Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   windows vista fährt hoch,komm aber nicht auf den startbildschirm (https://www.trojaner-board.de/136467-windows-vista-faehrt-hoch-komm-startbildschirm.html)

lolale 12.06.2013 13:59

windows vista fährt hoch,komm aber nicht auf den startbildschirm
 
Hallo,

ich habe gerade mein laptop angemacht und dann kam sofort die frage, ob ich Windows normal oder im abgesicherten Modus starten möchte. ich habe erst normal gestartet, dann war der Bildschirm schwarz, zeiger weiß. danach habe ich ihn*im abgesicherten Modus gestartet, dass gleiche. dann mit Eingabe Aufforderung. ich habe rstrui.exe eingegeben, hat sich aber auch nichts getan, außer dass wieder kam im welchem Modus ich hochfahren will. dann kann ein blauer Bildschirm und da stand sowas drauf,dass Windows herunterfährt bevor etwa beschädigt wird. könnt ihr mir ebitte helfen?

lg lolale

markusg 12.06.2013 14:01

Hi,
kommst du an nen pc mit brenner?
download:
http://filepony.de/download-otlpe/
und brenne es mit ISOBurner auf eine CD.
ISO Burner - Download - Filepony
isoburner anleitung:
http://www.trojaner-board.de/83208-b...ei-cd-dvd.html
• Wenn der Download fertig ist mache ein doppel Klick auf die OTLPENet.exe, was ISOBurner öffnet um es auf die CD zu brennen.
Starte dein System neu und boote von der CD die du gerade erstellt hast.
Wenn du nicht weist wie du deinen Computer dazu bringst von der CD zu booten,
http://www.trojaner-board.de/81857-c...cd-booten.html

• Dein System sollte jetzt einen REATOGO-X-PE Desktop anzeigen.
• Mache einen doppel Klick auf das OTLPE Icon.
• Wenn du gefragt wirst "Do you wish to load the remote registry", dann wähle Yes.
• Wenn du gefragt wirst "Do you wish to load remote user profile(s) for scanning", dann wähle Yes.
• entferne den haken bei "Automatically Load All Remaining Users" wenn er gesetzt ist.

• OTL sollte nun starten.
Kopiere nun den Inhalt in die http://larusso.trojaner-board.de/Images/otlfix.jpg
Textbox.
Code:

activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
explorer.exe
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe

• Drücke Run Scan um den Scan zu starten.
• Wenn er fertig ist werden die Dateien in C:\otl.txt gesichert
• Kopiere diesen Ordner auf deinen USB-Stick wenn du keine Internetverbindung auf diesem System hast.
poste beide logs

lolale 12.06.2013 14:06

hi,

ich habe schon einmal sp eine otpl cd gebrannt. kann ich die wieder verwenden?

markusg 12.06.2013 14:08

joa, rein damit :-)

lolale 12.06.2013 14:20

was meinst du mit “kopiere nun derb Inhalt in suite benutzerdefinierte textbox?

wenn ich auf das otple doppelklicke kommt ein Fenster das heißt “browse for folder“ und wenn ich auf was klick(ramdisk,system,data,reatogope oder shared documents) kommt “target is not windows2000or later

markusg 12.06.2013 14:32

klappe da alles auf, wähle windows bzw wind, klicke drauf und dann zeigt otl ne eingabebox, da das oben aus der code box einfügen

lolale 12.06.2013 14:41

hi,

ich habe schon einmal sp eine otpl cd gebrannt. kann ich die wieder verwenden?

markusg 12.06.2013 14:48

du hast auch schon mal diese Frage gestellt.

lolale 12.06.2013 14:58

oh das war keine Absicht. aber was ist mit dem brows efor folder und dass da immer kommt target is not windows2000 or later? soll ich besser die cd nochmal brennen?

markusg 12.06.2013 15:15

ne auch dazu habe ich schon ne antwort gepostet. in post6

lolale 13.06.2013 05:31

ok hat ein bisschen gedauert bis ich es gecheckt habe,sorry... aber jetzt hab ich es gemacht & hier sind die logs

kommando zurück...der scan hängt sich auf bei "manual file scan-getting folder structure.." und dann kommt irgendwann "otlpe out of memory"

markusg 13.06.2013 12:08

versuchs mal ohne mein script

lolale 13.06.2013 13:34

ok das ging...hier das, was danach geöffnet wurde

markusg 13.06.2013 13:40

hmm jetzt zeigt er leider nich all zu viel an, testen wirs mal
auf deinem zweiten pc gehe auf start, programme zubehör editor, kopiere dort
rein:
Code:

:OTL
:Files
:Commands
[EMPTYFLASH]
[emptytemp]



dieses speicherst du auf nem usb stick als fix.txt
nutze nun wieder OTLPENet.exe (starte also von der erstellten cd) und hake alles an, wie es bereits im post zu OTLPENet.exe beschrieben ist.
• Klicke nun bitte auf den Fix Button.
es sollte nun eine meldung ähnlich dieser: "load fix from file" erscheinen, lade also die fix.txt von deinem stick.
wenn dies nicht funktioniert, bitte den fix manuell eintragen.
dann klicke erneut den fix buton. pc startet evtl. neu. wenn ja, nimm die cd aus dem laufwerk, windows sollte nun normal starten und die otl.txt öffnen,
log posten bitte.

lolale 13.06.2013 14:01

wenn ich es öffnen will, kommt eine fehlermeldung, wenn ich es manuell eingebe kommen immer die sachen die klein auf den tasten sehen(beim i ne 5 , und ich kann auch kein doppelpunkt machen)

ok hab es irgendwie hinbekommen

hier die datei

lolale 13.06.2013 14:15

bitte

markusg 13.06.2013 18:59

log zeigt nichts an. startet er wieder, bzw geht die systemstart reperatur über f8?

lolale 14.06.2013 12:53

hi, ja er startet wieder ganz normal und geht.
Jetzt hat mir mein microsoft security 2 trojaner angezeigt und gesagt es wird bereinigt.
Soll ich trotzdem noch irgendwas machen?

markusg 14.06.2013 13:03

ja, die microsoft funde posten dann:
Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

lolale 14.06.2013 13:18

ich kann die microsoft funde nicht mehr posten, die sind schon "bekämpft" oder kann steht das noch irgendwo wenn was war?

markusg 14.06.2013 13:20

wieso hast du was gelöscht, stand da was von.
wo das log ist, steht in der Anleitung

lolale 14.06.2013 13:23

log TDSSKiller ist zu groß und kann nicht angehängt werden??

ja bei microsoft security kam ne meldung unten rechts an meinem desktop da stand das alles bekämpft wird und ich hab es dann auf gemacht und auf entfernen geklickt.... ?!?!

