ausdemFF | 08.11.2011 13:06 | Internet Speed halbiert nach teilweiser entfernung von TrojanDownloader:Win32/Small.gen!I Hallo,
ich bin Marcel und habe einen Trojaner.
Dieser hat sich gestern im Laufe des Vormittags bemerkbar gemacht da meine Firewall ständig andere Programme blocken wollte. Einmal war es ebay.exe und auch mal Ploizz.exe .
Ich hab mir da nicht soviel Gedanken gemacht und gesehen das eine 0kb SVCHOST da ist erstellt in users/mein Name/App Data/ Roaming/Microsoft/
Diese + alle weiteren die das Programm erstellt hat hab ich gelöscht. DANACH am Abend hat mich Windows Defender erst drauf aufmerksam gemacht das
TrojanDownloader:Win32/Small.gen!I
hier nicht sein sollte. Seitdem ist mein Downspeed auf 350kb anstatt ca 800 (PERMANENT) und der Upstream auf 35 von 75. Hab geschaut ob ichs allein irgendwie lösen kann, aber, hier bin ich nun.
Es gab auch zeitgleich mehrere TCP & UDP Flood Angriffe auif meinen Router wenn ich das richtig gelesen habe. Die Logfile ist mit in der Zip in welcher auch Scans sind.
Betriebssystem Windows 7 + Avira Professional + Windows Defender + CCleaner & Tweak Me!
OTL: Code:
OTL logfile created on: 08.11.2011 11:44:00 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\xxx\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,09 Gb Available Physical Memory | 69,68% Memory free
6,00 Gb Paging File | 4,93 Gb Available in Paging File | 82,25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232,88 Gb Total Space | 13,65 Gb Free Space | 5,86% Space Free | Partition Type: NTFS
Drive D: | 465,70 Gb Total Space | 5,06 Gb Free Space | 1,09% Space Free | Partition Type: FAT32
Computer Name: xxx | User Name: xxx | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.11.08 11:40:54 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\xxx\Desktop\OTL.exe
PRC - [2011.11.08 11:33:51 | 000,050,477 | ---- | M] () -- C:\Users\xxx\Desktop\Defogger.exe
PRC - [2011.11.05 13:37:18 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2011.11.05 13:34:56 | 000,463,824 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe
PRC - [2011.11.05 13:34:50 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.11.05 13:34:33 | 000,342,480 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avmailc.exe
PRC - [2011.11.05 13:34:21 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.11.05 13:34:15 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.11.05 13:34:11 | 000,616,400 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avfwsvc.exe
PRC - [2011.08.30 17:18:30 | 002,358,656 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe
PRC - [2011.08.03 12:50:00 | 002,255,464 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011.08.03 12:50:00 | 000,812,648 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2011.08.03 02:31:42 | 000,379,496 | ---- | M] (NVIDIA Corporation) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011.08.01 14:56:42 | 001,821,576 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft IntelliPoint\ipoint.exe
PRC - [2011.07.29 20:31:40 | 001,249,064 | ---- | M] () -- C:\ProgramData\TVersity\Media Server\MediaServer.exe
PRC - [2011.06.24 05:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.12.10 18:30:50 | 000,086,880 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2010.12.10 18:29:30 | 000,238,944 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe
PRC - [2010.11.20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2010.11.20 13:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.01.09 20:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
PRC - [2009.10.02 13:14:48 | 000,643,592 | ---- | M] (Avid Technology, Inc.) -- C:\Windows\System32\M-AudioTaskBarIcon.exe
PRC - [2009.08.27 16:09:10 | 001,253,376 | ---- | M] (MAGIX AG) -- C:\Programme\Common Files\MAGIX Services\Database\bin\FABS.exe
PRC - [2008.09.29 12:15:00 | 000,155,648 | ---- | M] (NVIDIA) -- C:\Programme\NVIDIA Corporation\nTune\nTuneService.exe
PRC - [2008.09.10 12:31:36 | 000,114,688 | ---- | M] (NVIDIA) -- C:\Programme\NVIDIA Corporation\System Update\UpdateCenterService.exe
========== Modules (No Company Name) ==========
MOD - [2011.11.08 11:33:51 | 000,050,477 | ---- | M] () -- C:\Users\xxx\Desktop\Defogger.exe
MOD - [2011.07.18 22:04:08 | 000,296,448 | ---- | M] () -- C:\Programme\Notepad++\NppShell_04.dll
MOD - [2011.03.17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Programme\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010.03.15 10:28:22 | 000,141,824 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
MOD - [2008.07.24 22:51:32 | 000,299,008 | ---- | M] () -- C:\Programme\IconChanger\IconChng.dll
MOD - [2005.07.18 16:46:08 | 000,074,240 | ---- | M] () -- C:\Programme\iPhone Folders\zlibwapi.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (FileZilla Server)
SRV - [2011.11.05 13:37:18 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.11.05 13:34:56 | 000,463,824 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE -- (AntiVirWebService)
SRV - [2011.11.05 13:34:33 | 000,342,480 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService)
SRV - [2011.11.05 13:34:21 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.11.05 13:34:11 | 000,616,400 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe -- (AntiVirFirewallService)
SRV - [2011.10.12 22:30:31 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011.08.30 17:18:30 | 002,358,656 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2011.08.03 12:50:00 | 002,255,464 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011.08.03 02:31:42 | 000,379,496 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011.07.29 20:31:40 | 001,249,064 | ---- | M] () [Auto | Running] -- C:\ProgramData\TVersity\Media Server\MediaServer.exe -- (TVersityMediaServer)
