This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Firefox - "Recommended for you" [Solved]

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I'm not sure if this is even a Virus/Maleware whatever, but its rather annoying. When I'm surfing, from time to time, I get this Popup in the lower right corner of my browser with the title "Recommended for you" with some advertisment. I've been searching the web for some kind of solution, but I simply can't find anything (Best thing i found was a "fix" where you block the ad, but i don't consider this as an real solution). So I'm hoping someone of you would be so kind to help me remove that. Regards, blawa
Hi,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
Hello,

thank you for your help.

Here are the files as requested:

DDS.txt
.
DDS (Ver_2011-08-26.01) - NTFSAMD64 
Internet Explorer: 9.0.8112.16421  BrowserJavaVersion: 1.6.0_26
Run by [removed] at 19:46:47 on 2012-05-13
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.43.1031.18.6135.1111 [GMT 2:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Broadcom\BPowMon\BPowMon.exe
c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe
c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\AlienRespawn\sftservice.EXE
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Alienware\Command Center\AlienFusionService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\AlienRespawn\Components\DSUpdate\DSUpd.exe
C:\Program Files (x86)\AlienRespawn\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Alienware\Command Center\AlienFusionController.exe
C:\Program Files\Alienware\Command Center\DoorController.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
C:\Program Files\Alienware\Command Center\ThermalController.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
c:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\devenv.exe
c:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\devenv.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\blawa\Downloads\OTL.exe
C:\Windows\system32\svchost.exe -k imgsvc
c:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\vcpackages\VCPkgSrv.exe
C:\Program Files (x86)\Heroes of Newerth\hon.exe
c:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\vcpackages\VCPkgSrv.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = my.daemon-search.com
uDefault_Page_URL = hxxp://www.dell.at/alienware
uURLSearchHooks: uTorrentBar_DE Toolbar: {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll
mURLSearchHooks: uTorrentBar_DE Toolbar: {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll
BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: uTorrentBar_DE Toolbar: {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: Microsoft-Webtestaufzeichnung 10.0-Hilfsprogramm: {dda57003-0068-4ed2-9d32-4d1ec707d94d} - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
TB: uTorrentBar_DE Toolbar: {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll
TB: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll
TB: toolplugin: {dfefcdee-cf1a-4fc8-89af-189327213627} - C:\Users\blawa\AppData\Roaming\toolplugin\toolbar.dll
EB: Webtestaufzeichnung 10.0: {5802d092-1784-4908-8cdb-99b6842d353d} - mscoree.dll
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe -silent
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
uRun: [EAUpdater] C:\Users\blawa\AppData\Roaming\EA\ea_updater.exe
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r
mRun: [UpdReg] C:\Windows\UpdReg.EXE
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [] 
mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [Guard.Mail.ru.gui] "C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe" /gui
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
StartupFolder: C:\Users\blawa\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Bild an &Bluetooth-Gerät senden… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Seite an &Bluetooth-Gerät senden… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{90456561-14A2-458A-9C08-2EE9CD27CE06} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{90456561-14A2-458A-9C08-2EE9CD27CE06}\55053403034363439313 : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{ADC455F9-F27A-46AA-9B8E-26D4D7BEACF8} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{B8440B9F-2A81-4B68-8205-0E75E113D44F} : DhcpNameServer = 192.168.0.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{30F9B915-B755-4826-820B-08FBA6BD249D}
{326E768D-4182-46FD-9C16-1449A49795F4}
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
{c840e246-6b95-475e-9bd7-caa1c7eca9f2}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{DDA57003-0068-4ed2-9D32-4D1EC707D94D}
{32099AAC-C132-4136-9E9A-4E364A424E17}
{c840e246-6b95-475e-9bd7-caa1c7eca9f2}
{30F9B915-B755-4826-820B-08FBA6BD249D}
{DFEFCDEE-CF1A-4FC8-89AF-189327213627}
EB-X64: {5802D092-1784-4908-8CDB-99B6842D353D} - No File
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r
mRun-x64: [UpdReg] C:\Windows\UpdReg.EXE
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [(Standard)] 
mRun-x64: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun-x64: [Guard.Mail.ru.gui] "C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe" /gui
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
IE-X64: {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Hosts: 149.5.18.172 www.google-analytics.com.
Hosts: 149.5.18.172 ad-emea.doubleclick.net.
Hosts: 149.5.18.172 www.statcounter.com.
Hosts: 108.163.215.51 www.google-analytics.com.
Hosts: 108.163.215.51 ad-emea.doubleclick.net.
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\blawa\AppData\Roaming\Mozilla\Firefox\Profiles\n18ln615.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - google.at
FF - prefs.js: keyword.URL - hxxp://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
.
—- FIREFOX POLICIES —-
FF - user.js: browser.search.selectedEngine - Search the web
FF - user.js: browser.search.order.1 - Search the web
FF - user.js: browser.search.defaultenginename - Search the web
FF - user.js: keyword.URL - hxxp://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q=
FF - user.js: privacy.item.cookies - false
FF - user.js: privacy.sanitize.promptOnSanitize - false
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys –> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys –> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys –> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 AlienFusionService;Alienware Fusion Service;C:\Program Files\Alienware\Command Center\AlienFusionService.exe [2011-3-21 15296]
R2 BPowMon;Broadcom Power monitoring service;C:\Program Files\Broadcom\BPowMon\BPowMon.exe [2009-10-27 117608]
R2 Guard.Mail.ru;Guard.Mail.ru;C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe [2011-12-28 1564368]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-7-2 13336]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-4-18 654408]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\AlienRespawn\SftService.exe [2011-7-2 1688384]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-2-29 382272]
R3 AWOPFilterDriver;AWOPFilterDriver;\??\C:\Windows\system32\drivers\AWOPFilterDriver.sys –> C:\Windows\system32\drivers\AWOPFilterDriver.sys [?]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys –> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys –> C:\Windows\system32\DRIVERS\k57nd60a.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys –> C:\Windows\system32\drivers\mbam.sys [?]
R3 mio;Master IO Filter Driver;C:\Windows\system32\DRIVERS\mio.sys –> C:\Windows\system32\DRIVERS\mio.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys –> C:\Windows\system32\drivers\nvhda64v.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-2-25 2348352]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-5-9 257696]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-3-6 1436424]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-4 129976]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys –> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft-Netzwerkinspektion;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 VSPerfDrv100;Performance Tools Driver 10.0;C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-3-17 68440]
S3 WatAdminSvc;Windows-Aktivierungstechnologieservice;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 MSSQLServerADHelper100;SQL Server Hilfsdienst für Active Directory;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2009-7-21 61976]
S4 RsFx0103;RsFx0103 Driver;C:\Windows\system32\DRIVERS\RsFx0103.sys –> C:\Windows\system32\DRIVERS\RsFx0103.sys [?]
S4 SQLAgent$SQLEXPRESS;SQL Server-Agent (SQLEXPRESS);C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-3-30 427880]
.
=============== Created Last 30 ================
.
2012-05-13 16:55:18	——–	d—–w-	C:\Program Files (x86)\Lame For Audacity
2012-05-13 00:28:04	69000	—-a-w-	C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8D49CBB2-86A4-4020-9B10-4E663B3D0DC5}\offreg.dll
2012-05-13 00:27:28	8917360	—-a-w-	C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8D49CBB2-86A4-4020-9B10-4E663B3D0DC5}\mpengine.dll
2012-05-12 00:27:02	8917360	——w-	C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-09 17:40:13	8769696	—-a-w-	C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-05-09 17:11:24	419488	—-a-w-	C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-08 22:01:04	1544704	—-a-w-	C:\Windows\System32\DWrite.dll
2012-05-08 22:01:04	1077248	—-a-w-	C:\Windows\SysWow64\DWrite.dll
2012-05-08 22:01:02	5559664	—-a-w-	C:\Windows\System32\ntoskrnl.exe
2012-05-08 22:01:02	3146240	—-a-w-	C:\Windows\System32\win32k.sys
2012-05-08 22:01:01	3968368	—-a-w-	C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-08 22:01:01	3913072	—-a-w-	C:\Windows\SysWow64\ntoskrnl.exe
2012-05-08 22:00:45	75120	—-a-w-	C:\Windows\System32\drivers\partmgr.sys
2012-05-08 22:00:37	1918320	—-a-w-	C:\Windows\System32\drivers\tcpip.sys
2012-05-08 22:00:36	936960	—-a-w-	C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-05-08 22:00:36	1732096	—-a-w-	C:\Program Files\Windows Journal\NBDoc.DLL
2012-05-08 22:00:36	1402880	—-a-w-	C:\Program Files\Windows Journal\JNWDRV.dll
2012-05-08 22:00:36	1393664	—-a-w-	C:\Program Files\Windows Journal\JNTFiltr.dll
2012-05-08 22:00:36	1367552	—-a-w-	C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2012-05-07 07:28:52	——–	d—–w-	C:\ProgramData\Battle.net
2012-05-05 13:39:18	——–	d—–w-	C:\Users\blawa\AppData\Roaming\TortoiseSVN
2012-05-05 13:30:59	——–	d—–w-	C:\Users\blawa\AppData\Local\TSVNCache
2012-05-05 13:30:58	——–	d—–w-	C:\Users\blawa\AppData\Roaming\Subversion
2012-05-05 13:30:57	——–	d—–w-	C:\Users\blawa\AppData\Local\CrashRpt
2012-05-05 13:26:56	——–	d—–w-	C:\Program Files (x86)\Common Files\TortoiseOverlays
2012-05-05 13:26:55	——–	d—–w-	C:\Program Files\TortoiseSVN
2012-05-05 13:26:55	——–	d—–w-	C:\Program Files\Common Files\TortoiseOverlays
2012-05-05 12:51:43	——–	d—–w-	C:\Program Files (x86)\FMOD SoundSystem
2012-05-04 10:23:37	——–	d—–w-	C:\Program Files (x86)\Mozilla Maintenance Service
2012-05-04 10:23:34	157352	—-a-w-	C:\Program Files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
2012-05-04 10:23:34	129976	—-a-w-	C:\Program Files (x86)\Mozilla Firefox\maintenanceservice.exe
2012-05-03 13:43:24	——–	d—–w-	C:\Program Files\CCleaner
2012-04-17 12:02:01	——–	d—–w-	C:\Users\blawa\AppData\Local\Apple Computer
2012-04-17 11:38:30	——–	d—–w-	C:\Users\blawa\AppData\Local\Apple
2012-04-15 10:01:18	——–	d—–w-	C:\Program Files (x86)\Audacity
.
==================== Find3M  ====================
.
2012-05-09 17:40:31	70304	—-a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-04 13:56:40	24904	—-a-w-	C:\Windows\System32\drivers\mbam.sys
2012-03-20 18:44:12	98688	—-a-w-	C:\Windows\System32\drivers\NisDrvWFP.sys
2012-03-20 18:44:12	203888	—-a-w-	C:\Windows\System32\drivers\MpFilter.sys
2012-03-18 13:17:17	466456	—-a-w-	C:\Windows\System32\wrap_oal.dll
2012-03-18 13:17:17	444952	—-a-w-	C:\Windows\SysWow64\wrap_oal.dll
2012-03-18 13:17:17	122904	—-a-w-	C:\Windows\System32\OpenAL32.dll
2012-03-18 13:17:17	109080	—-a-w-	C:\Windows\SysWow64\OpenAL32.dll
2012-03-01 06:46:16	23408	—-a-w-	C:\Windows\System32\drivers\fs_rec.sys
2012-03-01 06:38:27	220672	—-a-w-	C:\Windows\System32\wintrust.dll
2012-03-01 06:33:50	81408	—-a-w-	C:\Windows\System32\imagehlp.dll
2012-03-01 06:28:47	5120	—-a-w-	C:\Windows\System32\wmi.dll
2012-03-01 05:37:41	172544	—-a-w-	C:\Windows\SysWow64\wintrust.dll
2012-03-01 05:33:23	159232	—-a-w-	C:\Windows\SysWow64\imagehlp.dll
2012-03-01 05:29:16	5120	—-a-w-	C:\Windows\SysWow64\wmi.dll
2012-02-29 21:00:22	3089728	—-a-w-	C:\Windows\System32\nvsvc64.dll
2012-02-29 21:00:09	6074176	—-a-w-	C:\Windows\System32\nvcpl.dll
2012-02-29 20:59:47	889664	—-a-w-	C:\Windows\System32\nvvsvc.exe
2012-02-29 20:59:47	63296	—-a-w-	C:\Windows\System32\nvshext.dll
2012-02-29 20:59:47	2561856	—-a-w-	C:\Windows\System32\nvsvcr.dll
2012-02-29 20:59:47	118080	—-a-w-	C:\Windows\System32\nvmctray.dll
2012-02-29 12:26:56	416064	—-a-w-	C:\Windows\SysWow64\nvStreaming.exe
2012-02-28 06:56:48	2311168	—-a-w-	C:\Windows\System32\jscript9.dll
2012-02-28 06:49:56	1390080	—-a-w-	C:\Windows\System32\wininet.dll
2012-02-28 06:48:57	1493504	—-a-w-	C:\Windows\System32\inetcpl.cpl
2012-02-28 06:42:55	2382848	—-a-w-	C:\Windows\System32\mshtml.tlb
2012-02-28 01:18:55	1799168	—-a-w-	C:\Windows\SysWow64\jscript9.dll
2012-02-28 01:11:21	1427456	—-a-w-	C:\Windows\SysWow64\inetcpl.cpl
2012-02-28 01:11:07	1127424	—-a-w-	C:\Windows\SysWow64\wininet.dll
2012-02-28 01:03:16	2382848	—-a-w-	C:\Windows\SysWow64\mshtml.tlb
2012-02-24 09:36:50	230952	—-a-w-	C:\Windows\System32\drivers\PCTSD64.sys
2012-02-22 16:23:25	249856	——w-	C:\Windows\Setup1.exe
2012-02-22 16:23:24	73216	—-a-w-	C:\Windows\ST6UNST.EXE
2012-02-21 11:10:15	21840	—-a-w-	C:\Windows\SysWow64\SIntfNT.dll
2012-02-21 11:10:15	17212	—-a-w-	C:\Windows\SysWow64\SIntf32.dll
2012-02-21 11:10:15	12067	—-a-w-	C:\Windows\SysWow64\SIntf16.dll
2012-02-21 11:01:01	2829	—-a-w-	C:\Windows\DIIUnin.pif
2012-02-21 11:01:01	102400	—-a-w-	C:\Windows\DIIUnin.exe
2012-02-17 06:38:26	1031680	—-a-w-	C:\Windows\System32\rdpcore.dll
2012-02-17 05:34:22	826880	—-a-w-	C:\Windows\SysWow64\rdpcore.dll
2012-02-17 04:58:24	210944	—-a-w-	C:\Windows\System32\drivers\rdpwd.sys
2012-02-17 04:57:32	23552	—-a-w-	C:\Windows\System32\drivers\tdtcp.sys
.
============= FINISH: 19:47:18,32 ===============

But I encountered a problem with aswMBR.exe - it crashes during run (i tried it multiple times, its always on a file related to MS Team Foundation Server).
Is there an alternate programm I could use?

