|
Plagegeister aller Art und deren Bekämpfung: Allgemeine Fragen...Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
03.04.2011, 16:40 | #1 |
| Allgemeine Fragen... Hallo, was das Thema PC angeht bin ich nicht so geschult und habe einige Fragen bezüglich mir unbekannten Sachen. Da wäre z.B. 1. das beim Start meines Computers immer 2 Fenster auftauchen, Fehler und Windows-Sicherheit. (siehe Anhang)...wie bekomme ich das weg? 2. Bei verschiedenen Programmen ist es so, wenn ich sie minimiere, werden sie nicht wie normalerweise in der Taskleiste abgelegt sondern verschwinden regelrecht. Laufen aber trotzdem noch!...Warum passiert sowas? 3. Taskmanager --> Prozesse Kmymia.exe...was ist das? |
03.04.2011, 17:32 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Allgemeine Fragen... Du hast wahrscheinlich "Gäste" im System. Auf dem Screenshot sieht man Malwarebytes, poste alle Logs davon, die im Reiter Logdateien sichtbar sind.
__________________
__________________ |
03.04.2011, 17:43 | #3 |
| Allgemeine Fragen... Malwarebytes' Anti-Malware 1.50.1.1100
__________________Malwarebytes Datenbank Version: 6255 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 03.04.2011 16:58:40 mbam-log-2011-04-03 (16-58-40).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 163152 Laufzeit: 6 Minute(n), 39 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 3 Infizierte Registrierungswerte: 1 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 4 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runAPI45 (Backdoor.Agent) -> Value: runAPI45 -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: c:\Windows\System32\winrssrvh.dll (Heuristics.Shuriken) -> Quarantined and deleted successfully. c:\Users\Gpa\AppData\Roaming\data.dat (Stolen.Data) -> Quarantined and deleted successfully. c:\Windows\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully. c:\Windows\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully. |
03.04.2011, 17:50 | #4 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Allgemeine Fragen...Zitat:
Bitte routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!
__________________ Logfiles bitte immer in CODE-Tags posten |
03.04.2011, 19:21 | #5 |
| Allgemeine Fragen... Malwarebytes' Anti-Malware 1.50.1.1100 Malwarebytes Datenbank Version: 6256 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 03.04.2011 20:19:45 mbam-log-2011-04-03 (20-19-38).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|) Durchsuchte Objekte: 382966 Laufzeit: 1 Stunde(n), 23 Minute(n), 1 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 1 Infizierte Registrierungswerte: 1 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 2 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> No action taken. Infizierte Registrierungswerte: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> No action taken. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> No action taken. c:\Windows.old\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> No action taken. |
03.04.2011, 19:40 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Allgemeine Fragen... Warum entfernst du die Funde nicht?
__________________ --> Allgemeine Fragen... |
03.04.2011, 19:46 | #7 |
| Allgemeine Fragen... Ja hab ich, nur erst gerade eben ^_^ |
03.04.2011, 19:54 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Allgemeine Fragen... Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
__________________ Logfiles bitte immer in CODE-Tags posten |
03.04.2011, 20:11 | #9 |
| Allgemeine Fragen... OTL Logfile: Code:
ATTFilter OTL logfile created on: 4/3/2011 8:56:57 PM - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Gpa\Downloads Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000409 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy 2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 55.00% Memory free 4.00 Gb Paging File | 3.00 Gb Available in Paging File | 70.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 74.38 Gb Total Space | 21.99 Gb Free Space | 29.57% Space Free | Partition Type: NTFS Drive E: | 232.88 Gb Total Space | 152.79 Gb Free Space | 65.61% Space Free | Partition Type: NTFS Computer Name: HORST | User Name: Gpa | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Gpa\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Windows\Kmymia.exe () PRC - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.) PRC - C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH) PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Programme\DivX\DivX Update\DivXUpdate.exe () PRC - C:\Programme\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.) PRC - C:\Programme\Application Updater\ApplicationUpdater.exe (Spigot, Inc.) PRC - C:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corp.) PRC - C:\Programme\Windows Media Player\wmplayer.exe (Microsoft Corporation) PRC - C:\Programme\ICQ6Toolbar\ICQ Service.exe () PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation) PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation) ========== Modules (SafeList) ========== MOD - C:\Users\Gpa\Downloads\OTL.exe (OldTimer Tools) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (TeamViewer6) -- C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (Application Updater) -- C:\Program Files\Application Updater\ApplicationUpdater.exe (Spigot, Inc.) SRV - (ICQ Service) -- C:\Programme\ICQ6Toolbar\ICQ Service.exe () SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation) SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (truecrypt) -- C:\Windows\System32\drivers\truecrypt.sys (TrueCrypt Foundation) DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (vmbus) -- C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation) DRV - (storflt) -- C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation) DRV - (storvsc) -- C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation) DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation) DRV - (s3cap) -- C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation) DRV - (VMBusHID) -- C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation) DRV - (e1kexpress) Intel(R) -- C:\Windows\System32\drivers\e1k6032.sys (Intel Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) IE - HKCU\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - user.js..browser.search.selectedEngine: "Google" FF - user.js..browser.search.order.1: "Google" FF - user.js..browser.search.defaultenginename: "Google" FF - user.js..keyword.URL: "hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q=" FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/03/28 21:30:03 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/03/28 21:30:03 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/28 21:36:29 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/03 17:42:32 | 000,000,000 | ---D | M] [2011/03/29 22:15:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gpa\AppData\Roaming\mozilla\Extensions [2011/03/28 21:47:36 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2011/03/28 21:43:31 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2011/03/28 21:40:50 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} File not found (No name found) -- [2011/03/28 21:47:35 | 000,000,000 | ---D | M] (Widgi Toolbar Platform) -- C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM [2011/03/28 21:43:31 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2011/03/28 21:40:50 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011/03/28 21:47:36 | 000,000,000 | ---D | M] (pdfforge Toolbar) -- C:\PROGRAM FILES\PDFFORGE TOOLBAR\FF [2011/03/18 19:56:37 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Programme\Mozilla Firefox\components\browsercomps.dll [2011/01/25 11:55:14 | 000,644,096 | ---- | M] (Synatix GmbH) -- C:\Programme\Mozilla Firefox\Plugins\npmieze.dll [2010/01/01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2010/01/01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\bing.xml [2010/01/01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml [2011/04/03 17:42:32 | 000,000,140 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\Google.src [2010/01/01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml [2010/01/01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml [2010/01/01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009/06/10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.) O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.) O3 - HKLM\..