SRV - [2011.06.12 11:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2010.12.28 09:00:34 | 001,296,728 | ---- | M] (www.BitComet.com) [On_Demand | Stopped] -- C:\Program Files\BitComet\tools\BitCometService.exe -- (BITCOMET_HELPER_SERVICE)
SRV - [2009.08.27 16:09:10 | 001,253,376 | ---- | M] (MAGIX AG) [Unknown | Running] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs)
SRV - [2009.07.14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008.09.29 12:15:00 | 000,155,648 | ---- | M] (NVIDIA) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe -- (nTuneService)
SRV - [2008.09.10 12:31:36 | 000,114,688 | ---- | M] (NVIDIA) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe -- (UpdateCenterService)
SRV - [2008.08.07 10:10:02 | 003,276,800 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
========== Driver Services (SafeList) ==========
DRV - [2011.11.05 13:38:12 | 000,111,160 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avfwot.sys -- (avfwot)
DRV - [2011.11.05 13:38:12 | 000,091,096 | ---- | M] (Avira GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\avfwim.sys -- (avfwim)
DRV - [2011.10.11 14:00:01 | 000,134,344 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.10.11 14:00:01 | 000,074,640 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.10.11 14:00:01 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2011.08.03 12:50:00 | 010,304,104 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2011.07.29 12:54:56 | 000,014,216 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\epmntdrv.sys -- (epmntdrv)
DRV - [2011.07.29 12:54:56 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2011.05.18 07:09:04 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d)
DRV - [2010.11.20 13:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 13:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 13:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 11:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010.11.20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (winusb)
DRV - [2010.11.20 10:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 10:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010.06.17 14:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.05.07 06:49:28 | 000,061,824 | ---- | M] (SCM Microsystems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SCL01132.sys -- (SCL01132)
DRV - [2009.10.02 13:14:42 | 000,042,248 | ---- | M] (M-Audio) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MAudioConectiv_DFU.sys -- (MADFUCONECTIV)
DRV - [2009.10.02 13:14:38 | 000,158,344 | ---- | M] (Avid Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MAudioConectiv.sys -- (MAUSBCONECTIV)
DRV - [2009.07.13 23:09:17 | 004,194,816 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2008.09.29 12:17:06 | 000,029,952 | ---- | M] (NVIDIA Corp.) [Kernel | On_Demand | Running] -- C:\Windows\nvoclock.sys -- (NVR0Dev)
DRV - [2008.09.10 12:28:48 | 000,036,896 | ---- | M] (NVidia Corp.) [Kernel | Auto | Running] -- C:\Windows\nvflash.sys -- (NVR0FLASHDev)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B5 6E 2B 63 8B 71 CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.03 16:22:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.07 07:01:44 | 000,000,000 | ---D | M]
[2011.06.20 17:49:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xxx\AppData\Roaming\mozilla\Extensions
[2011.06.20 17:49:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xxx\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.11.06 13:35:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\nxh9q5dv.default\extensions
[2011.11.06 02:42:31 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\nxh9q5dv.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011.11.04 23:39:04 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\nxh9q5dv.default\extensions\foxmarks@kei.com
[2011.11.05 13:56:20 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\nxh9q5dv.default\extensions\support@lastpass.com
[2011.10.25 14:42:19 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.10.25 14:42:21 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\xxx\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXH9Q5DV.DEFAULT\EXTENSIONS\{023E9CA0-63F3-47B1-BCB2-9BADF9D9EF28}.XPI
() (No name found) -- C:\USERS\xxx\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXH9Q5DV.DEFAULT\EXTENSIONS\{578E7CAA-210F-4967-A0D3-88FE5B59A39F}.XPI
() (No name found) -- C:\USERS\xxx\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NXH9Q5DV.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011.10.28 19:16:39 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.09.09 05:49:04 | 001,037,112 | ---- | M] (BitComet) -- C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll
[2011.10.03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.10.28 19:16:37 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.28 19:16:37 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.10.28 19:16:37 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.28 19:16:37 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.28 19:16:37 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.28 19:16:37 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2011.09.11 07:57:32 | 000,001,411 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Programme\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [M-Audio Taskbar Icon] C:\Windows\System32\M-AudioTaskBarIcon.exe (Avid Technology, Inc.)