14:18:38.0707 3296 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
14:18:38.0873 3296 ============================================================
14:18:38.0874 3296 Current date / time: 2013/06/14 14:18:38.0873
14:18:38.0874 3296 SystemInfo:
14:18:38.0874 3296
14:18:38.0874 3296 OS Version: 6.0.6002 ServicePack: 2.0
14:18:38.0874 3296 Product type: Workstation
14:18:38.0874 3296 ComputerName: LOLA-PC
14:18:38.0875 3296 UserName: Lola
14:18:38.0875 3296 Windows directory: C:\Windows
14:18:38.0875 3296 System windows directory: C:\Windows
14:18:38.0875 3296 Processor architecture: Intel x86
14:18:38.0875 3296 Number of processors: 2
14:18:38.0875 3296 Page size: 0x1000
14:18:38.0875 3296 Boot type: Normal boot
14:18:38.0875 3296 ============================================================
14:18:43.0222 3296 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
14:18:43.0226 3296 ============================================================
14:18:43.0226 3296 \Device\Harddisk0\DR0:
14:18:43.0227 3296 MBR partitions:
14:18:43.0227 3296 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1194800, BlocksNum 0xBC51800
14:18:43.0227 3296 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xCDE6000, BlocksNum 0x103DF170
14:18:43.0227 3296 ============================================================
14:18:43.0231 3296 C: <-> \Device\Harddisk0\DR0\Partition1
14:18:43.0337 3296 D: <-> \Device\Harddisk0\DR0\Partition2
14:18:43.0338 3296 ============================================================
14:18:43.0338 3296 Initialize success
14:18:43.0338 3296 ============================================================
14:18:50.0012 4548 ============================================================
14:18:50.0012 4548 Scan started
14:18:50.0012 4548 Mode: Manual;
14:18:50.0012 4548 ============================================================
14:18:50.0962 4548 ================ Scan system memory ========================
14:18:50.0962 4548 System memory - ok
14:18:50.0972 4548 ================ Scan services =============================
14:18:51.0252 4548 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
14:18:51.0262 4548 ACPI - ok
14:18:51.0322 4548 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
14:18:51.0342 4548 adp94xx - ok
14:18:51.0382 4548 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
14:18:51.0392 4548 adpahci - ok
14:18:51.0412 4548 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
14:18:51.0422 4548 adpu160m - ok
14:18:51.0452 4548 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
14:18:51.0462 4548 adpu320 - ok
14:18:51.0512 4548 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
14:18:51.0522 4548 AeLookupSvc - ok
14:18:51.0572 4548 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
14:18:51.0582 4548 AFD - ok
14:18:51.0612 4548 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
14:18:51.0622 4548 agp440 - ok
14:18:51.0662 4548 [ 0DEE2B628D4C6E23285BB91EFFDABFDE ] ahcix86s C:\Windows\system32\drivers\ahcix86s.sys
14:18:51.0672 4548 ahcix86s - ok
14:18:51.0742 4548 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
14:18:51.0742 4548 aic78xx - ok
14:18:51.0762 4548 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
14:18:51.0772 4548 ALG - ok
14:18:51.0792 4548 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
14:18:51.0792 4548 aliide - ok
14:18:51.0822 4548 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
14:18:51.0822 4548 amdagp - ok
14:18:51.0842 4548 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
14:18:51.0852 4548 amdide - ok
14:18:51.0882 4548 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
14:18:51.0882 4548 AmdK7 - ok
14:18:51.0912 4548 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
14:18:51.0912 4548 AmdK8 - ok
14:18:51.0942 4548 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
14:18:51.0942 4548 Appinfo - ok
14:18:51.0972 4548 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
14:18:51.0982 4548 arc - ok
14:18:52.0022 4548 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
14:18:52.0022 4548 arcsas - ok
14:18:52.0162 4548 [ 2FE0D5DB69014980A970D3BF9A85D2B1 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
14:18:52.0162 4548 aspnet_state - ok
14:18:52.0202 4548 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
14:18:52.0202 4548 AsyncMac - ok
14:18:52.0232 4548 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys
14:18:52.0232 4548 atapi - ok
14:18:52.0302 4548 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
14:18:52.0312 4548 AudioEndpointBuilder - ok
14:18:52.0332 4548 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
14:18:52.0342 4548 Audiosrv - ok
14:18:52.0372 4548 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
14:18:52.0372 4548 Beep - ok
14:18:52.0452 4548 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
14:18:52.0462 4548 BFE - ok
14:18:52.0552 4548 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\System32\qmgr.dll
14:18:52.0582 4548 BITS - ok
14:18:52.0642 4548 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
14:18:52.0642 4548 blbdrive - ok
14:18:52.0672 4548 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
14:18:52.0672 4548 bowser - ok
14:18:52.0712 4548 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
14:18:52.0712 4548 BrFiltLo - ok
14:18:52.0742 4548 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
14:18:52.0742 4548 BrFiltUp - ok
14:18:52.0792 4548 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
14:18:52.0792 4548 Browser - ok
14:18:52.0822 4548 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
14:18:52.0832 4548 Brserid - ok
14:18:52.0852 4548 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
14:18:52.0852 4548 BrSerWdm - ok
14:18:52.0882 4548 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
14:18:52.0882 4548 BrUsbMdm - ok
14:18:52.0902 4548 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
14:18:52.0902 4548 BrUsbSer - ok
14:18:52.0922 4548 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
14:18:52.0932 4548 BTHMODEM - ok
14:18:52.0972 4548 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
14:18:52.0972 4548 cdfs - ok
14:18:53.0022 4548 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
14:18:53.0022 4548 cdrom - ok
14:18:53.0052 4548 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
14:18:53.0062 4548 CertPropSvc - ok
14:18:53.0082 4548 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
14:18:53.0082 4548 circlass - ok
14:18:53.0122 4548 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
14:18:53.0132 4548 CLFS - ok
14:18:53.0202 4548 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:18:53.0212 4548 clr_optimization_v2.0.50727_32 - ok
14:18:53.0252 4548 [ 6D7C8A951AF6AD6835C029B3CB88D333 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
14:18:53.0252 4548 clr_optimization_v4.0.30319_32 - ok
14:18:53.0312 4548 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
14:18:53.0322 4548 CmBatt - ok
14:18:53.0332 4548 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
14:18:53.0342 4548 cmdide - ok
14:18:53.0352 4548 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
14:18:53.0352 4548 Compbatt - ok
14:18:53.0362 4548 COMSysApp - ok
14:18:53.0372 4548 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
14:18:53.0382 4548 crcdisk - ok
14:18:53.0402 4548 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
14:18:53.0402 4548 Crusoe - ok
14:18:53.0452 4548 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll
14:18:53.0462 4548 CryptSvc - ok
14:18:53.0532 4548 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
14:18:53.0562 4548 DcomLaunch - ok
14:18:53.0592 4548 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
14:18:53.0592 4548 DfsC - ok
14:18:53.0712 4548 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
14:18:53.0812 4548 DFSR - ok
14:18:53.0862 4548 [ 649705E3DAE598BC0F957BACBF9A2BD5 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
14:18:53.0872 4548 dg_ssudbus - ok
14:18:53.0942 4548 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
14:18:53.0952 4548 Dhcp - ok
14:18:53.0982 4548 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
14:18:53.0982 4548 disk - ok
14:18:54.0052 4548 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
14:18:54.0052 4548 Dnscache - ok
14:18:54.0082 4548 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
14:18:54.0082 4548 dot3svc - ok
14:18:54.0132 4548 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
14:18:54.0152 4548 DPS - ok
14:18:54.0202 4548 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
14:18:54.0212 4548 drmkaud - ok
14:18:54.0272 4548 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
14:18:54.0302 4548 DXGKrnl - ok
14:18:54.0362 4548 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
14:18:54.0362 4548 E1G60 - ok
14:18:54.0402 4548 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
14:18:54.0412 4548 EapHost - ok
14:18:54.0502 4548 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
14:18:54.0512 4548 Ecache - ok
14:18:54.0582 4548 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
14:18:54.0592 4548 ehRecvr - ok
14:18:54.0622 4548 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
14:18:54.0622 4548 ehSched - ok
14:18:54.0632 4548 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
14:18:54.0632 4548 ehstart - ok
14:18:54.0722 4548 [ 2A2F1FA78751C9932098529EE1EDEB1A ] eLoggerSvc6 C:\Program Files\Norman\Npm\Bin\Elogsvc.exe
14:18:55.0392 4548 eLoggerSvc6 - ok
14:18:55.0442 4548 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
14:18:55.0462 4548 elxstor - ok
14:18:55.0542 4548 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
14:18:55.0572 4548 EMDMgmt - ok
14:18:55.0602 4548 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
14:18:55.0602 4548 ErrDev - ok
14:18:55.0682 4548 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
14:18:55.0692 4548 EventSystem - ok
14:18:55.0762 4548 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
14:18:55.0762 4548 exfat - ok
14:18:55.0812 4548 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
14:18:55.0812 4548 fastfat - ok
14:18:55.0852 4548 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
14:18:55.0852 4548 fdc - ok
14:18:55.0892 4548 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
14:18:55.0892 4548 fdPHost - ok
14:18:55.0902 4548 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
14:18:55.0912 4548 FDResPub - ok
14:18:55.0932 4548 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
14:18:55.0932 4548 FileInfo - ok
14:18:55.0962 4548 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
14:18:55.0972 4548 Filetrace - ok
14:18:55.0982 4548 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
14:18:55.0992 4548 flpydisk - ok
14:18:56.0042 4548 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
14:18:56.0042 4548 FltMgr - ok
14:18:56.0252 4548 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
14:18:56.0292 4548 FontCache - ok
14:18:56.0352 4548 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
14:18:56.0362 4548 FontCache3.0.0.0 - ok
14:18:56.0382 4548 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
14:18:56.0392 4548 Fs_Rec - ok
14:18:56.0412 4548 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
14:18:56.0422 4548 gagp30kx - ok
14:18:56.0462 4548 [ F1785FB4B89442AAC648492B35EBCDC9 ] GpdDevDPort C:\Windows\system32\directport.sys
14:18:56.0532 4548 GpdDevDPort - ok
14:18:56.0572 4548 [ E48C4E69E2126AAC01888C60CC6ED966 ] GpdKbFilter C:\Windows\system32\kbfiltr.sys
14:18:56.0612 4548 GpdKbFilter - ok
14:18:56.0652 4548 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
14:18:56.0682 4548 gpsvc - ok
14:18:56.0772 4548 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
14:18:56.0782 4548 gupdate - ok
14:18:56.0792 4548 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
14:18:56.0792 4548 gupdatem - ok
14:18:56.0842 4548 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
14:18:56.0852 4548 gusvc - ok
14:18:56.0902 4548 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
14:18:56.0912 4548 HdAudAddService - ok
14:18:56.0962 4548 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
14:18:56.0982 4548 HDAudBus - ok
14:18:57.0022 4548 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
14:18:57.0022 4548 HidBth - ok
14:18:57.0042 4548 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
14:18:57.0052 4548 HidIr - ok
14:18:57.0082 4548 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll
14:18:57.0092 4548 hidserv - ok
14:18:57.0132 4548 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
14:18:57.0132 4548 HidUsb - ok
14:18:57.0172 4548 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
14:18:57.0182 4548 hkmsvc - ok
14:18:57.0202 4548 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
14:18:57.0212 4548 HpCISSs - ok
14:18:57.0252 4548 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
14:18:57.0262 4548 HTTP - ok
14:18:57.0292 4548 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
14:18:57.0292 4548 i2omp - ok
14:18:57.0342 4548 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
14:18:57.0342 4548 i8042prt - ok
14:18:57.0392 4548 [ E5A0034847537EAEE3C00349D5C34C5F ] iaStor C:\Windows\system32\drivers\iastor.sys
14:18:57.0402 4548 iaStor - ok
14:18:57.0432 4548 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
14:18:57.0432 4548 iaStorV - ok
14:18:57.0522 4548 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
14:18:57.0552 4548 idsvc - ok
14:18:57.0902 4548 [ 8266AE06DF974E5BA047B3E9E9E70B3F ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
14:18:58.0312 4548 igfx - ok
14:18:58.0352 4548 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
14:18:58.0362 4548 iirsp - ok
14:18:58.0412 4548 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
14:18:58.0452 4548 IKEEXT - ok
14:18:58.0572 4548 [ FBBE3F1697D393BE685CD6192B1EC95A ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
14:18:58.0652 4548 IntcAzAudAddService - ok
14:18:58.0702 4548 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
14:18:58.0702 4548 intelide - ok
14:18:58.0732 4548 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
14:18:58.0732 4548 intelppm - ok
14:18:58.0772 4548 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
14:18:58.0782 4548 IPBusEnum - ok
14:18:58.0802 4548 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
14:18:58.0812 4548 IpFilterDriver - ok
14:18:58.0842 4548 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
14:18:58.0852 4548 iphlpsvc - ok
14:18:58.0862 4548 IpInIp - ok
14:18:58.0892 4548 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
14:18:58.0892 4548 IPMIDRV - ok
14:18:58.0912 4548 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
14:18:58.0912 4548 IPNAT - ok
14:18:58.0932 4548 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
14:18:58.0932 4548 IRENUM - ok
14:18:58.0962 4548 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
14:18:58.0962 4548 isapnp - ok
14:18:59.0002 4548 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
14:18:59.0012 4548 iScsiPrt - ok
14:18:59.0032 4548 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
14:18:59.0042 4548 iteatapi - ok
14:18:59.0062 4548 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
14:18:59.0062 4548 iteraid - ok
14:18:59.0092 4548 [ C36F3A1A4E8416EF43F30DEAB7701730 ] JRAID C:\Windows\system32\drivers\jraid.sys
14:18:59.0102 4548 JRAID - ok
14:18:59.0122 4548 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
14:18:59.0122 4548 kbdclass - ok
14:18:59.0162 4548 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
14:18:59.0172 4548 kbdhid - ok
14:18:59.0202 4548 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
14:18:59.0202 4548 KeyIso - ok
14:18:59.0262 4548 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
14:18:59.0282 4548 KSecDD - ok
14:18:59.0342 4548 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
14:18:59.0362 4548 KtmRm - ok
14:18:59.0392 4548 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\system32\srvsvc.dll
14:18:59.0402 4548 LanmanServer - ok
14:18:59.0452 4548 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
14:18:59.0462 4548 LanmanWorkstation - ok
14:18:59.0492 4548 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
14:18:59.0502 4548 lltdio - ok
14:18:59.0542 4548 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
14:18:59.0552 4548 lltdsvc - ok
14:18:59.0582 4548 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
14:18:59.0582 4548 lmhosts - ok
14:18:59.0612 4548 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
14:18:59.0612 4548 LSI_FC - ok
14:18:59.0642 4548 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
14:18:59.0652 4548 LSI_SAS - ok
14:18:59.0672 4548 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
14:18:59.0682 4548 LSI_SCSI - ok
14:18:59.0702 4548 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
14:18:59.0712 4548 luafv - ok
14:18:59.0772 4548 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
14:18:59.0772 4548 MBAMProtector - ok
14:18:59.0852 4548 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
14:18:59.0872 4548 MBAMScheduler - ok
14:18:59.0932 4548 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
14:18:59.0962 4548 MBAMService - ok
14:19:00.0012 4548 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
14:19:00.0012 4548 Mcx2Svc - ok
14:19:00.0042 4548 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
14:19:00.0052 4548 megasas - ok
14:19:00.0082 4548 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
14:19:00.0112 4548 MegaSR - ok
14:19:00.0142 4548 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
14:19:00.0152 4548 MMCSS - ok
14:19:00.0172 4548 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
14:19:00.0172 4548 Modem - ok
14:19:00.0202 4548 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
14:19:00.0202 4548 monitor - ok
14:19:00.0222 4548 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
14:19:00.0222 4548 mouclass - ok
14:19:00.0242 4548 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
14:19:00.0242 4548 mouhid - ok
14:19:00.0272 4548 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
14:19:00.0272 4548 MountMgr - ok
14:19:00.0342 4548 [ CF105EE42E3F71E648CEBB3F666E1CF0 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
14:19:00.0342 4548 MpFilter - ok
14:19:00.0372 4548 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
14:19:00.0372 4548 mpio - ok
14:19:00.0502 4548 [ A69630D039C38018689190234F866D77 ] MpKsl9812266e C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4333F5BA-7AFE-42C9-B4DF-1E5B57D605DA}\MpKsl9812266e.sys
14:19:00.0512 4548 MpKsl9812266e - ok
14:19:00.0552 4548 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
14:19:00.0552 4548 mpsdrv - ok
14:19:00.0612 4548 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
14:19:00.0632 4548 MpsSvc - ok
14:19:00.0662 4548 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
14:19:00.0672 4548 Mraid35x - ok
14:19:00.0722 4548 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
14:19:00.0722 4548 MRxDAV - ok
14:19:00.0762 4548 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
14:19:00.0762 4548 mrxsmb - ok
14:19:00.0802 4548 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
14:19:00.0812 4548 mrxsmb10 - ok
14:19:00.0822 4548 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
14:19:00.0832 4548 mrxsmb20 - ok
14:19:00.0892 4548 [ 5457DCFA7C0DA43522F4D9D4049C1472 ] msahci C:\Windows\system32\drivers\msahci.sys
14:19:00.0892 4548 msahci - ok
14:19:00.0912 4548 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
14:19:00.0922 4548 msdsm - ok
14:19:00.0962 4548 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
14:19:00.0972 4548 MSDTC - ok
14:19:01.0012 4548 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
14:19:01.0012 4548 Msfs - ok
14:19:01.0032 4548 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
14:19:01.0042 4548 msisadrv - ok
14:19:01.0082 4548 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
14:19:01.0082 4548 MSiSCSI - ok
14:19:01.0092 4548 msiserver - ok
14:19:01.0122 4548 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
14:19:01.0122 4548 MSKSSRV - ok
14:19:01.0182 4548 [ C1F19D2BACBEE9AB64D9AE69E9859AC0 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe
14:19:01.0182 4548 MsMpSvc - ok
14:19:01.0202 4548 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
14:19:01.0202 4548 MSPCLOCK - ok
14:19:01.0222 4548 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
14:19:01.0222 4548 MSPQM - ok
14:19:01.0262 4548 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
14:19:01.0272 4548 MsRPC - ok
14:19:01.0302 4548 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
14:19:01.0302 4548 mssmbios - ok
14:19:01.0322 4548 Scan interrupted by user!
14:19:01.0322 4548 ================ Scan global ===============================
14:19:01.0322 4548 Scan interrupted by user!
14:19:01.0322 4548 ================ Scan MBR ==================================
14:19:01.0322 4548 Scan interrupted by user!
14:19:01.0322 4548 ================ Scan VBR ==================================
14:19:01.0322 4548 Scan interrupted by user!
14:19:01.0322 4548 ============================================================
14:19:01.0322 4548 Scan finished
14:19:01.0322 4548 ============================================================
14:19:01.0332 5920 Detected object count: 0
14:19:01.0332 5920 Actual detected object count: 0
14:19:15.0718 2520 ============================================================
14:19:15.0718 2520 Scan started
14:19:15.0718 2520 Mode: Manual; SigCheck; TDLFS;
14:19:15.0718 2520 ============================================================
14:19:16.0124 2520 ================ Scan system memory ========================
14:19:16.0124 2520 System memory - ok
14:19:16.0124 2520 ================ Scan services =============================
14:19:16.0350 2520 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
14:19:16.0590 2520 ACPI - ok
14:19:16.0630 2520 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
14:19:16.0690 2520 adp94xx - ok
14:19:16.0720 2520 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
14:19:16.0770 2520 adpahci - ok
14:19:16.0780 2520 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
14:19:16.0820 2520 adpu160m - ok
14:19:16.0850 2520 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
14:19:16.0880 2520 adpu320 - ok
14:19:16.0910 2520 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
14:19:16.0980 2520 AeLookupSvc - ok
