rockie82 | 21.07.2013 11:44 | GVU Trojaner - Abgesicherter Modus geht nicht Hallo zusammen,
ich habe mir auf meinem Rechner den GVU Trojaner eingefangen. Ich habe Windows 7
Abgesicherter Modus mit Eingabeaufforderung funktioniert nicht. Ich gelange jedes Mal wieder zum GVU-Screen. Windows normal starten bringt auch sofort den GVU-Screen. Ich habe schon von der CD mit OTLPE gebootet, gescannt (Ich hoffe, dass ich auch das richtige gescannt habe) und folgendes kommt raus: Code:
OTL logfile created on: 7/21/2013 1:32:35 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
64bit-Windows 7 Home Premium Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 88.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\Windows | %ProgramFiles% = D:\Program Files (x86)
Drive C: | 100.00 Mb Total Space | 74.37 Mb Free Space | 74.37% Space Free | Partition Type: NTFS
Drive D: | 453.94 Gb Total Space | 254.96 Gb Free Space | 56.17% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet004
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011/10/02 16:18:06 | 000,010,712 | ---- | M] (SafeNet, Inc.) [Auto] -- D:\Program Files\SafeNet\Authentication\SAC\x64\SACSrv.exe -- (SACSrv)
SRV:64bit: - [2010/10/25 05:10:22 | 000,119,632 | ---- | M] (Devguru Co., Ltd.) [Auto] -- D:\Windows\System32\dgdersvc.exe -- (dgdersvc)
SRV:64bit: - [2010/05/03 00:29:18 | 001,436,424 | ---- | M] (Acresso Software Inc.) [On_Demand] -- D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2010/01/23 02:12:18 | 000,673,792 | ---- | M] () [Auto] -- D:\Program Files\Autodesk\Inventor 2011\Moldflow\bin\mitsijm.exe -- (mitsijm2011)
SRV:64bit: - [2009/10/02 13:39:44 | 000,873,248 | ---- | M] (Broadcom Corporation.) [Auto] -- D:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2009/09/30 09:44:58 | 000,844,320 | ---- | M] (Acer Incorporated) [Auto] -- D:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe -- (ePowerSvc)
SRV:64bit: - [2009/07/03 21:47:12 | 000,240,160 | ---- | M] (Acer) [Auto] -- D:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe -- (Updater Service)
SRV - [2013/06/18 10:21:21 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand] -- D:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/06/13 05:17:51 | 004,150,112 | ---- | M] (TeamViewer GmbH) [Auto] -- D:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2013/06/12 01:25:30 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- D:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/13 18:54:12 | 004,937,264 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- D:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2013/04/17 22:34:38 | 000,283,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- D:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe -- (avgwd)
SRV - [2013/04/10 05:07:36 | 001,428,472 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- D:\Program Files (x86)\AVG\AVG2013\avgfws.exe -- (avgfws)
SRV - [2013/02/04 11:43:22 | 000,155,824 | ---- | M] (Avanquest Software) [On_Demand] -- D:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion)
SRV - [2012/09/12 06:08:23 | 000,234,784 | ---- | M] (Apple Inc.) [Auto] -- D:\AirPrint\airprint.exe -- (AirPrint)
SRV - [2011/09/05 22:02:20 | 000,140,456 | ---- | M] () [Auto] -- D:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2011/06/06 06:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- D:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/11/12 11:12:02 | 000,118,152 | ---- | M] (SecureW2 B.V.) [Auto] -- D:\Program Files (x86)\SecureW2\sw2_service.exe -- (SW2SVC)
SRV - [2010/10/25 05:07:48 | 000,095,568 | ---- | M] (Devguru Co., Ltd.) [Auto] -- D:\Windows\SysWOW64\dgdersvc.exe -- (dgdersvc)
SRV - [2010/03/18 08:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- D:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/01/27 16:31:37 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand] -- D:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/08/28 05:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto] -- D:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe -- (Greg_Service)
SRV - [2009/08/25 13:38:06 | 000,935,208 | ---- | M] (Nero AG) [Auto] -- D:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2009/08/20 21:25:50 | 000,062,720 | ---- | M] (NewTech Infosystems, Inc.) [Auto] -- D:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2009/07/24 13:38:50 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto] -- D:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- D:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/12/08 10:16:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [Auto] -- D:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor7.0)
SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto] -- D:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/04/07 03:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand] -- D:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013/05/20 05:24:27 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System] -- D:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2013/03/28 20:53:48 | 000,246,072 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] -- D:\Windows\System32\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2013/03/20 21:08:24 | 000,240,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] -- D:\Windows\System32\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2013/02/07 22:37:56 | 000,116,536 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot] -- D:\Windows\System32\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2013/02/07 22:37:54 | 000,311,096 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot] -- D:\Windows\System32\drivers\avgloga.sys -- (Avgloga)
