OTL logfile created on: 10/11/2013 1:25:40 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Star\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.16 Gb Total Physical Memory | 2.90 Gb Available Physical Memory | 91.66% Memory free
7.17 Gb Paging File | 7.09 Gb Available in Paging File | 98.87% Paging File free
Paging file location(s): C:\pagefile.sys 0 0F:\pagefile.sys 1024 1024 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.93 Gb Total Space | 27.92 Gb Free Space | 69.91% Space Free | Partition Type: NTFS
Drive D: | 29.30 Gb Total Space | 9.49 Gb Free Space | 32.37% Space Free | Partition Type: NTFS
Drive E: | 15.63 Gb Total Space | 2.99 Gb Free Space | 19.11% Space Free | Partition Type: NTFS
Drive F: | 29.30 Gb Total Space | 5.33 Gb Free Space | 18.20% Space Free | Partition Type: NTFS
Drive G: | 2.87 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 14.90 Gb Total Space | 8.94 Gb Free Space | 60.02% Space Free | Partition Type: FAT32
Computer Name: STAR43715 | User Name: Star | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/10/11 11:23:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Star\Desktop\OTL.exe
PRC - [2008/07/03 04:38:24 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- h:\e5500 xp drivers (cab)\e5500\xp\x86\audio\r267815\wdm\stacsv.exe -- (STacSV)
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - [2012/11/29 06:50:25 | 003,463,080 | ---- | M] (TeamViewer GmbH) [Auto | Stopped] -- C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2012/03/06 01:45:36 | 000,198,520 | ---- | M] (Juniper Networks, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe -- (JuniperAccessService)
SRV - [2011/08/10 08:13:48 | 000,208,896 | ---- | M] () [Disabled | Stopped] -- C:\Programme\OnlineUpdateBG\schedservicemain.exe -- (oubgschedservice)
SRV - [2011/03/09 12:04:12 | 000,326,616 | ---- | M] (Transaction Software, D 81829 Munich) [Auto | Stopped] -- C:\Programme\ewa\database\TransBase WIS\tbmux32.exe -- (EWA net DB WIS)
SRV - [2011/03/09 12:04:12 | 000,326,616 | ---- | M] (Transaction Software, D 81829 Munich) [Auto | Stopped] -- C:\Programme\ewa\database\TransBase EWA\tbmux32.exe -- (EWA net DB Core)
SRV - [2010/02/10 18:50:50 | 000,072,296 | ---- | M] (O2Micro International) [Auto | Stopped] -- C:\WINDOWS\system32\drivers\o2flash.exe -- (O2FLASH)
SRV - [2007/11/27 13:33:52 | 000,417,792 | ---- | M] (Transaction Software, D 81829 Munich) [Auto | Stopped] -- C:\Programme\ewa\database\TransBase EPC\tbmux32.exe -- (EWA net DB EPC)
SRV - [2006/09/02 16:36:33 | 002,528,960 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE -- (LiveUpdate)
SRV - [2004/11/16 17:07:26 | 000,094,208 | ---- | M] (KoDiSys GmbH) [Auto | Stopped] -- C:\WINDOWS\zak\service.exe -- (SDImpersonationService)
SRV - [2004/10/25 11:00:52 | 000,007,680 | ---- | M] (Gigatronik) [Auto | Stopped] -- c:\Programme\HardwareAssistent\HWAssistentService.exe -- (HWAssistentService)
SRV - [2003/07/31 19:29:04 | 000,065,536 | ---- | M] (Alexandria Software Consulting) [Auto | Stopped] -- C:\Programme\ewa\server\bin\tomcat.exe -- (EWA net Server)
SRV - [2003/04/18 19:06:26 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\srvany.exe -- (O2SDIOAssist)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\wudfrd.sys -- (WudfRd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\WudfPf.sys -- (WudfPf)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\HSF_CNXT.sys -- (winachsf)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\vmxnet.sys -- (vmxnet)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\vmx_svga.sys -- (vmx_svga)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\vmmouse.sys -- (vmmouse)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\vmci.sys -- (vmci)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\TrueSight.sys -- (TrueSight)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | Auto | Stopped] -- system32\DRIVERS\mdmxsdk.sys -- (mdmxsdk)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- C:\DOCUME~1\Star\LOCALS~1\Temp\Mydrivers32.SYS -- (HWiNFO32)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\HSFHWAZL.sys -- (HSFHWAZL)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\HSF_DPV.sys -- (HSF_DPV)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\oz776.sys -- (guardian2)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Accelern.sys -- (Acceler)
DRV - [2013/10/09 13:48:57 | 000,048,728 | ---- | M] (MalwareBytes) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamchameleon.sys -- (mbamchameleon)
DRV - [2012/08/17 12:40:12 | 000,721,904 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2012/07/11 17:20:36 | 000,116,224 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV - [2012/07/11 17:20:34 | 006,650,752 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETwNx32.sys -- (NETwNx32)
