013-02-22 06:57 . 2013-04-10 21:40        17817088        ----a-w-        c:\windows\system32\mshtml.dll
2013-02-22 06:29 . 2013-04-10 21:40        10925568        ----a-w-        c:\windows\system32\ieframe.dll
2013-02-22 06:27 . 2013-04-10 21:40        2312704        ----a-w-        c:\windows\system32\jscript9.dll
2013-02-22 06:21 . 2013-04-10 21:40        1346560        ----a-w-        c:\windows\system32\urlmon.dll
2013-02-22 06:20 . 2013-04-10 21:40        1392128        ----a-w-        c:\windows\system32\wininet.dll
2013-02-22 06:19 . 2013-04-10 21:40        1494528        ----a-w-        c:\windows\system32\inetcpl.cpl
2013-02-22 06:18 . 2013-04-10 21:40        237056        ----a-w-        c:\windows\system32\url.dll
2013-02-22 06:17 . 2013-04-10 21:40        85504        ----a-w-        c:\windows\system32\jsproxy.dll
2013-02-22 06:15 . 2013-04-10 21:40        173056        ----a-w-        c:\windows\system32\ieUnatt.exe
2013-02-22 06:15 . 2013-04-10 21:40        599040        ----a-w-        c:\windows\system32\vbscript.dll
2013-02-22 06:15 . 2013-04-10 21:40        816640        ----a-w-        c:\windows\system32\jscript.dll
2013-02-22 06:14 . 2013-04-10 21:40        729088        ----a-w-        c:\windows\system32\msfeeds.dll
2013-02-22 06:13 . 2013-04-10 21:40        2147840        ----a-w-        c:\windows\system32\iertutil.dll
2013-02-22 06:13 . 2013-04-10 21:40        96768        ----a-w-        c:\windows\system32\mshtmled.dll
2013-02-22 06:12 . 2013-04-10 21:40        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2013-02-22 06:09 . 2013-04-10 21:40        248320        ----a-w-        c:\windows\system32\ieui.dll
2013-02-22 03:46 . 2013-04-10 21:40        1800704        ----a-w-        c:\windows\SysWow64\jscript9.dll
2013-02-22 03:38 . 2013-04-10 21:40        1129472        ----a-w-        c:\windows\SysWow64\wininet.dll
2013-02-22 03:37 . 2013-04-10 21:40        1427968        ----a-w-        c:\windows\SysWow64\inetcpl.cpl
2013-02-22 03:34 . 2013-04-10 21:40        142848        ----a-w-        c:\windows\SysWow64\ieUnatt.exe
2013-02-22 03:34 . 2013-04-10 21:40        420864        ----a-w-        c:\windows\SysWow64\vbscript.dll
2013-02-22 03:31 . 2013-04-10 21:40        2382848        ----a-w-        c:\windows\SysWow64\mshtml.tlb
2013-02-15 06:08 . 2013-04-10 15:09        44032        ----a-w-        c:\windows\system32\tsgqec.dll
2013-02-15 06:06 . 2013-04-10 15:09        3717632        ----a-w-        c:\windows\system32\mstscax.dll
2013-02-15 06:02 . 2013-04-10 15:09        158720        ----a-w-        c:\windows\system32\aaclient.dll
2013-02-15 04:37 . 2013-04-10 15:09        3217408        ----a-w-        c:\windows\SysWow64\mstscax.dll
2013-02-15 04:34 . 2013-04-10 15:09        131584        ----a-w-        c:\windows\SysWow64\aaclient.dll
2013-02-15 03:25 . 2013-04-10 15:09        36864        ----a-w-        c:\windows\SysWow64\tsgqec.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{bb4c50c9-d7f0-48ef-a67c-daf6a86830e4}]
2010-11-21 03:24        297808        ----a-w-        c:\windows\System32\mscoree.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"Facebook Update"="c:\users\Ali\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2013-02-05 138096]
"SecureBanking"="c:\program files (x86)\Secure Banking\SecureBanking.exe" [2012-05-23 364544]
"RESTART_STICKY_NOTES"="c:\windows\system32\StikyNot.exe" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-03-29 630912]
"RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2011-03-30 87336]
"CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2012-04-14 111080]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-05-06 345312]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"PDFPrint"="c:\program files (x86)\PDF24\pdf24.exe" [2013-03-20 162856]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
watchmi tray.lnk - c:\windows\Installer\{F0559C5E-7912-4391-B1A0-6B975F0E5064}\SHCT_TRAY_PROGRAMG_A10D8603999C4E9488776EF2533C58C9.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-02-28 161384]
R3 BrSerIb;Brother MFC Serial Interface Driver(WDM);c:\windows\system32\DRIVERS\BrSerIb.sys [2009-07-14 281088]
R3 BrUsbSIb;Brother MFC Serial USB Driver(WDM);c:\windows\system32\DRIVERS\BrUsbSIb.sys [2009-06-10 15360]
R3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2012-06-08 89192]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2013-05-08 1431888]
R3 Remote Solver for Flow Simulation 2012;Remote Solver for Flow Simulation 2012;c:\program files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2012-04-09 114824]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-12-13 54784]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2010-09-23 129008]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 amd_sata;amd_sata;c:\windows\system32\drivers\amd_sata.sys [2011-12-12 82048]
S0 amd_xata;amd_xata;c:\windows\system32\drivers\amd_xata.sys [2011-12-12 42624]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-03-30 28600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-03-29 235520]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-03-29 361984]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2013-03-30 86752]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 CyberLink PowerDVD 10 MS Monitor Service;CyberLink PowerDVD 10 MS Monitor Service;c:\program files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [2011-04-13 70952]
S2 CyberLink PowerDVD 10 MS Service;CyberLink PowerDVD 10 MS Service;c:\program files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [2011-04-13 312616]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-29 399432]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-29 676936]
S2 MemeoBackgroundService;MemeoBackgroundService;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe [2011-09-28 25824]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe [2011-06-10 641464]
S2 watchmi;watchmi service;c:\program files (x86)\watchmi\TvdService.exe [2012-01-31 70144]
S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys [2011-10-26 102528]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys [2011-10-26 219776]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-29 25928]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-02-16 676968]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-11-25 694888]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2012-01-13 56448]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-10 14:56        1642448        ----a-w-        c:\program files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-05-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2008-01-01 19:06]
.
2013-05-09 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-732902274-989681646-235948354-1002Core.job
- c:\users\Ali\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-05 21:02]
.
2013-05-13 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-732902274-989681646-235948354-1002UA.job
- c:\users\Ali\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-05 21:02]
.
2013-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-14 10:41]
.
2013-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-14 10:41]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-03-13 12452968]
"MedionReminder"="c:\program files (x86)\CyberLink\PowerRecover\Reminder.exe" [2011-05-25 443688]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"MedionReminder"="c:\program files (x86)\CyberLink\PowerRecover\Reminder.exe" [2011-05-25 443688]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - LocalService
FontCache
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4
TCP: DhcpNameServer = 192.168.2.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-05-14  21:18:05
ComboFix-quarantined-files.txt  2013-05-14 19:18
ComboFix2.txt  2013-05-14 19:03
ComboFix3.txt  2013-05-10 22:19
.
Vor Suchlauf: 10 Verzeichnis(se), 875.163.627.520 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 875.104.079.872 Bytes frei
.
- - End Of File - - 3095074B5777947748586F982BA336F0


--- --- ---


cosinus 15.05.2013 10:27

Rootkitscan mit GMER

Bitte lade dir GMER Rootkit Scanner GMER herunter: (Dateiname zufällig)
  • Schließe alle anderen Programme, deaktiviere deinen Virenscanner und trenne den Rechner vom Internet bevor du GMER startest.
  • Sollte sich nach dem Start ein Fenster mit folgender Warnung öffnen:
    WARNING !!!
    GMER has found system modification, which might have been caused by ROOTKIT activity.
    Do you want to fully scan your system ?
    Unbedingt auf "No" klicken.
  • Entferne rechts den Haken bei: IAT/EAT und Show All
  • Setze den Haken bei Quickscan und entferne ihn bei allen anderen Laufwerken.
  • Starte den Scan mit "Scan".
  • Mache nichts am Computer während der Scan läuft.
  • Wenn der Scan fertig ist klicke auf Save und speichere die Logfile unter Gmer.txt auf deinem Desktop. Mit "Ok" wird GMER beendet.
Antiviren-Programm und sonstige Scanner wieder einschalten, bevor Du ins Netz gehst!


Tauchen Probleme auf?
  • Probiere alternativ den abgesicherten Modus.
  • Erhältst du einen Bluescreen, dann entferne den Haken vor Devices.


Anschließend bitte MBAR ausführen:

Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

rico89 16.05.2013 20:36

Code:

Malwarebytes Anti-Rootkit BETA 1.05.0.1001
www.malwarebytes.org

Database version: v2013.05.16.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Ali :: ALI-PC [administrator]

16.05.2013 21:33:42
mbar-log-2013-05-16 (21-33-42).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 31211
Time elapsed: 6 minute(s), 25 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


cosinus 16.05.2013 21:23

Wo ist das Log von GMER?

rico89 16.05.2013 22:25

Upss hier isser

Code:

GMER Logfile:

       
Code:

       
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-05-16 21:19:25
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000063 ST1000DM rev.CC4B 931,51GB
Running: om9469wr.exe; Driver: C:\Users\Ali\AppData\Local\Temp\pftdrpow.sys


---- Kernel code sections - GMER 2.1 ----

INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560                                                                                                                                     fffff800041be000 45 bytes [43, F0, C7, 45, FC, FF, FF, ...]
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 606                                                                                                                                     fffff800041be02e 35 bytes [59, 5F, 5E, 5B, 8B, E5, 5D, ...]

---- User code sections - GMER 2.1 ----

.text     C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe[1984] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                            0000000076ae1465 2 bytes [AE, 76]
.text     C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe[1984] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                           0000000076ae14bb 2 bytes [AE, 76]
.text     ...                                                                                                                                                                                                    * 2
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[1404] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                   0000000076ae1465 2 bytes [AE, 76]
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[1404] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                  0000000076ae14bb 2 bytes [AE, 76]
.text     ...                                                                                                                                                                                                    * 2
.text     C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe[4384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                 0000000076ae1465 2 bytes [AE, 76]
.text     C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe[4384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                0000000076ae14bb 2 bytes [AE, 76]
.text     ...                                                                                                                                                                                                    * 2
.text     C:\Program Files (x86)\Secure Banking\sbservice.exe[4716] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69                                                                                      0000000076ae1465 2 bytes [AE, 76]
.text     C:\Program Files (x86)\Secure Banking\sbservice.exe[4716] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155                                                                                     0000000076ae14bb 2 bytes [AE, 76]
.text     ...                                                                                                                                                                                                    * 2
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\syswow64\USER32.dll!EnableWindow                                                                                                0000000075322da4 5 bytes JMP 0000000169139ebc
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamW                                                                                     000000007533cbf3 5 bytes JMP 00000001692891b6
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\syswow64\USER32.dll!DialogBoxParamW                                                                                             000000007533cfca 5 bytes JMP 000000016909189b
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\syswow64\USER32.dll!DialogBoxParamA                                                                                             000000007535cb0c 5 bytes JMP 0000000169289151
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamA                                                                                     000000007535ce64 5 bytes JMP 000000016928921b
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectA                                                                                         000000007536fbd1 5 bytes JMP 00000001692890d8
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectW                                                                                         000000007536fc9d 5 bytes JMP 000000016928905f
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\syswow64\USER32.dll!MessageBoxExA                                                                                               000000007536fcd6 5 bytes JMP 0000000169288ffb
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\syswow64\USER32.dll!MessageBoxExW                                                                                               000000007536fcfa 5 bytes JMP 0000000169288f97
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\syswow64\OLEAUT32.dll!OleCreatePropertyFrameIndirect                                                                            0000000076c693ec 5 bytes JMP 00000001692893d0
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                    0000000076ae1465 2 bytes [AE, 76]
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                   0000000076ae14bb 2 bytes [AE, 76]
.text     ...                                                                                                                                                                                                    * 2
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll!PropertySheetW  000000006f65388e 5 bytes JMP 0000000169289280
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll!PropertySheet   000000006f6f7922 5 bytes JMP 0000000169289328
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4536] C:\Windows\syswow64\comdlg32.dll!PageSetupDlgW                                                                                             0000000075762694 5 bytes JMP 00000001692895c8
?         C:\Windows\system32\mssprxy.dll [4536] entry point in ".rdata" section                                                                                                                                 0000000073aa71e6
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\syswow64\USER32.dll!EnableWindow                                                                                                0000000075322da4 5 bytes JMP 0000000169139ebc
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamW                                                                                     000000007533cbf3 5 bytes JMP 00000001692891b6
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\syswow64\USER32.dll!DialogBoxParamW                                                                                             000000007533cfca 5 bytes JMP 000000016909189b
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\syswow64\USER32.dll!DialogBoxParamA                                                                                             000000007535cb0c 5 bytes JMP 0000000169289151
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamA                                                                                     000000007535ce64 5 bytes JMP 000000016928921b
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectA                                                                                         000000007536fbd1 5 bytes JMP 00000001692890d8
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectW                                                                                         000000007536fc9d 5 bytes JMP 000000016928905f
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\syswow64\USER32.dll!MessageBoxExA                                                                                               000000007536fcd6 5 bytes JMP 0000000169288ffb
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\syswow64\USER32.dll!MessageBoxExW                                                                                               000000007536fcfa 5 bytes JMP 0000000169288f97
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\syswow64\OLEAUT32.dll!OleCreatePropertyFrameIndirect                                                                            0000000076c693ec 5 bytes JMP 00000001692893d0
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                    0000000076ae1465 2 bytes [AE, 76]
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                   0000000076ae14bb 2 bytes [AE, 76]
.text     ...                                                                                                                                                                                                    * 2
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll!PropertySheetW  000000006f65388e 5 bytes JMP 0000000169289280
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll!PropertySheet   000000006f6f7922 5 bytes JMP 0000000169289328
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4368] C:\Windows\syswow64\comdlg32.dll!PageSetupDlgW                                                                                             0000000075762694 5 bytes JMP 00000001692895c8
?         C:\Windows\system32\mssprxy.dll [4368] entry point in ".rdata" section                                                                                                                                 0000000073aa71e6
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W                                                                                         0000000077a325fd 6 bytes JMP 0000000169158054
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A                                                                                         0000000077a42a63 6 bytes JMP 00000001690f980d
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\kernel32.dll!CreateThread                                                                                              00000000757e34b5 5 bytes JMP 00000001690f75e3
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                                             0000000075318a29 5 bytes JMP 00000001691603df
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!CreateWindowExA                                                                                             000000007531d22e 5 bytes JMP 0000000169103643
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!GetKeyState                                                                                                 000000007532291f 5 bytes JMP 00000001690ddda7
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!EnableWindow                                                                                                0000000075322da4 5 bytes JMP 0000000169139ebc
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!CallNextHookEx                                                                                              0000000075326285 5 bytes JMP 0000000169157ff1
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                                                           0000000075327603 5 bytes JMP 00000001691325b4
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!CreateDialogIndirectParamA                                                                                  000000007532b029 5 bytes JMP 0000000169289558
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!CreateDialogIndirectParamW                                                                                  000000007532c63e 5 bytes JMP 0000000169289590
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!IsDialogMessage                                                                                             00000000753350ed 5 bytes JMP 0000000169289c52
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!CreateDialogParamA                                                                                          0000000075335246 5 bytes JMP 00000001692894e8
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!EndDialog                                                                                                   000000007533b99c 5 bytes JMP 0000000169289f26
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!IsDialogMessageW                                                                                            000000007533c701 5 bytes JMP 0000000169289c7a
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamW                                                                                     000000007533cbf3 5 bytes JMP 00000001692891b6
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!DialogBoxParamW                                                                                             000000007533cfca 5 bytes JMP 000000016909189b
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                                                            000000007533eb96 5 bytes JMP 00000001690ddecd
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx                                                                                         000000007533f52b 5 bytes JMP 000000016917ed14
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!SendInput                                                                                                   000000007533ff4a 5 bytes JMP 000000016928a519
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!CreateDialogParamW                                                                                          00000000753410dc 5 bytes JMP 0000000169289520
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!SetKeyboardState                                                                                            00000000753414b2 5 bytes JMP 000000016928a571
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!SetCursorPos                                                                                                0000000075359cfd 5 bytes JMP 000000016928a5f2
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!DialogBoxParamA                                                                                             000000007535cb0c 5 bytes JMP 0000000169289151
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamA                                                                                     000000007535ce64 5 bytes JMP 000000016928921b
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectA                                                                                         000000007536fbd1 5 bytes JMP 00000001692890d8
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectW                                                                                         000000007536fc9d 5 bytes JMP 000000016928905f
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!MessageBoxExA                                                                                               000000007536fcd6 5 bytes JMP 0000000169288ffb
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!MessageBoxExW                                                                                               000000007536fcfa 5 bytes JMP 0000000169288f97
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\USER32.dll!keybd_event                                                                                                 00000000753702bf 5 bytes JMP 000000016928a4d6
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\ole32.dll!OleLoadFromStream                                                                                            0000000075946143 5 bytes JMP 0000000169289984
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\OLEAUT32.dll!SysFreeString                                                                                             0000000076c03e59 5 bytes JMP 0000000169289a7c
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\OLEAUT32.dll!VariantClear                                                                                              0000000076c03eae 5 bytes JMP 0000000169289afa
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\OLEAUT32.dll!SysAllocStringByteLen                                                                                     0000000076c04731 5 bytes JMP 00000001692899ee
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\OLEAUT32.dll!VariantChangeType                                                                                         0000000076c05dee 5 bytes JMP 0000000169289a9a
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\OLEAUT32.dll!OleCreatePropertyFrameIndirect                                                                            0000000076c693ec 5 bytes JMP 00000001692893d0
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                    0000000076ae1465 2 bytes [AE, 76]
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                   0000000076ae14bb 2 bytes [AE, 76]
.text     ...                                                                                                                                                                                                    * 2
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll!PropertySheetW  000000006f65388e 5 bytes JMP 0000000169289280
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll!PropertySheet   000000006f6f7922 5 bytes JMP 0000000169289328
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\comdlg32.dll!PrintDlgW                                                                                                 00000000757533a3 5 bytes JMP 000000016928966c
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\comdlg32.dll!PageSetupDlgW                                                                                             0000000075762694 5 bytes JMP 00000001692895c8
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[4596] C:\Windows\syswow64\comdlg32.dll!PrintDlgA                                                                                                 000000007576e8ff 5 bytes JMP 0000000169289738
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W                                                                                         0000000077a325fd 6 bytes JMP 0000000169158054
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A                                                                                         0000000077a42a63 6 bytes JMP 00000001690f980d
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\kernel32.dll!CreateThread                                                                                              00000000757e34b5 5 bytes JMP 00000001690f75e3
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                                             0000000075318a29 5 bytes JMP 00000001691603df
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!CreateWindowExA                                                                                             000000007531d22e 5 bytes JMP 0000000169103643
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!GetKeyState                                                                                                 000000007532291f 5 bytes JMP 00000001690ddda7
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!EnableWindow                                                                                                0000000075322da4 5 bytes JMP 0000000169139ebc
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!CallNextHookEx                                                                                              0000000075326285 5 bytes JMP 0000000169157ff1
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                                                           0000000075327603 5 bytes JMP 00000001691325b4
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!CreateDialogIndirectParamA                                                                                  000000007532b029 5 bytes JMP 0000000169289558
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!CreateDialogIndirectParamW                                                                                  000000007532c63e 5 bytes JMP 0000000169289590
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!IsDialogMessage                                                                                             00000000753350ed 5 bytes JMP 0000000169289c52
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!CreateDialogParamA                                                                                          0000000075335246 5 bytes JMP 00000001692894e8
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!EndDialog                                                                                                   000000007533b99c 5 bytes JMP 0000000169289f26
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!IsDialogMessageW                                                                                            000000007533c701 5 bytes JMP 0000000169289c7a
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamW                                                                                     000000007533cbf3 5 bytes JMP 00000001692891b6
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!DialogBoxParamW                                                                                             000000007533cfca 5 bytes JMP 000000016909189b
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                                                            000000007533eb96 5 bytes JMP 00000001690ddecd
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx                                                                                         000000007533f52b 5 bytes JMP 000000016917ed14
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!SendInput                                                                                                   000000007533ff4a 5 bytes JMP 000000016928a519
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!CreateDialogParamW                                                                                          00000000753410dc 5 bytes JMP 0000000169289520
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!SetKeyboardState                                                                                            00000000753414b2 5 bytes JMP 000000016928a571
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!SetCursorPos                                                                                                0000000075359cfd 5 bytes JMP 000000016928a5f2
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!DialogBoxParamA                                                                                             000000007535cb0c 5 bytes JMP 0000000169289151
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamA                                                                                     000000007535ce64 5 bytes JMP 000000016928921b
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectA                                                                                         000000007536fbd1 5 bytes JMP 00000001692890d8
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectW                                                                                         000000007536fc9d 5 bytes JMP 000000016928905f
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!MessageBoxExA                                                                                               000000007536fcd6 5 bytes JMP 0000000169288ffb
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!MessageBoxExW                                                                                               000000007536fcfa 5 bytes JMP 0000000169288f97
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\USER32.dll!keybd_event                                                                                                 00000000753702bf 5 bytes JMP 000000016928a4d6
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\ole32.dll!OleLoadFromStream                                                                                            0000000075946143 5 bytes JMP 0000000169289984
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\OLEAUT32.dll!SysFreeString                                                                                             0000000076c03e59 5 bytes JMP 0000000169289a7c
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\OLEAUT32.dll!VariantClear                                                                                              0000000076c03eae 5 bytes JMP 0000000169289afa
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\OLEAUT32.dll!SysAllocStringByteLen                                                                                     0000000076c04731 5 bytes JMP 00000001692899ee
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\OLEAUT32.dll!VariantChangeType                                                                                         0000000076c05dee 5 bytes JMP 0000000169289a9a
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\OLEAUT32.dll!OleCreatePropertyFrameIndirect                                                                            0000000076c693ec 5 bytes JMP 00000001692893d0
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                    0000000076ae1465 2 bytes [AE, 76]
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                   0000000076ae14bb 2 bytes [AE, 76]
.text     ...                                                                                                                                                                                                    * 2
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll!PropertySheetW  000000006f65388e 5 bytes JMP 0000000169289280
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll!PropertySheet   000000006f6f7922 5 bytes JMP 0000000169289328
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\comdlg32.dll!PrintDlgW                                                                                                 00000000757533a3 5 bytes JMP 000000016928966c
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\comdlg32.dll!PageSetupDlgW                                                                                             0000000075762694 5 bytes JMP 00000001692895c8
.text     C:\Program Files (x86)\Internet Explorer\iexplore.exe[5880] C:\Windows\syswow64\comdlg32.dll!PrintDlgA                                                                                                 000000007576e8ff 5 bytes JMP 0000000169289738
.text     C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_7_700_202_ActiveX.exe[5888] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                  0000000076ae1465 2 bytes [AE, 76]
.text     C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_7_700_202_ActiveX.exe[5888] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                 0000000076ae14bb 2 bytes [AE, 76]
.text     ...                                                                                                                                                                                                    * 2

---- Threads - GMER 2.1 ----

Thread    C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [5836:2508]                                                                                                                                 0000000077a53e45
Thread    C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [5836:3944]                                                                                                                                 0000000077a53e45
Thread    C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [5836:3564]                                                                                                                                 0000000076837587
Thread    C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [5836:3568]                                                                                                                                 0000000063e10cb3
Thread    C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [5836:5292]                                                                                                                                 0000000077a52e25

---- EOF - GMER 2.1 ----


--- --- ---


cosinus 16.05.2013 22:31

aswMBR

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).




