Trojaner Sparkasse 40 Tans    Schönen guten Tag, 
hab das selbe Problem wie einige andere Leute hier. Beim Besuch der Sparkassen Seite wurde ich zur eingabe von 40 Tans aufgefordert. Hab nun schon einiges Versucht um den Schädling loszuwerden bin mir jedoch nicht sicher ob ich erfolgreich war. 
Anbei der Log von OTL. 
Sind noch weitere Logs von nöten um absolute Sicherheit zu haben? 
schon jetzt vielen Dank!  
OTL Logfile:   Code:  
 OTL Extras logfile created on: 11.08.2010 14:50:00 - Run 2 
OTL by OldTimer - Version 3.2.9.1     Folder = C:\Users\****\Downloads 
64bit- An unknown product  (Version = 6.1.7600) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.7600.16385) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 65,00% Memory free 
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 76,00% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) 
Drive C: | 244,04 Gb Total Space | 209,32 Gb Free Space | 85,77% Space Free | Partition Type: NTFS 
Drive D: | 7,10 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF 
Drive E: | 352,03 Gb Total Space | 322,43 Gb Free Space | 91,59% Space Free | Partition Type: NTFS 
Drive F: | 931,51 Gb Total Space | 856,19 Gb Free Space | 91,91% Space Free | Partition Type: NTFS 
G: Drive not present or media not loaded 
H: Drive not present or media not loaded 
I: Drive not present or media not loaded 
  
Computer Name: **** 
Current User Name: **** 
Logged in as Administrator. 
  
Current Boot Mode: Normal 
Scan Mode: All users 
Include 64bit Scans 
Company Name Whitelist: Off 
Skip Microsoft Files: Off 
File Age = 30 Days 
Output = Minimal 
   ========== Extra Registry (SafeList) ========== 
  
   ========== File Associations ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) 
  
[HKEY_USERS\S-1-5-21-617034234-4035192787-2737487772-1001\SOFTWARE\Classes\<extension>] 
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
  
[HKEY_USERS\S-1-5-21-617034234-4035192787-2737487772-1003\SOFTWARE\Classes\<extension>] 
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
   ========== Shell Spawning ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* File not found 
cmdfile [open] -- "%1" %* File not found 
comfile [open] -- "%1" %* File not found 
exefile [open] -- "%1" %* File not found 
helpfile [open] -- Reg Error: Key error. 
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation) 
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation) 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) 
piffile [open] -- "%1" %* File not found 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" File not found 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) 
scrfile [open] -- "%1" /S File not found 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) 
exefile [open] -- "%1" %* 
helpfile [open] -- Reg Error: Key error. 
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation) 
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation) 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
   ========== Security Center Settings ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
"cval" = 1 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data] 
"AntiVirusOverride" = 0 
"AntiSpywareOverride" = 0 
"FirewallOverride" = 0 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
   ========== Authorized Applications List ========== 
  