DRV - [2012/07/11 17:20:22 | 001,656,499 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2012/07/11 17:20:22 | 000,048,128 | ---- | M] (REDC) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2012/07/11 17:20:20 | 000,113,664 | ---- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AESTAud.sys -- (AESTAud)
DRV - [2012/04/13 12:05:06 | 000,073,096 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftser2k.sys -- (FTSER2K)
DRV - [2012/02/15 12:00:28 | 003,369,984 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2011/03/23 14:51:56 | 000,063,976 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\o2sdjxp.sys -- (O2SDJRDR)
DRV - [2011/01/26 15:48:50 | 000,229,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2011/01/04 03:58:42 | 000,061,728 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\o2mdrxp.sys -- (O2MDRRDR)
DRV - [2010/10/19 16:33:40 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HECI.sys -- (MEI)
DRV - [2010/10/15 09:29:16 | 000,260,864 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\IntcDAud.sys -- (IntcDAud)
DRV - [2010/10/07 13:11:38 | 006,609,920 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETwLx32.sys -- (NETwLx32)
DRV - [2009/08/14 14:24:07 | 000,017,968 | R--- | M] (VMware, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\vmscsi.sys -- (vmscsi)
DRV - [2007/06/27 13:05:52 | 000,053,184 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2004/06/08 16:35:00 | 000,030,208 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Stopped] -- C:\Programme\Temp\JidaN.sys -- (JidaN)
DRV - [2001/08/17 13:17:44 | 000,042,432 | ---- | M] (Digi International, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\digirlpt.sys -- (DIGIRPS)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Update_Check_Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-343818398-861567501-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-343818398-861567501-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://aftersales.I.daimler.com
IE - HKU\S-1-5-21-343818398-861567501-725345543-1003\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-343818398-861567501-725345543-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search
IE - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\npctrl.1.0.30716.0.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\
O1 HOSTS File: ([2013/10/10 18:36:59 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (WebCGMHlprObj Class) - {56B38F40-4E70-11d4-A076-0080AD86BA2F} - C:\WINDOWS\system32\cgmopenbho.dll (CGM Open Consortium, Inc.)
O4 - HKLM..\Run: [BWK] c:\programme\BWK\Startup.lnk ()
O4 - HKLM..\Run: [HotFixInstaller] C:\Programme\HotFixInst\HotfixInst.exe (GIGATRONIK Stuttgart GmbH)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LaunchComServer] C:\Program Files\SDconnect Toolkit\bin\TKTray.exe (I+ME ACTIA GmbH, DE, Braunschweig)
O4 - HKLM..\Run: [SDNC] C:\Programme\SDnetControl\SDNC.exe (GIGATRONIK Stuttgart GmbH)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKU\S-1-5-21-343818398-861567501-725345543-1003..\Run: [SDprinterConfig] C:\Programme\SDprinterConfig\SDprinterConfig.exe (GIGATRONIK Stuttgart GmbH)
O4 - HKU\S-1-5-21-343818398-861567501-725345543-1003..\Run: [StarInsecure] C:\WINDOWS\StarInsecure\hstart.exe (NTWind Software)
O4 - HKU\S-1-5-21-343818398-861567501-725345543-1003..\RunOnce: [Report] C:\AdwCleaner\AdwCleaner[S0].txt ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\IEDevTools present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Security present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\SQM present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Suggested Sites present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\IEDevTools present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Security present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\SQM present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Suggested Sites present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\IEDevTools present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Security present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\SQM present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Suggested Sites present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\IEDevTools present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Security present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\SQM present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Suggested Sites present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\IEDevTools present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Security present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\SQM present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Suggested Sites present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKLM\..Trusted Domains: daimler.com ([]* in Trusted sites)