Attachments:

Hey blawa,

Let's give TDSSKiller a shot.

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Hello,

that worked just fine, even thought he didn't detect anything.

Log:

20:37:48.0106 3924	TDSS rootkit removing tool 2.7.34.0 May  2 2012 09:59:18
20:37:48.0190 3924	============================================================
20:37:48.0190 3924	Current date / time: 2012/05/13 20:37:48.0190
20:37:48.0190 3924	SystemInfo:
20:37:48.0190 3924	
20:37:48.0190 3924	OS Version: 6.1.7601 ServicePack: 1.0
20:37:48.0190 3924	Product type: Workstation
20:37:48.0190 3924	ComputerName: BLAWA-PC
20:37:48.0190 3924	UserName: blawa
20:37:48.0190 3924	Windows directory: C:\Windows
20:37:48.0190 3924	System windows directory: C:\Windows
20:37:48.0190 3924	Running under WOW64
20:37:48.0190 3924	Processor architecture: Intel x64
20:37:48.0190 3924	Number of processors: 8
20:37:48.0190 3924	Page size: 0x1000
20:37:48.0190 3924	Boot type: Normal boot
20:37:48.0190 3924	============================================================
20:37:48.0528 3924	Drive \Device\Harddisk0\DR0 - Size: 0x15D51500000 (1397.27 Gb), SectorSize: 0x200, Cylinders: 0x2C882, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:37:48.0562 3924	============================================================
20:37:48.0562 3924	\Device\Harddisk0\DR0:
20:37:48.0562 3924	MBR partitions:
20:37:48.0562 3924	\Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x4B000, BlocksNum 0x1377000
20:37:48.0562 3924	\Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x13C2000, BlocksNum 0xAD6C8000
20:37:48.0562 3924	============================================================
20:37:48.0591 3924	C: <-> \Device\Harddisk0\DR0\Partition1
20:37:48.0591 3924	============================================================
20:37:48.0591 3924	Initialize success
20:37:48.0591 3924	============================================================
20:37:52.0600 9024	============================================================
20:37:52.0600 9024	Scan started
20:37:52.0600 9024	Mode: Manual; 
20:37:52.0600 9024	============================================================
20:37:52.0767 9024	1394ohci		(a87d604aea360176311474c87a63bb88) C:\Windows\system32\DRIVERS\1394ohci.sys
20:37:52.0769 9024	1394ohci - ok
20:37:52.0807 9024	ACPI			(d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
20:37:52.0808 9024	ACPI - ok
20:37:52.0842 9024	AcpiPmi		 (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
20:37:52.0842 9024	AcpiPmi - ok
20:37:52.0927 9024	AdobeARMservice (11a52cf7b265631deeb24c6149309eff) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
20:37:52.0928 9024	AdobeARMservice - ok
20:37:53.0085 9024	AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
20:37:53.0086 9024	AdobeFlashPlayerUpdateSvc - ok
20:37:53.0149 9024	adp94xx		 (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys
20:37:53.0151 9024	adp94xx - ok
20:37:53.0213 9024	adpahci		 (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys
20:37:53.0214 9024	adpahci - ok
20:37:53.0263 9024	adpu320		 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys
20:37:53.0263 9024	adpu320 - ok
20:37:53.0308 9024	AeLookupSvc	 (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
20:37:53.0308 9024	AeLookupSvc - ok
20:37:53.0372 9024	AFD			 (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
20:37:53.0374 9024	AFD - ok
20:37:53.0395 9024	agp440		  (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
20:37:53.0396 9024	agp440 - ok
20:37:53.0421 9024	ALG			 (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
20:37:53.0422 9024	ALG - ok
20:37:53.0486 9024	AlienFusionService (4f87355217be7e04cc698e27677bf3af) C:\Program Files\Alienware\Command Center\AlienFusionService.exe
20:37:53.0487 9024	AlienFusionService - ok
20:37:53.0515 9024	aliide		  (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
20:37:53.0515 9024	aliide - ok
20:37:53.0533 9024	amdide		  (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
20:37:53.0533 9024	amdide - ok
20:37:53.0566 9024	AmdK8		   (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys
20:37:53.0567 9024	AmdK8 - ok
20:37:53.0574 9024	AmdPPM		  (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys
20:37:53.0575 9024	AmdPPM - ok
20:37:53.0636 9024	amdsata		 (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
20:37:53.0637 9024	amdsata - ok
20:37:53.0684 9024	amdsbs		  (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys
20:37:53.0685 9024	amdsbs - ok
20:37:53.0703 9024	amdxata		 (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
20:37:53.0703 9024	amdxata - ok
20:37:53.0745 9024	AppID		   (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
20:37:53.0746 9024	AppID - ok
20:37:53.0754 9024	AppIDSvc		(0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
20:37:53.0754 9024	AppIDSvc - ok
20:37:53.0778 9024	Appinfo		 (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
20:37:53.0779 9024	Appinfo - ok
20:37:53.0797 9024	arc			 (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys
20:37:53.0797 9024	arc - ok
20:37:53.0822 9024	arcsas		  (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys
20:37:53.0822 9024	arcsas - ok
20:37:53.0915 9024	aspnet_state	(9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
20:37:53.0915 9024	aspnet_state - ok
20:37:53.0947 9024	AsyncMac		(769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
20:37:53.0947 9024	AsyncMac - ok
20:37:53.0996 9024	atapi		   (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
20:37:53.0997 9024	atapi - ok
20:37:54.0083 9024	athr			(e0fabc10635c670bd7d89fd214a405d7) C:\Windows\system32\DRIVERS\athrx.sys
20:37:54.0089 9024	athr - ok
20:37:54.0148 9024	AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
20:37:54.0151 9024	AudioEndpointBuilder - ok
20:37:54.0154 9024	AudioSrv		(f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
20:37:54.0157 9024	AudioSrv - ok
20:37:54.0208 9024	AWOPFilterDriver (7f95bab2fb176061b8b7f2dde003e7d3) C:\Windows\system32\drivers\AWOPFilterDriver.sys
20:37:54.0208 9024	AWOPFilterDriver - ok
20:37:54.0243 9024	AxInstSV		(a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
20:37:54.0243 9024	AxInstSV - ok
20:37:54.0292 9024	b06bdrv		 (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys
20:37:54.0293 9024	b06bdrv - ok
20:37:54.0343 9024	b57nd60a		(b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
20:37:54.0344 9024	b57nd60a - ok
20:37:54.0372 9024	BDESVC		  (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
20:37:54.0372 9024	BDESVC - ok
20:37:54.0387 9024	Beep			(16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
20:37:54.0387 9024	Beep - ok
20:37:54.0467 9024	BFE			 (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
20:37:54.0470 9024	BFE - ok
20:37:54.0529 9024	BITS			(1ea7969e3271cbc59e1730697dc74682) C:\Windows\System32\qmgr.dll
20:37:54.0533 9024	BITS - ok
20:37:54.0564 9024	blbdrive		(61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
20:37:54.0564 9024	blbdrive - ok
20:37:54.0591 9024	bowser		  (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
20:37:54.0592 9024	bowser - ok
20:37:54.0629 9024	BPowMon		 (cd6d4b6583f56f03f9c6971cff159314) C:\Program Files\Broadcom\BPowMon\BPowMon.exe
20:37:54.0630 9024	BPowMon - ok
20:37:54.0646 9024	BrFiltLo		(f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys
20:37:54.0646 9024	BrFiltLo - ok
20:37:54.0666 9024	BrFiltUp		(b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys
20:37:54.0666 9024	BrFiltUp - ok
20:37:54.0695 9024	Browser		 (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
20:37:54.0696 9024	Browser - ok
20:37:54.0759 9024	Brserid		 (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
20:37:54.0760 9024	Brserid - ok
20:37:54.0807 9024	BrSerWdm		(a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
20:37:54.0807 9024	BrSerWdm - ok
20:37:54.0827 9024	BrUsbMdm		(b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
20:37:54.0827 9024	BrUsbMdm - ok
20:37:54.0829 9024	BrUsbSer		(a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
20:37:54.0830 9024	BrUsbSer - ok
20:37:54.0881 9024	BthEnum		 (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\drivers\BthEnum.sys
20:37:54.0881 9024	BthEnum - ok
20:37:54.0909 9024	BTHMODEM		(9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys
20:37:54.0910 9024	BTHMODEM - ok
20:37:54.0936 9024	BthPan		  (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
20:37:54.0936 9024	BthPan - ok
20:37:54.0983 9024	BTHPORT		 (64c198198501f7560ee41d8d1efa7952) C:\Windows\system32\Drivers\BTHport.sys
20:37:54.0985 9024	BTHPORT - ok
20:37:55.0003 9024	bthserv		 (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
20:37:55.0004 9024	bthserv - ok
20:37:55.0036 9024	BTHUSB		  (f188b7394d81010767b6df3178519a37) C:\Windows\system32\Drivers\BTHUSB.sys
20:37:55.0036 9024	BTHUSB - ok
20:37:55.0064 9024	btwaudio		(6bcfdc2b5b7f66d484486d4bd4b39a6b) C:\Windows\system32\drivers\btwaudio.sys
20:37:55.0064 9024	btwaudio - ok
20:37:55.0098 9024	btwavdt		 (82dc8b7c626e526681c1bebed2bc3ff9) C:\Windows\system32\DRIVERS\btwavdt.sys
20:37:55.0098 9024	btwavdt - ok
20:37:55.0162 9024	btwdins		 (d65aa164acd0f6706dbcfbbcc9731584) c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
20:37:55.0165 9024	btwdins - ok
20:37:55.0176 9024	btwl2cap		(6149301dc3f81d6f9667a3fbac410975) C:\Windows\system32\DRIVERS\btwl2cap.sys
20:37:55.0176 9024	btwl2cap - ok
20:37:55.0196 9024	btwrchid		(28e105ad3b79f440bf94780f507bf66a) C:\Windows\system32\DRIVERS\btwrchid.sys
20:37:55.0196 9024	btwrchid - ok
20:37:55.0233 9024	cdfs			(b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
20:37:55.0233 9024	cdfs - ok
20:37:55.0274 9024	cdrom		   (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
20:37:55.0275 9024	cdrom - ok
20:37:55.0311 9024	CertPropSvc	 (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
20:37:55.0312 9024	CertPropSvc - ok
20:37:55.0329 9024	circlass		(d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys
20:37:55.0329 9024	circlass - ok
20:37:55.0364 9024	CLFS			(fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
20:37:55.0366 9024	CLFS - ok
20:37:55.0449 9024	clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:37:55.0449 9024	clr_optimization_v2.0.50727_32 - ok
20:37:55.0502 9024	clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
20:37:55.0503 9024	clr_optimization_v2.0.50727_64 - ok
20:37:55.0587 9024	clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:37:55.0590 9024	clr_optimization_v4.0.30319_32 - ok
20:37:55.0644 9024	clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
20:37:55.0645 9024	clr_optimization_v4.0.30319_64 - ok
20:37:55.0683 9024	CmBatt		  (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys
20:37:55.0684 9024	CmBatt - ok
20:37:55.0701 9024	cmdide		  (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
20:37:55.0701 9024	cmdide - ok
20:37:55.0755 9024	CNG			 (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
20:37:55.0757 9024	CNG - ok
20:37:55.0759 9024	Compbatt		(102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys
20:37:55.0760 9024	Compbatt - ok
20:37:55.0784 9024	CompositeBus	(03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys
20:37:55.0784 9024	CompositeBus - ok
20:37:55.0798 9024	COMSysApp - ok
20:37:55.0821 9024	crcdisk		 (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys
20:37:55.0822 9024	crcdisk - ok
20:37:55.0862 9024	CryptSvc		(15597883fbe9b056f276ada3ad87d9af) C:\Windows\system32\cryptsvc.dll
20:37:55.0863 9024	CryptSvc - ok
20:37:55.0922 9024	DcomLaunch	  (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
20:37:55.0925 9024	DcomLaunch - ok
20:37:55.0961 9024	defragsvc	   (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
20:37:55.0963 9024	defragsvc - ok
20:37:55.0994 9024	DfsC			(9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
20:37:55.0995 9024	DfsC - ok
20:37:56.0040 9024	Dhcp			(43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
20:37:56.0042 9024	Dhcp - ok
20:37:56.0075 9024	discache		(13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
20:37:56.0075 9024	discache - ok
20:37:56.0080 9024	Disk			(9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys
20:37:56.0080 9024	Disk - ok
20:37:56.0129 9024	Dnscache		(16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
20:37:56.0130 9024	Dnscache - ok
20:37:56.0182 9024	dot3svc		 (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
20:37:56.0184 9024	dot3svc - ok
20:37:56.0235 9024	DPS			 (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
20:37:56.0236 9024	DPS - ok
20:37:56.0278 9024	drmkaud		 (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
20:37:56.0278 9024	drmkaud - ok
20:37:56.0366 9024	dtsoftbus01	 (fb9bef3401ee5ecc2603311b9c64f44a) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
20:37:56.0367 9024	dtsoftbus01 - ok
20:37:56.0456 9024	DXGKrnl		 (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
20:37:56.0459 9024	DXGKrnl - ok
20:37:56.0495 9024	EapHost		 (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
20:37:56.0495 9024	EapHost - ok
20:37:56.0606 9024	ebdrv		   (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys
20:37:56.0619 9024	ebdrv - ok
20:37:56.0706 9024	EFS			 (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
20:37:56.0707 9024	EFS - ok
20:37:56.0789 9024	ehRecvr		 (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
20:37:56.0792 9024	ehRecvr - ok
20:37:56.0823 9024	ehSched		 (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
20:37:56.0825 9024	ehSched - ok
20:37:56.0889 9024	elxstor		 (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys
20:37:56.0891 9024	elxstor - ok
20:37:56.0917 9024	ErrDev		  (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
20:37:56.0917 9024	ErrDev - ok
20:37:56.0978 9024	EventSystem	 (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
20:37:56.0980 9024	EventSystem - ok
20:37:57.0019 9024	exfat		   (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
20:37:57.0020 9024	exfat - ok
20:37:57.0061 9024	fastfat		 (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
20:37:57.0062 9024	fastfat - ok
20:37:57.0101 9024	Fax			 (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
20:37:57.0104 9024	Fax - ok
20:37:57.0126 9024	fdc			 (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys
20:37:57.0126 9024	fdc - ok
20:37:57.0143 9024	fdPHost		 (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
20:37:57.0143 9024	fdPHost - ok
20:37:57.0163 9024	FDResPub		(802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
20:37:57.0164 9024	FDResPub - ok
20:37:57.0194 9024	FileInfo		(655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
20:37:57.0194 9024	FileInfo - ok
20:37:57.0215 9024	Filetrace	   (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
20:37:57.0215 9024	Filetrace - ok
20:37:57.0304 9024	FLEXnet Licensing Service (8669be94f63944e4f899c3950b520241) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
20:37:57.0308 9024	FLEXnet Licensing Service - ok
20:37:57.0414 9024	FLEXnet Licensing Service 64 (a4297244d4f817278a6ae45b1899ca9c) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
20:37:57.0420 9024	FLEXnet Licensing Service 64 - ok
20:37:57.0476 9024	flpydisk		(c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys
20:37:57.0476 9024	flpydisk - ok
20:37:57.0510 9024	FltMgr		  (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
20:37:57.0512 9024	FltMgr - ok
20:37:57.0572 9024	FontCache	   (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
20:37:57.0577 9024	FontCache - ok
20:37:57.0635 9024	FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
20:37:57.0636 9024	FontCache3.0.0.0 - ok
20:37:57.0662 9024	FsDepends	   (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
20:37:57.0662 9024	FsDepends - ok
20:37:57.0699 9024	Fs_Rec		  (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
20:37:57.0700 9024	Fs_Rec - ok
20:37:57.0729 9024	fvevol		  (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
20:37:57.0730 9024	fvevol - ok
20:37:57.0749 9024	gagp30kx		(8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys
20:37:57.0750 9024	gagp30kx - ok
20:37:57.0806 9024	gpsvc		   (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
20:37:57.0809 9024	gpsvc - ok
20:37:57.0884 9024	Guard.Mail.ru   (e859ca020ed61899f3c74a8d0032d05c) C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe
20:37:57.0890 9024	Guard.Mail.ru - ok
20:37:57.0897 9024	hcw85cir		(f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
20:37:57.0898 9024	hcw85cir - ok
20:37:57.0932 9024	HDAudBus		(97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys
20:37:57.0933 9024	HDAudBus - ok
20:37:57.0953 9024	HidBatt		 (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys
20:37:57.0953 9024	HidBatt - ok
20:37:57.0976 9024	HidBth		  (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys
20:37:57.0976 9024	HidBth - ok
20:37:58.0008 9024	HidIr		   (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys
20:37:58.0009 9024	HidIr - ok
20:37:58.0026 9024	hidserv		 (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
20:37:58.0027 9024	hidserv - ok
20:37:58.0041 9024	HidUsb		  (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
20:37:58.0041 9024	HidUsb - ok
20:37:58.0064 9024	hkmsvc		  (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
20:37:58.0065 9024	hkmsvc - ok
20:37:58.0106 9024	HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
20:37:58.0108 9024	HomeGroupListener - ok
20:37:58.0176 9024	HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
20:37:58.0177 9024	HomeGroupProvider - ok
20:37:58.0249 9024	HpSAMD		  (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
20:37:58.0250 9024	HpSAMD - ok
20:37:58.0294 9024	HTTP			(0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
20:37:58.0297 9024	HTTP - ok
20:37:58.0316 9024	hwpolicy		(a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
20:37:58.0316 9024	hwpolicy - ok
20:37:58.0365 9024	i8042prt		(fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
20:37:58.0366 9024	i8042prt - ok
20:37:58.0427 9024	iaStor		  (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\drivers\iaStor.sys
20:37:58.0429 9024	iaStor - ok
20:37:58.0461 9024	IAStorDataMgrSvc (31a0e93cdf29007d6c6fffb632f375ed) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
20:37:58.0461 9024	IAStorDataMgrSvc - ok
20:37:58.0536 9024	iaStorV		 (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
20:37:58.0538 9024	iaStorV - ok
20:37:58.0611 9024	idsvc		   (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
20:37:58.0621 9024	idsvc - ok
20:37:58.0637 9024	iirsp		   (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys
20:37:58.0638 9024	iirsp - ok
20:37:58.0687 9024	IKEEXT		  (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
20:37:58.0691 9024	IKEEXT - ok
20:37:58.0796 9024	IntcAzAudAddService (697c927e0de2abaf1a5f455033f687cd) C:\Windows\system32\drivers\RTKVHD64.sys
20:37:58.0805 9024	IntcAzAudAddService - ok
20:37:58.0822 9024	intelide		(f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
20:37:58.0822 9024	intelide - ok
20:37:58.0856 9024	intelppm		(ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
20:37:58.0857 9024	intelppm - ok
20:37:58.0892 9024	IPBusEnum	   (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
20:37:58.0892 9024	IPBusEnum - ok
20:37:58.0938 9024	IpFilterDriver  (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:37:58.0938 9024	IpFilterDriver - ok
20:37:58.0970 9024	IPMIDRV		 (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
20:37:58.0971 9024	IPMIDRV - ok
20:37:58.0986 9024	IPNAT		   (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
20:37:58.0987 9024	IPNAT - ok
20:37:58.0990 9024	IRENUM		  (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
20:37:58.0990 9024	IRENUM - ok
20:37:59.0007 9024	isapnp		  (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
20:37:59.0007 9024	isapnp - ok
20:37:59.0059 9024	iScsiPrt		(d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
20:37:59.0060 9024	iScsiPrt - ok
20:37:59.0091 9024	JRAID		   (c0d9ba660a41ee8a269ef804e6cd0d7b) C:\Windows\system32\drivers\jraid.sys
20:37:59.0091 9024	JRAID - ok
20:37:59.0138 9024	k57nd60a		(9d7ea8c7215d8d4ae7be110eee61085d) C:\Windows\system32\DRIVERS\k57nd60a.sys
20:37:59.0140 9024	k57nd60a - ok
20:37:59.0165 9024	kbdclass		(bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
20:37:59.0165 9024	kbdclass - ok
20:37:59.0169 9024	kbdhid		  (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
20:37:59.0170 9024	kbdhid - ok
20:37:59.0195 9024	KeyIso		  (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:37:59.0196 9024	KeyIso - ok
20:37:59.0247 9024	KSecDD		  (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
20:37:59.0248 9024	KSecDD - ok
20:37:59.0299 9024	KSecPkg		 (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
20:37:59.0300 9024	KSecPkg - ok
20:37:59.0317 9024	ksthunk		 (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
20:37:59.0317 9024	ksthunk - ok
20:37:59.0376 9024	KtmRm		   (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
20:37:59.0378 9024	KtmRm - ok
20:37:59.0407 9024	LanmanServer	(d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll
20:37:59.0409 9024	LanmanServer - ok
20:37:59.0437 9024	LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
20:37:59.0438 9024	LanmanWorkstation - ok
20:37:59.0469 9024	lltdio		  (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
20:37:59.0469 9024	lltdio - ok
20:37:59.0505 9024	lltdsvc		 (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
20:37:59.0507 9024	lltdsvc - ok
20:37:59.0524 9024	lmhosts		 (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
20:37:59.0525 9024	lmhosts - ok
20:37:59.0568 9024	LSI_FC		  (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys
20:37:59.0568 9024	LSI_FC - ok
20:37:59.0613 9024	LSI_SAS		 (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys
20:37:59.0613 9024	LSI_SAS - ok
20:37:59.0634 9024	LSI_SAS2		(30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys
20:37:59.0635 9024	LSI_SAS2 - ok
20:37:59.0675 9024	LSI_SCSI		(0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys
20:37:59.0676 9024	LSI_SCSI - ok
20:37:59.0722 9024	luafv		   (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
20:37:59.0723 9024	luafv - ok
20:37:59.0770 9024	MBAMProtector   (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys
20:37:59.0770 9024	MBAMProtector - ok
20:37:59.0862 9024	MBAMService	 (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
20:37:59.0865 9024	MBAMService - ok
20:37:59.0890 9024	Mcx2Svc		 (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
20:37:59.0890 9024	Mcx2Svc - ok
20:37:59.0913 9024	megasas		 (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys
20:37:59.0913 9024	megasas - ok
20:37:59.0965 9024	MegaSR		  (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys
20:37:59.0966 9024	MegaSR - ok
20:38:00.0017 9024	mio			 (495a8efc5e850a4a36392faa1b932dbc) C:\Windows\system32\DRIVERS\mio.sys
20:38:00.0017 9024	mio - ok
20:38:00.0047 9024	MMCSS		   (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
20:38:00.0048 9024	MMCSS - ok
20:38:00.0080 9024	Modem		   (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
20:38:00.0080 9024	Modem - ok
20:38:00.0092 9024	monitor		 (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
20:38:00.0092 9024	monitor - ok
20:38:00.0117 9024	mouclass		(7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
20:38:00.0118 9024	mouclass - ok
20:38:00.0160 9024	mouhid		  (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
20:38:00.0161 9024	mouhid - ok
20:38:00.0179 9024	mountmgr		(32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
20:38:00.0180 9024	mountmgr - ok
20:38:00.0291 9024	MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
20:38:00.0292 9024	MozillaMaintenance - ok
20:38:00.0363 9024	MpFilter		(94c66ededcdb6a126880472f9a704d8e) C:\Windows\system32\DRIVERS\MpFilter.sys
20:38:00.0364 9024	MpFilter - ok
20:38:00.0408 9024	mpio			(a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
20:38:00.0408 9024	mpio - ok
20:38:00.0432 9024	mpsdrv		  (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
20:38:00.0432 9024	mpsdrv - ok
20:38:00.0504 9024	MpsSvc		  (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll
20:38:00.0508 9024	MpsSvc - ok
20:38:00.0538 9024	MRxDAV		  (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
20:38:00.0539 9024	MRxDAV - ok
20:38:00.0590 9024	mrxsmb		  (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
20:38:00.0591 9024	mrxsmb - ok
20:38:00.0651 9024	mrxsmb10		(d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:38:00.0652 9024	mrxsmb10 - ok
20:38:00.0677 9024	mrxsmb20		(9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:38:00.0678 9024	mrxsmb20 - ok
20:38:00.0693 9024	msahci		  (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
20:38:00.0693 9024	msahci - ok
20:38:00.0751 9024	msdsm		   (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
20:38:00.0752 9024	msdsm - ok
20:38:00.0801 9024	MSDTC		   (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
20:38:00.0802 9024	MSDTC - ok
20:38:00.0811 9024	Msfs			(aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
20:38:00.0811 9024	Msfs - ok
20:38:00.0827 9024	mshidkmdf	   (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
20:38:00.0828 9024	mshidkmdf - ok
20:38:00.0835 9024	msisadrv		(d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
20:38:00.0835 9024	msisadrv - ok
20:38:00.0857 9024	MSiSCSI		 (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
20:38:00.0858 9024	MSiSCSI - ok
20:38:00.0860 9024	msiserver - ok
20:38:00.0881 9024	MSKSSRV		 (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
20:38:00.0882 9024	MSKSSRV - ok
20:38:00.0959 9024	MsMpSvc		 (59faaf2c83c8169ea20f9e335e418907) c:\Program Files\Microsoft Security Client\MsMpEng.exe
20:38:00.0967 9024	MsMpSvc - ok
20:38:00.0991 9024	MSPCLOCK		(bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
20:38:00.0991 9024	MSPCLOCK - ok
20:38:00.0994 9024	MSPQM		   (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
20:38:00.0995 9024	MSPQM - ok
20:38:01.0025 9024	MsRPC		   (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
20:38:01.0027 9024	MsRPC - ok
20:38:01.0034 9024	mssmbios		(0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
20:38:01.0034 9024	mssmbios - ok
20:38:01.0114 9024	MSSQL$SQLEXPRESS - ok
20:38:01.0193 9024	MSSQLServerADHelper100 (7a2a8c975356858eb38466a6b1592e8d) c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE
20:38:01.0194 9024	MSSQLServerADHelper100 - ok
20:38:01.0214 9024	MSTEE		   (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
20:38:01.0214 9024	MSTEE - ok
20:38:01.0229 9024	MTConfig		(7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys
20:38:01.0229 9024	MTConfig - ok
20:38:01.0242 9024	Mup			 (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
20:38:01.0242 9024	Mup - ok
20:38:01.0297 9024	napagent		(582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
20:38:01.0299 9024	napagent - ok
20:38:01.0328 9024	NativeWifiP	 (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
20:38:01.0330 9024	NativeWifiP - ok
20:38:01.0399 9024	NDIS			(c38b8ae57f78915905064a9a24dc1586) C:\Windows\system32\drivers\ndis.sys
20:38:01.0403 9024	NDIS - ok
20:38:01.0440 9024	NdisCap		 (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
20:38:01.0440 9024	NdisCap - ok
20:38:01.0470 9024	NdisTapi		(30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
20:38:01.0470 9024	NdisTapi - ok
20:38:01.0496 9024	Ndisuio		 (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
20:38:01.0497 9024	Ndisuio - ok
20:38:01.0523 9024	NdisWan		 (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
20:38:01.0524 9024	NdisWan - ok
20:38:01.0557 9024	NDProxy		 (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
20:38:01.0557 9024	NDProxy - ok
20:38:01.0584 9024	NetBIOS		 (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
20:38:01.0584 9024	NetBIOS - ok
20:38:01.0612 9024	NetBT		   (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
20:38:01.0613 9024	NetBT - ok
20:38:01.0615 9024	Netlogon		(c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:38:01.0615 9024	Netlogon - ok
20:38:01.0667 9024	Netman		  (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
20:38:01.0669 9024	Netman - ok
20:38:01.0759 9024	NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:38:01.0760 9024	NetMsmqActivator - ok
20:38:01.0762 9024	NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:38:01.0762 9024	NetPipeActivator - ok
20:38:01.0802 9024	netprofm		(5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
20:38:01.0804 9024	netprofm - ok
20:38:01.0806 9024	NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:38:01.0807 9024	NetTcpActivator - ok
20:38:01.0808 9024	NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:38:01.0809 9024	NetTcpPortSharing - ok
20:38:01.0817 9024	nfrd960		 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys
20:38:01.0817 9024	nfrd960 - ok
20:38:01.0858 9024	NisDrv		  (91b4e0273d2f6c24ef845f2b41311289) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
20:38:01.0858 9024	NisDrv - ok
20:38:01.0925 9024	NisSrv		  (10a43829a9e606af3eef25a1c1665923) c:\Program Files\Microsoft Security Client\NisSrv.exe
20:38:01.0926 9024	NisSrv - ok
20:38:01.0987 9024	NlaSvc		  (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
20:38:01.0988 9024	NlaSvc - ok
20:38:02.0009 9024	Npfs			(1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
20:38:02.0009 9024	Npfs - ok
20:38:02.0041 9024	nsi			 (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
20:38:02.0042 9024	nsi - ok
20:38:02.0060 9024	nsiproxy		(e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
20:38:02.0060 9024	nsiproxy - ok
20:38:02.0140 9024	Ntfs			(a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
20:38:02.0147 9024	Ntfs - ok
20:38:02.0211 9024	Null			(9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
20:38:02.0211 9024	Null - ok
20:38:02.0237 9024	NVHDA		   (8d4aac74b571fc356560e5b308955e93) C:\Windows\system32\drivers\nvhda64v.sys
20:38:02.0238 9024	NVHDA - ok
20:38:02.0412 9024	nvlddmkm		(0eb204639119370f5f8f2871fbf4e14b) C:\Windows\system32\DRIVERS\nvlddmkm.sys
20:38:02.0518 9024	nvlddmkm - ok
20:38:02.0590 9024	nvraid		  (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
20:38:02.0591 9024	nvraid - ok
20:38:02.0615 9024	nvstor		  (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
20:38:02.0616 9024	nvstor - ok
20:38:02.0655 9024	NVSvc		   (32ff8ee6dcee5c0cb91ff892fb1ca364) C:\Windows\system32\nvvsvc.exe
20:38:02.0659 9024	NVSvc - ok
20:38:02.0764 9024	nvUpdatusService (bd012dc22c78be1071bc21eb125d782f) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
20:38:02.0773 9024	nvUpdatusService - ok
20:38:02.0815 9024	nv_agp		  (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
20:38:02.0816 9024	nv_agp - ok
20:38:02.0845 9024	ohci1394		(3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
20:38:02.0845 9024	ohci1394 - ok
20:38:02.0892 9024	p2pimsvc		(3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
20:38:02.0894 9024	p2pimsvc - ok
20:38:02.0952 9024	p2psvc		  (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
20:38:02.0954 9024	p2psvc - ok
20:38:02.0984 9024	Parport		 (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys
20:38:02.0984 9024	Parport - ok
20:38:03.0036 9024	partmgr		 (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
20:38:03.0036 9024	partmgr - ok
20:38:03.0070 9024	PcaSvc		  (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
20:38:03.0071 9024	PcaSvc - ok
20:38:03.0115 9024	pci			 (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
20:38:03.0116 9024	pci - ok
20:38:03.0124 9024	pciide		  (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
20:38:03.0124 9024	pciide - ok
20:38:03.0165 9024	pcmcia		  (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys
20:38:03.0166 9024	pcmcia - ok
20:38:03.0192 9024	pcw			 (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
20:38:03.0193 9024	pcw - ok
20:38:03.0244 9024	PEAUTH		  (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
20:38:03.0247 9024	PEAUTH - ok
20:38:03.0326 9024	PerfHost		(e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
20:38:03.0327 9024	PerfHost - ok
20:38:03.0384 9024	pla			 (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
20:38:03.0390 9024	pla - ok
20:38:03.0459 9024	PlugPlay		(25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
20:38:03.0462 9024	PlugPlay - ok
20:38:03.0483 9024	PnkBstrA - ok
20:38:03.0505 9024	PNRPAutoReg	 (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
20:38:03.0506 9024	PNRPAutoReg - ok
20:38:03.0510 9024	PNRPsvc		 (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
20:38:03.0512 9024	PNRPsvc - ok
20:38:03.0560 9024	PolicyAgent	 (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
20:38:03.0562 9024	PolicyAgent - ok
20:38:03.0601 9024	Power		   (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
20:38:03.0602 9024	Power - ok
20:38:03.0626 9024	PptpMiniport	(f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
20:38:03.0627 9024	PptpMiniport - ok
20:38:03.0665 9024	Processor	   (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys
20:38:03.0665 9024	Processor - ok
20:38:03.0694 9024	ProfSvc		 (5c78838b4d166d1a27db3a8a820c799a) C:\Windows\system32\profsvc.dll
20:38:03.0696 9024	ProfSvc - ok
20:38:03.0717 9024	ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:38:03.0718 9024	ProtectedStorage - ok
20:38:03.0763 9024	Psched		  (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
20:38:03.0763 9024	Psched - ok
20:38:03.0783 9024	PxHlpa64		(87b04878a6d59d6c79251dc960c674c1) C:\Windows\system32\Drivers\PxHlpa64.sys
20:38:03.0784 9024	PxHlpa64 - ok
20:38:03.0852 9024	ql2300		  (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys
20:38:03.0858 9024	ql2300 - ok
20:38:03.0908 9024	ql40xx		  (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys
20:38:03.0909 9024	ql40xx - ok
20:38:03.0953 9024	QWAVE		   (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
20:38:03.0954 9024	QWAVE - ok
20:38:03.0969 9024	QWAVEdrv		(76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
20:38:03.0970 9024	QWAVEdrv - ok
20:38:03.0980 9024	RasAcd		  (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
20:38:03.0981 9024	RasAcd - ok
20:38:04.0000 9024	RasAgileVpn	 (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
20:38:04.0000 9024	RasAgileVpn - ok
20:38:04.0025 9024	RasAuto		 (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
20:38:04.0026 9024	RasAuto - ok
20:38:04.0057 9024	Rasl2tp		 (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
20:38:04.0058 9024	Rasl2tp - ok
20:38:04.0097 9024	RasMan		  (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
20:38:04.0099 9024	RasMan - ok
20:38:04.0125 9024	RasPppoe		(855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
20:38:04.0125 9024	RasPppoe - ok
20:38:04.0146 9024	RasSstp		 (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
20:38:04.0146 9024	RasSstp - ok
20:38:04.0192 9024	rdbss		   (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
20:38:04.0194 9024	rdbss - ok
20:38:04.0226 9024	rdpbus		  (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys
20:38:04.0226 9024	rdpbus - ok
20:38:04.0236 9024	RDPCDD		  (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
20:38:04.0236 9024	RDPCDD - ok
20:38:04.0257 9024	RDPENCDD		(bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
20:38:04.0258 9024	RDPENCDD - ok
20:38:04.0277 9024	RDPREFMP		(216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
20:38:04.0278 9024	RDPREFMP - ok
20:38:04.0338 9024	RDPWD		   (6d76e6433574b058adcb0c50df834492) C:\Windows\system32\drivers\RDPWD.sys
20:38:04.0339 9024	RDPWD - ok
20:38:04.0363 9024	rdyboost		(34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
20:38:04.0364 9024	rdyboost - ok
20:38:04.0387 9024	RemoteAccess	(254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
20:38:04.0388 9024	RemoteAccess - ok
20:38:04.0428 9024	RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
20:38:04.0429 9024	RemoteRegistry - ok
20:38:04.0481 9024	RFCOMM		  (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
20:38:04.0482 9024	RFCOMM - ok
20:38:04.0591 9024	RoxMediaDB12OEM (3c957189b31c34d3ad21967b12b6aed7) C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
20:38:04.0596 9024	RoxMediaDB12OEM - ok
20:38:04.0655 9024	RoxWatch12	  (2b73088cc2ca757a172b425c9398e5bc) C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
20:38:04.0656 9024	RoxWatch12 - ok
20:38:04.0698 9024	RpcEptMapper	(e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
20:38:04.0699 9024	RpcEptMapper - ok
20:38:04.0726 9024	RpcLocator	  (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
20:38:04.0727 9024	RpcLocator - ok
20:38:04.0772 9024	RpcSs		   (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
20:38:04.0775 9024	RpcSs - ok
20:38:04.0826 9024	RsFx0103		(cd553b8633466a6d1c115812f2619f1f) C:\Windows\system32\DRIVERS\RsFx0103.sys
20:38:04.0827 9024	RsFx0103 - ok
20:38:04.0843 9024	rspndr		  (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
20:38:04.0844 9024	rspndr - ok
20:38:04.0846 9024	SamSs		   (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:38:04.0847 9024	SamSs - ok
20:38:04.0884 9024	sbp2port		(ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
20:38:04.0885 9024	sbp2port - ok
20:38:04.0931 9024	SCardSvr		(9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
20:38:04.0932 9024	SCardSvr - ok
20:38:04.0936 9024	scfilter		(253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
20:38:04.0936 9024	scfilter - ok
20:38:04.0977 9024	Schedule		(262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
20:38:04.0982 9024	Schedule - ok
20:38:05.0010 9024	SCPolicySvc	 (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
20:38:05.0010 9024	SCPolicySvc - ok
20:38:05.0051 9024	SDRSVC		  (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
20:38:05.0052 9024	SDRSVC - ok
20:38:05.0072 9024	secdrv		  (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
20:38:05.0072 9024	secdrv - ok
20:38:05.0100 9024	seclogon		(bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
20:38:05.0101 9024	seclogon - ok
20:38:05.0131 9024	SENS			(c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
20:38:05.0132 9024	SENS - ok
20:38:05.0136 9024	SensrSvc		(0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
20:38:05.0137 9024	SensrSvc - ok
20:38:05.0179 9024	Serenum		 (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys
20:38:05.0179 9024	Serenum - ok
20:38:05.0199 9024	Serial		  (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys
20:38:05.0200 9024	Serial - ok
20:38:05.0209 9024	sermouse		(1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys
20:38:05.0209 9024	sermouse - ok
20:38:05.0233 9024	SessionEnv	  (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
20:38:05.0234 9024	SessionEnv - ok
20:38:05.0249 9024	sffdisk		 (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
20:38:05.0249 9024	sffdisk - ok
20:38:05.0269 9024	sffp_mmc		(ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
20:38:05.0269 9024	sffp_mmc - ok
20:38:05.0280 9024	sffp_sd		 (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
20:38:05.0280 9024	sffp_sd - ok
20:38:05.0295 9024	sfloppy		 (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys
20:38:05.0296 9024	sfloppy - ok
20:38:05.0415 9024	SftService	  (6f36ee03af65de9aeb024809866d19b1) C:\Program Files (x86)\AlienRespawn\sftservice.EXE
20:38:05.0422 9024	SftService - ok
20:38:05.0484 9024	SharedAccess	(b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
20:38:05.0486 9024	SharedAccess - ok
20:38:05.0525 9024	ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
20:38:05.0528 9024	ShellHWDetection - ok
20:38:05.0539 9024	SI3132		  (0f498dee92fd73dd999bae4d506367f5) C:\Windows\system32\drivers\SI3132.sys
20:38:05.0540 9024	SI3132 - ok
20:38:05.0543 9024	SiFilter		(127ce10e01f53f2edaca7fe42e5631ea) C:\Windows\system32\drivers\SiWinAcc.sys
20:38:05.0543 9024	SiFilter - ok
20:38:05.0565 9024	SiRemFil		(b742c37002b8ebef6e230df9b4b28546) C:\Windows\system32\drivers\SiRemFil.sys
20:38:05.0565 9024	SiRemFil - ok
20:38:05.0581 9024	SiSRaid2		(843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys
20:38:05.0582 9024	SiSRaid2 - ok
20:38:05.0610 9024	SiSRaid4		(6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys
20:38:05.0610 9024	SiSRaid4 - ok
20:38:05.0644 9024	Smb			 (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
20:38:05.0644 9024	Smb - ok
20:38:05.0665 9024	SNMPTRAP		(6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
20:38:05.0666 9024	SNMPTRAP - ok
20:38:05.0670 9024	spldr		   (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
20:38:05.0670 9024	spldr - ok
20:38:05.0721 9024	Spooler		 (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
20:38:05.0724 9024	Spooler - ok
20:38:05.0820 9024	sppsvc		  (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
20:38:05.0843 9024	sppsvc - ok
20:38:05.0868 9024	sppuinotify	 (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
20:38:05.0869 9024	sppuinotify - ok
20:38:06.0010 9024	SQLAgent$SQLEXPRESS (12e6d95cde974b131defaa44bab8b056) c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE
20:38:06.0012 9024	SQLAgent$SQLEXPRESS - ok
20:38:06.0087 9024	SQLBrowser	  (b54b48f6d92423440c264e91225c5ff1) c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
20:38:06.0088 9024	SQLBrowser - ok
20:38:06.0131 9024	SQLWriter	   (6d65985945b03ca59b67d0b73702fc7b) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
20:38:06.0132 9024	SQLWriter - ok
20:38:06.0190 9024	srv			 (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
20:38:06.0192 9024	srv - ok
20:38:06.0256 9024	srv2			(b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
20:38:06.0257 9024	srv2 - ok
20:38:06.0290 9024	srvnet		  (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
20:38:06.0291 9024	srvnet - ok
20:38:06.0339 9024	SSDPSRV		 (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
20:38:06.0341 9024	SSDPSRV - ok
20:38:06.0352 9024	SstpSvc		 (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
20:38:06.0353 9024	SstpSvc - ok
20:38:06.0386 9024	Steam Client Service - ok
20:38:06.0511 9024	Stereo Service  (fc0a58529a02b1eed55ddc58696b7908) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
20:38:06.0512 9024	Stereo Service - ok
20:38:06.0536 9024	stexstor		(f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys
20:38:06.0537 9024	stexstor - ok
20:38:06.0594 9024	stisvc		  (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
20:38:06.0598 9024	stisvc - ok
20:38:06.0654 9024	stllssvr		(7731f46ec0d687a931cba063e8f90ef0) C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
20:38:06.0655 9024	stllssvr - ok
20:38:06.0672 9024	swenum		  (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
20:38:06.0673 9024	swenum - ok
20:38:06.0733 9024	swprv		   (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
20:38:06.0736 9024	swprv - ok
20:38:06.0800 9024	SysMain		 (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
20:38:06.0807 9024	SysMain - ok
20:38:06.0839 9024	TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
20:38:06.0841 9024	TabletInputService - ok
20:38:06.0863 9024	TapiSrv		 (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
20:38:06.0865 9024	TapiSrv - ok
20:38:06.0884 9024	TBS			 (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
20:38:06.0885 9024	TBS - ok
20:38:06.0965 9024	Tcpip		   (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
20:38:06.0972 9024	Tcpip - ok
20:38:06.0994 9024	TCPIP6		  (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
20:38:07.0001 9024	TCPIP6 - ok
20:38:07.0009 9024	tcpipreg		(df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
20:38:07.0010 9024	tcpipreg - ok
20:38:07.0044 9024	TDPIPE		  (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
20:38:07.0045 9024	TDPIPE - ok
20:38:07.0075 9024	TDTCP		   (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
20:38:07.0075 9024	TDTCP - ok
20:38:07.0114 9024	tdx			 (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
20:38:07.0115 9024	tdx - ok
20:38:07.0120 9024	TermDD		  (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys
20:38:07.0121 9024	TermDD - ok
20:38:07.0171 9024	TermService	 (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
20:38:07.0174 9024	TermService - ok
20:38:07.0208 9024	Themes		  (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
20:38:07.0209 9024	Themes - ok
20:38:07.0240 9024	THREADORDER	 (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
20:38:07.0240 9024	THREADORDER - ok
20:38:07.0274 9024	TrkWks		  (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
20:38:07.0275 9024	TrkWks - ok
20:38:07.0324 9024	TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
20:38:07.0325 9024	TrustedInstaller - ok
20:38:07.0346 9024	tssecsrv		(ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
20:38:07.0346 9024	tssecsrv - ok
20:38:07.0382 9024	TsUsbFlt		(d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
20:38:07.0382 9024	TsUsbFlt - ok
20:38:07.0391 9024	TsUsbGD		 (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys
20:38:07.0391 9024	TsUsbGD - ok
20:38:07.0440 9024	tunnel		  (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
20:38:07.0440 9024	tunnel - ok
20:38:07.0473 9024	uagp35		  (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys
20:38:07.0473 9024	uagp35 - ok
20:38:07.0513 9024	udfs			(ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
20:38:07.0515 9024	udfs - ok
20:38:07.0533 9024	UI0Detect	   (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
20:38:07.0534 9024	UI0Detect - ok
20:38:07.0569 9024	uliagpkx		(4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
20:38:07.0569 9024	uliagpkx - ok
20:38:07.0600 9024	umbus		   (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
20:38:07.0600 9024	umbus - ok
20:38:07.0631 9024	UmPass		  (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys
20:38:07.0632 9024	UmPass - ok
20:38:07.0682 9024	upnphost		(d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
20:38:07.0684 9024	upnphost - ok
20:38:07.0743 9024	usbaudio		(82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
20:38:07.0744 9024	usbaudio - ok
20:38:07.0777 9024	usbccgp		 (19ad7990c0b67e48dac5b26f99628223) C:\Windows\system32\DRIVERS\usbccgp.sys
20:38:07.0778 9024	usbccgp - ok
20:38:07.0803 9024	usbcir		  (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
20:38:07.0803 9024	usbcir - ok
20:38:07.0807 9024	usbehci		 (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
20:38:07.0808 9024	usbehci - ok
20:38:07.0850 9024	usbhub		  (8b892002d7b79312821169a14317ab86) C:\Windows\system32\DRIVERS\usbhub.sys
20:38:07.0851 9024	usbhub - ok
20:38:07.0865 9024	usbohci		 (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\drivers\usbohci.sys
20:38:07.0866 9024	usbohci - ok
20:38:07.0888 9024	usbprint		(73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\drivers\usbprint.sys
20:38:07.0888 9024	usbprint - ok
20:38:07.0950 9024	USBSTOR		 (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:38:07.0951 9024	USBSTOR - ok
20:38:07.0981 9024	usbuhci		 (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\DRIVERS\usbuhci.sys
20:38:07.0982 9024	usbuhci - ok
20:38:07.0998 9024	UxSms		   (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
20:38:07.0999 9024	UxSms - ok
20:38:08.0027 9024	VaultSvc		(c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
20:38:08.0027 9024	VaultSvc - ok
20:38:08.0049 9024	vdrvroot		(c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
20:38:08.0049 9024	vdrvroot - ok
20:38:08.0100 9024	vds			 (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
20:38:08.0103 9024	vds - ok
20:38:08.0131 9024	vga			 (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
20:38:08.0131 9024	vga - ok
20:38:08.0151 9024	VgaSave		 (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
20:38:08.0151 9024	VgaSave - ok
20:38:08.0201 9024	vhdmp		   (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
20:38:08.0202 9024	vhdmp - ok
20:38:08.0223 9024	viaide		  (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
20:38:08.0224 9024	viaide - ok
20:38:08.0244 9024	volmgr		  (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
20:38:08.0244 9024	volmgr - ok
20:38:08.0310 9024	volmgrx		 (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
20:38:08.0312 9024	volmgrx - ok
20:38:08.0348 9024	volsnap		 (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
20:38:08.0349 9024	volsnap - ok
20:38:08.0389 9024	vsmraid		 (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys
20:38:08.0389 9024	vsmraid - ok
20:38:08.0511 9024	VSPerfDrv100	(1928b9ca20f51bfbbad54d2c2c447b13) C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys
20:38:08.0512 9024	VSPerfDrv100 - ok
20:38:08.0587 9024	VSS			 (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
20:38:08.0593 9024	VSS - ok
20:38:08.0610 9024	vwifibus		(36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
20:38:08.0610 9024	vwifibus - ok
20:38:08.0634 9024	vwififlt		(6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
20:38:08.0634 9024	vwififlt - ok
20:38:08.0670 9024	W32Time		 (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
20:38:08.0672 9024	W32Time - ok
20:38:08.0686 9024	WacomPen		(4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys
20:38:08.0687 9024	WacomPen - ok
20:38:08.0718 9024	WANARP		  (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
20:38:08.0719 9024	WANARP - ok
20:38:08.0721 9024	Wanarpv6		(356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
20:38:08.0721 9024	Wanarpv6 - ok
20:38:08.0797 9024	WatAdminSvc	 (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
20:38:08.0802 9024	WatAdminSvc - ok
20:38:08.0867 9024	wbengine		(78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
20:38:08.0873 9024	wbengine - ok
20:38:08.0897 9024	WbioSrvc		(3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
20:38:08.0899 9024	WbioSrvc - ok
20:38:08.0938 9024	wcncsvc		 (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
20:38:08.0941 9024	wcncsvc - ok
20:38:08.0957 9024	WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
20:38:08.0958 9024	WcsPlugInService - ok
20:38:08.0973 9024	Wd			  (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys
20:38:08.0973 9024	Wd - ok
20:38:09.0024 9024	Wdf01000		(441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
20:38:09.0027 9024	Wdf01000 - ok
20:38:09.0053 9024	WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
20:38:09.0055 9024	WdiServiceHost - ok
20:38:09.0056 9024	WdiSystemHost   (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
20:38:09.0058 9024	WdiSystemHost - ok
20:38:09.0081 9024	WebClient	   (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
20:38:09.0083 9024	WebClient - ok
20:38:09.0121 9024	Wecsvc		  (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
20:38:09.0123 9024	Wecsvc - ok
20:38:09.0144 9024	wercplsupport   (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
20:38:09.0145 9024	wercplsupport - ok
20:38:09.0173 9024	WerSvc		  (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
20:38:09.0174 9024	WerSvc - ok
20:38:09.0181 9024	WfpLwf		  (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
20:38:09.0181 9024	WfpLwf - ok
20:38:09.0245 9024	WimFltr		 (b14ef15bd757fa488f9c970eee9c0d35) C:\Windows\system32\DRIVERS\wimfltr.sys
20:38:09.0246 9024	WimFltr - ok
20:38:09.0291 9024	WIMMount		(05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
20:38:09.0291 9024	WIMMount - ok
20:38:09.0331 9024	Winmgmt		 (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
20:38:09.0332 9024	Winmgmt - ok
20:38:09.0411 9024	WinRM		   (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
20:38:09.0420 9024	WinRM - ok
20:38:09.0481 9024	WinUsb		  (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
20:38:09.0482 9024	WinUsb - ok
20:38:09.0561 9024	Wlansvc		 (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
20:38:09.0566 9024	Wlansvc - ok
20:38:09.0574 9024	WmiAcpi		 (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
20:38:09.0574 9024	WmiAcpi - ok
20:38:09.0615 9024	wmiApSrv		(38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
20:38:09.0616 9024	wmiApSrv - ok
20:38:09.0638 9024	WMPNetworkSvc - ok
20:38:09.0653 9024	WPCSvc		  (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
20:38:09.0654 9024	WPCSvc - ok
20:38:09.0683 9024	WPDBusEnum	  (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
20:38:09.0684 9024	WPDBusEnum - ok
20:38:09.0702 9024	ws2ifsl		 (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
20:38:09.0702 9024	ws2ifsl - ok
20:38:09.0703 9024	WSearch - ok
20:38:09.0784 9024	wuauserv		(9df12edbc698b0bc353b3ef84861e430) C:\Windows\system32\wuaueng.dll
20:38:09.0795 9024	wuauserv - ok
20:38:09.0823 9024	WudfPf		  (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
20:38:09.0824 9024	WudfPf - ok
20:38:09.0856 9024	WUDFRd		  (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
20:38:09.0857 9024	WUDFRd - ok
20:38:09.0868 9024	wudfsvc		 (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
20:38:09.0869 9024	wudfsvc - ok
20:38:09.0914 9024	WwanSvc		 (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
20:38:09.0916 9024	WwanSvc - ok
20:38:09.0939 9024	MBR (0x1B8)	 (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
20:38:09.0991 9024	\Device\Harddisk0\DR0 - ok
20:38:09.0999 9024	Boot (0x1200)   (45b39ff1edd10c8781b353f6b71313e6) \Device\Harddisk0\DR0\Partition0
20:38:10.0000 9024	\Device\Harddisk0\DR0\Partition0 - ok
20:38:10.0002 9024	Boot (0x1200)   (31adb3d6c5f8679e3785f154dcebbc27) \Device\Harddisk0\DR0\Partition1
20:38:10.0002 9024	\Device\Harddisk0\DR0\Partition1 - ok
20:38:10.0003 9024	============================================================
20:38:10.0003 9024	Scan finished
20:38:10.0003 9024	============================================================
20:38:10.0007 8624	Detected object count: 0
20:38:10.0007 8624	Actual detected object count: 0
20:38:15.0172 5076	Deinitialize success
Hi blawa,

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Hello,

here is the LOG:

ComboFix 12-05-13.03 - blawa 13.05.2012  21:39:51.1.8 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.43.1031.18.6135.3450 [GMT 2:00]
ausgeführt von:: c:\users\blawa\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\A1
c:\program files (x86)\A1\A1 FTP\A1FTP.chm
c:\program files (x86)\A1\A1 FTP\A1FTP.exe
c:\program files (x86)\A1\A1 FTP\A1ftp.ini
c:\program files (x86)\A1\A1 FTP\M2Updater.exe
c:\users\blawa\AppData\Roaming\toolplugin\toolbar.dll
c:\windows\assembly\tmp\U
c:\windows\system32\drivers\etc\hosts.ics
.
.
(((((((((((((((((((((((   Dateien erstellt von 2012-04-13 bis 2012-05-13  ))))))))))))))))))))))))))))))
.
.
2012-05-13 19:44 . 2012-05-13 19:44	——–	d—–w-	c:\users\UpdatusUser\AppData\Local\temp
2012-05-13 19:44 . 2012-05-13 19:44	——–	d—–w-	c:\users\Default\AppData\Local\temp
2012-05-13 16:55 . 2012-05-13 16:55	——–	d—–w-	c:\program files (x86)\Lame For Audacity
2012-05-13 00:28 . 2012-05-13 00:28	69000	—-a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8D49CBB2-86A4-4020-9B10-4E663B3D0DC5}\offreg.dll
2012-05-13 00:27 . 2012-04-13 08:46	8917360	—-a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8D49CBB2-86A4-4020-9B10-4E663B3D0DC5}\mpengine.dll
2012-05-12 00:27 . 2012-04-13 08:46	8917360	—-a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-09 17:40 . 2012-05-09 17:40	8769696	—-a-w-	c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-05-09 17:11 . 2012-05-09 17:40	419488	—-a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2012-05-08 22:01 . 2012-03-03 06:35	1544704	—-a-w-	c:\windows\system32\DWrite.dll
2012-05-08 22:01 . 2012-03-03 05:31	1077248	—-a-w-	c:\windows\SysWow64\DWrite.dll
2012-05-08 22:01 . 2012-03-31 06:05	5559664	—-a-w-	c:\windows\system32\ntoskrnl.exe
2012-05-08 22:01 . 2012-03-31 03:10	3146240	—-a-w-	c:\windows\system32\win32k.sys
2012-05-08 22:01 . 2012-03-31 04:39	3968368	—-a-w-	c:\windows\SysWow64\ntkrnlpa.exe
2012-05-08 22:01 . 2012-03-31 04:39	3913072	—-a-w-	c:\windows\SysWow64\ntoskrnl.exe
2012-05-08 22:00 . 2012-03-17 07:58	75120	—-a-w-	c:\windows\system32\drivers\partmgr.sys
2012-05-08 22:00 . 2012-03-30 11:35	1918320	—-a-w-	c:\windows\system32\drivers\tcpip.sys
2012-05-08 22:00 . 2012-03-31 05:42	1732096	—-a-w-	c:\program files\Windows Journal\NBDoc.DLL
2012-05-08 22:00 . 2012-03-31 05:40	1402880	—-a-w-	c:\program files\Windows Journal\JNWDRV.dll
2012-05-08 22:00 . 2012-03-31 05:40	1367552	—-a-w-	c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-05-08 22:00 . 2012-03-31 05:40	1393664	—-a-w-	c:\program files\Windows Journal\JNTFiltr.dll
2012-05-08 22:00 . 2012-03-31 04:29	936960	—-a-w-	c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-05-07 07:28 . 2012-05-07 07:29	——–	d—–w-	c:\programdata\Battle.net
2012-05-05 13:39 . 2012-05-05 13:39	——–	d—–w-	c:\users\blawa\AppData\Roaming\TortoiseSVN
2012-05-05 13:30 . 2012-05-09 10:04	——–	d—–w-	c:\users\blawa\AppData\Local\TSVNCache
2012-05-05 13:30 . 2012-05-05 13:30	——–	d—–w-	c:\users\blawa\AppData\Roaming\Subversion
2012-05-05 13:30 . 2012-05-05 13:30	——–	d—–w-	c:\users\blawa\AppData\Local\CrashRpt
2012-05-05 13:26 . 2012-05-05 13:26	——–	d—–w-	c:\program files (x86)\Common Files\TortoiseOverlays
2012-05-05 13:26 . 2012-05-05 13:26	——–	d—–w-	c:\program files\TortoiseSVN
2012-05-05 13:26 . 2012-05-05 13:26	——–	d—–w-	c:\program files\Common Files\TortoiseOverlays
2012-05-05 12:51 . 2012-05-05 15:11	——–	d—–w-	c:\program files (x86)\FMOD SoundSystem
2012-05-04 10:23 . 2012-05-04 10:23	——–	d—–w-	c:\program files (x86)\Mozilla Maintenance Service
2012-05-04 10:23 . 2012-05-04 10:23	157352	—-a-w-	c:\program files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
2012-05-04 10:23 . 2012-05-04 10:23	129976	—-a-w-	c:\program files (x86)\Mozilla Firefox\maintenanceservice.exe
2012-05-03 13:43 . 2012-05-03 13:43	——–	d—–w-	c:\program files\CCleaner
2012-04-17 12:02 . 2012-04-17 12:02	——–	d—–w-	c:\users\blawa\AppData\Local\Apple Computer
2012-04-17 11:45 . 2012-04-18 12:07	——–	d—–w-	c:\users\blawa\AppData\Roaming\Apple Computer
2012-04-17 11:38 . 2012-04-17 11:38	——–	d—–w-	c:\program files (x86)\Common Files\Apple
2012-04-17 11:38 . 2012-04-17 11:38	——–	d—–w-	c:\users\blawa\AppData\Local\Apple
2012-04-17 11:38 . 2012-04-17 11:38	——–	d—–w-	c:\programdata\Apple
2012-04-17 11:38 . 2012-04-17 11:38	——–	d—–w-	c:\program files (x86)\Apple Software Update
2012-04-15 10:01 . 2012-05-13 16:59	——–	d—–w-	c:\users\blawa\AppData\Roaming\Audacity
2012-04-15 10:01 . 2012-04-15 10:01	——–	d—–w-	c:\program files (x86)\Audacity
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-09 17:40 . 2011-07-07 22:59	70304	—-a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-04 13:56 . 2012-03-10 14:18	24904	—-a-w-	c:\windows\system32\drivers\mbam.sys
2012-03-20 18:44 . 2011-04-27 13:25	98688	—-a-w-	c:\windows\system32\drivers\NisDrvWFP.sys
2012-03-20 18:44 . 2011-04-18 11:18	203888	—-a-w-	c:\windows\system32\drivers\MpFilter.sys
2012-03-18 13:17 . 2012-03-18 13:16	466456	—-a-w-	c:\windows\system32\wrap_oal.dll
2012-03-18 13:17 . 2012-03-18 13:16	444952	—-a-w-	c:\windows\SysWow64\wrap_oal.dll
2012-03-18 13:17 . 2012-03-18 13:16	122904	—-a-w-	c:\windows\system32\OpenAL32.dll
2012-03-18 13:17 . 2012-03-18 13:16	109080	—-a-w-	c:\windows\SysWow64\OpenAL32.dll
2012-03-15 02:03 . 2011-09-16 22:40	2490752	—-a-w-	c:\programdata\Microsoft\VisualStudio\10.0\1031\ResourceCache.dll
2012-03-01 06:46 . 2012-04-11 01:00	23408	—-a-w-	c:\windows\system32\drivers\fs_rec.sys
2012-03-01 06:38 . 2012-04-11 01:00	220672	—-a-w-	c:\windows\system32\wintrust.dll
2012-03-01 06:33 . 2012-04-11 01:00	81408	—-a-w-	c:\windows\system32\imagehlp.dll
2012-03-01 06:28 . 2012-04-11 01:00	5120	—-a-w-	c:\windows\system32\wmi.dll
2012-03-01 05:37 . 2012-04-11 01:00	172544	—-a-w-	c:\windows\SysWow64\wintrust.dll
2012-03-01 05:33 . 2012-04-11 01:00	159232	—-a-w-	c:\windows\SysWow64\imagehlp.dll
2012-03-01 05:29 . 2012-04-11 01:00	5120	—-a-w-	c:\windows\SysWow64\wmi.dll
2012-03-01 00:02 . 2012-03-15 14:34	8008000	—-a-w-	c:\windows\system32\nvcuda.dll
2012-03-01 00:02 . 2012-03-15 14:34	68928	—-a-w-	c:\windows\system32\OpenCL.dll
2012-03-01 00:02 . 2012-03-15 14:34	61248	—-a-w-	c:\windows\SysWow64\OpenCL.dll
2012-03-01 00:02 . 2012-03-15 14:34	5892928	—-a-w-	c:\windows\SysWow64\nvcuda.dll
2012-03-01 00:02 . 2012-03-15 14:34	2872640	—-a-w-	c:\windows\system32\nvcuvenc.dll
2012-03-01 00:02 . 2012-03-15 14:34	2672448	—-a-w-	c:\windows\system32\nvcuvid.dll
2012-03-01 00:02 . 2012-03-15 14:34	25543488	—-a-w-	c:\windows\system32\nvoglv64.dll
2012-03-01 00:02 . 2012-03-15 14:34	2517312	—-a-w-	c:\windows\SysWow64\nvcuvid.dll
2012-03-01 00:02 . 2012-03-15 14:34	2437440	—-a-w-	c:\windows\SysWow64\nvcuvenc.dll
2012-03-01 00:02 . 2012-03-15 14:34	19444544	—-a-w-	c:\windows\SysWow64\nvoglv32.dll
2012-03-01 00:02 . 2012-03-15 14:34	13626688	—-a-w-	c:\windows\system32\drivers\nvlddmkm.sys
2012-03-01 00:02 . 2012-03-15 14:34	25222976	—-a-w-	c:\windows\system32\nvcompiler.dll
2012-03-01 00:02 . 2012-03-15 14:34	17543488	—-a-w-	c:\windows\SysWow64\nvcompiler.dll
2012-03-01 00:02 . 2011-11-17 12:36	1737536	—-a-w-	c:\windows\system32\nvdispco64.dll
2012-03-01 00:02 . 2011-11-17 12:36	1466176	—-a-w-	c:\windows\system32\nvgenco64.dll
2012-03-01 00:02 . 2011-07-02 19:53	9717568	—-a-w-	c:\windows\system32\nvwgf2umx.dll
2012-03-01 00:02 . 2011-07-02 19:53	7713088	—-a-w-	c:\windows\SysWow64\nvwgf2um.dll
2012-03-01 00:02 . 2011-07-02 19:53	17642816	—-a-w-	c:\windows\system32\nvd3dumx.dll
2012-03-01 00:02 . 2011-07-02 19:53	15009600	—-a-w-	c:\windows\SysWow64\nvd3dum.dll
2012-03-01 00:02 . 2011-07-02 19:53	2660160	—-a-w-	c:\windows\system32\nvapi64.dll
2012-03-01 00:02 . 2011-07-02 19:53	2301248	—-a-w-	c:\windows\SysWow64\nvapi.dll
2012-02-29 21:00 . 2011-04-03 20:14	3089728	—-a-w-	c:\windows\system32\nvsvc64.dll
2012-02-29 21:00 . 2011-04-03 20:14	6074176	—-a-w-	c:\windows\system32\nvcpl.dll
2012-02-29 20:59 . 2011-04-03 20:15	889664	—-a-w-	c:\windows\system32\nvvsvc.exe
2012-02-29 20:59 . 2011-04-03 20:15	63296	—-a-w-	c:\windows\system32\nvshext.dll
2012-02-29 20:59 . 2011-04-03 20:15	118080	—-a-w-	c:\windows\system32\nvmctray.dll
2012-02-29 20:59 . 2011-04-03 20:15	2561856	—-a-w-	c:\windows\system32\nvsvcr.dll
2012-02-29 12:26 . 2012-02-29 12:26	416064	—-a-w-	c:\windows\SysWow64\nvStreaming.exe
2012-02-28 06:56 . 2012-04-11 01:02	2311168	—-a-w-	c:\windows\system32\jscript9.dll
2012-02-28 06:49 . 2012-04-11 01:02	1390080	—-a-w-	c:\windows\system32\wininet.dll
2012-02-28 06:48 . 2012-04-11 01:02	1493504	—-a-w-	c:\windows\system32\inetcpl.cpl
2012-02-28 06:42 . 2012-04-11 01:02	2382848	—-a-w-	c:\windows\system32\mshtml.tlb
2012-02-28 01:18 . 2012-04-11 01:02	1799168	—-a-w-	c:\windows\SysWow64\jscript9.dll
2012-02-28 01:11 . 2012-04-11 01:02	1427456	—-a-w-	c:\windows\SysWow64\inetcpl.cpl
2012-02-28 01:11 . 2012-04-11 01:02	1127424	—-a-w-	c:\windows\SysWow64\wininet.dll
2012-02-28 01:03 . 2012-04-11 01:02	2382848	—-a-w-	c:\windows\SysWow64\mshtml.tlb
2012-02-24 09:36 . 2012-03-10 11:29	230952	—-a-w-	c:\windows\system32\drivers\PCTSD64.sys
2012-02-22 16:23 . 2012-02-22 16:23	249856	——w-	c:\windows\Setup1.exe
2012-02-22 16:23 . 2012-02-22 16:23	73216	—-a-w-	c:\windows\ST6UNST.EXE
2012-02-21 11:10 . 2012-02-21 11:10	21840	—-a-w-	c:\windows\SysWow64\SIntfNT.dll
2012-02-21 11:10 . 2012-02-21 11:10	17212	—-a-w-	c:\windows\SysWow64\SIntf32.dll
2012-02-21 11:10 . 2012-02-21 11:10	12067	—-a-w-	c:\windows\SysWow64\SIntf16.dll
2012-02-21 11:01 . 2012-02-21 11:01	2829	—-a-w-	c:\windows\DIIUnin.pif
2012-02-21 11:01 . 2012-02-21 11:01	102400	—-a-w-	c:\windows\DIIUnin.exe
2012-02-17 06:38 . 2012-03-14 06:48	1031680	—-a-w-	c:\windows\system32\rdpcore.dll
2012-02-17 05:34 . 2012-03-14 06:48	826880	—-a-w-	c:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58 . 2012-03-14 06:48	210944	—-a-w-	c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:57 . 2012-03-14 06:48	23552	—-a-w-	c:\windows\system32\drivers\tdtcp.sys
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{c840e246-6b95-475e-9bd7-caa1c7eca9f2}"= "c:\program files (x86)\uTorrentBar_DE\prxtbuTor.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{c840e246-6b95-475e-9bd7-caa1c7eca9f2}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-03-28 16:22	176936	—-a-w-	c:\program files (x86)\ConduitEngine\prxConduitEngin.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{c840e246-6b95-475e-9bd7-caa1c7eca9f2}]
2011-03-28 16:22	176936	—-a-w-	c:\program files (x86)\uTorrentBar_DE\prxtbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{c840e246-6b95-475e-9bd7-caa1c7eca9f2}"= "c:\program files (x86)\uTorrentBar_DE\prxtbuTor.dll" [2011-03-28 176936]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\prxConduitEngin.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{c840e246-6b95-475e-9bd7-caa1c7eca9f2}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-02 1242448]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"EAUpdater"="c:\users\blawa\AppData\Roaming\EA\ea_updater.exe" [2010-11-21 1169224]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-03 284696]
"THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" [2009-12-01 963584]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-06-06 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Guard.Mail.ru.gui"="c:\program files (x86)\Guard-ICQ\GuardICQ.exe" [2011-12-28 1564368]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
.
c:\users\blawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-1 1079584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-03-01 2348352]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-09 257696]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-03-06 1436424]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-04 129976]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-03-17 68440]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 MSSQLServerADHelper100;SQL Server Hilfsdienst für Active Directory;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-21 61976]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x]
R4 SQLAgent$SQLEXPRESS;SQL Server-Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AlienFusionService;Alienware Fusion Service;c:\program files\Alienware\Command Center\AlienFusionService.exe [2011-03-21 15296]
S2 BPowMon;Broadcom Power monitoring service;c:\program files\Broadcom\BPowMon\BPowMon.exe [2009-10-27 117608]
S2 Guard.Mail.ru;Guard.Mail.ru;c:\program files (x86)\Guard-ICQ\GuardICQ.exe [2011-12-28 1564368]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\AlienRespawn\sftservice.EXE [2011-05-16 1688384]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-29 382272]
S3 AWOPFilterDriver;AWOPFilterDriver;c:\windows\system32\drivers\AWOPFilterDriver.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 mio;Master IO Filter Driver;c:\windows\system32\DRIVERS\mio.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
.
.
— Andere Dienste/Treiber im Speicher —
.
*NewlyCreated* - 65663405
*NewlyCreated* - 93979989
*Deregistered* - 65663405
*Deregistered* - 93979989
*Deregistered* - aswMBR
.
Inhalt des "geplante Tasks" Ordners
.
2012-05-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-09 17:40]
.
2012-04-18 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\AlienAutopsy\uaclauncher.exe [2011-03-22 17:20]
.
2012-05-13 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\AlienAutopsy\pcdrcui.exe [2011-03-22 17:20]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-02-03 10038304]
"Command Center Controllers"="c:\program files\Alienware\Command Center\AWCCStartupOrchestrator.exe" [2011-03-21 13256]
"RunDLLEntry_THXCfg"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]
"RunDLLEntry_EptMon"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
——- Zusätzlicher Suchlauf ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = my.daemon-search.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Bild an &Bluetooth-Gerät senden… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Seite an &Bluetooth-Gerät senden… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files (x86)\ICQ7.7\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\blawa\AppData\Roaming\Mozilla\Firefox\Profiles\n18ln615.default\
FF - prefs.js: browser.search.selectedEngine - Search the web
FF - prefs.js: browser.startup.homepage - google.at
FF - prefs.js: keyword.URL - hxxp://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q=
FF - prefs.js: network.proxy.type - 0
FF - user.js: browser.search.selectedEngine - Search the web
FF - user.js: browser.search.order.1 - Search the web
FF - user.js: browser.search.defaultenginename - Search the web
FF - user.js: keyword.URL - hxxp://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q=
FF - user.js: privacy.item.cookies - false
FF - user.js: privacy.sanitize.promptOnSanitize - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-Overwolf - c:\program files (x86)\Overwolf\Overwolf.exe
Toolbar-Locked - (no file)
HKLM-Run-(Standard) - (no file)
AddRemove-toolplugin - c:\users\blawa\AppData\Local\Temp\WZSE0.TMP\setup.exe
.
.
.
——————— Gesperrte Registrierungsschluessel ———————
.
[HKEY_USERS\S-1-5-21-2209728477-714789964-3075794624-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:94,70,8b,2f,33,c6,ea,50,12,a8,29,33,01,6a,8c,fe,81,94,fb,f6,ad,89,b6,
   94,b9,7f,85,8e,65,c4,61,39,e7,8c,17,d7,7d,88,99,f9,d4,c9,bc,87,36,df,06,92,\
"??"=hex:a3,77,26,48,47,4c,a5,0f,61,eb,40,19,f6,57,bd,a1
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-05-13  21:46:28
ComboFix-quarantined-files.txt  2012-05-13 19:46
.
Vor Suchlauf: 19 Verzeichnis(se), 1.010.185.207.808 Bytes frei
Nach Suchlauf: 21 Verzeichnis(se), 1.011.126.792.192 Bytes frei
.
- - End Of File - - 441E1D0018ED18F771BFB35F77F83532
Open Programs and Features by clicking the Start button [external image: Posted Image], clicking Control Panel, clicking Programs, and then clicking Programs and Features.

Select a Conduit Toolbar, and then click Uninstall.

===================================================

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

DDS::
uStart Page = my.daemon-search.com

Firefox::
FF - ProfilePath - c:\users\blawa\AppData\Roaming\Mozilla\Firefox\Profiles\n18ln615.default\
FF - prefs.js: browser.search.selectedEngine - Search the web
FF - prefs.js: keyword.URL - hxxp://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q=
FF - user.js: browser.search.selectedEngine - Search the web
FF - user.js: browser.search.order.1 - Search the web
FF - user.js: browser.search.defaultenginename - Search the web
FF - user.js: keyword.URL - hxxp://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q=
Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste
Here is the log:

ComboFix 12-05-14.01 - blawa 14.05.2012   9:04.2.8 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.43.1031.18.6135.3488 [GMT 2:00]
ausgeführt von:: c:\users\blawa\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\blawa\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((   Dateien erstellt von 2012-04-14 bis 2012-05-14  ))))))))))))))))))))))))))))))
.
.
2012-05-14 07:08 . 2012-05-14 07:08	——–	d—–w-	c:\users\UpdatusUser\AppData\Local\temp
2012-05-14 07:08 . 2012-05-14 07:08	——–	d—–w-	c:\users\Default\AppData\Local\temp
2012-05-14 07:02 . 2012-05-14 07:02	69000	—-a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D9746B6F-DA79-4855-82CF-01E8D9EB269C}\offreg.dll
2012-05-14 01:35 . 2012-04-13 08:46	8917360	—-a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D9746B6F-DA79-4855-82CF-01E8D9EB269C}\mpengine.dll
2012-05-13 19:53 . 2012-04-13 08:46	8917360	—-a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-13 16:55 . 2012-05-13 16:55	——–	d—–w-	c:\program files (x86)\Lame For Audacity
2012-05-09 17:40 . 2012-05-09 17:40	8769696	—-a-w-	c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-05-09 17:11 . 2012-05-09 17:40	419488	—-a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2012-05-08 22:01 . 2012-03-03 06:35	1544704	—-a-w-	c:\windows\system32\DWrite.dll
2012-05-08 22:01 . 2012-03-03 05:31	1077248	—-a-w-	c:\windows\SysWow64\DWrite.dll
2012-05-08 22:01 . 2012-03-31 06:05	5559664	—-a-w-	c:\windows\system32\ntoskrnl.exe
2012-05-08 22:01 . 2012-03-31 03:10	3146240	—-a-w-	c:\windows\system32\win32k.sys
2012-05-08 22:01 . 2012-03-31 04:39	3968368	—-a-w-	c:\windows\SysWow64\ntkrnlpa.exe
2012-05-08 22:01 . 2012-03-31 04:39	3913072	—-a-w-	c:\windows\SysWow64\ntoskrnl.exe
2012-05-08 22:00 . 2012-03-17 07:58	75120	—-a-w-	c:\windows\system32\drivers\partmgr.sys
2012-05-08 22:00 . 2012-03-30 11:35	1918320	—-a-w-	c:\windows\system32\drivers\tcpip.sys
2012-05-08 22:00 . 2012-03-31 05:42	1732096	—-a-w-	c:\program files\Windows Journal\NBDoc.DLL
2012-05-08 22:00 . 2012-03-31 05:40	1402880	—-a-w-	c:\program files\Windows Journal\JNWDRV.dll
2012-05-08 22:00 . 2012-03-31 05:40	1367552	—-a-w-	c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-05-08 22:00 . 2012-03-31 05:40	1393664	—-a-w-	c:\program files\Windows Journal\JNTFiltr.dll
2012-05-08 22:00 . 2012-03-31 04:29	936960	—-a-w-	c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-05-07 07:28 . 2012-05-07 07:29	——–	d—–w-	c:\programdata\Battle.net
2012-05-05 13:39 . 2012-05-05 13:39	——–	d—–w-	c:\users\blawa\AppData\Roaming\TortoiseSVN
2012-05-05 13:30 . 2012-05-09 10:04	——–	d—–w-	c:\users\blawa\AppData\Local\TSVNCache
2012-05-05 13:30 . 2012-05-05 13:30	——–	d—–w-	c:\users\blawa\AppData\Roaming\Subversion
2012-05-05 13:30 . 2012-05-05 13:30	——–	d—–w-	c:\users\blawa\AppData\Local\CrashRpt
2012-05-05 13:26 . 2012-05-05 13:26	——–	d—–w-	c:\program files (x86)\Common Files\TortoiseOverlays
2012-05-05 13:26 . 2012-05-05 13:26	——–	d—–w-	c:\program files\TortoiseSVN
2012-05-05 13:26 . 2012-05-05 13:26	——–	d—–w-	c:\program files\Common Files\TortoiseOverlays
2012-05-05 12:51 . 2012-05-05 15:11	——–	d—–w-	c:\program files (x86)\FMOD SoundSystem
2012-05-04 10:23 . 2012-05-04 10:23	——–	d—–w-	c:\program files (x86)\Mozilla Maintenance Service
2012-05-04 10:23 . 2012-05-04 10:23	157352	—-a-w-	c:\program files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
2012-05-04 10:23 . 2012-05-04 10:23	129976	—-a-w-	c:\program files (x86)\Mozilla Firefox\maintenanceservice.exe
2012-05-03 13:43 . 2012-05-03 13:43	——–	d—–w-	c:\program files\CCleaner
2012-04-17 12:02 . 2012-04-17 12:02	——–	d—–w-	c:\users\blawa\AppData\Local\Apple Computer
2012-04-17 11:45 . 2012-04-18 12:07	——–	d—–w-	c:\users\blawa\AppData\Roaming\Apple Computer
2012-04-17 11:38 . 2012-04-17 11:38	——–	d—–w-	c:\program files (x86)\Common Files\Apple
2012-04-17 11:38 . 2012-04-17 11:38	——–	d—–w-	c:\users\blawa\AppData\Local\Apple
2012-04-17 11:38 . 2012-04-17 11:38	——–	d—–w-	c:\programdata\Apple
2012-04-17 11:38 . 2012-04-17 11:38	——–	d—–w-	c:\program files (x86)\Apple Software Update
2012-04-15 10:01 . 2012-05-13 16:59	——–	d—–w-	c:\users\blawa\AppData\Roaming\Audacity
2012-04-15 10:01 . 2012-04-15 10:01	——–	d—–w-	c:\program files (x86)\Audacity
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-09 17:40 . 2011-07-07 22:59	70304	—-a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-04 13:56 . 2012-03-10 14:18	24904	—-a-w-	c:\windows\system32\drivers\mbam.sys
2012-03-20 18:44 . 2011-04-27 13:25	98688	—-a-w-	c:\windows\system32\drivers\NisDrvWFP.sys
2012-03-20 18:44 . 2011-04-18 11:18	203888	—-a-w-	c:\windows\system32\drivers\MpFilter.sys
2012-03-18 13:17 . 2012-03-18 13:16	466456	—-a-w-	c:\windows\system32\wrap_oal.dll
2012-03-18 13:17 . 2012-03-18 13:16	444952	—-a-w-	c:\windows\SysWow64\wrap_oal.dll
2012-03-18 13:17 . 2012-03-18 13:16	122904	—-a-w-	c:\windows\system32\OpenAL32.dll
2012-03-18 13:17 . 2012-03-18 13:16	109080	—-a-w-	c:\windows\SysWow64\OpenAL32.dll
2012-03-15 02:03 . 2011-09-16 22:40	2490752	—-a-w-	c:\programdata\Microsoft\VisualStudio\10.0\1031\ResourceCache.dll
2012-03-01 06:46 . 2012-04-11 01:00	23408	—-a-w-	c:\windows\system32\drivers\fs_rec.sys
2012-03-01 06:38 . 2012-04-11 01:00	220672	—-a-w-	c:\windows\system32\wintrust.dll
2012-03-01 06:33 . 2012-04-11 01:00	81408	—-a-w-	c:\windows\system32\imagehlp.dll
2012-03-01 06:28 . 2012-04-11 01:00	5120	—-a-w-	c:\windows\system32\wmi.dll
2012-03-01 05:37 . 2012-04-11 01:00	172544	—-a-w-	c:\windows\SysWow64\wintrust.dll
2012-03-01 05:33 . 2012-04-11 01:00	159232	—-a-w-	c:\windows\SysWow64\imagehlp.dll
2012-03-01 05:29 . 2012-04-11 01:00	5120	—-a-w-	c:\windows\SysWow64\wmi.dll
2012-03-01 00:02 . 2012-03-15 14:34	8008000	—-a-w-	c:\windows\system32\nvcuda.dll
2012-03-01 00:02 . 2012-03-15 14:34	68928	—-a-w-	c:\windows\system32\OpenCL.dll
2012-03-01 00:02 . 2012-03-15 14:34	61248	—-a-w-	c:\windows\SysWow64\OpenCL.dll
2012-03-01 00:02 . 2012-03-15 14:34	5892928	—-a-w-	c:\windows\SysWow64\nvcuda.dll
2012-03-01 00:02 . 2012-03-15 14:34	2872640	—-a-w-	c:\windows\system32\nvcuvenc.dll
2012-03-01 00:02 . 2012-03-15 14:34	2672448	—-a-w-	c:\windows\system32\nvcuvid.dll
2012-03-01 00:02 . 2012-03-15 14:34	25543488	—-a-w-	c:\windows\system32\nvoglv64.dll
2012-03-01 00:02 . 2012-03-15 14:34	2517312	—-a-w-	c:\windows\SysWow64\nvcuvid.dll
2012-03-01 00:02 . 2012-03-15 14:34	2437440	—-a-w-	c:\windows\SysWow64\nvcuvenc.dll
2012-03-01 00:02 . 2012-03-15 14:34	19444544	—-a-w-	c:\windows\SysWow64\nvoglv32.dll
2012-03-01 00:02 . 2012-03-15 14:34	13626688	—-a-w-	c:\windows\system32\drivers\nvlddmkm.sys
2012-03-01 00:02 . 2012-03-15 14:34	25222976	—-a-w-	c:\windows\system32\nvcompiler.dll
2012-03-01 00:02 . 2012-03-15 14:34	17543488	—-a-w-	c:\windows\SysWow64\nvcompiler.dll
2012-03-01 00:02 . 2011-11-17 12:36	1737536	—-a-w-	c:\windows\system32\nvdispco64.dll
2012-03-01 00:02 . 2011-11-17 12:36	1466176	—-a-w-	c:\windows\system32\nvgenco64.dll
2012-03-01 00:02 . 2011-07-02 19:53	9717568	—-a-w-	c:\windows\system32\nvwgf2umx.dll
2012-03-01 00:02 . 2011-07-02 19:53	7713088	—-a-w-	c:\windows\SysWow64\nvwgf2um.dll
2012-03-01 00:02 . 2011-07-02 19:53	17642816	—-a-w-	c:\windows\system32\nvd3dumx.dll
2012-03-01 00:02 . 2011-07-02 19:53	15009600	—-a-w-	c:\windows\SysWow64\nvd3dum.dll
2012-03-01 00:02 . 2011-07-02 19:53	2660160	—-a-w-	c:\windows\system32\nvapi64.dll
2012-03-01 00:02 . 2011-07-02 19:53	2301248	—-a-w-	c:\windows\SysWow64\nvapi.dll
2012-02-29 21:00 . 2011-04-03 20:14	3089728	—-a-w-	c:\windows\system32\nvsvc64.dll
2012-02-29 21:00 . 2011-04-03 20:14	6074176	—-a-w-	c:\windows\system32\nvcpl.dll
2012-02-29 20:59 . 2011-04-03 20:15	889664	—-a-w-	c:\windows\system32\nvvsvc.exe
2012-02-29 20:59 . 2011-04-03 20:15	63296	—-a-w-	c:\windows\system32\nvshext.dll
2012-02-29 20:59 . 2011-04-03 20:15	118080	—-a-w-	c:\windows\system32\nvmctray.dll
2012-02-29 20:59 . 2011-04-03 20:15	2561856	—-a-w-	c:\windows\system32\nvsvcr.dll
2012-02-29 12:26 . 2012-02-29 12:26	416064	—-a-w-	c:\windows\SysWow64\nvStreaming.exe
2012-02-28 06:56 . 2012-04-11 01:02	2311168	—-a-w-	c:\windows\system32\jscript9.dll
2012-02-28 06:49 . 2012-04-11 01:02	1390080	—-a-w-	c:\windows\system32\wininet.dll
2012-02-28 06:48 . 2012-04-11 01:02	1493504	—-a-w-	c:\windows\system32\inetcpl.cpl
2012-02-28 06:42 . 2012-04-11 01:02	2382848	—-a-w-	c:\windows\system32\mshtml.tlb
2012-02-28 01:18 . 2012-04-11 01:02	1799168	—-a-w-	c:\windows\SysWow64\jscript9.dll
2012-02-28 01:11 . 2012-04-11 01:02	1427456	—-a-w-	c:\windows\SysWow64\inetcpl.cpl
2012-02-28 01:11 . 2012-04-11 01:02	1127424	—-a-w-	c:\windows\SysWow64\wininet.dll
2012-02-28 01:03 . 2012-04-11 01:02	2382848	—-a-w-	c:\windows\SysWow64\mshtml.tlb
2012-02-24 09:36 . 2012-03-10 11:29	230952	—-a-w-	c:\windows\system32\drivers\PCTSD64.sys
2012-02-22 16:23 . 2012-02-22 16:23	249856	——w-	c:\windows\Setup1.exe
2012-02-22 16:23 . 2012-02-22 16:23	73216	—-a-w-	c:\windows\ST6UNST.EXE
2012-02-21 11:10 . 2012-02-21 11:10	21840	—-a-w-	c:\windows\SysWow64\SIntfNT.dll
2012-02-21 11:10 . 2012-02-21 11:10	17212	—-a-w-	c:\windows\SysWow64\SIntf32.dll
2012-02-21 11:10 . 2012-02-21 11:10	12067	—-a-w-	c:\windows\SysWow64\SIntf16.dll
2012-02-21 11:01 . 2012-02-21 11:01	2829	—-a-w-	c:\windows\DIIUnin.pif
2012-02-21 11:01 . 2012-02-21 11:01	102400	—-a-w-	c:\windows\DIIUnin.exe
2012-02-17 06:38 . 2012-03-14 06:48	1031680	—-a-w-	c:\windows\system32\rdpcore.dll
2012-02-17 05:34 . 2012-03-14 06:48	826880	—-a-w-	c:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58 . 2012-03-14 06:48	210944	—-a-w-	c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:57 . 2012-03-14 06:48	23552	—-a-w-	c:\windows\system32\drivers\tdtcp.sys
.
.
(((((((((((((((((((((((((((((   SnapShot@2012-05-13_19.45.05   )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{c840e246-6b95-475e-9bd7-caa1c7eca9f2}"= "c:\program files (x86)\uTorrentBar_DE\prxtbuTor.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{c840e246-6b95-475e-9bd7-caa1c7eca9f2}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{c840e246-6b95-475e-9bd7-caa1c7eca9f2}]
2011-03-28 16:22	176936	—-a-w-	c:\program files (x86)\uTorrentBar_DE\prxtbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{c840e246-6b95-475e-9bd7-caa1c7eca9f2}"= "c:\program files (x86)\uTorrentBar_DE\prxtbuTor.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{c840e246-6b95-475e-9bd7-caa1c7eca9f2}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	64792	—-a-w-	c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-02 1242448]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"EAUpdater"="c:\users\blawa\AppData\Roaming\EA\ea_updater.exe" [2010-11-21 1169224]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-03 284696]
"THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" [2009-12-01 963584]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-06-06 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Guard.Mail.ru.gui"="c:\program files (x86)\Guard-ICQ\GuardICQ.exe" [2011-12-28 1564368]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
.
c:\users\blawa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-1 1079584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-03-01 2348352]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-09 257696]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-03-06 1436424]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-04 129976]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-03-17 68440]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 MSSQLServerADHelper100;SQL Server Hilfsdienst für Active Directory;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-21 61976]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x]
R4 SQLAgent$SQLEXPRESS;SQL Server-Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AlienFusionService;Alienware Fusion Service;c:\program files\Alienware\Command Center\AlienFusionService.exe [2011-03-21 15296]
S2 BPowMon;Broadcom Power monitoring service;c:\program files\Broadcom\BPowMon\BPowMon.exe [2009-10-27 117608]
S2 Guard.Mail.ru;Guard.Mail.ru;c:\program files (x86)\Guard-ICQ\GuardICQ.exe [2011-12-28 1564368]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\AlienRespawn\sftservice.EXE [2011-05-16 1688384]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-29 382272]
S3 AWOPFilterDriver;AWOPFilterDriver;c:\windows\system32\drivers\AWOPFilterDriver.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 mio;Master IO Filter Driver;c:\windows\system32\DRIVERS\mio.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
.
.
— Andere Dienste/Treiber im Speicher —
.
*NewlyCreated* - 65663405
*NewlyCreated* - 93979989
*Deregistered* - 65663405
*Deregistered* - 93979989
*Deregistered* - aswMBR
.
Inhalt des "geplante Tasks" Ordners
.
2012-05-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-09 17:40]
.
2012-04-18 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\AlienAutopsy\uaclauncher.exe [2011-03-22 17:20]
.
2012-05-13 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\AlienAutopsy\pcdrcui.exe [2011-03-22 17:20]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20	75544	—-a-w-	c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-02-03 10038304]
"Command Center Controllers"="c:\program files\Alienware\Command Center\AWCCStartupOrchestrator.exe" [2011-03-21 13256]
"RunDLLEntry_THXCfg"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]
"RunDLLEntry_EptMon"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
.
——- Zusätzlicher Suchlauf ——-
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Bild an &Bluetooth-Gerät senden… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Seite an &Bluetooth-Gerät senden… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files (x86)\ICQ7.7\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\blawa\AppData\Roaming\Mozilla\Firefox\Profiles\n18ln615.default\
FF - prefs.js: browser.startup.homepage - google.at
FF - prefs.js: network.proxy.type - 0
FF - user.js: privacy.item.cookies - false
FF - user.js: privacy.sanitize.promptOnSanitize - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
.
.
.
——————— Gesperrte Registrierungsschluessel ———————
.
[HKEY_USERS\S-1-5-21-2209728477-714789964-3075794624-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:94,70,8b,2f,33,c6,ea,50,12,a8,29,33,01,6a,8c,fe,81,94,fb,f6,ad,89,b6,
   94,b9,7f,85,8e,65,c4,61,39,e7,8c,17,d7,7d,88,99,f9,d4,c9,bc,87,36,df,06,92,\
"??"=hex:a3,77,26,48,47,4c,a5,0f,61,eb,40,19,f6,57,bd,a1
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-05-14  09:09:59
ComboFix-quarantined-files.txt  2012-05-14 07:09
ComboFix2.txt  2012-05-13 19:46
.
Vor Suchlauf: 20 Verzeichnis(se), 1.012.026.843.136 Bytes frei
Nach Suchlauf: 21 Verzeichnis(se), 1.011.723.087.872 Bytes frei
.
- - End Of File - - 09873DAA6E57888FA414A2B05E39FD30
Hi blawa,

How is your computer behaving now?

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
===================================================

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 7 Update 4.
  • After the download completes, close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Double click the Java setup file you just downloaded and follow the prompts to begin the installation.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
===================================================

Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer if required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader.
  • Make sure you uncheck Yes, install McAfee Security Scan Plus - optional if prompted.
Alternative Option: after uninstalling Adobe Reader, you could try downloading and installing SlimPDF Reader from >here< SlimPDF Reader comes with no bloatware and loads extremely quickly.
Hello,

Here is the Report:

C:\Qoobox\Quarantine\C\Users\blawa\AppData\Roaming\toolplugin\toolbar.dll.vir	Win32/Adware.ToolPlugin application	cleaned by deleting - quarantined
C:\Users\blawa\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\49853cf7-1d1a0fc3	a variant of Java/Agent.DP trojan	deleted - quarantined
C:\Users\blawa\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\297a1d7f-7fa942fd	multiple threats	deleted - quarantined
C:\Users\blawa\Downloads\DivxUpdate.exe	Win32/Adware.ToolPlugin application	deleted - quarantined
C:\Users\blawa\Downloads\installer_counter-strike.exe	multiple threats	deleted - quarantined
Great! Your computer appears to be clean. Let's remove the tools we used and send you on your way.

Please delete DDS, aswMBR, and TDSSKiller.

Follow these steps to uninstall Combofix

* Click START
* Now type ComboFix /Uninstall in the searchbox and hit ENTER. Note the space between the X and the /, it needs to be there.
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]

===================================================

Here are some tips to reduce the potential for spyware infection in the future:

Updates
  • It is very important that you keep your Operating System and applications up to date so that you will be less susceptible to malware.
  • It's a good idea to have Windows Update automatically download and install updates as they become available.
  • Secunia Online Software Inspector is a great tool that will tell you which of your applications are outdated and vulnerable to attack.
Run Anti-Virus Software
  • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.
  • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system.
  • When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
  • Once complete, remember to re-engage your resident security before going online.
Passwords
  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection.
  • Refer to this Microsoft article
    Strong passwords: How to create and use them and consider a password keeper, to keep all your passwords safe.
Spyware Protection
  • This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
  • How to Prevent Malware by miekiemoes
  • PC Safety and Security–What Do I Need?
Additional Software
  • To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements.
  • Google Chrome is a great alternative to Internet Explorer and Firefox.
Follow these steps, keep your antivirus program and antispyware programs updated, and scan with them on a regular basis. By doing so, your potential for being infected again will reduce dramatically. 

Hopefully this should take care of your problems! Good luck.

Do you have any further questions? 

**Please respond one more time to confirm your problem is resolved so I can close this thread.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI