Advertisement
Guest User

herrwuetent_FRST.txt

a guest
Aug 20th, 2013
254
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 61.20 KB | None | 0 0
  1. Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-08-2013 04
  2. Ran by Koester (administrator) on 20-08-2013 19:47:03
  3. Running from C:\Users\Koester\Desktop
  4. Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)
  5. Internet Explorer Version 10
  6. Boot Mode: Normal
  7.  
  8. ==================== Processes (Whitelisted) =================
  9.  
  10. (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
  11. (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
  12. (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
  13. (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
  14. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
  15. (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
  16. (ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
  17. () C:\Program Files\ATKGFNEX\GFNEXSrv.exe
  18. (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
  19. (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
  20. (National Instruments Corporation) C:\Windows\SysWOW64\lkads.exe
  21. (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
  22. ( ) C:\Program Files\Autodesk\Inventor 2013\Moldflow\bin\mitsijm.exe
  23. (National Instruments Corporation) C:\Program Files (x86)\National Instruments\MAX\nimxs.exe
  24. (National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe
  25. (National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe
  26. (Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
  27. (Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
  28. () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
  29. (Raxco Software, Inc.) C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
  30. () C:\Windows\SysWOW64\PnkBstrA.exe
  31. (ATK) C:\Program files\P4G\BatteryLife.exe
  32. () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
  33. (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
  34. (National Instruments, Inc.) C:\Windows\SysWOW64\lkcitdl.exe
  35. (National Instruments Corporation) C:\Windows\SysWOW64\lktsrv.exe
  36. (National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\Tagger\tagsrv.exe
  37. (ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe
  38. (ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe
  39. (ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\KBFiltr.exe
  40. (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
  41. (ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe
  42. (National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe
  43. (National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
  44. (National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe
  45. (ASUS) C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
  46. (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
  47. (ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
  48. (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
  49. (Mozilla Corporation) C:\Program Files\Waterfox\waterfox.exe
  50.  
  51. ==================== Registry (Whitelisted) ==================
  52.  
  53. HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [7350912 2010-02-04] (ASUS)
  54. HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-01-05] (ASUS)
  55. HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
  56. HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [348624 2012-05-02] (Avira Operations GmbH & Co. KG)
  57. BootExecute: PDBoot.exeautocheck autochk *
  58.  
  59. ==================== Internet (Whitelisted) ====================
  60.  
  61. HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
  62. HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
  63. StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
  64. SearchScopes: HKCU - {F7C7A225-4F75-4291-9DA0-09ACC5116F97} URL = http://www.mysearchresults.com/search?c=4005&t=14&q={searchTerms}
  65. BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
  66. BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
  67. BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
  68. BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
  69. BHO-x32: HistoryTriggerBHO Class - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics)
  70. BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
  71. BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
  72. BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
  73. BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
  74. Toolbar: HKCU - No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
  75. Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
  76. Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
  77. Winsock: Catalog5 10 C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll [24320] (National Instruments Corporation)
  78. Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
  79. Winsock: Catalog5-x64 10 C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll [26368] (National Instruments Corporation)
  80. Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
  81.  
  82. FireFox:
  83. ========
  84. FF ProfilePath: C:\Users\Koester\AppData\Roaming\Mozilla\Firefox\Profiles\0uwboc2e.default
  85. FF Homepage: www.heise.de
  86. FF NetworkProxy: "type", 0
  87. FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll ()
  88. FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
  89. FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
  90. FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
  91. FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
  92. FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
  93. FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
  94. FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
  95. FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
  96. FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
  97. FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
  98. FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll No File
  99. FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
  100. FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
  101. FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
  102. FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
  103. FF Plugin-x32: @nitropdf.com/NitroPDF - C:\Program Files (x86)\Nitro\Pro 8\npnitromozilla.dll (Nitro PDF)
  104. FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
  105. FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
  106. FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
  107. FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
  108. FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
  109. FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
  110. FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
  111. FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\The Settlers 7 - Paths to a Kingdom\Data\Base\_Dbg\Bin\Release\orbit\npuplaypc.dll (Ubisoft)
  112. FF Extension: Adblock Plus Pop-up Addon - C:\Users\Koester\AppData\Roaming\Mozilla\Firefox\Profiles\0uwboc2e.default\Extensions\adblockpopups@jessehakanen.net
  113. FF Extension: No Name - C:\Users\Koester\AppData\Roaming\Mozilla\Firefox\Profiles\0uwboc2e.default\Extensions\staged
  114. FF Extension: adblockpopups - C:\Users\Koester\AppData\Roaming\Mozilla\Firefox\Profiles\0uwboc2e.default\Extensions\adblockpopups@jessehakanen.net.xpi
  115. FF Extension: elemhidehelper - C:\Users\Koester\AppData\Roaming\Mozilla\Firefox\Profiles\0uwboc2e.default\Extensions\elemhidehelper@adblockplus.org.xpi
  116. FF Extension: fhdp - C:\Users\Koester\AppData\Roaming\Mozilla\Firefox\Profiles\0uwboc2e.default\Extensions\fhdp@fhdp.tv.xpi
  117. FF Extension: printedit - C:\Users\Koester\AppData\Roaming\Mozilla\Firefox\Profiles\0uwboc2e.default\Extensions\printedit@DW-dev.xpi
  118. FF Extension: No Name - C:\Users\Koester\AppData\Roaming\Mozilla\Firefox\Profiles\0uwboc2e.default\Extensions\{09408840-3f84-11dd-ae16-0800200c9a66}.xpi
  119. FF Extension: No Name - C:\Users\Koester\AppData\Roaming\Mozilla\Firefox\Profiles\0uwboc2e.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
  120. FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
  121. FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
  122.  
  123. Chrome:
  124. =======
  125. Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
  126. CHR Extension: (DealPly Shopping) - C:\Users\Koester\AppData\Local\Google\Chrome\User Data\Default\Extensions\mphpbdjcljebbcnfopfngmfdackbbdgf\3.5.0.0_0
  127. CHR HKLM-x32\...\Chrome\Extension: [bkomkajifikmkfnjgphkjcfeepbnojok] - C:\Program Files (x86)\PriceGong\2.6.11\pricegong.crx
  128. CHR HKLM-x32\...\Chrome\Extension: [dednnpigldgdbpgcdpfppmlcnnbjciel] - C:\Users\Koester\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.crx
  129. CHR HKLM-x32\...\Chrome\Extension: [kkfggacklibaabdomphfdpcodjgihgon] - C:\Program Files (x86)\FirstRowSportApp.com\stv10.crx
  130. CHR HKLM-x32\...\Chrome\Extension: [lpmkgpnbiojfaoklbkpfneikocaobfai] - C:\Users\Koester\AppData\Roaming\Media Finder\Extensions\mf_plugin_gc.crx
  131. CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
  132.  
  133. ==================== Services (Whitelisted) =================
  134.  
