Bezahlaufforderungs Trojaner Hilfe!!!! Hallo liebes Forum,
habe mir heute anscheinend auch dieses Virus eingefangen der mir durch dieses Fenster mit der Aufforderung zum Bezahlen mein Windows sperrt. Schonmal vielen Dank für die Hilfe.
Hoffe ihr könnt mir sagen was ich tun muss. Danke euch
Hier der OTL.txtOTL Logfile: Code:
OTL logfile created on: 11.03.2012 16:16:00 - Run 1
OTL by OldTimer - Version 3.2.36.3 Folder = C:\Dokumente und Einstellungen\Kerim.Z\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,99 Gb Total Physical Memory | 1,61 Gb Available Physical Memory | 81,05% Memory free
3,33 Gb Paging File | 3,14 Gb Available in Paging File | 94,33% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 82,82 Gb Total Space | 10,68 Gb Free Space | 12,90% Space Free | Partition Type: NTFS
Drive D: | 61,29 Gb Total Space | 60,39 Gb Free Space | 98,53% Space Free | Partition Type: NTFS
Computer Name: *** | User Name: *** | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.03.11 16:05:49 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Kerim.Z\Desktop\OTL.exe
PRC - [2008.04.14 13:00:00 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2009.02.27 15:41:26 | 000,311,296 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\pdfshell.DEU
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (AppMgmt)
SRV - [2012.02.27 00:15:42 | 000,055,144 | ---- | M] (Apple Inc.) [Auto | Stopped] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2011.10.21 15:23:42 | 000,196,176 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Programme\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011.10.13 17:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Microsoft\BingBar\SeaPort.EXE -- (BBUpdate)
SRV - [2011.09.04 22:20:51 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.09.04 22:20:35 | 000,428,200 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Programme\Avira\AntiVir Desktop\AVWEBGRD.EXE -- (AntiVirWebService)
SRV - [2011.09.04 22:20:32 | 000,340,136 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Programme\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService)
SRV - [2011.09.04 22:20:31 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.06.10 13:25:18 | 000,016,152 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Freedom Scientific\JAWS\12.0\JTVNCProxy.exe -- (JTVNCProxy_12.0)
SRV - [2011.01.27 00:34:05 | 000,435,008 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Programme\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2010.11.19 15:31:52 | 001,051,968 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Programme\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010.11.19 15:29:54 | 000,030,016 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2010.05.14 21:14:17 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.04.27 12:43:48 | 000,611,840 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2009.06.09 11:41:00 | 004,261,144 | ---- | M] (Freedom Scientific BLV Group, LLC) [Auto | Stopped] -- C:\Programme\Freedom Scientific\JAWS\10.0\jfw.exe -- (JFWService)
SRV - [2009.06.09 11:28:00 | 000,016,152 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Freedom Scientific\JAWS\10.0\JTVNCProxy.exe -- (JTVNCProxy_10.0)
SRV - [2009.05.19 17:29:58 | 000,107,744 | ---- | M] (SRS Labs, Inc.) [Auto | Stopped] -- C:\Programme\SRS Labs\SRS Premium Sound\SRS_VolSync.exe -- (SRS_VolSync_Service)
SRV - [2008.05.08 00:29:38 | 000,122,880 | ---- | M] (CrypKey (Canada) Ltd.) [Auto | Stopped] -- C:\WINDOWS\System32\Crypserv.exe -- (Crypkey License)
SRV - [2007.05.29 22:07:58 | 000,598,960 | ---- | M] ( ) [Auto | Stopped] -- C:\WINDOWS\System32\lxdecoms.exe -- (lxde_device)
SRV - [2007.05.29 22:06:43 | 000,099,248 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdeserv.exe -- (lxdeCATSCustConnectService)
SRV - [2006.10.26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | Auto | Stopped] -- -- (uacFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (aksusb)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (akshasp)
DRV - [2011.09.04 22:20:59 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.09.04 22:20:59 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.06.10 13:30:26 | 000,014,880 | ---- | M] (Freedom Scientific BLV Group, LLC.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\powerbrl.sys -- (PowerBrl)