   ========== HKEY_LOCAL_MACHINE Uninstall List ========== 
  
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 
"{4CE36E6A-300B-427C-BEC7-B261CC13814E}" = iTunes 
"{591362D4-590B-457E-9BA3-F4D9508B88BA}" = MobileMe Control Panel 
"{5F94D3B9-2B02-9C37-740B-A59C7B8D17CC}" = ATI Catalyst Install Manager 
"{877924AA-E044-4266-B37D-E974CD799934}" = Bonjour 
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 
"{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007 
"{A792E67C-FDA4-A301-0C3C-53BA86EFBB5A}" = ccc-utility64 
"{CA4AF936-3312-4AF4-A191-527531490DCD}" = Apple Mobile Device Support 
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator 
"{138DAD46-BF86-4840-8FE4-6730F469A806}" = TAXMAN 2008 spezial 
"{1716D952-F601-4A07-8988-7FCFAEDE6FDC}" = TAXMAN Bibliothek 2008 
"{17A50383-2F75-4F6D-BAF9-8E22662E3797}" = TAXMAN 2009 spezial 
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform 
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17 
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime 
"{2FA2CDE4-ABE2-461D-A2FF-33EA4A3BBB49}" = TAXMAN 2010 spezial 
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2 
"{3D6A24EA-A543-6C84-351E-D7646E7AB86E}" = Catalyst Control Center InstallProxy 
"{47CAFF95-C3D8-ABF2-70BC-89DE00D8FB19}" = Catalyst Control Center Graphics Light 
"{4962EBAC-AE7C-1B22-1EA0-0916A7E40954}" = Catalyst Control Center Graphics Full Existing 
"{49A62E2B-B35C-941D-DF48-601207CF14C0}" = Catalyst Control Center Graphics Previews Common 
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support 
"{58BAA8D0-404E-4585-9FD3-ED1BB72AC2EE}" = Adobe Flash Player 9 ActiveX 
"{59624372-3B85-47f4-9B04-4911E551DF1E}" = Lexware Info Service 
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update 
"{6A490E11-6C8A-777C-4E00-43F3CC16A1EC}" = CCC Help English 
"{6A92FDF6-3E24-4D82-A1B4-51FBDD4A0493}" = TAXMAN 2008 spezial 
"{700C61BE-9424-4B20-9153-7A0C59722AF4}" = TAXMAN Bibliothek 2009 
"{72736F5F-520D-472A-88CC-7B02872FD34E}" = ATI Catalyst Registration 
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable 
"{77919701-C3E7-09AA-D2F7-DBF42CD7C13D}" = Catalyst Control Center HydraVision Full 
"{78B2F09F-BDC7-7865-CF4C-233B64A3BE51}" = Catalyst Control Center Graphics Full New 
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP 
"{87BB78C4-F36D-4D93-A7C7-F80F18219848}" = AMD DnD V1.0.19 
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial  
"{8D7133DE-27D2-47E5-B248-4180278D32AA}" = Catalyst Control Center - Branding 
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007 
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007 
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007 
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007 
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007 
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007 
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007 
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007 
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007 
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007 
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007 
"{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007 
"{90150407-6000-11D3-8CFE-0050048383C9}" = Microsoft Access 2002 
"{99AD9D6D-A456-49EE-8360-F22EE7AA1272}" = Express Gate 
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 
"{A67BB21E-D419-45BB-AB86-7D87D14BBCE2}" = Safari 
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper 
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.2 - Deutsch 
"{D055F157-931D-4413-9AB6-D436D9EFD8B1}" = Steuer Update 14.01 
"{D241BBEC-B1C7-7953-EDDE-D90A654A8D2C}" = ccc-core-static 
"{D5C24E77-099E-9B84-5BE2-708E70B938A9}" = Catalyst Control Center Core Implementation 
"{D5C8E140-6E6F-11DD-9AA9-0050560400B1}" = Haufe iDesk-Service 
"{DC4757E2-BAE3-0BFE-C6E5-576CB911FF52}" = Catalyst Control Center Graphics Previews Vista 
"{F48AAE0F-52F4-11DD-B1F7-0050560400B1}" = Haufe iDesk-Browser 
"{F4E16EDA-D4CA-48C3-94C8-4D5F0B4351C1}" = TAXMAN 2009 spezial 
"{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Earth 
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin 
"Adobe Photoshop Elements 2.0" = Adobe Photoshop Elements 2.0 
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus 
"ENTERPRISE" = Microsoft Office Enterprise 2007 
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Plattform-Geräte-Manager 
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware 
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6) 
   ========== Last 10 Event Log Errors ========== 
  
[ Application Events ] 
Error - 05.07.2010 14:18:02 | Computer Name = **** | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 01.08.2010 13:00:01 | Computer Name = **** | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 01.08.2010 13:05:59 | Computer Name = **** | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 03.08.2010 16:39:42 | Computer Name = **** | Source = EventSystem | ID = 4622 
Description =  
  
Error - 08.08.2010 07:32:46 | Computer Name = **** | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 09.08.2010 06:40:20 | Computer Name = **** | Source = Windows Backup | ID = 4103 
Description =  
  
Error - 09.08.2010 06:42:27 | Computer Name = **** | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 09.08.2010 06:42:27 | Computer Name = **** | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 11.08.2010 08:03:27 | Computer Name = **** | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 11.08.2010 08:03:27 | Computer Name = **** | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
[ System Events ] 
Error - 11.08.2010 06:18:12 | Computer Name = **** | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. 
  