DRV:64bit: - [2013/02/07 22:37:50 | 000,071,480 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot] -- D:\Windows\System32\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2013/02/07 22:37:42 | 000,206,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] -- D:\Windows\System32\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2013/02/07 22:37:40 | 000,045,880 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot] -- D:\Windows\System32\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2012/09/04 04:39:32 | 000,050,296 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] -- D:\Windows\System32\drivers\avgfwd6a.sys -- (Avgfwfd)
DRV:64bit: - [2012/07/09 07:42:54 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011/05/10 02:06:14 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\netaapl64.sys -- (Netaapl)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/10/25 05:10:22 | 000,020,552 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand] -- D:\Windows\System32\drivers\dgderdrv.sys -- (dgderdrv)
DRV:64bit: - [2010/07/08 09:52:44 | 000,022,304 | ---- | M] (SafeNet, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\IKEYIFD.SYS -- (iKeyIFD)
DRV:64bit: - [2010/07/08 09:52:44 | 000,016,160 | ---- | M] (SafeNet, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\IKEYENUM.SYS -- (iKeyEnum)
DRV:64bit: - [2010/06/09 19:01:10 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot] -- D:\Windows\System32\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/09/21 15:00:44 | 001,537,024 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009/09/21 03:33:06 | 000,016,392 | ---- | M] (Teruten Inc) [File_System | On_Demand] -- D:\Windows\System32\drivers\TFsExDisk.sys -- (TFsExDisk)
DRV:64bit: - [2009/08/21 17:24:04 | 000,084,512 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2009/08/11 16:59:50 | 000,686,080 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2009/07/02 07:46:58 | 000,052,264 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\btusbflt.sys -- (btusbflt)
DRV:64bit: - [2009/06/20 08:35:00 | 000,317,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink (TM)
DRV:64bit: - [2009/06/19 22:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\L1E62x64.sys -- (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20)
DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- D:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 16:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/06/10 16:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\netw5v64.sys -- (netw5v64) Intel(R)
DRV:64bit: - [2009/06/10 16:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\system32\DRIVERS\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\system32\DRIVERS\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/04 20:46:50 | 000,216,064 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2009/05/25 08:34:54 | 000,151,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\s1029unic.sys -- (s1029unic) Sony Ericsson Device 1029 USB Ethernet Emulation (WDM)
DRV:64bit: - [2009/05/25 08:34:54 | 000,139,304 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\s1029mgmt.sys -- (s1029mgmt) Sony Ericsson Device 1029 USB WMC Device Management Drivers (WDM)
DRV:64bit: - [2009/05/25 08:34:54 | 000,135,208 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\s1029obex.sys -- (s1029obex)
DRV:64bit: - [2009/05/25 08:34:52 | 000,158,760 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\s1029mdm.sys -- (s1029mdm)
DRV:64bit: - [2009/05/25 08:34:52 | 000,034,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\s1029nd5.sys -- (s1029nd5) Sony Ericsson Device 1029 USB Ethernet Emulation (NDIS)
DRV:64bit: - [2009/05/25 08:34:50 | 000,019,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\s1029mdfl.sys -- (s1029mdfl)
DRV:64bit: - [2009/05/25 08:34:48 | 000,116,264 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\s1029bus.sys -- (s1029bus) Sony Ericsson Device 1029 driver (WDM)
DRV:64bit: - [2009/05/24 23:57:42 | 000,243,760 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2009/03/25 11:48:00 | 000,153,128 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\s1018mdm.sys -- (s1018mdm)
DRV:64bit: - [2009/03/25 11:48:00 | 000,146,472 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\s1018unic.sys -- (s1018unic) Sony Ericsson Device 1018 USB Ethernet Emulation (WDM)
DRV:64bit: - [2009/03/25 11:48:00 | 000,133,160 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\s1018mgmt.sys -- (s1018mgmt) Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM)
DRV:64bit: - [2009/03/25 11:48:00 | 000,128,552 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\s1018obex.sys -- (s1018obex)
DRV:64bit: - [2009/03/25 11:48:00 | 000,113,704 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\s1018bus.sys -- (s1018bus) Sony Ericsson Device 1018 driver (WDM)
DRV:64bit: - [2009/03/25 11:48:00 | 000,034,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\s1018nd5.sys -- (s1018nd5) Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS)