O4 - HKCU..\Run: [ncid.Net] C:\Programme\ncid.Net\ncid.Net.exe (Gerhard Junker)
O4 - HKCU..\Run: [Pidgin] C:\Program Files\Pidgin\pidgin.exe (The Pidgin developer community)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O8 - Extra context menu item: &Alles mit BitComet herunterladen - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Mit BitComet herunter&laden - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{42C4B1FC-554F-4648-B813-04C89BADD8D0}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9C5B3D2D-DB52-402B-AEC3-0285D1BECEC7}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{05978b59-c5d8-11e0-850e-406186c2d919}\Shell - "" = AutoRun
O33 - MountPoints2\{05978b59-c5d8-11e0-850e-406186c2d919}\Shell\AutoRun\command - "" = "L:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{8f7f0038-9b51-11e0-8582-406186c2d919}\Shell - "" = AutoRun
O33 - MountPoints2\{8f7f0038-9b51-11e0-8582-406186c2d919}\Shell\AutoRun\command - "" = J:\autorun\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {B8DB38AA-C10B-9756-993B-9481422BFC9C} - Browser Customizations
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
MsConfig - StartUpReg: NVIDIA nTune - hkey= - key= - C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011.11.08 11:40:51 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\xxx\Desktop\OTL.exe
[2011.11.08 00:02:14 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011.11.07 18:47:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Gerhard Junker
[2011.11.07 18:47:14 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\Gerhard_Junker
[2011.11.07 18:43:03 | 000,000,000 | ---D | C] -- C:\ProgramData\ncid.Net
[2011.11.07 18:43:03 | 000,000,000 | ---D | C] -- C:\Program Files\ncid.Net
[2011.11.07 18:02:01 | 000,000,000 | ---D | C] -- C:\Users\xxx\Documents\Network Monitor 3
[2011.11.07 17:48:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NET Traffic Meter
[2011.11.07 17:48:47 | 000,000,000 | ---D | C] -- C:\Program Files\NET Traffic Meter
[2011.11.07 17:38:31 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\NetMeter
[2011.11.07 17:38:29 | 000,000,000 | ---D | C] -- C:\Program Files\NetMeter
[2011.11.07 17:26:11 | 000,000,000 | ---D | C] -- C:\ProgramData\DeskSoft
[2011.11.07 17:25:35 | 000,024,816 | ---- | C] (DeskSoft) -- C:\Windows\System32\drivers\dsnpfd.sys
[2011.11.07 17:25:34 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\DeskSoft
[2011.11.07 15:05:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Axence NetTools Pro 4.0
[2011.11.07 15:05:13 | 000,000,000 | ---D | C] -- C:\Program Files\Axence
[2011.11.07 08:56:03 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\gtk-2.0
[2011.11.07 08:38:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011.11.07 08:36:57 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy 2
[2011.11.07 07:42:42 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\.purple
[2011.11.07 07:39:12 | 000,000,000 | ---D | C] -- C:\Program Files\Pidgin
[2011.11.07 03:54:28 | 000,000,000 | ---D | C] -- C:\Program Files\MSECache
[2011.11.07 03:52:54 | 000,000,000 | ---D | C] -- C:\Program Settings
[2011.11.06 00:08:44 | 000,000,000 | ---D | C] -- C:\Windows\W7SBC
[2011.11.05 23:59:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RocketDock
[2011.11.05 23:58:58 | 000,000,000 | ---D | C] -- C:\Program Files\RocketDock
[2011.11.05 23:58:26 | 000,000,000 | ---D | C] -- C:\Program Files\foobar2000
[2011.11.05 23:58:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IconChanger
[2011.11.05 23:58:09 | 000,000,000 | ---D | C] -- C:\Program Files\IconChanger
[2011.11.05 23:57:52 | 000,000,000 | ---D | C] -- C:\Program Files\Rainmeter
[2011.11.05 18:34:08 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Stardock
[2011.11.05 18:33:55 | 000,042,672 | ---- | C] (Stardock.Net, Inc) -- C:\Windows\System32\wbsys.dll
[2011.11.05 18:33:49 | 000,000,000 | ---D | C] -- C:\Program Files\Stardock
[2011.11.05 18:18:29 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\Auslogics
[2011.11.05 18:18:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
[2011.11.05 18:18:22 | 000,000,000 | ---D | C] -- C:\Program Files\Auslogics
[2011.11.05 17:55:40 | 000,000,000 | ---D | C] -- C:\Program Files\Setup Files
[2011.11.05 16:17:45 | 000,000,000 | ---D | C] -- C:\Users\xxx\Documents\Verknüpfungen
[2011.11.05 15:27:10 | 000,000,000 | ---D | C] -- C:\Program Files\Dr. Hardware 2011
[2011.11.05 14:46:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweakMe!
[2011.11.05 14:46:59 | 000,000,000 | ---D | C] -- C:\Program Files\TweakMe!
[2011.11.05 14:35:17 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\Frameworkx.com
[2011.11.05 14:20:05 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\NeoSmart_Technologies
[2011.11.05 14:17:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSmart Technologies
[2011.11.05 14:17:16 | 000,000,000 | ---D | C] -- C:\Program Files\NeoSmart Technologies
[2011.11.05 13:43:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011.11.05 13:43:05 | 000,111,160 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avfwot.sys
[2011.11.05 13:43:05 | 000,091,096 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avfwim.sys
[2011.11.05 06:01:46 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\Xilisoft
[2011.11.05 01:32:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free FLV Converter
[2011.11.05 01:32:47 | 000,307,200 | ---- | C] (FLV.com) -- C:\Windows\System32\TubeFinder.exe
[2011.11.05 01:32:42 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\FreeFLVConverter
[2011.11.05 01:32:42 | 000,000,000 | ---D | C] -- C:\Program Files\Free FLV Converter
[2011.11.04 14:57:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
[2011.11.03 17:55:12 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2011.11.03 16:22:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet
[2011.11.03 16:22:39 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\BitComet
[2011.11.03 16:22:37 | 000,000,000 | ---D | C] -- C:\Program Files\BitComet
[2011.11.03 10:56:49 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2011.11.03 10:34:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011.11.03 10:34:47 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2011.11.02 17:46:53 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\Installer5804
[2011.11.02 17:40:09 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\Installer5848
[2011.11.01 11:18:44 | 000,000,000 | ---D | C] -- C:\Users\xxx\Documents\Outlook-Dateien
[2011.11.01 09:05:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011.11.01 09:05:27 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011.11.01 09:03:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.11.01 09:02:23 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.10.31 09:36:17 | 009,925,160 | ---- | C] (LastPass) -- C:\Program Files\Common Files\lpuninstall.exe
[2011.10.31 09:36:14 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
[2011.10.31 09:36:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastPass
[2011.10.31 09:36:10 | 000,000,000 | ---D | C] -- C:\Program Files\LastPass
[2011.10.28 07:18:56 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\MicroVision Applications
[2011.10.28 07:17:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SureThing
[2011.10.28 07:17:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SureThing Shared
[2011.10.28 07:17:29 | 000,000,000 | ---D | C] -- C:\Program Files\SureThing
[2011.10.28 07:17:29 | 000,000,000 | ---D | C] -- C:\Windows\MVUNINST
[2011.10.25 13:07:00 | 000,000,000 | ---D | C] -- C:\Users\xxx\Documents\iZotope
[2011.10.23 20:59:33 | 000,000,000 | ---D | C] -- C:\Users\xxx\Documents\backup
[2011.10.22 23:53:57 | 000,000,000 | -H-D | C] -- C:\ProgramData\{E26B3878-7CEC-469C-B449-5CAA336DF8CD}
[2011.10.22 23:49:26 | 000,000,000 | -H-D | C] -- C:\ProgramData\{C78336EC-F2EB-4640-99A4-DFE96581B90B}
[2011.10.18 11:35:45 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\Avira
[2011.10.18 11:35:06 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2011.10.18 11:35:05 | 000,134,344 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011.10.18 11:35:05 | 000,074,640 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011.10.18 11:35:05 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avkmgr.sys
[2011.10.18 11:34:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011.10.18 11:34:27 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011.10.14 00:59:16 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\TempDIR
[2011.10.13 23:59:43 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlexyDeskop
[2011.10.13 23:59:43 | 000,000,000 | ---D | C] -- C:\Program Files\plexydesk
[2011.10.13 23:51:24 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\Bump Technologies, Inc
[2011.10.13 23:46:52 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\Bump Technologies, Inc
[2011.10.13 23:41:26 | 000,000,000 | ---D | C] -- C:\Windows\System32\directx
[2011.10.13 21:51:11 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\MediaMonkey
[2011.10.13 21:51:07 | 000,000,000 | ---D | C] -- C:\Program Files\MediaMonkey
[2011.10.13 21:37:56 | 000,000,000 | -H-D | C] -- C:\$WINDOWS.~BT