O15 - HKLM\..Trusted Domains: daimler.com ([*.I] * in Trusted sites)
O15 - HKLM\..Trusted Domains: dccac.net ([www] * in Trusted sites)
O15 - HKLM\..Trusted Domains: mercedes-benz.com ([ewa-brasil] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mercedes-benz.com ([retailfactory] * in Trusted sites)
O15 - HKLM\..Trusted Domains: mercedes-benz.com ([retailfactory2] * in Trusted sites)
O15 - HKLM\..Trusted Domains: mercedes-benz-mobile.com ([www] http in Trusted sites)
O15 - HKLM\..Trusted Domains: startekinfo.com ([www] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: daimler.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: daimler.com ([*.I] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: dccac.net ([www] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: evobus.com ([*] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: mercedes-amg.com ([*] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: mercedes-benz.com ([ewa-brasil] http in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: mercedes-benz.com ([retailfactory] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: mercedes-benz.com ([retailfactory2] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: mercedes-benz-mobile.com ([www] http in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: servicecode.net ([*] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: startekinfo.com ([www] * in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupControlXP Class)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 205.171.2.65
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1710BAF9-63EA-466A-802B-8FACFAC57DAA}: DhcpNameServer = 192.168.0.1 205.171.2.65
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1CFDA05D-9B30-4048-926E-9765644CE039}: DhcpNameServer = 192.168.0.1 205.171.2.65
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{25B05A5C-CA65-437F-9890-FC01F87D3A45}: DhcpNameServer = 202.96.128.166 202.96.134.133
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BCE70BE3-A753-49B6-8C38-AD91DE2E2C74}: DhcpNameServer = 192.168.0.1 205.171.2.65
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EF053F6B-6113-4261-B905-06D24EF2AAD0}: DhcpNameServer = 192.168.0.1 205.171.2.65
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Star\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Star\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/06/22 15:55:26 | 000,000,024 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2013/10/08 15:02:32 | 000,000,059 | RHS- | M] () - H:\autorun.inf -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/10/11 13:24:23 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Star\Desktop\OTL.exe
[2013/10/11 13:14:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2013/10/11 13:13:35 | 001,032,220 | ---- | C] (Thisisu) -- C:\Documents and Settings\Star\Desktop\JRT.exe
[2013/10/11 13:05:16 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013/10/10 18:37:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\logs
[2013/10/10 18:35:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2013/10/10 18:31:55 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013/10/10 15:32:44 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2013/10/10 15:28:59 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2013/10/10 13:57:16 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2013/10/10 13:57:16 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2013/10/10 13:57:16 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2013/10/10 13:57:16 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2013/10/10 13:57:05 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/10/10 13:56:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2013/10/10 13:53:14 | 005,131,844 | R--- | C] (Swearware) -- C:\Documents and Settings\Star\Desktop\ComboFix.exe
[2013/10/09 13:48:57 | 000,048,728 | ---- | C] (MalwareBytes) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2013/10/09 11:43:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Star\Desktop\RK_Quarantine
[2013/10/09 11:04:07 | 000,000,000 | ---D | C] -- C:\$AVG
[2013/10/09 10:46:36 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2013/10/09 10:45:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2013/10/08 16:38:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Star\Start Menu\Programs\WinRAR
[2013/10/08 16:38:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Star\Application Data\WinRAR
[2013/10/08 16:38:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
[2013/10/08 16:38:46 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2013/10/08 11:15:56 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Star\My Documents\My Videos
[2013/10/08 11:13:11 | 000,032,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbccgp.sys
[2013/10/07 14:01:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Star\Desktop\mbar
[2013/10/07 11:05:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2013/10/07 11:04:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/10/11 13:10:45 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/10/11 11:23:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Star\Desktop\OTL.exe
[2013/10/11 11:13:12 | 001,032,220 | ---- | M] (Thisisu) -- C:\Documents and Settings\Star\Desktop\JRT.exe
[2013/10/11 11:04:22 | 001,048,960 | ---- | M] () -- C:\Documents and Settings\Star\Desktop\adwcleaner.exe
[2013/10/10 18:36:59 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2013/10/10 15:32:52 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2013/10/10 13:22:29 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{DCCAB0E0-E10A-4CD2-83F1-30DB1E240CAC}.job
[2013/10/10 11:52:50 | 005,131,844 | R--- | M] (Swearware) -- C:\Documents and Settings\Star\Desktop\ComboFix.exe
[2013/10/09 13:48:57 | 000,048,728 | ---- | M] (MalwareBytes) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2013/10/09 11:33:54 | 000,002,978 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2013/10/09 10:41:10 | 000,950,272 | ---- | M] () -- C:\Documents and Settings\Star\Desktop\RogueKiller.exe
[2013/10/07 11:34:38 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/09/19 11:55:49 | 000,017,408 | ---- | M] () -- C:\WINDOWS\System32\rpcnetp.dll
[2013/09/19 11:55:28 | 000,017,408 | ---- | M] () -- C:\WINDOWS\System32\rpcnetp.exe
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/10/11 13:05:10 | 001,048,960 | ---- | C] () -- C:\Documents and Settings\Star\Desktop\adwcleaner.exe
[2013/10/10 15:32:52 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2013/10/10 15:32:47 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2013/10/10 13:57:16 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2013/10/10 13:57:16 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2013/10/10 13:57:16 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2013/10/10 13:57:16 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2013/10/10 13:57:16 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2013/10/09 17:04:09 | 000,950,272 | ---- | C] () -- C:\Documents and Settings\Star\Desktop\RogueKiller.exe
[2013/10/09 11:33:53 | 000,002,978 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2013/08/02 12:39:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2013/06/24 17:15:48 | 000,982,240 | ---- | C] () -- C:\WINDOWS\System32\igkrng500.bin
[2013/06/24 17:15:44 | 000,439,308 | ---- | C] () -- C:\WINDOWS\System32\igcompkrng500.bin
[2013/06/24 16:28:43 | 000,017,408 | ---- | C] () -- C:\WINDOWS\System32\rpcnetp.dll
[2013/06/24 16:26:51 | 000,017,408 | ---- | C] () -- C:\WINDOWS\System32\rpcnetp.exe
[2013/02/11 12:07:25 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\instsrv.exe
[2013/02/11 12:07:25 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\srvany.exe
[2013/02/11 12:04:57 | 000,195,480 | ---- | C] () -- C:\WINDOWS\System32\igfcg600m.bin
[2013/02/11 12:04:57 | 000,004,096 | ---- | C] ( ) -- C:\WINDOWS\System32\IGFXDEVLib.dll
[2013/02/11 12:04:54 | 000,145,804 | ---- | C] () -- C:\WINDOWS\System32\igcompkrng600.bin
[2013/02/11 12:04:54 | 000,000,151 | ---- | C] () -- C:\WINDOWS\System32\GfxUI.exe.config
[2013/02/11 12:04:53 | 000,783,644 | ---- | C] () -- C:\WINDOWS\System32\igkrng600.bin
[2012/08/17 19:32:30 | 000,000,102 | ---- | C] () -- C:\Documents and Settings\Star\.ewanapi_cookie
[2012/08/17 19:26:49 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2012/08/17 14:11:24 | 000,001,606 | ---- | C] () -- C:\WINDOWS\System32\font.ini
[2012/08/16 06:13:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\DAS32R2.INI
[2012/08/16 03:53:54 | 000,000,078 | ---- | C] () -- C:\WINDOWS\init.ini
[2012/08/16 03:50:38 | 000,000,033 | ---- | C] () -- C:\WINDOWS\starfont.ini
[2012/08/16 03:34:25 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Star\Local Settings\Application Data\fusioncache.dat
[2012/08/16 03:23:04 | 000,360,549 | ---- | C] () -- C:\WINDOWS\System32\ivm_lic.dll
[2012/08/16 03:23:04 | 000,012,032 | ---- | C] () -- C:\WINDOWS\System32\drivers\D990TRAN.sys
[2012/08/16 03:15:00 | 000,114,742 | ---- | C] () -- C:\WINDOWS\System32\SerialNumberAccessDll.dll.old
[2012/08/16 03:15:00 | 000,114,742 | ---- | C] () -- C:\WINDOWS\System32\SerialNumberAccessDll.dll
[2012/08/16 03:07:37 | 000,000,784 | ---- | C] () -- C:\WINDOWS\starpad.ini
[2012/08/16 03:01:42 | 000,298,496 | ---- | C] () -- C:\WINDOWS\System32\StarInsecure.dll
========== ZeroAccess Check ==========
[2012/08/16 04:00:56 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/14 05:00:00 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2008/04/14 05:00:00 | 000,472,064 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/14 05:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report >
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Star\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.16 Gb Total Physical Memory | 2.90 Gb Available Physical Memory | 91.66% Memory free
7.17 Gb Paging File | 7.09 Gb Available in Paging File | 98.87% Paging File free
Paging file location(s): C:\pagefile.sys 0 0F:\pagefile.sys 1024 1024 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.93 Gb Total Space | 27.92 Gb Free Space | 69.91% Space Free | Partition Type: NTFS
Drive D: | 29.30 Gb Total Space | 9.49 Gb Free Space | 32.37% Space Free | Partition Type: NTFS
Drive E: | 15.63 Gb Total Space | 2.99 Gb Free Space | 19.11% Space Free | Partition Type: NTFS
Drive F: | 29.30 Gb Total Space | 5.33 Gb Free Space | 18.20% Space Free | Partition Type: NTFS
Drive G: | 2.87 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 14.90 Gb Total Space | 8.94 Gb Free Space | 60.02% Space Free | Partition Type: FAT32
Computer Name: STAR43715 | User Name: Star | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/10/11 11:23:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Star\Desktop\OTL.exe
PRC - [2008/07/03 04:38:24 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- h:\e5500 xp drivers (cab)\e5500\xp\x86\audio\r267815\wdm\stacsv.exe -- (STacSV)
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - [2012/11/29 06:50:25 | 003,463,080 | ---- | M] (TeamViewer GmbH) [Auto | Stopped] -- C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2012/03/06 01:45:36 | 000,198,520 | ---- | M] (Juniper Networks, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe -- (JuniperAccessService)
SRV - [2011/08/10 08:13:48 | 000,208,896 | ---- | M] () [Disabled | Stopped] -- C:\Programme\OnlineUpdateBG\schedservicemain.exe -- (oubgschedservice)
SRV - [2011/03/09 12:04:12 | 000,326,616 | ---- | M] (Transaction Software, D 81829 Munich) [Auto | Stopped] -- C:\Programme\ewa\database\TransBase WIS\tbmux32.exe -- (EWA net DB WIS)
SRV - [2011/03/09 12:04:12 | 000,326,616 | ---- | M] (Transaction Software, D 81829 Munich) [Auto | Stopped] -- C:\Programme\ewa\database\TransBase EWA\tbmux32.exe -- (EWA net DB Core)
SRV - [2010/02/10 18:50:50 | 000,072,296 | ---- | M] (O2Micro International) [Auto | Stopped] -- C:\WINDOWS\system32\drivers\o2flash.exe -- (O2FLASH)
SRV - [2007/11/27 13:33:52 | 000,417,792 | ---- | M] (Transaction Software, D 81829 Munich) [Auto | Stopped] -- C:\Programme\ewa\database\TransBase EPC\tbmux32.exe -- (EWA net DB EPC)
SRV - [2006/09/02 16:36:33 | 002,528,960 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE -- (LiveUpdate)
SRV - [2004/11/16 17:07:26 | 000,094,208 | ---- | M] (KoDiSys GmbH) [Auto | Stopped] -- C:\WINDOWS\zak\service.exe -- (SDImpersonationService)
SRV - [2004/10/25 11:00:52 | 000,007,680 | ---- | M] (Gigatronik) [Auto | Stopped] -- c:\Programme\HardwareAssistent\HWAssistentService.exe -- (HWAssistentService)
SRV - [2003/07/31 19:29:04 | 000,065,536 | ---- | M] (Alexandria Software Consulting) [Auto | Stopped] -- C:\Programme\ewa\server\bin\tomcat.exe -- (EWA net Server)
SRV - [2003/04/18 19:06:26 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\srvany.exe -- (O2SDIOAssist)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\wudfrd.sys -- (WudfRd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\WudfPf.sys -- (WudfPf)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\HSF_CNXT.sys -- (winachsf)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\vmxnet.sys -- (vmxnet)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\vmx_svga.sys -- (vmx_svga)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\vmmouse.sys -- (vmmouse)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\vmci.sys -- (vmci)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\TrueSight.sys -- (TrueSight)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | Auto | Stopped] -- system32\DRIVERS\mdmxsdk.sys -- (mdmxsdk)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- C:\DOCUME~1\Star\LOCALS~1\Temp\Mydrivers32.SYS -- (HWiNFO32)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\HSFHWAZL.sys -- (HSFHWAZL)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\HSF_DPV.sys -- (HSF_DPV)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\oz776.sys -- (guardian2)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Accelern.sys -- (Acceler)
DRV - [2013/10/09 13:48:57 | 000,048,728 | ---- | M] (MalwareBytes) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamchameleon.sys -- (mbamchameleon)
DRV - [2012/08/17 12:40:12 | 000,721,904 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2012/07/11 17:20:36 | 000,116,224 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV - [2012/07/11 17:20:34 | 006,650,752 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETwNx32.sys -- (NETwNx32)
DRV - [2012/07/11 17:20:22 | 001,656,499 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2012/07/11 17:20:22 | 000,048,128 | ---- | M] (REDC) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2012/07/11 17:20:20 | 000,113,664 | ---- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AESTAud.sys -- (AESTAud)
DRV - [2012/04/13 12:05:06 | 000,073,096 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftser2k.sys -- (FTSER2K)
DRV - [2012/02/15 12:00:28 | 003,369,984 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2011/03/23 14:51:56 | 000,063,976 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\o2sdjxp.sys -- (O2SDJRDR)
DRV - [2011/01/26 15:48:50 | 000,229,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2011/01/04 03:58:42 | 000,061,728 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\o2mdrxp.sys -- (O2MDRRDR)
DRV - [2010/10/19 16:33:40 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HECI.sys -- (MEI)
DRV - [2010/10/15 09:29:16 | 000,260,864 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\IntcDAud.sys -- (IntcDAud)
DRV - [2010/10/07 13:11:38 | 006,609,920 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETwLx32.sys -- (NETwLx32)
DRV - [2009/08/14 14:24:07 | 000,017,968 | R--- | M] (VMware, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\vmscsi.sys -- (vmscsi)
DRV - [2007/06/27 13:05:52 | 000,053,184 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2004/06/08 16:35:00 | 000,030,208 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Stopped] -- C:\Programme\Temp\JidaN.sys -- (JidaN)
DRV - [2001/08/17 13:17:44 | 000,042,432 | ---- | M] (Digi International, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\digirlpt.sys -- (DIGIRPS)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Update_Check_Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-343818398-861567501-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-343818398-861567501-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://aftersales.I.daimler.com
IE - HKU\S-1-5-21-343818398-861567501-725345543-1003\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-343818398-861567501-725345543-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search
IE - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\npctrl.1.0.30716.0.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\
O1 HOSTS File: ([2013/10/10 18:36:59 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (WebCGMHlprObj Class) - {56B38F40-4E70-11d4-A076-0080AD86BA2F} - C:\WINDOWS\system32\cgmopenbho.dll (CGM Open Consortium, Inc.)
O4 - HKLM..\Run: [BWK] c:\programme\BWK\Startup.lnk ()
O4 - HKLM..\Run: [HotFixInstaller] C:\Programme\HotFixInst\HotfixInst.exe (GIGATRONIK Stuttgart GmbH)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LaunchComServer] C:\Program Files\SDconnect Toolkit\bin\TKTray.exe (I+ME ACTIA GmbH, DE, Braunschweig)
O4 - HKLM..\Run: [SDNC] C:\Programme\SDnetControl\SDNC.exe (GIGATRONIK Stuttgart GmbH)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKU\S-1-5-21-343818398-861567501-725345543-1003..\Run: [SDprinterConfig] C:\Programme\SDprinterConfig\SDprinterConfig.exe (GIGATRONIK Stuttgart GmbH)
O4 - HKU\S-1-5-21-343818398-861567501-725345543-1003..\Run: [StarInsecure] C:\WINDOWS\StarInsecure\hstart.exe (NTWind Software)
O4 - HKU\S-1-5-21-343818398-861567501-725345543-1003..\RunOnce: [Report] C:\AdwCleaner\AdwCleaner[S0].txt ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\IEDevTools present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Security present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\SQM present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Suggested Sites present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\IEDevTools present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Security present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\SQM present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Suggested Sites present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\IEDevTools present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Security present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\SQM present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Suggested Sites present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\IEDevTools present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Security present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\SQM present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Suggested Sites present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\IEDevTools present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Security present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\SQM present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Suggested Sites present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-343818398-861567501-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKLM\..Trusted Domains: daimler.com ([]* in Trusted sites)