Error - 11.08.2010 06:18:13 | Computer Name = **** | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. 
  
Error - 11.08.2010 06:18:13 | Computer Name = **** | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. 
  
Error - 11.08.2010 06:18:14 | Computer Name = **** | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. 
  
Error - 11.08.2010 08:46:59 | Computer Name = **** | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. 
  
Error - 11.08.2010 08:47:00 | Computer Name = **** | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. 
  
Error - 11.08.2010 08:47:00 | Computer Name = **** | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. 
  
Error - 11.08.2010 08:47:01 | Computer Name = **** | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. 
  
Error - 11.08.2010 08:47:01 | Computer Name = **** | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. 
  
Error - 11.08.2010 08:47:02 | Computer Name = **** | Source = Disk | ID = 262155 
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. 
  
  
< End of report >   --- --- ---  
OTL Logfile:   Code:  
 OTL logfile created on: 11.08.2010 14:50:00 - Run 2 
OTL by OldTimer - Version 3.2.9.1     Folder = C:\Users\Kinder\Downloads 
64bit- An unknown product  (Version = 6.1.7600) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.7600.16385) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 65,00% Memory free 
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 76,00% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) 
Drive C: | 244,04 Gb Total Space | 209,32 Gb Free Space | 85,77% Space Free | Partition Type: NTFS 
Drive D: | 7,10 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF 
Drive E: | 352,03 Gb Total Space | 322,43 Gb Free Space | 91,59% Space Free | Partition Type: NTFS 
Drive F: | 931,51 Gb Total Space | 856,19 Gb Free Space | 91,91% Space Free | Partition Type: NTFS 
G: Drive not present or media not loaded 
H: Drive not present or media not loaded 
I: Drive not present or media not loaded 
  
Computer Name: ****-PC 
Current User Name: **** 
Logged in as Administrator. 
  
Current Boot Mode: Normal 
Scan Mode: All users 
Include 64bit Scans 
Company Name Whitelist: Off 
Skip Microsoft Files: Off 
File Age = 30 Days 
Output = Minimal 
   ========== Processes (SafeList) ========== 
  
PRC - C:\Users\Kinder\Downloads\OTL.exe (OldTimer Tools) 
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) 
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) 
PRC - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe () 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) 
PRC - C:\ASUS.SYS\config\DVMExportService.exe (DeviceVM) 
  
   ========== Modules (SafeList) ========== 
  
MOD - C:\Users\Kinder\Downloads\OTL.exe (OldTimer Tools) 
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation) 
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation) 
  
   ========== Win32 Services (SafeList) ========== 
  
SRV:64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com) 
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD) 
SRV:64bit: - (UmRdpService) -- C:\Windows\SysNative\umrdp.dll (Microsoft Corporation) 
SRV:64bit: - (StorSvc) -- C:\Windows\SysNative\StorSvc.dll (Microsoft Corporation) 
SRV:64bit: - (PeerDistSvc) -- C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation) 
SRV:64bit: - (CscService) -- C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation) 
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) 
SRV - (Apple Mobile Device) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) 
SRV - (NMSAccess) -- C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe () 
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) 
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) 
SRV - (DvmMDES) -- C:\ASUS.SYS\config\DVMExportService.exe (DeviceVM) 
  