[2011.10.13 21:13:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EASEUS Partition Master 9.1.0 Home Edition
[2011.10.13 21:12:51 | 000,000,000 | ---D | C] -- C:\Program Files\EASEUS
[2011.10.12 22:30:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rosetta Stone
[2011.10.12 22:30:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Rosetta Stone
[2011.10.12 22:30:18 | 000,000,000 | ---D | C] -- C:\Program Files\Rosetta Stone
[2011.10.12 18:34:42 | 000,000,000 | ---D | C] -- C:\Users\xxx\Documents\GForce
[2011.10.12 18:34:42 | 000,000,000 | ---D | C] -- C:\Program Files\GForce
[2011.10.12 18:20:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Arturia
[2011.10.12 08:20:05 | 000,000,000 | ---D | C] -- C:\Users\xxx\Documents\Kontakte Alt
========== Files - Modified Within 30 Days ==========
[2011.11.08 11:40:54 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\xxx\Desktop\OTL.exe
[2011.11.08 11:39:39 | 000,000,000 | ---- | M] () -- C:\Users\xxx\defogger_reenable
[2011.11.08 11:39:00 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.11.08 11:33:51 | 000,050,477 | ---- | M] () -- C:\Users\xxx\Desktop\Defogger.exe
[2011.11.08 11:23:23 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.11.08 11:16:17 | 000,020,800 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.11.08 11:16:17 | 000,020,800 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.11.08 11:09:00 | 000,000,843 | ---- | M] () -- C:\Windows\System32\tversity.cookies
[2011.11.08 11:08:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.11.08 07:18:48 | 000,233,472 | ---- | M] () -- C:\Users\xxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.11.07 22:47:07 | 000,717,336 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.11.07 22:47:07 | 000,667,932 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.11.07 22:47:07 | 000,155,856 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.11.07 22:47:07 | 000,125,766 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.11.07 18:47:16 | 000,000,081 | ---- | M] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2011.11.07 18:19:03 | 000,003,124 | ---- | M] () -- C:\Users\xxx\Documents\cc_20111107_181859.reg
[2011.11.07 17:25:35 | 000,024,816 | ---- | M] (DeskSoft) -- C:\Windows\System32\drivers\dsnpfd.sys
[2011.11.07 10:50:13 | 000,013,326 | ---- | M] () -- C:\Users\xxx\Documents\cc_20111107_105010.reg
[2011.11.07 08:28:57 | 000,007,608 | ---- | M] () -- C:\Users\xxx\AppData\Local\Resmon.ResmonCfg
[2011.11.07 07:39:37 | 000,000,937 | ---- | M] () -- C:\Users\Public\Desktop\Pidgin.lnk
[2011.11.07 07:04:43 | 000,001,886 | ---- | M] () -- C:\Users\xxx\Documents\cc_20111107_070440.reg
[2011.11.06 13:40:46 | 000,001,516 | ---- | M] () -- C:\Users\xxx\Documents\cc_20111106_134043.reg
[2011.11.06 10:13:12 | 002,281,928 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.11.06 10:05:56 | 000,091,306 | ---- | M] () -- C:\Users\xxx\Documents\cc_20111106_100546.reg
[2011.11.05 20:51:55 | 000,005,554 | ---- | M] () -- C:\Windows\System32\Utility.xml
[2011.11.05 14:08:27 | 000,000,466 | ---- | M] () -- C:\Users\xxx\Documents\bibo.reg
[2011.11.05 13:38:12 | 000,111,160 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avfwot.sys
[2011.11.05 13:38:12 | 000,091,096 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avfwim.sys
[2011.11.05 02:25:07 | 000,000,176 | ---- | M] () -- C:\Windows\System32\w3data.vss
[2011.11.05 02:25:07 | 000,000,176 | ---- | M] () -- C:\Windows\System32\msvcsv60.dll
[2011.11.05 02:25:07 | 000,000,176 | ---- | M] () -- C:\Windows\msocreg32.dat
[2011.11.03 10:59:16 | 000,000,600 | ---- | M] () -- C:\Users\xxx\AppData\Roaming\winscp.rnd
[2011.11.02 14:48:47 | 000,049,382 | ---- | M] () -- C:\Users\xxx\Documents\dragon age 2.rtf
[2011.10.31 09:36:17 | 009,925,160 | ---- | M] (LastPass) -- C:\Program Files\Common Files\lpuninstall.exe
[2011.10.28 07:25:35 | 000,054,444 | ---- | M] () -- C:\Users\xxx\Documents\cordless1.std
[2011.10.20 17:04:23 | 001,866,317 | ---- | M] () -- C:\Users\xxx\Documents\IMG_0235.JPG
[2011.10.20 17:04:22 | 001,751,155 | ---- | M] () -- C:\Users\xxx\Documents\IMG_0230.JPG
[2011.10.20 17:04:22 | 001,708,458 | ---- | M] () -- C:\Users\xxx\Documents\IMG_0231.JPG
[2011.10.20 16:58:00 | 000,055,926 | ---- | M] () -- C:\Users\xxx\Documents\Unbenanntes Dokument 2.pdf
[2011.10.20 16:58:00 | 000,000,032 | ---- | M] () -- C:\Users\xxx\Documents\Teil 1.3
[2011.10.16 15:10:03 | 000,399,876 | RHS- | M] () -- C:\TOGMY
[2011.10.16 15:10:03 | 000,000,000 | RHS- | M] () -- C:\jkcv.ld
[2011.10.14 08:42:17 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2011.10.13 21:47:23 | 000,001,908 | ---- | M] () -- C:\Windows\diagwrn.xml
[2011.10.13 21:47:23 | 000,001,908 | ---- | M] () -- C:\Windows\diagerr.xml
[2011.10.13 21:22:38 | 000,001,119 | -H-- | M] () -- C:\Windows\EPMBatch.ept
[2011.10.12 17:57:27 | 000,022,648 | ---- | M] () -- C:\Users\xxx\Documents\cc_20111012_185722.reg
[2011.10.11 14:00:01 | 000,134,344 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011.10.11 14:00:01 | 000,074,640 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011.10.11 14:00:01 | 000,036,000 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avkmgr.sys
========== Files Created - No Company Name ==========
[2011.11.08 11:39:39 | 000,000,000 | ---- | C] () -- C:\Users\xxx\defogger_reenable
[2011.11.08 11:33:47 | 000,050,477 | ---- | C] () -- C:\Users\xxx\Desktop\Defogger.exe
[2011.11.07 18:47:16 | 000,000,081 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2011.11.07 18:19:01 | 000,003,124 | ---- | C] () -- C:\Users\xxx\Documents\cc_20111107_181859.reg
[2011.11.07 10:50:11 | 000,013,326 | ---- | C] () -- C:\Users\xxx\Documents\cc_20111107_105010.reg
[2011.11.07 08:28:57 | 000,007,608 | ---- | C] () -- C:\Users\xxx\AppData\Local\Resmon.ResmonCfg
[2011.11.07 07:39:37 | 000,000,937 | ---- | C] () -- C:\Users\Public\Desktop\Pidgin.lnk
[2011.11.07 07:04:42 | 000,001,886 | ---- | C] () -- C:\Users\xxx\Documents\cc_20111107_070440.reg
[2011.11.06 13:40:44 | 000,001,516 | ---- | C] () -- C:\Users\xxx\Documents\cc_20111106_134043.reg
[2011.11.06 10:05:48 | 000,091,306 | ---- | C] () -- C:\Users\xxx\Documents\cc_20111106_100546.reg
[2011.11.05 20:51:55 | 000,005,554 | ---- | C] () -- C:\Windows\System32\Utility.xml
[2011.11.05 18:34:05 | 000,057,904 | ---- | C] () -- C:\Windows\System32\wbload.dll
[2011.11.05 14:08:27 | 000,000,466 | ---- | C] () -- C:\Users\xxx\Documents\bibo.reg
[2011.11.05 13:42:28 | 000,000,512 | R--- | C] () -- C:\Users\xxx\Documents\HBEDV.KEY
[2011.11.05 01:32:44 | 000,208,500 | ---- | C] () -- C:\Windows\System32\ReyXpBasics.tlb
[2011.11.05 01:32:43 | 000,364,544 | ---- | C] () -- C:\Windows\System32\PropertyGrid.ocx
[2011.11.05 01:32:42 | 000,024,576 | ---- | C] () -- C:\Windows\System32\ControlSubX.ocx
[2011.11.02 17:41:24 | 000,001,361 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit 2.lnk
[2011.11.02 14:48:46 | 000,049,382 | ---- | C] () -- C:\Users\xxx\Documents\dragon age 2.rtf
[2011.10.28 07:25:35 | 000,054,444 | ---- | C] () -- C:\Users\xxx\Documents\cordless1.std
[2011.10.20 17:04:23 | 001,866,317 | ---- | C] () -- C:\Users\xxx\Documents\IMG_0235.JPG
[2011.10.20 17:04:22 | 001,751,155 | ---- | C] () -- C:\Users\xxx\Documents\IMG_0230.JPG
[2011.10.20 17:04:22 | 001,708,458 | ---- | C] () -- C:\Users\xxx\Documents\IMG_0231.JPG
[2011.10.20 16:57:39 | 000,000,032 | ---- | C] () -- C:\Users\xxx\Documents\Teil 1.3
[2011.10.20 16:57:34 | 000,055,926 | ---- | C] () -- C:\Users\xxx\Documents\Unbenanntes Dokument 2.pdf
[2011.10.16 15:10:03 | 000,000,000 | RHS- | C] () -- C:\jkcv.ld
[2011.10.16 15:10:02 | 000,399,876 | RHS- | C] () -- C:\TOGMY
[2011.10.14 08:42:15 | 000,000,001 | -HS- | C] () -- C:\BOOTNXT
[2011.10.13 21:19:26 | 000,001,119 | -H-- | C] () -- C:\Windows\EPMBatch.ept
[2011.10.13 21:13:10 | 000,019,840 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll
[2011.10.13 21:13:09 | 002,469,760 | ---- | C] () -- C:\Windows\System32\BootMan.exe
[2011.10.13 21:13:09 | 000,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe
[2011.10.13 21:13:09 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys
[2011.10.13 21:13:09 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys
[2011.10.12 21:56:35 | 000,001,908 | ---- | C] () -- C:\Windows\diagwrn.xml
[2011.10.12 21:56:35 | 000,001,908 | ---- | C] () -- C:\Windows\diagerr.xml
[2011.10.12 17:57:24 | 000,022,648 | ---- | C] () -- C:\Users\xxx\Documents\cc_20111012_185722.reg
[2011.09.26 10:54:25 | 000,000,072 | ---- | C] () -- C:\Windows\SSB.ini
[2011.09.25 23:24:05 | 000,000,000 | -H-- | C] () -- C:\Users\xxx\AppData\Roaming\.51BEE852859F7D89.sys
[2011.09.25 22:11:27 | 000,000,034 | ---- | C] () -- C:\Windows\System32\mnprxpd2e.bin
[2011.09.12 13:19:03 | 000,403,912 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2011.09.11 08:27:55 | 000,000,600 | ---- | C] () -- C:\Users\xxx\AppData\Roaming\winscp.rnd
[2011.08.03 02:31:54 | 000,311,912 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe
[2011.07.16 03:32:11 | 000,002,756 | ---- | C] () -- C:\Windows\System32\ssolekuy.dll
[2011.07.16 03:32:11 | 000,002,756 | ---- | C] () -- C:\Windows\System32\ssoleht.dll