DRV - [2010.04.06 09:45:50 | 000,323,328 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8187.sys -- (RTLWUSB)
DRV - [2010.03.19 23:36:33 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010.02.26 13:32:58 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2010.02.26 13:32:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010.02.26 13:32:44 | 000,022,528 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010.02.26 13:32:44 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2010.02.26 13:21:22 | 000,137,344 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2010.02.26 13:21:22 | 000,008,320 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)
DRV - [2010.02.24 13:41:50 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Stopped] -- C:\Programme\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2010.02.11 13:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2009.08.05 22:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2009.07.06 09:48:02 | 000,011,448 | ---- | M] () [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\AsUpIO.sys -- (AsUpIO)
DRV - [2009.05.18 09:27:10 | 000,233,512 | R--- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SRS_PremiumSound_i386.sys -- (SRS_PremiumSound_Service)
DRV - [2009.05.12 16:18:54 | 005,080,064 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009.05.11 11:49:19 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009.05.11 09:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.04.15 12:03:42 | 000,090,112 | ---- | M] (Chingachguk & Denger2k (Elite & SP edition)) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\multikey.sys -- (multikey)
DRV - [2009.03.27 15:43:42 | 001,529,600 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\athw.sys -- (AR5416)
DRV - [2009.03.02 06:03:46 | 000,038,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1c51x86.sys -- (L1c)
DRV - [2008.12.30 09:53:54 | 000,156,816 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2008.12.30 09:53:54 | 000,057,384 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwhid.sys -- (btwhid)
DRV - [2008.12.30 09:53:54 | 000,047,272 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2008.12.30 09:53:54 | 000,037,032 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwmodem.sys -- (btwmodem)
DRV - [2008.12.30 09:53:52 | 000,991,656 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2008.12.30 09:53:52 | 000,037,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2008.12.30 09:53:50 | 000,534,568 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2008.11.19 02:21:28 | 000,039,040 | ---- | M] (GenesysLogic Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\uvclf.sys -- (uvclf)
DRV - [2008.08.26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.08.05 19:10:12 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2008.04.08 14:59:28 | 000,010,752 | ---- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASUSACPI.SYS -- (AsusACPI)
DRV - [2008.03.17 17:45:52 | 000,019,584 | ---- | M] () [Kernel | System | Stopped] -- C:\WINDOWS\system32\ckldrv.sys -- (NetworkX)
DRV - [2008.02.25 10:59:02 | 000,101,120 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2007.02.07 16:57:20 | 000,035,840 | ---- | M] (CACE Technologies) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\npf_devolo.sys -- (NPF_devolo) NetGroup Packet Filter Driver (devolo)
DRV - [2006.01.04 14:41:48 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2005.06.09 12:34:12 | 000,015,648 | ---- | M] () [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\Drivers\sentkey.sys -- (Sentinel)
DRV - [1999.09.10 13:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\drivers\aspi32.sys -- (Aspi32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland: Hotmail, Skype Download und Messenger sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 52 17 58 6E AA E4 CB 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {C0531841-7290-41DD-8A37-C47A12B4BBB3}
IE - HKCU\..\SearchScopes\{908EC305-75A9-407D-AA35-AB014527CA29}: "URL" = hxxp://www.bing.com/search?FORM=ASUBDF&PC=MAAU&q={searchTerms}&src=IE-SearchBox
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2354287
IE - HKCU\..\SearchScopes\{C0531841-7290-41DD-8A37-C47A12B4BBB3}: "URL" = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7RNTN_de
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Web Search..."
FF - prefs.js..browser.search.defaultthis.engineName: "BrotherSoft Extreme Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2776682&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.2
FF - prefs.js..extensions.enabledItems: plugin@yontoo.com:1.20.00
FF - prefs.js..keyword.URL: "hxxp://vshare.toolbarhome.com/search.aspx?srch=ku&q="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Programme\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.688: C:\Programme\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.688: C:\Programme\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.688: C:\Programme\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.57\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.57\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Programme\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
[2010.08.25 20:09:53 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Mozilla\Extensions
[2011.08.21 18:23:48 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Mozilla\Firefox\Profiles\oeom7n5s.default\extensions
[2010.08.25 20:42:16 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Mozilla\Firefox\Profiles\oeom7n5s.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.06.23 17:28:22 | 000,000,000 | ---D | M] (Yontoo Layers) -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Mozilla\Firefox\Profiles\oeom7n5s.default\extensions\plugin@yontoo.com
[2011.04.29 19:49:08 | 000,000,000 | ---D | M] (vShare) -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Mozilla\Firefox\Profiles\oeom7n5s.default\extensions\vshare@toolbar
[2010.12.22 16:23:04 | 000,000,941 | ---- | M] () -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Mozilla\Firefox\Profiles\oeom7n5s.default\searchplugins\conduit.xml
[2010.09.19 14:42:36 | 000,002,689 | ---- | M] () -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Mozilla\Firefox\Profiles\oeom7n5s.default\searchplugins\search-defender.xml
[2011.05.01 20:08:39 | 000,001,583 | ---- | M] () -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Mozilla\Firefox\Profiles\oeom7n5s.default\searchplugins\web-search.xml
[2010.08.07 00:32:23 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAMME\JAVA\JRE6\LIB\DEPLOY\JQS\FF
O1 HOSTS File: ([2008.04.14 13:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Programme\vShare\vshare_toolbar.dll ()
O2 - BHO: (Lexmark Symbolleiste) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Programme\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {1C749E08-6B62-11E0-B6DA-075F4824019B} - No CLSID value found.
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No CLSID value found.
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Programme\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Programme\Yontoo Layers\YontooIEClient.dll (Yontoo Technology, Inc.)
O3 - HKLM\..\Toolbar: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Programme\vShare\vshare_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Lexmark Symbolleiste) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Programme\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Programme\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Programme\vShare\vshare_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Lexmark Symbolleiste) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Programme\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [FaxCenterServer] C:\Programme\Lexmark Fax Solutions\fm3032.exe ()
O4 - HKLM..\Run: [lxdeamon] C:\Programme\Lexmark 4800 Series\lxdeamon.exe ()
O4 - HKLM..\Run: [lxdemon.exe] C:\Programme\Lexmark 4800 Series\lxdemon.exe ()
O4 - HKCU..\Run: [PC Suite Tray] C:\Programme\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKCU..\Run: [SkypeM] C:\Dokumente und Einstellungen\Kerim.Z\Lokale Einstellungen\Anwendungsdaten\Skype\Skype.exe (Iron Mountain Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\Kerim.Z\Startmenü\Programme\Autostart\Dropbox.lnk = C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutorun = 145
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = [binary data]
O8 - Extra context menu item: An vorhandenes PDF anfügen - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Programme\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html File not found
O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Senden an &Bluetooth-Gerät... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Senden an Bluetooth - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx (WRC Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C7B405F6-871F-4504-A528-B4A3BFDCED63}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Programme\vShare\vshare_toolbar.dll ()
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (C:\WINDOWS\SYSTEM32\RtlGina\RtlGina.DLL) - C:\WINDOWS\system32\RtlGina\RtlGina.dll (Realtek)
O20 - Winlogon\Notify\igdlogin: DllName - (igdlogin.dll) - C:\WINDOWS\System32\igdlogin.dll ()
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O28 - HKLM ShellExecuteHooks: {6979AAD7-86EE-481F-B591-152A33E86ECB} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.04 11:10:12 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{34567b7f-06a9-11e0-b68f-0025d3a3ccbc}\Shell - "" = AutoRun
O33 - MountPoints2\{34567b7f-06a9-11e0-b68f-0025d3a3ccbc}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{34567b7f-06a9-11e0-b68f-0025d3a3ccbc}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{9aaaa31a-20a1-11e0-b6cf-0025d3a3ccbc}\Shell - "" = AutoRun
O33 - MountPoints2\{9aaaa31a-20a1-11e0-b6cf-0025d3a3ccbc}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9aaaa31a-20a1-11e0-b6cf-0025d3a3ccbc}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O33 - MountPoints2\{af22d3ac-188c-11df-b425-0025d3a3ccbc}\Shell - "" = AutoRun
O33 - MountPoints2\{af22d3ac-188c-11df-b425-0025d3a3ccbc}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{af22d3ac-188c-11df-b425-0025d3a3ccbc}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{b43735a8-2f74-11e0-b6ff-0025d3a3ccbc}\Shell - "" = AutoRun
O33 - MountPoints2\{b43735a8-2f74-11e0-b6ff-0025d3a3ccbc}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b43735a8-2f74-11e0-b6ff-0025d3a3ccbc}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{b43735a9-2f74-11e0-b6ff-0025d3a3ccbc}\Shell - "" = AutoRun
O33 - MountPoints2\{b43735a9-2f74-11e0-b6ff-0025d3a3ccbc}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b43735a9-2f74-11e0-b6ff-0025d3a3ccbc}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{b43735ac-2f74-11e0-b6ff-0025d3a3ccbc}\Shell - "" = AutoRun
O33 - MountPoints2\{b43735ac-2f74-11e0-b6ff-0025d3a3ccbc}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b43735ac-2f74-11e0-b6ff-0025d3a3ccbc}\Shell\AutoRun\command - "" = K:\AutoRun.exe
O33 - MountPoints2\{b43735ad-2f74-11e0-b6ff-0025d3a3ccbc}\Shell - "" = AutoRun
O33 - MountPoints2\{b43735ad-2f74-11e0-b6ff-0025d3a3ccbc}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b43735ad-2f74-11e0-b6ff-0025d3a3ccbc}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{b43735ae-2f74-11e0-b6ff-0025d3a3ccbc}\Shell - "" = AutoRun
O33 - MountPoints2\{b43735ae-2f74-11e0-b6ff-0025d3a3ccbc}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b43735ae-2f74-11e0-b6ff-0025d3a3ccbc}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{b43735af-2f74-11e0-b6ff-0025d3a3ccbc}\Shell - "" = AutoRun
O33 - MountPoints2\{b43735af-2f74-11e0-b6ff-0025d3a3ccbc}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b43735af-2f74-11e0-b6ff-0025d3a3ccbc}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{c8835a74-00f9-11df-b3ed-be21e63e3a02}\Shell - "" = AutoRun
O33 - MountPoints2\{c8835a74-00f9-11df-b3ed-be21e63e3a02}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c8835a74-00f9-11df-b3ed-be21e63e3a02}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012.03.11 16:05:48 | 000,594,944 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Kerim.Z\Desktop\OTL.exe
[2012.03.10 18:59:28 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\iTunes
[2012.03.10 18:58:01 | 000,000,000 | ---D | C] -- C:\Programme\iPod
[2012.03.10 18:57:54 | 000,000,000 | ---D | C] -- C:\Programme\iTunes
[2012.03.10 18:52:02 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\NetworkService\Anwendungsdaten\Apple Computer
[2012.02.23 17:39:53 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Adobe
[2012.02.22 20:30:47 | 000,000,000 | ---D | C] -- C:\Lexmark ToolBar
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\Dokumente und Einstellungen\All Users\*.tmp files -> C:\Dokumente und Einstellungen\All Users\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.03.11 16:05:49 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Kerim.Z\Desktop\OTL.exe
[2012.03.11 15:54:19 | 000,455,386 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2012.03.11 15:54:19 | 000,438,040 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.03.11 15:54:19 | 000,083,336 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2012.03.11 15:54:19 | 000,070,360 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012.03.11 15:50:00 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.03.11 15:30:27 | 002,000,000 | ---- | M] () -- C:\WINDOWS\System32\HJSMEM.DAT
[2012.03.11 12:59:47 | 000,000,400 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{55F42137-AA7D-4D7F-8C9A-333CA313AA48}.job
[2012.03.10 18:59:28 | 000,001,528 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\iTunes.lnk
[2012.03.10 18:47:02 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012.03.10 14:57:27 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.03.09 10:42:57 | 000,009,069 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\lxde
[2012.02.26 12:42:48 | 000,001,044 | ---- | M] () -- C:\Dokumente und Einstellungen\Kerim.Z\Startmenü\Programme\Autostart\Dropbox.lnk
[2012.02.26 12:42:47 | 000,001,044 | ---- | M] () -- C:\Dokumente und Einstellungen\Kerim.Z\Desktop\Dropbox.lnk
[2012.02.23 23:56:04 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012.02.21 15:43:40 | 001,453,470 | ---- | M] () -- C:\Dokumente und Einstellungen\Kerim.Z\Eigene Dateien\teilnahme2 Marfamtag2.PDF
[2012.02.21 15:38:42 | 001,094,857 | ---- | M] () -- C:\Dokumente und Einstellungen\Kerim.Z\Eigene Dateien\Teilnahme1 Marfantag 2012.PDF
[2012.02.21 14:27:37 | 000,602,174 | ---- | M] () -- C:\Dokumente und Einstellungen\Kerim.Z\Eigene Dateien\Personalausweiß Rückseite.PDF
[2012.02.21 13:35:59 | 000,587,958 | ---- | M] () -- C:\Dokumente und Einstellungen\Kerim.Z\Eigene Dateien\Personalausweiß Forderseite.PDF
[2012.02.17 14:45:04 | 000,234,368 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.02.17 01:04:17 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012.02.13 20:21:36 | 000,000,723 | ---- | M] () -- C:\Dokumente und Einstellungen\Kerim.Z\Desktop\Internet Explorer.lnk
[2012.02.13 20:12:40 | 000,001,590 | ---- | M] () -- C:\Dokumente und Einstellungen\Kerim.Z\Desktop\QuickTime Player.lnk
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\Dokumente und Einstellungen\All Users\*.tmp files -> C:\Dokumente und Einstellungen\All Users\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.03.10 18:59:28 | 000,001,528 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\iTunes.lnk
[2012.02.21 15:44:07 | 001,453,470 | ---- | C] () -- C:\Dokumente und Einstellungen\Kerim.Z\Eigene Dateien\teilnahme2 Marfamtag2.PDF
[2012.02.21 15:39:30 | 001,094,857 | ---- | C] () -- C:\Dokumente und Einstellungen\Kerim.Z\Eigene Dateien\Teilnahme1 Marfantag 2012.PDF
[2012.02.21 14:28:12 | 000,602,174 | ---- | C] () -- C:\Dokumente und Einstellungen\Kerim.Z\Eigene Dateien\Personalausweiß Rückseite.PDF
[2012.02.21 13:36:37 | 000,587,958 | ---- | C] () -- C:\Dokumente und Einstellungen\Kerim.Z\Eigene Dateien\Personalausweiß Forderseite.PDF
[2012.02.16 13:13:28 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.02.16 13:13:28 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2012.02.13 20:16:37 | 000,000,723 | ---- | C] () -- C:\Dokumente und Einstellungen\Kerim.Z\Desktop\Internet Explorer.lnk
[2012.02.13 20:12:40 | 000,001,590 | ---- | C] () -- C:\Dokumente und Einstellungen\Kerim.Z\Desktop\QuickTime Player.lnk
[2011.12.23 18:11:59 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.10.27 20:21:59 | 000,000,060 | ---- | C] () -- C:\WINDOWS\System32\lxderwrd.ini
[2011.10.27 20:21:55 | 000,434,176 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdehcp.dll
[2011.10.27 20:21:55 | 000,348,160 | ---- | C] () -- C:\WINDOWS\System32\lxdeinst.dll
[2011.10.27 20:15:03 | 000,348,160 | R--- | C] () -- C:\WINDOWS\System32\lxdecoin.dll
[2011.10.22 21:59:34 | 000,047,864 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011.09.28 18:40:01 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\LXF3PMON.DLL
[2011.09.28 18:40:01 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\lxf3oem.dll
[2011.09.28 18:40:01 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\LXF3FXPU.DLL
[2011.07.19 13:26:02 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.EXE
[2011.07.19 13:26:02 | 000,006,836 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.INI
[2011.07.17 12:46:24 | 000,376,832 | ---- | C] () -- C:\WINDOWS\System32\AegisI5Installer.exe
[2011.07.17 12:45:56 | 000,451,072 | ---- | C] () -- C:\WINDOWS\System32\ISSRemoveSP.exe
[2011.06.23 10:50:27 | 000,000,004 | ---- | C] () -- C:\WINDOWS\vx86036.dat