\Toolbar: (Gutscheinmieze) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - C:\Users\Gpa\AppData\Roaming\Gutscheinmieze\toolbar.dll (Synatix GmbH) O3 - HKCU\..\Toolbar\WebBrowser: (Gutscheinmieze) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - C:\Users\Gpa\AppData\Roaming\Gutscheinmieze\toolbar.dll (Synatix GmbH) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.) O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.4\ICQ.exe (ICQ, LLC.) O4 - HKCU..\Run: [IKXGVMFZHI] File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: Free YouTube Download - C:\Users\Gpa\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Gpa\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009/06/10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - Unable to obtain root file information for disk E:\ O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011/04/03 17:51:04 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\{295F13A8-D99B-480E-A9C5-C21F05C0784E} [2011/04/03 17:46:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\appmgmt [2011/04/03 17:42:26 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Gutscheinmieze [2011/04/03 16:48:00 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Malwarebytes [2011/04/03 16:47:53 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2011/04/03 16:47:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011/04/03 16:47:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011/04/03 16:47:50 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2011/04/03 16:47:49 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware [2011/04/03 16:30:24 | 000,000,000 | ---D | C] -- C:\Programme\Trend Micro [2011/04/03 16:30:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis [2011/04/03 11:55:43 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Xfire [2011/04/03 11:55:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xfire [2011/04/03 11:55:40 | 000,000,000 | ---D | C] -- C:\Users\Gpa\Xfire [2011/04/03 11:55:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Xfire [2011/04/03 01:08:44 | 000,000,000 | ---D | C] -- C:\Windows\Sun [2011/04/03 00:20:05 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Avira [2011/04/03 00:05:23 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\gctmp [2011/04/03 00:05:22 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Xenocode [2011/04/02 23:28:16 | 000,000,000 | ---D | C] -- C:\ProgramData\NFS Underground [2011/04/02 22:30:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games [2011/04/02 11:36:38 | 000,000,000 | ---D | C] -- C:\Users\Gpa\Documents\ICQ [2011/03/31 23:25:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft [2011/03/31 23:25:15 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Blizzard Entertainment [2011/03/31 23:24:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment [2011/03/31 23:18:15 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\WinRAR [2011/03/31 23:17:49 | 000,000,000 | ---D | C] -- C:\plugins [2011/03/31 20:18:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth [2011/03/31 18:25:03 | 000,000,000 | ---D | C] -- C:\Windows\de [2011/03/31 18:16:16 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft SQL Server Compact Edition [2011/03/31 18:15:10 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH [2011/03/31 18:14:07 | 000,000,000 | ---D | C] -- C:\Programme\Windows Live [2011/03/31 18:10:49 | 002,983,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbon.dll [2011/03/31 18:10:49 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbonRes.dll [2011/03/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Windows Live [2011/03/30 15:52:32 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Adobe [2011/03/29 22:15:16 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Mozilla [2011/03/29 22:15:16 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Mozilla [2011/03/29 19:05:42 | 000,000,000 | ---D | C] -- C:\Programme\Pidgin [2011/03/29 16:40:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Google [2011/03/29 16:39:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google SketchUp 8 [2011/03/29 16:39:04 | 000,000,000 | ---D | C] -- C:\Programme\Google [2011/03/29 14:03:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR [2011/03/29 14:03:53 | 000,000,000 | ---D | C] -- C:\Programme\WinRAR [2011/03/29 05:07:36 | 000,000,000 | ---D | C] -- C:\Windows\Panther [2011/03/29 04:50:11 | 000,000,000 | ---D | C] -- C:\Windows.old [2011/03/29 04:12:30 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2011/03/29 04:10:04 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch [2011/03/28 22:15:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft [2011/03/28 22:04:56 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\.minecraft [2011/03/28 21:53:45 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_43.dll [2011/03/28 21:53:45 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll [2011/03/28 21:53:45 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll [2011/03/28 21:53:45 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll [2011/03/28 21:53:45 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll [2011/03/28 21:53:45 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll [2011/03/28 21:53:45 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll [2011/03/28 21:53:44 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll [2011/03/28 21:53:44 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_6.dll [2011/03/28 21:53:44 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_4.dll [2011/03/28 21:53:43 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_6.dll [2011/03/28 21:53:43 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_7.dll [2011/03/28 21:53:42 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll [2011/03/28 21:53:42 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll [2011/03/28 21:53:42 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll [2011/03/28 21:53:42 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll [2011/03/28 21:53:41 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_41.dll [2011/03/28 21:53:41 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll [2011/03/28 21:53:41 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_41.dll [2011/03/28 21:53:41 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll [2011/03/28 21:53:41 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_41.dll [2011/03/28 21:53:41 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll [2011/03/28 21:53:40 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_4.dll [2011/03/28 21:53:40 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll [2011/03/28 21:53:39 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_40.dll [2011/03/28 21:53:39 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_4.dll [2011/03/28 21:53:39 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_6.dll [2011/03/28 21:53:38 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_40.dll [2011/03/28 21:53:38 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll [2011/03/28 21:53:38 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll [2011/03/28 21:53:37 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll [2011/03/28 21:53:37 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll [2011/03/28 21:53:37 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll [2011/03/28 21:53:36 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll [2011/03/28 21:53:36 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll [2011/03/28 21:53:36 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll [2011/03/28 21:53:36 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_1.dll [2011/03/28 21:53:36 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll [2011/03/28 21:53:36 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll [2011/03/28 21:53:36 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_0.dll [2011/03/28 21:53:35 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_38.dll [2011/03/28 21:53:35 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_38.dll [2011/03/28 21:53:35 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_0.dll [2011/03/28 21:53:35 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_38.dll [2011/03/28 21:53:35 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_1.dll [2011/03/28 21:53:35 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_4.dll [2011/03/28 21:53:34 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_0.dll [2011/03/28 21:53:33 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_37.dll [2011/03/28 21:53:33 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_37.dll [2011/03/28 21:53:33 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_36.dll [2011/03/28 21:53:33 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_37.dll [2011/03/28 21:53:33 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_36.dll [2011/03/28 21:53:33 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_10.dll [2011/03/28 21:53:33 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_3.dll [2011/03/28 21:53:32 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_36.dll [2011/03/28 21:53:32 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_9.dll [2011/03/28 21:53:31 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_35.dll [2011/03/28 21:53:31 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_34.dll [2011/03/28 21:53:31 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_35.dll [2011/03/28 21:53:31 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_34.dll [2011/03/28 21:53:31 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_35.dll [2011/03/28 21:53:31 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_34.dll [2011/03/28 21:53:31 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_8.dll [2011/03/28 21:53:31 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_3.dll [2011/03/28 21:53:31 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_2.dll [2011/03/28 21:53:30 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_33.dll [2011/03/28 21:53:30 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_33.dll [2011/03/28 21:53:30 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_33.dll [2011/03/28 21:53:30 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_7.dll [2011/03/28 21:53:29 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_6.dll [2011/03/28 21:53:29 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_5.dll [2011/03/28 21:53:28 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_32.dll [2011/03/28 21:53:28 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_31.dll [2011/03/28 21:53:28 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10.dll [2011/03/28 21:53:28 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_4.dll [2011/03/28 21:53:28 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_1.dll [2011/03/28 21:53:27 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_3.dll [2011/03/28 21:53:27 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_2.dll [2011/03/28 21:53:26 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_2.dll [2011/03/28 21:53:26 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_1.dll [2011/03/28 21:53:25 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_1.dll [2011/03/28 21:53:18 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_30.dll [2011/03/28 21:53:18 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_0.dll [2011/03/28 21:53:18 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_0.dll [2011/03/28 21:53:17 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_29.dll [2011/03/28 21:53:17 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_28.dll [2011/03/28 21:53:17 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_27.dll [2011/03/28 21:53:17 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_26.dll [2011/03/28 21:53:16 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_25.dll [2011/03/28 21:53:16 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_24.dll [2011/03/28 21:51:22 | 000,034,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lhacm.acm [2011/03/28 21:51:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Teamspeak2 RC2 [2011/03/28 21:51:19 | 000,000,000 | ---D | C] -- C:\Programme\Teamspeak2_RC2 [2011/03/28 21:50:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client [2011/03/28 21:50:17 | 000,000,000 | ---D | C] -- C:\Programme\TeamSpeak 3 Client [2011/03/28 21:49:17 | 000,231,248 | ---- | C] (TrueCrypt Foundation) -- C:\Windows\System32\drivers\truecrypt.sys [2011/03/28 21:49:08 | 000,000,000 | ---D | C] -- C:\Programme\TrueCrypt [2011/03/28 21:48:22 | 000,000,000 | ---D | C] -- C:\Programme\TeamViewer [2011/03/28 21:47:35 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Spigot [2011/03/28 21:47:35 | 000,000,000 | ---D | C] -- C:\Programme\pdfforge Toolbar [2011/03/28 21:47:35 | 000,000,000 | ---D | C] -- C:\Programme\Application Updater [2011/03/28 21:47:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator [2011/03/28 21:47:12 | 000,137,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSMAPI32.OCX [2011/03/28 21:47:10 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCMCDE.DLL [2011/03/28 21:47:10 | 000,125,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6DE.DLL [2011/03/28 21:47:10 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCC2DE.DLL [2011/03/28 21:47:10 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSMPIDE.DLL [2011/03/28 21:47:10 | 000,000,000 | ---D | C] -- C:\Programme\PDFCreator [2011/03/28 21:45:59 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.3 [2011/03/28 21:44:09 | 000,000,000 | ---D | C] -- C:\Programme\OpenOffice.org 3 [2011/03/28 21:43:31 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe [2011/03/28 21:43:31 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe [2011/03/28 21:43:31 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe [2011/03/28 21:41:37 | 000,000,000 | ---D | C] -- C:\Programme\Miranda IM [2011/03/28 21:41:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2011/03/28 21:41:05 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Java [2011/03/28 21:40:49 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll [2011/03/28 21:40:38 | 000,000,000 | ---D | C] -- C:\Programme\Java [2011/03/28 21:38:29 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Apple Computer [2011/03/28 21:38:29 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Apple Computer [2011/03/28 21:38:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2011/03/28 21:38:05 | 000,107,368 | ---- | C] (GEAR Software Inc.) -- C:\Windows\System32\GEARAspi.dll [2011/03/28 21:38:05 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE [2011/03/28 21:37:36 | 000,000,000 | ---D | C] -- C:\Programme\iPod [2011/03/28 21:37:35 | 000,000,000 | ---D | C] -- C:\Programme\iTunes [2011/03/28 21:37:35 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2011/03/28 21:36:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime [2011/03/28 21:36:21 | 000,000,000 | ---D | C] -- C:\Programme\QuickTime [2011/03/28 21:36:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer [2011/03/28 21:36:14 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Apple [2011/03/28 21:36:13 | 000,000,000 | ---D | C] -- C:\Programme\Apple Software Update [2011/03/28 21:35:56 | 000,000,000 | ---D | C] -- C:\Programme\Bonjour [2011/03/28 21:35:51 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Apple [2011/03/28 21:35:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple [2011/03/28 21:34:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7.4 [2011/03/28 21:34:42 | 000,000,000 | ---D | C] -- C:\Programme\ICQ6Toolbar [2011/03/28 21:34:42 | 000,000,000 | ---D | C] -- C:\ProgramData\ICQ [2011/03/28 21:34:41 | 000,000,000 | -H-D | C] -- C:\Programme\InstallShield Installation Information [2011/03/28 21:34:31 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\ICQ [2011/03/28 21:34:27 | 000,000,000 | ---D | C] -- C:\Programme\ICQ7.4 [2011/03/28 21:33:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP [2011/03/28 21:33:17 | 000,000,000 | ---D | C] -- C:\Programme\GIMP-2.0 [2011/03/28 21:32:17 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\DVDVideoSoftIEHelpers [2011/03/28 21:32:17 | 000,000,000 | ---D | C] -- C:\Users\Gpa\Documents\DVDVideoSoft [2011/03/28 21:32:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft [2011/03/28 21:32:11 | 000,000,000 | ---D | C] -- C:\Programme\DVDVideoSoft [2011/03/28 21:32:11 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\DVDVideoSoft [2011/03/28 21:31:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed [2011/03/28 21:31:05 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox [2011/03/28 21:31:01 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\DDMSettings [2011/03/28 21:29:47 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\DivX [2011/03/28 21:29:38 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\PX Storage Engine [2011/03/28 21:29:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus [2011/03/28 21:29:16 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\DivX Shared [2011/03/28 21:27:15 | 000,000,000 | ---D | C] -- C:\Programme\DivX [2011/03/28 21:26:30 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX [2011/03/28 21:26:05 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner [2011/03/28 21:23:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2011/03/28 21:23:08 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2011/03/28 21:23:07 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2011/03/28 21:23:07 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys [2011/03/28 21:23:07 | 000,000,000 | ---D | C] -- C:\Programme\Avira [2011/03/28 21:23:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2011/03/28 21:16:29 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Adobe [2011/03/28 21:16:29 | 000,000,000 | ---D | C] -- C:\Programme\Adobe [2011/03/28 21:15:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe [2011/03/28 21:07:30 | 000,000,000 | ---D | C] -- C:\Windows\de-DE [2011/03/28 21:07:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\XPSViewer [2011/03/28 21:07:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\de-DE [2011/03/28 21:07:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\de [2011/03/28 21:07:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\0407 [2011/03/28 21:02:19 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\volsnap.sys.mui [2011/03/28 21:02:19 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\usbport.sys.mui [2011/03/28 21:02:19 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\vhdmp.sys.mui [2011/03/28 21:02:19 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\portcls.sys.mui [2011/03/28 21:02:19 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\wd.sys.mui [2011/03/28 21:02:18 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\usbhub.sys.mui [2011/03/28 21:02:18 | 000,004,096 | ---- | C] (SCM Microsystems, Inc.) -- C:\Windows\System32\drivers\de-DE\pscr.sys.mui [2011/03/28 21:02:18 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\tpm.sys.mui [2011/03/28 21:02:18 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\umbus.sys.mui [2011/03/28 21:02:18 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\serscan.sys.mui [2011/03/28 21:02:14 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\pcmcia.sys.mui [2011/03/28 21:02:14 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\vwifibus.sys.mui [2011/03/28 21:02:13 | 000,033,280 | ---- | C] (Marvell) -- C:\Windows\System32\drivers\de-DE\yk62x86.sys.mui [2011/03/28 21:02:13 | 000,013,312 | ---- | C] (Broadcom Corporation) -- C:\Windows\System32\drivers\de-DE\k57nd60x.sys.mui [2011/03/28 21:02:13 | 000,003,072 | ---- | C] (VIA Technologies, Inc. ) -- C:\Windows\System32\drivers\de-DE\getn62.sys.mui [2011/03/28 21:02:13 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\rndismpx.sys.mui [2011/03/28 21:02:13 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\rndismp6.sys.mui [2011/03/28 21:02:12 | 000,025,088 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e1y6032.sys.mui [2011/03/28 21:02:12 | 000,025,088 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e1e6032.sys.mui [2011/03/28 21:02:12 | 000,022,016 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\E1G60I32.sys.mui [2011/03/28 21:02:12 | 000,013,312 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e1q6032.sys.mui [2011/03/28 21:02:12 | 000,013,312 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e1k6032.sys.mui [2011/03/28 21:02:12 | 000,013,312 | ---- | C] (Broadcom Corporation) -- C:\Windows\System32\drivers\de-DE\b57nd60x.sys.mui [2011/03/28 21:02:12 | 000,006,144 | ---- | C] (Broadcom Corporation) -- C:\Windows\System32\drivers\de-DE\bcm4sbxp.sys.mui [2011/03/28 21:02:12 | 000,005,120 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e100b325.sys.mui [2011/03/28 21:02:10 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\serial.sys.mui [2011/03/28 21:02:10 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\sermouse.sys.mui [2011/03/28 21:02:10 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mouclass.sys.mui [2011/03/28 21:02:10 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\parport.sys.mui [2011/03/28 21:02:10 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\parvdm.sys.mui [2011/03/28 21:02:10 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mouhid.sys.mui [2011/03/28 21:02:10 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\MTConfig.sys.mui [2011/03/28 21:02:09 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\i8042prt.sys.mui [2011/03/28 21:02:09 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\msdsm.sys.mui [2011/03/28 21:02:09 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ataport.sys.mui [2011/03/28 21:02:09 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\amdide.sys.mui [2011/03/28 21:02:08 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mpio.sys.mui [2011/03/28 21:02:08 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\scsiport.sys.mui [2011/03/28 21:02:06 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\afd.sys.mui [2011/03/28 21:02:04 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\tcpip.sys.mui [2011/03/28 21:02:04 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\bfe.dll.mui [2011/03/28 21:02:04 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\tunnel.sys.mui [2011/03/28 21:02:04 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\modem.sys.mui [2011/03/28 21:02:04 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\wdf01000.sys.mui [2011/03/28 21:02:04 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ws2ifsl.sys.mui [2011/03/28 21:02:04 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\usbrpm.sys.mui [2011/03/28 21:02:02 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\fvevol.sys.mui [2011/03/28 21:02:02 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\srv.sys.mui [2011/03/28 21:02:02 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\scfilter.sys.mui [2011/03/28 21:01:59 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\pacer.sys.mui [2011/03/28 21:01:59 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\rdbss.sys.mui [2011/03/28 21:01:59 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\RNDISMP.sys.mui [2011/03/28 21:01:59 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\qwavedrv.sys.mui [2011/03/28 21:01:59 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\partmgr.sys.mui [2011/03/28 21:01:55 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ntfs.sys.mui [2011/03/28 21:01:55 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\nwifi.sys.mui [2011/03/28 21:01:54 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ndis.sys.mui [2011/03/28 21:01:54 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ndisuio.sys.mui [2011/03/28 21:01:51 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ndiscap.sys.mui [2011/03/28 21:01:49 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mountmgr.sys.mui [2011/03/28 21:01:48 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\luafv.sys.mui [2011/03/28 21:01:48 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ipnat.sys.mui [2011/03/28 21:01:47 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\http.sys.mui [2011/03/28 21:01:44 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\fltmgr.sys.mui [2011/03/28 21:01:42 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\volmgrx.sys.mui [2011/03/28 21:01:36 | 000,011,776 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\de-DE\BrSerIb.sys.mui [2011/03/28 21:01:36 | 000,010,752 | ---- | C] (Agere Systems) -- C:\Windows\System32\drivers\de-DE\ltmdmnt.sys.mui [2011/03/28 21:01:36 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\pci.sys.mui [2011/03/28 21:01:36 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\IPMIDrv.sys.mui [2011/03/28 21:01:36 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\kbdclass.sys.mui [2011/03/28 21:01:36 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\vdrvroot.sys.mui [2011/03/28 21:01:36 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\isapnp.sys.mui [2011/03/28 21:01:36 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mssmbios.sys.mui [2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\VIAAGP.SYS.mui [2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ULIAGPKX.SYS.mui [2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\SISAGP.SYS.mui [2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\pnpmem.sys.mui [2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\NV_AGP.SYS.mui [2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\kbdhid.sys.mui [2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\AMDAGP.SYS.mui [2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\AGP440.sys.mui [2011/03/28 21:01:35 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\viac7.sys.mui [2011/03/28 21:01:35 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\processr.sys.mui [2011/03/28 21:01:35 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\intelppm.sys.mui [2011/03/28 21:01:35 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\amdppm.sys.mui [2011/03/28 21:01:35 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\amdk8.sys.mui [2011/03/28 21:01:35 | 000,011,776 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\de-DE\BrSerId.sys.mui [2011/03/28 21:01:35 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\battc.sys.mui [2011/03/28 21:01:35 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\bthport.sys.mui [2011/03/28 21:01:35 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\bthpan.sys.mui [2011/03/28 21:01:35 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\wacompen.sys.mui [2011/03/28 21:01:35 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\hdaudbus.sys.mui [2011/03/28 21:01:35 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\HdAudio.sys.mui [2011/03/28 21:01:35 | 000,003,584 | ---- | C] (ATI Technologies Inc.) -- C:\Windows\System32\drivers\de-DE\atikmdag.sys.mui [2011/03/28 21:01:35 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\hidbth.sys.mui [2011/03/28 21:01:35 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\UAGP35.SYS.mui [2011/03/28 21:01:35 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\GAGP30KX.SYS.mui [2011/03/28 21:01:35 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\Dot4usb.sys.mui [2011/03/28 21:01:35 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\BTHUSB.SYS.mui [2011/03/28 21:01:35 | 000,002,560 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\de-DE\BrParwdm.sys.mui [2011/03/28 21:01:35 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\disk.sys.mui [2011/03/28 21:01:35 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\cdrom.sys.mui [2011/03/28 21:01:35 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\bthenum.sys.mui [2011/03/28 21:01:34 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ohci1394.sys.mui [2011/03/28 21:01:34 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\1394ohci.sys.mui [2011/03/28 21:01:34 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\acpi.sys.mui [2011/03/28 20:50:49 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft.NET [2011/03/28 20:19:48 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe [2011/03/28 20:19:48 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll [2011/03/28 20:19:48 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll [2011/03/28 20:13:07 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browserchoice.exe [2011/03/28 20:11:55 | 000,222,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe [2011/03/28 20:11:42 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ks.sys [2011/03/28 20:10:31 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll [2011/03/28 20:10:31 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2011/03/28 20:10:31 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2011/03/28 20:10:31 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2011/03/28 20:10:30 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2011/03/28 20:10:30 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2011/03/28 20:10:29 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2011/03/28 20:10:29 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2011/03/28 20:10:29 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2011/03/28 20:10:18 | 001,320,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertEnroll.dll [2011/03/28 20:10:18 | 000,507,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winload.exe [2011/03/28 20:10:18 | 000,442,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winresume.exe [2011/03/28 20:10:15 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbc32.dll [2011/03/28 20:10:06 | 000,294,400 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll [2011/03/28 20:10:06 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll [2011/03/28 20:10:06 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll [2011/03/28 20:10:02 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40.dll [2011/03/28 20:10:02 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40u.dll [2011/03/28 20:09:58 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll [2011/03/28 20:09:58 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdri.dll [2011/03/28 20:09:58 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax [2011/03/28 20:09:45 | 001,037,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lsasrv.dll [2011/03/28 20:09:42 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll [2011/03/28 20:09:41 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll [2011/03/28 20:09:39 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll [2011/03/28 20:09:38 | 000,850,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll [2011/03/28 20:09:38 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll [2011/03/28 20:09:38 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax [2011/03/28 20:09:29 | 000,496,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskschd.dll [2011/03/28 20:09:29 | 000,351,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmicmiplugin.dll [2011/03/28 20:09:29 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskcomp.dll [2011/03/28 20:09:29 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\schtasks.exe [2011/03/28 20:09:25 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll [2011/03/28 20:09:25 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll [2011/03/28 20:09:22 | 002,329,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2011/03/28 20:09:17 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL [2011/03/28 20:09:16 | 001,328,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll [2011/03/28 20:09:16 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\avifil32.dll [2011/03/28 20:09:16 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciavi32.dll [2011/03/28 20:09:12 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll [2011/03/28 20:09:03 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll [2011/03/28 20:09:00 | 000,197,632 | ---- | C] (Intel(R) Corporation) -- C:\Windows\System32\ir32_32.dll [2011/03/28 20:09:00 | 000,082,944 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll [2011/03/28 20:08:58 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtutils.dll [2011/03/28 20:08:45 | 001,170,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll [2011/03/28 20:08:44 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll [2011/03/28 20:08:44 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL [2011/03/28 20:08:44 | 001,074,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll [2011/03/28 20:08:44 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll [2011/03/28 20:08:43 | 001,495,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ExplorerFrame.dll [2011/03/28 20:08:43 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll [2011/03/28 20:08:43 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll [2011/03/28 20:08:43 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll [2011/03/28 20:08:43 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll [2011/03/28 20:08:38 | 002,614,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe [2011/03/28 20:08:37 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\asycfilt.dll [2011/03/28 20:08:36 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll [2011/03/28 20:08:34 | 000,026,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Diskdump.sys [2011/03/28 20:08:20 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\upnp.dll [2011/03/28 20:08:19 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2011/03/28 20:08:19 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\davclnt.dll [2011/03/28 20:08:19 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscapi.dll [2011/03/28 20:08:19 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2011/03/28 20:08:19 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\slwga.dll [2011/03/28 20:08:16 | 003,957,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe [2011/03/28 20:08:16 | 003,901,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe [2011/03/28 20:08:15 | 000,369,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc.dll [2011/03/28 20:08:15 | 000,365,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_isv.dll [2011/03/28 20:08:15 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_isv.exe [2011/03/28 20:08:15 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate.exe [2011/03/28 20:08:15 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp.exe [2011/03/28 20:08:15 | 000,277,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp_isv.exe [2011/03/28 20:08:15 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp_isv.dll [2011/03/28 20:08:15 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp.dll [2011/03/28 20:08:14 | 000,101,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\consent.exe [2011/03/28 20:08:12 | 000,738,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpmde.dll [2011/03/28 20:01:54 | 000,219,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys [2011/03/28 20:01:54 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll [2011/03/28 19:51:23 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\vlc [2011/03/28 19:51:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2011/03/28 19:50:44 | 000,000,000 | ---D | C] -- C:\Programme\VideoLAN [2011/03/28 19:45:55 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Macromedia [2011/03/28 19:45:55 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Adobe [2011/03/28 19:44:15 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome [2011/03/28 19:42:38 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Google [2011/03/28 19:42:12 | 000,000,000 | ---D | C] -- C:\Programme\Intel [2011/03/28 19:37:33 | 000,000,000 | ---D | C] -- C:\Windows\System32\vmm32 [2011/03/28 19:37:33 | 000,000,000 | ---D | C] -- C:\Programme\Dell [2011/03/28 19:37:05 | 000,000,000 | -HSD | C] -- C:\Windows\Installer [2011/03/28 19:34:16 | 000,000,000 | R--D | C] -- C:\Users\Gpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2011/03/28 19:34:16 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Searches [2011/03/28 19:34:16 | 000,000,000 | R--D | C] -- C:\Users\Gpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2011/03/28 19:34:16 | 000,000,000 | -H-D | C] -- C:\Users\Gpa\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned [2011/03/28 19:34:04 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Identities [2011/03/28 19:33:59 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Contacts [2011/03/28 19:33:39 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\VirtualStore [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\AppData\Local\Temporary Internet Files [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Templates [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Start Menu [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\SendTo [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Recent [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\PrintHood [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\NetHood [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Documents\My Videos [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Documents\My Pictures [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Documents\My Music [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\My Documents [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Local Settings [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\AppData\Local\History [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Cookies [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Application Data [2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\AppData\Local\Application Data [2011/03/28 19:33:35 | 000,000,000 | --SD | C] -- C:\Users\Gpa\AppData\Roaming\Microsoft [2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Videos [2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Saved Games [2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Pictures [2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Music [2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Links [2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Favorites [2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Downloads [2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Documents [2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Desktop [2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2011/03/28 19:33:35 | 000,000,000 | -H-D | C] -- C:\Users\Gpa\AppData [2011/03/28 19:33:35 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Temp [2011/03/28 19:33:35 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Microsoft [2011/03/28 19:33:35 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Media Center Programs [2011/03/28 19:32:14 | 000,000,000 | -HSD | C] -- C:\Recovery [2011/03/27 02:31:17 | 000,000,000 | -HSD | C] -- C:\Boot [2011/03/26 19:55:05 | 000,000,000 | ---D | C] -- C:\Intel [2011/03/26 18:57:59 | 000,000,000 | ---D | C] -- C:\dell [2011/03/26 17:50:34 | 000,000,000 | -HSD | C] -- C:\Programme [2011/03/26 17:50:34 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen [2011/03/26 17:32:18 | 000,000,000 | -HSD | C] -- C:\System Volume Information [2010/08/25 18:59:08 