[2011.07.16 03:32:11 | 000,002,756 | ---- | C] () -- C:\Windows\System32\sslibkh.dll
[2011.07.16 03:32:11 | 000,002,756 | ---- | C] () -- C:\Windows\System32\sslibjy.dll
[2011.07.16 03:32:11 | 000,002,756 | ---- | C] () -- C:\Windows\System32\sslibfg.dll
[2011.07.16 03:32:11 | 000,002,756 | ---- | C] () -- C:\Windows\System32\sslibeh.dll
[2011.07.16 03:32:11 | 000,002,756 | ---- | C] () -- C:\Windows\System32\slibff.dll
[2011.07.16 03:32:11 | 000,002,756 | ---- | C] () -- C:\Windows\System32\slibddf.dll
[2011.07.16 03:32:06 | 000,678,746 | ---- | C] () -- C:\Windows\unins000.exe
[2011.07.16 03:32:05 | 000,021,007 | ---- | C] () -- C:\Windows\unins000.dat
[2011.07.07 03:19:44 | 000,000,176 | ---- | C] () -- C:\Windows\System32\msvcsv60.dll
[2011.07.07 03:19:44 | 000,000,176 | ---- | C] () -- C:\Windows\msocreg32.dat
[2011.07.06 12:06:29 | 000,040,960 | ---- | C] () -- C:\Users\xxx\AppData\Roaming\TweetAdder
[2011.07.05 08:42:31 | 000,210,944 | ---- | C] () -- C:\Windows\System32\MSVCRT10.DLL
[2011.06.27 22:21:31 | 000,002,892 | ---- | C] () -- C:\Windows\System32\audcon.sys
[2011.06.27 22:19:29 | 000,000,045 | ---- | C] () -- C:\Windows\System32\SYNSOPOS.exe.cfg
[2011.06.27 22:19:27 | 000,086,016 | ---- | C] () -- C:\Windows\System32\SYNSOPOS.exe
[2011.06.27 19:05:28 | 000,058,141 | ---- | C] () -- C:\Users\xxx\AppData\Roaming\SQLite3.dll
[2011.06.27 18:53:25 | 001,032,266 | ---- | C] () -- C:\Windows\System32\libmmd.dll
[2011.06.27 18:36:27 | 000,163,840 | ---- | C] () -- C:\Windows\System32\ArtFfct.dll
[2011.06.26 20:43:31 | 000,233,472 | ---- | C] () -- C:\Users\xxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.06.20 18:41:22 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011.06.20 18:40:28 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.06.20 17:49:07 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.06.20 17:35:57 | 000,067,584 | ---- | C] () -- C:\Users\xxx\AppData\Roaming\chrtmp
[2011.06.20 17:32:53 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011.06.20 17:32:52 | 000,644,608 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011.06.20 17:32:52 | 000,243,200 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011.06.20 17:32:52 | 000,073,216 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011.06.20 17:27:03 | 000,175,616 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2011.06.20 16:47:42 | 000,111,104 | ---- | C] () -- C:\Windows\System32\Uharc.exe
[2011.06.20 16:47:42 | 000,008,636 | ---- | C] () -- C:\Windows\System32\modifype.exe
[2011.06.20 14:45:46 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.06.20 14:45:46 | 000,000,000 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2010.12.06 14:58:56 | 002,496,715 | ---- | C] () -- C:\Windows\System32\abgx360.exe
[2009.11.17 16:13:12 | 000,208,896 | ---- | C] () -- C:\Windows\System32\LXPrnUtil10.dll
[2009.11.17 16:11:26 | 000,303,104 | ---- | C] () -- C:\Windows\System32\dnt27VC8.dll
[2009.11.17 16:09:36 | 000,143,360 | ---- | C] () -- C:\Windows\System32\dntvmc27VC8.dll
[2009.11.17 16:09:20 | 000,086,016 | ---- | C] () -- C:\Windows\System32\dntvm27VC8.dll
[2009.07.28 21:46:36 | 000,717,336 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.28 21:46:36 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.28 21:46:36 | 000,155,856 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.28 21:46:36 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 05:33:53 | 002,281,928 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 03:05:48 | 000,667,932 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 03:05:48 | 000,125,766 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2007.04.27 09:43:58 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2005.04.04 19:56:28 | 000,229,536 | -H-- | C] () -- C:\Users\xxx\AppData\Roaming\logs.dat
========== LOP Check ==========
[2011.11.08 11:42:51 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\.purple
[2011.07.06 21:09:26 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Ableton
[2011.08.16 02:02:15 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Anvil Studio
[2011.11.05 18:18:29 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Auslogics
[2011.11.05 15:52:44 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\BitComet
[2011.10.13 23:46:52 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Bump Technologies, Inc
[2011.08.11 19:13:22 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Canneverbe Limited
[2011.11.07 17:25:34 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\DeskSoft
[2011.07.16 02:42:20 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\FabFilter