  135. R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86224 2012-05-02] (Avira Operations GmbH & Co. KG)
  136. R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110032 2012-05-02] (Avira Operations GmbH & Co. KG)
  137. R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] ()
  138. R2 LkCitadelServer; C:\Windows\SysWOW64\lkcitdl.exe [695136 2011-05-06] (National Instruments, Inc.)
  139. R2 lkClassAds; C:\Windows\SysWOW64\lkads.exe [50328 2012-06-05] (National Instruments Corporation)
  140. R2 lkTimeSync; C:\Windows\SysWOW64\lktsrv.exe [60568 2012-06-05] (National Instruments Corporation)
  141. R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
  142. S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
  143. R2 mitsijm2013; C:\Program Files\Autodesk\Inventor 2013\Moldflow\bin\mitsijm.exe [339776 2012-01-31] ( )
  144. R2 mxssvr; C:\Program Files (x86)\National Instruments\MAX\nimxs.exe [51360 2012-05-22] (National Instruments Corporation)
  145. R2 NIApplicationWebServer; C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [53960 2012-05-22] (National Instruments Corporation)
  146. S4 NIApplicationWebServer64; C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [76488 2012-05-22] (National Instruments Corporation)
  147. R2 NIDomainService; C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe [370328 2012-06-05] (National Instruments Corporation)
  148. S3 NILM License Manager; C:\Program Files (x86)\National Instruments\Shared\License Manager\Bin\lmgrd.exe [1427688 2010-08-02] (Macrovision Corporation)
  149. R2 nimDNSResponder; C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [258776 2012-05-31] (National Instruments Corporation)
  150. R2 NINetworkDiscovery; C:\Program Files (x86)\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe [169192 2012-06-05] (National Instruments Corporation)
  151. R2 niSvcLoc; C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe [53952 2012-05-22] (National Instruments Corporation)
  152. R2 NITaggerService; C:\Program Files (x86)\National Instruments\Shared\Tagger\tagsrv.exe [680624 2012-06-07] (National Instruments Corporation)
  153. R2 NitroDriverReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [230408 2012-11-29] (Nitro PDF Software)
  154. S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [36352 2010-11-08] ()
  155. R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [80896 2011-03-31] ()
  156. R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75064 2011-10-19] ()
  157.  
  158. ==================== Drivers (Whitelisted) ====================
  159.  
  160. S3 Andbus; C:\Windows\System32\DRIVERS\lgandbus64.sys [19456 2010-12-23] (LG Electronics Inc.)
  161. S3 AndDiag; C:\Windows\System32\DRIVERS\lganddiag64.sys [27648 2010-12-23] (LG Electronics Inc.)
  162. S3 AndGps; C:\Windows\System32\DRIVERS\lgandgps64.sys [27136 2010-12-23] (LG Electronics Inc.)
  163. S3 ANDModem; C:\Windows\System32\DRIVERS\lgandmodem64.sys [34304 2010-12-23] (LG Electronics Inc.)
  164. S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2011-09-06] (Google Inc)
  165. R2 ASMMAP64; C:\Program Files\ATKGFNEX\ASMMAP64.sys [14904 2007-07-24] ()
  166. R2 ASMMAP64; C:\Program Files\ATKGFNEX\ASMMAP64.sys [14904 2007-07-24] ()
  167. R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98848 2012-04-25] (Avira GmbH)
  168. R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132832 2012-04-27] (Avira GmbH)
  169. R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [27760 2012-05-02] (Avira GmbH)
  170. S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2010-07-15] ()
  171. S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2010-07-15] ()
  172. S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2010-07-15] ()
  173. S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2010-07-15] ()
  174. R3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-19] (Siliten)
  175. R3 ITECIRfilter; C:\Windows\System32\DRIVERS\ITECIRfilter.sys [28264 2011-03-22] (ITE Tech. Inc. )
  176. R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
  177. R3 LgBttPort; C:\Windows\System32\DRIVERS\lgbtpt64.sys [16384 2009-09-29] (LG Electronics Inc.)
  178. R3 lgbusenum; C:\Windows\System32\DRIVERS\lgbtbs64.sys [14848 2009-09-29] (LG Electronics Inc.)
  179. R3 LGVMODEM; C:\Windows\System32\DRIVERS\lgvmdm64.sys [17408 2009-09-29] (LG Electronics Inc.)
  180. R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
  181. R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
  182. S3 NIEthernetDeviceEnumerator; C:\Windows\System32\DRIVERS\niede.sys [38064 2010-06-15] (National Instruments Corporation)
  183. S3 NMgamingmsFltr; C:\Windows\System32\drivers\NMgamingms.sys [11264 2009-07-24] (Primax Ltd)
  184. R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-04-11] ()
  185. S3 usbbus; C:\Windows\System32\DRIVERS\lgx64bus.sys [17920 2011-04-27] (LG Electronics Inc.)
  186. S3 UsbDiag; C:\Windows\System32\DRIVERS\lgx64diag.sys [28160 2011-04-27] (LG Electronics Inc.)
  187. S3 USBModem; C:\Windows\System32\DRIVERS\lgx64modem.sys [34816 2011-04-27] (LG Electronics Inc.)
  188. S3 WsAudio_Device; C:\Windows\System32\drivers\VirtualAudio.sys [31080 2013-01-08] (Wondershare)
  189. U3 ahr9spj4; C:\Windows\System32\Drivers\ahr9spj4.sys [0 ] (Microsoft Corporation)
  190. S3 catchme; \??\C:\ComboFix\catchme.sys [x]
  191. S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]
  192. S1 StarOpen; No ImagePath
  193. S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
  194. S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
  195. S3 VGPU; System32\drivers\rdvgkmd.sys [x]
  196. S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [x]
  197.  
  198. ========================== Drivers MD5 =======================
  199.  