   ========== Driver Services (SafeList) ========== 
  
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys () 
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.) 
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atipmdag.sys (ATI Technologies Inc.) 
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.) 
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.) 
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH) 
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) 
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) 
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) 
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) 
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) 
DRV:64bit: - (vmbus) -- C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation) 
DRV:64bit: - (storflt) -- C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation) 
DRV:64bit: - (storvsc) -- C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation) 
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) 
DRV:64bit: - (s3cap) -- C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation) 
DRV:64bit: - (VMBusHID) -- C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation) 
DRV:64bit: - (CSC) -- C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation) 
DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof () 
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation                                            ) 
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) 
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) 
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) 
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) 
DRV:64bit: - (VIAHdAudAddService) -- C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.) 
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.) 
DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ASACPI.sys () 
DRV - (SASDIFSV) -- C:\Programme\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com) 
DRV - (SASKUTIL) -- C:\Programme\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com) 
DRV - (StarOpen) -- C:\Windows\SysWow64\drivers\StarOpen.sys () 
  
   ========== Standard Registry (SafeList) ========== 
  
   ========== Internet Explorer ========== 
  
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm 
  
  
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
  
  
IE - HKU\S-1-5-21-617034234-4035192787-2737487772-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN, Messenger und Hotmail sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN 
IE - HKU\S-1-5-21-617034234-4035192787-2737487772-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de 
IE - HKU\S-1-5-21-617034234-4035192787-2737487772-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 17 A0 DA B1 61 C5 CA 01  [binary data] 
IE - HKU\S-1-5-21-617034234-4035192787-2737487772-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
IE - HKU\S-1-5-21-617034234-4035192787-2737487772-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local 
  
IE - HKU\S-1-5-21-617034234-4035192787-2737487772-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
   ========== FireFox ========== 
  
FF - prefs.js..browser.search.defaultenginename: "Yahoo" 
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=302398" 
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (de)" 
FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=302398&p=" 
  
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.08.03 21:47:15 | 000,000,000 | ---D | M] 
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.08.03 21:47:15 | 000,000,000 | ---D | M] 
  
[2010.03.17 01:50:48 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\mozilla\Extensions 
[2010.03.17 02:19:57 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\mozilla\Firefox\Profiles\pw1ogac7.default\extensions 
[2010.05.13 00:33:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions 
[2010.08.03 21:47:14 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml 
[2010.08.03 21:47:14 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml 
[2010.08.03 21:47:14 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml 
[2010.08.03 21:47:14 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml 
[2010.08.03 21:47:14 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml 
  
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts 
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.) 
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) 
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA) 
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) 
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) 
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) 
O4 - HKU\S-1-5-21-617034234-4035192787-2737487772-1001..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com) 
O4 - HKU\S-1-5-21-617034234-4035192787-2737487772-1003..\Run: [{04F77C0D-179A-0724-ECD7-DE0D85DC73ED}] C:\Users\Kinder\AppData\Roaming\Utcei\voca.exe File not found 
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found 
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation) 
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) 
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) 
O13 - gopher Prefix: missing 
O13 - gopher Prefix: missing 
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) 
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02) 
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) 
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.0.43.81 217.0.43.65 
O18:64bit: - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\haufereader - No CLSID value found 
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found 
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found 
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) 
O18 - Protocol\Handler\haufereader - No CLSID value found 
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation) 
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) 
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found 
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found 
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. 
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. 
O32 - HKLM CDRom: AutoRun - 1 
O33 - MountPoints2\{a6bdd33c-315a-11df-b4a2-e0cb4eb6edf9}\Shell - "" = AutoRun 
O33 - MountPoints2\{a6bdd33c-315a-11df-b4a2-e0cb4eb6edf9}\Shell\AutoRun\command - "" = G:\SETUP.EXE -- File not found 
O33 - MountPoints2\{a6bdd33c-315a-11df-b4a2-e0cb4eb6edf9}\Shell\configure\command - "" = G:\SETUP.EXE -- File not found 
O33 - MountPoints2\{a6bdd33c-315a-11df-b4a2-e0cb4eb6edf9}\Shell\install\command - "" = G:\SETUP.EXE -- File not found 
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found 
O35:64bit: - HKLM\..comfile [open] -- "%1" %* 
O35:64bit: - HKLM\..exefile [open] -- "%1" %* 
O35 - HKLM\..comfile [open] -- "%1" %* 
O35 - HKLM\..exefile [open] -- "%1" %* 
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* 
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* 
O37 - HKLM\...com [@ = comfile] -- "%1" %* 
O37 - HKLM\...exe [@ = exefile] -- "%1" %* 
  