14:19:17.0030 2520 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
14:19:17.0080 2520 AFD - ok
14:19:17.0110 2520 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
14:19:17.0140 2520 agp440 - ok
14:19:17.0180 2520 [ 0DEE2B628D4C6E23285BB91EFFDABFDE ] ahcix86s C:\Windows\system32\drivers\ahcix86s.sys
14:19:17.0220 2520 ahcix86s - ok
14:19:17.0250 2520 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
14:19:17.0280 2520 aic78xx - ok
14:19:17.0310 2520 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
14:19:17.0390 2520 ALG - ok
14:19:17.0420 2520 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
14:19:17.0440 2520 aliide - ok
14:19:17.0460 2520 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
14:19:17.0500 2520 amdagp - ok
14:19:17.0520 2520 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
14:19:17.0550 2520 amdide - ok
14:19:17.0580 2520 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
14:19:17.0650 2520 AmdK7 - ok
14:19:17.0680 2520 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
14:19:17.0760 2520 AmdK8 - ok
14:19:17.0780 2520 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
14:19:17.0840 2520 Appinfo - ok
14:19:17.0870 2520 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
14:19:17.0900 2520 arc - ok
14:19:17.0920 2520 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
14:19:17.0960 2520 arcsas - ok
14:19:18.0190 2520 [ 2FE0D5DB69014980A970D3BF9A85D2B1 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
14:19:18.0230 2520 aspnet_state - ok
14:19:18.0270 2520 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
14:19:18.0340 2520 AsyncMac - ok
14:19:18.0380 2520 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys
14:19:18.0410 2520 atapi - ok
14:19:18.0460 2520 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
14:19:18.0520 2520 AudioEndpointBuilder - ok
14:19:18.0540 2520 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
14:19:18.0600 2520 Audiosrv - ok
14:19:18.0620 2520 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
14:19:18.0700 2520 Beep - ok
14:19:18.0740 2520 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
14:19:18.0840 2520 BFE - ok
14:19:18.0910 2520 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\System32\qmgr.dll
14:19:18.0990 2520 BITS - ok
14:19:19.0010 2520 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
14:19:19.0070 2520 blbdrive - ok
14:19:19.0110 2520 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
14:19:19.0150 2520 bowser - ok
14:19:19.0180 2520 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
14:19:19.0230 2520 BrFiltLo - ok
14:19:19.0250 2520 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
14:19:19.0310 2520 BrFiltUp - ok
14:19:19.0350 2520 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
14:19:19.0430 2520 Browser - ok
14:19:19.0450 2520 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
14:19:19.0570 2520 Brserid - ok
14:19:19.0600 2520 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
14:19:19.0720 2520 BrSerWdm - ok
14:19:19.0750 2520 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
14:19:19.0870 2520 BrUsbMdm - ok
14:19:19.0890 2520 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
14:19:20.0000 2520 BrUsbSer - ok
14:19:20.0020 2520 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
14:19:20.0140 2520 BTHMODEM - ok
14:19:20.0170 2520 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
14:19:20.0260 2520 cdfs - ok
14:19:20.0290 2520 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
14:19:20.0350 2520 cdrom - ok
14:19:20.0390 2520 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
14:19:20.0440 2520 CertPropSvc - ok
14:19:20.0460 2520 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
14:19:20.0530 2520 circlass - ok
14:19:20.0570 2520 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
14:19:20.0620 2520 CLFS - ok
14:19:20.0680 2520 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:19:20.0700 2520 clr_optimization_v2.0.50727_32 - ok
14:19:20.0740 2520 [ 6D7C8A951AF6AD6835C029B3CB88D333 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
14:19:20.0790 2520 clr_optimization_v4.0.30319_32 - ok
14:19:20.0820 2520 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
14:19:20.0900 2520 CmBatt - ok
14:19:20.0920 2520 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
14:19:20.0950 2520 cmdide - ok
14:19:20.0960 2520 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
14:19:20.0990 2520 Compbatt - ok
14:19:21.0000 2520 COMSysApp - ok
14:19:21.0010 2520 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
14:19:21.0040 2520 crcdisk - ok
14:19:21.0060 2520 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
14:19:21.0120 2520 Crusoe - ok
14:19:21.0160 2520 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll
14:19:21.0230 2520 CryptSvc - ok
14:19:21.0300 2520 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
14:19:21.0390 2520 DcomLaunch - ok
14:19:21.0410 2520 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
14:19:21.0450 2520 DfsC - ok
14:19:21.0580 2520 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
14:19:21.0750 2520 DFSR - ok
14:19:21.0790 2520 [ 649705E3DAE598BC0F957BACBF9A2BD5 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
14:19:21.0820 2520 dg_ssudbus - ok
14:19:21.0870 2520 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
14:19:21.0940 2520 Dhcp - ok
14:19:21.0980 2520 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
14:19:22.0010 2520 disk - ok
14:19:22.0050 2520 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
14:19:22.0100 2520 Dnscache - ok
14:19:22.0130 2520 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
14:19:22.0200 2520 dot3svc - ok
14:19:22.0240 2520 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
14:19:22.0350 2520 DPS - ok
14:19:22.0390 2520 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
14:19:22.0450 2520 drmkaud - ok
14:19:22.0510 2520 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
14:19:22.0570 2520 DXGKrnl - ok
14:19:22.0610 2520 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
14:19:22.0690 2520 E1G60 - ok
14:19:22.0710 2520 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
14:19:22.0810 2520 EapHost - ok
14:19:22.0840 2520 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
14:19:22.0880 2520 Ecache - ok
14:19:22.0950 2520 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
14:19:23.0000 2520 ehRecvr - ok
14:19:23.0020 2520 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
14:19:23.0090 2520 ehSched - ok
14:19:23.0100 2520 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
14:19:23.0150 2520 ehstart - ok
14:19:23.0220 2520 [ 2A2F1FA78751C9932098529EE1EDEB1A ] eLoggerSvc6 C:\Program Files\Norman\Npm\Bin\Elogsvc.exe
14:19:23.0240 2520 eLoggerSvc6 ( UnsignedFile.Multi.Generic ) - warning
14:19:23.0250 2520 eLoggerSvc6 - detected UnsignedFile.Multi.Generic (1)
14:19:23.0300 2520 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
14:19:23.0340 2520 elxstor - ok
14:19:23.0400 2520 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
14:19:23.0500 2520 EMDMgmt - ok
14:19:23.0520 2520 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
14:19:23.0590 2520 ErrDev - ok
14:19:23.0650 2520 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
14:19:23.0720 2520 EventSystem - ok
14:19:23.0760 2520 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
14:19:23.0820 2520 exfat - ok
14:19:23.0920 2520 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
14:19:24.0030 2520 fastfat - ok
14:19:24.0040 2520 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
14:19:24.0120 2520 fdc - ok
14:19:24.0150 2520 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
14:19:24.0220 2520 fdPHost - ok
14:19:24.0230 2520 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
14:19:24.0350 2520 FDResPub - ok
14:19:24.0380 2520 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
14:19:24.0410 2520 FileInfo - ok
14:19:24.0430 2520 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
14:19:24.0510 2520 Filetrace - ok
14:19:24.0530 2520 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
14:19:24.0600 2520 flpydisk - ok
14:19:24.0640 2520 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
14:19:24.0680 2520 FltMgr - ok
14:19:24.0740 2520 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
14:19:24.0830 2520 FontCache - ok
14:19:24.0880 2520 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
14:19:24.0910 2520 FontCache3.0.0.0 - ok
14:19:24.0940 2520 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
14:19:24.0990 2520 Fs_Rec - ok
14:19:25.0010 2520 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
14:19:25.0040 2520 gagp30kx - ok
14:19:25.0080 2520 [ F1785FB4B89442AAC648492B35EBCDC9 ] GpdDevDPort C:\Windows\system32\directport.sys
14:19:25.0090 2520 GpdDevDPort ( UnsignedFile.Multi.Generic ) - warning
14:19:25.0090 2520 GpdDevDPort - detected UnsignedFile.Multi.Generic (1)
14:19:25.0110 2520 [ E48C4E69E2126AAC01888C60CC6ED966 ] GpdKbFilter C:\Windows\system32\kbfiltr.sys
14:19:25.0130 2520 GpdKbFilter ( UnsignedFile.Multi.Generic ) - warning
14:19:25.0130 2520 GpdKbFilter - detected UnsignedFile.Multi.Generic (1)
14:19:25.0170 2520 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
14:19:25.0280 2520 gpsvc - ok
14:19:25.0360 2520 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
14:19:25.0380 2520 gupdate - ok
14:19:25.0420 2520 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
14:19:25.0450 2520 gupdatem - ok
14:19:25.0470 2520 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
14:19:25.0500 2520 gusvc - ok
14:19:25.0550 2520 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
14:19:25.0680 2520 HdAudAddService - ok
14:19:25.0730 2520 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
14:19:25.0830 2520 HDAudBus - ok
14:19:25.0870 2520 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
14:19:25.0980 2520 HidBth - ok
14:19:26.0000 2520 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
14:19:26.0110 2520 HidIr - ok
14:19:26.0150 2520 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll
14:19:26.0210 2520 hidserv - ok
14:19:26.0250 2520 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
14:19:26.0310 2520 HidUsb - ok
14:19:26.0350 2520 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
14:19:26.0420 2520 hkmsvc - ok
14:19:26.0450 2520 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
14:19:26.0480 2520 HpCISSs - ok
14:19:26.0520 2520 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
14:19:26.0610 2520 HTTP - ok
14:19:26.0650 2520 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
14:19:26.0680 2520 i2omp - ok
14:19:26.0700 2520 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
14:19:26.0760 2520 i8042prt - ok
14:19:26.0810 2520 [ E5A0034847537EAEE3C00349D5C34C5F ] iaStor C:\Windows\system32\drivers\iastor.sys
14:19:26.0850 2520 iaStor - ok
14:19:26.0880 2520 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
14:19:26.0920 2520 iaStorV - ok
14:19:27.0000 2520 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
14:19:27.0070 2520 idsvc - ok
14:19:27.0400 2520 [ 8266AE06DF974E5BA047B3E9E9E70B3F ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
14:19:27.0930 2520 igfx - ok
14:19:27.0950 2520 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
14:19:27.0980 2520 iirsp - ok
14:19:28.0030 2520 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
14:19:28.0120 2520 IKEEXT - ok
14:19:28.0230 2520 [ FBBE3F1697D393BE685CD6192B1EC95A ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
14:19:28.0380 2520 IntcAzAudAddService - ok
14:19:28.0400 2520 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
14:19:28.0430 2520 intelide - ok
14:19:28.0460 2520 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
14:19:28.0520 2520 intelppm - ok
14:19:28.0560 2520 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
14:19:28.0620 2520 IPBusEnum - ok
14:19:28.0650 2520 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
14:19:28.0730 2520 IpFilterDriver - ok
14:19:28.0760 2520 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
14:19:28.0810 2520 iphlpsvc - ok
14:19:28.0820 2520 IpInIp - ok
14:19:28.0840 2520 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
14:19:28.0920 2520 IPMIDRV - ok
14:19:28.0940 2520 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
14:19:29.0010 2520 IPNAT - ok
14:19:29.0030 2520 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
14:19:29.0090 2520 IRENUM - ok
14:19:29.0140 2520 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
14:19:29.0180 2520 isapnp - ok
14:19:29.0210 2520 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
14:19:29.0250 2520 iScsiPrt - ok
14:19:29.0280 2520 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
14:19:29.0300 2520 iteatapi - ok
14:19:29.0330 2520 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
14:19:29.0360 2520 iteraid - ok
14:19:29.0390 2520 [ C36F3A1A4E8416EF43F30DEAB7701730 ] JRAID C:\Windows\system32\drivers\jraid.sys
14:19:29.0460 2520 JRAID - ok
14:19:29.0480 2520 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
14:19:29.0520 2520 kbdclass - ok
14:19:29.0550 2520 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
14:19:29.0610 2520 kbdhid - ok
14:19:29.0640 2520 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
14:19:29.0710 2520 KeyIso - ok
14:19:29.0760 2520 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
14:19:29.0820 2520 KSecDD - ok
14:19:29.0870 2520 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
14:19:29.0980 2520 KtmRm - ok
14:19:30.0010 2520 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\system32\srvsvc.dll
14:19:30.0050 2520 LanmanServer - ok
14:19:30.0100 2520 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
14:19:30.0170 2520 LanmanWorkstation - ok
14:19:30.0200 2520 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
14:19:30.0280 2520 lltdio - ok
14:19:30.0330 2520 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
14:19:30.0400 2520 lltdsvc - ok
14:19:30.0420 2520 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
14:19:30.0530 2520 lmhosts - ok
14:19:30.0570 2520 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
14:19:30.0600 2520 LSI_FC - ok
14:19:30.0630 2520 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
14:19:30.0660 2520 LSI_SAS - ok
14:19:30.0690 2520 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
14:19:30.0730 2520 LSI_SCSI - ok
14:19:30.0750 2520 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
14:19:30.0830 2520 luafv - ok
14:19:30.0870 2520 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
14:19:30.0900 2520 MBAMProtector - ok
14:19:30.0970 2520 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
14:19:31.0020 2520 MBAMScheduler - ok
14:19:31.0070 2520 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
14:19:31.0150 2520 MBAMService - ok
14:19:31.0190 2520 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
14:19:31.0230 2520 Mcx2Svc - ok
14:19:31.0250 2520 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
14:19:31.0280 2520 megasas - ok
14:19:31.0320 2520 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
14:19:31.0360 2520 MegaSR - ok
14:19:31.0400 2520 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
14:19:31.0480 2520 MMCSS - ok
14:19:31.0500 2520 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
14:19:31.0560 2520 Modem - ok
14:19:31.0590 2520 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
14:19:31.0650 2520 monitor - ok
14:19:31.0660 2520 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
14:19:31.0700 2520 mouclass - ok
14:19:31.0720 2520 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
14:19:31.0800 2520 mouhid - ok
14:19:31.0820 2520 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
14:19:31.0850 2520 MountMgr - ok
14:19:31.0890 2520 [ CF105EE42E3F71E648CEBB3F666E1CF0 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
14:19:31.0940 2520 MpFilter - ok
14:19:31.0970 2520 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
14:19:32.0010 2520 mpio - ok
14:19:32.0120 2520 [ A69630D039C38018689190234F866D77 ] MpKsl9812266e C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4333F5BA-7AFE-42C9-B4DF-1E5B57D605DA}\MpKsl9812266e.sys
14:19:32.0140 2520 MpKsl9812266e - ok
14:19:32.0160 2520 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
14:19:32.0230 2520 mpsdrv - ok
14:19:32.0280 2520 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
14:19:32.0370 2520 MpsSvc - ok
14:19:32.0400 2520 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
14:19:32.0430 2520 Mraid35x - ok
14:19:32.0470 2520 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
14:19:32.0520 2520 MRxDAV - ok
14:19:32.0560 2520 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
14:19:32.0590 2520 mrxsmb - ok
14:19:32.0640 2520 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
14:19:32.0690 2520 mrxsmb10 - ok
14:19:32.0700 2520 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
14:19:32.0740 2520 mrxsmb20 - ok
14:19:32.0770 2520 [ 5457DCFA7C0DA43522F4D9D4049C1472 ] msahci C:\Windows\system32\drivers\msahci.sys
14:19:32.0800 2520 msahci - ok
14:19:32.0830 2520 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
14:19:32.0860 2520 msdsm - ok
14:19:32.0900 2520 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
14:19:33.0010 2520 MSDTC - ok
14:19:33.0050 2520 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
14:19:33.0130 2520 Msfs - ok
14:19:33.0150 2520 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
14:19:33.0180 2520 msisadrv - ok
14:19:33.0230 2520 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
14:19:33.0310 2520 MSiSCSI - ok
14:19:33.0330 2520 msiserver - ok
14:19:33.0350 2520 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
14:19:33.0420 2520 MSKSSRV - ok
14:19:33.0470 2520 [ C1F19D2BACBEE9AB64D9AE69E9859AC0 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe
14:19:33.0500 2520 MsMpSvc - ok
14:19:33.0520 2520 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
14:19:33.0590 2520 MSPCLOCK - ok
14:19:33.0620 2520 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
14:19:33.0690 2520 MSPQM - ok
14:19:33.0740 2520 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
14:19:33.0780 2520 MsRPC - ok
14:19:33.0810 2520 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
14:19:33.0840 2520 mssmbios - ok
14:19:33.0860 2520 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
14:19:33.0930 2520 MSTEE - ok
14:19:33.0950 2520 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
14:19:33.0990 2520 Mup - ok
14:19:34.0030 2520 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
14:19:34.0110 2520 napagent - ok
14:19:34.0170 2520 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
14:19:34.0230 2520 NativeWifiP - ok
14:19:34.0300 2520 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
14:19:34.0390 2520 NDIS - ok
14:19:34.0430 2520 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
14:19:34.0500 2520 NdisTapi - ok
14:19:34.0520 2520 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
14:19:34.0580 2520 Ndisuio - ok
14:19:34.0610 2520 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
14:19:34.0680 2520 NdisWan - ok
14:19:34.0690 2520 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
14:19:34.0750 2520 NDProxy - ok
14:19:34.0890 2520 [ B044BB341E164DA6750A9B8E6A5FF6A1 ] Nero BackItUp Scheduler 3 C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
14:19:35.0150 2520 Nero BackItUp Scheduler 3 - ok
14:19:35.0170 2520 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
14:19:35.0240 2520 NetBIOS - ok
14:19:35.0290 2520 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
14:19:35.0370 2520 netbt - ok
14:19:35.0400 2520 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
14:19:35.0440 2520 Netlogon - ok
14:19:35.0480 2520 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
14:19:35.0580 2520 Netman - ok
14:19:35.0620 2520 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
14:19:35.0670 2520 NetMsmqActivator - ok
14:19:35.0690 2520 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
14:19:35.0730 2520 NetPipeActivator - ok
14:19:35.0760 2520 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
14:19:35.0840 2520 netprofm - ok
14:19:35.0850 2520 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
14:19:35.0900 2520 NetTcpActivator - ok
14:19:35.0910 2520 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
14:19:35.0960 2520 NetTcpPortSharing - ok
14:19:36.0120 2520 [ 840D89327C45B0CB9E1AB130249046E2 ] NETw5v32 C:\Windows\system32\DRIVERS\NETw5v32.sys
14:19:36.0420 2520 NETw5v32 - ok
14:19:36.0470 2520 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
14:19:36.0510 2520 nfrd960 - ok
14:19:36.0580 2520 [ 832E098BCA8235436FE2D8AE50AC3718 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
14:19:36.0630 2520 NisDrv - ok
14:19:36.0670 2520 [ E570ECA850F30EB740C2E9699DF3D2BD ] NisSrv C:\Program Files\Microsoft Security Client\NisSrv.exe
14:19:36.0730 2520 NisSrv - ok
14:19:36.0760 2520 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
14:19:36.0830 2520 NlaSvc - ok
14:19:36.0930 2520 [ EBA1B4BF2E2375ABDADEDB649F283541 ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
14:19:37.0030 2520 NMIndexingService - ok
14:19:37.0080 2520 [ 9099A0621485743C88C484DFD447639A ] Norman NJeeves C:\Program Files\Norman\Npm\bin\NJEEVES.EXE
14:19:39.0020 2520 Norman NJeeves ( UnsignedFile.Multi.Generic ) - warning
14:19:39.0020 2520 Norman NJeeves - detected UnsignedFile.Multi.Generic (1)
14:19:39.0100 2520 [ A69620970077A0B2D01730D475B149AD ] Norman ZANDA C:\Program Files\Norman\Npm\Bin\Zanda.exe
14:19:39.0310 2520 Norman ZANDA ( UnsignedFile.Multi.Generic ) - warning
14:19:39.0310 2520 Norman ZANDA - detected UnsignedFile.Multi.Generic (1)
14:19:39.0350 2520 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
14:19:39.0400 2520 Npfs - ok
14:19:39.0430 2520 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
14:19:39.0520 2520 nsi - ok
14:19:39.0550 2520 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
14:19:39.0630 2520 nsiproxy - ok
14:19:39.0720 2520 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
14:19:39.0830 2520 Ntfs - ok
14:19:39.0850 2520 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
14:19:39.0960 2520 ntrigdigi - ok
14:19:39.0980 2520 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
14:19:40.0050 2520 Null - ok
14:19:40.0090 2520 [ 24645A40D2AC27AB096277376B3B1B02 ] NVCScheduler C:\Program Files\Norman\Npm\bin\NVCSCHED.EXE
14:19:40.0350 2520 NVCScheduler ( UnsignedFile.Multi.Generic ) - warning
14:19:40.0350 2520 NVCScheduler - detected UnsignedFile.Multi.Generic (1)
14:19:40.0390 2520 [ C1F022966E678E780E2B801D3409614A ] NVOY C:\Program Files\Norman\npm\bin\nvoy.exe
14:19:40.0540 2520 NVOY ( UnsignedFile.Multi.Generic ) - warning
14:19:40.0540 2520 NVOY - detected UnsignedFile.Multi.Generic (1)
14:19:40.0660 2520 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
14:19:40.0700 2520 nvraid - ok
14:19:40.0720 2520 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
14:19:40.0760 2520 nvstor - ok
14:19:40.0780 2520 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
14:19:40.0810 2520 nv_agp - ok
14:19:40.0820 2520 NwlnkFlt - ok
14:19:40.0830 2520 NwlnkFwd - ok
14:19:40.0960 2520 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
14:19:41.0030 2520 odserv - ok
14:19:41.0070 2520 [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
14:19:41.0210 2520 ohci1394 - ok
14:19:41.0240 2520 [ B7EDD9FD6387802DFAA795372AECF212 ] OsdService C:\Program Files\OEM\OSD_1.16\OsdService.exe
14:19:41.0370 2520 OsdService ( UnsignedFile.Multi.Generic ) - warning
14:19:41.0370 2520 OsdService - detected UnsignedFile.Multi.Generic (1)
14:19:41.0420 2520 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
14:19:41.0450 2520 ose - ok
14:19:41.0510 2520 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
14:19:41.0630 2520 p2pimsvc - ok
14:19:41.0670 2520 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
14:19:41.0730 2520 p2psvc - ok
14:19:41.0760 2520 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
14:19:41.0870 2520 Parport - ok
14:19:41.0910 2520 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
14:19:41.0950 2520 partmgr - ok
14:19:41.0970 2520 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
14:19:42.0080 2520 Parvdm - ok
14:19:42.0120 2520 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
14:19:42.0180 2520 PcaSvc - ok
14:19:42.0220 2520 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
14:19:42.0270 2520 pci - ok
14:19:42.0290 2520 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
14:19:42.0320 2520 pciide - ok
14:19:42.0350 2520 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
14:19:42.0390 2520 pcmcia - ok
14:19:42.0440 2520 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
14:19:42.0620 2520 PEAUTH - ok
14:19:42.0730 2520 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
14:19:42.0910 2520 pla - ok
14:19:42.0950 2520 [ 875E4E0661F3A5994DF9E5E3A0A4F96B ] PLFlash DeviceIoControl Service C:\Windows\system32\IoctlSvc.exe
14:19:42.0990 2520 PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - warning
14:19:42.0990 2520 PLFlash DeviceIoControl Service - detected UnsignedFile.Multi.Generic (1)
14:19:43.0030 2520 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
14:19:43.0120 2520 PlugPlay - ok
14:19:43.0340 2520 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
14:19:43.0390 2520 PNRPAutoReg - ok
14:19:43.0420 2520 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
14:19:43.0470 2520 PNRPsvc - ok
14:19:43.0520 2520 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
14:19:43.0640 2520 PolicyAgent - ok
14:19:43.0680 2520 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
14:19:43.0750 2520 PptpMiniport - ok
14:19:43.0780 2520 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
14:19:43.0850 2520 Processor - ok
14:19:43.0890 2520 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
14:19:43.0970 2520 ProfSvc - ok
14:19:43.0990 2520 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
14:19:44.0020 2520 ProtectedStorage - ok
14:19:44.0050 2520 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
14:19:44.0110 2520 PSched - ok
14:19:44.0140 2520 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
14:19:44.0170 2520 PxHelp20 - ok
14:19:44.0240 2520 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
14:19:44.0380 2520 ql2300 - ok
14:19:44.0420 2520 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
14:19:44.0460 2520 ql40xx - ok
14:19:44.0490 2520 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
14:19:44.0560 2520 QWAVE - ok
14:19:44.0580 2520 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
14:19:44.0630 2520 QWAVEdrv - ok
14:19:44.0650 2520 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
14:19:44.0730 2520 RasAcd - ok
14:19:44.0770 2520 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
14:19:44.0860 2520 RasAuto - ok
14:19:44.0890 2520 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
14:19:44.0980 2520 Rasl2tp - ok
14:19:45.0030 2520 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
14:19:45.0110 2520 RasMan - ok
14:19:45.0170 2520 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
14:19:45.0240 2520 RasPppoe - ok
14:19:45.0270 2520 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
14:19:45.0310 2520 RasSstp - ok
14:19:45.0350 2520 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
14:19:45.0450 2520 rdbss - ok
14:19:45.0480 2520 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
14:19:45.0560 2520 RDPCDD - ok
14:19:45.0600 2520 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
14:19:45.0680 2520 rdpdr - ok
14:19:45.0690 2520 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
14:19:45.0750 2520 RDPENCDD - ok
14:19:45.0790 2520 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
14:19:45.0840 2520 RDPWD - ok
14:19:45.0890 2520 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
14:19:45.0970 2520 RemoteAccess - ok
14:19:46.0010 2520 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
14:19:46.0080 2520 RemoteRegistry - ok
14:19:46.0100 2520 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
14:19:46.0320 2520 RpcLocator - ok
14:19:46.0350 2520 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll
14:19:46.0420 2520 RpcSs - ok
14:19:46.0450 2520 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
14:19:46.0530 2520 rspndr - ok
14:19:46.0590 2520 [ 8CCA591019216E9523E3CB385CE643E6 ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh86.sys
14:19:46.0670 2520 RTL8169 - ok
14:19:46.0700 2520 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
14:19:46.0730 2520 SamSs - ok
14:19:46.0750 2520 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
14:19:46.0790 2520 sbp2port - ok
14:19:46.0840 2520 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
14:19:46.0910 2520 SCardSvr - ok
14:19:46.0980 2520 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
14:19:47.0100 2520 Schedule - ok
14:19:47.0140 2520 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
14:19:47.0210 2520 SCPolicySvc - ok
14:19:47.0250 2520 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
14:19:47.0320 2520 SDRSVC - ok
14:19:47.0340 2520 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
14:19:47.0460 2520 secdrv - ok
14:19:47.0470 2520 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
14:19:47.0550 2520 seclogon - ok
14:19:47.0580 2520 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
14:19:47.0660 2520 SENS - ok
14:19:47.0690 2520 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
14:19:47.0800 2520 Serenum - ok
14:19:47.0830 2520 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
14:19:47.0940 2520 Serial - ok
14:19:47.0960 2520 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
14:19:48.0030 2520 sermouse - ok
14:19:48.0060 2520 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
14:19:48.0130 2520 SessionEnv - ok
14:19:48.0150 2520 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
14:19:48.0200 2520 sffdisk - ok
14:19:48.0230 2520 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
14:19:48.0300 2520 sffp_mmc - ok
14:19:48.0330 2520 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
14:19:48.0410 2520 sffp_sd - ok
14:19:48.0430 2520 [ C33BFBD6E9E41FCD9FFEF9729E9FAED6 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
14:19:48.0510 2520 sfloppy - ok
14:19:48.0560 2520 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
14:19:48.0650 2520 SharedAccess - ok
14:19:48.0690 2520 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
14:19:48.0770 2520 ShellHWDetection - ok
14:19:48.0800 2520 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
14:19:48.0840 2520 sisagp - ok
14:19:48.0860 2520 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
14:19:48.0910 2520 SiSRaid2 - ok
14:19:48.0940 2520 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
14:19:48.0980 2520 SiSRaid4 - ok
14:19:49.0030 2520 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
14:19:49.0060 2520 SkypeUpdate - ok
14:19:49.0210 2520 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
14:19:49.0530 2520 slsvc - ok
14:19:49.0580 2520 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
14:19:49.0640 2520 SLUINotify - ok
14:19:49.0680 2520 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
14:19:49.0730 2520 Smb - ok
14:19:49.0770 2520 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
14:19:49.0820 2520 SNMPTRAP - ok
14:19:49.0860 2520 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
14:19:49.0900 2520 spldr - ok
14:19:49.0930 2520 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
14:19:50.0000 2520 Spooler - ok
14:19:50.0050 2520 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
14:19:50.0120 2520 srv - ok
14:19:50.0150 2520 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
14:19:50.0200 2520 srv2 - ok
14:19:50.0240 2520 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
14:19:50.0280 2520 srvnet - ok
14:19:50.0320 2520 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
14:19:50.0390 2520 SSDPSRV - ok
14:19:50.0440 2520 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
14:19:50.0490 2520 SstpSvc - ok
14:19:50.0550 2520 [ 6D82CB78DE57A073E95431F3486B1B27 ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys
14:19:50.0580 2520 ssudmdm - ok
14:19:50.0650 2520 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
14:19:50.0740 2520 stisvc - ok
14:19:50.0770 2520 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
14:19:50.0810 2520 swenum - ok
14:19:50.0850 2520 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
14:19:50.0930 2520 swprv - ok
14:19:50.0950 2520 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
14:19:50.0980 2520 Symc8xx - ok
14:19:51.0000 2520 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
14:19:51.0030 2520 Sym_hi - ok
14:19:51.0050 2520 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
14:19:51.0080 2520 Sym_u3 - ok
14:19:51.0130 2520 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
14:19:51.0250 2520 SysMain - ok
14:19:51.0280 2520 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
14:19:51.0360 2520 TabletInputService - ok
14:19:51.0500 2520 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
14:19:51.0580 2520 TapiSrv - ok
14:19:51.0600 2520 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
14:19:51.0690 2520 TBS - ok
14:19:51.0750 2520 [ 3535CD93F944C00F098E73E12EE7FEB6 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
14:19:51.0840 2520 Tcpip - ok
14:19:51.0900 2520 [ 3535CD93F944C00F098E73E12EE7FEB6 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
14:19:51.0970 2520 Tcpip6 - ok
14:19:52.0010 2520 [ CD21572F83F7EC6E2C20C465967BEDD9 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
14:19:52.0070 2520 tcpipreg - ok
14:19:52.0100 2520 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
14:19:52.0170 2520 TDPIPE - ok
14:19:52.0200 2520 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
14:19:52.0300 2520 TDTCP - ok
14:19:52.0350 2520 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
14:19:52.0400 2520 tdx - ok
14:19:52.0430 2520 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
14:19:52.0470 2520 TermDD - ok
14:19:52.0500 2520 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
14:19:52.0580 2520 TermService - ok
14:19:52.0670 2520 [ 250B9120C7C103AFDC0C6643F9691055 ] TestHandler C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
14:19:52.0710 2520 TestHandler ( UnsignedFile.Multi.Generic ) - warning
14:19:52.0710 2520 TestHandler - detected UnsignedFile.Multi.Generic (1)
14:19:52.0740 2520 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
14:19:52.0790 2520 Themes - ok
14:19:52.0820 2520 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
14:19:52.0880 2520 THREADORDER - ok
14:19:52.0930 2520 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
14:19:53.0010 2520 TrkWks - ok
14:19:53.0070 2520 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
14:19:53.0140 2520 TrustedInstaller - ok
14:19:53.0170 2520 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
14:19:53.0250 2520 tssecsrv - ok
14:19:53.0310 2520 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
14:19:53.0360 2520 tunmp - ok
14:19:53.0390 2520 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
14:19:53.0420 2520 tunnel - ok
14:19:53.0450 2520 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
14:19:53.0480 2520 uagp35 - ok
14:19:53.0520 2520 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
14:19:53.0580 2520 udfs - ok
14:19:53.0610 2520 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
14:19:53.0700 2520 UI0Detect - ok
14:19:53.0730 2520 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
14:19:53.0760 2520 uliagpkx - ok
14:19:53.0800 2520 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
14:19:53.0850 2520 uliahci - ok
14:19:53.0880 2520 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
14:19:53.0910 2520 UlSata - ok
14:19:53.0950 2520 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
14:19:53.0990 2520 ulsata2 - ok
14:19:54.0020 2520 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
14:19:54.0100 2520 umbus - ok
14:19:54.0130 2520 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
14:19:54.0210 2520 upnphost - ok
14:19:54.0220 2520 USBAAPL - ok
14:19:54.0260 2520 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
14:19:54.0320 2520 usbccgp - ok
14:19:54.0350 2520 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
14:19:54.0480 2520 usbcir - ok
14:19:54.0520 2520 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
14:19:54.0590 2520 usbehci - ok
14:19:54.0650 2520 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
14:19:54.0710 2520 usbhub - ok
14:19:54.0740 2520 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
14:19:54.0840 2520 usbohci - ok
14:19:54.0880 2520 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
14:19:54.0950 2520 usbprint - ok
14:19:54.0980 2520 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
14:19:55.0180 2520 USBSTOR - ok
14:19:55.0200 2520 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
14:19:55.0250 2520 usbuhci - ok
14:19:55.0290 2520 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
14:19:55.0360 2520 usbvideo - ok
14:19:55.0410 2520 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
14:19:55.0500 2520 UxSms - ok
14:19:55.0550 2520 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
14:19:55.0660 2520 vds - ok
14:19:55.0700 2520 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
14:19:55.0780 2520 vga - ok
14:19:55.0800 2520 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
14:19:55.0880 2520 VgaSave - ok
14:19:55.0900 2520 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
14:19:55.0930 2520 viaagp - ok
14:19:55.0950 2520 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
14:19:56.0010 2520 ViaC7 - ok
14:19:56.0030 2520 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
14:19:56.0060 2520 viaide - ok
14:19:56.0090 2520 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
14:19:56.0120 2520 volmgr - ok
14:19:56.0170 2520 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
14:19:56.0210 2520 volmgrx - ok
14:19:56.0260 2520 [ 786DB5771F05EF300390399F626BF30A ] volsnap C:\Windows\system32\drivers\volsnap.sys
14:19:56.0300 2520 volsnap - ok
14:19:56.0330 2520 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
14:19:56.0370 2520 vsmraid - ok
14:19:56.0430 2520 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
14:19:56.0600 2520 VSS - ok
14:19:56.0640 2520 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
14:19:56.0710 2520 W32Time - ok
14:19:56.0740 2520 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
14:19:56.0850 2520 WacomPen - ok
14:19:56.0870 2520 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
14:19:56.0930 2520 Wanarp - ok
14:19:56.0930 2520 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
14:19:56.0980 2520 Wanarpv6 - ok
14:19:57.0030 2520 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
14:19:57.0110 2520 wcncsvc - ok
14:19:57.0150 2520 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
14:19:57.0210 2520 WcsPlugInService - ok
14:19:57.0240 2520 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
14:19:57.0270 2520 Wd - ok
14:19:57.0420 2520 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
14:19:57.0500 2520 Wdf01000 - ok
14:19:57.0520 2520 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
14:19:57.0610 2520 WdiServiceHost - ok
14:19:57.0620 2520 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
14:19:57.0690 2520 WdiSystemHost - ok
14:19:57.0740 2520 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
14:19:57.0800 2520 WebClient - ok
14:19:57.0840 2520 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
14:19:57.0900 2520 Wecsvc - ok
14:19:57.0930 2520 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
14:19:57.0990 2520 wercplsupport - ok
14:19:58.0040 2520 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
14:19:58.0090 2520 WerSvc - ok
14:19:58.0150 2520 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
14:19:58.0200 2520 WinDefend - ok
14:19:58.0210 2520 WinHttpAutoProxySvc - ok
14:19:58.0280 2520 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
14:19:58.0340 2520 Winmgmt - ok
14:19:58.0410 2520 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
14:19:58.0560 2520 WinRM - ok
14:19:58.0640 2520 [ 30FC6E5448D0CBAAA95280EEEF7FEDAE ] WinUSB C:\Windows\system32\DRIVERS\WinUSB.sys
14:19:58.0790 2520 WinUSB - ok
14:19:58.0850 2520 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
14:19:58.0950 2520 Wlansvc - ok
14:19:59.0000 2520 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
14:19:59.0060 2520 WmiAcpi - ok
14:19:59.0110 2520 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
14:19:59.0160 2520 wmiApSrv - ok
14:19:59.0240 2520 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
14:19:59.0380 2520 WMPNetworkSvc - ok
14:19:59.0410 2520 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
14:19:59.0470 2520 WPCSvc - ok
14:19:59.0510 2520 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
14:19:59.0570 2520 WPDBusEnum - ok
14:19:59.0610 2520 [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
14:19:59.0710 2520 WpdUsb - ok
14:19:59.0790 2520 [ 762CD41257671CE9DD1B57967537E0D9 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
14:19:59.0890 2520 WPFFontCache_v0400 - ok
14:19:59.0930 2520 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
14:19:59.0990 2520 ws2ifsl - ok
14:20:00.0020 2520 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\System32\wscsvc.dll
14:20:00.0080 2520 wscsvc - ok
14:20:00.0080 2520 WSearch - ok
14:20:00.0330 2520 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
14:20:00.0690 2520 wuauserv - ok
14:20:00.0730 2520 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
14:20:00.0770 2520 WudfPf - ok
14:20:00.0810 2520 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
14:20:00.0850 2520 WUDFRd - ok
14:20:00.0890 2520 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
14:20:00.0940 2520 wudfsvc - ok
14:20:00.0980 2520 ================ Scan global ===============================
14:20:01.0010 2520 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
14:20:01.0070 2520 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
14:20:01.0120 2520 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
14:20:01.0180 2520 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
14:20:01.0190 2520 [Global] - ok
14:20:01.0190 2520 ================ Scan MBR ==================================
14:20:01.0210 2520 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
14:20:01.0860 2520 \Device\Harddisk0\DR0 - ok
14:20:01.0860 2520 ================ Scan VBR ==================================
14:20:01.0870 2520 [ 13AA97369B33C1745B9CB83A70C3986D ] \Device\Harddisk0\DR0\Partition1
14:20:01.0870 2520 \Device\Harddisk0\DR0\Partition1 - ok
14:20:01.0910 2520 [ 8989E6204F137B3E84142541D412573E ] \Device\Harddisk0\DR0\Partition2
14:20:01.0920 2520 \Device\Harddisk0\DR0\Partition2 - ok
14:20:01.0920 2520 ============================================================
14:20:01.0920 2520 Scan finished
14:20:01.0920 2520 ============================================================
14:20:01.0940 5076 Detected object count: 10
14:20:01.0940 5076 Actual detected object count: 10
14:21:23.0240 5076 eLoggerSvc6 ( UnsignedFile.Multi.Generic ) - skipped by user
14:21:23.0240 5076 eLoggerSvc6 ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:21:23.0240 5076 GpdDevDPort ( UnsignedFile.Multi.Generic ) - skipped by user
14:21:23.0240 5076 GpdDevDPort ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:21:23.0240 5076 GpdKbFilter ( UnsignedFile.Multi.Generic ) - skipped by user
14:21:23.0240 5076 GpdKbFilter ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:21:23.0250 5076 Norman NJeeves ( UnsignedFile.Multi.Generic ) - skipped by user
14:21:23.0250 5076 Norman NJeeves ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:21:23.0250 5076 Norman ZANDA ( UnsignedFile.Multi.Generic ) - skipped by user
14:21:23.0250 5076 Norman ZANDA ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:21:23.0250 5076 NVCScheduler ( UnsignedFile.Multi.Generic ) - skipped by user
14:21:23.0250 5076 NVCScheduler ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:21:23.0260 5076 NVOY ( UnsignedFile.Multi.Generic ) - skipped by user
14:21:23.0260 5076 NVOY ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:21:23.0260 5076 OsdService ( UnsignedFile.Multi.Generic ) - skipped by user
14:21:23.0260 5076 OsdService ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:21:23.0260 5076 PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - skipped by user
14:21:23.0260 5076 PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:21:23.0270 5076 TestHandler ( UnsignedFile.Multi.Generic ) - skipped by user
14:21:23.0270 5076 TestHandler ( UnsignedFile.Multi.Generic ) - User select action: Skip

sorry anders ging es nicht

wie geht es jetzt weiter?

markusg 14.06.2013 14:26

Hi,
Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


lolale 14.06.2013 15:24

Liste der Anhänge anzeigen (Anzahl: 1)
hat nicht gemeckert.
Jetzt wieder aktivieren?

markusg 14.06.2013 18:04

zwischen den scans kannst du deine Programme aktivieren, während dessen bzw bei den fixes nicht
malwarebytes:
Downloade Dir bitte Malwarebytes
  • Installiere
    das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung --> Suche
    nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere vollständiger Scan durchführen und drücke auf Scannen.
  • Wenn der Scan beendet
    ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste
    das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.

lolale 14.06.2013 20:36

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.06.14.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Lola :: LOLA-PC [Administrator]

14.06.2013 19:41:47
mbam-log-2013-06-14 (19-41-47).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 354910
Laufzeit: 1 Stunde(n), 26 Minute(n), 51 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

passt dann jetzt alles? kannst du mir bitte noch tipps für die zukunft geben?

markusg 15.06.2013 13:47

Tipps gibts noch.

lade den CCleaner standard:
CCleaner - Download - Filepony
falls der CCleaner
bereits instaliert, überspringen.
öffnen, Tools (extras),uninstall Llist, als txt speichern. öffnen.
hinter, jedes von dir benötigte programm, schreibe notwendig.
hinter, jedes, von dir nicht benötigte, unnötig.
hinter, dir unbekannte, unbekannt.
liste posten.

lolale 18.06.2013 23:30

7-Zip 9.22beta 22.02.2012 3,63MB unbekannt
Activation Assistant for the 2007 Microsoft Office suites Microsoft Corporation 15.09.2008 14,0MB unbekannt
Adobe Flash Player 10 ActiveX Adobe Systems Incorporated 20.09.2011 10.3.183.7 notwendig
Adobe Flash Player 11 Plugin Adobe Systems Incorporated 29.01.2013 11.5.502.146 notwendig
Adobe Reader 8.1.2 - Deutsch Adobe Systems Incorporated 17.07.2008 99,6MB 8.1.2 notwendig
Apple Application Support Apple Inc. 29.01.2013 65,0MB 2.3 unnötig
Apple Software Update Apple Inc. 29.01.2013 2,38MB 2.1.3.127 unnötig
Ask Toolbar Ask.com 24.05.2013 4,92MB 1.15.23.0 unnötig
Ask Toolbar Updater Ask.com 24.05.2013 1.2.5.36191 unnötig
CCleaner Piriform 24.05.2013 5,62MB 4.02 unbekannt
Citavi 4 Swiss Academic Software 29.05.2013 243MB 4.0.0.12 notwendig
Compatibility Pack für 2007 Office System Microsoft Corporation 11.01.2013 282MB 12.0.6612.1000 unbekannt
Dropbox Dropbox, Inc. 1.6.18 notwendig
Free Studio version 5.1.7 DVDVideoSoft Ltd. 27.08.2011 69,6MB notwendig
Free YouTube Download version 3.1.41.1201 DVDVideoSoft Ltd. 06.12.2012 5,93MB 3.1.41.1201 notwendig
Free YouTube to MP3 Converter version 3.10.15.1228 DVDVideoSoft Ltd. 15.01.2012 2,72MB notwendig
FSCLounge Fujitsu Siemens Computers 15.09.2008 8,47MB 1.0.0 unbekannt
Fujitsu Siemens Computers Recovery Fujitsu Siemens Computers 15.09.2008 7,06MB 1.3.9 unbekannt
Google Toolbar for Internet Explorer Google Inc. 28.04.2009 7.4.3607.2246 unnötig
Intel(R) Graphics Media Accelerator Driver 17.07.2008 unbekannt
Java 7 Update 21 Oracle 23.05.2013 129MB 7.0.210 notwendig
Malwarebytes Anti-Malware Version 1.75.0.1300 Malwarebytes Corporation 15.06.2013 1.75.0.1300 notwendig
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft Corporation unbekannt
Microsoft .NET Framework 3.5 SP1 Microsoft Corporation 11.01.2013 unbekannt
Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Corporation 09.04.2013 unbekannt 4.0.30320
Microsoft .NET Framework 4.5 Microsoft Corporation 29.05.2013 4.5.50709 unbekannt
Microsoft Office File Validation Add-In Microsoft Corporation 04.10.2011 7,95MB 14.0.5130.5003 unbekannt
Microsoft Office Home and Student 2007 Microsoft Corporation 07.03.2012 296MB 12.0.6612.1000 notwendig
Microsoft Office Live Add-in 1.5 Microsoft Corporation 05.07.2012 506KB 2.0.4024.1 unbekannt
Microsoft Office PowerPoint Viewer 2007 (German) Microsoft Corporation 11.01.2013 98,8MB 12.0.6612.1000 notwendig
Microsoft Security Essentials Microsoft Corporation 26.02.2013 4.2.223.1 notwendig
Microsoft Works Microsoft Corporation 11.10.2012 1,18GB 9.7.0621 notwendig
Move Networks Media Player for Internet Explorer unbekannt
Mozilla Firefox 18.0.1 (x86 de) Mozilla 18.0.1 notwendig
MSXML 4.0 SP2 (KB936181) Microsoft Corporation 15.09.2008 1,26MB 4.20.9848.0 unbekannt
MSXML 4.0 SP2 (KB941833) Microsoft Corporation 16.09.2008 1,26MB 4.20.9849.0 unbekannt
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 12.11.2008 1,27MB 4.20.9870.0 unbekannt
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 25.11.2009 1,33MB 4.20.9876.0 unbekannt
Nero 8 Essentials Nero AG 17.07.2008 1,71GB 8.3.161 notwendig
Norman Security Suite Norman ASA 15.09.2008 118MB 7.00.0200 unbekannt
OSD_1.16 OEM 15.09.2008 1,22MB 1.0.0 unbekant
PDF24 Creator 5.3.0 PDF24.org 28.02.2013 notwendig
Picasa 3 Google, Inc. 3.8 notwendig
QuickTime Apple Inc. 29.01.2013 73,1MB 7.73.80.64 unnötig
Realtek High Definition Audio Driver Realtek Semiconductor Corp. unbekannt
Samsung Kies Samsung Electronics Co., Ltd. 09.04.2013 168MB 2.5.3.13034_9 unnötig

markusg 19.06.2013 00:13

deinstaliere:
Adobe Flash Player alle
Adobe - Adobe Flash Player installieren
neueste version laden, instalieren.
adobe reader:
Adobe - Adobe Reader herunterladen - Alle Versionen
haken bei mcafee security scan raus nehmen
bitte auch mal den adobe reader wie folgt konfigurieren:
adobe reader öffnen, bearbeiten, voreinstellungen.
allgemein:
nur zertifizierte zusatz module verwenden, anhaken.
Sicherheit (erweitert)
Erweiterte Sicherheit anhaken
und alle Dateien auswählen.
internet:
hier sollte alles deaktiviert werden, es ist sehr unsicher pdfs automatisch zu öffnen, zu downloaden etc.
es ist immer besser diese direkt abzuspeichern da man nur so die kontrolle hat was auf dem pc vor geht.
bei javascript den haken bei java script verwenden raus nehmen
bei updater, automatisch instalieren wählen.
übernehmen /ok

deinstaliere:
Ask : beide
Google Toolbar
Move
Norman

Öffne CCleaner, analysieren, starten, PC neustarten
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

lolale 19.06.2013 10:57

bei ask toolbar updater kam eine error meldung, dass es nicht gefunden wurde...

hier die datei:AdwCleaner Logfile:
Code:

# AdwCleaner v2.303 - Datei am 19/06/2013 um 12:30:05 erstellt
# Aktualisiert am 08/06/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : Lola - LOLA-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Lola\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gelöscht : C:\Users\Lola\AppData\Roaming\Mozilla\Firefox\Profiles\pdzzfday.default\searchplugins\Askcom.xml
Datei Gelöscht : C:\Users\Lola\AppData\Roaming\Mozilla\Firefox\Profiles\pdzzfday.default\searchplugins\Web Search.xml
Ordner Gelöscht : C:\Program Files\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Program Files\Moozy
Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\Users\Lola\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Lola\AppData\Roaming\OpenCandy