  200. C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit
  201. C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit
  202. C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit
  203. C:\Windows\system32\DRIVERS\adp94xx.sys ==> MD5 is legit
  204. C:\Windows\system32\DRIVERS\adpahci.sys ==> MD5 is legit
  205. C:\Windows\system32\DRIVERS\adpu320.sys ==> MD5 is legit
  206. C:\Windows\system32\drivers\afd.sys 1C7857B62DE5994A75B054A9FD4C3825
  207. C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit
  208. C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit
  209. C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit
  210. C:\Windows\system32\DRIVERS\amdk8.sys ==> MD5 is legit
  211. C:\Windows\system32\DRIVERS\amdppm.sys ==> MD5 is legit
  212. C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49
  213. C:\Windows\system32\DRIVERS\amdsbs.sys ==> MD5 is legit
  214. C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048
  215. C:\Windows\System32\DRIVERS\lgandbus64.sys 48CD7E6520D47D62EAB0E6CE3EC30C65
  216. C:\Windows\System32\DRIVERS\lganddiag64.sys 08CBACC00D15DCDBBAAE1A7C8F231C61
  217. C:\Windows\System32\DRIVERS\lgandgps64.sys CEA9A4CD6B3A83428CE8501240833668
  218. C:\Windows\System32\DRIVERS\lgandmodem64.sys E2B5663E547FA5E756B253EFA8EC8286
  219. C:\Windows\System32\Drivers\lgandnetadb.sys FCD37C63B42352BFABC17D593745B460
  220. C:\Windows\System32\Drivers\ssadadb.sys 3CF7A4350C9646D92F147D620EC0D363
  221. C:\Windows\system32\drivers\appid.sys ==> MD5 is legit
  222. C:\Windows\system32\DRIVERS\arc.sys ==> MD5 is legit
  223. C:\Windows\system32\DRIVERS\arcsas.sys ==> MD5 is legit
  224. C:\Program Files\ATKGFNEX\ASMMAP64.sys 2DB34EDD17D3A8DA7105A19C95A3DD68
  225. C:\Program Files\ATKGFNEX\ASMMAP64.sys 2DB34EDD17D3A8DA7105A19C95A3DD68
  226. C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit
  227. C:\Windows\System32\drivers\atapi.sys ==> MD5 is legit
  228. C:\Windows\System32\DRIVERS\athrx.sys A5E770426D18F8EF332A593F3289DA91
  229. C:\Windows\System32\DRIVERS\avgntflt.sys 26E38B5A58C6C55FAFBC563EEDDB0867
  230. C:\Windows\System32\DRIVERS\avipbb.sys 9D1F00BEFF84CBBF46D7F052BC7E0565
  231. C:\Windows\System32\DRIVERS\avkmgr.sys 248DB59FC86DE44D2779F4C7FB1A567D
  232. C:\Windows\system32\DRIVERS\bxvbda.sys ==> MD5 is legit
  233. C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit
  234. C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit
  235. C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit
  236. C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit
  237. C:\Windows\system32\DRIVERS\BrFiltLo.sys ==> MD5 is legit
  238. C:\Windows\system32\DRIVERS\BrFiltUp.sys ==> MD5 is legit
  239. C:\Windows\System32\DRIVERS\bridge.sys 5C2F352A4E961D72518261257AAE204B
  240. C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit
  241. C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit
  242. C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit
  243. C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit
  244. C:\Windows\system32\drivers\BthEnum.sys CF98190A94F62E405C8CB255018B2315
  245. C:\Windows\System32\DRIVERS\bthmodem.sys ==> MD5 is legit
  246. C:\Windows\System32\DRIVERS\bthpan.sys 02DD601B708DD0667E1331FA8518E9FF
  247. C:\Windows\System32\Drivers\BTHport.sys 738D0E9272F59EB7A1449C3EC118E6C4
  248. C:\Windows\System32\Drivers\BTHUSB.sys F188B7394D81010767B6DF3178519A37
  249. C:\Windows\System32\drivers\btusbflt.sys 2641A3FE3D7B0646308F33B67F3B5300
  250. C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit
  251. C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit
  252. C:\Windows\System32\DRIVERS\circlass.sys ==> MD5 is legit
  253. C:\Windows\System32\CLFS.sys ==> MD5 is legit
  254. C:\Windows\System32\DRIVERS\CmBatt.sys ==> MD5 is legit
  255. C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit
  256. C:\Windows\System32\Drivers\cng.sys AAFCB52FE0037207FB6FBEA070D25EFE
  257. C:\Windows\System32\DRIVERS\compbatt.sys ==> MD5 is legit
  258. C:\Windows\system32\drivers\CompositeBus.sys ==> MD5 is legit
  259. C:\Windows\system32\DRIVERS\crcdisk.sys ==> MD5 is legit
  260. C:\Windows\System32\drivers\csc.sys ==> MD5 is legit
  261. C:\Windows\System32\Drivers\DefragFS.sys CEC7F24E28B40829C0FD2D523E72B5D3
  262. C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit
  263. C:\Windows\System32\drivers\discache.sys ==> MD5 is legit
  264. C:\Windows\System32\DRIVERS\disk.sys ==> MD5 is legit
  265. C:\Windows\System32\drivers\drmkaud.sys ==> MD5 is legit
  266. C:\Windows\System32\drivers\dxgkrnl.sys AF2E16242AA723F68F461B6EAE2EAD3D
  267. C:\Windows\System32\DRIVERS\E1G6032E.sys ==> MD5 is legit
  268. C:\Windows\system32\DRIVERS\evbda.sys ==> MD5 is legit
  269. C:\Windows\System32\Drivers\ElbyCDIO.sys A05FC7ECA0966EBB70E4D17B855A853B
  270. C:\Windows\system32\DRIVERS\elxstor.sys ==> MD5 is legit
  271. C:\Windows\system32\epmntdrv.sys 9EAFB3B3B60B8AD958985152A9309ACA
  272. C:\Windows\system32\epmntdrv.sys 9EAFB3B3B60B8AD958985152A9309ACA
  273. C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit
  274. C:\Windows\system32\EuGdiDrv.sys FB949ED2C93C878A189039F3D7730942
  275. C:\Windows\system32\EuGdiDrv.sys FB949ED2C93C878A189039F3D7730942
  276. C:\Windows\system32\DRIVERS\fdc.sys ==> MD5 is legit
  277. C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit
  278. C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit
  279. C:\Windows\system32\DRIVERS\flpydisk.sys ==> MD5 is legit
  280. C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit
  281. C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit
  282. C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B
  283. C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0
  284. C:\Windows\system32\DRIVERS\gagp30kx.sys ==> MD5 is legit
  285. C:\Windows\System32\DRIVERS\ggflt.sys A4198F2BD8AA592CB90476277A81B5E1
  286. C:\Windows\System32\DRIVERS\ggsemc.sys D266350BDAAB9EB6C1AEC370EEAAFF3A
  287. C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit
  288. C:\Windows\system32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A
  289. C:\Windows\system32\drivers\HDAudBus.sys ==> MD5 is legit
  290. C:\Windows\system32\DRIVERS\HidBatt.sys ==> MD5 is legit
  291. C:\Windows\system32\DRIVERS\hidbth.sys ==> MD5 is legit
  292. C:\Windows\System32\DRIVERS\hidir.sys ==> MD5 is legit
  293. C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit
  294. C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit
  295. C:\Windows\System32\Drivers\ANDROIDUSB.sys F47CEC45FB85791D4AB237563AD0FA8F
  296. C:\Windows\System32\DRIVERS\htcnprot.sys B8B1B284362E1D8135112573395D5DA5
  297. C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit
  298. C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit
  299. C:\Windows\system32\drivers\i8042prt.sys ==> MD5 is legit
  300. C:\Windows\System32\DRIVERS\iaStor.sys BBB3B6DF1ABB0FE35802EDE85CC1C011
  301. C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366
  302. C:\Windows\system32\DRIVERS\iirsp.sys ==> MD5 is legit
  303. C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys CAA8BC6737DFA3BF1A50175CFB226788
  304. C:\Windows\System32\drivers\RTKVHD64.sys F26B0F42FA499677D8938B94C2CCE7DD
  305. C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit
  306. C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit
  307. C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit
  308. C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit
  309. C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit
  310. C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit
  311. C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit
  312. C:\Windows\system32\drivers\msiscsi.sys ==> MD5 is legit
  313. C:\Windows\System32\DRIVERS\itecir.sys 8D990A44B4F2B68E2C56A3724EC3EB84
  314. C:\Windows\System32\DRIVERS\ITECIRfilter.sys E5AAC07B053D15BA8F67BA7D49C20971
  315. C:\Windows\System32\DRIVERS\ivusb.sys 2F9F76349BB8C578873A58C840BA0589
  316. C:\Windows\system32\drivers\kbdclass.sys ==> MD5 is legit
  317. C:\Windows\system32\drivers\kbdhid.sys ==> MD5 is legit
  318. C:\Windows\System32\DRIVERS\kbfiltr.sys E63EF8C3271D014F14E2469CE75FECB4
  319. C:\Windows\System32\Drivers\ksecdd.sys 97A7070AEA4C058B6418519E869A63B4
  320. C:\Windows\System32\Drivers\ksecpkg.sys 7EFB9333E4ECCE6AE4AE9D777D9E553E
  321. C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit
  322. C:\Windows\System32\DRIVERS\lgbtpt64.sys 174803F2EEA3B22165DFE0E5A1F20685
  323. C:\Windows\System32\DRIVERS\lgbtbs64.sys 565F93BB7C0361E61B3DAEA670C354D6
  324. C:\Windows\System32\DRIVERS\lgvmdm64.sys ABF477857B7CED873362EC92C6CE10A7
  325. C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit
  326. C:\Windows\system32\DRIVERS\lsi_fc.sys ==> MD5 is legit
  327. C:\Windows\system32\DRIVERS\lsi_sas.sys ==> MD5 is legit
  328. C:\Windows\system32\DRIVERS\lsi_sas2.sys ==> MD5 is legit
  329. C:\Windows\system32\DRIVERS\lsi_scsi.sys ==> MD5 is legit
  330. C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit
  331. C:\Windows\system32\drivers\mbam.sys 0BB97D43299910CBFBA59C461B99B910
  332. C:\Windows\system32\drivers\mbam.sys 0BB97D43299910CBFBA59C461B99B910
  333. C:\Windows\system32\DRIVERS\megasas.sys ==> MD5 is legit
  334. C:\Windows\system32\DRIVERS\MegaSR.sys ==> MD5 is legit
  335. C:\Windows\System32\drivers\modem.sys ==> MD5 is legit
  336. C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit
  337. C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit
  338. C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit
  339. C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit
  340. C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit
  341. C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit
  342. C:\Windows\system32\drivers\mrxdav.sys ==> MD5 is legit
  343. C:\Windows\System32\DRIVERS\mrxsmb.sys A5D9106A73DC88564C825D317CAC68AC
  344. C:\Windows\System32\DRIVERS\mrxsmb10.sys D711B3C1D5F42C0C2415687BE09FC163
  345. C:\Windows\System32\DRIVERS\mrxsmb20.sys 9423E9D355C8D303E76B8CFBD8A5C30C
  346. C:\Windows\System32\drivers\msahci.sys ==> MD5 is legit
  347. C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit
  348. C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit
  349. C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit
  350. C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit
  351. C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit
  352. C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit
  353. C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit
  354. C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit
  355. C:\Windows\system32\drivers\mssmbios.sys ==> MD5 is legit
  356. C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit
  357. C:\Windows\system32\DRIVERS\MTConfig.sys ==> MD5 is legit
  358. C:\Windows\System32\DRIVERS\ATK64AMD.sys 032D35C996F21D19A205A7C8F0B76F3C
  359. C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit
  360. C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit
  361. C:\Windows\System32\drivers\ndis.sys 760E38053BF56E501D562B70AD796B88
  362. C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit
  363. C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit
  364. C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit
  365. C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit
  366. C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit
  367. C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit
  368. C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit
  369. C:\Windows\system32\DRIVERS\nfrd960.sys ==> MD5 is legit
  370. C:\Windows\System32\DRIVERS\niede.sys 4BF901A678408022003E4DB2445F7CE8
  371. C:\Windows\System32\drivers\NMgamingms.sys FBCA3FD51604147770EB4FB53D6144A8
  372. C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit
  373. C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit
  374. C:\Windows\System32\Drivers\Ntfs.sys B98F8C6E31CD07B2E6F71F7F648E38C0
  375. C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit
  376. C:\Windows\System32\drivers\nvhda64v.sys 1F07B814C0BB5AABA703ABFF1F31F2E8
  377. C:\Windows\System32\DRIVERS\nvlddmkm.sys BA0B4889C40380A01ECDF84C227A89C9
  378. C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD
  379. C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A
  380. C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit
  381. C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit
  382. C:\Windows\system32\DRIVERS\parport.sys ==> MD5 is legit
  383. C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C
  384. C:\Windows\System32\drivers\pci.sys ==> MD5 is legit
  385. C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit
  386. C:\Windows\system32\DRIVERS\pcmcia.sys ==> MD5 is legit
  387. C:\Windows\System32\Drivers\pcouffin.sys AF7CE12C4F3DC8CB2B07685C916BBCFE
  388. C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit
  389. C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit
  390. C:\Windows\System32\DRIVERS\point64.sys 33328FA8A580885AB0065BE6DB266E9F
  391. C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit
  392. C:\Windows\system32\DRIVERS\processr.sys ==> MD5 is legit
  393. C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit
  394. C:\Windows\system32\DRIVERS\ql2300.sys ==> MD5 is legit
  395. C:\Windows\system32\DRIVERS\ql40xx.sys ==> MD5 is legit
  396. C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit
  397. C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit
  398. C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit
  399. C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit
  400. C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit
  401. C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit
  402. C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit
  403. C:\Windows\System32\DRIVERS\rdpbus.sys ==> MD5 is legit
  404. C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit
  405. C:\Windows\System32\drivers\rdpdr.sys ==> MD5 is legit