O15 - HKLM\..Trusted Domains: daimler.com ([*.I] * in Trusted sites)
O15 - HKLM\..Trusted Domains: dccac.net ([www] * in Trusted sites)
O15 - HKLM\..Trusted Domains: mercedes-benz.com ([ewa-brasil] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mercedes-benz.com ([retailfactory] * in Trusted sites)
O15 - HKLM\..Trusted Domains: mercedes-benz.com ([retailfactory2] * in Trusted sites)
O15 - HKLM\..Trusted Domains: mercedes-benz-mobile.com ([www] http in Trusted sites)
O15 - HKLM\..Trusted Domains: startekinfo.com ([www] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: daimler.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: daimler.com ([*.I] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: dccac.net ([www] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: evobus.com ([*] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: mercedes-amg.com ([*] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: mercedes-benz.com ([ewa-brasil] http in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: mercedes-benz.com ([retailfactory] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: mercedes-benz.com ([retailfactory2] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: mercedes-benz-mobile.com ([www] http in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: servicecode.net ([*] * in Trusted sites)
O15 - HKU\S-1-5-21-343818398-861567501-725345543-1003\..Trusted Domains: startekinfo.com ([www] * in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupControlXP Class)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 205.171.2.65
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1710BAF9-63EA-466A-802B-8FACFAC57DAA}: DhcpNameServer = 192.168.0.1 205.171.2.65
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1CFDA05D-9B30-4048-926E-9765644CE039}: DhcpNameServer = 192.168.0.1 205.171.2.65
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{25B05A5C-CA65-437F-9890-FC01F87D3A45}: DhcpNameServer = 202.96.128.166 202.96.134.133
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BCE70BE3-A753-49B6-8C38-AD91DE2E2C74}: DhcpNameServer = 192.168.0.1 205.171.2.65
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EF053F6B-6113-4261-B905-06D24EF2AAD0}: DhcpNameServer = 192.168.0.1 205.171.2.65
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Star\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Star\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/06/22 15:55:26 | 000,000,024 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2013/10/08 15:02:32 | 000,000,059 | RHS- | M] () - H:\autorun.inf -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/10/11 13:24:23 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Star\Desktop\OTL.exe
[2013/10/11 13:14:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2013/10/11 13:13:35 | 001,032,220 | ---- | C] (Thisisu) -- C:\Documents and Settings\Star\Desktop\JRT.exe
[2013/10/11 13:05:16 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013/10/10 18:37:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\logs
[2013/10/10 18:35:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2013/10/10 18:31:55 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013/10/10 15:32:44 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2013/10/10 15:28:59 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2013/10/10 13:57:16 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2013/10/10 13:57:16 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2013/10/10 13:57:16 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2013/10/10 13:57:16 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2013/10/10 13:57:05 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/10/10 13:56:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2013/10/10 13:53:14 | 005,131,844 | R--- | C] (Swearware) -- C:\Documents and Settings\Star\Desktop\ComboFix.exe
[2013/10/09 13:48:57 | 000,048,728 | ---- | C] (MalwareBytes) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2013/10/09 11:43:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Star\Desktop\RK_Quarantine
[2013/10/09 11:04:07 | 000,000,000 | ---D | C] -- C:\$AVG
[2013/10/09 10:46:36 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2013/10/09 10:45:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2013/10/08 16:38:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Star\Start Menu\Programs\WinRAR
[2013/10/08 16:38:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Star\Application Data\WinRAR
[2013/10/08 16:38:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
[2013/10/08 16:38:46 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2013/10/08 11:15:56 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Star\My Documents\My Videos
[2013/10/08 11:13:11 | 000,032,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbccgp.sys
[2013/10/07 14:01:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Star\Desktop\mbar