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16470

Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=e489272e-fad2-4ad4-975a-e4cbdd720640&searchtype=ds&q={searchTerms}&installDate=28/02/2013 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=e489272e-fad2-4ad4-975a-e4cbdd720640&searchtype=ds&q={searchTerms}&installDate=28/02/2013 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=e489272e-fad2-4ad4-975a-e4cbdd720640&searchtype=ds&q={searchTerms}&installDate=28/02/2013 --> hxxp://www.google.com
Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=e489272e-fad2-4ad4-975a-e4cbdd720640&searchtype=ds&q={searchTerms}&installDate=28/02/2013 --> hxxp://www.google.com

-\\ Mozilla Firefox v18.0.1 (de)

Datei : C:\Users\Lola\AppData\Roaming\Mozilla\Firefox\Profiles\pdzzfday.default\prefs.js

Gelöscht : user_pref("browser.newtab.url", "hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&use[...]
Gelöscht : user_pref("browser.search.defaultengine", "Ask.com");
Gelöscht : user_pref("browser.search.defaultenginename", "Ask.com");
Gelöscht : user_pref("browser.search.order.1", "Ask.com");
Gelöscht : user_pref("browser.search.selectedEngine", "Ask.com");

*************************

AdwCleaner[S1].txt - [4282 octets] - [19/06/2013 12:30:05]

########## EOF - C:\AdwCleaner[S1].txt - [4342 octets] ##########

--- --- ---

markusg 19.06.2013 18:05

Hi,
Hitman Pro - Download - Filepony

Hitmanpro laden, doppelklicken, Scan klicken.
Nichts löschen, auf weiter klicken.
Log speichern und posten, bzw als xml exportieren, packen und anhängen

lolale 21.06.2013 06:59

Code:

HitmanPro 3.7.6.201
www.hitmanpro.com

  Computer name . . . . : LOLA-PC
  Windows . . . . . . . : 6.0.2.6002.X86/2
  User name . . . . . . : Lola-PC\Lola
  UAC . . . . . . . . . : Enabled
  License . . . . . . . : Free

  Scan date . . . . . . : 2013-06-21 07:51:10
  Scan mode . . . . . . : Normal
  Scan duration . . . . : 6m 5s
  Disk access mode  . . : Direct disk access (SRB)
  Cloud . . . . . . . . : Internet
  Reboot  . . . . . . . : No

  Threats . . . . . . . : 0
  Traces  . . . . . . . : 24

  Objects scanned . . . : 1.853.351
  Files scanned . . . . : 25.349
  Remnants scanned  . . : 354.130 files / 1.473.872 keys

Cookies _____________________________________________________________________

  C:\Users\Lola\AppData\Roaming\Mozilla\Firefox\Profiles\pdzzfday.default\cookies.sqlite:atdmt.com
  C:\Users\Lola\AppData\Roaming\Mozilla\Firefox\Profiles\pdzzfday.default\cookies.sqlite:doubleclick.net
  C:\Users\Lola\AppData\Roaming\Mozilla\Firefox\Profiles\pdzzfday.default\cookies.sqlite:serving-sys.com
  C:\Users\Lola\AppData\Roaming\Mozilla\Firefox\Profiles\pdzzfday.default\cookies.sqlite:track.adform.net


markusg 04.07.2013 14:48

Funde bitte löschen, neues OTL Log.

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
C:\Windows\system32\*.tsp
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
explorer.exe
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs
CREATERESTOREPOINT

  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Kopiere
    nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread

lolale 09.07.2013 16:26

Code:

OTL logfile created on: 09.07.2013 16:42:01 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Lola\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,96 Gb Total Physical Memory | 1,64 Gb Available Physical Memory | 55,25% Memory free
6,12 Gb Paging File | 4,81 Gb Available in Paging File | 78,67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 94,16 Gb Total Space | 37,46 Gb Free Space | 39,79% Space Free | Partition Type: NTFS
Drive D: | 129,94 Gb Total Space | 106,45 Gb Free Space | 81,92% Space Free | Partition Type: NTFS
 
Computer Name: LOLA-PC | User Name: Lola | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2013.07.09 16:37:29 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Lola\Desktop\OTL.exe
PRC - [2013.05.10 09:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013.04.04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2013.03.28 07:23:26 | 000,310,640 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\Samsung\Kies\KiesTrayAgent.exe
PRC - [2013.03.28 07:23:22 | 001,511,792 | ---- | M] (Samsung) -- C:\Programme\Samsung\Kies\Kies.exe
PRC - [2013.02.19 11:53:08 | 000,162,856 | ---- | M] (Geek Software GmbH) -- C:\Programme\PDF24\pdf24.exe
PRC - [2013.01.27 12:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\NisSrv.exe
PRC - [2013.01.27 12:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\MsMpEng.exe
PRC - [2013.01.27 12:11:06 | 000,947,152 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\msseces.exe
PRC - [2009.04.11 08:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008.06.18 13:19:44 | 000,376,832 | ---- | M] (ODM) -- C:\Programme\OEM\OSD_1.16\osd.exe
PRC - [2008.05.13 11:12:54 | 006,139,904 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008.04.25 14:23:36 | 000,303,104 | ---- | M] (Fujitsu Siemens Computers) -- C:\Programme\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
PRC - [2008.02.26 03:23:34 | 000,443,968 | ---- | M] (Google Inc.) -- C:\Programme\Picasa2\PicasaMediaDetector.exe
PRC - [2008.02.22 09:24:28 | 000,094,208 | ---- | M] (TODO: <公司名稱>) -- C:\Programme\OEM\OSD_1.16\OsdService.exe
PRC - [2008.01.21 04:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2008.01.21 04:25:33 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2013.05.29 07:58:45 | 017,494,016 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\5acae2666774d0baebd5bbb72adf2146\Kies.Theme.ni.dll
MOD - [2013.05.29 07:58:14 | 000,232,960 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\bd38349bbe199a814b24e9344b53c836\ASF_cSharpAPI.ni.dll
MOD - [2013.05.29 07:58:14 | 000,064,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.AllShare\bf08939db31707c5b1be0a1470df84cb\Kies.Common.AllShare.ni.dll
MOD - [2013.05.29 07:57:06 | 002,148,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common23b84511#\cdf83a8d86e87259eb24cc365f333726\Kies.Common.Multimedia.ni.dll
MOD - [2013.05.29 07:57:00 | 000,180,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Commonc65c5a95#\5deae74bff60f29b807fa4548d8d7a36\Kies.Common.DeviceServiceLib.Interface.ni.dll
MOD - [2013.05.29 07:56:35 | 000,275,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.Util\a74c29c7794336a08b84ddfb7242202d\Kies.Common.Util.ni.dll
MOD - [2013.05.29 07:56:34 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Locale\178d211fca77bb382c45b8b8f46cde60\Kies.Locale.ni.dll
MOD - [2013.05.29 07:56:32 | 001,800,192 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\2eec4587ddc790ab2adddf2025cf6fdc\Kies.UI.ni.dll
MOD - [2013.05.29 07:56:32 | 000,081,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\6e823687276fd4a3f2e9ee6e1fe497f5\Kies.MVVM.ni.dll
MOD - [2013.05.29 07:56:25 | 001,210,368 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Interface\398efe259beb033fe74ddeed7f2c194f\Kies.Interface.ni.dll
MOD - [2013.05.29 07:56:09 | 002,055,168 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies\a0de7e74b6303fbaed083f81a6f94666\Kies.ni.exe
MOD - [2013.05.29 06:28:00 | 018,524,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\97e6b67983d07a066b68b3ae8be2f53d\PresentationFramework.ni.dll
MOD - [2013.05.29 06:27:54 | 000,786,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\4cfa42c8b69a64e192f3255ec900457d\System.Runtime.Remoting.ni.dll
MOD - [2013.05.29 06:27:46 | 012,692,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\22ae167d586450ad3a9b9a9ee43ebc86\System.Windows.Forms.ni.dll
MOD - [2013.05.29 06:27:21 | 010,914,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\b52bc540630c3aa5de542c382af35c20\PresentationCore.ni.dll
MOD - [2013.05.29 06:26:57 | 003,905,024 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\cd235caf797fb017f140016be88f33b7\WindowsBase.ni.dll
MOD - [2013.05.29 06:26:50 | 001,630,720 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\72269ea7cc6281139e4d155e7c57dc67\System.Drawing.ni.dll
MOD - [2013.05.29 06:26:47 | 007,559,680 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\9ba07396ae369d010c5c3927a82ef426\System.Xml.ni.dll
MOD - [2013.05.29 06:26:41 | 006,995,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\b9f7adbc90a2bcbe8eb9e6e8d2bb975b\System.Core.ni.dll
MOD - [2013.05.29 06:26:30 | 000,958,464 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\28586400bcaf94c13a9fd0dff4a1e090\System.Configuration.ni.dll
MOD - [2013.05.29 06:26:28 | 001,870,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\cc4d9093563dadee370788bbc3ecf4fb\System.Xaml.ni.dll
MOD - [2013.05.29 06:26:22 | 000,220,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\ad2f6440da38a0dbae2df194782b35d1\System.ServiceProcess.ni.dll
MOD - [2013.05.29 06:26:21 | 009,925,120 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\e40da7a49f8c3f0108e7c835b342f382\System.ni.dll
MOD - [2013.05.29 06:26:02 | 016,501,248 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\51e2934144ba15628ba5a31be2dae7dc\mscorlib.ni.dll
 
 
========== Services (SafeList) ==========
 
SRV - [2013.06.23 13:53:23 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.05.10 09:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013.01.27 12:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013.01.27 12:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011.07.20 06:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008.04.25 14:23:36 | 000,303,104 | ---- | M] (Fujitsu Siemens Computers) [Auto | Running] -- C:\Programme\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler)
SRV - [2008.02.22 09:24:28 | 000,094,208 | ---- | M] (TODO: <公司名稱>) [Auto | Running] -- C:\Programme\OEM\OSD_1.16\OsdService.exe -- (OsdService)
SRV - [2008.01.21 04:25:33 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2006.10.26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\usbaapl.sys -- (USBAAPL)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Lola\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - [2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2013.02.22 09:17:04 | 000,181,784 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm)
DRV - [2013.02.22 09:17:04 | 000,083,864 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus)
DRV - [2013.01.20 16:59:04 | 000,100,328 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2009.07.14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB)
DRV - [2008.06.17 21:27:28 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\directport.sys -- (GpdDevDPort)
DRV - [2008.05.01 08:35:54 | 003,660,800 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32)
DRV - [2008.04.03 14:58:46 | 000,076,688 | ---- | M] (JMicron Technology Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\jraid.sys -- (JRAID)
DRV - [2008.03.31 12:02:34 | 000,008,192 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\kbfiltr.sys -- (GpdKbFilter)
DRV - [2007.12.28 19:21:54 | 000,104,448 | ---- | M] (Realtek Corporation                                            ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2007.12.19 19:45:00 | 000,170,000 | ---- | M] (AMD Technologies Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ahcix86s.sys -- (ahcix86s)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = D:\Dokumente\Uni Heidelberg\Sport semester 5\Handball
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = DB E2 A6 E4 1B DE CD 01  [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{2F19142E-D90C-4CF3-907B-7C1D5CB25FC3}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=0C90CEBA-511B-4D0C-804A-03E9943D905B&apn_sauid=CDFA2CCB-E630-4A48-B07F-70BF0D548FB2
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_de
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "https://www.google.de/"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}\\: C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2013.05.29 06:41:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.06.23 13:53:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
 
[2013.01.28 10:04:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lola\AppData\Roaming\mozilla\Extensions
[2013.06.19 11:50:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lola\AppData\Roaming\mozilla\Firefox\Profiles\pdzzfday.default\extensions
[2013.01.28 10:03:15 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.06.23 13:53:27 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\browser\extensions
[2013.06.23 13:53:27 | 000,000,000 | ---D | M] (Default) -- C:\Programme\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
O1 HOSTS File: ([2013.06.14 16:17:36 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [FSCRecovery] c:\Programme\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryReminder.exe (Fujitsu Siemens Computers GmbH)
O4 - HKLM..\Run: [FSCRecoveryCleanUp] c:\Programme\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryCleanUp.exe (Fujitsu Siemens Computers GmbH)
O4 - HKLM..\Run: [Google EULA Launcher] c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe ( )
O4 - HKLM..\Run: [KiesTrayAgent] C:\Programme\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OSD] C:\Programme\OEM\OSD_1.16\osd.exe (ODM)
O4 - HKLM..\Run: [PDFPrint] C:\Programme\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [KiesPreload] C:\Program Files\Samsung\Kies\Kies.exe (Samsung)
O4 - HKCU..\Run: [Picasa Media Detector] C:\Programme\Picasa2\PicasaMediaDetector.exe (Google Inc.)
O4 - HKCU..\Run: [Sidebar] C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Citavi Picker... - C:\ProgramData\Swiss Academic Software\Citavi Picker\Internet Explorer\ShowContextMenu.html ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Free YouTube Download - C:\Users\Lola\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm File not found
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Lola\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{12FF7DEB-E43A-4FBE-ACF0-C6851C095096}: DhcpNameServer = 82.212.62.62 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9451677E-6020-46DA-8709-048ADFE45790}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Lola\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Lola\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {9F612429-4A00-3D44-88CF-146DA2EE1F92} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.07.09 16:37:15 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Lola\Desktop\OTL.exe
[2013.07.01 22:07:46 | 000,000,000 | ---D | C] -- C:\Users\Lola\Desktop\Shred
[2013.06.23 13:53:29 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2013.06.21 07:50:35 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2013.06.21 07:49:21 | 009,171,472 | ---- | C] (SurfRight B.V.) -- C:\Users\Lola\Desktop\HitmanPro.exe
[2013.06.19 12:09:09 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2013.06.19 00:17:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013.06.19 00:17:40 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013.06.15 00:55:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.06.15 00:55:00 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.06.15 00:55:00 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.06.14 16:21:57 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.06.14 16:21:53 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.06.14 16:21:53 | 000,000,000 | ---D | C] -- C:\Users\Lola\AppData\Local\temp
[2013.06.14 15:59:55 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.06.14 15:59:55 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.06.14 15:59:55 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.06.14 15:59:47 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013.06.14 15:58:24 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.06.14 15:57:58 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.06.14 15:56:13 | 005,080,197 | R--- | C] (Swearware) -- C:\Users\Lola\Desktop\ComboFix.exe
[2013.06.14 14:16:40 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Lola\Desktop\tdsskiller.exe
[2013.06.14 00:08:37 | 000,000,000 | ---D | C] -- C:\_OTL
[5 C:\Users\Lola\Desktop\*.tmp files -> C:\Users\Lola\Desktop\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.07.09 16:37:29 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Lola\Desktop\OTL.exe
[2013.07.09 16:21:30 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.07.09 16:21:30 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.07.09 16:21:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.07.09 16:21:08 | 3179,958,272 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.04 21:15:18 | 000,689,668 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.07.04 21:15:18 | 000,634,484 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.07.04 21:15:18 | 000,151,188 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.07.04 21:15:18 | 000,120,050 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.06.21 07:50:05 | 009,171,472 | ---- | M] (SurfRight B.V.) -- C:\Users\Lola\Desktop\HitmanPro.exe
[2013.06.19 12:29:25 | 000,648,201 | ---- | M] () -- C:\Users\Lola\Desktop\adwcleaner.exe
[2013.06.14 16:17:36 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013.06.14 15:56:53 | 005,080,197 | R--- | M] (Swearware) -- C:\Users\Lola\Desktop\ComboFix.exe
[2013.06.14 14:16:52 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Lola\Desktop\tdsskiller.exe
[5 C:\Users\Lola\Desktop\*.tmp files -> C:\Users\Lola\Desktop\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.06.19 12:29:08 | 000,648,201 | ---- | C] () -- C:\Users\Lola\Desktop\adwcleaner.exe
[2013.06.19 12:10:50 | 000,002,425 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2013.06.14 15:59:55 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.06.14 15:59:55 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.06.14 15:59:55 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.06.14 15:59:55 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.06.14 15:59:55 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.06.12 14:45:44 | 3179,958,272 | -HS- | C] () -- C:\hiberfil.sys
[2011.12.10 05:02:26 | 000,000,031 | ---- | C] () -- C:\Windows\tkkg_3.ini
[2011.12.10 05:02:15 | 000,182,528 | ---- | C] () -- C:\Windows\PI.EXE
[2011.08.04 16:23:54 | 000,000,000 | ---- | C] () -- C:\Users\Lola\AppData\Local\{867C4C52-85B7-4F89-A209-95CC966CA83E}
[2011.05.30 06:36:24 | 000,000,000 | ---- | C] () -- C:\Users\Lola\AppData\Local\{4A377C42-9CC8-4EF1-825E-341BAB429BA3}
[2011.04.05 15:53:49 | 000,019,281 | ---- | C] () -- C:\Users\Lola\AppData\Roaming\UserTile.png
[2010.05.08 00:37:11 | 000,001,356 | ---- | C] () -- C:\Users\Lola\AppData\Local\d3d9caps.dat
[2008.11.05 14:59:10 | 000,221,696 | ---- | C] () -- C:\Users\Lola\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.11.05 13:38:10 | 000,000,090 | ---- | C] () -- C:\Users\Lola\AppData\Roaming\wklnhst.dat
[2008.09.15 22:12:09 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2013.04.09 12:09:04 | 000,000,000 | ---D | M] -- C:\Users\Lola\AppData\Roaming\Dropbox
[2012.12.07 21:12:57 | 000,000,000 | ---D | M] -- C:\Users\Lola\AppData\Roaming\DVDVideoSoft
[2012.04.25 18:34:28 | 000,000,000 | ---D | M] -- C:\Users\Lola\AppData\Roaming\EverAd
[2012.02.09 00:28:18 | 000,000,000 | ---D | M] -- C:\Users\Lola\AppData\Roaming\ICQ
[2011.10.21 17:55:50 | 000,000,000 | ---D | M] -- C:\Users\Lola\AppData\Roaming\Leadertech
[2012.02.22 19:45:08 | 000,000,000 | ---D | M] -- C:\Users\Lola\AppData\Roaming\redsn0w
[2013.04.09 12:12:07 | 000,000,000 | ---D | M] -- C:\Users\Lola\AppData\Roaming\Samsung
[2013.05.29 10:55:08 | 000,000,000 | ---D | M] -- C:\Users\Lola\AppData\Roaming\Swiss Academic Software
[2008.11.05 13:38:19 | 000,000,000 | ---D | M] -- C:\Users\Lola\AppData\Roaming\Template
[2012.11.19 16:26:45 | 000,000,000 | ---D | M] -- C:\Users\Lola\AppData\Roaming\TuneUp Software
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %SYSTEMDRIVE%\*. >
[2013.06.14 16:21:57 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN
[2009.12.07 18:33:13 | 000,000,000 | ---D | M] -- C:\Boot
[2008.09.15 18:02:10 | 000,000,000 | ---D | M] -- C:\BSI
[2013.06.14 16:21:55 | 000,000,000 | ---D | M] -- C:\ComboFix
[2013.06.19 12:31:06 | 000,000,000 | ---D | M] -- C:\Config.Msi
[2006.11.02 15:02:03 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2008.09.15 17:58:20 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2008.07.17 05:14:14 | 000,000,000 | R--D | M] -- C:\DRIVER
[2008.09.15 18:02:31 | 000,000,000 | ---D | M] -- C:\ebay
[2008.09.15 18:03:21 | 000,000,000 | ---D | M] -- C:\Google
[2011.02.05 04:02:35 | 000,000,000 | ---D | M] -- C:\Intel
[2008.07.17 05:14:14 | 000,000,000 | R--D | M] -- C:\MANUAL
[2008.07.17 05:20:18 | 000,000,000 | R--D | M] -- C:\MSOCache
[2008.07.17 05:20:04 | 000,000,000 | ---D | M] -- C:\Nero
[2008.09.15 18:04:53 | 000,000,000 | ---D | M] -- C:\NVC
[2008.09.15 18:04:58 | 000,000,000 | ---D | M] -- C:\Off2007HStTrial
[2008.01.21 04:32:31 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2013.01.11 00:30:02 | 000,000,000 | ---D | M] -- C:\Poker
[2013.06.23 13:53:29 | 000,000,000 | R--D | M] -- C:\Program Files
[2013.06.21 07:50:35 | 000,000,000 | ---D | M] -- C:\ProgramData
[2008.09.15 17:58:20 | 000,000,000 | -HSD | M] -- C:\Programme
[2013.06.14 16:21:55 | 000,000,000 | ---D | M] -- C:\Qoobox
[2013.07.09 16:47:03 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2010.06.12 17:19:21 | 000,000,000 | ---D | M] -- C:\temp
[2011.12.10 05:02:20 | 000,000,000 | ---D | M] -- C:\TIVOLA
[2008.07.17 06:46:25 | 000,000,000 | ---D | M] -- C:\TMP
[2008.09.15 18:06:45 | 000,000,000 | R--D | M] -- C:\Users
[2013.07.01 22:06:51 | 000,000,000 | ---D | M] -- C:\Windows
[2009.06.22 04:02:49 | 000,000,000 | ---D | M] -- C:\WINMELD2008
[2009.07.15 23:37:39 | 000,000,000 | ---D | M] -- C:\Works
[2013.06.14 00:08:37 | 000,000,000 | ---D | M] -- C:\_OTL
 
< %PROGRAMFILES%\*.exe >
 
< %LOCALAPPDATA%\*.exe >
 
< %systemroot%\*. /mp /s >
 
< C:\Windows\system32\*.tsp >
[2006.11.02 11:44:49 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp
[2006.11.02 11:44:49 | 000,038,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp
[2006.11.02 11:44:49 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp
[2006.11.02 11:44:49 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp
[2009.04.11 08:27:17 | 000,280,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp
[2006.11.02 15:01:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2006.11.02 15:01:49 | 000,032,560 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
< MD5 for: AGP440.SYS  >
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\erdnt\cache\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: AHCIX86S.SYS  >
[2007.12.19 19:45:00 | 000,170,000 | ---- | M] (AMD Technologies Inc.) MD5=0DEE2B628D4C6E23285BB91EFFDABFDE -- C:\Windows\System32\drivers\ahcix86s.sys
[2007.12.19 19:45:00 | 000,170,000 | ---- | M] (AMD Technologies Inc.) MD5=0DEE2B628D4C6E23285BB91EFFDABFDE -- C:\Windows\System32\DriverStore\FileRepository\ahcix86s.inf_71554ba4\ahcix86s.sys
 
< MD5 for: ATAPI.SYS  >
[2008.03.12 08:38:18 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys
[2008.03.12 08:38:18 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\erdnt\cache\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.03.12 08:24:20 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=96DC4E1A9F90CCD489950A8935425C59 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\erdnt\cache\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EXPLORER.EXE  >
[2008.10.29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008.10.29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008.10.30 05:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\erdnt\cache\explorer.exe
[2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008.10.28 04:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008.01.21 04:24:24 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
 
< MD5 for: IASTOR.SYS  >
[2007.09.30 00:03:12 | 000,308,248 | ---- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F -- C:\Windows\System32\drivers\iaStor.sys
[2007.09.30 00:03:12 | 000,308,248 | ---- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_7baf6192\iaStor.sys
[2007.09.30 00:03:12 | 000,308,248 | ---- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_41af7b1f\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\erdnt\cache\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.21 04:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 04:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\erdnt\cache\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\Windows\erdnt\cache\user32.dll
[2008.01.21 04:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\erdnt\cache\userinit.exe
[2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\erdnt\cache\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2013.04.04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.01.21 04:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 04:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.21 04:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2008.07.17 14:42:07 | 013,115,392 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008.07.17 14:41:58 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008.07.17 14:42:07 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2008.07.17 14:42:15 | 017,633,280 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2008.07.17 14:42:18 | 006,684,672 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\system32\*.dll /lockedfiles >
[2012.12.08 19:28:30 | 000,353,792 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\dxtmsft.dll
[2012.12.08 19:28:30 | 000,223,232 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\dxtrans.dll
 
< %USERPROFILE%\*.* >
[2013.07.09 17:18:29 | 003,670,016 | -HS- | M] () -- C:\Users\Lola\ntuser.dat
[2013.06.13 23:24:20 | 000,008,192 | -H-- | M] () -- C:\Users\Lola\ntuser.dat.LOG
[2013.07.09 17:18:29 | 000,262,144 | -H-- | M] () -- C:\Users\Lola\ntuser.dat.LOG1
[2008.09.15 18:06:45 | 000,000,000 | -H-- | M] () -- C:\Users\Lola\ntuser.dat.LOG2
[2009.10.18 13:24:48 | 000,065,536 | -HS- | M] () -- C:\Users\Lola\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2009.10.18 13:24:48 | 000,524,288 | -HS- | M] () -- C:\Users\Lola\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2008.09.15 18:20:07 | 000,524,288 | -HS- | M] () -- C:\Users\Lola\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2013.07.06 00:01:42 | 000,065,536 | -HS- | M] () -- C:\Users\Lola\NTUSER.DAT{f72e7fb5-be42-11de-8906-00030da067d8}.TM.blf
[2013.07.06 00:01:42 | 000,524,288 | -HS- | M] () -- C:\Users\Lola\NTUSER.DAT{f72e7fb5-be42-11de-8906-00030da067d8}.TMContainer00000000000000000001.regtrans-ms
[2009.10.21 15:35:22 | 000,524,288 | -HS- | M] () -- C:\Users\Lola\NTUSER.DAT{f72e7fb5-be42-11de-8906-00030da067d8}.TMContainer00000000000000000002.regtrans-ms
[2008.09.15 18:06:45 | 000,000,020 | -HS- | M] () -- C:\Users\Lola\ntuser.ini
 
< %USERPROFILE%\Local Settings\Temp\*.exe >
 
< %USERPROFILE%\Local Settings\Temp\*.dll >
 
< %USERPROFILE%\Application Data\*.exe >
 
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

< End of report >

Code:

OTL Extras logfile created on: 09.07.2013 16:42:01 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Lola\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,96 Gb Total Physical Memory | 1,64 Gb Available Physical Memory | 55,25% Memory free
6,12 Gb Paging File | 4,81 Gb Available in Paging File | 78,67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 94,16 Gb Total Space | 37,46 Gb Free Space | 39,79% Space Free | Partition Type: NTFS
Drive D: | 129,94 Gb Total Space | 106,45 Gb Free Space | 81,92% Space Free | Partition Type: NTFS
 