  406. C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit
  407. C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit
  408. C:\Windows\System32\drivers\rdpvideominiport.sys 313F68E1A3E6345A4F47A36B07062F34
  409. C:\Windows\System32\Drivers\RDPWD.sys E61608AA35E98999AF9AAEEEA6114B0A
  410. C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit
  411. C:\Windows\System32\DRIVERS\rfcomm.sys 3DD798846E2C28102B922C56E71B7932
  412. C:\Windows\System32\DRIVERS\rimmpx64.sys 6FAF5B04BEDC66D300D9D233B2D222F0
  413. C:\Windows\System32\DRIVERS\rimspx64.sys 67F50C31713106FD1B0F286F86AA2B2E
  414. C:\Windows\System32\DRIVERS\rixdpx64.sys 4D7EF3D46346EC4C58784DB964B365DE
  415. C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit
  416. C:\Windows\System32\DRIVERS\Rt64win7.sys EE082E06A82FF630351D1E0EBBD3D8D0
  417. C:\Windows\system32\drivers\vms3cap.sys ==> MD5 is legit
  418. C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit
  419. C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit
  420. C:\Windows\system32\drivers\sdbus.sys 111E0EBC0AD79CB0FA014B907B231CF0
  421. C:\Windows\system32\DRIVERS\serenum.sys ==> MD5 is legit
  422. C:\Windows\system32\DRIVERS\serial.sys ==> MD5 is legit
  423. C:\Windows\system32\DRIVERS\sermouse.sys ==> MD5 is legit
  424. C:\Windows\System32\DRIVERS\sffdisk.sys ==> MD5 is legit
  425. C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit
  426. C:\Windows\System32\DRIVERS\sffp_sd.sys ==> MD5 is legit
  427. C:\Windows\System32\DRIVERS\sfloppy.sys ==> MD5 is legit
  428. C:\Windows\system32\DRIVERS\SiSRaid2.sys ==> MD5 is legit
  429. C:\Windows\system32\DRIVERS\sisraid4.sys ==> MD5 is legit
  430. C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit
  431. C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit
  432. C:\Windows\System32\Drivers\sptd.sys D41D8CD98F00B204E9800998ECF8427E
  433. C:\Windows\System32\DRIVERS\srv.sys 441FBA48BFF01FDB9D5969EBC1838F0B
  434. C:\Windows\System32\DRIVERS\srv2.sys B4ADEBBF5E3677CCE9651E0F01F7CC28
  435. C:\Windows\System32\DRIVERS\srvnet.sys 27E461F0BE5BFF5FC737328F749538C3
  436. C:\Windows\System32\DRIVERS\ssadbus.sys 52D6F40B50ECFC051979FEC68E74F0F8
  437. C:\Windows\System32\DRIVERS\ssadmdfl.sys D6CFD3B2EABCF9327DE39C62BABFA1E3
  438. C:\Windows\System32\DRIVERS\ssadmdm.sys 5EB01E6148742C3EC2185AC92F6D16FD
  439. C:\Windows\System32\DRIVERS\ssadserd.sys FF20F67DD5644BD1D2E7FCD95AF7F03B
  440. C:\Windows\system32\DRIVERS\stexstor.sys ==> MD5 is legit
  441. C:\Windows\System32\drivers\vmstorfl.sys ==> MD5 is legit
  442. C:\Windows\system32\drivers\storvsc.sys ==> MD5 is legit
  443. C:\Windows\system32\drivers\swenum.sys ==> MD5 is legit
  444. C:\Windows\System32\DRIVERS\tap0901.sys 3B73C849B41FB20D77B0E553214061A5
  445. C:\Windows\System32\drivers\tcpip.sys DB74544B75566C974815E79A62433F29
  446. C:\Windows\System32\DRIVERS\tcpip.sys DB74544B75566C974815E79A62433F29
  447. C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC
  448. C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit
  449. C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8
  450. C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit
  451. C:\Windows\system32\drivers\termdd.sys ==> MD5 is legit
  452. C:\Windows\System32\DRIVERS\tssecsrv.sys 4CE278FC9671BA81A138D70823FCAA09
  453. C:\Windows\System32\drivers\tsusbflt.sys 17C6B51CBCCDED95B3CC14E22791F85E
  454. C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit
  455. C:\Windows\system32\DRIVERS\uagp35.sys ==> MD5 is legit
  456. C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit
  457. C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit
  458. C:\Windows\system32\drivers\umbus.sys ==> MD5 is legit
  459. C:\Windows\system32\DRIVERS\umpass.sys ==> MD5 is legit
  460. C:\Windows\System32\Drivers\usbaapl64.sys ==> MD5 is legit
  461. C:\Windows\System32\DRIVERS\lgx64bus.sys C85B8247FADD432FA54FE11667C8D97D
  462. C:\Windows\System32\DRIVERS\usbccgp.sys 6F1A3157A1C89435352CEB543CDB359C
  463. C:\Windows\system32\drivers\usbcir.sys ==> MD5 is legit
  464. C:\Windows\System32\DRIVERS\lgx64diag.sys D8CDC12F5429878F23DDB3785A0FDF95
  465. C:\Windows\System32\DRIVERS\usbehci.sys C025055FE7B87701EB042095DF1A2D7B
  466. C:\Windows\System32\DRIVERS\usbhub.sys 287C6C9410B111B68B52CA298F7B8C24
  467. C:\Windows\System32\DRIVERS\lgx64modem.sys 79FA7A22B0F6F0082F640CBC82A00FCE
  468. C:\Windows\system32\DRIVERS\usbohci.sys ==> MD5 is legit
  469. C:\Windows\System32\DRIVERS\usbprint.sys ==> MD5 is legit
  470. C:\Windows\System32\drivers\usbser.sys 0F0C72A657C622286013788B886968AD
  471. C:\Windows\System32\DRIVERS\USBSTOR.SYS FED648B01349A3C8395A5169DB5FB7D6
  472. C:\Windows\System32\DRIVERS\usbuhci.sys 62069A34518BCF9C1FD9E74B3F6DB7CD
  473. C:\Windows\System32\Drivers\usbvideo.sys 454800C2BC7F3927CE030141EE4F4C50
  474. C:\Windows\system32\drivers\usb8023x.sys 7B28E2FBE75115660FAB31079C0A9F29
  475. C:\Windows\System32\DRIVERS\VClone.sys FD911873C0BB6945FA38C16E9A2B58F9
  476. C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit
  477. C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit
  478. C:\Windows\System32\drivers\vga.sys ==> MD5 is legit
  479. C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit
  480. C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit
  481. C:\Windows\System32\drivers\vmbus.sys ==> MD5 is legit
  482. C:\Windows\system32\drivers\VMBusHID.sys ==> MD5 is legit
  483. C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit
  484. C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit
  485. C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit
  486. C:\Windows\system32\DRIVERS\vsmraid.sys ==> MD5 is legit
  487. C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit
  488. C:\Windows\System32\DRIVERS\vwififlt.sys ==> MD5 is legit
  489. C:\Windows\System32\DRIVERS\vwifimp.sys ==> MD5 is legit
  490. C:\Windows\system32\DRIVERS\wacompen.sys ==> MD5 is legit
  491. C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
  492. C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
  493. C:\Windows\system32\DRIVERS\wd.sys ==> MD5 is legit
  494. C:\Windows\System32\drivers\Wdf01000.sys 442783E2CB0DA19873B7A63833FF4CB4
  495. C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit
  496. C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit
  497. C:\Windows\SysWow64\drivers\wimmount.sys ==> MD5 is legit
  498. C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D
  499. C:\Windows\system32\drivers\wmiacpi.sys ==> MD5 is legit
  500. C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit
  501. C:\Windows\System32\drivers\VirtualAudio.sys ADD2FE1A9F4EE41A6D724819550D4E1F
  502. C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F
  503. C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659
  504. C:\Windows\System32\Drivers\ahr9spj4.sys
  505.  
  506. ==================== NetSvcs (Whitelisted) ===================
  507.  
  508.  
  509. ==================== One Month Created Files and Folders ========
  510.  