[2011.06.23 10:44:46 | 000,000,067 | ---- | C] () -- C:\WINDOWS\Crypkey.ini
[2011.06.23 10:44:43 | 000,027,648 | R--- | C] () -- C:\WINDOWS\Setup_ck.exe
[2011.06.23 10:44:43 | 000,019,584 | ---- | C] () -- C:\WINDOWS\System32\Ckldrv.sys
[2011.06.23 10:44:43 | 000,018,432 | ---- | C] () -- C:\WINDOWS\Setup_ck.dll
[2011.06.23 10:44:43 | 000,011,776 | ---- | C] () -- C:\WINDOWS\Ckrfresh.exe
[2010.10.11 21:53:10 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\$_hpcst$.hpc
[2010.08.25 20:09:35 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010.08.06 16:04:16 | 000,264,192 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2010.07.25 12:09:51 | 000,011,448 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsUpIO.sys
[2010.07.11 19:10:19 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.04.27 22:41:55 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010.03.19 23:25:23 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI
========== LOP Check ==========
[2011.03.12 22:17:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AIM
[2011.08.13 13:43:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Baum Retec
[2011.01.21 01:16:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\boost_interprocess
[2010.03.19 23:35:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DAEMON Tools Lite
[2011.07.15 14:17:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Freedom Scientific
[2010.06.09 17:04:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Installations
[2011.12.04 01:20:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\iRinger
[2010.06.09 17:14:40 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Nokia
[2010.06.07 16:17:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Suite
[2011.06.23 17:28:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tarma Installer
[2010.09.25 22:53:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
[2010.09.22 19:39:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software
[2011.03.17 14:23:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Viewpoint
[2010.12.06 12:08:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\XSign
[2011.11.30 13:49:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010.09.22 19:38:06 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2011.03.17 18:34:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\acccore
[2009.06.04 19:08:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\ASUS
[2011.08.13 13:03:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\BAUM Retec
[2010.03.19 23:43:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\DAEMON Tools Lite
[2012.03.11 15:32:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Dropbox
[2010.09.02 15:49:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\EeeStorageUploader
[2010.01.13 03:27:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Freedom Scientific
[2012.02.07 16:16:43 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\GetRightToGo
[2010.09.14 13:26:25 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\GHISLER
[2010.08.10 18:14:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\gtk-2.0
[2011.10.15 15:59:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\JAWS Scripts For Skype
[2011.12.09 11:47:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Lexmark Productivity Studio
[2010.12.26 22:38:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Miranda
[2010.06.07 16:06:43 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Nokia
[2011.07.09 12:57:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\PC Suite
[2011.07.15 12:35:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Publish Providers
[2011.07.15 12:35:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\Sony
[2010.08.07 14:41:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\TeamViewer
[2010.09.22 19:39:40 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\TuneUp Software
[2011.04.29 19:49:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Kerim.Z\Anwendungsdaten\vShare
[2012.03.11 12:59:47 | 000,000,400 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{55F42137-AA7D-4D7F-8C9A-333CA313AA48}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 161 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:DFC5A2B2
@Alternate Data Stream - 104 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:D1B5B4F1
@Alternate Data Stream - 102 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:430C6D84
< End of report > --- --- --- |