Computer Name: LOLA-PC | User Name: Lola | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
https [open] -- Reg Error: Value error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00B35F05-6B35-40E9-886E-64E987C8C200}" = lport=137 | protocol=17 | dir=in | app=system |
"{0E004C7F-3F6E-4211-A756-2EB16A856E4F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{11058473-2381-42C4-AC13-E686A5300A75}" = rport=138 | protocol=17 | dir=out | app=system |
"{1BDB07F4-29D8-4098-B2D5-1BD90189067C}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{1CD8C96F-6DC1-4A31-A52F-74135E837C71}" = rport=139 | protocol=6 | dir=out | app=system |
"{24E6FACD-808C-4CAA-9EA9-E64D717CE183}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{27826FDA-B96D-43DA-A842-2E91D3FDEBCF}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4D71C97E-0243-4DF7-B2BD-28AAC934AE29}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{518A4F2A-0874-4A74-B2EA-FD0D1C57DBCA}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{6F38F2A4-B48C-4105-A822-C2A119D1075E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{81F74208-DE8C-44CD-94ED-C754EABD00E2}" = rport=137 | protocol=17 | dir=out | app=system |
"{87ECF752-3057-4D90-8E85-C07457193029}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{991B0ED9-CFB8-4E22-9F41-E2B360DC8A02}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{DABA267C-A02E-432A-89E0-B8EE969CEFDA}" = lport=138 | protocol=17 | dir=in | app=system |
"{E2EE5894-B2B2-4801-A1D2-E88F845A6B96}" = lport=445 | protocol=6 | dir=in | app=system |
"{F51932C8-22F2-4B21-B05C-B7F113A10ABF}" = lport=139 | protocol=6 | dir=in | app=system |
"{F5DC49DD-9211-4610-8647-CB83773216B7}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{FB343AD5-D9F8-405D-A9B5-1376E8F06A42}" = rport=445 | protocol=6 | dir=out | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04E5D393-80B2-420F-A4EB-5FEDF6DC4EE3}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbtray.exe |
"{1398B037-399E-4538-A49C-FC3F01E6BC6F}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbstreamerclient.exe |
"{4EF058BD-38D3-4CEC-B2C6-F73F9008B87D}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{50633086-E8A9-4373-A88B-F208C0DBF460}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{6BB788B2-9571-4CCC-87D2-D2FEFFF4EA06}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{6EA2B23F-55AA-4BE8-A77E-4E8E4A689A39}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbtray.exe |
"{792A5E66-ED0C-4E98-9EF4-D8C6A0493006}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbir.exe |
"{7B90F1FC-8E45-4AE6-A447-AE23B3D31D76}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{7CE7907D-BB82-4DA6-BDD7-32583FB65A41}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{7E3254BF-37F1-4A58-ABA5-0DAFA0B72AC6}" = protocol=6 | dir=in | app=c:\program files\fujitsu siemens computers\fsclounge\fscwbaseupdaterservice\2\fscwbaseupdaterservice.exe |
"{80A00A2A-DF6C-401A-B99F-BB07D0A07DD1}" = protocol=17 | dir=in | app=c:\users\lola\appdata\roaming\dropbox\bin\dropbox.exe |
"{85CDED79-3344-4499-B6E5-E6F8D5B385BC}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orb.exe |
"{8BD12D2D-B675-4A55-84E6-6C0CB1FBE82D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8CF74D67-63E7-4146-99C6-D506908AA189}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A72CB973-23CF-4D78-8DFC-7524E85C2641}" = protocol=6 | dir=in | app=c:\users\lola\appdata\roaming\dropbox\bin\dropbox.exe |
"{A8A125F8-223A-47CA-91D9-F396A569B3C4}" = protocol=17 | dir=in | app=c:\program files\fujitsu siemens computers\fsclounge\fscwbaseupdaterservice\2\fscwbaseupdaterservice.exe |
"{B06244F8-C190-468A-8260-F26DA6C8E177}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbir.exe |
"{B3CA070B-E686-4070-98AF-4DCF6C69165F}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{B555E651-C5C1-4CEC-8FFE-24169EDF69E0}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C6B62C12-48DA-4360-98B5-4E2F5D8C90CD}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orb.exe |
"{E5222BBF-EC3F-401E-A3FD-8B949DB27753}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{E5F5F745-27D4-4B03-9FC0-E60E6B145875}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbstreamerclient.exe |
"{E969AD85-2C0A-44B6-8352-A88EFC73917E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"TCP Query User{69FDB36C-7D06-4488-8434-170FFDD27672}C:\program files\icq7.4\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.4\icq.exe |
"TCP Query User{7EE026CD-B053-4874-A7D0-82B0ED85B76E}C:\program files\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files\winamp\winamp.exe |
"TCP Query User{8F34D6EC-7473-4CEC-85EF-ABC6D48EC133}C:\program files\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files\winamp\winamp.exe |
"TCP Query User{99781D76-F6F3-4248-BD33-FF2F3EC30AE6}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{C10B7F70-01DF-4902-9913-B7563076BA2F}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{D9F88CAF-ABD3-4200-946F-4E1FE73E340C}C:\users\lola\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\lola\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{EC2633DC-47CF-4600-BD5A-E6B16CF5D2A9}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{455D66CB-AB69-4B49-8C0F-ECACDF2A4C4E}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{543A33AF-BEE5-4BC8-9FD4-8491B77DEB90}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{5578E39C-BB16-48D5-AFE3-D9BFEC162DAA}C:\users\lola\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\lola\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{698D1E41-F6B9-453E-8494-6420A0BA00E5}C:\program files\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files\winamp\winamp.exe |
"UDP Query User{B055C153-E709-4376-9E29-DF526795F52A}C:\program files\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files\winamp\winamp.exe |
"UDP Query User{DB9DC1B6-2582-4CC4-8430-AB050551451B}C:\program files\icq7.4\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.4\icq.exe |
"UDP Query User{F38350CA-43D3-4BC3-9B2D-0866716EB3FF}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack
"{26A24AE4-039D-4CA4-87B4-2F83217021FF}" = Java 7 Update 21
"{2F926AE7-9FB7-4B34-906F-9C29A6D146A7}" = SystemDiagnostics
"{390DD8BB-BB57-4942-A029-2D913E4E9D74}" = Microsoft Security Client
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50779A29-834E-4E36-BBEB-B7CABC67A825}" = Microsoft Security Client DE-DE Language Pack
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{73289228-1853-4623-982A-EB17FF0270CA}" = OSD_1.16
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 5.3.0
"{854C47D1-C2A0-4492-8655-C3F8D49C1031}" = Nero 8 Essentials
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{9A3BC157-B94F-4EFD-ABA9-1E56DEB00655}" = FSCLounge
"{9A4D182C-35C7-4791-8484-4304EBC9101A}" = Windows 7 Upgrade Advisor
"{9F612429-4A00-3D44-88CF-146DA2EE1F92}" = Microsoft .NET Framework 4.5
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.7) - Deutsch
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{AFC454ED-A26F-4816-826B-C35129D82E1F}" = Fujitsu Siemens Computers Recovery
"{CC0A85B2-734A-45B3-B678-05F6A6499AC7}" = Citavi 4
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"7-Zip" = 7-Zip 9.22beta
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"CCleaner" = CCleaner
"Free Studio_is1" = Free Studio version 5.1.7
"Free YouTube Download_is1" = Free YouTube Download version 3.1.41.1201
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.15.1228
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 21.0 (x86 de)" = Mozilla Firefox 21.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Picasa 3" = Picasa 3
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 0.9.9
"Winamp" = Winamp
"YTdetect" = Yahoo! Detect
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 18.09.2012 18:08:59 | Computer Name = Lola-PC | Source = NormanNPT | ID = 131073
Description =
 
Error - 18.09.2012 19:09:54 | Computer Name = Lola-PC | Source = NormanNPT | ID = 131073
Description =
 
Error - 19.09.2012 04:16:24 | Computer Name = Lola-PC | Source = NormanNPT | ID = 131073
Description =
 
Error - 19.09.2012 05:37:24 | Computer Name = Lola-PC | Source = NormanNPT | ID = 131073
Description =
 
Error - 19.09.2012 06:38:19 | Computer Name = Lola-PC | Source = NormanNPT | ID = 131073
Description =
 
Error - 19.09.2012 07:39:14 | Computer Name = Lola-PC | Source = NormanNPT | ID = 131073
Description =
 
Error - 19.09.2012 16:02:33 | Computer Name = Lola-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 19.09.2012 16:07:18 | Computer Name = Lola-PC | Source = NormanNPT | ID = 131073
Description =
 
Error - 19.09.2012 17:08:09 | Computer Name = Lola-PC | Source = NormanNPT | ID = 131073
Description =
 
Error - 19.09.2012 18:09:04 | Computer Name = Lola-PC | Source = NormanNPT | ID = 131073
Description =
 
[ OSession Events ]
Error - 14.06.2012 07:55:07 | Computer Name = Lola-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2863
 seconds with 1440 seconds of active time.  This session ended with a crash.
 
[ System Events ]
Error - 16.04.2009 01:43:52 | Computer Name = Lola-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 16.04.2009 01:45:02 | Computer Name = Lola-PC | Source = Service Control Manager | ID = 7009
Description =
 
Error - 16.04.2009 01:45:02 | Computer Name = Lola-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 16.04.2009 03:01:33 | Computer Name = Lola-PC | Source = HTTP | ID = 15016
Description =
 
Error - 16.04.2009 11:23:53 | Computer Name = Lola-PC | Source = HTTP | ID = 15016
Description =
 
Error - 16.04.2009 13:56:36 | Computer Name = Lola-PC | Source = HTTP | ID = 15016
Description =
 
Error - 16.04.2009 16:56:11 | Computer Name = Lola-PC | Source = HTTP | ID = 15016
Description =
 
Error - 18.04.2009 10:39:34 | Computer Name = Lola-PC | Source = bowser | ID = 8003
Description =
 
Error - 19.04.2009 07:49:04 | Computer Name = Lola-PC | Source = HTTP | ID = 15016
Description =
 
Error - 19.04.2009 07:49:33 | Computer Name = Lola-PC | Source = bowser | ID = 8003
Description =
 
 
< End of report >


markusg 09.07.2013 16:56

Hi,


otl fix

Fixen mit OTL

  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die Textbox.

Code:

:OTL
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\SearchScopes\{2F19142E-D90C-4CF3-907B-7C1D5CB25FC3}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=0C90CEBA-511B-4D0C-804A-03E9943D905B&apn_sauid=CDFA2CCB-E630-4A48-B07F-70BF0D548FB2
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O8 - Extra context menu item: Free YouTube Download - C:\Users\Lola\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm File not found
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Lola\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not
found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
File not found
:files
:Commands
[emptytemp]

  • Solltest du deinen Benutzernamen z. B. durch "*****" unkenntlich gemacht haben, so füge an entsprechender Stelle deinen richtigen Benutzernamen ein. Andernfalls wird der Fix nicht funktionieren.
  • Schließe bitte nun alle Programme.
  • Klicke nun bitte auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
  • Nach dem Neustart findest Du ein Textdokument auf deinem Desktop.
    ( Auch zu finden unter C:\_OTL\MovedFiles\<Uhrzeit_Datum>.txt)
    Kopiere nun den Inhalt hier in Deinen Thread


bitte teste, ob es im Firefox, internet explorer, und sonstigen
evtl. instalierte Browser, irgendwelche ungewollten toolbars, umleitungen oder sonstigen Probleme gibt.
Teste wie pc und programme allgemein laufen.

lolale 09.07.2013 22:54

Code:

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2F19142E-D90C-4CF3-907B-7C1D5CB25FC3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2F19142E-D90C-4CF3-907B-7C1D5CB25FC3}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Free YouTube Download\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Free YouTube to Mp3 Converter\ deleted successfully.
File C:\Users\Lola\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...\ deleted successfully.
File res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html not found.
========== FILES ==========
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Lola
->Temp folder emptied: 269082709 bytes
->Temporary Internet Files folder emptied: 22590820 bytes
->Java cache emptied: 16681595 bytes
->FireFox cache emptied: 352734026 bytes
->Apple Safari cache emptied: 3015680 bytes
->Flash cache emptied: 1325 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 213080 bytes
RecycleBin emptied: 24520470 bytes
 
Total Files Cleaned = 657,00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 07092013_234223

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


markusg 09.07.2013 22:57

Der Test um den ich bat, und der unter dem OTL script steht, fehlt

lolale 09.07.2013 23:48

wie soll ich den test machen? hab alles durchgeschaut und mir ist nichts aufgefallen...

markusg 09.07.2013 23:51

Ja, dass solltest du ja auch so machen.
Wenn alles läuft, öffne bitte OTL, klicke bereinigen, PC startet neu, Remover werden gelöscht.
Lösche übrig gebliebene Logs, Setups, von uns verwendete Programme.
PC absichern:
als antimalware programm würde ich emsisoft empfehlen.
diese haben für mich den besten schutz kostet aber etwas.
Computeractive Software Store - Emsisoft Anti-Malware 8 [1-PC] - 63% off RRP
testversion:
Meine Antivirus-Empfehlung: Emsisoft Anti-Malware
insbesondere wenn du onlinebanking, einkäufe, sonstige zahlungsabwicklungen oder ähnlich wichtiges, wie zb berufliches machst, also sensible daten zu schützen sind, solltest du in sicherheitssoftware investieren.
vor dem aktivieren der lizenz die 30 tage testzeitraum ausnutzen.

kostenlos, aber eben nicht ganz so gut währe avast zu empfehlen.
http://www.trojaner-board.de/110895-...antivirus.html

sag mir welches du nutzt, dann gebe ich konfigurationshinweise.
bitte dein bisheriges av deinstalieren
die folgende anleitung ist umfangreich, dass ist mir klar, sie sollte aber umgesetzt werden, da nur dann dein pc sicher ist. stelle so viele fragen wie nötig, ich arbeite gern alles mit dir durch!

http://www.trojaner-board.de/96344-a...-rechners.html
Starte bitte mit der Passage, Windows Vista und Windows 7
Bitte beginne damit, Windows Updates zu instalieren.
Am besten geht dies, wenn du über Start, Suchen gehst, und dort Windows Updates eingibst.
Prüfe unter "Einstellungen ändern" dass folgendes ausgewählt ist:
- Updates automatisch Instalieren,
- Täglich
- Uhrzeit wählen
- Bitte den gesammten rest anhaken, außer:
- detailierte benachichtungen anzeigen, wenn neue Microsoft software verfügbar ist.
Klicke jetzt die Schaltfläche "OK"
Klicke jetzt "nach Updates suchen".
Bitte instaliere zunächst wichtige Updates.
Es wird nötig sein, den PC zwischendurch neu zu starten. falls dies der Fall ist, musst du erneut über Start, Suchen, Windows Update aufrufen, auf Updates suchen klicken und die nächsten instalieren.
Mache das selbe bitte mit den optionalen Updates.
Bitte übernimm den rest so, wie es im Abschnitt windows 7 / Vista zu lesen ist.
aus dem Abschnitt xp, bitte den punkt "datenausführungsverhinderung, dep" übernehmen.
als browser rate ich dir zu chrome:
http://support.google.com/chrome/bin...&answer=118663
anleitung lesen bitte
falls du nen andern nutzen willst, sags mir dann muss ich teile der nun folgenden anleitung anpassen.


Sandboxie
Die devinition einer Sandbox ist hier nachzulesen:
Sandbox
Kurz gesagt, man kann Programme fast 100 %ig isuliert vom System ausführen.

Der Vorteil liegt klar auf der Hand, wenn über den Browser Schadcode eingeschläust wird, kann dieser nicht nach außen dringen.
Download Link:
Sandboxie - Download - Filepony

anleitung:
http://www.trojaner-board.de/71542-a...sandboxie.html
ausführliche anleitung als pdf, auch abarbeiten:
Sandbox Einstellungen |

bitte folgende zusatz konfiguration machen:
sandboxie control öffnen, menü sandbox anklicken, defauldbox wählen.
dort klicke auf sandbox einstellungen.
beschrenkungen, bei programm start und internet zugriff schreibe:
chrome.exe
dann gehe auf anwendungen, webbrowser, chrome.
dort aktiviere alles außer gesammten profil ordner freigeben.
Wie du evtl. schon gesehen hast, kannst du einige Funktionen nicht nutzen.
Dies ist nur in der Vollversion nötig, zu deren Kauf ich dir rate.
Du kannst zb unter "Erzwungene Programmstarts" festlegen, dass alle Browser in der Sandbox starten.
Ansonsten musst du immer auf "Sandboxed webbrowser" klicken bzw Rechtsklick, in Sandboxie starten.
Eine lebenslange Lizenz kostet 30 €, und ist auf allen deinen PC's nutzbar.

Weiter mit:
Maßnahmen für ALLE Windows-Versionen
alles komplett durcharbeiten
anmerkung zu file hippo.
in den settings zusätzlich auswählen:
hide beta updates.
Run updateChecker when Windows starts

Backup Programm:
in meiner Anleitung ist bereits ein Backup Programm verlinkt, als Alternative bietet sich auch das Windows eigene Backup Programm an:
http://www.trojaner-board.de/82962-w...en-backup.html
Dies ist aber leider nur für Windows 7 Nutzer vernünftig nutzbar.
Alle Anderen sollten sich aber auf jeden fall auch ein Backup Programm instalieren, denn dies kann unter Umständen sehr wichtig sein, zum Beispiel, wenn die Festplatte einmal kaputt ist.

Zum Schluss, die allgemeinen sicherheitstipps beachten, wenn es dich betrifft, den Tipp zum Onlinebanking beachten und alle Passwörter ändern
bitte auch lesen, wie mache ich programme für alle sichtbar:
Programme für alle Konten nutzbar machen - PCtipp.ch - Praxis & Hilfe
surfe jetzt also nur noch im standard nutzer konto und dort in der sandbox.
wenn du die kostenlose version nutzt, dann mit klick auf sandboxed web browser, wenn du die bezahlversion hast, kannst du erzwungene programm starts festlegen, dann wird sandboxie immer gestartet wenn du nen browser aufrufst.
wenn du mit der maus über den browser fährst sollte der eingerahmt sein, dann bist du im sandboxed web browser

passwort sicherheit:
jeder dienst benötigt ein eigenes, mindestens 12-stelliges passwort
bei der passwort verwaltung und erstellung hilft roboform
Passwort Manager, Formular Ausfueller, Passwort Management | RoboForm Passwort Manager
anleitung:
RoboForm-Bedienungsanleitung: Passwort-Manager, Verwalten von Passwörtern und persönlichen Daten


Alle Zeitangaben in WEZ +1. Es ist jetzt 14:13 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19