TDSS-Killer

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

rico89 17.05.2013 17:10

Ok hier erstmal der Log zu aswMBR

Code:

aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-05-17 17:50:50
-----------------------------
17:50:50.685    OS Version: Windows x64 6.1.7601 Service Pack 1
17:50:50.685    Number of processors: 4 586 0x1001
17:50:50.685    ComputerName: ALI-PC  UserName: Ali
17:50:51.730    Initialize success
17:53:15.733    AVAST engine defs: 13051700
17:53:25.421    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000063
17:53:25.437    Disk 0 Vendor: ST1000DM CC4B Size: 953869MB BusType: 11
17:53:25.546    Disk 0 MBR read successfully
17:53:25.546    Disk 0 MBR scan
17:53:25.561    Disk 0 Windows 7 default MBR code
17:53:25.561    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
17:53:25.577    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS      901543 MB offset 206848
17:53:25.608    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        51200 MB offset 1846566912
17:53:25.671    Disk 0 Partition 4 00    12  Compaq diag NTFS        1024 MB offset 1951424512
17:53:25.702    Disk 0 scanning C:\Windows\system32\drivers
17:53:39.118    Service scanning
17:54:03.189    Modules scanning
17:54:03.189    Disk 0 trace - called modules:
17:54:03.220    ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
17:54:03.235    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800501f060]
17:54:03.235    3 CLASSPNP.SYS[fffff880015ad43f] -> nt!IofCallDriver -> [0xfffffa8003ff1ac0]
17:54:03.251    5 amd_xata.sys[fffff880010b4d00] -> nt!IofCallDriver -> \Device\00000063[0xfffffa8004d47060]
17:54:04.281    AVAST engine scan C:\Windows
17:54:07.182    AVAST engine scan C:\Windows\system32
17:57:19.593    AVAST engine scan C:\Windows\system32\drivers
17:57:31.730    AVAST engine scan C:\Users\Ali
18:02:38.785    AVAST engine scan C:\ProgramData
18:04:47.035    Scan finished successfully
18:05:00.124    Disk 0 MBR has been saved successfully to "C:\Users\Ali\Desktop\MBR.dat"
18:05:00.124    The log file has been saved successfully to "C:\Users\Ali\Desktop\aswMBR.txt"



Dann noch der Log zu TDSS Killer, wurden allerdings wohl nichts gefunden.


Code:

18:07:49.0471 5640  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
18:07:49.0986 5640  ============================================================
18:07:49.0986 5640  Current date / time: 2013/05/17 18:07:49.0986
18:07:49.0986 5640  SystemInfo:
18:07:49.0986 5640 
18:07:49.0986 5640  OS Version: 6.1.7601 ServicePack: 1.0
18:07:49.0986 5640  Product type: Workstation
18:07:49.0986 5640  ComputerName: ALI-PC
18:07:49.0986 5640  UserName: Ali
18:07:49.0986 5640  Windows directory: C:\Windows
18:07:49.0986 5640  System windows directory: C:\Windows
18:07:49.0986 5640  Running under WOW64
18:07:49.0986 5640  Processor architecture: Intel x64
18:07:49.0986 5640  Number of processors: 4
18:07:49.0986 5640  Page size: 0x1000
18:07:49.0986 5640  Boot type: Normal boot
18:07:49.0986 5640  ============================================================
18:07:50.0391 5640  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
18:07:50.0423 5640  ============================================================
18:07:50.0423 5640  \Device\Harddisk0\DR0:
18:07:50.0423 5640  MBR partitions:
18:07:50.0423 5640  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
18:07:50.0423 5640  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x6E0D3800
18:07:50.0423 5640  \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x6E106000, BlocksNum 0x6400000
18:07:50.0423 5640  ============================================================
18:07:50.0454 5640  C: <-> \Device\Harddisk0\DR0\Partition2
18:07:50.0485 5640  D: <-> \Device\Harddisk0\DR0\Partition3
18:07:50.0485 5640  ============================================================
18:07:50.0485 5640  Initialize success
18:07:50.0485 5640  ============================================================
18:07:52.0170 5744  ============================================================
18:07:52.0170 5744  Scan started
18:07:52.0170 5744  Mode: Manual;
18:07:52.0170 5744  ============================================================
18:07:52.0310 5744  ================ Scan system memory ========================
18:07:52.0310 5744  Scan interrupted by user!
18:07:52.0310 5744  ================ Scan services =============================
18:07:52.0326 5744  Scan interrupted by user!
18:07:52.0326 5744  ================ Scan global ===============================
18:07:52.0326 5744  Scan interrupted by user!
18:07:52.0326 5744  ================ Scan MBR ==================================
18:07:52.0326 5744  Scan interrupted by user!
18:07:52.0326 5744  ================ Scan VBR ==================================
18:07:52.0326 5744  Scan interrupted by user!
18:07:52.0326 5744  ============================================================
18:07:52.0326 5744  Scan finished
18:07:52.0326 5744  ============================================================
18:07:52.0326 5440  Detected object count: 0
18:07:52.0326 5440  Actual detected object count: 0
18:07:56.0741 3048  ============================================================
18:07:56.0741 3048  Scan started
18:07:56.0741 3048  Mode: Manual;
18:07:56.0741 3048  ============================================================
18:07:56.0865 3048  ================ Scan system memory ========================
18:07:56.0865 3048  System memory - ok
18:07:56.0865 3048  ================ Scan services =============================
18:07:56.0959 3048  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
18:07:56.0959 3048  1394ohci - ok
18:07:56.0990 3048  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
18:07:56.0990 3048  ACPI - ok
18:07:57.0006 3048  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi        C:\Windows\system32\drivers\acpipmi.sys
18:07:57.0006 3048  AcpiPmi - ok
18:07:57.0084 3048  [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
18:07:57.0084 3048  AdobeARMservice - ok
18:07:57.0193 3048  [ F040037B149FD0F5A5044AE563390FA7 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
18:07:57.0193 3048  AdobeFlashPlayerUpdateSvc - ok
18:07:57.0224 3048  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
18:07:57.0224 3048  adp94xx - ok
18:07:57.0240 3048  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci        C:\Windows\system32\drivers\adpahci.sys
18:07:57.0255 3048  adpahci - ok
18:07:57.0271 3048  [ E109549C90F62FB570B9540C4B148E54 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
18:07:57.0271 3048  adpu320 - ok
18:07:57.0287 3048  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
18:07:57.0302 3048  AeLookupSvc - ok
18:07:57.0333 3048  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD            C:\Windows\system32\drivers\afd.sys
18:07:57.0333 3048  AFD - ok
18:07:57.0365 3048  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\Windows\system32\drivers\agp440.sys
18:07:57.0365 3048  agp440 - ok
18:07:57.0380 3048  [ 3290D6946B5E30E70414990574883DDB ] ALG            C:\Windows\System32\alg.exe
18:07:57.0380 3048  ALG - ok
18:07:57.0411 3048  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\Windows\system32\drivers\aliide.sys
18:07:57.0411 3048  aliide - ok
18:07:57.0427 3048  [ 8893C00A6D0A5820D4608202F99E8AD6 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
18:07:57.0443 3048  AMD External Events Utility - ok
18:07:57.0474 3048  AMD FUEL Service - ok
18:07:57.0505 3048  [ 2EF1BA6D5DC79FCE5E9216C8C2D3F193 ] amdhub30        C:\Windows\system32\DRIVERS\amdhub30.sys
18:07:57.0505 3048  amdhub30 - ok
18:07:57.0521 3048  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\Windows\system32\drivers\amdide.sys
18:07:57.0521 3048  amdide - ok
18:07:57.0536 3048  [ 6A2EEB0C4133B20773BB3DD0B7B377B4 ] amdiox64        C:\Windows\system32\DRIVERS\amdiox64.sys
18:07:57.0536 3048  amdiox64 - ok
18:07:57.0552 3048  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
18:07:57.0552 3048  AmdK8 - ok
18:07:57.0692 3048  [ ACF6058602D202F36C0A2C0C97DB5E3B ] amdkmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
18:07:57.0755 3048  amdkmdag - ok
18:07:57.0786 3048  [ 1E55EA0AD65688EB43CCE6AED573E82C ] amdkmdap        C:\Windows\system32\DRIVERS\atikmpag.sys
18:07:57.0786 3048  amdkmdap - ok
18:07:57.0801 3048  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
18:07:57.0817 3048  AmdPPM - ok
18:07:57.0833 3048  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata        C:\Windows\system32\drivers\amdsata.sys
18:07:57.0833 3048  amdsata - ok
18:07:57.0848 3048  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
18:07:57.0848 3048  amdsbs - ok
18:07:57.0879 3048  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata        C:\Windows\system32\drivers\amdxata.sys
18:07:57.0879 3048  amdxata - ok
18:07:57.0895 3048  [ 541A6C49C792ED71FB3EFF8C815CFE60 ] amdxhc          C:\Windows\system32\DRIVERS\amdxhc.sys
18:07:57.0895 3048  amdxhc - ok
18:07:57.0911 3048  [ A1434F35B7B171CB697D74D33F7D029F ] amd_sata        C:\Windows\system32\drivers\amd_sata.sys
18:07:57.0911 3048  amd_sata - ok
18:07:57.0911 3048  [ E9B5A82FA268BB2D1B012030D5F4E096 ] amd_xata        C:\Windows\system32\drivers\amd_xata.sys
18:07:57.0911 3048  amd_xata - ok
18:07:57.0973 3048  [ D9A92E6DD41C5ADC045AE485026AA40C ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
18:07:57.0973 3048  AntiVirSchedulerService - ok
18:07:57.0989 3048  [ 66A7A38F7C439153B758548375EB9E5E ] AntiVirService  C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
18:07:58.0004 3048  AntiVirService - ok
18:07:58.0035 3048  [ 89A69C3F2F319B43379399547526D952 ] AppID          C:\Windows\system32\drivers\appid.sys
18:07:58.0035 3048  AppID - ok
18:07:58.0067 3048  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
18:07:58.0067 3048  AppIDSvc - ok
18:07:58.0082 3048  [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo        C:\Windows\System32\appinfo.dll
18:07:58.0082 3048  Appinfo - ok
18:07:58.0098 3048  [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
18:07:58.0098 3048  Apple Mobile Device - ok
18:07:58.0129 3048  [ C484F8CEB1717C540242531DB7845C4E ] arc            C:\Windows\system32\drivers\arc.sys
18:07:58.0129 3048  arc - ok
18:07:58.0145 3048  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\Windows\system32\drivers\arcsas.sys
18:07:58.0145 3048  arcsas - ok
18:07:58.0160 3048  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
18:07:58.0160 3048  AsyncMac - ok
18:07:58.0191 3048  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi          C:\Windows\system32\drivers\atapi.sys
18:07:58.0191 3048  atapi - ok
18:07:58.0223 3048  [ 24464B908E143D2561E9E452FEE97309 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
18:07:58.0223 3048  AtiHDAudioService - ok
18:07:58.0238 3048  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
18:07:58.0254 3048  AudioEndpointBuilder - ok
18:07:58.0254 3048  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
18:07:58.0269 3048  AudioSrv - ok
18:07:58.0285 3048  [ 09E6069EF94B345061B4BD3CEBD974C8 ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
18:07:58.0285 3048  avgntflt - ok
18:07:58.0301 3048  [ 488486DAD09A5B6C6DBB8B990A8B2307 ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
18:07:58.0316 3048  avipbb - ok
18:07:58.0332 3048  [ 490FA25161BF3E51993EB724ECF0ACEB ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
18:07:58.0332 3048  avkmgr - ok
18:07:58.0347 3048  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\Windows\System32\AxInstSV.dll
18:07:58.0347 3048  AxInstSV - ok
18:07:58.0363 3048  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv        C:\Windows\system32\drivers\bxvbda.sys
18:07:58.0379 3048  b06bdrv - ok
18:07:58.0394 3048  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
18:07:58.0394 3048  b57nd60a - ok
18:07:58.0425 3048  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\Windows\System32\bdesvc.dll
18:07:58.0425 3048  BDESVC - ok
18:07:58.0441 3048  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\Windows\system32\drivers\Beep.sys
18:07:58.0441 3048  Beep - ok
18:07:58.0472 3048  [ 82974D6A2FD19445CC5171FC378668A4 ] BFE            C:\Windows\System32\bfe.dll
18:07:58.0488 3048  BFE - ok
18:07:58.0519 3048  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\Windows\system32\qmgr.dll
18:07:58.0519 3048  BITS - ok
18:07:58.0535 3048  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
18:07:58.0535 3048  blbdrive - ok
18:07:58.0550 3048  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
18:07:58.0550 3048  Bonjour Service - ok
18:07:58.0581 3048  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
18:07:58.0581 3048  bowser - ok
18:07:58.0597 3048  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
18:07:58.0597 3048  BrFiltLo - ok
18:07:58.0628 3048  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
18:07:58.0628 3048  BrFiltUp - ok
18:07:58.0644 3048  [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP        C:\Windows\system32\DRIVERS\bridge.sys
18:07:58.0659 3048  BridgeMP - ok
18:07:58.0675 3048  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser        C:\Windows\System32\browser.dll
18:07:58.0675 3048  Browser - ok
18:07:58.0691 3048  [ E5E9B1625A767CEB6F319C12D33EAB78 ] BrSerIb        C:\Windows\system32\DRIVERS\BrSerIb.sys
18:07:58.0706 3048  BrSerIb - ok
18:07:58.0706 3048  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
18:07:58.0706 3048  Brserid - ok
18:07:58.0722 3048  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
18:07:58.0722 3048  BrSerWdm - ok
18:07:58.0753 3048  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
18:07:58.0753 3048  BrUsbMdm - ok
18:07:58.0769 3048  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
18:07:58.0769 3048  BrUsbSer - ok
18:07:58.0800 3048  [ D9F6B30AD93CBD165EC71FADF51DF25E ] BrUsbSIb        C:\Windows\system32\DRIVERS\BrUsbSIb.sys
18:07:58.0800 3048  BrUsbSIb - ok
18:07:58.0800 3048  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
18:07:58.0800 3048  BTHMODEM - ok
18:07:58.0815 3048  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv        C:\Windows\system32\bthserv.dll
18:07:58.0831 3048  bthserv - ok
18:07:58.0847 3048  catchme - ok
18:07:58.0862 3048  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
18:07:58.0862 3048  cdfs - ok
18:07:58.0878 3048  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
18:07:58.0878 3048  cdrom - ok
18:07:58.0893 3048  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc    C:\Windows\System32\certprop.dll
18:07:58.0893 3048  CertPropSvc - ok
18:07:58.0925 3048  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\Windows\system32\drivers\circlass.sys
18:07:58.0925 3048  circlass - ok
18:07:58.0940 3048  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\Windows\system32\CLFS.sys
18:07:58.0940 3048  CLFS - ok
18:07:58.0971 3048  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:07:58.0971 3048  clr_optimization_v2.0.50727_32 - ok
18:07:59.0034 3048  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
18:07:59.0034 3048  clr_optimization_v2.0.50727_64 - ok
18:07:59.0065 3048  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:07:59.0065 3048  clr_optimization_v4.0.30319_32 - ok
18:07:59.0096 3048  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
18:07:59.0096 3048  clr_optimization_v4.0.30319_64 - ok
18:07:59.0112 3048  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\Windows\system32\drivers\CmBatt.sys
18:07:59.0112 3048  CmBatt - ok
18:07:59.0127 3048  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\Windows\system32\drivers\cmdide.sys
18:07:59.0127 3048  cmdide - ok
18:07:59.0159 3048  [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG            C:\Windows\system32\Drivers\cng.sys
18:07:59.0159 3048  CNG - ok
18:07:59.0174 3048  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
18:07:59.0174 3048  Compbatt - ok
18:07:59.0190 3048  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
18:07:59.0190 3048  CompositeBus - ok
18:07:59.0205 3048  COMSysApp - ok
18:07:59.0283 3048  [ A2E0A490F1F49ED6E3B83DB52679B036 ] CoordinatorServiceHost C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
18:07:59.0283 3048  CoordinatorServiceHost - ok
18:07:59.0283 3048  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
18:07:59.0283 3048  crcdisk - ok
18:07:59.0330 3048  [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc        C:\Windows\system32\cryptsvc.dll
18:07:59.0330 3048  CryptSvc - ok
18:07:59.0377 3048  [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc          C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
18:07:59.0393 3048  cvhsvc - ok
18:07:59.0424 3048  [ 7F5CD87CA5BDB4D83F992D8C77201483 ] CyberLink PowerDVD 10 MS Monitor Service C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe
18:07:59.0424 3048  CyberLink PowerDVD 10 MS Monitor Service - ok
18:07:59.0439 3048  [ 9FAF58E876A3B1DB3030A0A5805F2D86 ] CyberLink PowerDVD 10 MS Service C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe
18:07:59.0439 3048  CyberLink PowerDVD 10 MS Service - ok
18:07:59.0471 3048  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\Windows\system32\rpcss.dll
18:07:59.0486 3048  DcomLaunch - ok
18:07:59.0517 3048  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc      C:\Windows\System32\defragsvc.dll
18:07:59.0517 3048  defragsvc - ok
18:07:59.0533 3048  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
18:07:59.0533 3048  DfsC - ok
18:07:59.0549 3048  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\Windows\system32\dhcpcore.dll
18:07:59.0549 3048  Dhcp - ok
18:07:59.0549 3048  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\Windows\system32\drivers\discache.sys
18:07:59.0564 3048  discache - ok
18:07:59.0580 3048  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\Windows\system32\drivers\disk.sys
18:07:59.0595 3048  Disk - ok
18:07:59.0611 3048  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
18:07:59.0611 3048  Dnscache - ok
18:07:59.0627 3048  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc        C:\Windows\System32\dot3svc.dll
18:07:59.0627 3048  dot3svc - ok
18:07:59.0642 3048  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS            C:\Windows\system32\dps.dll
18:07:59.0642 3048  DPS - ok
18:07:59.0673 3048  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
18:07:59.0673 3048  drmkaud - ok
18:07:59.0720 3048  [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
18:07:59.0720 3048  DXGKrnl - ok
18:07:59.0736 3048  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost        C:\Windows\System32\eapsvc.dll
18:07:59.0736 3048  EapHost - ok
18:07:59.0783 3048  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv          C:\Windows\system32\drivers\evbda.sys
18:07:59.0798 3048  ebdrv - ok
18:07:59.0829 3048  [ C118A82CD78818C29AB228366EBF81C3 ] EFS            C:\Windows\System32\lsass.exe
18:07:59.0845 3048  EFS - ok
18:07:59.0892 3048  [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
18:07:59.0892 3048  ehRecvr - ok
18:07:59.0907 3048  [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched        C:\Windows\ehome\ehsched.exe
18:07:59.0907 3048  ehSched - ok
18:07:59.0939 3048  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
18:07:59.0954 3048  elxstor - ok
18:07:59.0970 3048  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\Windows\system32\drivers\errdev.sys
18:07:59.0970 3048  ErrDev - ok
18:08:00.0001 3048  esgiguard - ok
18:08:00.0017 3048  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem    C:\Windows\system32\es.dll
18:08:00.0032 3048  EventSystem - ok
18:08:00.0048 3048  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat          C:\Windows\system32\drivers\exfat.sys
18:08:00.0048 3048  exfat - ok
18:08:00.0063 3048  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat        C:\Windows\system32\drivers\fastfat.sys
18:08:00.0063 3048  fastfat - ok
18:08:00.0095 3048  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax            C:\Windows\system32\fxssvc.exe
18:08:00.0110 3048  Fax - ok
18:08:00.0126 3048  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc            C:\Windows\system32\drivers\fdc.sys
18:08:00.0126 3048  fdc - ok
18:08:00.0141 3048  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost        C:\Windows\system32\fdPHost.dll
18:08:00.0141 3048  fdPHost - ok
18:08:00.0141 3048  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\Windows\system32\fdrespub.dll
18:08:00.0141 3048  FDResPub - ok
18:08:00.0157 3048  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
18:08:00.0157 3048  FileInfo - ok
18:08:00.0173 3048  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
18:08:00.0173 3048  Filetrace - ok
18:08:00.0204 3048  [ 73081CF28F0AE20A52CA4F67CEE6E6B0 ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
18:08:00.0219 3048  FLEXnet Licensing Service - ok
18:08:00.0251 3048  [ 5CEE6CD43AE5844C49300EA0B1E557EE ] FLEXnet Licensing Service 64 C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
18:08:00.0266 3048  FLEXnet Licensing Service 64 - ok
18:08:00.0266 3048  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
18:08:00.0282 3048  flpydisk - ok
18:08:00.0297 3048  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
18:08:00.0297 3048  FltMgr - ok
18:08:00.0344 3048  [ C4C183E6551084039EC862DA1C945E3D ] FontCache      C:\Windows\system32\FntCache.dll
18:08:00.0344 3048  FontCache - ok
18:08:00.0375 3048  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
18:08:00.0375 3048  FontCache3.0.0.0 - ok
18:08:00.0375 3048  [ D43703496149971890703B4B1B723EAC ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
18:08:00.0375 3048  FsDepends - ok
18:08:00.0407 3048  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
18:08:00.0407 3048  Fs_Rec - ok
18:08:00.0422 3048  [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
18:08:00.0438 3048  fvevol - ok
18:08:00.0438 3048  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
18:08:00.0438 3048  gagp30kx - ok
18:08:00.0453 3048  [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
18:08:00.0453 3048  GEARAspiWDM - ok
18:08:00.0485 3048  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc          C:\Windows\System32\gpsvc.dll
18:08:00.0485 3048  gpsvc - ok
18:08:00.0531 3048  [ F02A533F517EB38333CB12A9E8963773 ] gupdate        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
18:08:00.0531 3048  gupdate - ok
18:08:00.0563 3048  [ F02A533F517EB38333CB12A9E8963773 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
18:08:00.0563 3048  gupdatem - ok
18:08:00.0578 3048  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
18:08:00.0578 3048  hcw85cir - ok
18:08:00.0609 3048  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
18:08:00.0625 3048  HdAudAddService - ok
18:08:00.0625 3048  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
18:08:00.0641 3048  HDAudBus - ok
18:08:00.0656 3048  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt        C:\Windows\system32\drivers\HidBatt.sys
18:08:00.0656 3048  HidBatt - ok
18:08:00.0672 3048  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\Windows\system32\drivers\hidbth.sys
18:08:00.0672 3048  HidBth - ok
18:08:00.0687 3048  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr          C:\Windows\system32\drivers\hidir.sys
18:08:00.0687 3048  HidIr - ok
18:08:00.0703 3048  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv        C:\Windows\System32\hidserv.dll
18:08:00.0703 3048  hidserv - ok
18:08:00.0703 3048  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
18:08:00.0719 3048  HidUsb - ok
18:08:00.0734 3048  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\Windows\system32\kmsvc.dll
18:08:00.0734 3048  hkmsvc - ok
18:08:00.0750 3048  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
18:08:00.0750 3048  HomeGroupListener - ok
18:08:00.0765 3048  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
18:08:00.0765 3048  HomeGroupProvider - ok
18:08:00.0765 3048  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
18:08:00.0765 3048  HpSAMD - ok
18:08:00.0781 3048  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
18:08:00.0797 3048  HTTP - ok
18:08:00.0797 3048  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
18:08:00.0797 3048  hwpolicy - ok
18:08:00.0828 3048  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
18:08:00.0828 3048  i8042prt - ok
18:08:00.0843 3048  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
18:08:00.0843 3048  iaStorV - ok
18:08:00.0890 3048  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
18:08:00.0906 3048  idsvc - ok
18:08:01.0015 3048  [ A87261EF1546325B559374F5689CF5BC ] igfx            C:\Windows\system32\DRIVERS\igdkmd64.sys
18:08:01.0046 3048  igfx - ok
18:08:01.0062 3048  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
18:08:01.0062 3048  iirsp - ok
18:08:01.0077 3048  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\Windows\System32\ikeext.dll
18:08:01.0093 3048  IKEEXT - ok
18:08:01.0171 3048  [ 21F54139C93FC595902B58ED947D47D5 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
18:08:01.0202 3048  IntcAzAudAddService - ok
18:08:01.0218 3048  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\Windows\system32\drivers\intelide.sys
18:08:01.0218 3048  intelide - ok
18:08:01.0218 3048  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\Windows\system32\drivers\intelppm.sys
18:08:01.0218 3048  intelppm - ok
18:08:01.0233 3048  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
18:08:01.0233 3048  IPBusEnum - ok
18:08:01.0249 3048  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:08:01.0249 3048  IpFilterDriver - ok
18:08:01.0280 3048  [ 08C2957BB30058E663720C5606885653 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
18:08:01.0280 3048  iphlpsvc - ok
18:08:01.0296 3048  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV        C:\Windows\system32\drivers\IPMIDrv.sys
18:08:01.0296 3048  IPMIDRV - ok
18:08:01.0311 3048  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
18:08:01.0311 3048  IPNAT - ok
18:08:01.0343 3048  [ 4EFFC8FF6D349E971E94B1C670C0C66A ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
18:08:01.0358 3048  iPod Service - ok
18:08:01.0358 3048  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
18:08:01.0358 3048  IRENUM - ok
18:08:01.0374 3048  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
18:08:01.0374 3048  isapnp - ok
18:08:01.0405 3048  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
18:08:01.0405 3048  iScsiPrt - ok
18:08:01.0436 3048  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
18:08:01.0436 3048  kbdclass - ok
18:08:01.0452 3048  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
18:08:01.0452 3048  kbdhid - ok
18:08:01.0452 3048  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\Windows\system32\lsass.exe
18:08:01.0467 3048  KeyIso - ok
18:08:01.0483 3048  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
18:08:01.0483 3048  KSecDD - ok
18:08:01.0499 3048  [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
18:08:01.0499 3048  KSecPkg - ok
18:08:01.0514 3048  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
18:08:01.0514 3048  ksthunk - ok
18:08:01.0530 3048  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm          C:\Windows\system32\msdtckrm.dll
18:08:01.0530 3048  KtmRm - ok
18:08:01.0561 3048  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\Windows\System32\srvsvc.dll
18:08:01.0561 3048  LanmanServer - ok
18:08:01.0577 3048  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:08:01.0577 3048  LanmanWorkstation - ok
18:08:01.0608 3048  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
18:08:01.0608 3048  lltdio - ok
18:08:01.0623 3048  [ C1185803384AB3FEED115F79F109427F ] lltdsvc        C:\Windows\System32\lltdsvc.dll
18:08:01.0623 3048  lltdsvc - ok
18:08:01.0639 3048  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts        C:\Windows\System32\lmhsvc.dll
18:08:01.0639 3048  lmhosts - ok
18:08:01.0655 3048  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
18:08:01.0655 3048  LSI_FC - ok
18:08:01.0670 3048  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
18:08:01.0670 3048  LSI_SAS - ok
18:08:01.0686 3048  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
18:08:01.0686 3048  LSI_SAS2 - ok
18:08:01.0717 3048  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
18:08:01.0717 3048  LSI_SCSI - ok
18:08:01.0733 3048  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv          C:\Windows\system32\drivers\luafv.sys
18:08:01.0733 3048  luafv - ok
18:08:01.0764 3048  [ A8FE8F2783B2929B56F5370A89356CE9 ] MBAMProtector  C:\Windows\system32\drivers\mbam.sys
18:08:01.0764 3048  MBAMProtector - ok
18:08:01.0779 3048  [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
18:08:01.0779 3048  MBAMScheduler - ok
18:08:01.0826 3048  [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
18:08:01.0826 3048  MBAMService - ok
18:08:01.0826 3048  [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
18:08:01.0842 3048  Mcx2Svc - ok
18:08:01.0842 3048  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas        C:\Windows\system32\drivers\megasas.sys
18:08:01.0842 3048  megasas - ok
18:08:01.0873 3048  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
18:08:01.0873 3048  MegaSR - ok
18:08:01.0904 3048  [ 8A43D23ACE2E8C95A2D87B6E9599DEDA ] MemeoBackgroundService C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe
18:08:01.0904 3048  MemeoBackgroundService - ok
18:08:01.0904 3048  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS          C:\Windows\system32\mmcss.dll
18:08:01.0904 3048  MMCSS - ok
18:08:01.0920 3048  [ 800BA92F7010378B09F9ED9270F07137 ] Modem          C:\Windows\system32\drivers\modem.sys
18:08:01.0920 3048  Modem - ok
18:08:01.0935 3048  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
18:08:01.0935 3048  monitor - ok
18:08:01.0951 3048  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
18:08:01.0951 3048  mouclass - ok
18:08:01.0967 3048  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
18:08:01.0967 3048  mouhid - ok
18:08:01.0982 3048  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
18:08:01.0982 3048  mountmgr - ok
18:08:01.0982 3048  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\Windows\system32\drivers\mpio.sys
18:08:01.0982 3048  mpio - ok
18:08:02.0013 3048  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
18:08:02.0013 3048  mpsdrv - ok
18:08:02.0029 3048  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc          C:\Windows\system32\mpssvc.dll
18:08:02.0029 3048  MpsSvc - ok
18:08:02.0060 3048  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
18:08:02.0060 3048  MRxDAV - ok
18:08:02.0076 3048  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
18:08:02.0076 3048  mrxsmb - ok
18:08:02.0076 3048  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:08:02.0091 3048  mrxsmb10 - ok
18:08:02.0091 3048  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:08:02.0091 3048  mrxsmb20 - ok
18:08:02.0107 3048  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\Windows\system32\drivers\msahci.sys
18:08:02.0123 3048  msahci - ok
18:08:02.0123 3048  [ DB801A638D011B9633829EB6F663C900 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
18:08:02.0123 3048  msdsm - ok
18:08:02.0138 3048  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC          C:\Windows\System32\msdtc.exe
18:08:02.0154 3048  MSDTC - ok
18:08:02.0154 3048  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
18:08:02.0154 3048  Msfs - ok
18:08:02.0169 3048  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
18:08:02.0169 3048  mshidkmdf - ok
18:08:02.0185 3048  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
18:08:02.0185 3048  msisadrv - ok
18:08:02.0201 3048  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
18:08:02.0201 3048  MSiSCSI - ok
18:08:02.0201 3048  msiserver - ok
18:08:02.0216 3048  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
18:08:02.0216 3048  MSKSSRV - ok
18:08:02.0232 3048  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
18:08:02.0232 3048  MSPCLOCK - ok
18:08:02.0247 3048  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
18:08:02.0247 3048  MSPQM - ok