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) 
  
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk - C:\PROGRA~2\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE - (Adobe Systems, Inc.) 
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk - C:\Programme (x86)\Microsoft Office\Office10\OSA.EXE - File not found 
MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) 
MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) 
MsConfig:64bit - StartUpReg: AppleSyncNotifier - hkey= - key= - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.) 
MsConfig:64bit - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) 
MsConfig:64bit - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) 
MsConfig:64bit - StartUpReg: LexwareInfoService - hkey= - key= - C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Lexware GmbH & Co. KG) 
MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.) 
MsConfig:64bit - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) 
MsConfig:64bit - State: "startup" - Reg Error: Key error. 
MsConfig:64bit - State: "services" - Reg Error: Key error. 
  
SafeBootMin:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com) 
SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) 
SafeBootMin:64bit: Base - Driver Group 
SafeBootMin:64bit: Boot Bus Extender - Driver Group 
SafeBootMin:64bit: Boot file system - Driver Group 
SafeBootMin:64bit: File system - Driver Group 
SafeBootMin:64bit: Filter - Driver Group 
SafeBootMin:64bit: HelpSvc - Service 
SafeBootMin:64bit: PCI Configuration - Driver Group 
SafeBootMin:64bit: PNP Filter - Driver Group 
SafeBootMin:64bit: Primary disk - Driver Group 
SafeBootMin:64bit: sacsvr - Service 
SafeBootMin:64bit: SCSI Class - Driver Group 
SafeBootMin:64bit: System Bus Extender - Driver Group 
SafeBootMin:64bit: vmms - Service 
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers 
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive 
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive 
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller 
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc 
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard 
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse 
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters 
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter 
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System 
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive 
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy 
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers 
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume 
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices 
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices 
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices 
SafeBootMin: Base - Driver Group 
SafeBootMin: Boot Bus Extender - Driver Group 
SafeBootMin: Boot file system - Driver Group 
SafeBootMin: File system - Driver Group 
SafeBootMin: Filter - Driver Group 
SafeBootMin: HelpSvc - Service 
SafeBootMin: PCI Configuration - Driver Group 
SafeBootMin: PNP Filter - Driver Group 
SafeBootMin: Primary disk - Driver Group 
SafeBootMin: sacsvr - Service 
SafeBootMin: SCSI Class - Driver Group 
SafeBootMin: System Bus Extender - Driver Group 
SafeBootMin: vmms - Service 
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers 
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive 
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive 
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller 
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc 
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard 
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse 
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters 
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter 
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System 
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive 
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy 
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers 
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume 
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices 
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices 
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices 
  