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll ========== Files - Modified Within 30 Days ========== [2011/04/03 20:47:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1001UA.job [2011/04/03 20:31:10 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011/04/03 20:31:10 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011/04/03 20:24:12 | 000,000,242 | -H-- | M] () -- C:\Windows\tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job [2011/04/03 20:24:04 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011/04/03 20:24:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1003UA.job [2011/04/03 20:23:52 | 000,000,306 | -HS- | M] () -- C:\Windows\tasks\SQBLFMXO.job [2011/04/03 20:23:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011/04/03 20:23:36 | 1556,828,160 | -HS- | M] () -- C:\hiberfil.sys [2011/04/03 20:22:01 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011/04/03 19:47:01 | 000,001,058 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1001Core.job [2011/04/03 17:30:52 | 000,289,938 | ---- | M] () -- C:\Users\Gpa\Desktop\Unbenannt.jpg [2011/04/03 16:47:54 | 000,001,063 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/04/03 16:30:24 | 000,002,035 | ---- | M] () -- C:\Users\Gpa\Desktop\HijackThis.lnk [2011/04/03 11:55:41 | 000,000,781 | ---- | M] () -- C:\Users\Public\Desktop\Xfire.lnk [2011/04/03 00:24:00 | 000,001,058 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1003Core.job [2011/04/03 00:17:04 | 000,163,328 | ---- | M] () -- C:\Windows\Kmymia.exe [2011/04/02 22:30:25 | 000,000,757 | ---- | M] () -- C:\Users\Gpa\Desktop\GTA San Andreas.lnk [2011/04/01 16:52:17 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf [2011/03/31 23:49:49 | 000,007,168 | ---- | M] () -- C:\Users\Gpa\AppData\Roaming\clean2.exe [2011/03/31 23:27:41 | 000,000,809 | ---- | M] () -- C:\Users\Public\Desktop\World of Warcraft.lnk [2011/03/31 23:18:38 | 000,000,000 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\short.zip [2011/03/31 23:18:37 | 000,000,000 | ---- | M] () -- C:\h.zip [2011/03/30 15:55:35 | 000,348,685 | ---- | M] () -- C:\Users\Gpa\Desktop\Auftragsbestaetigung_186068.pdf [2011/03/30 15:53:43 | 000,011,801 | ---- | M] () -- C:\Users\Gpa\Desktop\__www.handytick.de_konto_auftrag_pdf_186068_Auftragsbestaetigung_186068.pdf [2011/03/29 12:10:01 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011/03/29 12:10:01 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011/03/29 12:10:01 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011/03/29 12:10:01 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011/03/29 12:05:31 | 000,292,696 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011/03/29 05:07:31 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK [2011/03/29 04:13:57 | 000,042,045 | ---- | M] () -- C:\Windows\System32\license.rtf [2011/03/28 22:15:03 | 000,000,991 | ---- | M] () -- C:\Users\Gpa\Desktop\Minecraft.lnk [2011/03/28 21:54:47 | 000,000,509 | ---- | M] () -- C:\Users\Gpa\Desktop\Lokaler Datenträger (E).lnk [2011/03/28 21:51:22 | 000,034,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\lhacm.acm [2011/03/28 21:49:17 | 000,231,248 | ---- | M] (TrueCrypt Foundation) -- C:\Windows\System32\drivers\truecrypt.sys [2011/03/28 21:40:40 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe [2011/03/28 21:40:40 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe [2011/03/28 21:40:40 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe [2011/03/28 21:40:39 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll [2011/03/28 21:34:47 | 000,001,790 | ---- | M] () -- C:\Users\Gpa\Application Data\Microsoft\Internet Explorer\Quick Launch\ICQ7.4.lnk [2011/03/28 21:07:11 | 000,295,922 | ---- | M] () -- C:\Windows\System32\perfi007.dat [2011/03/28 21:07:11 | 000,038,104 | ---- | M] () -- C:\Windows\System32\perfd007.dat [2011/03/28 19:46:00 | 000,407,526 | RHS- | M] () -- C:\LKWJR [2011/03/28 19:46:00 | 000,000,020 | RHS- | M] () -- C:\win7.ld [2011/03/28 19:38:38 | 000,001,403 | ---- | M] () -- C:\Users\Gpa\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2011/03/11 13:33:52 | 000,036,352 | ---- | M] () -- C:\Windows\System32\xfcodec.dll ========== Files Created - No Company Name ========== [2011/04/03 17:30:51 | 000,289,938 | ---- | C] () -- C:\Users\Gpa\Desktop\Unbenannt.jpg [2011/04/03 16:47:54 | 000,001,063 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/04/03 16:30:24 | 000,002,035 | ---- | C] () -- C:\Users\Gpa\Desktop\HijackThis.lnk [2011/04/03 11:55:41 | 000,000,781 | ---- | C] () -- C:\Users\Public\Desktop\Xfire.lnk [2011/04/03 00:17:09 | 000,163,328 | ---- | C] () -- C:\Windows\Kmymia.exe [2011/04/03 00:17:06 | 000,000,242 | -H-- | C] () -- C:\Windows\tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job [2011/04/03 00:17:03 | 000,000,306 | -HS- | C] () -- C:\Windows\tasks\SQBLFMXO.job [2011/04/02 22:30:25 | 000,000,757 | ---- | C] () -- C:\Users\Gpa\Desktop\GTA San Andreas.lnk [2011/04/01 16:52:17 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf [2011/03/31 23:49:49 | 000,007,168 | ---- | C] () -- C:\Users\Gpa\AppData\Roaming\clean2.exe [2011/03/31 23:25:15 | 000,000,809 | ---- | C] () -- C:\Users\Public\Desktop\World of Warcraft.lnk [2011/03/31 23:18:38 | 000,000,000 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\short.zip [2011/03/31 23:18:37 | 000,000,000 | ---- | C] () -- C:\h.zip [2011/03/31 20:17:36 | 000,001,090 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011/03/31 20:17:34 | 000,001,086 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011/03/31 18:21:18 | 000,001,251 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk [2011/03/31 18:16:30 | 000,001,320 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk [2011/03/30 15:55:35 | 000,348,685 | ---- | C] () -- C:\Users\Gpa\Desktop\Auftragsbestaetigung_186068.pdf [2011/03/30 15:53:43 | 000,011,801 | ---- | C] () -- C:\Users\Gpa\Desktop\__www.handytick.de_konto_auftrag_pdf_186068_Auftragsbestaetigung_186068.pdf [2011/03/29 19:38:59 | 000,000,991 | ---- | C] () -- C:\Users\Gpa\Desktop\Minecraft.lnk [2011/03/29 19:05:57 | 000,000,945 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pidgin.lnk [2011/03/29 04:13:47 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk [2011/03/29 04:13:37 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk [2011/03/29 04:08:25 | 1556,828,160 | -HS- | C] () -- C:\hiberfil.sys [2011/03/29 00:19:53 | 000,001,110 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1003UA.job [2011/03/29 00:19:51 | 000,001,058 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1003Core.job [2011/03/28 21:54:47 | 000,000,509 | ---- | C] () -- C:\Users\Gpa\Desktop\Lokaler Datenträger (E).lnk [2011/03/28 21:48:26 | 000,001,128 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 6.lnk [2011/03/28 21:47:11 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll [2011/03/28 21:36:14 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk [2011/03/28 21:34:47 | 000,001,790 | ---- | C] () -- C:\Users\Gpa\Application Data\Microsoft\Internet Explorer\Quick Launch\ICQ7.4.lnk [2011/03/28 21:31:06 | 000,001,100 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2011/03/28 21:17:22 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2011/03/28 21:08:27 | 000,653,928 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2011/03/28 21:08:27 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2011/03/28 21:08:27 | 000,129,800 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2011/03/28 21:08:27 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2011/03/28 19:46:00 | 000,000,020 | RHS- | C] () -- C:\win7.ld [2011/03/28 19:45:59 | 000,407,526 | RHS- | C] () -- C:\LKWJR [2011/03/28 19:42:41 | 000,001,110 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1001UA.job [2011/03/28 19:42:39 | 000,001,058 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1001Core.job [2011/03/28 19:38:37 | 000,001,403 | ---- | C] () -- C:\Users\Gpa\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2011/03/28 