DRV:64bit: - [2009/03/25 11:48:00 | 000,019,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\s1018mdfl.sys -- (s1018mdfl)
DRV:64bit: - [2008/07/30 05:45:40 | 000,062,632 | ---- | M] (Aladdin Knowledge Systems, Ltd.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\aksifdh.sys -- (AKSIFDH)
DRV:64bit: - [2008/07/30 05:45:40 | 000,044,712 | ---- | M] (Aladdin Knowledge Systems, Ltd.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\aksup.sys -- (AKSUP)
DRV - [2010/10/25 05:07:48 | 000,018,120 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand] -- D:\Windows\SysWOW64\drivers\dgderdrv.sys -- (dgderdrv)
DRV - [2009/09/29 15:00:52 | 000,146,928 | ---- | M] (CyberLink Corp.) [2010/01/27 21:13:49] [Kernel | Auto] -- D:\Program Files (x86)\CyberLink\PowerDVD8\000.fcl -- ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054})
DRV - [2009/09/21 03:33:06 | 000,016,392 | ---- | M] (Teruten Inc) [File_System | On_Demand] -- D:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Jan_ON_D\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&m=easynote_tj65&r=27360410j7c6l0450z195f4401u262
IE - HKU\Jan_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\Jan_ON_D\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - Reg Error: Key error. File not found
IE - HKU\Jan_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Jan_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\NetworkService_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: D:\Windows\System32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: D:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: D:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=:
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@canon.com/EPPEX: D:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: D:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: D:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin: D:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: D:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: D:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.2: D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: D:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011/03/10 11:00:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011/03/10 11:00:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\crossriderapp1950@crossrider.com: C:\Users\Jan\AppData\Local\RewardsArcadeSuite\1950\Firefox [2012/01/17 13:40:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}: C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ [2013/06/05 06:03:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/06/12 05:09:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/06/12 05:09:50 | 000,000,000 | ---D | M]
[2013/06/28 09:12:22 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Jan\AppData\Roaming\Mozilla\Extensions
[2013/06/12 05:09:57 | 000,000,000 | ---D | M] (No name found) -- D:\Program Files (x86)\Mozilla Firefox\extensions
[2013/06/12 05:09:57 | 000,000,000 | ---D | M] (No name found) -- D:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/06/28 09:10:10 | 000,000,000 | ---D | M] (Default) -- D:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) --
[2011/02/02 16:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- D:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/05/09 12:57:27 | 000,075,208 | ---- | M] (Foxit Software Company) -- D:\Program Files (x86)\mozilla firefox\plugins\npFoxitReaderPlugin.dll
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - D:\Windows\System32\drivers\etc\hosts
O2:64bit: - BHO: (DVDVideoSoft WebPageAdjuster Class) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - D:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - D:\Program Files (x86)\PriceGong\2.5.3\PriceGongIE.dll (PriceGong)
O2 - BHO: (DivX) - {1E37A1FF-843E-4627-A8C4-00279C4ACDC2} - D:\Users\Jan\AppData\Roaming\DivX\IE\DivX.dll (DivX, LLC. Rovi Corporation)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - D:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - D:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - D:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - D:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (NoScript) - {601369AE-97AF-4402-807D-7516155B484B} - D:\Users\Jan\AppData\Roaming\NoScript\IE\NoScript.dll (Giorgio Maone)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - D:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.)
O2 - BHO: (RewardsArcadeSuite) - {B6EF6C45-5E8D-4c3b-B580-A5073261A381} - D:\Program Files (x86)\RewardsArcadeSuite\RewardsArcadeSuite.dll (215 Apps)
O2 - BHO: (DVDVideoSoft WebPageAdjuster Class) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - D:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - D:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - D:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - D:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\Jan_ON_D\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\Jan_ON_D\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - D:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] D:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [NvCplDaemon] D:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [SACMonitor] D:\Program Files\SafeNet\Authentication\SAC\x64\SACMonitor.exe (SafeNet, Inc.)