SafeBootNet:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com) 
SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) 
SafeBootNet:64bit: Base - Driver Group 
SafeBootNet:64bit: Boot Bus Extender - Driver Group 
SafeBootNet:64bit: Boot file system - Driver Group 
SafeBootNet:64bit: File system - Driver Group 
SafeBootNet:64bit: Filter - Driver Group 
SafeBootNet:64bit: HelpSvc - Service 
SafeBootNet:64bit: Messenger - Service 
SafeBootNet:64bit: NDIS Wrapper - Driver Group 
SafeBootNet:64bit: NetBIOSGroup - Driver Group 
SafeBootNet:64bit: NetDDEGroup - Driver Group 
SafeBootNet:64bit: Network - Driver Group 
SafeBootNet:64bit: NetworkProvider - Driver Group 
SafeBootNet:64bit: PCI Configuration - Driver Group 
SafeBootNet:64bit: PNP Filter - Driver Group 
SafeBootNet:64bit: PNP_TDI - Driver Group 
SafeBootNet:64bit: Primary disk - Driver Group 
SafeBootNet:64bit: rdsessmgr - Service 
SafeBootNet:64bit: sacsvr - Service 
SafeBootNet:64bit: SCSI Class - Driver Group 
SafeBootNet:64bit: Streams Drivers - Driver Group 
SafeBootNet:64bit: System Bus Extender - Driver Group 
SafeBootNet:64bit: TDI - Driver Group 
SafeBootNet:64bit: vmms - Service 
SafeBootNet:64bit: WudfUsbccidDriver - Driver 
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers 
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive 
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive 
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller 
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc 
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard 
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse 
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net 
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient 
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService 
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans 
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters 
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter 
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System 
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive 
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers 
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy 
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers 
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume 
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices 
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices 
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices 
SafeBootNet: Base - Driver Group 
SafeBootNet: Boot Bus Extender - Driver Group 
SafeBootNet: Boot file system - Driver Group 
SafeBootNet: File system - Driver Group 
SafeBootNet: Filter - Driver Group 
SafeBootNet: HelpSvc - Service 
SafeBootNet: Messenger - Service 
SafeBootNet: NDIS Wrapper - Driver Group 
SafeBootNet: NetBIOSGroup - Driver Group 
SafeBootNet: NetDDEGroup - Driver Group 
SafeBootNet: Network - Driver Group 
SafeBootNet: NetworkProvider - Driver Group 
SafeBootNet: PCI Configuration - Driver Group 
SafeBootNet: PNP Filter - Driver Group 
SafeBootNet: PNP_TDI - Driver Group 
SafeBootNet: Primary disk - Driver Group 
SafeBootNet: rdsessmgr - Service 
SafeBootNet: sacsvr - Service 
SafeBootNet: SCSI Class - Driver Group 
SafeBootNet: Streams Drivers - Driver Group 
SafeBootNet: System Bus Extender - Driver Group 
SafeBootNet: TDI - Driver Group 
SafeBootNet: vmms - Service 
SafeBootNet: WudfUsbccidDriver - Driver 
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers 
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive 
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive 
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller 
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc 
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard 
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse 
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net 
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient 
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService 
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans 
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters 
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter 
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System 
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive 
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers 
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy 
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers 
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume 
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices 
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices 
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices 
  
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll 
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack 
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE 
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx 
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help 
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools 
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements 
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player 
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access 
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll 
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings 
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install 
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding 
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts 
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help 
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface 
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework 
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP 
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig 
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) 
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework 
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll 
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack 
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE 
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx 
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help 
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools 
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements 
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player 
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access 
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner 
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework 
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll 
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings 
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install 
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding 
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts 
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player 
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help 
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface 
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP 
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig 
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP 
  
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) 
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) 
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.) 
  
CREATERESTOREPOINT 
Restore point Set: OTL Restore Point 
   ========== Files/Folders - Created Within 30 Days ========== 
  
[2010.08.11 14:01:32 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\SUPERAntiSpyware.com 
[2010.08.11 14:01:32 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com 
[2010.08.11 14:01:28 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE 
[2010.08.11 14:01:26 | 000,000,000 | ---D | C] -- C:\Programme\SUPERAntiSpyware 
[2010.08.11 13:57:46 | 000,000,000 | ---D | C] -- C:\Users\****\AppData\Roaming\Malwarebytes 
[2010.08.11 13:57:39 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 
[2010.08.11 13:57:38 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys 
[2010.08.11 13:57:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware 
[2010.08.11 13:57:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes 
[2010.08.11 13:49:30 | 005,507,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe 
[2010.08.11 13:49:29 | 003,955,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe 
[2010.08.11 13:49:29 | 003,899,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe 
[2010.08.11 13:49:13 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll 
[2010.08.11 13:49:13 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll 
[2010.08.11 13:49:13 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll 
[2010.08.11 13:49:13 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll 
[2010.08.11 13:49:13 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe 
[2010.08.11 13:49:13 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe 
[2010.08.11 13:48:55 | 000,082,944 | ---- | C] (Radius Inc.) -- C:\Windows\SysWow64\iccvid.dll 
[2010.08.11 13:48:04 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rtutils.dll 
[2010.08.11 13:48:03 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rtutils.dll 
[2010.08.01 19:02:18 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll 
   ========== Files - Modified Within 30 Days ========== 
  
[2010.08.11 14:50:55 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI 
[2010.08.11 14:50:55 | 000,643,628 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat 
[2010.08.11 14:50:55 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat 
[2010.08.11 14:50:55 | 000,126,188 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat 
[2010.08.11 14:50:55 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat 
[2010.08.11 14:50:46 | 001,572,864 | -HS- | M] () -- C:\Users\****\NTUSER.DAT 
[2010.08.11 14:50:10 | 000,000,406 | -H-- | M] () -- C:\dvmexp.idx 
[2010.08.11 14:47:15 | 000,014,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
[2010.08.11 14:47:15 | 000,014,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
[2010.08.11 14:43:56 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job 
[2010.08.11 14:40:00 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT 
[2010.08.11 14:39:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat 
[2010.08.11 14:39:53 | 3220,529,152 | -HS- | M] () -- C:\hiberfil.sys 
[2010.08.11 14:07:37 | 000,346,280 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT 
[2010.08.11 14:01:28 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 
[2010.08.11 14:01:01 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job 
[2010.08.11 13:57:42 | 000,001,009 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk 
[2010.08.11 11:45:43 | 000,002,491 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk 
[2010.08.08 18:15:47 | 003,117,022 | -H-- | M] () -- C:\Users\****\AppData\Local\IconCache.db 
[2010.07.29 08:30:34 | 000,082,944 | ---- | M] (Radius Inc.) -- C:\Windows\SysWow64\iccvid.dll 
   ========== Files Created - No Company Name ========== 
  
[2010.08.11 14:01:28 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 
[2010.08.11 13:57:42 | 000,001,009 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk 
[2010.03.20 12:39:15 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI 
[2010.03.19 18:02:02 | 000,024,576 | R--- | C] () -- C:\Windows\SysWow64\AsIO.dll 
[2010.03.19 18:02:02 | 000,014,392 | R--- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys 
[2010.03.19 17:46:12 | 000,007,168 | ---- | C] () -- C:\Windows\SysWow64\drivers\StarOpen.sys 
[2010.03.17 02:31:40 | 000,015,613 | ---- | C] () -- C:\Windows\Ascd_tmp.ini 
[2010.03.17 01:57:29 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini 
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll 
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll 
[2009.04.02 14:30:14 | 000,010,296 | ---- | C] () -- C:\Windows\SysWow64\drivers\ASUSHWIO.SYS 
[2008.11.07 19:08:20 | 000,362,029 | ---- | C] () -- C:\Windows\SysWow64\sqlite3.dll 
[2006.04.21 11:08:22 | 000,253,952 | ---- | C] () -- C:\Windows\SysWow64\HtmlHelp.dll 
[2001.10.10 09:57:58 | 000,073,786 | ---- | C] () -- C:\Windows\SysWow64\dntvmc23.dll 
[2001.10.10 09:57:58 | 000,061,497 | ---- | C] () -- C:\Windows\SysWow64\dntvm23.dll 
[2001.03.07 09:02:30 | 000,229,431 | ---- | C] () -- C:\Windows\SysWow64\dnt23.dll 
   ========== LOP Check ========== 
  