[2011.06.28 18:06:24 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\FlashFXP
[2011.06.20 20:45:15 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Foxit Software
[2011.11.05 03:22:09 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\FreeFLVConverter
[2011.11.07 08:56:03 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\gtk-2.0
[2011.08.12 06:34:09 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\ImgBurn
[2011.08.15 06:30:31 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Intermedia Software
[2011.10.13 04:59:52 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\iZotope
[2011.08.08 09:01:54 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Lexware
[2011.08.02 09:32:34 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\MAGIX
[2011.09.12 00:50:40 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\MotionDSP
[2011.08.16 04:55:09 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Music Recognition
[2011.11.07 17:43:31 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\NetMeter
[2011.11.08 08:05:02 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Notepad++
[2011.07.27 15:46:44 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\SongManager
[2011.08.28 01:58:19 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\TeamViewer
[2011.06.27 18:55:48 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Teragon Audio
[2011.06.20 17:49:07 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Thunderbird
[2011.06.20 16:29:59 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Trillian
[2011.07.26 18:52:46 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\TuneUp Software
[2011.06.27 18:50:16 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Waves Audio
[2011.09.28 22:30:40 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\WindSolutions
[2011.11.05 06:01:46 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Xilisoft
[2011.11.07 09:38:15 | 000,032,630 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*. >
[2011.07.06 08:04:45 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2011.10.13 21:37:56 | 000,000,000 | -H-D | M] -- C:\$WINDOWS.~BT
[2011.11.08 19:47:34 | 000,000,000 | -HSD | M] -- C:\Boot
[2011.11.08 03:01:07 | 000,000,000 | -HSD | M] -- C:\Config.Msi
[2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2011.06.20 15:08:44 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2011.11.07 12:29:29 | 000,000,000 | ---D | M] -- C:\Downloads
[2011.09.12 21:40:38 | 000,000,000 | ---D | M] -- C:\HP Universal Print Driver
[2011.09.14 14:12:01 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2011.09.12 01:08:33 | 000,000,000 | ---D | M] -- C:\NVIDIA
[2009.07.14 03:37:05 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2011.11.07 18:43:03 | 000,000,000 | R--D | M] -- C:\Program Files
[2011.11.07 03:52:54 | 000,000,000 | ---D | M] -- C:\Program Settings
[2011.11.07 18:47:16 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2011.06.20 15:08:44 | 000,000,000 | -HSD | M] -- C:\Programme
[2011.10.13 22:58:43 | 000,000,000 | -HSD | M] -- C:\Recovery
[2011.11.08 11:45:26 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2011.09.12 01:05:03 | 000,000,000 | R--D | M] -- C:\Users
[2011.11.08 10:08:26 | 000,000,000 | ---D | M] -- C:\Windows
< %PROGRAMFILES%\*.exe >
< %LOCALAPPDATA%\*.exe >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.manifest /3 >
< MD5 for: EXPLORER.EXE >
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
< MD5 for: REGEDIT.EXE >
[2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\regedit.exe
[2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\winsxs\x86_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_f4050b883d2c3c08\regedit.exe
< MD5 for: USERINIT.EXE >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
< MD5 for: WININIT.EXE >
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
< MD5 for: WINLOGON.EXE >
[2009.10.28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009.10.28 06:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010.11.20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010.11.20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009.07.14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoRebootWithLoggedOnUsers" = 1
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-11-07 23:04:42
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 170 bytes -> C:\ProgramData\TEMP:8CE646EE
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:24721E3C
< End of report > Bin euch schonmal im vorraus dankbar. Wenn es nicht anders geht mach ich Ihn halt Platt am Ende. Aber es wäre toll wenn ihr eine Lösung hättet.
Marcel |