18:08:02.0263 3048  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
18:08:02.0263 3048  MsRPC - ok
18:08:02.0279 3048  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
18:08:02.0279 3048  mssmbios - ok
18:08:02.0279 3048  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
18:08:02.0279 3048  MSTEE - ok
18:08:02.0294 3048  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
18:08:02.0294 3048  MTConfig - ok
18:08:02.0310 3048  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup            C:\Windows\system32\Drivers\mup.sys
18:08:02.0310 3048  Mup - ok
18:08:02.0325 3048  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\Windows\system32\qagentRT.dll
18:08:02.0325 3048  napagent - ok
18:08:02.0341 3048  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
18:08:02.0341 3048  NativeWifiP - ok
18:08:02.0388 3048  [ 760E38053BF56E501D562B70AD796B88 ] NDIS            C:\Windows\system32\drivers\ndis.sys
18:08:02.0403 3048  NDIS - ok
18:08:02.0419 3048  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
18:08:02.0419 3048  NdisCap - ok
18:08:02.0435 3048  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
18:08:02.0435 3048  NdisTapi - ok
18:08:02.0435 3048  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
18:08:02.0435 3048  Ndisuio - ok
18:08:02.0450 3048  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
18:08:02.0450 3048  NdisWan - ok
18:08:02.0450 3048  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
18:08:02.0466 3048  NDProxy - ok
18:08:02.0466 3048  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
18:08:02.0466 3048  NetBIOS - ok
18:08:02.0481 3048  [ 09594D1089C523423B32A4229263F068 ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
18:08:02.0481 3048  NetBT - ok
18:08:02.0497 3048  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\Windows\system32\lsass.exe
18:08:02.0497 3048  Netlogon - ok
18:08:02.0513 3048  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\Windows\System32\netman.dll
18:08:02.0528 3048  Netman - ok
18:08:02.0528 3048  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\Windows\System32\netprofm.dll
18:08:02.0544 3048  netprofm - ok
18:08:02.0544 3048  [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:08:02.0559 3048  NetTcpPortSharing - ok
18:08:02.0575 3048  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
18:08:02.0575 3048  nfrd960 - ok
18:08:02.0606 3048  [ 8AD77806D336673F270DB31645267293 ] NlaSvc          C:\Windows\System32\nlasvc.dll
18:08:02.0606 3048  NlaSvc - ok
18:08:02.0622 3048  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
18:08:02.0622 3048  Npfs - ok
18:08:02.0622 3048  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi            C:\Windows\system32\nsisvc.dll
18:08:02.0622 3048  nsi - ok
18:08:02.0637 3048  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
18:08:02.0637 3048  nsiproxy - ok
18:08:02.0669 3048  [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
18:08:02.0669 3048  Ntfs - ok
18:08:02.0684 3048  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\Windows\system32\drivers\Null.sys
18:08:02.0684 3048  Null - ok
18:08:02.0715 3048  [ A85B4F2EF3A7304A5399EF0526423040 ] NVENETFD        C:\Windows\system32\DRIVERS\nvm62x64.sys
18:08:02.0715 3048  NVENETFD - ok
18:08:02.0903 3048  [ DD81FBC57AB9134CDDC5CE90880BFD80 ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
18:08:02.0949 3048  nvlddmkm - ok
18:08:02.0981 3048  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\Windows\system32\drivers\nvraid.sys
18:08:02.0996 3048  nvraid - ok
18:08:02.0996 3048  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\Windows\system32\drivers\nvstor.sys
18:08:02.0996 3048  nvstor - ok
18:08:03.0027 3048  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
18:08:03.0027 3048  nv_agp - ok
18:08:03.0043 3048  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
18:08:03.0043 3048  ohci1394 - ok
18:08:03.0074 3048  [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:08:03.0074 3048  ose - ok
18:08:03.0183 3048  [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc        C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
18:08:03.0199 3048  osppsvc - ok
18:08:03.0230 3048  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
18:08:03.0230 3048  p2pimsvc - ok
18:08:03.0246 3048  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\Windows\system32\p2psvc.dll
18:08:03.0246 3048  p2psvc - ok
18:08:03.0261 3048  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport        C:\Windows\system32\drivers\parport.sys
18:08:03.0261 3048  Parport - ok
18:08:03.0277 3048  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr        C:\Windows\system32\drivers\partmgr.sys
18:08:03.0277 3048  partmgr - ok
18:08:03.0293 3048  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\Windows\System32\pcasvc.dll
18:08:03.0293 3048  PcaSvc - ok
18:08:03.0308 3048  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci            C:\Windows\system32\drivers\pci.sys
18:08:03.0308 3048  pci - ok
18:08:03.0324 3048  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\Windows\system32\drivers\pciide.sys
18:08:03.0324 3048  pciide - ok
18:08:03.0339 3048  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
18:08:03.0339 3048  pcmcia - ok
18:08:03.0355 3048  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw            C:\Windows\system32\drivers\pcw.sys
18:08:03.0355 3048  pcw - ok
18:08:03.0371 3048  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
18:08:03.0371 3048  PEAUTH - ok
18:08:03.0402 3048  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
18:08:03.0402 3048  PerfHost - ok
18:08:03.0433 3048  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla            C:\Windows\system32\pla.dll
18:08:03.0433 3048  pla - ok
18:08:03.0464 3048  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
18:08:03.0480 3048  PlugPlay - ok
18:08:03.0480 3048  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
18:08:03.0480 3048  PNRPAutoReg - ok
18:08:03.0495 3048  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
18:08:03.0495 3048  PNRPsvc - ok
18:08:03.0527 3048  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
18:08:03.0527 3048  PolicyAgent - ok
18:08:03.0542 3048  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power          C:\Windows\system32\umpo.dll
18:08:03.0542 3048  Power - ok
18:08:03.0558 3048  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
18:08:03.0558 3048  PptpMiniport - ok
18:08:03.0573 3048  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor      C:\Windows\system32\drivers\processr.sys
18:08:03.0573 3048  Processor - ok
18:08:03.0573 3048  [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc        C:\Windows\system32\profsvc.dll
18:08:03.0589 3048  ProfSvc - ok
18:08:03.0589 3048  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
18:08:03.0589 3048  ProtectedStorage - ok
18:08:03.0605 3048  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
18:08:03.0605 3048  Psched - ok
18:08:03.0636 3048  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
18:08:03.0651 3048  ql2300 - ok
18:08:03.0651 3048  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
18:08:03.0651 3048  ql40xx - ok
18:08:03.0667 3048  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE          C:\Windows\system32\qwave.dll
18:08:03.0667 3048  QWAVE - ok
18:08:03.0683 3048  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
18:08:03.0683 3048  QWAVEdrv - ok
18:08:03.0683 3048  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
18:08:03.0683 3048  RasAcd - ok
18:08:03.0698 3048  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
18:08:03.0714 3048  RasAgileVpn - ok
18:08:03.0714 3048  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto        C:\Windows\System32\rasauto.dll
18:08:03.0714 3048  RasAuto - ok
18:08:03.0729 3048  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
18:08:03.0729 3048  Rasl2tp - ok
18:08:03.0745 3048  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\Windows\System32\rasmans.dll
18:08:03.0761 3048  RasMan - ok
18:08:03.0761 3048  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
18:08:03.0761 3048  RasPppoe - ok
18:08:03.0776 3048  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
18:08:03.0776 3048  RasSstp - ok
18:08:03.0776 3048  [ 77F665941019A1594D887A74F301FA2F ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
18:08:03.0776 3048  rdbss - ok
18:08:03.0792 3048  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\Windows\system32\drivers\rdpbus.sys
18:08:03.0792 3048  rdpbus - ok
18:08:03.0792 3048  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
18:08:03.0792 3048  RDPCDD - ok
18:08:03.0823 3048  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
18:08:03.0823 3048  RDPENCDD - ok
18:08:03.0839 3048  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
18:08:03.0839 3048  RDPREFMP - ok
18:08:03.0854 3048  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
18:08:03.0854 3048  RDPWD - ok
18:08:03.0870 3048  [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
18:08:03.0870 3048  rdyboost - ok
18:08:03.0932 3048  [ 6713253B37D6DCFC442A286F1D7B5350 ] Remote Solver for Flow Simulation 2012 C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe
18:08:03.0932 3048  Remote Solver for Flow Simulation 2012 - ok
18:08:03.0948 3048  [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess    C:\Windows\System32\mprdim.dll
18:08:03.0963 3048  RemoteAccess - ok
18:08:03.0963 3048  [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
18:08:03.0963 3048  RemoteRegistry - ok
18:08:03.0979 3048  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
18:08:03.0979 3048  RpcEptMapper - ok
18:08:03.0995 3048  [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator      C:\Windows\system32\locator.exe
18:08:03.0995 3048  RpcLocator - ok
18:08:04.0010 3048  [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs          C:\Windows\system32\rpcss.dll
18:08:04.0010 3048  RpcSs - ok
18:08:04.0026 3048  [ DDC86E4F8E7456261E637E3552E804FF ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
18:08:04.0026 3048  rspndr - ok
18:08:04.0041 3048  [ 39A719875F572241C585A629EE62EB14 ] RTL8167        C:\Windows\system32\DRIVERS\Rt64win7.sys
18:08:04.0057 3048  RTL8167 - ok
18:08:04.0088 3048  [ B3F36B4B3F192EA87DDC119F3A0B3E45 ] RTL8192su      C:\Windows\system32\DRIVERS\RTL8192su.sys
18:08:04.0088 3048  RTL8192su - ok
18:08:04.0104 3048  [ C118A82CD78818C29AB228366EBF81C3 ] SamSs          C:\Windows\system32\lsass.exe
18:08:04.0104 3048  SamSs - ok
18:08:04.0119 3048  [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
18:08:04.0119 3048  sbp2port - ok
18:08:04.0135 3048  [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr        C:\Windows\System32\SCardSvr.dll
18:08:04.0135 3048  SCardSvr - ok
18:08:04.0151 3048  [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
18:08:04.0151 3048  scfilter - ok
18:08:04.0166 3048  [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule        C:\Windows\system32\schedsvc.dll
18:08:04.0166 3048  Schedule - ok
18:08:04.0182 3048  [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc    C:\Windows\System32\certprop.dll
18:08:04.0197 3048  SCPolicySvc - ok
18:08:04.0197 3048  [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
18:08:04.0197 3048  SDRSVC - ok
18:08:04.0213 3048  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
18:08:04.0213 3048  secdrv - ok
18:08:04.0213 3048  [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon        C:\Windows\system32\seclogon.dll
18:08:04.0213 3048  seclogon - ok
18:08:04.0229 3048  [ C32AB8FA018EF34C0F113BD501436D21 ] SENS            C:\Windows\system32\sens.dll
18:08:04.0229 3048  SENS - ok
18:08:04.0244 3048  [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
18:08:04.0260 3048  SensrSvc - ok
18:08:04.0275 3048  [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum        C:\Windows\system32\drivers\serenum.sys
18:08:04.0275 3048  Serenum - ok
18:08:04.0291 3048  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial          C:\Windows\system32\drivers\serial.sys
18:08:04.0291 3048  Serial - ok
18:08:04.0322 3048  [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse        C:\Windows\system32\drivers\sermouse.sys
18:08:04.0322 3048  sermouse - ok
18:08:04.0338 3048  [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv      C:\Windows\system32\sessenv.dll
18:08:04.0353 3048  SessionEnv - ok
18:08:04.0353 3048  [ A554811BCD09279536440C964AE35BBF ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
18:08:04.0353 3048  sffdisk - ok
18:08:04.0385 3048  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
18:08:04.0385 3048  sffp_mmc - ok
18:08:04.0385 3048  [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
18:08:04.0400 3048  sffp_sd - ok
18:08:04.0416 3048  [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
18:08:04.0416 3048  sfloppy - ok
18:08:04.0447 3048  [ C6CC9297BD53E5229653303E556AA539 ] Sftfs          C:\Windows\system32\DRIVERS\Sftfslh.sys
18:08:04.0463 3048  Sftfs - ok
18:08:04.0494 3048  [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist        C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
18:08:04.0494 3048  sftlist - ok
18:08:04.0509 3048  [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay        C:\Windows\system32\DRIVERS\Sftplaylh.sys
18:08:04.0509 3048  Sftplay - ok
18:08:04.0525 3048  [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir        C:\Windows\system32\DRIVERS\Sftredirlh.sys
18:08:04.0525 3048  Sftredir - ok
18:08:04.0525 3048  [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol          C:\Windows\system32\DRIVERS\Sftvollh.sys
18:08:04.0525 3048  Sftvol - ok
18:08:04.0541 3048  [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa          C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
18:08:04.0541 3048  sftvsa - ok
18:08:04.0572 3048  [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess    C:\Windows\System32\ipnathlp.dll
18:08:04.0572 3048  SharedAccess - ok
18:08:04.0587 3048  [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
18:08:04.0587 3048  ShellHWDetection - ok
18:08:04.0587 3048  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
18:08:04.0587 3048  SiSRaid2 - ok
18:08:04.0619 3048  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
18:08:04.0619 3048  SiSRaid4 - ok
18:08:04.0650 3048  [ 7C15061CD0372487903B07B9BB03AFAD ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
18:08:04.0650 3048  SkypeUpdate - ok
18:08:04.0665 3048  [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
18:08:04.0681 3048  Smb - ok
18:08:04.0697 3048  [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
18:08:04.0697 3048  SNMPTRAP - ok
18:08:04.0728 3048  [ 4945020BC094C322571184A6E8056B3A ] SolidWorks Licensing Service C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
18:08:04.0728 3048  SolidWorks Licensing Service - ok
18:08:04.0728 3048  [ B9E31E5CACDFE584F34F730A677803F9 ] spldr          C:\Windows\system32\drivers\spldr.sys
18:08:04.0728 3048  spldr - ok
18:08:04.0759 3048  [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler        C:\Windows\System32\spoolsv.exe
18:08:04.0759 3048  Spooler - ok
18:08:04.0806 3048  [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc          C:\Windows\system32\sppsvc.exe
18:08:04.0821 3048  sppsvc - ok
18:08:04.0853 3048  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify    C:\Windows\system32\sppuinotify.dll
18:08:04.0853 3048  sppuinotify - ok
18:08:04.0884 3048  [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv            C:\Windows\system32\DRIVERS\srv.sys
18:08:04.0884 3048  srv - ok
18:08:04.0899 3048  [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
18:08:04.0899 3048  srv2 - ok
18:08:04.0899 3048  [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
18:08:04.0915 3048  srvnet - ok
18:08:04.0931 3048  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
18:08:04.0931 3048  SSDPSRV - ok
18:08:04.0946 3048  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc        C:\Windows\system32\sstpsvc.dll
18:08:04.0946 3048  SstpSvc - ok
18:08:04.0962 3048  [ F3817967ED533D08327DC73BC4D5542A ] stexstor        C:\Windows\system32\drivers\stexstor.sys
18:08:04.0962 3048  stexstor - ok
18:08:04.0977 3048  [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc          C:\Windows\System32\wiaservc.dll
18:08:04.0977 3048  stisvc - ok
18:08:05.0009 3048  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
18:08:05.0009 3048  swenum - ok
18:08:05.0024 3048  [ E08E46FDD841B7184194011CA1955A0B ] swprv          C:\Windows\System32\swprv.dll
18:08:05.0024 3048  swprv - ok
18:08:05.0055 3048  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain        C:\Windows\system32\sysmain.dll
18:08:05.0055 3048  SysMain - ok
18:08:05.0071 3048  [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
18:08:05.0071 3048  TabletInputService - ok
18:08:05.0087 3048  [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv        C:\Windows\System32\tapisrv.dll
18:08:05.0087 3048  TapiSrv - ok
18:08:05.0102 3048  [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS            C:\Windows\System32\tbssvc.dll
18:08:05.0102 3048  TBS - ok
18:08:05.0149 3048  [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
18:08:05.0165 3048  Tcpip - ok
18:08:05.0196 3048  [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
18:08:05.0196 3048  TCPIP6 - ok
18:08:05.0227 3048  [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
18:08:05.0227 3048  tcpipreg - ok
18:08:05.0227 3048  [ 3371D21011695B16333A3934340C4E7C ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
18:08:05.0227 3048  TDPIPE - ok
18:08:05.0258 3048  [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
18:08:05.0258 3048  TDTCP - ok
18:08:05.0258 3048  [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
18:08:05.0258 3048  tdx - ok
18:08:05.0274 3048  [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
18:08:05.0274 3048  TermDD - ok
18:08:05.0289 3048  [ 2E648163254233755035B46DD7B89123 ] TermService    C:\Windows\System32\termsrv.dll
18:08:05.0289 3048  TermService - ok
18:08:05.0305 3048  [ F0344071948D1A1FA732231785A0664C ] Themes          C:\Windows\system32\themeservice.dll
18:08:05.0305 3048  Themes - ok
18:08:05.0321 3048  [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER    C:\Windows\system32\mmcss.dll
18:08:05.0321 3048  THREADORDER - ok
18:08:05.0336 3048  [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks          C:\Windows\System32\trkwks.dll
18:08:05.0352 3048  TrkWks - ok
18:08:05.0383 3048  [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
18:08:05.0383 3048  TrustedInstaller - ok
18:08:05.0399 3048  [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
18:08:05.0399 3048  tssecsrv - ok
18:08:05.0414 3048  [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
18:08:05.0414 3048  TsUsbFlt - ok
18:08:05.0445 3048  [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD        C:\Windows\system32\drivers\TsUsbGD.sys
18:08:05.0445 3048  TsUsbGD - ok
18:08:05.0461 3048  [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
18:08:05.0461 3048  tunnel - ok
18:08:05.0477 3048  [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
18:08:05.0477 3048  uagp35 - ok
18:08:05.0492 3048  [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
18:08:05.0492 3048  udfs - ok
18:08:05.0508 3048  [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
18:08:05.0523 3048  UI0Detect - ok
18:08:05.0539 3048  [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
18:08:05.0539 3048  uliagpkx - ok
18:08:05.0555 3048  [ DC54A574663A895C8763AF0FA1FF7561 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
18:08:05.0555 3048  umbus - ok
18:08:05.0570 3048  [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass          C:\Windows\system32\drivers\umpass.sys
18:08:05.0570 3048  UmPass - ok
18:08:05.0586 3048  [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost        C:\Windows\System32\upnphost.dll
18:08:05.0586 3048  upnphost - ok
18:08:05.0617 3048  [ C9E9D59C0099A9FF51697E9306A44240 ] USBAAPL64      C:\Windows\system32\Drivers\usbaapl64.sys
18:08:05.0617 3048  USBAAPL64 - ok
18:08:05.0633 3048  [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
18:08:05.0633 3048  usbccgp - ok
18:08:05.0664 3048  [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
18:08:05.0664 3048  usbcir - ok
18:08:05.0679 3048  [ C025055FE7B87701EB042095DF1A2D7B ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
18:08:05.0679 3048  usbehci - ok
18:08:05.0679 3048  [ 33A58C5630200E17B51C8D73DD64181B ] usbfilter      C:\Windows\system32\DRIVERS\usbfilter.sys
18:08:05.0679 3048  usbfilter - ok
18:08:05.0695 3048  [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
18:08:05.0695 3048  usbhub - ok
18:08:05.0711 3048  [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci        C:\Windows\system32\DRIVERS\usbohci.sys
18:08:05.0711 3048  usbohci - ok
18:08:05.0726 3048  [ 73188F58FB384E75C4063D29413CEE3D ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
18:08:05.0726 3048  usbprint - ok
18:08:05.0742 3048  [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
18:08:05.0742 3048  usbscan - ok
18:08:05.0773 3048  [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:08:05.0773 3048  USBSTOR - ok
18:08:05.0789 3048  [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci        C:\Windows\system32\drivers\usbuhci.sys
18:08:05.0789 3048  usbuhci - ok
18:08:05.0820 3048  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms          C:\Windows\System32\uxsms.dll
18:08:05.0835 3048  UxSms - ok
18:08:05.0835 3048  [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc        C:\Windows\system32\lsass.exe
18:08:05.0835 3048  VaultSvc - ok
18:08:05.0851 3048  [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
18:08:05.0851 3048  vdrvroot - ok
18:08:05.0882 3048  [ 8D6B481601D01A456E75C3210F1830BE ] vds            C:\Windows\System32\vds.exe
18:08:05.0898 3048  vds - ok
18:08:05.0898 3048  [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
18:08:05.0898 3048  vga - ok
18:08:05.0898 3048  [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave        C:\Windows\System32\drivers\vga.sys
18:08:05.0913 3048  VgaSave - ok
18:08:05.0929 3048  [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp          C:\Windows\system32\drivers\vhdmp.sys
18:08:05.0945 3048  vhdmp - ok
18:08:05.0976 3048  [ E5689D93FFE4E5D66C0178761240DD54 ] viaide          C:\Windows\system32\drivers\viaide.sys
18:08:05.0976 3048  viaide - ok
18:08:05.0991 3048  [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
18:08:05.0991 3048  volmgr - ok
18:08:06.0007 3048  [ A255814907C89BE58B79EF2F189B843B ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
18:08:06.0007 3048  volmgrx - ok
18:08:06.0038 3048  [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
18:08:06.0038 3048  volsnap - ok
18:08:06.0069 3048  [ 193D323A88F442334D652AC5C1F56414 ] vpnagent        C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
18:08:06.0069 3048  vpnagent - ok
18:08:06.0085 3048  [ 13E6D95E7AC67ABB7A1196557EF8849F ] vpnva          C:\Windows\system32\DRIVERS\vpnva64.sys
18:08:06.0085 3048  vpnva - ok
18:08:06.0085 3048  [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
18:08:06.0101 3048  vsmraid - ok
18:08:06.0147 3048  [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS            C:\Windows\system32\vssvc.exe
18:08:06.0147 3048  VSS - ok
18:08:06.0163 3048  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
18:08:06.0163 3048  vwifibus - ok
18:08:06.0194 3048  [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
18:08:06.0194 3048  vwififlt - ok
18:08:06.0225 3048  [ 1C9D80CC3849B3788048078C26486E1A ] W32Time        C:\Windows\system32\w32time.dll
18:08:06.0225 3048  W32Time - ok
18:08:06.0241 3048  [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
18:08:06.0241 3048  WacomPen - ok
18:08:06.0272 3048  [ 356AFD78A6ED4457169241AC3965230C ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
18:08:06.0272 3048  WANARP - ok
18:08:06.0288 3048  [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
18:08:06.0288 3048  Wanarpv6 - ok
18:08:06.0319 3048  [ 63D7250ED2C2E3CD9B11139A608D6C39 ] watchmi        C:\Program Files (x86)\watchmi\TvdService.exe
18:08:06.0319 3048  watchmi - ok
18:08:06.0350 3048  [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine        C:\Windows\system32\wbengine.exe
18:08:06.0366 3048  wbengine - ok
18:08:06.0397 3048  [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
18:08:06.0397 3048  WbioSrvc - ok
18:08:06.0413 3048  [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc        C:\Windows\System32\wcncsvc.dll
18:08:06.0413 3048  wcncsvc - ok
18:08:06.0428 3048  [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
18:08:06.0428 3048  WcsPlugInService - ok
18:08:06.0444 3048  [ 72889E16FF12BA0F235467D6091B17DC ] Wd              C:\Windows\system32\drivers\wd.sys
18:08:06.0444 3048  Wd - ok
18:08:06.0475 3048  [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
18:08:06.0491 3048  Wdf01000 - ok
18:08:06.0491 3048  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost  C:\Windows\system32\wdi.dll
18:08:06.0506 3048  WdiServiceHost - ok
18:08:06.0506 3048  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost  C:\Windows\system32\wdi.dll
18:08:06.0506 3048  WdiSystemHost - ok
18:08:06.0522 3048  [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient      C:\Windows\System32\webclnt.dll
18:08:06.0522 3048  WebClient - ok
18:08:06.0537 3048  [ C749025A679C5103E575E3B48E092C43 ] Wecsvc          C:\Windows\system32\wecsvc.dll
18:08:06.0537 3048  Wecsvc - ok
18:08:06.0553 3048  [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
18:08:06.0553 3048  wercplsupport - ok
18:08:06.0569 3048  [ 6D137963730144698CBD10F202E9F251 ] WerSvc          C:\Windows\System32\WerSvc.dll
18:08:06.0569 3048  WerSvc - ok
18:08:06.0584 3048  [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
18:08:06.0584 3048  WfpLwf - ok
18:08:06.0584 3048  [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
18:08:06.0584 3048  WIMMount - ok
18:08:06.0600 3048  WinDefend - ok
18:08:06.0615 3048  WinHttpAutoProxySvc - ok
18:08:06.0647 3048  [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
18:08:06.0647 3048  Winmgmt - ok
18:08:06.0693 3048  [ BCB1310604AA415C4508708975B3931E ] WinRM          C:\Windows\system32\WsmSvc.dll
18:08:06.0709 3048  WinRM - ok
18:08:06.0756 3048  [ FE88B288356E7B47B74B13372ADD906D ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
18:08:06.0756 3048  WinUsb - ok
18:08:06.0771 3048  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc        C:\Windows\System32\wlansvc.dll
18:08:06.0787 3048  Wlansvc - ok
18:08:06.0818 3048  [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc        C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
18:08:06.0818 3048  wlcrasvc - ok
18:08:06.0865 3048  [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
18:08:06.0865 3048  wlidsvc - ok
18:08:06.0881 3048  [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
18:08:06.0881 3048  WmiAcpi - ok
18:08:06.0896 3048  [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
18:08:06.0896 3048  wmiApSrv - ok
18:08:06.0912 3048  WMPNetworkSvc - ok
18:08:06.0927 3048  [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
18:08:06.0927 3048  WPCSvc - ok
18:08:06.0927 3048  [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
18:08:06.0943 3048  WPDBusEnum - ok
18:08:06.0943 3048  [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
18:08:06.0943 3048  ws2ifsl - ok
18:08:06.0959 3048  [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc          C:\Windows\system32\wscsvc.dll
18:08:06.0959 3048  wscsvc - ok
18:08:06.0959 3048  WSearch - ok
18:08:06.0974 3048  [ 82E8F5AA03DF7DBDB8A33F700D5D8CDA ] wsvd            C:\Windows\system32\DRIVERS\wsvd.sys
18:08:06.0974 3048  wsvd - ok
18:08:07.0052 3048  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
18:08:07.0068 3048  wuauserv - ok
18:08:07.0083 3048  [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
18:08:07.0083 3048  WudfPf - ok
18:08:07.0099 3048  [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
18:08:07.0099 3048  WUDFRd - ok
18:08:07.0115 3048  [ B20F051B03A966392364C83F009F7D17 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
18:08:07.0115 3048  wudfsvc - ok
18:08:07.0130 3048  [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc        C:\Windows\System32\wwansvc.dll
18:08:07.0146 3048  WwanSvc - ok
18:08:07.0161 3048  ================ Scan global ===============================
18:08:07.0193 3048  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
18:08:07.0208 3048  [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
18:08:07.0208 3048  [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
18:08:07.0224 3048  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
18:08:07.0239 3048  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
18:08:07.0239 3048  [Global] - ok
18:08:07.0239 3048  ================ Scan MBR ==================================
18:08:07.0255 3048  [ AF00FC1920E1CF861B39B90A4375EDF3 ] \Device\Harddisk0\DR0
18:08:07.0349 3048  \Device\Harddisk0\DR0 - ok
18:08:07.0349 3048  ================ Scan VBR ==================================
18:08:07.0349 3048  [ 521BA6E06CF73128BB0825C3637A31E0 ] \Device\Harddisk0\DR0\Partition1
18:08:07.0364 3048  \Device\Harddisk0\DR0\Partition1 - ok
18:08:07.0364 3048  [ 4993626D5E885B3541AE4E9A7F708F20 ] \Device\Harddisk0\DR0\Partition2
18:08:07.0364 3048  \Device\Harddisk0\DR0\Partition2 - ok
18:08:07.0380 3048  [ A39A13EC2C80736C96AE795F1E13A7A9 ] \Device\Harddisk0\DR0\Partition3
18:08:07.0380 3048  \Device\Harddisk0\DR0\Partition3 - ok
18:08:07.0380 3048  ============================================================
18:08:07.0380 3048  Scan finished
18:08:07.0380 3048  ============================================================
18:08:07.0395 3492  Detected object count: 0
18:08:07.0395 3492  Actual detected object count: 0


cosinus 17.05.2013 18:42

Was zum Geier hast du da beim tdsskiller gemacht?? :wtf:

Code:

18:07:52.0326 5744  Scan interrupted by user!
18:07:52.0326 5744  ================ Scan MBR ==================================
18:07:52.0326 5744  Scan interrupted by user!
18:07:52.0326 5744  ================ Scan VBR ==================================
18:07:52.0326 5744  Scan interrupted by user!

Laut Log hast du den Scan abgebrochen!

Code:

18:07:56.0741 3048  Scan started
18:07:56.0741 3048  Mode: Manual;

Falsch eingestellt hast den tdsskiller auch
Bitte die Anleitungen richtig lesen, dann nochmal machen aber richtig

rico89 18.05.2013 10:48

Der hat 2 Logs gespeichert.


Code:

11:38:01.0381 5692  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
11:38:01.0630 5692  ============================================================
11:38:01.0630 5692  Current date / time: 2013/05/18 11:38:01.0630
11:38:01.0630 5692  SystemInfo:
11:38:01.0630 5692 
11:38:01.0630 5692  OS Version: 6.1.7601 ServicePack: 1.0
11:38:01.0630 5692  Product type: Workstation
11:38:01.0630 5692  ComputerName: ALI-PC
11:38:01.0630 5692  UserName: Ali
11:38:01.0630 5692  Windows directory: C:\Windows
11:38:01.0630 5692  System windows directory: C:\Windows
11:38:01.0630 5692  Running under WOW64
11:38:01.0630 5692  Processor architecture: Intel x64
11:38:01.0630 5692  Number of processors: 4
11:38:01.0630 5692  Page size: 0x1000
11:38:01.0630 5692  Boot type: Normal boot
11:38:01.0630 5692  ============================================================
11:38:02.0894 5692  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:38:02.0910 5692  ============================================================
11:38:02.0910 5692  \Device\Harddisk0\DR0:
11:38:02.0910 5692  MBR partitions:
11:38:02.0910 5692  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
11:38:02.0910 5692  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x6E0D3800
11:38:02.0910 5692  \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x6E106000, BlocksNum 0x6400000
11:38:02.0910 5692  ============================================================
11:38:02.0925 5692  C: <-> \Device\Harddisk0\DR0\Partition2
11:38:02.0956 5692  D: <-> \Device\Harddisk0\DR0\Partition3
11:38:02.0956 5692  ============================================================
11:38:02.0956 5692  Initialize success
11:38:02.0956 5692  ============================================================
11:38:54.0998 5400  ============================================================
11:38:54.0998 5400  Scan started
11:38:54.0998 5400  Mode: Manual; SigCheck; TDLFS;
11:38:54.0998 5400  ============================================================
11:38:56.0184 5400  ================ Scan system memory ========================
11:38:56.0184 5400  System memory - ok
11:38:56.0184 5400  ================ Scan services =============================
11:38:56.0449 5400  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
11:38:56.0558 5400  1394ohci - ok
11:38:56.0589 5400  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
11:38:56.0605 5400  ACPI - ok
11:38:56.0620 5400  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi        C:\Windows\system32\drivers\acpipmi.sys
11:38:56.0683 5400  AcpiPmi - ok
11:38:56.0761 5400  [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
11:38:56.0792 5400  AdobeARMservice - ok
11:38:56.0901 5400  [ F040037B149FD0F5A5044AE563390FA7 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
11:38:56.0932 5400  AdobeFlashPlayerUpdateSvc - ok
11:38:56.0995 5400  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
11:38:57.0026 5400  adp94xx - ok
11:38:57.0057 5400  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci        C:\Windows\system32\drivers\adpahci.sys
11:38:57.0088 5400  adpahci - ok
11:38:57.0135 5400  [ E109549C90F62FB570B9540C4B148E54 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
11:38:57.0166 5400  adpu320 - ok
11:38:57.0198 5400  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
11:38:57.0291 5400  AeLookupSvc - ok
11:38:57.0338 5400  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD            C:\Windows\system32\drivers\afd.sys
11:38:57.0400 5400  AFD - ok
11:38:57.0432 5400  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\Windows\system32\drivers\agp440.sys
11:38:57.0447 5400  agp440 - ok
11:38:57.0478 5400  [ 3290D6946B5E30E70414990574883DDB ] ALG            C:\Windows\System32\alg.exe
11:38:57.0510 5400  ALG - ok
11:38:57.0541 5400  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\Windows\system32\drivers\aliide.sys
11:38:57.0556 5400  aliide - ok
11:38:57.0588 5400  [ 8893C00A6D0A5820D4608202F99E8AD6 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
11:38:57.0634 5400  AMD External Events Utility - ok
11:38:57.0697 5400  AMD FUEL Service - ok
11:38:57.0728 5400  [ 2EF1BA6D5DC79FCE5E9216C8C2D3F193 ] amdhub30        C:\Windows\system32\DRIVERS\amdhub30.sys
11:38:57.0744 5400  amdhub30 - ok
11:38:57.0759 5400  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\Windows\system32\drivers\amdide.sys
11:38:57.0759 5400  amdide - ok
11:38:57.0775 5400  [ 6A2EEB0C4133B20773BB3DD0B7B377B4 ] amdiox64        C:\Windows\system32\DRIVERS\amdiox64.sys
11:38:57.0790 5400  amdiox64 - ok
11:38:57.0822 5400  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
11:38:57.0853 5400  AmdK8 - ok
11:38:58.0040 5400  [ ACF6058602D202F36C0A2C0C97DB5E3B ] amdkmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
11:38:58.0274 5400  amdkmdag - ok
11:38:58.0305 5400  [ 1E55EA0AD65688EB43CCE6AED573E82C ] amdkmdap        C:\Windows\system32\DRIVERS\atikmpag.sys
11:38:58.0336 5400  amdkmdap - ok
11:38:58.0368 5400  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
11:38:58.0383 5400  AmdPPM - ok
11:38:58.0399 5400  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata        C:\Windows\system32\drivers\amdsata.sys
11:38:58.0414 5400  amdsata - ok
11:38:58.0446 5400  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
11:38:58.0461 5400  amdsbs - ok
11:38:58.0461 5400  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata        C:\Windows\system32\drivers\amdxata.sys
11:38:58.0477 5400  amdxata - ok
11:38:58.0508 5400  [ 541A6C49C792ED71FB3EFF8C815CFE60 ] amdxhc          C:\Windows\system32\DRIVERS\amdxhc.sys
11:38:58.0524 5400  amdxhc - ok
11:38:58.0539 5400  [ A1434F35B7B171CB697D74D33F7D029F ] amd_sata        C:\Windows\system32\drivers\amd_sata.sys
11:38:58.0555 5400  amd_sata - ok
11:38:58.0570 5400  [ E9B5A82FA268BB2D1B012030D5F4E096 ] amd_xata        C:\Windows\system32\drivers\amd_xata.sys
11:38:58.0586 5400  amd_xata - ok
11:38:58.0633 5400  [ D9A92E6DD41C5ADC045AE485026AA40C ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
11:38:58.0648 5400  AntiVirSchedulerService - ok
11:38:58.0680 5400  [ 66A7A38F7C439153B758548375EB9E5E ] AntiVirService  C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
11:38:58.0680 5400  AntiVirService - ok
11:38:58.0726 5400  [ 89A69C3F2F319B43379399547526D952 ] AppID          C:\Windows\system32\drivers\appid.sys
11:38:58.0836 5400  AppID - ok
11:38:58.0851 5400  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
11:38:58.0898 5400  AppIDSvc - ok
11:38:58.0976 5400  [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo        C:\Windows\System32\appinfo.dll
11:38:59.0023 5400  Appinfo - ok
11:38:59.0054 5400  [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
11:38:59.0085 5400  Apple Mobile Device - ok
11:38:59.0116 5400  [ C484F8CEB1717C540242531DB7845C4E ] arc            C:\Windows\system32\drivers\arc.sys
11:38:59.0132 5400  arc - ok
11:38:59.0163 5400  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\Windows\system32\drivers\arcsas.sys
11:38:59.0179 5400  arcsas - ok
11:38:59.0210 5400  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
11:38:59.0257 5400  AsyncMac - ok
11:38:59.0288 5400  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi          C:\Windows\system32\drivers\atapi.sys
11:38:59.0304 5400  atapi - ok
11:38:59.0350 5400  [ 24464B908E143D2561E9E452FEE97309 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
11:38:59.0350 5400  AtiHDAudioService - ok
11:38:59.0413 5400  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
11:38:59.0475 5400  AudioEndpointBuilder - ok
11:38:59.0491 5400  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
11:38:59.0522 5400  AudioSrv - ok
11:38:59.0584 5400  [ 09E6069EF94B345061B4BD3CEBD974C8 ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
11:38:59.0616 5400  avgntflt - ok
11:38:59.0678 5400  [ 488486DAD09A5B6C6DBB8B990A8B2307 ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
11:38:59.0709 5400  avipbb - ok
11:38:59.0740 5400  [ 490FA25161BF3E51993EB724ECF0ACEB ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
11:38:59.0740 5400  avkmgr - ok
11:38:59.0803 5400  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\Windows\System32\AxInstSV.dll
11:38:59.0896 5400  AxInstSV - ok
11:38:59.0928 5400  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv        C:\Windows\system32\drivers\bxvbda.sys
11:38:59.0959 5400  b06bdrv - ok
11:39:00.0006 5400  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
11:39:00.0052 5400  b57nd60a - ok
11:39:00.0099 5400  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\Windows\System32\bdesvc.dll
11:39:00.0146 5400  BDESVC - ok
11:39:00.0177 5400  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\Windows\system32\drivers\Beep.sys
11:39:00.0240 5400  Beep - ok
11:39:00.0318 5400  [ 82974D6A2FD19445CC5171FC378668A4 ] BFE            C:\Windows\System32\bfe.dll
11:39:00.0380 5400  BFE - ok
11:39:00.0396 5400  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\Windows\system32\qmgr.dll
11:39:00.0458 5400  BITS - ok
11:39:00.0474 5400  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
11:39:00.0520 5400  blbdrive - ok
11:39:00.0552 5400  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
11:39:00.0567 5400  Bonjour Service - ok
11:39:00.0645 5400  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
11:39:00.0692 5400  bowser - ok
11:39:00.0708 5400  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
11:39:00.0739 5400  BrFiltLo - ok
11:39:00.0770 5400  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
11:39:00.0801 5400  BrFiltUp - ok
11:39:00.0848 5400  [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP        C:\Windows\system32\DRIVERS\bridge.sys
11:39:00.0926 5400  BridgeMP - ok
11:39:00.0942 5400  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser        C:\Windows\System32\browser.dll
11:39:00.0957 5400  Browser - ok
11:39:00.0988 5400  [ E5E9B1625A767CEB6F319C12D33EAB78 ] BrSerIb        C:\Windows\system32\DRIVERS\BrSerIb.sys
11:39:01.0020 5400  BrSerIb - ok
11:39:01.0035 5400  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
11:39:01.0066 5400  Brserid - ok
11:39:01.0082 5400  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
11:39:01.0098 5400  BrSerWdm - ok
11:39:01.0129 5400  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
11:39:01.0144 5400  BrUsbMdm - ok
11:39:01.0176 5400  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
11:39:01.0191 5400  BrUsbSer - ok
11:39:01.0222 5400  [ D9F6B30AD93CBD165EC71FADF51DF25E ] BrUsbSIb        C:\Windows\system32\DRIVERS\BrUsbSIb.sys
11:39:01.0254 5400  BrUsbSIb - ok
11:39:01.0254 5400  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
11:39:01.0285 5400  BTHMODEM - ok
11:39:01.0300 5400  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv        C:\Windows\system32\bthserv.dll
11:39:01.0332 5400  bthserv - ok
11:39:01.0347 5400  catchme - ok
11:39:01.0363 5400  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
11:39:01.0425 5400  cdfs - ok
11:39:01.0472 5400  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
11:39:01.0503 5400  cdrom - ok
11:39:01.0534 5400  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc    C:\Windows\System32\certprop.dll
11:39:01.0612 5400  CertPropSvc - ok
11:39:01.0644 5400  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\Windows\system32\drivers\circlass.sys
11:39:01.0659 5400  circlass - ok
11:39:01.0675 5400  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\Windows\system32\CLFS.sys
11:39:01.0690 5400  CLFS - ok
11:39:01.0768 5400  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:39:01.0800 5400  clr_optimization_v2.0.50727_32 - ok
11:39:01.0846 5400  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
11:39:01.0878 5400  clr_optimization_v2.0.50727_64 - ok
11:39:01.0956 5400  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
11:39:02.0002 5400  clr_optimization_v4.0.30319_32 - ok
11:39:02.0080 5400  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
11:39:02.0096 5400  clr_optimization_v4.0.30319_64 - ok
11:39:02.0112 5400  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\Windows\system32\drivers\CmBatt.sys
11:39:02.0127 5400  CmBatt - ok
11:39:02.0143 5400  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\Windows\system32\drivers\cmdide.sys
11:39:02.0143 5400  cmdide - ok
11:39:02.0174 5400  [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG            C:\Windows\system32\Drivers\cng.sys
11:39:02.0205 5400  CNG - ok
11:39:02.0221 5400  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
11:39:02.0236 5400  Compbatt - ok
11:39:02.0252 5400  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
11:39:02.0283 5400  CompositeBus - ok
11:39:02.0299 5400  COMSysApp - ok
11:39:02.0346 5400  [ A2E0A490F1F49ED6E3B83DB52679B036 ] CoordinatorServiceHost C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
11:39:02.0377 5400  CoordinatorServiceHost - ok
11:39:02.0392 5400  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
11:39:02.0392 5400  crcdisk - ok
11:39:02.0424 5400  [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc        C:\Windows\system32\cryptsvc.dll
11:39:02.0470 5400  CryptSvc - ok
11:39:02.0533 5400  [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc          C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
11:39:02.0548 5400  cvhsvc - ok
11:39:02.0658 5400  [ 7F5CD87CA5BDB4D83F992D8C77201483 ] CyberLink PowerDVD 10 MS Monitor Service C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe
11:39:02.0689 5400  CyberLink PowerDVD 10 MS Monitor Service - ok
11:39:02.0720 5400  [ 9FAF58E876A3B1DB3030A0A5805F2D86 ] CyberLink PowerDVD 10 MS Service C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe
11:39:02.0736 5400  CyberLink PowerDVD 10 MS Service - ok
11:39:02.0767 5400  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\Windows\system32\rpcss.dll
11:39:02.0829 5400  DcomLaunch - ok
11:39:02.0876 5400  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc      C:\Windows\System32\defragsvc.dll
11:39:02.0938 5400  defragsvc - ok
11:39:02.0954 5400  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
11:39:03.0001 5400  DfsC - ok
11:39:03.0032 5400  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\Windows\system32\dhcpcore.dll
11:39:03.0063 5400  Dhcp - ok
11:39:03.0063 5400  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\Windows\system32\drivers\discache.sys
11:39:03.0110 5400  discache - ok
11:39:03.0126 5400  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\Windows\system32\drivers\disk.sys
11:39:03.0141 5400  Disk - ok
11:39:03.0172 5400  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
11:39:03.0219 5400  Dnscache - ok
11:39:03.0250 5400  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc        C:\Windows\System32\dot3svc.dll
11:39:03.0313 5400  dot3svc - ok
11:39:03.0313 5400  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS            C:\Windows\system32\dps.dll
11:39:03.0344 5400  DPS - ok
11:39:03.0375 5400  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
11:39:03.0422 5400  drmkaud - ok
11:39:03.0453 5400  [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
11:39:03.0484 5400  DXGKrnl - ok
11:39:03.0516 5400  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost        C:\Windows\System32\eapsvc.dll
11:39:03.0547 5400  EapHost - ok
11:39:03.0609 5400  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv          C:\Windows\system32\drivers\evbda.sys
11:39:03.0703 5400  ebdrv - ok
11:39:03.0718 5400  [ C118A82CD78818C29AB228366EBF81C3 ] EFS            C:\Windows\System32\lsass.exe
11:39:03.0750 5400  EFS - ok
11:39:03.0796 5400  [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
11:39:03.0859 5400  ehRecvr - ok
11:39:03.0874 5400  [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched        C:\Windows\ehome\ehsched.exe
11:39:03.0921 5400  ehSched - ok
11:39:03.0937 5400  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
11:39:03.0968 5400  elxstor - ok
11:39:03.0984 5400  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\Windows\system32\drivers\errdev.sys
11:39:03.0999 5400  ErrDev - ok
11:39:04.0046 5400  esgiguard - ok
11:39:04.0077 5400  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem    C:\Windows\system32\es.dll
11:39:04.0124 5400  EventSystem - ok
11:39:04.0155 5400  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat          C:\Windows\system32\drivers\exfat.sys
11:39:04.0202 5400  exfat - ok
11:39:04.0218 5400  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat        C:\Windows\system32\drivers\fastfat.sys
11:39:04.0280 5400  fastfat - ok
11:39:04.0311 5400  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax            C:\Windows\system32\fxssvc.exe
11:39:04.0358 5400  Fax - ok
11:39:04.0374 5400  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc            C:\Windows\system32\drivers\fdc.sys
11:39:04.0420 5400  fdc - ok
11:39:04.0436 5400  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost        C:\Windows\system32\fdPHost.dll
11:39:04.0498 5400  fdPHost - ok
11:39:04.0514 5400  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\Windows\system32\fdrespub.dll
11:39:04.0545 5400  FDResPub - ok
11:39:04.0561 5400  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
11:39:04.0576 5400  FileInfo - ok
11:39:04.0576 5400  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
11:39:04.0623 5400  Filetrace - ok
11:39:04.0670 5400  [ 73081CF28F0AE20A52CA4F67CEE6E6B0 ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
11:39:04.0701 5400  FLEXnet Licensing Service - ok
11:39:04.0764 5400  [ 5CEE6CD43AE5844C49300EA0B1E557EE ] FLEXnet Licensing Service 64 C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
11:39:04.0826 5400  FLEXnet Licensing Service 64 - ok
11:39:04.0857 5400  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
11:39:04.0873 5400  flpydisk - ok
11:39:04.0888 5400  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
11:39:04.0920 5400  FltMgr - ok
11:39:04.0966 5400  [ C4C183E6551084039EC862DA1C945E3D ] FontCache      C:\Windows\system32\FntCache.dll
11:39:05.0044 5400  FontCache - ok
11:39:05.0091 5400  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
11:39:05.0107 5400  FontCache3.0.0.0 - ok
11:39:05.0107 5400  [ D43703496149971890703B4B1B723EAC ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
11:39:05.0122 5400  FsDepends - ok
11:39:05.0154 5400  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
11:39:05.0154 5400  Fs_Rec - ok
11:39:05.0185 5400  [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
11:39:05.0200 5400  fvevol - ok
11:39:05.0200 5400  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
11:39:05.0216 5400  gagp30kx - ok
11:39:05.0247 5400  [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
11:39:05.0247 5400  GEARAspiWDM - ok
11:39:05.0278 5400  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc          C:\Windows\System32\gpsvc.dll
11:39:05.0325 5400  gpsvc - ok
11:39:05.0372 5400  [ F02A533F517EB38333CB12A9E8963773 ] gupdate        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:39:05.0388 5400  gupdate - ok
11:39:05.0419 5400  [ F02A533F517EB38333CB12A9E8963773 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:39:05.0419 5400  gupdatem - ok
11:39:05.0450 5400  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
11:39:05.0466 5400  hcw85cir - ok
11:39:05.0512 5400  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
11:39:05.0544 5400  HdAudAddService - ok
11:39:05.0559 5400  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
11:39:05.0575 5400  HDAudBus - ok
11:39:05.0590 5400  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt        C:\Windows\system32\drivers\HidBatt.sys
11:39:05.0606 5400  HidBatt - ok
11:39:05.0622 5400  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\Windows\system32\drivers\hidbth.sys
11:39:05.0653 5400  HidBth - ok
11:39:05.0684 5400  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr          C:\Windows\system32\drivers\hidir.sys
11:39:05.0700 5400  HidIr - ok
11:39:05.0715 5400  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv        C:\Windows\System32\hidserv.dll
11:39:05.0762 5400  hidserv - ok
11:39:05.0793 5400  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
11:39:05.0824 5400  HidUsb - ok
11:39:05.0840 5400  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\Windows\system32\kmsvc.dll
11:39:05.0918 5400  hkmsvc - ok
11:39:05.0934 5400  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
11:39:05.0965 5400  HomeGroupListener - ok
11:39:05.0996 5400  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
11:39:06.0012 5400  HomeGroupProvider - ok
11:39:06.0027 5400  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
11:39:06.0043 5400  HpSAMD - ok
11:39:06.0090 5400  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
11:39:06.0136 5400  HTTP - ok
11:39:06.0136 5400  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
11:39:06.0168 5400  hwpolicy - ok
11:39:06.0214 5400  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
11:39:06.0246 5400  i8042prt - ok
11:39:06.0292 5400  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
11:39:06.0324 5400  iaStorV - ok
11:39:06.0370 5400  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
11:39:06.0433 5400  idsvc - ok
11:39:06.0558 5400  [ A87261EF1546325B559374F5689CF5BC ] igfx            C:\Windows\system32\DRIVERS\igdkmd64.sys
11:39:06.0729 5400  igfx - ok
11:39:06.0745 5400  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
11:39:06.0760 5400  iirsp - ok
11:39:06.0792 5400  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\Windows\System32\ikeext.dll
11:39:06.0854 5400  IKEEXT - ok
11:39:06.0994 5400  [ 21F54139C93FC595902B58ED947D47D5 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
11:39:07.0057 5400  IntcAzAudAddService - ok
11:39:07.0072 5400  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\Windows\system32\drivers\intelide.sys
11:39:07.0088 5400  intelide - ok
11:39:07.0104 5400  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\Windows\system32\drivers\intelppm.sys
11:39:07.0135 5400  intelppm - ok
11:39:07.0135 5400  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
11:39:07.0182 5400  IPBusEnum - ok
11:39:07.0197 5400  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:39:07.0244 5400  IpFilterDriver - ok
11:39:07.0275 5400  [ 08C2957BB30058E663720C5606885653 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
11:39:07.0322 5400  iphlpsvc - ok
11:39:07.0338 5400  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV        C:\Windows\system32\drivers\IPMIDrv.sys
11:39:07.0369 5400  IPMIDRV - ok
11:39:07.0384 5400  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
11:39:07.0416 5400  IPNAT - ok
11:39:07.0462 5400  [ 4EFFC8FF6D349E971E94B1C670C0C66A ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
11:39:07.0478 5400  iPod Service - ok
11:39:07.0509 5400  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
11:39:07.0556 5400  IRENUM - ok
11:39:07.0587 5400  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
11:39:07.0618 5400  isapnp - ok
11:39:07.0634 5400  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
11:39:07.0665 5400  iScsiPrt - ok
11:39:07.0712 5400  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
11:39:07.0743 5400  kbdclass - ok
11:39:07.0743 5400  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
11:39:07.0759 5400  kbdhid - ok
11:39:07.0774 5400  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\Windows\system32\lsass.exe
11:39:07.0790 5400  KeyIso - ok
11:39:07.0821 5400  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
11:39:07.0837 5400  KSecDD - ok
11:39:07.0852 5400  [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
11:39:07.0868 5400  KSecPkg - ok
11:39:07.0868 5400  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
11:39:07.0899 5400  ksthunk - ok
11:39:07.0915 5400  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm          C:\Windows\system32\msdtckrm.dll
11:39:07.0962 5400  KtmRm - ok
11:39:07.0977 5400  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\Windows\System32\srvsvc.dll
11:39:08.0024 5400  LanmanServer - ok
11:39:08.0040 5400  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
11:39:08.0086 5400  LanmanWorkstation - ok
11:39:08.0102 5400  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
11:39:08.0149 5400  lltdio - ok
11:39:08.0149 5400  [ C1185803384AB3FEED115F79F109427F ] lltdsvc        C:\Windows\System32\lltdsvc.dll
11:39:08.0196 5400  lltdsvc - ok
11:39:08.0196 5400  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts        C:\Windows\System32\lmhsvc.dll
11:39:08.0242 5400  lmhosts - ok
11:39:08.0274 5400  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
11:39:08.0289 5400  LSI_FC - ok
11:39:08.0305 5400  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
11:39:08.0320 5400  LSI_SAS - ok
11:39:08.0336 5400  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
11:39:08.0352 5400  LSI_SAS2 - ok
11:39:08.0398 5400  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
11:39:08.0414 5400  LSI_SCSI - ok
11:39:08.0430 5400  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv          C:\Windows\system32\drivers\luafv.sys
11:39:08.0461 5400  luafv - ok
11:39:08.0508 5400  [ A8FE8F2783B2929B56F5370A89356CE9 ] MBAMProtector  C:\Windows\system32\drivers\mbam.sys
11:39:08.0539 5400  MBAMProtector - ok
11:39:08.0570 5400  [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
11:39:08.0586 5400  MBAMScheduler - ok
11:39:08.0617 5400  [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
11:39:08.0648 5400  MBAMService - ok
11:39:08.0679 5400  [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
11:39:08.0710 5400  Mcx2Svc - ok
11:39:08.0710 5400  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas        C:\Windows\system32\drivers\megasas.sys
11:39:08.0726 5400  megasas - ok
11:39:08.0757 5400  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
11:39:08.0773 5400  MegaSR - ok
11:39:08.0804 5400  [ 8A43D23ACE2E8C95A2D87B6E9599DEDA ] MemeoBackgroundService C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe
11:39:08.0820 5400  MemeoBackgroundService - ok
11:39:08.0835 5400  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS          C:\Windows\system32\mmcss.dll
11:39:08.0882 5400  MMCSS - ok
11:39:08.0882 5400  [ 800BA92F7010378B09F9ED9270F07137 ] Modem          C:\Windows\system32\drivers\modem.sys
11:39:08.0929 5400  Modem - ok
11:39:08.0944 5400  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
11:39:08.0960 5400  monitor - ok
11:39:08.0991 5400  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
11:39:08.0991 5400  mouclass - ok
11:39:09.0038 5400  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
11:39:09.0069 5400  mouhid - ok
11:39:09.0085 5400  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
11:39:09.0100 5400  mountmgr - ok
11:39:09.0132 5400  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\Windows\system32\drivers\mpio.sys
11:39:09.0147 5400  mpio - ok
11:39:09.0147 5400  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
11:39:09.0178 5400  mpsdrv - ok
11:39:09.0194 5400  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc          C:\Windows\system32\mpssvc.dll
11:39:09.0256 5400  MpsSvc - ok
11:39:09.0256 5400  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
11:39:09.0303 5400  MRxDAV - ok
11:39:09.0319 5400  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
11:39:09.0350 5400  mrxsmb - ok
11:39:09.0366 5400  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:39:09.0397 5400  mrxsmb10 - ok
11:39:09.0412 5400  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:39:09.0428 5400  mrxsmb20 - ok
11:39:09.0444 5400  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\Windows\system32\drivers\msahci.sys
11:39:09.0459 5400  msahci - ok
11:39:09.0475 5400  [ DB801A638D011B9633829EB6F663C900 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
11:39:09.0490 5400  msdsm - ok
11:39:09.0506 5400  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC          C:\Windows\System32\msdtc.exe
11:39:09.0522 5400  MSDTC - ok
11:39:09.0537 5400  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
11:39:09.0568 5400  Msfs - ok
11:39:09.0584 5400  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
11:39:09.0631 5400  mshidkmdf - ok
11:39:09.0646 5400  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
11:39:09.0678 5400  msisadrv - ok
11:39:09.0709 5400  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
11:39:09.0756 5400  MSiSCSI - ok
11:39:09.0756 5400  msiserver - ok
11:39:09.0771 5400  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
11:39:09.0802 5400  MSKSSRV - ok
11:39:09.0834 5400  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
11:39:09.0865 5400  MSPCLOCK - ok
11:39:09.0880 5400  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
11:39:09.0912 5400  MSPQM - ok
11:39:09.0927 5400  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
11:39:09.0943 5400  MsRPC - ok
11:39:09.0958 5400  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
11:39:09.0958 5400  mssmbios - ok
11:39:09.0974 5400  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
11:39:10.0005 5400  MSTEE - ok
11:39:10.0052 5400  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
11:39:10.0068 5400  MTConfig - ok
11:39:10.0083 5400  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup            C:\Windows\system32\Drivers\mup.sys
11:39:10.0099 5400  Mup - ok
11:39:10.0130 5400  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\Windows\system32\qagentRT.dll
11:39:10.0161 5400  napagent - ok
11:39:10.0208 5400  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
11:39:10.0255 5400  NativeWifiP - ok
11:39:10.0286 5400  [ 760E38053BF56E501D562B70AD796B88 ] NDIS            C:\Windows\system32\drivers\ndis.sys
11:39:10.0317 5400  NDIS - ok
11:39:10.0348 5400  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
11:39:10.0380 5400  NdisCap - ok
11:39:10.0395 5400  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
11:39:10.0426 5400  NdisTapi - ok
11:39:10.0442 5400  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
11:39:10.0473 5400  Ndisuio - ok
11:39:10.0489 5400  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
11:39:10.0536 5400  NdisWan - ok
11:39:10.0536 5400  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
11:39:10.0567 5400  NDProxy - ok
11:39:10.0582 5400  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
11:39:10.0629 5400  NetBIOS - ok
11:39:10.0645 5400  [ 09594D1089C523423B32A4229263F068 ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
11:39:10.0692 5400  NetBT - ok
11:39:10.0707 5400  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\Windows\system32\lsass.exe
11:39:10.0707 5400  Netlogon - ok
11:39:10.0754 5400  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\Windows\System32\netman.dll
11:39:10.0801 5400  Netman - ok
11:39:10.0816 5400  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\Windows\System32\netprofm.dll
11:39:10.0863 5400  netprofm - ok
11:39:10.0879 5400  [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:39:10.0894 5400  NetTcpPortSharing - ok
11:39:10.0910 5400  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
11:39:10.0926 5400  nfrd960 - ok
11:39:10.0941 5400  [ 8AD77806D336673F270DB31645267293 ] NlaSvc          C:\Windows\System32\nlasvc.dll
11:39:10.0972 5400  NlaSvc - ok
11:39:10.0988 5400  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
11:39:11.0019 5400  Npfs - ok
11:39:11.0019 5400  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi            C:\Windows\system32\nsisvc.dll
11:39:11.0066 5400  nsi - ok
11:39:11.0066 5400  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
11:39:11.0113 5400  nsiproxy - ok
11:39:11.0160 5400  [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
11:39:11.0206 5400  Ntfs - ok
11:39:11.0222 5400  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\Windows\system32\drivers\Null.sys
11:39:11.0253 5400  Null - ok
11:39:11.0316 5400  [ A85B4F2EF3A7304A5399EF0526423040 ] NVENETFD        C:\Windows\system32\DRIVERS\nvm62x64.sys
11:39:11.0362 5400  NVENETFD - ok
11:39:11.0550 5400  [ DD81FBC57AB9134CDDC5CE90880BFD80 ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
11:39:11.0830 5400  nvlddmkm - ok
11:39:11.0846 5400  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\Windows\system32\drivers\nvraid.sys
11:39:11.0862 5400  nvraid - ok
11:39:11.0877 5400  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\Windows\system32\drivers\nvstor.sys
11:39:11.0893 5400  nvstor - ok
11:39:11.0908 5400  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
11:39:11.0924 5400  nv_agp - ok
11:39:11.0955 5400  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
11:39:11.0986 5400  ohci1394 - ok
11:39:12.0018 5400  [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:39:12.0033 5400  ose - ok
11:39:12.0127 5400  [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc        C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
11:39:12.0267 5400  osppsvc - ok
11:39:12.0283 5400  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
11:39:12.0298 5400  p2pimsvc - ok
11:39:12.0314 5400  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\Windows\system32\p2psvc.dll
11:39:12.0345 5400  p2psvc - ok
11:39:12.0361 5400  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport        C:\Windows\system32\drivers\parport.sys
11:39:12.0376 5400  Parport - ok
11:39:12.0392 5400  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr        C:\Windows\system32\drivers\partmgr.sys
11:39:12.0408 5400  partmgr - ok
11:39:12.0423 5400  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\Windows\System32\pcasvc.dll
11:39:12.0454 5400  PcaSvc - ok
11:39:12.0486 5400  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci            C:\Windows\system32\drivers\pci.sys
11:39:12.0501 5400  pci - ok
11:39:12.0517 5400  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\Windows\system32\drivers\pciide.sys
11:39:12.0532 5400  pciide - ok
11:39:12.0548 5400  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
11:39:12.0564 5400  pcmcia - ok
11:39:12.0579 5400  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw            C:\Windows\system32\drivers\pcw.sys
11:39:12.0595 5400  pcw - ok
11:39:12.0610 5400  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
11:39:12.0673 5400  PEAUTH - ok
11:39:12.0720 5400  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
11:39:12.0751 5400  PerfHost - ok
11:39:12.0798 5400  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla            C:\Windows\system32\pla.dll
11:39:12.0845 5400  pla - ok
11:39:12.0891 5400  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
11:39:12.0938 5400  PlugPlay - ok
11:39:12.0954 5400  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
11:39:12.0985 5400  PNRPAutoReg - ok
11:39:12.0985 5400  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
11:39:13.0001 5400  PNRPsvc - ok
11:39:13.0032 5400  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
11:39:13.0063 5400  PolicyAgent - ok
11:39:13.0079 5400  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power          C:\Windows\system32\umpo.dll
11:39:13.0125 5400  Power - ok
11:39:13.0141 5400  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
11:39:13.0188 5400  PptpMiniport - ok
11:39:13.0188 5400  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor      C:\Windows\system32\drivers\processr.sys
11:39:13.0203 5400  Processor - ok
11:39:13.0250 5400  [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc        C:\Windows\system32\profsvc.dll
11:39:13.0266 5400  ProfSvc - ok
11:39:13.0281 5400  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
11:39:13.0297 5400  ProtectedStorage - ok
11:39:13.0313 5400  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
11:39:13.0359 5400  Psched - ok
11:39:13.0391 5400  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
11:39:13.0437 5400  ql2300 - ok
11:39:13.0453 5400  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
11:39:13.0469 5400  ql40xx - ok
11:39:13.0469 5400  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE          C:\Windows\system32\qwave.dll
11:39:13.0500 5400  QWAVE - ok
11:39:13.0515 5400  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
11:39:13.0531 5400  QWAVEdrv - ok
11:39:13.0547 5400  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
11:39:13.0578 5400  RasAcd - ok
11:39:13.0609 5400  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
11:39:13.0656 5400  RasAgileVpn - ok
11:39:13.0671 5400  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto        C:\Windows\System32\rasauto.dll
11:39:13.0718 5400  RasAuto - ok
11:39:13.0734 5400  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
11:39:13.0781 5400  Rasl2tp - ok
11:39:13.0796 5400  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\Windows\System32\rasmans.dll
11:39:13.0827 5400  RasMan - ok
11:39:13.0859 5400  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
11:39:13.0905 5400  RasPppoe - ok
11:39:13.0921 5400  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
11:39:13.0968 5400  RasSstp - ok
11:39:13.0983 5400  [ 77F665941019A1594D887A74F301FA2F ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
11:39:14.0015 5400  rdbss - ok
11:39:14.0015 5400  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\Windows\system32\drivers\rdpbus.sys
11:39:14.0046 5400  rdpbus - ok
11:39:14.0061 5400  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
11:39:14.0093 5400  RDPCDD - ok
11:39:14.0124 5400  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
11:39:14.0155 5400  RDPENCDD - ok
11:39:14.0171 5400  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
11:39:14.0202 5400  RDPREFMP - ok
11:39:14.0217 5400  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
11:39:14.0264 5400  RDPWD - ok
11:39:14.0280 5400  [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
11:39:14.0295 5400  rdyboost - ok
11:39:14.0389 5400  [ 6713253B37D6DCFC442A286F1D7B5350 ] Remote Solver for Flow Simulation 2012 C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe
11:39:14.0420 5400  Remote Solver for Flow Simulation 2012 - ok
11:39:14.0451 5400  [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess    C:\Windows\System32\mprdim.dll
11:39:14.0498 5400  RemoteAccess - ok
11:39:14.0498 5400  [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
11:39:14.0545 5400  RemoteRegistry - ok
11:39:14.0561 5400  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
11:39:14.0592 5400  RpcEptMapper - ok
11:39:14.0607 5400  [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator      C:\Windows\system32\locator.exe
11:39:14.0623 5400  RpcLocator - ok
11:39:14.0639 5400  [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs          C:\Windows\system32\rpcss.dll
11:39:14.0670 5400  RpcSs - ok
11:39:14.0685 5400  [ DDC86E4F8E7456261E637E3552E804FF ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
11:39:14.0717 5400  rspndr - ok
11:39:14.0748 5400  [ 39A719875F572241C585A629EE62EB14 ] RTL8167        C:\Windows\system32\DRIVERS\Rt64win7.sys
11:39:14.0779 5400  RTL8167 - ok
11:39:14.0810 5400  [ B3F36B4B3F192EA87DDC119F3A0B3E45 ] RTL8192su      C:\Windows\system32\DRIVERS\RTL8192su.sys
11:39:14.0857 5400  RTL8192su - ok
11:39:14.0873 5400  [ C118A82CD78818C29AB228366EBF81C3 ] SamSs          C:\Windows\system32\lsass.exe
11:39:14.0873 5400  SamSs - ok
11:39:14.0904 5400  [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
11:39:14.0904 5400  sbp2port - ok
11:39:14.0919 5400  [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr        C:\Windows\System32\SCardSvr.dll
11:39:14.0951 5400  SCardSvr - ok
11:39:14.0966 5400  [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
11:39:15.0013 5400  scfilter - ok
11:39:15.0029 5400  [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule        C:\Windows\system32\schedsvc.dll
11:39:15.0091 5400  Schedule - ok
11:39:15.0107 5400  [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc    C:\Windows\System32\certprop.dll
11:39:15.0122 5400  SCPolicySvc - ok
11:39:15.0138 5400  [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
11:39:15.0185 5400  SDRSVC - ok
11:39:15.0200 5400  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
11:39:15.0231 5400  secdrv - ok
11:39:15.0247 5400  [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon        C:\Windows\system32\seclogon.dll
11:39:15.0278 5400  seclogon - ok
11:39:15.0278 5400  [ C32AB8FA018EF34C0F113BD501436D21 ] SENS            C:\Windows\system32\sens.dll
11:39:15.0325 5400  SENS - ok
11:39:15.0341 5400  [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
11:39:15.0372 5400  SensrSvc - ok
11:39:15.0403 5400  [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum        C:\Windows\system32\drivers\serenum.sys
11:39:15.0419 5400  Serenum - ok
11:39:15.0450 5400  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial          C:\Windows\system32\drivers\serial.sys
11:39:15.0465 5400  Serial - ok
11:39:15.0481 5400  [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse        C:\Windows\system32\drivers\sermouse.sys
11:39:15.0512 5400  sermouse - ok
11:39:15.0528 5400  [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv      C:\Windows\system32\sessenv.dll
11:39:15.0559 5400  SessionEnv - ok
11:39:15.0606 5400  [ A554811BCD09279536440C964AE35BBF ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
11:39:15.0637 5400  sffdisk - ok
11:39:15.0653 5400  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
11:39:15.0668 5400  sffp_mmc - ok
11:39:15.0684 5400  [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
11:39:15.0699 5400  sffp_sd - ok
11:39:15.0715 5400  [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
11:39:15.0746 5400  sfloppy - ok
11:39:15.0777 5400  [ C6CC9297BD53E5229653303E556AA539 ] Sftfs          C:\Windows\system32\DRIVERS\Sftfslh.sys
11:39:15.0809 5400  Sftfs - ok
11:39:15.0840 5400  [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist        C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
11:39:15.0855 5400  sftlist - ok
11:39:15.0871 5400  [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay        C:\Windows\system32\DRIVERS\Sftplaylh.sys
11:39:15.0887 5400  Sftplay - ok
11:39:15.0902 5400  [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir        C:\Windows\system32\DRIVERS\Sftredirlh.sys
11:39:15.0902 5400  Sftredir - ok
11:39:15.0918 5400  [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol          C:\Windows\system32\DRIVERS\Sftvollh.sys
11:39:15.0918 5400  Sftvol - ok
11:39:15.0933 5400  [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa          C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
11:39:15.0949 5400  sftvsa - ok
11:39:15.0980 5400  [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess    C:\Windows\System32\ipnathlp.dll
11:39:16.0011 5400  SharedAccess - ok
11:39:16.0027 5400  [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
11:39:16.0074 5400  ShellHWDetection - ok
11:39:16.0089 5400  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
11:39:16.0089 5400  SiSRaid2 - ok
11:39:16.0121 5400  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
11:39:16.0136 5400  SiSRaid4 - ok
11:39:16.0167 5400  [ 7C15061CD0372487903B07B9BB03AFAD ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
11:39:16.0199 5400  SkypeUpdate - ok
11:39:16.0230 5400  [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
11:39:16.0277 5400  Smb - ok
11:39:16.0292 5400  [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
11:39:16.0308 5400  SNMPTRAP - ok
11:39:16.0323 5400  [ 4945020BC094C322571184A6E8056B3A ] SolidWorks Licensing Service C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
11:39:16.0355 5400  SolidWorks Licensing Service ( UnsignedFile.Multi.Generic ) - warning
11:39:16.0355 5400  SolidWorks Licensing Service - detected UnsignedFile.Multi.Generic (1)
11:39:16.0370 5400  [ B9E31E5CACDFE584F34F730A677803F9 ] spldr          C:\Windows\system32\drivers\spldr.sys
11:39:16.0386 5400  spldr - ok
11:39:16.0417 5400  [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler        C:\Windows\System32\spoolsv.exe
11:39:16.0448 5400  Spooler - ok
11:39:16.0495 5400  [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc          C:\Windows\system32\sppsvc.exe
11:39:16.0589 5400  sppsvc - ok
11:39:16.0604 5400  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify    C:\Windows\system32\sppuinotify.dll
11:39:16.0635 5400  sppuinotify - ok
11:39:16.0682 5400  [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv            C:\Windows\system32\DRIVERS\srv.sys
11:39:16.0745 5400  srv - ok
11:39:16.0760 5400  [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
11:39:16.0807 5400  srv2 - ok
11:39:16.0807 5400  [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
11:39:16.0838 5400  srvnet - ok
11:39:16.0869 5400  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
11:39:16.0901 5400  SSDPSRV - ok
11:39:16.0916 5400  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc        C:\Windows\system32\sstpsvc.dll
11:39:16.0963 5400  SstpSvc - ok
11:39:16.0963 5400  [ F3817967ED533D08327DC73BC4D5542A ] stexstor        C:\Windows\system32\drivers\stexstor.sys
11:39:16.0979 5400  stexstor - ok
11:39:16.0994 5400  [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc          C:\Windows\System32\wiaservc.dll
11:39:17.0025 5400  stisvc - ok
11:39:17.0041 5400  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
11:39:17.0057 5400  swenum - ok
11:39:17.0072 5400  [ E08E46FDD841B7184194011CA1955A0B ] swprv          C:\Windows\System32\swprv.dll
11:39:17.0119 5400  swprv - ok
11:39:17.0150 5400  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain        C:\Windows\system32\sysmain.dll
11:39:17.0213 5400  SysMain - ok
11:39:17.0213 5400  [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
11:39:17.0244 5400  TabletInputService - ok
11:39:17.0259 5400  [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv        C:\Windows\System32\tapisrv.dll
11:39:17.0306 5400  TapiSrv - ok
11:39:17.0322 5400  [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS            C:\Windows\System32\tbssvc.dll
11:39:17.0353 5400  TBS - ok
11:39:17.0415 5400  [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
11:39:17.0509 5400  Tcpip - ok
11:39:17.0556 5400  [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
11:39:17.0587 5400  TCPIP6 - ok
11:39:17.0603 5400  [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
11:39:17.0618 5400  tcpipreg - ok
11:39:17.0634 5400  [ 3371D21011695B16333A3934340C4E7C ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
11:39:17.0665 5400  TDPIPE - ok
11:39:17.0696 5400  [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
11:39:17.0712 5400  TDTCP - ok
11:39:17.0743 5400  [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
11:39:17.0774 5400  tdx - ok
11:39:17.0774 5400  [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
11:39:17.0790 5400  TermDD - ok
11:39:17.0805 5400  [ 2E648163254233755035B46DD7B89123 ] TermService    C:\Windows\System32\termsrv.dll
11:39:17.0868 5400  TermService - ok
11:39:17.0883 5400  [ F0344071948D1A1FA732231785A0664C ] Themes          C:\Windows\system32\themeservice.dll
11:39:17.0899 5400  Themes - ok
11:39:17.0915 5400  [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER    C:\Windows\system32\mmcss.dll
11:39:17.0946 5400  THREADORDER - ok
11:39:17.0961 5400  [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks          C:\Windows\System32\trkwks.dll
11:39:17.0993 5400  TrkWks - ok
11:39:18.0039 5400  [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
11:39:18.0086 5400  TrustedInstaller - ok
11:39:18.0102 5400  [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
11:39:18.0133 5400  tssecsrv - ok
11:39:18.0149 5400  [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
11:39:18.0164 5400  TsUsbFlt - ok
11:39:18.0180 5400  [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD        C:\Windows\system32\drivers\TsUsbGD.sys
11:39:18.0211 5400  TsUsbGD - ok
11:39:18.0242 5400  [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
11:39:18.0289 5400  tunnel - ok
11:39:18.0320 5400  [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
11:39:18.0336 5400  uagp35 - ok
11:39:18.0351 5400  [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
11:39:18.0414 5400  udfs - ok
11:39:18.0429 5400  [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
11:39:18.0461 5400  UI0Detect - ok
11:39:18.0461 5400  [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
11:39:18.0476 5400  uliagpkx - ok
11:39:18.0492 5400  [ DC54A574663A895C8763AF0FA1FF7561 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
11:39:18.0523 5400  umbus - ok
11:39:18.0539 5400  [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass          C:\Windows\system32\drivers\umpass.sys
11:39:18.0570 5400  UmPass - ok
11:39:18.0585 5400  [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost        C:\Windows\System32\upnphost.dll
11:39:18.0632 5400  upnphost - ok
11:39:18.0663 5400  [ C9E9D59C0099A9FF51697E9306A44240 ] USBAAPL64      C:\Windows\system32\Drivers\usbaapl64.sys
11:39:18.0695 5400  USBAAPL64 - ok
11:39:18.0726 5400  [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
11:39:18.0757 5400  usbccgp - ok
11:39:18.0773 5400  [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
11:39:18.0788 5400  usbcir - ok
11:39:18.0804 5400  [ C025055FE7B87701EB042095DF1A2D7B ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
11:39:18.0835 5400  usbehci - ok
11:39:18.0851 5400  [ 33A58C5630200E17B51C8D73DD64181B ] usbfilter      C:\Windows\system32\DRIVERS\usbfilter.sys
11:39:18.0851 5400  usbfilter - ok
11:39:18.0882 5400  [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
11:39:18.0913 5400  usbhub - ok
11:39:18.0929 5400  [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci        C:\Windows\system32\DRIVERS\usbohci.sys
11:39:18.0929 5400  usbohci - ok
11:39:18.0960 5400  [ 73188F58FB384E75C4063D29413CEE3D ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
11:39:18.0991 5400  usbprint - ok
11:39:19.0007 5400  [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
11:39:19.0022 5400  usbscan - ok
11:39:19.0038 5400  [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:39:19.0085 5400  USBSTOR - ok
11:39:19.0100 5400  [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci        C:\Windows\system32\drivers\usbuhci.sys
11:39:19.0116 5400  usbuhci - ok
11:39:19.0131 5400  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms          C:\Windows\System32\uxsms.dll
11:39:19.0163 5400  UxSms - ok
11:39:19.0163 5400  [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc        C:\Windows\system32\lsass.exe
11:39:19.0178 5400  VaultSvc - ok
11:39:19.0194 5400  [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
11:39:19.0209 5400  vdrvroot - ok
11:39:19.0225 5400  [ 8D6B481601D01A456E75C3210F1830BE ] vds            C:\Windows\System32\vds.exe
11:39:19.0256 5400  vds - ok
11:39:19.0287 5400  [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
11:39:19.0303 5400  vga - ok
11:39:19.0319 5400  [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave        C:\Windows\System32\drivers\vga.sys
11:39:19.0350 5400  VgaSave - ok
11:39:19.0365 5400  [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp          C:\Windows\system32\drivers\vhdmp.sys
11:39:19.0381 5400  vhdmp - ok
11:39:19.0397 5400  [ E5689D93FFE4E5D66C0178761240DD54 ] viaide          C:\Windows\system32\drivers\viaide.sys
11:39:19.0412 5400  viaide - ok
11:39:19.0428 5400  [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
11:39:19.0443 5400  volmgr - ok
11:39:19.0443 5400  [ A255814907C89BE58B79EF2F189B843B ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
11:39:19.0459 5400  volmgrx - ok
11:39:19.0475 5400  [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
11:39:19.0490 5400  volsnap - ok
11:39:19.0521 5400  [ 193D323A88F442334D652AC5C1F56414 ] vpnagent        C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
11:39:19.0568 5400  vpnagent - ok
11:39:19.0584 5400  [ 13E6D95E7AC67ABB7A1196557EF8849F ] vpnva          C:\Windows\system32\DRIVERS\vpnva64.sys
11:39:19.0584 5400  vpnva - ok
11:39:19.0599 5400  [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
11:39:19.0615 5400  vsmraid - ok
11:39:19.0662 5400  [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS            C:\Windows\system32\vssvc.exe
11:39:19.0740 5400  VSS - ok
11:39:19.0740 5400  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
11:39:19.0755 5400  vwifibus - ok
11:39:19.0787 5400  [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
11:39:19.0818 5400  vwififlt - ok
11:39:19.0833 5400  [ 1C9D80CC3849B3788048078C26486E1A ] W32Time        C:\Windows\system32\w32time.dll
11:39:19.0865 5400  W32Time - ok
11:39:19.0880 5400  [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
11:39:19.0911 5400  WacomPen - ok
11:39:19.0927 5400  [ 356AFD78A6ED4457169241AC3965230C ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
11:39:19.0958 5400  WANARP - ok
11:39:19.0974 5400  [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
11:39:19.0989 5400  Wanarpv6 - ok
11:39:20.0021 5400  [ 63D7250ED2C2E3CD9B11139A608D6C39 ] watchmi        C:\Program Files (x86)\watchmi\TvdService.exe
11:39:20.0036 5400  watchmi ( UnsignedFile.Multi.Generic ) - warning
11:39:20.0036 5400  watchmi - detected UnsignedFile.Multi.Generic (1)
11:39:20.0083 5400  [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine        C:\Windows\system32\wbengine.exe
11:39:20.0177 5400  wbengine - ok
11:39:20.0192 5400  [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
11:39:20.0239 5400  WbioSrvc - ok
11:39:20.0255 5400  [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc        C:\Windows\System32\wcncsvc.dll
11:39:20.0301 5400  wcncsvc - ok
11:39:20.0301 5400  [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
11:39:20.0333 5400  WcsPlugInService - ok
11:39:20.0364 5400  [ 72889E16FF12BA0F235467D6091B17DC ] Wd              C:\Windows\system32\drivers\wd.sys
11:39:20.0379 5400  Wd - ok
11:39:20.0395 5400  [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
11:39:20.0426 5400  Wdf01000 - ok
11:39:20.0442 5400  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost  C:\Windows\system32\wdi.dll
11:39:20.0520 5400  WdiServiceHost - ok
11:39:20.0535 5400  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost  C:\Windows\system32\wdi.dll
11:39:20.0551 5400  WdiSystemHost - ok
11:39:20.0567 5400  [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient      C:\Windows\System32\webclnt.dll
11:39:20.0613 5400  WebClient - ok
11:39:20.0613 5400  [ C749025A679C5103E575E3B48E092C43 ] Wecsvc          C:\Windows\system32\wecsvc.dll
11:39:20.0660 5400  Wecsvc - ok
11:39:20.0676 5400  [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
11:39:20.0707 5400  wercplsupport - ok
11:39:20.0738 5400  [ 6D137963730144698CBD10F202E9F251 ] WerSvc          C:\Windows\System32\WerSvc.dll
11:39:20.0785 5400  WerSvc - ok
11:39:20.0816 5400  [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
11:39:20.0832 5400  WfpLwf - ok
11:39:20.0847 5400  [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
11:39:20.0863 5400  WIMMount - ok
11:39:20.0879 5400  WinDefend - ok
11:39:20.0879 5400  WinHttpAutoProxySvc - ok
11:39:20.0925 5400  [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
11:39:20.0972 5400  Winmgmt - ok
11:39:21.0019 5400  [ BCB1310604AA415C4508708975B3931E ] WinRM          C:\Windows\system32\WsmSvc.dll
11:39:21.0097 5400  WinRM - ok
11:39:21.0159 5400  [ FE88B288356E7B47B74B13372ADD906D ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
11:39:21.0191 5400  WinUsb - ok
11:39:21.0222 5400  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc        C:\Windows\System32\wlansvc.dll
11:39:21.0253 5400  Wlansvc - ok
11:39:21.0284 5400  [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc        C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
11:39:21.0300 5400  wlcrasvc - ok
11:39:21.0331 5400  [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
11:39:21.0378 5400  wlidsvc - ok
11:39:21.0409 5400  [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
11:39:21.0440 5400  WmiAcpi - ok
11:39:21.0440 5400  [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
11:39:21.0471 5400  wmiApSrv - ok
11:39:21.0487 5400  WMPNetworkSvc - ok
11:39:21.0503 5400  [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
11:39:21.0518 5400  WPCSvc - ok
11:39:21.0534 5400  [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
11:39:21.0549 5400  WPDBusEnum - ok
11:39:21.0549 5400  [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
11:39:21.0581 5400  ws2ifsl - ok
11:39:21.0596 5400  [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc          C:\Windows\system32\wscsvc.dll
11:39:21.0612 5400  wscsvc - ok
11:39:21.0612 5400  WSearch - ok
11:39:21.0659 5400  [ 82E8F5AA03DF7DBDB8A33F700D5D8CDA ] wsvd            C:\Windows\system32\DRIVERS\wsvd.sys
11:39:21.0659 5400  wsvd - ok
11:39:21.0721 5400  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
11:39:21.0768 5400  wuauserv - ok
11:39:21.0799 5400  [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
11:39:21.0815 5400  WudfPf - ok
11:39:21.0846 5400  [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
11:39:21.0877 5400  WUDFRd - ok
11:39:21.0877 5400  [ B20F051B03A966392364C83F009F7D17 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
11:39:21.0893 5400  wudfsvc - ok
11:39:21.0908 5400  [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc        C:\Windows\System32\wwansvc.dll
11:39:21.0939 5400  WwanSvc - ok
11:39:21.0971 5400  ================ Scan global ===============================
11:39:21.0986 5400  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
11:39:22.0017 5400  [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
11:39:22.0033 5400  [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
11:39:22.0049 5400  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
11:39:22.0064 5400  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
11:39:22.0080 5400  [Global] - ok
11:39:22.0080 5400  ================ Scan MBR ==================================
11:39:22.0095 5400  [ AF00FC1920E1CF861B39B90A4375EDF3 ] \Device\Harddisk0\DR0
11:39:22.0314 5400  \Device\Harddisk0\DR0 - ok
11:39:22.0314 5400  ================ Scan VBR ==================================
11:39:22.0314 5400  [ 521BA6E06CF73128BB0825C3637A31E0 ] \Device\Harddisk0\DR0\Partition1
11:39:22.0314 5400  \Device\Harddisk0\DR0\Partition1 - ok
11:39:22.0345 5400  [ 4993626D5E885B3541AE4E9A7F708F20 ] \Device\Harddisk0\DR0\Partition2
11:39:22.0345 5400  \Device\Harddisk0\DR0\Partition2 - ok
11:39:22.0376 5400  [ A39A13EC2C80736C96AE795F1E13A7A9 ] \Device\Harddisk0\DR0\Partition3
11:39:22.0376 5400  \Device\Harddisk0\DR0\Partition3 - ok
11:39:22.0376 5400  ============================================================
11:39:22.0376 5400  Scan finished
11:39:22.0376 5400  ============================================================
11:39:22.0392 5596  Detected object count: 2
11:39:22.0392 5596  Actual detected object count: 2
11:40:28.0209 5596  SolidWorks Licensing Service ( UnsignedFile.Multi.Generic ) - skipped by user
11:40:28.0209 5596  SolidWorks Licensing Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:40:28.0209 5596  watchmi ( UnsignedFile.Multi.Generic ) - skipped by user
11:40:28.0209 5596  watchmi ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:41:19.0908 0372  Deinitialize success