[2010.08.09 12:36:25 | 000,000,000 | ---D | M] -- C:\Users\Kinder\AppData\Roaming\Orhiyx 
[2010.08.01 19:07:43 | 000,000,000 | ---D | M] -- C:\Users\Kinder\AppData\Roaming\QIP 
[2010.08.11 14:05:40 | 000,000,000 | ---D | M] -- C:\Users\Kinder\AppData\Roaming\Utcei 
[2010.03.20 11:25:30 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Canneverbe Limited 
[2010.03.17 02:20:35 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\DAEMON Tools Lite 
[2010.03.17 17:41:19 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Lexware 
[2010.07.03 19:12:21 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT 
   ========== Purity Check ========== 
  
  
   ========== Custom Scans ========== 
  
   < %ALLUSERSPROFILE%\Application Data\*. > 
   < %ALLUSERSPROFILE%\Application Data\*.exe /s > 
   < %APPDATA%\*. > 
[2010.03.19 17:24:43 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Adobe 
[2010.05.13 00:35:47 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Apple Computer 
[2010.03.17 02:09:45 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\ATI 
[2010.03.20 11:25:30 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Canneverbe Limited 
[2010.03.17 02:20:35 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\DAEMON Tools Lite 
[2010.03.17 00:59:53 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Identities 
[2010.03.17 16:25:09 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\InstallShield 
[2010.03.17 17:41:19 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Lexware 
[2010.03.17 02:16:14 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Macromedia 
[2010.08.11 13:57:46 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Malwarebytes 
[2009.07.14 20:18:34 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Media Center Programs 
[2010.04.14 19:35:44 | 000,000,000 | --SD | M] -- C:\Users\****\AppData\Roaming\Microsoft 
[2010.03.17 01:50:48 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\Mozilla 
[2010.08.11 14:01:32 | 000,000,000 | ---D | M] -- C:\Users\****\AppData\Roaming\SUPERAntiSpyware.com 
   < %APPDATA%\*.exe /s > 
[2010.03.17 02:06:46 | 000,010,134 | R--- | M] () -- C:\Users\****\AppData\Roaming\Microsoft\Installer\{3D6A24EA-A543-6C84-351E-D7646E7AB86E}\ARPPRODUCTICON.exe 
[2010.03.17 16:32:17 | 000,086,016 | R--- | M] (InstallShield Software Corp.) -- C:\Users\****\AppData\Roaming\Microsoft\Installer\{F48AAE0F-52F4-11DD-B1F7-0050560400B1}\ARPPRODUCTICON.exe 
   < %SYSTEMDRIVE%\*.exe > 
  
   < MD5 for: AGP440.SYS  > 
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys 
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys 
   < MD5 for: ATAPI.SYS  > 
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys 
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys 
   < MD5 for: CNGAUDIT.DLL  > 
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll 
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll 
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll 
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll 
   < MD5 for: IASTORV.SYS  > 
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys 
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys 
   < MD5 for: NETLOGON.DLL  > 
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll 
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll 
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll 
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll 
   < MD5 for: NVSTOR.SYS  > 
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys 
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys 
   < MD5 for: SCECLI.DLL  > 
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll 
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll 
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll 
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll 
   < MD5 for: USER32.DLL  > 
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll 
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll 
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\SysWOW64\user32.dll 
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll 
   < MD5 for: USERINIT.EXE  > 
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe 
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe 
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe 
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe 
   < MD5 for: WINLOGON.EXE  > 
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe 
[2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe 
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe 
   < MD5 for: WS2IFSL.SYS  > 
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys 
   < %systemroot%\system32\drivers\*.sys /lockedfiles > 
   < %systemroot%\System32\config\*.sav > 
   < %systemroot%\*. /mp /s > 
   < %systemroot%\system32\*.dll /lockedfiles > 
< End of report >   --- --- ---     |