19:34:19 | 000,001,409 | ---- | C] () -- C:\Users\Gpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2011/03/28 19:33:36 | 000,000,290 | ---- | C] () -- C:\Users\Gpa\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk [2011/03/28 19:33:36 | 000,000,272 | ---- | C] () -- C:\Users\Gpa\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk [2011/03/27 02:31:18 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK [2011/03/27 02:31:17 | 000,383,562 | RHS- | C] () -- C:\bootmgr [2011/03/11 13:33:52 | 000,036,352 | ---- | C] () -- C:\Windows\System32\xfcodec.dll [2010/08/25 19:30:02 | 000,439,308 | ---- | C] () -- C:\Windows\System32\igcompkrng500.bin [2010/08/25 19:30:00 | 000,982,240 | ---- | C] () -- C:\Windows\System32\igkrng500.bin [2010/08/25 19:30:00 | 000,092,356 | ---- | C] () -- C:\Windows\System32\igfcg500m.bin [2010/08/25 18:57:00 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config [2010/08/25 18:52:00 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll [2010/08/25 18:52:00 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll [2009/07/14 06:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009/07/14 06:33:53 | 000,292,696 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2009/07/14 04:05:48 | 000,615,810 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2009/07/14 04:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2009/07/14 04:05:48 | 000,106,190 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2009/07/14 04:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2009/07/14 04:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2009/07/14 04:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2009/07/14 02:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2009/07/14 01:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009/07/14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll [2009/07/14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll [2009/07/14 00:09:19 | 000,139,824 | ---- | C] () -- C:\Windows\System32\igfcg500.bin [2009/06/10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat < End of report > |
04.04.2011, 08:27 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Allgemeine Fragen... Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL PRC - C:\Windows\Kmymia.exe () O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.) O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.) O3 - HKLM\..\Toolbar: (Gutscheinmieze) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - C:\Users\Gpa\AppData\Roaming\Gutscheinmieze\toolbar.dll (Synatix GmbH) O3 - HKCU\..\Toolbar\WebBrowser: (Gutscheinmieze) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - C:\Users\Gpa\AppData\Roaming\Gutscheinmieze\toolbar.dll (Synatix GmbH) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.) O4 - HKCU..\Run: [IKXGVMFZHI] File not found [2011/04/03 17:51:04 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\{295F13A8-D99B-480E-A9C5-C21F05C0784E} [2011/04/03 17:42:26 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Gutscheinmieze [2011/04/03 00:05:23 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\gctmp [2011/03/28 21:37:35 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521} :Files C:\Windows\tasks\*.job C:\Windows\Kmymia.exe C:\Users\Gpa\AppData\Roaming\clean2.exe C:\h.zip :Commands [purity] [resethosts] [emptytemp] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.
__________________ Logfiles bitte immer in CODE-Tags posten |
04.04.2011, 12:57 | #11 |
| Allgemeine Fragen... Als ich den Fix ausgeführt habe wurden automatisch alle Programme geschlossen bzw. es war nur noch der Bildschirm zu sehen, keine Taskleiste etc. Ist/war das normal? Es hat sich kein Logfile geöffnet! |
04.04.2011, 13:04 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Allgemeine Fragen... Ja das ist durchaus normal. Starte Windows neu und schau mal in den Ordner C:\_OTL - da sollte das Fixlog zu sehen sein.
__________________ Logfiles bitte immer in CODE-Tags posten |
04.04.2011, 13:11 | #13 |
| Allgemeine Fragen... All processes killed ========== OTL ========== No active process named Kmymia.exe was found! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ deleted successfully. C:\Programme\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ deleted successfully. C:\Programme\ICQ6Toolbar\ICQToolBar.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{B922D405-6D13-4A2B-AE89-08A030DA4402} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ not found. File C:\Programme\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27}\ deleted successfully. C:\Users\Gpa\AppData\Roaming\Gutscheinmieze\toolbar.dll moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27}\ not found. File C:\Users\Gpa\AppData\Roaming\Gutscheinmieze\toolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings deleted successfully. C:\Programme\Common Files\Spigot\Search Settings\SearchSettings.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\IKXGVMFZHI deleted successfully. C:\Users\Gpa\AppData\Local\{295F13A8-D99B-480E-A9C5-C21F05C0784E} folder moved successfully. C:\Users\Gpa\AppData\Roaming\Gutscheinmieze folder moved successfully. C:\Users\Gpa\AppData\Local\gctmp folder moved successfully. C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\x86 folder moved successfully. C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86 folder moved successfully. C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521} folder moved successfully. ========== FILES ========== C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully. C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully. C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1001Core.job moved successfully. C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1001UA.job moved successfully. C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1003Core.job moved successfully. C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1003UA.job moved successfully. C:\Windows\tasks\SQBLFMXO.job moved successfully. C:\Windows\tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job moved successfully. C:\Windows\Kmymia.exe moved successfully. C:\Users\Gpa\AppData\Roaming\clean2.exe moved successfully. C:\h.zip moved successfully. ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Gpa ->Temp folder emptied: 2101308 bytes ->Temporary Internet Files folder emptied: 42235887 bytes ->Java cache emptied: 1864694 bytes ->FireFox cache emptied: 128835662 bytes ->Google Chrome cache emptied: 254435757 bytes ->Flash cache emptied: 4864 bytes User: psx ->Temp folder emptied: 93720428 bytes ->Temporary Internet Files folder emptied: 52892773 bytes ->Java cache emptied: 604 bytes ->Google Chrome cache emptied: 320866170 bytes ->Flash cache emptied: 7124 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1425 bytes RecycleBin emptied: 15611664 bytes Total Files Cleaned = 870.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 04042011_135002 Files\Folders moved on Reboot... Registry entries deleted on Reboot... |
04.04.2011, 13:19 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Allgemeine Fragen... Ich brauch den Quarantäneordner von OTL. Bitte folgendes machen: 1.) GANZ WICHTIG!! Virenscanner deaktivieren, der darf da nicht rummurksen! 2.) Ordner C:\_OTL in eine Datei zippen 3.) Die erstellte ZIP-Datei hier hochladen => http://www.trojaner-board.de/54791-a...ner-board.html 4.) Wenns erfolgreich war Bescheid sagen 5.) Erst dann wieder den Virenscanner einschalten
__________________ Logfiles bitte immer in CODE-Tags posten |
04.04.2011, 13:31 | #15 |
| Allgemeine Fragen... Das zippen funktioniert nicht. Mir wird der Zugriff verweigert. |
Themen zu Allgemeine Fragen... |
allgemeine, anhang, bekannte, bezüglich, compu, computers, fehler, fenster, frage, fragen, laufe, laufen, programme, programmen, prozesse, sache, start, taskleiste, taskmanager, thema, unbekannte, unbekannten, verschiedene, verschiedenen, verschwinden |