und



Code:

11:45:43.0030 2300  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
11:45:45.0043 2300  ============================================================
11:45:45.0043 2300  Current date / time: 2013/05/18 11:45:45.0043
11:45:45.0043 2300  SystemInfo:
11:45:45.0043 2300 
11:45:45.0043 2300  OS Version: 6.1.7601 ServicePack: 1.0
11:45:45.0043 2300  Product type: Workstation
11:45:45.0043 2300  ComputerName: ALI-PC
11:45:45.0043 2300  UserName: Ali
11:45:45.0043 2300  Windows directory: C:\Windows
11:45:45.0043 2300  System windows directory: C:\Windows
11:45:45.0043 2300  Running under WOW64
11:45:45.0043 2300  Processor architecture: Intel x64
11:45:45.0043 2300  Number of processors: 4
11:45:45.0043 2300  Page size: 0x1000
11:45:45.0043 2300  Boot type: Normal boot
11:45:45.0043 2300  ============================================================
11:45:46.0431 2300  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:45:46.0462 2300  ============================================================
11:45:46.0462 2300  \Device\Harddisk0\DR0:
11:45:46.0462 2300  MBR partitions:
11:45:46.0462 2300  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
11:45:46.0462 2300  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x6E0D3800
11:45:46.0462 2300  \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x6E106000, BlocksNum 0x6400000
11:45:46.0462 2300  ============================================================
11:45:46.0478 2300  C: <-> \Device\Harddisk0\DR0\Partition2
11:45:46.0509 2300  D: <-> \Device\Harddisk0\DR0\Partition3
11:45:46.0509 2300  ============================================================
11:45:46.0509 2300  Initialize success
11:45:46.0509 2300  ============================================================


cosinus 19.05.2013 02:19

Logs sind ok

JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.




Im Anschluss:

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).


Danach eine Kontrolle mit OTL bitte:
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles in CODE-Tags hier in den Thread.

rico89 19.05.2013 12:29

JRT Log

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Home Premium x64
Ran by Ali on 19.05.2013 at 12:47:27,67
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] C:\Windows\syswow64\sho336F.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoEC61.tmp



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\Ali\appdata\local\{14EAC74E-B753-442C-9817-E09CFAFF671C}
Successfully deleted: [Empty Folder] C:\Users\Ali\appdata\local\{20E34768-5806-48C5-9DBF-F3FB8B296E44}
Successfully deleted: [Empty Folder] C:\Users\Ali\appdata\local\{2A230A30-EC0A-4F9D-BBC2-5FF4EDAF4CAE}
Successfully deleted: [Empty Folder] C:\Users\Ali\appdata\local\{2C022E2E-0D64-4264-9019-6AF522A8BAF0}
Successfully deleted: [Empty Folder] C:\Users\Ali\appdata\local\{522AD0D7-90EB-4C59-AEF2-6BCDDBE526D8}
Successfully deleted: [Empty Folder] C:\Users\Ali\appdata\local\{5CE34088-BF66-4D82-98B1-5BA5C81F2F1E}
Successfully deleted: [Empty Folder] C:\Users\Ali\appdata\local\{63959D95-5E1F-44B3-B9AE-84722F314DFA}
Successfully deleted: [Empty Folder] C:\Users\Ali\appdata\local\{66D6C13A-8773-4A8E-BC61-47975B298723}
Successfully deleted: [Empty Folder] C:\Users\Ali\appdata\local\{A8D1432B-C913-40F4-A203-D92236EB18A3}
Successfully deleted: [Empty Folder] C:\Users\Ali\appdata\local\{B1A39E47-3000-4230-93C3-9CFB6076E7B6}
Successfully deleted: [Empty Folder] C:\Users\Ali\appdata\local\{F578281F-C2C0-4857-8BE3-0829A097AE2E}
Successfully deleted: [Empty Folder] C:\Users\Ali\appdata\local\{FF286E22-4084-431F-99A0-C79951C819B6}



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 19.05.2013 at 12:51:00,21
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



AdwCleaner Log


AdwCleaner Logfile:
Code:

# AdwCleaner v2.301 - Datei am 19/05/2013 um 12:58:28 erstellt
# Aktualisiert am 16/05/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Ali - ALI-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Ali\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\Software\PIP

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16483

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Google Chrome v26.0.1410.64

Datei : C:\Users\Ali\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[S1].txt - [831 octets] - [19/05/2013 12:58:28]

########## EOF - C:\AdwCleaner[S1].txt - [890 octets] ##########

--- --- ---


[/CODE]


OTL Log


OTL Logfile:
Code:

OTL logfile created on: 19.05.2013 13:21:58 - Run 2
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Ali\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,48 Gb Total Physical Memory | 1,94 Gb Available Physical Memory | 55,65% Memory free
6,95 Gb Paging File | 4,72 Gb Available in Paging File | 67,91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 880,41 Gb Total Space | 813,41 Gb Free Space | 92,39% Space Free | Partition Type: NTFS
Drive D: | 50,00 Gb Total Space | 27,01 Gb Free Space | 54,03% Space Free | Partition Type: NTFS
Drive E: | 7,05 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
 
Computer Name: ALI-PC | User Name: Ali | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Ali\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_7_700_202_ActiveX.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Secure Banking\SecureBanking.exe (Secure Banking)
PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Secure Banking\sbservice.exe ()
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe (CyberLink)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe (CyberLink)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe (CyberLink)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\30e3a21202000677d0a9270572251477\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\7366a39c36523a084bc11c230929ff92\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\WOT\WOT.dll ()
MOD - C:\Program Files (x86)\Secure Banking\funcs.dll ()
MOD - C:\Program Files (x86)\Secure Banking\SecureBanking.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll ()
MOD - C:\Program Files (x86)\Secure Banking\sbservice.exe ()
MOD - C:\Program Files (x86)\Tobias Buchner\YouProxy\SpicIE.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Flexera Software, Inc.)
SRV:64bit: - (CoordinatorServiceHost) -- C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe (Dassault Systèmes SolidWorks Corp.)
SRV:64bit: - (Remote Solver for Flow Simulation 2012) -- C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe (Mentor Graphics Corporation)
SRV:64bit: - (AMD FUEL Service) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software, Inc.)
SRV - (SolidWorks Licensing Service) -- C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (watchmi) -- C:\Program Files (x86)\watchmi\TvdService.exe ()
SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (MemeoBackgroundService) -- C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe (Memeo)
SRV - (vpnagent) -- C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (CyberLink PowerDVD 10 MS Service) -- C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe (CyberLink)
SRV - (CyberLink PowerDVD 10 MS Monitor Service) -- C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe (CyberLink)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (esgiguard) -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys File not found
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (usbfilter) -- C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (amd_sata) -- C:\Windows\SysNative\drivers\amd_sata.sys (Advanced Micro Devices)
DRV:64bit: - (amd_xata) -- C:\Windows\SysNative\drivers\amd_xata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxhc) -- C:\Windows\SysNative\drivers\amdxhc.sys (Advanced Micro Devices, INC.)
DRV:64bit: - (amdhub30) -- C:\Windows\SysNative\drivers\amdhub30.sys (Advanced Micro Devices, INC.)
DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (vpnva) -- C:\Windows\SysNative\drivers\vpnva64.sys (Cisco Systems, Inc.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (RTL8192su) -- C:\Windows\SysNative\drivers\RTL8192su.sys (Realtek Semiconductor Corporation                          )
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (wsvd) -- C:\Windows\SysNative\drivers\wsvd.sys (CyberLink)
DRV:64bit: - (amdiox64) -- C:\Windows\SysNative\drivers\amdiox64.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (BrSerIb) -- C:\Windows\SysNative\drivers\BrSerIb.sys (Brother Industries Ltd.)
DRV:64bit: - (BrUsbSIb) -- C:\Windows\SysNative\drivers\BrUsbSIb.sys (Brother Industries Ltd.)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-732902274-989681646-235948354-1002\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-732902274-989681646-235948354-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/
IE - HKU\S-1-5-21-732902274-989681646-235948354-1002\..\SearchScopes,DefaultScope = {2EE7A148-AF2C-4C37-8D9A-FA99F8A50C86}
IE - HKU\S-1-5-21-732902274-989681646-235948354-1002\..\SearchScopes\{2EE7A148-AF2C-4C37-8D9A-FA99F8A50C86}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MDNE_enDE393DE497
IE - HKU\S-1-5-21-732902274-989681646-235948354-1002\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-732902274-989681646-235948354-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Ali\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 
 
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U10 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Ali\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll
CHR - plugin: Java Deployment Toolkit 7.0.100.18 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\Ali\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Ali\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Ali\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\Ali\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Mail = C:\Users\Ali\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2013.05.14 21:16:35 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll File not found
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKU\S-1-5-21-732902274-989681646-235948354-1002\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-732902274-989681646-235948354-1002\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKU\S-1-5-21-732902274-989681646-235948354-1002\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O4:64bit: - HKLM..\Run: [MedionReminder] C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe (CyberLink)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-732902274-989681646-235948354-1002..\Run: [Facebook Update] C:\Users\Ali\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-732902274-989681646-235948354-1002..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O4 - HKU\S-1-5-21-732902274-989681646-235948354-1002..\Run: [SecureBanking] C:\Program Files (x86)\Secure Banking\SecureBanking.exe (Secure Banking)
O4:64bit: - HKLM..\RunOnce: [MedionReminder] C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe (CyberLink)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-732902274-989681646-235948354-1002\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-732902274-989681646-235948354-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:64bit: - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O9:64bit: - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{72B8E66E-4DBE-4DD5-A9B2-435B47A7B3E9}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8AAD6D8A-0CD9-4833-8080-E9547C00E9E4}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013.05.10 01:30:45 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010.05.25 06:16:57 | 000,000,046 | -H-- | M] () - E:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.05.19 13:02:18 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Ali\Desktop\OTL.exe
[2013.05.19 12:47:26 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013.05.19 12:46:19 | 000,000,000 | ---D | C] -- C:\JRT
[2013.05.19 12:46:17 | 000,545,954 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\Ali\Desktop\JRT.exe
[2013.05.17 18:06:14 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Ali\Desktop\tdsskiller.exe
[2013.05.17 17:49:20 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\Ali\Desktop\aswMBR.exe
[2013.05.16 21:49:00 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2013.05.16 21:23:03 | 000,000,000 | ---D | C] -- C:\Users\Ali\Desktop\mbar
[2013.05.15 21:03:11 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013.05.15 21:03:10 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013.05.15 21:03:09 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.05.15 21:03:08 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013.05.15 21:03:08 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013.05.15 21:03:08 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013.05.15 21:03:08 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013.05.15 21:03:08 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013.05.15 21:03:08 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013.05.15 21:03:08 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013.05.15 21:03:08 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013.05.15 21:03:08 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013.05.15 21:03:07 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013.05.15 21:03:07 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.05.15 21:03:07 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013.05.15 19:05:59 | 000,265,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2013.05.15 19:05:59 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2013.05.15 19:05:51 | 001,930,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll
[2013.05.15 19:05:51 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2013.05.15 19:05:51 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll
[2013.05.15 19:05:51 | 000,111,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\consent.exe
[2013.05.15 19:05:43 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanprotdim.dll
[2013.05.15 18:52:20 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.05.11 00:11:36 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.05.11 00:11:36 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.05.11 00:11:36 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.05.11 00:10:31 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.05.10 13:06:27 | 000,000,000 | ---D | C] -- C:\Users\Ali\Desktop\Neuer Ordner (2)
[2013.05.10 12:49:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.05.10 12:49:08 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.05.10 12:49:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.05.10 01:30:31 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2013.05.10 01:29:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2013.05.09 20:52:53 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\Ykma
[2013.05.09 20:52:53 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\Idmol
[2013.05.09 14:38:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
[2013.05.08 19:15:34 | 000,000,000 | ---D | C] -- C:\Users\Ali\Desktop\Zeichnungen
[2013.05.08 19:07:27 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\TempSWBackupDirectory
[2013.05.08 19:06:17 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\SolidWorks
[2013.05.08 19:04:59 | 000,000,000 | ---D | C] -- C:\ProgramData\SolidWorks Flow Simulation
[2013.05.08 19:04:29 | 000,000,000 | ---D | C] -- C:\Users\Ali\Documents\SolidWorks Visual Studio Tools for Applications
[2013.05.08 19:01:20 | 000,000,000 | ---D | C] -- C:\Program Files\SolidWorks Corp
[2013.05.08 19:01:20 | 000,000,000 | ---D | C] -- C:\ProgramData\SolidWorks
[2013.05.08 19:01:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2013.05.08 19:01:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Macrovision Shared
[2013.05.08 19:00:42 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2013.05.08 19:00:31 | 000,000,000 | ---D | C] -- C:\Users\Ali\Documents\Visual Studio 2005
[2013.05.08 19:00:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005
[2013.05.08 19:00:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2013.05.08 18:59:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache
[2013.05.08 18:59:32 | 000,000,000 | ---D | C] -- C:\SolidWorks Data
[2013.05.08 18:48:42 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\help_images_otherUI
[2013.05.08 10:11:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2013.05.07 21:46:58 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\DassaultSystemes
[2013.05.07 21:46:58 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\DassaultSystemes
[2013.05.07 21:46:58 | 000,000,000 | ---D | C] -- C:\ProgramData\DassaultSystemes
[2013.05.07 21:46:29 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\EDrawings
[2013.05.07 21:44:31 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2013.05.07 21:43:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared
[2013.05.07 21:42:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SolidWorks Shared
[2013.05.07 21:42:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SolidWorks Shared
[2013.05.07 21:42:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SolidWorks Corp
[2013.05.07 21:42:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2012
[2013.05.07 21:29:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks Installations-Manager
[2013.05.07 21:29:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SolidWorks Installations-Manager
[2013.05.07 21:27:16 | 000,000,000 | ---D | C] -- C:\Users\Ali\Documents\SolidWorks Downloads
[2013.05.07 21:27:16 | 000,000,000 | ---D | C] -- C:\Windows\SolidWorks
[2013.05.07 21:27:15 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\SolidWorks
[2013.05.07 15:48:38 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\Apple Computer
[2013.05.07 15:48:38 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\Apple Computer
[2013.05.07 15:48:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013.05.07 15:48:19 | 000,033,240 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2013.05.07 15:48:11 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013.05.07 15:48:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2013.05.07 15:48:11 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013.05.07 15:48:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2013.05.07 15:48:11 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013.05.07 15:47:21 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\Apple
[2013.05.07 15:47:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2013.05.07 15:47:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2013.05.07 15:47:03 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2013.05.07 15:47:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2013.05.07 15:47:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2013.05.07 15:47:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2013.05.07 14:54:57 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Roaming\redsn0w
[2013.05.07 13:36:07 | 000,000,000 | ---D | C] -- C:\Users\Ali\Desktop\ipod jailbreak
[2013.05.06 17:57:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secure Banking
[2013.05.06 17:57:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Secure Banking
[2013.05.06 11:11:38 | 000,083,160 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avnetflt.sys
[2013.05.05 12:30:45 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\PDF24
[2013.05.05 12:27:37 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\Cisco
[2013.05.05 12:26:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco
[2013.05.05 12:26:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Cisco
[2013.05.05 12:26:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cisco
[2013.05.03 17:25:58 | 000,000,000 | ---D | C] -- C:\Users\Ali\Desktop\Alis Daten
[2013.05.03 16:53:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
[2013.05.03 16:53:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PDF24
[2013.05.03 16:52:48 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\Programs
[2013.05.02 14:41:40 | 000,000,000 | ---D | C] -- C:\Users\Ali\Desktop\Thrpiztrum
[2013.05.02 13:23:17 | 000,000,000 | R--D | C] -- C:\Users\Ali\Documents\Scanned Documents
[2013.05.02 13:23:17 | 000,000,000 | ---D | C] -- C:\Users\Ali\Documents\Fax
[2013.04.29 08:00:10 | 000,000,000 | ---D | C] -- C:\Users\Ali\.tfo4
[2013.04.22 10:11:21 | 000,000,000 | ---D | C] -- C:\Users\Ali\AppData\Local\Apps
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.05.19 13:11:03 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.05.19 13:07:06 | 000,016,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.05.19 13:07:06 | 000,016,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.05.19 13:07:00 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-732902274-989681646-235948354-1002UA.job
[2013.05.19 13:06:06 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.05.19 13:05:46 | 001,500,358 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.05.19 13:05:46 | 000,654,602 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.05.19 13:05:46 | 000,616,484 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.05.19 13:05:46 | 000,130,216 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.05.19 13:05:46 | 000,106,606 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.05.19 13:02:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ali\Desktop\OTL.exe
[2013.05.19 13:00:06 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.05.19 12:59:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.05.19 12:59:43 | 2800,545,792 | -HS- | M] () -- C:\hiberfil.sys
[2013.05.19 12:57:54 | 000,632,031 | ---- | M] () -- C:\Users\Ali\Desktop\adwcleaner.exe
[2013.05.19 12:46:19 | 000,545,954 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\Ali\Desktop\JRT.exe
[2013.05.17 18:06:18 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Ali\Desktop\tdsskiller.exe
[2013.05.17 18:05:00 | 000,000,512 | ---- | M] () -- C:\Users\Ali\Desktop\MBR.dat
[2013.05.17 17:50:46 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Users\Ali\Desktop\aswMBR.exe
[2013.05.17 17:49:25 | 000,014,840 | ---- | M] () -- C:\Users\Ali\Desktop\get-mirror-server.htm
[2013.05.16 22:07:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-732902274-989681646-235948354-1002Core.job
[2013.05.16 22:06:54 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.05.16 22:06:54 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.05.16 21:48:58 | 459,138,601 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2013.05.16 21:22:25 | 012,917,756 | ---- | M] () -- C:\Users\Ali\Desktop\mbar-1.05.0.1001.zip
[2013.05.16 21:22:17 | 000,015,041 | ---- | M] () -- C:\Users\Ali\Desktop\download-malwarebytes_anti_rootkit.htm
[2013.05.16 09:31:48 | 000,309,488 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.05.14 21:16:35 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013.05.14 21:10:26 | 000,001,130 | ---- | M] () -- C:\Users\Ali\Desktop\ComboFix - Verknüpfung.lnk
[2013.05.14 20:52:13 | 000,014,152 | ---- | M] () -- C:\Users\Ali\Desktop\combofix.lnk
[2013.05.12 13:28:14 | 000,000,000 | ---- | M] () -- C:\Users\Ali\AppData\Local\Temptable.xml
[2013.05.10 12:49:09 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.05.10 01:30:45 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
[2013.05.08 19:03:01 | 000,002,785 | ---- | M] () -- C:\Users\Public\Desktop\SolidWorks 2012 x64 Edition.lnk
[2013.05.08 18:50:01 | 000,002,119 | ---- | M] () -- C:\Users\Public\Desktop\SolidWorks eDrawings 2012.lnk
[2013.05.08 18:48:46 | 000,000,000 | ---- | M] () -- C:\Windows\eDrawingOfficeAutomator.INI
[2013.05.08 18:48:42 | 000,002,089 | ---- | M] () -- C:\Users\Public\Desktop\SolidWorks eDrawings 2012 x64 Edition.lnk
[2013.05.07 15:48:35 | 000,001,787 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013.05.07 12:45:54 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2013.05.06 11:11:28 | 000,083,160 | ---- | M] (Avira GmbH) -- C:\Windows\SysNative\drivers\avnetflt.sys
[2013.05.03 17:21:59 | 000,182,529 | ---- | M] () -- C:\Users\Ali\Desktop\002.jpg
[2013.05.03 16:44:28 | 000,005,829 | ---- | M] () -- C:\Users\Ali\Documents\LANXESSAli Isle1.odt
[2013.05.03 16:27:50 | 000,005,675 | ---- | M] () -- C:\Users\Ali\Documents\CURRENTAAli Islek.odt
[2013.05.03 16:13:53 | 000,005,896 | ---- | M] () -- C:\Users\Ali\Documents\LANXESSAli Islek.odt
[2013.05.03 14:08:24 | 000,043,626 | -HS- | M] () -- C:\Users\Ali\Desktop\Folder.jpg
[2013.05.03 14:08:24 | 000,043,626 | -HS- | M] () -- C:\Users\Ali\Desktop\AlbumArt_{BFC6AF81-D8F9-4040-835B-5D022FB48B1F}_Large.jpg
[2013.05.03 14:08:24 | 000,008,788 | -HS- | M] () -- C:\Users\Ali\Desktop\AlbumArtSmall.jpg
[2013.05.03 14:08:24 | 000,008,788 | -HS- | M] () -- C:\Users\Ali\Desktop\AlbumArt_{BFC6AF81-D8F9-4040-835B-5D022FB48B1F}_Small.jpg
[2013.05.02 14:43:20 | 000,000,432 | ---- | M] () -- C:\Windows\BRWMARK.INI
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.05.19 12:57:54 | 000,632,031 | ---- | C] () -- C:\Users\Ali\Desktop\adwcleaner.exe
[2013.05.17 18:05:00 | 000,000,512 | ---- | C] () -- C:\Users\Ali\Desktop\MBR.dat
[2013.05.17 17:48:38 | 000,014,840 | ---- | C] () -- C:\Users\Ali\Desktop\get-mirror-server.htm
[2013.05.16 21:48:58 | 459,138,601 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2013.05.16 21:22:09 | 012,917,756 | ---- | C] () -- C:\Users\Ali\Desktop\mbar-1.05.0.1001.zip
[2013.05.16 21:20:28 | 000,015,041 | ---- | C] () -- C:\Users\Ali\Desktop\download-malwarebytes_anti_rootkit.htm
[2013.05.14 21:10:26 | 000,001,130 | ---- | C] () -- C:\Users\Ali\Desktop\ComboFix - Verknüpfung.lnk
[2013.05.11 00:11:36 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.05.11 00:11:36 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.05.11 00:11:36 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.05.11 00:11:36 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.05.11 00:11:36 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.05.10 12:49:09 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.05.10 01:30:45 | 000,000,000 | ---- | C] () -- C:\autoexec.bat
[2013.05.08 19:15:51 | 000,000,000 | ---- | C] () -- C:\Users\Ali\AppData\Local\Temptable.xml
[2013.05.08 19:03:01 | 000,002,785 | ---- | C] () -- C:\Users\Public\Desktop\SolidWorks 2012 x64 Edition.lnk
[2013.05.08 18:48:46 | 000,000,000 | ---- | C] () -- C:\Windows\eDrawingOfficeAutomator.INI
[2013.05.08 18:48:42 | 000,002,089 | ---- | C] () -- C:\Users\Public\Desktop\SolidWorks eDrawings 2012 x64 Edition.lnk
[2013.05.07 21:42:55 | 000,002,119 | ---- | C] () -- C:\Users\Public\Desktop\SolidWorks eDrawings 2012.lnk
[2013.05.07 15:48:35 | 000,001,787 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013.05.07 15:47:20 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013.05.07 12:45:54 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2013.05.03 17:21:59 | 000,182,529 | ---- | C] () -- C:\Users\Ali\Desktop\002.jpg
[2013.05.03 16:33:46 | 000,005,829 | ---- | C] () -- C:\Users\Ali\Documents\LANXESSAli Isle1.odt
[2013.05.03 16:27:48 | 000,005,675 | ---- | C] () -- C:\Users\Ali\Documents\CURRENTAAli Islek.odt
[2013.05.03 16:13:51 | 000,005,896 | ---- | C] () -- C:\Users\Ali\Documents\LANXESSAli Islek.odt
[2013.05.03 14:08:17 | 000,043,626 | -HS- | C] () -- C:\Users\Ali\Desktop\Folder.jpg
[2013.05.03 14:08:17 | 000,043,626 | -HS- | C] () -- C:\Users\Ali\Desktop\AlbumArt_{BFC6AF81-D8F9-4040-835B-5D022FB48B1F}_Large.jpg
[2013.05.03 14:08:17 | 000,008,788 | -HS- | C] () -- C:\Users\Ali\Desktop\AlbumArtSmall.jpg
[2013.05.03 14:08:17 | 000,008,788 | -HS- | C] () -- C:\Users\Ali\Desktop\AlbumArt_{BFC6AF81-D8F9-4040-835B-5D022FB48B1F}_Small.jpg
[2013.04.12 20:20:45 | 000,000,367 | ---- | C] () -- C:\Users\Ali\Heimnetzgruppe - Verknüpfung.lnk
[2013.02.24 21:56:56 | 000,121,359 | ---- | C] () -- C:\Users\Ali\541019_10151490385920622_923617879_n.jpg
[2013.02.10 21:53:52 | 000,022,147 | ---- | C] () -- C:\Users\Ali\burpees-exercise.jpg
[2013.02.06 00:28:11 | 000,006,875 | ---- | C] () -- C:\Users\Ali\lebenslauif2.odt
[2013.02.05 23:48:40 | 000,008,234 | ---- | C] () -- C:\Users\Ali\phsio2.odt
[2012.12.23 01:03:04 | 000,000,000 | ---- | C] () -- C:\Users\Ali\defogger_reenable
[2012.12.09 22:02:52 | 001,841,122 | ---- | C] () -- C:\Users\Ali\MOV00165.3gp
[2012.09.03 11:03:44 | 000,000,432 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012.09.03 11:03:44 | 000,000,034 | ---- | C] () -- C:\Windows\SysWow64\BD7320.DAT
[2012.08.15 18:45:23 | 000,017,408 | ---- | C] () -- C:\Users\Ali\AppData\Local\WebpageIcons.db
[2012.08.14 12:57:37 | 000,000,017 | ---- | C] () -- C:\Windows\SysWow64\shortcut_ex.dat
[2012.08.14 12:49:49 | 011,027,660 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.04.25 21:49:04 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.04.25 20:29:27 | 000,204,960 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.04.25 20:29:27 | 000,157,152 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.04.25 20:29:26 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2012.03.29 09:22:32 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2012.03.03 01:33:26 | 000,023,040 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2012.09.23 14:20:37 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\Ashampoo
[2013.05.07 21:46:58 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\DassaultSystemes
[2012.10.03 16:44:36 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\e-academy Inc
[2013.05.07 21:46:29 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\EDrawings
[2012.12.22 15:25:30 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\Foyda
[2013.05.09 20:52:53 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\Idmol
[2013.05.07 14:54:57 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\redsn0w
[2013.05.12 18:26:00 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\SoftGrid Client
[2012.12.22 15:26:51 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\Teza
[2013.03.18 15:15:22 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\Tobias Buchner
[2012.08.14 12:50:55 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\TP
[2012.12.08 23:50:32 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\Windows Live Writer
[2013.05.10 21:04:03 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\Ykma
 
========== Purity Check ==========
 
 

< End of report >

--- --- ---


[/CODE]

cosinus 19.05.2013 20:32

Fixen mit OTL

  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die Textbox.
Code:

:OTL
[2012.12.22 15:25:30 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\Foyda
[2013.05.09 20:52:53 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\Idmol
[2013.05.10 21:04:03 | 000,000,000 | ---D | M] -- C:\Users\Ali\AppData\Roaming\Ykma
:Files
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]

  • Solltest du deinen Benutzernamen z. B. durch "*****" unkenntlich gemacht haben, so füge an entsprechender Stelle deinen richtigen Benutzernamen ein. Andernfalls wird der Fix nicht funktionieren.
  • Schließe bitte nun alle Programme.
  • Klicke nun bitte auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
  • Nach dem Neustart findest Du ein Textdokument auf deinem Desktop.
    ( Auch zu finden unter C:\_OTL\MovedFiles\<Uhrzeit_Datum>.txt)
    Kopiere nun den Inhalt hier in Deinen Thread

rico89 20.05.2013 10:23

Code:

All processes killed
========== OTL ==========
C:\Users\Ali\AppData\Roaming\Foyda folder moved successfully.
C:\Users\Ali\AppData\Roaming\Idmol folder moved successfully.
C:\Users\Ali\AppData\Roaming\Ykma folder moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Ali\Desktop\cmd.bat deleted successfully.
C:\Users\Ali\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Ali
->Temp folder emptied: 85732681 bytes
->Temporary Internet Files folder emptied: 296575149 bytes
->Java cache emptied: 14660819 bytes
->Google Chrome cache emptied: 241430816 bytes
->Flash cache emptied: 59342 bytes
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 56466 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1715914 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 50577003 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67832 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 749 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 659,00 mb
 
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
Error: Unble to create default HOSTS file!
 
OTL by OldTimer - Version 3.2.69.0 log created on 05202013_111454

Files\Folders moved on Reboot...
C:\Users\Ali\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Ali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JX23LAB1\134730-malware-citadel-3[1].htm moved successfully.
C:\Users\Ali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A59EDVPT\search[1].htm moved successfully.
C:\Users\Ali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
C:\Users\Ali\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
File move failed. C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt scheduled to be moved on reboot.
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


cosinus 20.05.2013 22:17

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Vollscan mit Malwarebytes Anti-Malware (MBAM) (falls du vor kurzem erst einen Vollscan gemacht hast, reicht auch ein Quickscan (spart Zeit), das dann mir bitte auch mitteilen)

Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren!

Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


rico89 21.05.2013 13:55

Anti-Malware Log:

Code:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.05.21.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Ali :: ALI-PC [Administrator]

21.05.2013 12:34:10
mbam-log-2013-05-21 (12-34-10).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|H:\|Q:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 365468
Laufzeit: 37 Minute(n), 44 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Qoobox\Quarantine\C\Users\Ali\AppData\Roaming\Ywiha\neick.exe.vir (Trojan.Zbot.RVgen) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)



ESET Log


Code:

ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=f005a4cf0b5de9498c5a004e2c0848a3
# engine=13879
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-05-21 12:46:44
# local_time=2013-05-21 02:46:44 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1799 16775165 100 96 7907 234563694 691 0
# compatibility_mode=5893 16776574 100 94 20738590 120770254 0 0
# scanned=158802
# found=0
# cleaned=0
# scan_time=4050


cosinus 21.05.2013 14:00

Nur ein Fund in der Q von CF, das ist harmlos

Sieht soweit ok aus :daumenhoc

Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

rico89 21.05.2013 15:45

Super, gut ich glaube das wars dann. Hoffe das ich nicht so schnell wieder hier antanzen muss :D


Vielen dank von meiner Seite, hast sehr sehr geholfen!

cosinus 21.05.2013 19:48

Dann wären wir durch! :daumenhoc


Falls du noch Lob oder Kritik loswerden möchtest => http://www.trojaner-board.de/lob-kritik-wuensche/



Die Programme, die hier zum Einsatz kamen, können alle wieder runter.

Combofix entfernen (nur relevant wenn es hier benutzt wurde!) : Start/Ausführen (Tastenkombination WIN+R), dort den Befehl combofix /uninstall eintippen und ausführen

Mit Hilfe von OTL kannst du auch viele andere Tools entfernen: Starte dazu einfach OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.

Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate
Windows XP:Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.
Windows Vista/7: Start, Systemsteuerung, Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks findest du hier => Browsers and Plugins - FilePony.de

Alle Plugins im Firefox-Browser kannst du auch ganz einfach hier auf Aktualität prüfen => https://www.mozilla.org/de/plugincheck

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein großes Sicherheitsrisiko, daher solltest Du die alten Versionen deinstallieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software (bzw. Programme und Funktionen) und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 17:47 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130