O4 - HKLM..\Run: [APSDaemon] D:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] D:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CanonSolutionMenuEx] D:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [IJNetworkScannerSelectorEX] D:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (CANON INC.)
O4 - HKU\Jan_ON_D..\Run: [Akamai NetSession Interface] File not found
O4 - HKU\Jan_ON_D..\Run: [ctfmon.exe] File not found
O4 - HKU\Jan_ON_D..\Run: [DAEMON Tools Lite] D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
O4 - HKU\Jan_ON_D..\Run: [MobileDocuments] D:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKU\Jan_ON_D..\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] D:\Users\Jan\AppData\Local\Temp\auaujurpcjhffktlw.exe (NVIDIA Corporation)
O4 - HKU\LocalService_ON_D..\Run: [Sidebar] D:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_D..\Run: [Sidebar] D:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [SPReview] File not found
O4 - HKU\Jan_ON_D..\RunOnce: [FlashPlayerUpdate] D:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_7_700_224_Plugin.exe (Adobe Systems Incorporated)
O4 - HKU\LocalService_ON_D..\RunOnce: [mctadmin] File not found
O4 - HKU\NetworkService_ON_D..\RunOnce: [mctadmin] File not found
O4 - Startup: D:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Jan.lnk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Bild an &Bluetooth-Gerät senden... - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Free YouTube Download - D:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - D:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm ()
O8:64bit: - Extra context menu item: Seite an &Bluetooth-Gerät senden... - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Free YouTube Download - D:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - D:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm ()
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - D:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
O9:64bit: - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - D:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
O9 - Extra Button: Senden an Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Senden an &Bluetooth-Gerät... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - D:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O9 - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - D:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - D:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - D:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13:64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 193.189.244.202 193.189.244.194
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - D:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - D:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - D:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKU\Jan_ON_D Winlogon: Shell - (cmd.exe) - D:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\ScCertProp: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/02 23:22:27 | 000,000,000 | ---D | M] - D:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{00ab45e4-4505-11e0-be55-00262d85403a}\Shell - "" = AutoRun
O33 - MountPoints2\{00ab45e4-4505-11e0-be55-00262d85403a}\Shell\AutoRun\command - "" = E:\autorun.exe
O33 - MountPoints2\{888a26a2-b07b-11e0-bffe-00262d85403a}\Shell - "" = AutoRun
O33 - MountPoints2\{888a26a2-b07b-11e0-bffe-00262d85403a}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{94bbc122-6d7c-11e1-92ce-00262d85403a}\Shell - "" = AutoRun
O33 - MountPoints2\{94bbc122-6d7c-11e1-92ce-00262d85403a}\Shell\AutoRun\command - "" = G:\Startme.exe
O33 - MountPoints2\{d7d2fca4-be91-11e2-bf85-00262d85403a}\Shell - "" = AutoRun
O33 - MountPoints2\{d7d2fca4-be91-11e2-bf85-00262d85403a}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2013/07/09 02:40:40 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/07/07 23:57:58 | 000,000,000 | -HSD | C] -- D:\Config.Msi
[2013/07/05 15:43:01 | 000,000,000 | ---D | C] -- D:\Users\Jan\AppData\Roaming\AVG2013
[2013/07/05 15:41:28 | 000,000,000 | ---D | C] -- D:\Users\Jan\AppData\Roaming\TuneUp Software
[2013/07/05 15:40:17 | 000,000,000 | -H-D | C] -- D:\$AVG
[2013/07/05 15:40:17 | 000,000,000 | ---D | C] -- D:\ProgramData\AVG2013
[2013/07/05 15:39:17 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\AVG
[2013/07/05 15:27:31 | 000,000,000 | -H-D | C] -- D:\ProgramData\Common Files
[2013/07/05 15:27:31 | 000,000,000 | ---D | C] -- D:\Users\Jan\AppData\Local\MFAData
[2013/07/05 15:27:31 | 000,000,000 | ---D | C] -- D:\ProgramData\MFAData
[2013/07/05 15:27:31 | 000,000,000 | ---D | C] -- D:\Users\Jan\AppData\Local\Avg2013
[2013/07/03 04:34:40 | 000,000,000 | ---D | C] -- D:\Users\Jan\Desktop\4leecher2you
[2013/06/28 09:35:49 | 000,062,632 | ---- | C] (Aladdin Knowledge Systems, Ltd.) -- D:\Windows\System32\drivers\aksifdh.sys
[2013/06/28 09:35:49 | 000,044,712 | ---- | C] (Aladdin Knowledge Systems, Ltd.) -- D:\Windows\System32\drivers\aksup.sys
[2013/06/28 09:34:57 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\SafeNet
[2013/06/28 09:34:49 | 000,000,000 | ---D | C] -- D:\Program Files\SafeNet
[2013/06/28 09:10:11 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Mozilla Maintenance Service
[2013/06/26 09:33:10 | 000,000,000 | ---D | C] -- D:\Users\Jan\AppData\Roaming\TeamViewer
[2013/06/26 06:56:06 | 000,000,000 | ---D | C] -- D:\Users\Jan\Desktop\Statistik
[2013/06/26 02:26:42 | 000,000,000 | ---D | C] -- D:\Users\Jan\Desktop\WIW01UEDW
[2013/06/25 00:00:06 | 000,000,000 | ---D | C] -- D:\Users\Jan\Desktop\Stieg Larssin - Vergebung (Millennium-Trilogie 3) (ungekuerzt)
[1 D:\Windows\SysWow64\*.tmp files -> D:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/07/11 00:19:53 | 000,067,584 | --S- | M] () -- D:\Windows\bootstat.dat
[2013/07/11 00:16:39 | 3217,235,968 | -HS- | M] () -- D:\hiberfil.sys
[2013/07/11 00:13:03 | 000,012,288 | ---- | M] () -- D:\Windows\System32\umstartup.etl
[2013/07/10 10:25:05 | 000,000,884 | ---- | M] () -- D:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/10 10:16:55 | 091,516,302 | ---- | M] () -- D:\Users\Jan\Desktop\Madison Ivy - Showers Make Me Horny.part3.rar
[2013/07/10 10:16:07 | 001,084,732 | ---- | M] () -- D:\ProgramData\2433f433
[2013/07/10 10:16:07 | 001,084,668 | ---- | M] () -- D:\Users\Jan\AppData\Local\2433f433
[2013/07/10 10:16:07 | 001,084,655 | ---- | M] () -- D:\Users\Jan\AppData\Roaming\2433f433
[2013/07/10 02:16:02 | 800,000,000 | ---- | M] () -- D:\Users\Jan\Desktop\Madison Ivy - Showers Make Me Horny.part2.rar
[2013/07/10 00:14:33 | 001,715,366 | ---- | M] () -- D:\Users\Jan\Desktop\KV.pdf
[2013/07/10 00:13:46 | 000,076,406 | ---- | M] () -- D:\Users\Jan\Desktop\GVV.pdf
[2013/07/09 02:40:40 | 000,000,993 | ---- | M] () -- D:\Users\Public\Desktop\AVG 2013.lnk
[2013/07/09 02:40:40 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/07/09 02:15:18 | 800,000,000 | ---- | M] () -- D:\Users\Jan\Desktop\Madison Ivy - Showers Make Me Horny.part1.rar
[2013/07/08 14:37:35 | 000,017,376 | -H-- | M] () -- D:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/08 14:37:35 | 000,017,376 | -H-- | M] () -- D:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/05 14:56:54 | 000,000,000 | R--D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
[2013/07/05 01:19:38 | 000,085,413 | ---- | M] () -- D:\Windows\FontData.fdb
[2013/06/28 10:24:10 | 000,018,006 | ---- | M] () -- D:\Users\Jan\Desktop\opr0OL46.pdf
[2013/06/28 09:34:57 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\SafeNet
[2013/06/28 09:10:13 | 000,001,171 | ---- | M] () -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013/06/28 07:15:53 | 000,013,255 | ---- | M] () -- D:\Users\Jan\Desktop\opr0OIGN.pdf
[2013/06/24 00:40:48 | 000,001,114 | ---- | M] () -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
[2013/06/24 00:40:48 | 000,001,102 | ---- | M] () -- D:\Users\Public\Desktop\TeamViewer 8.lnk
[2013/06/22 12:06:59 | 000,657,910 | ---- | M] () -- D:\Windows\System32\perfh007.dat
[2013/06/22 12:06:59 | 000,619,146 | ---- | M] () -- D:\Windows\System32\perfh009.dat
[2013/06/22 12:06:59 | 000,131,250 | ---- | M] () -- D:\Windows\System32\perfc007.dat
[2013/06/22 12:06:59 | 000,107,466 | ---- | M] () -- D:\Windows\System32\perfc009.dat
[2013/06/22 01:55:07 | 000,001,035 | ---- | M] () -- D:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Jan.lnk
[1 D:\Windows\SysWow64\*.tmp files -> D:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/07/10 10:16:07 | 001,084,732 | ---- | C] () -- D:\ProgramData\2433f433
[2013/07/10 10:16:07 | 001,084,668 | ---- | C] () -- D:\Users\Jan\AppData\Local\2433f433
[2013/07/10 10:16:07 | 001,084,655 | ---- | C] () -- D:\Users\Jan\AppData\Roaming\2433f433
[2013/07/10 10:08:15 | 091,516,302 | ---- | C] () -- D:\Users\Jan\Desktop\Madison Ivy - Showers Make Me Horny.part3.rar
[2013/07/10 00:14:33 | 001,715,366 | ---- | C] () -- D:\Users\Jan\Desktop\KV.pdf
[2013/07/10 00:13:44 | 000,076,406 | ---- | C] () -- D:\Users\Jan\Desktop\GVV.pdf
[2013/07/10 00:05:06 | 800,000,000 | ---- | C] () -- D:\Users\Jan\Desktop\Madison Ivy - Showers Make Me Horny.part2.rar
[2013/07/10 00:00:33 | 1611,404,517 | ---- | C] () -- D:\Users\Jan\Desktop\Madison_Ivy-Take_Out_s3x.wmv
[2013/07/09 00:04:10 | 800,000,000 | ---- | C] () -- D:\Users\Jan\Desktop\Madison Ivy - Showers Make Me Horny.part1.rar
[2013/07/05 15:41:29 | 000,000,993 | ---- | C] () -- D:\Users\Public\Desktop\AVG 2013.lnk
[2013/06/28 10:27:31 | 000,018,006 | ---- | C] () -- D:\Users\Jan\Desktop\opr0OL46.pdf
[2013/06/28 09:10:13 | 000,001,171 | ---- | C] () -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013/06/28 07:16:51 | 000,013,255 | ---- | C] () -- D:\Users\Jan\Desktop\opr0OIGN.pdf
[2013/06/22 01:55:07 | 000,001,035 | ---- | C] () -- D:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Jan.lnk
[2013/03/08 12:23:18 | 000,000,120 | ---- | C] () -- D:\Windows\wininit.ini
[2012/10/05 12:55:08 | 000,005,632 | ---- | C] () -- D:\Users\Jan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/11 07:00:26 | 000,386,560 | ---- | C] () -- D:\Windows\SysWow64\mmSQL.dll
[2011/06/26 12:34:58 | 000,000,717 | ---- | C] () -- D:\Windows\cdplayer.ini
[2011/06/21 04:25:02 | 000,252,928 | ---- | C] () -- D:\Windows\SysWow64\DShowRdpFilter.dll
[2011/04/13 10:04:12 | 000,022,016 | ---- | C] () -- D:\Windows\SysWow64\ODBCSTF.DLL
[2011/04/13 10:04:12 | 000,005,679 | ---- | C] () -- D:\Windows\SysWow64\REGSVR.EXE
[2011/04/13 10:04:07 | 000,009,216 | ---- | C] () -- D:\Windows\SysWow64\CBNVDD.DLL
[2011/02/26 10:39:12 | 000,218,820 | -H-- | C] () -- D:\Windows\SysWow64\mlfcache.dat
[2010/12/09 17:05:12 | 001,526,948 | ---- | C] () -- D:\Windows\SysWow64\PerfStringBackup.INI
[2010/10/25 05:09:56 | 000,974,848 | ---- | C] () -- D:\Windows\SysWow64\cis-2.4.dll
[2010/10/25 05:09:56 | 000,081,920 | ---- | C] () -- D:\Windows\SysWow64\issacapi_bs-2.3.dll
[2010/10/25 05:09:56 | 000,065,536 | ---- | C] () -- D:\Windows\SysWow64\issacapi_pe-2.3.dll
[2010/10/25 05:09:56 | 000,057,344 | ---- | C] () -- D:\Windows\SysWow64\issacapi_se-2.3.dll
[2010/05/09 12:36:38 | 000,075,776 | ---- | C] () -- D:\Windows\cadkasdeinst01e.exe
[2010/05/08 07:26:34 | 000,004,240 | ---- | C] () -- D:\Users\Jan\AppData\Roaming\wklnhst.dat
[2010/05/02 12:29:13 | 000,000,000 | ---- | C] () -- D:\Windows\nsreg.dat
[2010/01/28 00:39:11 | 000,001,695 | ---- | C] () -- D:\Windows\WPatchProgress.ini
[2010/01/27 16:32:59 | 000,000,033 | ---- | C] () -- D:\Windows\LaunApp.ini
[2010/01/27 16:10:47 | 000,200,704 | ---- | C] () -- D:\Windows\PLFSetI.exe
[2010/01/27 16:10:47 | 000,000,150 | ---- | C] () -- D:\Windows\PidList.ini
[2009/11/02 16:43:23 | 000,131,368 | ---- | C] () -- D:\ProgramData\FullRemove.exe
[2009/10/30 01:54:34 | 000,000,189 | ---- | C] () -- D:\Windows\Prelaunch.ini
[2009/10/30 01:54:34 | 000,000,168 | ---- | C] () -- D:\Windows\WisLangCode.ini
[2009/10/30 01:54:34 | 000,000,147 | ---- | C] () -- D:\Windows\WisPriority.ini
[2009/10/06 03:16:00 | 000,819,200 | ---- | C] () -- D:\Windows\SysWow64\xvidcore.dll
[2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- D:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- D:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- D:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- D:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- D:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 18:25:04 | 000,197,632 | ---- | C] () -- D:\Windows\SysWow64\ir32_32.dll
[2009/07/13 17:59:36 | 000,982,196 | ---- | C] () -- D:\Windows\SysWow64\igkrng500.bin
[2009/07/13 17:59:36 | 000,139,824 | ---- | C] () -- D:\Windows\SysWow64\igfcg500.bin
[2009/07/13 17:59:36 | 000,097,448 | ---- | C] () -- D:\Windows\SysWow64\igfcg500m.bin
[2009/07/13 17:59:35 | 000,417,344 | ---- | C] () -- D:\Windows\SysWow64\igcompkrng500.bin
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- D:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- D:\Windows\SysWow64\mlang.dat
[2008/10/07 04:13:30 | 000,197,912 | ---- | C] () -- D:\Windows\SysWow64\physxcudart_20.dll
[2008/10/07 04:13:22 | 000,058,648 | ---- | C] () -- D:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 04:13:20 | 000,058,648 | ---- | C] () -- D:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 04:13:20 | 000,058,648 | ---- | C] () -- D:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 04:13:20 | 000,058,648 | ---- | C] () -- D:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 04:13:20 | 000,058,648 | ---- | C] () -- D:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 04:13:20 | 000,058,648 | ---- | C] () -- D:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 04:13:20 | 000,058,648 | ---- | C] () -- D:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 04:13:20 | 000,058,648 | ---- | C] () -- D:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 04:13:20 | 000,058,648 | ---- | C] () -- D:\Windows\SysWow64\AgCPanelFrench.dll
[2007/10/25 11:26:10 | 000,005,632 | ---- | C] () -- D:\Windows\SysWow64\drivers\StarOpen.sys
[2002/08/06 18:00:00 | 000,049,152 | ---- | C] () -- D:\Windows\SysWow64\wrkgadm.exe
[2002/08/06 18:00:00 | 000,012,288 | ---- | C] () -- D:\Windows\SysWow64\HLINKPRX.DLL
========== LOP Check ==========
[2012/09/24 01:49:50 | 000,000,000 | ---D | M] -- D:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2010/04/27 08:34:59 | 000,000,000 | -HSD | M] -- D:\ProgramData\Anwendungsdaten
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Application Data
[2010/05/03 01:06:36 | 000,000,000 | ---D | M] -- D:\ProgramData\Autodesk
[2012/04/04 14:29:57 | 000,000,000 | ---D | M] -- D:\ProgramData\Avanquest
[2013/07/05 15:42:12 | 000,000,000 | ---D | M] -- D:\ProgramData\AVG2013
[2009/11/02 16:42:41 | 000,000,000 | ---D | M] -- D:\ProgramData\BackupManager
[2012/04/04 15:20:33 | 000,000,000 | ---D | M] -- D:\ProgramData\BVRP Software
[2013/02/27 13:22:35 | 000,000,000 | ---D | M] -- D:\ProgramData\Canon IJ Network Tool
[2010/06/06 15:02:11 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonBJ
[2013/02/27 13:27:06 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonEPP
[2013/03/04 11:42:33 | 000,000,000 | ---D | M] -- D:\ProgramData\CanonIJ
[2012/09/12 05:56:34 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonIJEGV
[2013/02/27 13:27:06 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonIJEPPEX2
[2013/02/27 13:13:37 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonIJETV
[2013/02/27 13:22:13 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonIJFAX
[2013/02/27 13:27:05 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonIJMyPrinter
[2013/07/05 14:31:49 | 000,000,000 | ---D | M] -- D:\ProgramData\CanonIJPLM
[2013/06/01 09:06:50 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonIJScan
[2013/02/27 13:27:07 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonIJSolutionMenuEX
[2013/02/27 13:19:39 | 000,000,000 | ---D | M] -- D:\ProgramData\CanonIJWSpt
[2013/07/05 15:27:31 | 000,000,000 | -H-D | M] -- D:\ProgramData\Common Files
[2013/05/20 05:27:44 | 000,000,000 | ---D | M] -- D:\ProgramData\DAEMON Tools Lite
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Desktop
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Documents
[2010/04/27 08:34:59 | 000,000,000 | -HSD | M] -- D:\ProgramData\Dokumente
[2010/04/27 08:34:59 | 000,000,000 | -HSD | M] -- D:\ProgramData\Favoriten
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Favorites
[2012/07/16 14:13:54 | 000,000,000 | ---D | M] -- D:\ProgramData\install_clap
[2013/07/10 08:42:08 | 000,000,000 | ---D | M] -- D:\ProgramData\MFAData
[2013/05/02 04:58:42 | 000,000,000 | ---D | M] -- D:\ProgramData\Mobile Master
[2010/04/27 08:35:13 | 000,000,000 | ---D | M] -- D:\ProgramData\OEM
[2009/10/30 01:39:39 | 000,000,000 | ---D | M] -- D:\ProgramData\Packard Bell
[2010/07/22 11:09:43 | 000,000,000 | ---D | M] -- D:\ProgramData\Partner
[2010/06/06 14:34:12 | 000,000,000 | ---D | M] -- D:\ProgramData\PC Drivers HeadQuarters
[2011/07/31 08:29:25 | 000,000,000 | ---D | M] -- D:\ProgramData\PC Suite
[2012/07/16 14:22:47 | 000,000,000 | ---D | M] -- D:\ProgramData\PDVD
[2010/12/20 03:58:38 | 000,000,000 | ---D | M] -- D:\ProgramData\PixelPlanet
[2010/11/10 13:34:48 | 000,000,000 | ---D | M] -- D:\ProgramData\PlagiarismFinder
[2010/12/09 12:13:56 | 000,000,000 | ---D | M] -- D:\ProgramData\Samsung
[2012/04/04 14:32:22 | 000,000,000 | ---D | M] -- D:\ProgramData\Sony
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Start Menu
[2010/04/27 08:34:59 | 000,000,000 | -HSD | M] -- D:\ProgramData\Startmenü
[2013/06/22 04:48:29 | 000,000,000 | ---D | M] -- D:\ProgramData\Temp
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Templates
[2010/06/06 14:34:28 | 000,000,000 | ---D | M] -- D:\ProgramData\UAB
[2010/04/27 08:34:59 | 000,000,000 | -HSD | M] -- D:\ProgramData\Vorlagen
[2012/08/06 10:57:12 | 000,000,000 | ---D | M] -- D:\ProgramData\WindSolutions
[2010/10/11 10:33:11 | 000,000,000 | ---D | M] -- D:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2013/06/08 06:34:31 | 000,032,640 | ---- | M] () -- D:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 122 bytes -> D:\ProgramData\Temp:AB689DEA
< End of report > Was kann ich tun? Bin am verzweifeln
Vielen Dank |