[2013/10/07 11:05:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2013/10/07 11:04:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/10/11 13:10:45 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/10/11 11:23:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Star\Desktop\OTL.exe
[2013/10/11 11:13:12 | 001,032,220 | ---- | M] (Thisisu) -- C:\Documents and Settings\Star\Desktop\JRT.exe
[2013/10/11 11:04:22 | 001,048,960 | ---- | M] () -- C:\Documents and Settings\Star\Desktop\adwcleaner.exe
[2013/10/10 18:36:59 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2013/10/10 15:32:52 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2013/10/10 13:22:29 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{DCCAB0E0-E10A-4CD2-83F1-30DB1E240CAC}.job
[2013/10/10 11:52:50 | 005,131,844 | R--- | M] (Swearware) -- C:\Documents and Settings\Star\Desktop\ComboFix.exe
[2013/10/09 13:48:57 | 000,048,728 | ---- | M] (MalwareBytes) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2013/10/09 11:33:54 | 000,002,978 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2013/10/09 10:41:10 | 000,950,272 | ---- | M] () -- C:\Documents and Settings\Star\Desktop\RogueKiller.exe
[2013/10/07 11:34:38 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/09/19 11:55:49 | 000,017,408 | ---- | M] () -- C:\WINDOWS\System32\rpcnetp.dll
[2013/09/19 11:55:28 | 000,017,408 | ---- | M] () -- C:\WINDOWS\System32\rpcnetp.exe
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/10/11 13:05:10 | 001,048,960 | ---- | C] () -- C:\Documents and Settings\Star\Desktop\adwcleaner.exe
[2013/10/10 15:32:52 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2013/10/10 15:32:47 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2013/10/10 13:57:16 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2013/10/10 13:57:16 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2013/10/10 13:57:16 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2013/10/10 13:57:16 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2013/10/10 13:57:16 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2013/10/09 17:04:09 | 000,950,272 | ---- | C] () -- C:\Documents and Settings\Star\Desktop\RogueKiller.exe
[2013/10/09 11:33:53 | 000,002,978 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2013/08/02 12:39:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2013/06/24 17:15:48 | 000,982,240 | ---- | C] () -- C:\WINDOWS\System32\igkrng500.bin
[2013/06/24 17:15:44 | 000,439,308 | ---- | C] () -- C:\WINDOWS\System32\igcompkrng500.bin
[2013/06/24 16:28:43 | 000,017,408 | ---- | C] () -- C:\WINDOWS\System32\rpcnetp.dll
[2013/06/24 16:26:51 | 000,017,408 | ---- | C] () -- C:\WINDOWS\System32\rpcnetp.exe
[2013/02/11 12:07:25 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\instsrv.exe
[2013/02/11 12:07:25 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\srvany.exe
[2013/02/11 12:04:57 | 000,195,480 | ---- | C] () -- C:\WINDOWS\System32\igfcg600m.bin
[2013/02/11 12:04:57 | 000,004,096 | ---- | C] ( ) -- C:\WINDOWS\System32\IGFXDEVLib.dll
[2013/02/11 12:04:54 | 000,145,804 | ---- | C] () -- C:\WINDOWS\System32\igcompkrng600.bin
[2013/02/11 12:04:54 | 000,000,151 | ---- | C] () -- C:\WINDOWS\System32\GfxUI.exe.config
[2013/02/11 12:04:53 | 000,783,644 | ---- | C] () -- C:\WINDOWS\System32\igkrng600.bin
[2012/08/17 19:32:30 | 000,000,102 | ---- | C] () -- C:\Documents and Settings\Star\.ewanapi_cookie
[2012/08/17 19:26:49 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2012/08/17 14:11:24 | 000,001,606 | ---- | C] () -- C:\WINDOWS\System32\font.ini
[2012/08/16 06:13:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\DAS32R2.INI
[2012/08/16 03:53:54 | 000,000,078 | ---- | C] () -- C:\WINDOWS\init.ini
[2012/08/16 03:50:38 | 000,000,033 | ---- | C] () -- C:\WINDOWS\starfont.ini
[2012/08/16 03:34:25 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Star\Local Settings\Application Data\fusioncache.dat
[2012/08/16 03:23:04 | 000,360,549 | ---- | C] () -- C:\WINDOWS\System32\ivm_lic.dll
[2012/08/16 03:23:04 | 000,012,032 | ---- | C] () -- C:\WINDOWS\System32\drivers\D990TRAN.sys
[2012/08/16 03:15:00 | 000,114,742 | ---- | C] () -- C:\WINDOWS\System32\SerialNumberAccessDll.dll.old
[2012/08/16 03:15:00 | 000,114,742 | ---- | C] () -- C:\WINDOWS\System32\SerialNumberAccessDll.dll
[2012/08/16 03:07:37 | 000,000,784 | ---- | C] () -- C:\WINDOWS\starpad.ini
[2012/08/16 03:01:42 | 000,298,496 | ---- | C] () -- C:\WINDOWS\System32\StarInsecure.dll
========== ZeroAccess Check ==========
[2012/08/16 04:00:56 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/14 05:00:00 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2008/04/14 05:00:00 | 000,472,064 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/14 05:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report >