  511. 2013-08-20 19:45 - 2013-08-20 19:45 - 00358507 _____ (Farbar) C:\Users\Koester\Desktop\FSS.exe
  512. 2013-08-20 19:44 - 2013-08-20 19:44 - 01576208 _____ (Farbar) C:\Users\Koester\Desktop\FRST64.exe
  513. 2013-08-20 19:28 - 2013-08-20 19:28 - 00026395 _____ C:\ComboFix.txt
  514. 2013-08-20 19:12 - 2013-08-20 19:12 - 00000552 _____ C:\Windows\PFRO.log
  515. 2013-08-20 18:02 - 2013-08-20 19:29 - 00000000 ____D C:\Qoobox
  516. 2013-08-20 18:02 - 2013-08-20 18:29 - 00000000 ____D C:\Windows\erdnt
  517. 2013-08-20 18:02 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
  518. 2013-08-20 18:02 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
  519. 2013-08-20 18:02 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
  520. 2013-08-20 18:02 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
  521. 2013-08-20 18:02 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
  522. 2013-08-20 18:02 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
  523. 2013-08-20 18:02 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
  524. 2013-08-20 18:02 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
  525. 2013-08-20 18:01 - 2013-08-20 17:58 - 05106564 ____R (Swearware) C:\Users\Koester\Desktop\ComboFix.exe
  526. 2013-08-20 16:42 - 2013-08-20 16:52 - 00176538 _____ C:\Users\Koester\Desktop\OTL.Txt
  527. 2013-08-20 13:09 - 2013-08-20 13:18 - 00000000 ____D C:\AdwCleaner
  528. 2013-08-20 13:08 - 2013-08-20 13:09 - 00800594 _____ C:\Users\Koester\Downloads\adwcleaner.exe
  529. 2013-08-20 13:06 - 2013-08-20 13:06 - 00584600 _____ C:\Users\Koester\Desktop\cbsidlm-tr1_14-AdwCleaner-ORG-75851221.exe
  530. 2013-08-20 13:02 - 2013-08-20 13:02 - 04745728 _____ (AVAST Software) C:\Users\Koester\Desktop\aswMBR-1.exe
  531. 2013-08-20 13:02 - 2013-08-20 13:02 - 00666633 _____ C:\Users\Koester\Desktop\2-adwcleaner.bin
  532. 2013-08-20 12:05 - 2013-08-20 17:40 - 00001064 _____ C:\Users\Koester\Desktop\Crashreport.txt
  533. 2013-08-20 10:55 - 2013-08-20 10:55 - 00085040 _____ C:\Users\Koester\Desktop\Extras.Txt
  534. 2013-08-20 10:32 - 2013-08-20 10:29 - 00602112 _____ (OldTimer Tools) C:\Users\Koester\Desktop\OTL.exe
  535. 2013-08-20 09:53 - 2013-08-20 09:53 - 00000000 ____D C:\Users\Koester\AppData\Roaming\Avira
  536. 2013-08-20 09:48 - 2013-08-20 09:48 - 00002036 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
  537. 2013-08-20 09:48 - 2013-08-20 09:48 - 00000000 ____D C:\ProgramData\Avira
  538. 2013-08-20 09:48 - 2013-08-20 09:48 - 00000000 ____D C:\Program Files (x86)\Avira
  539. 2013-08-20 09:48 - 2012-05-02 15:24 - 00027760 _____ (Avira GmbH) C:\Windows\system32\Drivers\avkmgr.sys
  540. 2013-08-20 09:48 - 2012-04-27 10:20 - 00132832 _____ (Avira GmbH) C:\Windows\system32\Drivers\avipbb.sys
  541. 2013-08-20 09:48 - 2012-04-25 00:32 - 00098848 _____ (Avira GmbH) C:\Windows\system32\Drivers\avgntflt.sys
  542. 2013-08-20 09:45 - 2013-08-20 09:45 - 00011589 _____ C:\Users\Koester\Desktop\hijackthis2.log
  543. 2013-08-19 17:54 - 2013-08-19 17:54 - 00001079 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
  544. 2013-08-19 14:04 - 2013-08-19 14:04 - 00000000 ____D C:\Users\Koester\AppData\Roaming\Malwarebytes
  545. 2013-08-19 14:03 - 2013-08-19 20:24 - 00000000 ____D C:\Users\Koester\Desktop\Malwarebytes.Anti-Malware.v1.50.MULTILINGUAL.WORKING-CRD
  546. 2013-08-19 12:57 - 2013-08-20 13:08 - 00000000 ____D C:\Users\Koester\AppData\Local\Google
  547. 2013-08-17 06:44 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
  548. 2013-08-17 06:44 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
  549. 2013-08-17 06:44 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
  550. 2013-08-17 06:44 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
  551. 2013-08-17 06:44 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
  552. 2013-08-17 06:44 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
  553. 2013-08-17 06:44 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
  554. 2013-08-17 06:44 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
  555. 2013-08-17 06:44 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
  556. 2013-08-17 06:44 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
  557. 2013-08-17 06:44 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
  558. 2013-08-16 19:44 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
  559. 2013-08-16 19:44 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
  560. 2013-08-16 19:44 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
  561. 2013-08-16 19:44 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
  562. 2013-08-16 19:44 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
  563. 2013-08-16 19:44 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
  564. 2013-08-16 19:44 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
  565. 2013-08-16 19:44 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
  566. 2013-08-16 19:44 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
  567. 2013-08-16 19:44 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
  568. 2013-08-16 19:44 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
  569. 2013-08-16 19:44 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
  570. 2013-08-16 19:44 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
  571. 2013-08-16 19:44 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
  572. 2013-08-16 19:44 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
  573. 2013-08-16 19:44 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
  574. 2013-08-16 19:44 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
  575. 2013-08-16 19:44 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
  576. 2013-08-16 19:44 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
  577. 2013-08-16 19:44 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
  578. 2013-08-16 19:44 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
  579. 2013-08-16 19:44 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
  580. 2013-08-16 19:44 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
  581. 2013-08-16 19:44 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
  582. 2013-08-16 19:44 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
  583. 2013-08-16 19:44 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
  584. 2013-08-16 19:44 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
  585. 2013-08-16 19:44 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
  586. 2013-08-16 19:44 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
  587. 2013-08-16 19:44 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
  588. 2013-08-16 19:44 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
  589. 2013-08-16 19:30 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
  590. 2013-08-16 19:30 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
  591. 2013-08-16 19:30 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
  592. 2013-08-16 19:30 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
  593. 2013-08-16 19:30 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
  594. 2013-08-16 19:30 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
  595. 2013-08-16 19:30 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
  596. 2013-08-16 19:30 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
  597. 2013-08-16 19:30 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
  598. 2013-08-16 19:30 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
  599. 2013-08-16 19:30 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
  600. 2013-08-16 19:30 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
  601. 2013-08-16 19:29 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
  602. 2013-08-16 19:29 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
  603. 2013-08-16 19:29 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
  604. 2013-08-16 19:28 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
  605. 2013-08-12 07:58 - 2013-08-12 07:58 - 00000000 ____D C:\Program Files\Common Files\EPSON
  606. 2013-08-12 07:56 - 2009-10-01 03:01 - 00088064 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\E_IBCBGCE.DLL
  607. 2013-08-12 07:56 - 2008-11-12 03:00 - 00118784 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\E_ILMGCE.DLL
  608. 2013-08-12 07:56 - 2007-04-10 01:06 - 00010752 _____ (SEIKO EPSON CORP.) C:\Windows\system32\E_GCINST.DLL
  609. 2013-08-12 07:55 - 2013-08-12 07:58 - 00000000 ____D C:\ProgramData\EPSON
  610. 2013-08-12 07:55 - 2013-08-12 07:55 - 17026048 _____ C:\Users\Koester\Downloads\epson375000eu.exe
  611. 2013-08-04 00:04 - 2013-08-03 18:22 - 1992904476 _____ C:\Users\Koester\Desktop\ddlsource.com_Red 2.2013.TS.Xvid-EXTRA.avi
  612. 2013-07-26 00:29 - 2013-08-20 19:13 - 00004190 _____ C:\Windows\setupact.log
  613. 2013-07-26 00:29 - 2013-07-26 00:29 - 00000000 _____ C:\Windows\setuperr.log
  614.  
  615. ==================== One Month Modified Files and Folders =======
  616.  
  617. 2013-08-20 19:46 - 2013-08-20 19:46 - 00000000 ____D C:\FRST
  618. 2013-08-20 19:45 - 2013-08-20 19:45 - 00358507 _____ (Farbar) C:\Users\Koester\Desktop\FSS.exe
  619. 2013-08-20 19:44 - 2013-08-20 19:44 - 01576208 _____ (Farbar) C:\Users\Koester\Desktop\FRST64.exe
  620. 2013-08-20 19:29 - 2013-08-20 18:02 - 00000000 ____D C:\Qoobox
  621. 2013-08-20 19:28 - 2013-08-20 19:28 - 00026395 _____ C:\ComboFix.txt
  622. 2013-08-20 19:18 - 2009-07-14 06:45 - 00023280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
  623. 2013-08-20 19:18 - 2009-07-14 06:45 - 00023280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
  624. 2013-08-20 19:17 - 2010-09-28 13:19 - 01726779 _____ C:\Windows\WindowsUpdate.log
  625. 2013-08-20 19:14 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
  626. 2013-08-20 19:13 - 2013-07-26 00:29 - 00004190 _____ C:\Windows\setupact.log
  627. 2013-08-20 19:13 - 2010-04-15 19:48 - 00000000 ____D C:\ProgramData\NVIDIA
  628. 2013-08-20 19:13 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
  629. 2013-08-20 19:12 - 2013-08-20 19:12 - 00000552 _____ C:\Windows\PFRO.log
  630. 2013-08-20 18:56 - 2013-03-17 22:36 - 00000000 ____D C:\Users\Koester\AppData\Roaming\vlc
  631. 2013-08-20 18:32 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
  632. 2013-08-20 18:29 - 2013-08-20 18:02 - 00000000 ____D C:\Windows\erdnt
  633. 2013-08-20 18:02 - 2009-07-14 07:08 - 00032620 _____ C:\Windows\Tasks\SCHEDLGU.TXT
  634. 2013-08-20 18:00 - 2012-02-17 13:43 - 00000000 ____D C:\Users\Koester\AppData\Roaming\Dropbox
  635. 2013-08-20 17:58 - 2013-08-20 18:01 - 05106564 ____R (Swearware) C:\Users\Koester\Desktop\ComboFix.exe
  636. 2013-08-20 17:40 - 2013-08-20 12:05 - 00001064 _____ C:\Users\Koester\Desktop\Crashreport.txt
  637. 2013-08-20 16:52 - 2013-08-20 16:42 - 00176538 _____ C:\Users\Koester\Desktop\OTL.Txt
  638. 2013-08-20 13:18 - 2013-08-20 13:09 - 00000000 ____D C:\AdwCleaner
  639. 2013-08-20 13:09 - 2013-08-20 13:08 - 00800594 _____ C:\Users\Koester\Downloads\adwcleaner.exe
  640. 2013-08-20 13:09 - 2010-04-11 19:03 - 00000000 ___RD C:\Users\Koester\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
  641. 2013-08-20 13:08 - 2013-08-19 12:57 - 00000000 ____D C:\Users\Koester\AppData\Local\Google
  642. 2013-08-20 13:07 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Resources
  643. 2013-08-20 13:06 - 2013-08-20 13:06 - 00584600 _____ C:\Users\Koester\Desktop\cbsidlm-tr1_14-AdwCleaner-ORG-75851221.exe
  644. 2013-08-20 13:02 - 2013-08-20 13:02 - 04745728 _____ (AVAST Software) C:\Users\Koester\Desktop\aswMBR-1.exe
  645. 2013-08-20 13:02 - 2013-08-20 13:02 - 00666633 _____ C:\Users\Koester\Desktop\2-adwcleaner.bin
  646. 2013-08-20 10:55 - 2013-08-20 10:55 - 00085040 _____ C:\Users\Koester\Desktop\Extras.Txt
  647. 2013-08-20 10:29 - 2013-08-20 10:32 - 00602112 _____ (OldTimer Tools) C:\Users\Koester\Desktop\OTL.exe
  648. 2013-08-20 09:53 - 2013-08-20 09:53 - 00000000 ____D C:\Users\Koester\AppData\Roaming\Avira
  649. 2013-08-20 09:48 - 2013-08-20 09:48 - 00002036 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
  650. 2013-08-20 09:48 - 2013-08-20 09:48 - 00000000 ____D C:\ProgramData\Avira
  651. 2013-08-20 09:48 - 2013-08-20 09:48 - 00000000 ____D C:\Program Files (x86)\Avira
  652. 2013-08-20 09:45 - 2013-08-20 09:45 - 00011589 _____ C:\Users\Koester\Desktop\hijackthis2.log
  653. 2013-08-20 09:44 - 2011-11-19 12:59 - 00000000 ____D C:\Users\Koester\Desktop\Tools
  654. 2013-08-19 20:24 - 2013-08-19 14:03 - 00000000 ____D C:\Users\Koester\Desktop\Malwarebytes.Anti-Malware.v1.50.MULTILINGUAL.WORKING-CRD
  655. 2013-08-19 20:24 - 2013-03-23 11:30 - 00000000 ____D C:\Program Files (x86)\Orcs Must Die!
  656. 2013-08-19 17:55 - 2010-12-12 17:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
  657. 2013-08-19 17:54 - 2013-08-19 17:54 - 00001079 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
  658. 2013-08-19 14:04 - 2013-08-19 14:04 - 00000000 ____D C:\Users\Koester\AppData\Roaming\Malwarebytes
  659. 2013-08-19 13:32 - 2013-02-18 08:51 - 00011924 _____ C:\Users\Koester\Desktop\hijackthis.log
  660. 2013-08-19 13:02 - 2012-03-29 13:09 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
  661. 2013-08-19 13:02 - 2011-05-27 18:16 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
  662. 2013-08-19 12:57 - 2010-05-07 01:24 - 00000000 ____D C:\Program Files (x86)\Google
  663. 2013-08-17 08:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
  664. 2013-08-16 19:38 - 2010-04-12 01:58 - 00697842 _____ C:\Windows\system32\perfh007.dat
  665. 2013-08-16 19:38 - 2010-04-12 01:58 - 00148874 _____ C:\Windows\system32\perfc007.dat
  666. 2013-08-16 19:38 - 2009-07-14 07:13 - 01640804 _____ C:\Windows\system32\PerfStringBackup.INI
  667. 2013-08-16 19:33 - 2013-07-12 08:00 - 00000000 ____D C:\Windows\system32\MRT
  668. 2013-08-16 19:31 - 2010-02-10 08:16 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
  669. 2013-08-12 07:58 - 2013-08-12 07:58 - 00000000 ____D C:\Program Files\Common Files\EPSON
  670. 2013-08-12 07:58 - 2013-08-12 07:55 - 00000000 ____D C:\ProgramData\EPSON
  671. 2013-08-12 07:55 - 2013-08-12 07:55 - 17026048 _____ C:\Users\Koester\Downloads\epson375000eu.exe
  672. 2013-08-03 18:22 - 2013-08-04 00:04 - 1992904476 _____ C:\Users\Koester\Desktop\ddlsource.com_Red 2.2013.TS.Xvid-EXTRA.avi
  673. 2013-07-31 20:33 - 2013-06-02 18:20 - 00000000 ____D C:\Users\Koester\AppData\Roaming\Winamp
  674. 2013-07-29 08:24 - 2010-04-11 19:30 - 00000000 ____D C:\Users\Koester\Desktop\JDownloader 0.8.9
  675. 2013-07-26 07:13 - 2013-08-16 19:44 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
  676. 2013-07-26 07:13 - 2013-08-16 19:44 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
  677. 2013-07-26 07:13 - 2013-08-16 19:44 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
  678. 2013-07-26 07:12 - 2013-08-16 19:44 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
  679. 2013-07-26 07:12 - 2013-08-16 19:44 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
  680. 2013-07-26 07:12 - 2013-08-16 19:44 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
  681. 2013-07-26 07:12 - 2013-08-16 19:44 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
  682. 2013-07-26 07:12 - 2013-08-16 19:44 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
  683. 2013-07-26 07:12 - 2013-08-16 19:44 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
  684. 2013-07-26 07:12 - 2013-08-16 19:44 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
  685. 2013-07-26 07:12 - 2013-08-16 19:44 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
  686. 2013-07-26 07:12 - 2013-08-16 19:44 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
  687. 2013-07-26 07:12 - 2013-08-16 19:44 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
  688. 2013-07-26 07:12 - 2013-08-16 19:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
  689. 2013-07-26 05:35 - 2013-08-16 19:44 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
  690. 2013-07-26 05:13 - 2013-08-16 19:44 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
  691. 2013-07-26 05:13 - 2013-08-16 19:44 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
  692. 2013-07-26 05:12 - 2013-08-16 19:44 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
  693. 2013-07-26 05:12 - 2013-08-16 19:44 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
  694. 2013-07-26 05:12 - 2013-08-16 19:44 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
  695. 2013-07-26 05:12 - 2013-08-16 19:44 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
  696. 2013-07-26 05:12 - 2013-08-16 19:44 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
  697. 2013-07-26 05:12 - 2013-08-16 19:44 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
  698. 2013-07-26 05:12 - 2013-08-16 19:44 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
  699. 2013-07-26 05:12 - 2013-08-16 19:44 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
  700. 2013-07-26 05:12 - 2013-08-16 19:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
  701. 2013-07-26 05:11 - 2013-08-16 19:44 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
  702. 2013-07-26 05:11 - 2013-08-16 19:44 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
  703. 2013-07-26 04:49 - 2013-08-16 19:44 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
  704. 2013-07-26 04:39 - 2013-08-16 19:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
  705. 2013-07-26 03:59 - 2013-08-16 19:44 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
  706. 2013-07-26 00:29 - 2013-07-26 00:29 - 00000000 _____ C:\Windows\setuperr.log
  707. 2013-07-25 11:25 - 2013-08-16 19:30 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
  708. 2013-07-25 10:57 - 2013-08-16 19:30 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
  709. 2013-07-22 23:08 - 2010-04-18 03:32 - 00000000 ____D C:\Windows\Minidump
  710. 2013-07-21 21:26 - 2013-06-02 18:32 - 00000000 ____D C:\Users\Koester\AppData\Roaming\MediaMonkey
  711.  
  712. ==================== Bamital & volsnap Check =================
  713.  
  714. C:\Windows\System32\winlogon.exe => MD5 is legit
  715. C:\Windows\System32\wininit.exe => MD5 is legit
  716. C:\Windows\SysWOW64\wininit.exe => MD5 is legit
  717. C:\Windows\explorer.exe => MD5 is legit
  718. C:\Windows\SysWOW64\explorer.exe => MD5 is legit
  719. C:\Windows\System32\svchost.exe => MD5 is legit
  720. C:\Windows\SysWOW64\svchost.exe => MD5 is legit
  721. C:\Windows\System32\services.exe => MD5 is legit
  722. C:\Windows\System32\User32.dll => MD5 is legit
  723. C:\Windows\SysWOW64\User32.dll => MD5 is legit
  724. C:\Windows\System32\userinit.exe => MD5 is legit
  725. C:\Windows\SysWOW64\userinit.exe => MD5 is legit
  726. C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
  727.  
  728. ==================== BCD ================================
  729.  
  730. Windows-Start-Manager
  731. ---------------------
  732. Bezeichner {bootmgr}
  733. device partition=C:
  734. description Windows Boot Manager
  735. locale en-US
  736. inherit {globalsettings}
  737. default {current}
  738. resumeobject {853fb1a6-45de-11df-97e1-cf38b467fcf9}
  739. displayorder {current}
  740. toolsdisplayorder {memdiag}
  741. timeout 30
  742.  
  743. Windows-Startladeprogramm
  744. -------------------------
  745. Bezeichner {current}
  746. device partition=C:
  747. path \Windows\system32\winload.exe
  748. description Windows 7
  749. locale en-US
  750. inherit {bootloadersettings}
  751. recoverysequence {853fb1a8-45de-11df-97e1-cf38b467fcf9}
  752. recoveryenabled Yes
  753. osdevice partition=C:
  754. systemroot \Windows
  755. resumeobject {853fb1a6-45de-11df-97e1-cf38b467fcf9}
  756. nx OptIn
  757.  
  758. Windows-Startladeprogramm
  759. -------------------------
  760. Bezeichner {853fb1a8-45de-11df-97e1-cf38b467fcf9}
  761. device ramdisk=[C:]\Recovery\853fb1a8-45de-11df-97e1-cf38b467fcf9\Winre.wim,{853fb1a9-45de-11df-97e1-cf38b467fcf9}
  762. path \windows\system32\winload.exe
  763. description Windows Recovery Environment
  764. inherit {bootloadersettings}
  765. osdevice ramdisk=[C:]\Recovery\853fb1a8-45de-11df-97e1-cf38b467fcf9\Winre.wim,{853fb1a9-45de-11df-97e1-cf38b467fcf9}
  766. systemroot \windows
  767. nx OptIn
  768. winpe Yes
  769.  
  770. Wiederaufnahme aus dem Ruhezustand
  771. ----------------------------------
  772. Bezeichner {853fb1a6-45de-11df-97e1-cf38b467fcf9}
  773. device partition=C:
  774. path \Windows\system32\winresume.exe
  775. description Windows Resume Application
  776. locale en-US
  777. inherit {resumeloadersettings}
  778. filedevice partition=C:
  779. filepath \hiberfil.sys
  780. debugoptionenabled No
  781.  
  782. Windows-Speichertestprogramm
  783. ----------------------------
  784. Bezeichner {memdiag}
  785. device partition=C:
  786. path \boot\memtest.exe
  787. description Windows Memory Diagnostic
  788. locale en-US
  789. inherit {globalsettings}
  790. badmemoryaccess Yes
  791.  
  792. EMS-Einstellungen
  793. -----------------
  794. Bezeichner {emssettings}
  795. bootems Yes
  796.  
  797. Debuggereinstellungen
  798. ---------------------
  799. Bezeichner {dbgsettings}
  800. debugtype Serial
  801. debugport 1
  802. baudrate 115200
  803.  
  804. RAM-Defekte
  805. -----------
  806. Bezeichner {badmemory}
  807.  
  808. Globale Einstellungen
  809. ---------------------
  810. Bezeichner {globalsettings}
  811. inherit {dbgsettings}
  812. {emssettings}
  813. {badmemory}
  814.  
  815. Startladeprogramm-Einstellungen
  816. -------------------------------
  817. Bezeichner {bootloadersettings}
  818. inherit {globalsettings}
  819. {hypervisorsettings}
  820.  
  821. Hypervisoreinstellungen
  822. -------------------
  823. Bezeichner {hypervisorsettings}
  824. hypervisordebugtype Serial
  825. hypervisordebugport 1
  826. hypervisorbaudrate 115200
  827.  
  828. Einstellungen zur Ladeprogrammfortsetzung
  829. -----------------------------------------
  830. Bezeichner {resumeloadersettings}
  831. inherit {globalsettings}
  832.  
  833. Ger„teoptionen
  834. --------------
  835. Bezeichner {853fb1a9-45de-11df-97e1-cf38b467fcf9}
  836. description Ramdisk Options
  837. ramdisksdidevice partition=C:
  838. ramdisksdipath \Recovery\853fb1a8-45de-11df-97e1-cf38b467fcf9\boot.sdi
  839.  
  840.  
  841.  
  842. LastRegBack: 2013-08-12 02:55
  843.  
  844. ==================== End Of Log ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement