Lars12345 | 29.07.2013 12:59 | Interpol Trojaner Hallo,
Vor ca. einer Stunde wurde mein Rechner duch einen Interpol Trojaner gesperrt.
Mithilfe von ReatogoPe habe ich OLTPE laufen lassen und den folgenden Log ausgegeben bekommen>
OTL Logfile: Code:
OTL logfile created on: 7/29/2013 3:55:11 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
64bit-Windows 7 Enterprise Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 83.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): d:\pagefile.sys 4096 4096 [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\Windows | %ProgramFiles% = D:\Program Files (x86)
Drive C: | 100.97 Mb Total Space | 70.30 Mb Free Space | 69.62% Space Free | Partition Type: NTFS
Drive D: | 63.85 Gb Total Space | 2.01 Gb Free Space | 3.14% Space Free | Partition Type: NTFS
Drive E: | 39.06 Gb Total Space | 9.05 Gb Free Space | 23.17% Space Free | Partition Type: NTFS
Drive F: | 982.11 Mb Total Space | 899.42 Mb Free Space | 91.58% Space Free | Partition Type: FAT
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2013/05/27 01:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand] -- D:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2013/02/26 15:45:09 | 001,432,400 | ---- | M] (Flexera Software, Inc.) [On_Demand] -- D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2012/01/31 03:10:36 | 000,339,776 | ---- | M] ( ) [Auto] -- D:\Program Files\Autodesk\Inventor 2013\Moldflow\bin\mitsijm.exe -- (mitsijm2013)
SRV:64bit: - [2011/11/01 07:37:56 | 001,518,352 | ---- | M] (Intel(R) Corporation) [Auto] -- D:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel(R)
SRV:64bit: - [2011/11/01 07:22:28 | 000,844,560 | ---- | M] (Intel(R) Corporation) [Auto] -- D:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel(R)
SRV:64bit: - [2011/07/12 11:53:58 | 000,133,992 | ---- | M] (Lenovo Group Limited) [Auto] -- D:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC)
SRV:64bit: - [2011/07/12 11:53:40 | 000,145,256 | ---- | M] (Lenovo Group Limited) [Auto] -- D:\Program Files\Lenovo\HOTKEY\tphkload.exe -- (TPHKLOAD)
SRV:64bit: - [2011/07/12 11:53:24 | 000,101,736 | ---- | M] (Lenovo Group Limited) [Auto] -- D:\Program Files\Lenovo\HOTKEY\micmute.exe -- (LENOVO.MICMUTE)
SRV:64bit: - [2011/07/12 11:53:18 | 000,142,696 | ---- | M] (Lenovo Group Limited) [Auto] -- D:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe -- (TPHKSVC)
SRV:64bit: - [2011/03/29 14:15:36 | 000,047,728 | ---- | M] (Lenovo.) [On_Demand] -- D:\Windows\System32\TPHDEXLG64.exe -- (TPHDEXLGSVC)
SRV:64bit: - [2010/02/01 18:45:34 | 006,159,656 | ---- | M] (Wacom Technology, Corp.) [Auto] -- D:\Windows\System32\Wacom_Tablet.exe -- (TabletServiceWacom)
SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand] -- D:\Windows\System32\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2008/07/15 08:09:48 | 000,111,616 | ---- | M] (Andrea Electronics Corporation) [Auto] -- D:\Windows\System32\AEADISRV.EXE -- (AEADIFilters)
SRV:64bit: - [2007/11/07 20:11:22 | 004,466,688 | ---- | M] (Microsoft Corporation) [Disabled] -- D:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe -- (msvsmon90)
SRV:64bit: - [2006/11/27 12:45:16 | 000,410,624 | ---- | M] (Conexant Systems, Inc.) [Auto] -- D:\Windows\System32\drivers\XAudio64.exe -- (XAudioService)
SRV - [2013/07/08 05:54:44 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand] -- D:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/06/12 10:16:33 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- D:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/06/03 05:57:49 | 003,085,264 | ---- | M] () [Auto] -- D:\ProgramData\BrowserProtect\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe -- (BrowserProtect)
SRV - [2013/05/11 06:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto] -- D:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/04/25 17:32:53 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand] -- D:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2013/04/16 07:24:40 | 000,206,448 | ---- | M] (Kaspersky Lab ZAO) [Auto] -- D:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe -- (AVP)
SRV - [2013/04/04 08:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto] -- D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 08:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto] -- D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013/01/02 08:56:20 | 000,102,400 | ---- | M] () [Auto] -- D:\Program Files (x86)\DiskBoss\bin\diskbsa.exe -- (DiskBoss Service)
SRV - [2012/10/26 09:41:20 | 002,048,408 | ---- | M] (TeamViewer GmbH) [Auto] -- D:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5)
SRV - [2012/08/13 07:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto] -- D:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/07/13 11:27:00 | 000,769,432 | ---- | M] (Nero AG) [Auto] -- D:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate) @C:\Program Files (x86)
SRV - [2012/03/16 11:36:10 | 000,034,104 | ---- | M] (Lenovo Group Limited) [Auto] -- D:\Program Files (x86)\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2012/03/15 00:07:00 | 001,662,528 | ---- | M] (Lenovo) [On_Demand] -- D:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE -- (Power Manager DBC Service)
SRV - [2012/03/15 00:07:00 | 000,320,576 | ---- | M] (Lenovo.) [On_Demand] -- D:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE -- (DozeSvc)
SRV - [2012/03/15 00:07:00 | 000,165,440 | ---- | M] (Lenovo Group Limited) [On_Demand] -- D:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.exe -- (PwmEWSvc)
SRV - [2012/01/18 00:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto] -- D:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2011/11/13 18:27:20 | 000,354,416 | ---- | M] (VMware, Inc.) [Auto] -- D:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2011/11/13 18:27:18 | 000,433,264 | ---- | M] (VMware, Inc.) [Auto] -- D:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)
SRV - [2011/11/13 17:55:18 | 011,839,488 | ---- | M] () [On_Demand] -- D:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe -- (VMwareHostd)
SRV - [2011/11/13 16:49:40 | 000,079,872 | ---- | M] (VMware, Inc.) [Auto] -- D:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe -- (VMAuthdService)
SRV - [2011/11/03 14:25:09 | 002,358,656 | ---- | M] (TeamViewer GmbH) [Disabled] -- D:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2011/11/03 05:11:25 | 003,246,040 | ---- | M] (Acronis) [Disabled] -- D:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv)
SRV - [2011/10/20 07:09:18 | 000,269,376 | ---- | M] (Lenovo) [Auto] -- D:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe -- (AcSvc)
SRV - [2011/10/20 07:09:16 | 000,134,208 | ---- | M] (Lenovo) [Auto] -- D:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe -- (AcPrfMgrSvc)
SRV - [2011/09/22 17:21:28 | 001,114,280 | ---- | M] (Acronis) [Auto] -- D:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2011/08/29 17:11:04 | 000,846,448 | ---- | M] (VMware, Inc.) [Auto] -- D:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe -- (VMUSBArbService)
SRV - [2010/03/18 08:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- D:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/10 08:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto] -- D:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2010/02/19 07:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- D:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- D:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2007/08/30 04:58:30 | 000,045,664 | ---- | M] (Schnapper-Software Robert Beer) [Auto] -- D:\Program Files (x86)\SchnapperPro\TimeSync.exe -- (SchnapperPro-TimeSync)
SRV - [2006/12/19 12:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) [Auto] -- D:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe -- (EpsonBidirectionalService)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013/06/13 08:14:16 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System] -- D:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2013/04/16 07:30:42 | 000,637,272 | ---- | M] (Kaspersky Lab) [File_System | System] -- D:\Windows\System32\drivers\klif.sys -- (KLIF)
DRV:64bit: - [2013/04/04 08:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand] -- D:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2013/02/13 06:12:06 | 000,085,864 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K)
DRV:64bit: - [2013/02/13 06:12:06 | 000,076,648 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS)
DRV:64bit: - [2013/01/11 06:52:56 | 000,019,032 | ---- | M] () [Kernel | On_Demand] -- D:\Windows\System32\pwdrvio.sys -- (pwdrvio)
DRV:64bit: - [2013/01/11 06:52:56 | 000,012,384 | ---- | M] () [Kernel | On_Demand] -- D:\Windows\System32\pwdspio.sys -- (pwdspio)
DRV:64bit: - [2012/03/15 00:07:00 | 000,029,512 | ---- | M] (Lenovo.) [Kernel | Boot] -- D:\Windows\System32\drivers\DZHDD64.SYS -- (DzHDD64)
DRV:64bit: - [2012/03/15 00:07:00 | 000,019,784 | ---- | M] (Lenovo Group Limited) [Kernel | System] -- D:\Windows\System32\drivers\TPPWR64V.SYS -- (TPPWRIF)
DRV:64bit: - [2012/02/15 05:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/01/18 00:44:36 | 004,865,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\lvuvc64.sys -- (LVUVC64) Logitech Webcam Pro 9000(UVC)
DRV:64bit: - [2012/01/18 00:44:28 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2011/12/16 11:53:28 | 000,016,376 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand] -- D:\Windows\System32\drivers\TVMonitor.sys -- (MonitorFunction)
DRV:64bit: - [2011/11/13 18:28:16 | 000,063,088 | ---- | M] (VMware, Inc.) [Kernel | Auto] -- D:\Windows\System32\drivers\vmx86.sys -- (vmx86)
DRV:64bit: - [2011/11/13 18:28:10 | 000,031,344 | ---- | M] (VMware, Inc.) [Kernel | Auto] -- D:\Windows\System32\drivers\VMparport.sys -- (VMparport)
DRV:64bit: - [2011/11/13 18:26:30 | 000,030,320 | ---- | M] (VMware, Inc.) [Kernel | Auto] -- D:\Windows\System32\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV:64bit: - [2011/11/13 16:33:56 | 000,045,680 | ---- | M] (VMware, Inc.) [Kernel | Auto] -- D:\Windows\System32\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV:64bit: - [2011/11/13 16:33:56 | 000,020,080 | ---- | M] (VMware, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV:64bit: - [2011/11/03 05:11:27 | 000,285,280 | ---- | M] (Acronis) [File_System | On_Demand] -- D:\Windows\System32\drivers\afcdp.sys -- (afcdp)
DRV:64bit: - [2011/11/03 05:11:22 | 001,263,200 | ---- | M] (Acronis) [Kernel | Boot] -- D:\Windows\System32\drivers\tdrpm273.sys -- (tdrpman273) Acronis Try&Decide and Restore Points filter (build 273)
DRV:64bit: - [2011/11/03 05:11:20 | 000,970,336 | ---- | M] (Acronis) [Kernel | Boot] -- D:\Windows\System32\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2011/11/03 05:11:14 | 000,277,088 | ---- | M] (Acronis) [Kernel | Boot] -- D:\Windows\System32\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2011/11/02 21:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot] -- D:\Windows\System32\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2011/10/05 04:55:02 | 000,729,152 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\netr7364.sys -- (netr7364)
DRV:64bit: - [2011/08/29 17:11:04 | 000,039,024 | ---- | M] (VMware, Inc.) [Kernel | Auto] -- D:\Windows\System32\drivers\hcmon.sys -- (hcmon)
DRV:64bit: - [2011/08/29 17:01:10 | 000,037,680 | ---- | M] (VMware, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\vmusb.sys -- (vmusb)
DRV:64bit: - [2011/08/10 08:55:35 | 000,011,576 | ---- | M] (Samsung Electronics) [Kernel | Auto] -- D:\Windows\System32\drivers\SSPORT.SYS -- (SSPORT)
DRV:64bit: - [2011/08/08 09:59:12 | 000,116,336 | ---- | M] (VMware, Inc.) [Kernel | Boot] -- D:\Windows\System32\drivers\vmci.sys -- (vmci)
DRV:64bit: - [2011/08/02 10:38:44 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\netaapl64.sys -- (Netaapl)
DRV:64bit: - [2011/03/29 14:13:40 | 000,139,888 | ---- | M] (Lenovo.) [Kernel | Boot] -- D:\Windows\System32\drivers\ApsX64.sys -- (Shockprf)
DRV:64bit: - [2011/03/29 14:11:48 | 000,023,664 | ---- | M] (Lenovo.) [Kernel | Boot] -- D:\Windows\System32\drivers\ApsHM64.sys -- (TPDIGIMN)
DRV:64bit: - [2011/03/10 12:36:24 | 000,029,488 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System] -- D:\Windows\System32\drivers\klim6.sys -- (KLIM6)
DRV:64bit: - [2011/03/04 07:23:28 | 000,011,864 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System] -- D:\Windows\System32\drivers\kl2.sys -- (kl2)
DRV:64bit: - [2011/03/04 07:23:24 | 000,460,888 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot] -- D:\Windows\System32\drivers\kl1.sys -- (KL1)
DRV:64bit: - [2011/01/15 18:36:06 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2011/01/15 18:35:52 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2011/01/15 18:34:39 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\tsusbhub.sys -- (tsusbhub)
DRV:64bit: - [2011/01/15 18:34:39 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:64bit: - [2011/01/15 18:34:39 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\system32\DRIVERS\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2011/01/15 18:34:39 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\system32\DRIVERS\terminpt.sys -- (terminpt)
DRV:64bit: - [2011/01/15 18:34:36 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2011/01/15 18:34:36 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\system32\DRIVERS\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/10/20 01:05:02 | 000,059,048 | ---- | M] (SafeNet, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\SNTUSB64.SYS -- (SNTUSB64)
DRV:64bit: - [2010/09/07 09:09:34 | 000,015,472 | ---- | M] (Lenovo Group Limited) [Kernel | System] -- D:\Windows\System32\drivers\smiifx64.sys -- (lenovo.smi)
DRV:64bit: - [2010/01/24 18:32:24 | 000,018,216 | ---- | M] (Wacom Technology) [Kernel | On_Demand] -- D:\Windows\System32\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV:64bit: - [2009/11/02 14:27:10 | 000,022,544 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand] -- D:\Windows\System32\drivers\klmouflt.sys -- (klmouflt)
DRV:64bit: - [2009/09/22 21:46:18 | 000,066,304 | ---- | M] (Microsoft Corporation) [Kernel | System] -- D:\Windows\System32\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV:64bit: - [2009/09/22 21:46:17 | 000,359,552 | ---- | M] (Microsoft Corporation) [Kernel | System] -- D:\Windows\System32\drivers\vpcvmm.sys -- (vpcvmm)
DRV:64bit: - [2009/09/22 21:32:39 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\vpcusb.sys -- (vpcusb)
DRV:64bit: - [2009/09/22 21:32:33 | 000,187,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\vpchbus.sys -- (vpcbus)
DRV:64bit: - [2009/09/21 18:29:22 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand] -- D:\Windows\System32\drivers\wacomvhid.sys -- (wacomvhid)
DRV:64bit: - [2009/09/17 01:05:02 | 000,145,448 | ---- | M] (SafeNet, Inc.) [Kernel | Auto] -- D:\Windows\System32\Drivers\Sentinel64.sys -- (Sentinel64)
DRV:64bit: - [2009/09/03 15:14:30 | 000,057,856 | ---- | M] (REDC) [Kernel | Auto] -- D:\Windows\System32\drivers\rixdpx64.sys -- (rismxdp)
DRV:64bit: - [2009/09/03 14:59:28 | 000,054,784 | ---- | M] (REDC) [Kernel | Auto] -- D:\Windows\System32\drivers\rimspx64.sys -- (rimsptsk)
DRV:64bit: - [2009/09/03 14:37:02 | 000,067,072 | ---- | M] (REDC) [Kernel | Auto] -- D:\Windows\System32\drivers\rimmpx64.sys -- (rimmptsk)
DRV:64bit: - [2009/07/13 20:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009/07/13 19:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- D:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 16:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\netw5v64.sys -- (netw5v64) Intel(R)
DRV:64bit: - [2009/06/10 16:35:20 | 000,278,016 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\e1e6032e.sys -- (e1express) Intel(R)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\system32\DRIVERS\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\system32\DRIVERS\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/03 05:33:20 | 003,557,248 | ---- | M] () [Kernel | On_Demand] -- D:\Windows\System32\drivers\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
DRV:64bit: - [2008/11/07 11:33:34 | 000,659,712 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\emOEM64.sys -- (USB28xxOEM)
DRV:64bit: - [2008/11/07 11:33:32 | 000,658,560 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\emBDA64.sys -- (USB28xxBGA)
DRV:64bit: - [2007/02/19 01:56:38 | 000,027,136 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\psadd.sys -- (psadd)
DRV:64bit: - [2007/02/16 14:12:36 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand] -- D:\Windows\System32\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV:64bit: - [2006/12/21 08:33:28 | 001,511,936 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\CAX_DPV.sys -- (HSF_DPV)
DRV:64bit: - [2006/12/21 08:30:50 | 000,300,032 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\CAXHWAZL.sys -- (CAXHWAZL)
DRV:64bit: - [2006/12/21 08:29:48 | 000,731,648 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\CAX_CNXT.sys -- (winachsf)
DRV:64bit: - [2006/11/27 12:45:06 | 000,009,728 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto] -- D:\Windows\System32\drivers\XAudio64.sys -- (XAudio)
DRV - [2012/09/12 07:52:59 | 000,017,408 | ---- | M] (MARX Datentechnik GmbH ) [Kernel | Auto] -- D:\Windows\SysWOW64\drivers\CBN.SYS -- (CBN)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Master_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://googel.de/
IE - HKU\Master_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\Master_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\Master_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Master_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\Master_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = localhost:21320
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: D:\Windows\System32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: D:\Windows\System32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: D:\Program Files\Microsoft Office\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: D:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@canon.com/EPPEX: D:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@checkpoint.com/FFApi: File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: D:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin: D:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin: D:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE: D:\Windows\SysWOW64\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0: D:\Program Files (x86)\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: D:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: D:\Program Files (x86)\Microsoft Office\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3: D:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9: D:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.0: D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.2: D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@vmware.com/vmrc,version=2.5.0.00000:
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.3: D:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Acrobat: D:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: D:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\IB UPDATER\FIREFOX
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}: C:\PROGRAM FILES\IB UPDATER\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\IB Updater\Firefox
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}: C:\Program Files\IB Updater\Firefox
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\linkfilter@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\FFExt\linkfilter@kaspersky.ru [2013/04/16 07:30:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\FFExt\virtualKeyboard@kaspersky.ru [2013/04/16 07:30:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013/06/25 10:37:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/21 05:07:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/07/11 21:01:24 | 000,000,000 | ---D | M]
[2013/05/21 05:07:49 | 000,000,000 | ---D | M] (No name found) -- D:\Program Files (x86)\Mozilla Firefox\extensions
[2013/04/12 06:59:21 | 000,000,000 | ---D | M] (Skype Click to Call) -- D:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/06/15 10:51:01 | 000,000,000 | ---D | M] (No name found) -- D:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/07/08 05:54:45 | 000,000,000 | ---D | M] (Default) -- D:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/06/13 14:45:42 | 000,034,048 | ---- | M] (Microsoft Corporation) -- D:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
[2013/04/27 13:01:42 | 000,006,470 | ---- | M] () -- D:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2011/11/13 11:51:09 | 000,002,519 | ---- | M] () -- D:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
O1 HOSTS File: ([2012/05/16 13:55:09 | 000,000,894 | ---- | M]) - D:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 validation.sls.microsoft.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - D:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\x64\ievkbd.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (no name) - {9D717F81-9148-4f12-8568-69135F087DB0} - No CLSID value found.
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - D:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (Ginyas Browser Companion) - {00cbb66b-1d3b-46d3-9577-323a336acb50} - D:\Program Files (x86)\GinyasBrowserCompanion\jsloader.dll ( )
O2 - BHO: (no name) - {074C1DC5-9320-4A9A-947D-C042949C6216} - No CLSID value found.
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - D:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - D:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Ginyas Browser Companion Verifier) - {963B125B-8B21-49A2-A3A8-E37092276531} - D:\Program Files (x86)\GinyasBrowserCompanion\updatebhoWin32.dll ( )
O2 - BHO: (no name) - {9D717F81-9148-4f12-8568-69135F087DB0} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - D:\Program Files (x86)\Delta\delta\1.8.16.16\bh\delta.dll (Delta-search.com)
O2 - BHO: (holasearch Helper Object) - {DFF9B2DA-EF99-4B26-83CB-7058299999D8} - D:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll (holasearch.com)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - D:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - D:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - D:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - D:\Program Files (x86)\Delta\delta\1.8.16.16\deltaTlbr.dll (Delta-search.com)
O3 - HKLM\..\Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Holasearch Toolbar) - {C510DFFB-0AFE-484C-BA40-CED5B74C4EEF} - D:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchTlbr.dll (holasearch.com)
O3 - HKLM\..\Toolbar: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\Master_ON_D\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] D:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4:64bit: - HKLM..\Run: [AcWin7Hlpr] D:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe (Lenovo)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] D:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Autodesk Sync] D:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (Autodesk, Inc.)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] D:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [CanonSolutionMenu] D:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] D:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] D:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] D:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVP] D:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [CanonSolutionMenuEx] D:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [EFI_Designer_Edition_Control] D:\Program Files (x86)\EFI\EFI Designer Edition\EFI_Designer_Edition_Control.exe (Electronics for Imaging)
O4 - HKLM..\Run: [IJNetworkScannerSelectorEX] D:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (CANON INC.)
O4 - HKLM..\Run: [LWS] D:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [PWMTRV] D:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [SwitchBoard] D:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TrueImageMonitor.exe] D:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [vmware-tray] D:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
O4 - HKU\LocalService_ON_D..\Run: [Sidebar] D:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\Master_ON_D..\Run: [{A8867815-C72B-5CE4-B9B9-8DBCD84CB317}] D:\Users\Master\AppData\Roaming\Viap\ifugi.exe ()
O4 - HKU\Master_ON_D..\Run: [AdobeBridge] File not found
O4 - HKU\Master_ON_D..\Run: [DAEMON Tools Lite] D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
O4 - HKU\Master_ON_D..\Run: [phonostar-PlayerTimer] D:\Program Files (x86)\phonostar-Player\phonostarTimer.exe ()
O4 - HKU\Master_ON_D..\Run: [servc] File not found
O4 - HKU\NetworkService_ON_D..\Run: [Sidebar] D:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\LocalService_ON_D..\RunOnce: [mctadmin] File not found
O4 - HKU\NetworkService_ON_D..\RunOnce: [mctadmin] File not found
O4 - Startup: Error locating startup folders.
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKU\Master_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - D:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\x64\ievkbd.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9:64bit: - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - D:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: SchnapperPro - {D6243B39-211B-440E-B4C5-26D2A579CAC8} - Reg Error: Key error. File not found
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - D:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\ievkbd.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - D:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: SchnapperPro - {D6243B39-211B-440E-B4C5-26D2A579CAC8} - Reg Error: Key error. File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - D:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - D:\Windows\System32\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - D:\Windows\System32\vsocklib.dll (VMware, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - D:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - D:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - D:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O13:64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\base64 {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\chrome {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\prox {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (c:\progra~3\browse~1\261339~1.144\{c16c1~1\browse~1.dll) - D:\ProgramData\BrowserProtect\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll ()
O20 - AppInit_DLLs: (c:\progra~2\magnipic\sprote~1.dll) - D:\Program Files (x86)\MagniPic\sprotector.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - D:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - D:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - D:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKU\Master_ON_D Winlogon: Shell - (explorer.exe) - D:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKU\Master_ON_D Winlogon: Shell - (C:\Users\Master\AppData\Roaming\cache.dat) - D:\Users\Master\AppData\Roaming\cache.dat ()
O20:64bit: - Winlogon\Notify\klogon: DllName - %SystemRoot%\System32\klogon.dll - D:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - File not found - -- [ NTFS ]
O32 - AutoRun File - [2013/04/25 17:32:06 | 000,000,000 | ---D | M] - D:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (auto_reactivate C:\bootwiz\asrm.bin) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2013/07/29 13:29:12 | 000,000,000 | ---D | C] -- D:\_OTL
[2013/07/26 08:28:03 | 000,000,000 | ---D | C] -- D:\Users\Master\AppData\Roaming\Ylna
[2013/07/26 08:28:03 | 000,000,000 | ---D | C] -- D:\Users\Master\AppData\Roaming\Coyt
[2013/07/26 08:27:19 | 000,000,000 | ---D | C] -- D:\Users\Master\AppData\Roaming\Viap
[2013/07/26 08:27:19 | 000,000,000 | ---D | C] -- D:\Users\Master\AppData\Roaming\Obwao
[2013/07/26 02:12:57 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/07/24 09:01:56 | 000,000,000 | ---D | C] -- D:\Users\Master\AppData\Roaming\WTablet
[2013/07/24 09:01:50 | 000,000,000 | R--D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablett
[2013/07/24 09:01:50 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\TabletPlugins
[2013/07/24 09:01:33 | 008,997,160 | ---- | C] (Wacom Technology, Corp.) -- D:\Windows\System32\WacomTablet.cpl
[2013/07/24 09:01:31 | 000,012,848 | ---- | C] (Wacom Technology) -- D:\Windows\System32\drivers\wacommousefilter.sys
[2013/07/24 09:01:21 | 000,016,168 | ---- | C] (Wacom Technology) -- D:\Windows\System32\drivers\wacomvhid.sys
[2013/07/24 09:01:16 | 000,018,216 | ---- | C] (Wacom Technology) -- D:\Windows\System32\drivers\wacmoumonitor.sys
[2013/07/24 09:01:12 | 000,000,000 | ---D | C] -- D:\Windows\System32\WTablet
[2013/07/24 09:01:07 | 000,409,896 | ---- | C] (Wacom Technology, Corp.) -- D:\Windows\SysWow64\Wacom_Tablet.dll
[2013/07/24 09:01:07 | 000,293,888 | ---- | C] (Wacom Technology, Corp.) -- D:\Windows\SysWow64\Wintab32.dll
[2013/07/24 09:01:06 | 000,483,624 | ---- | C] (Wacom Technology, Corp.) -- D:\Windows\System32\Wacom_Tablet.dll
[2013/07/24 09:00:58 | 006,159,656 | ---- | C] (Wacom Technology, Corp.) -- D:\Windows\System32\Wacom_Tablet.exe
[2013/07/24 09:00:46 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Tablet
[2013/07/11 21:02:14 | 000,391,168 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\ieui.dll
[2013/07/11 21:02:13 | 000,526,336 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\ieui.dll
[2013/07/11 21:02:12 | 000,136,704 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\iesysprep.dll
[2013/07/11 21:02:12 | 000,109,056 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\iesysprep.dll
[2013/07/11 21:02:12 | 000,089,600 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\RegisterIEPKEYs.exe
[2013/07/11 21:02:12 | 000,071,680 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/07/11 21:02:12 | 000,067,072 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\iesetup.dll
[2013/07/11 21:02:12 | 000,061,440 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\iesetup.dll
[2013/07/11 21:02:12 | 000,051,712 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\ie4uinit.exe
[2013/07/11 21:02:12 | 000,039,936 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\iernonce.dll
[2013/07/11 21:02:12 | 000,033,280 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\iernonce.dll
[2013/07/11 21:02:11 | 000,855,552 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\jscript.dll
[2013/07/11 21:02:11 | 000,690,688 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\jscript.dll
[2013/07/11 21:02:11 | 000,603,136 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\msfeeds.dll
[2013/07/11 21:02:11 | 000,493,056 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\msfeeds.dll
[2013/07/11 21:02:10 | 003,958,784 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\jscript9.dll
[2013/07/11 21:02:09 | 002,877,440 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\jscript9.dll
[2013/07/11 10:10:51 | 000,624,128 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\qedit.dll
[2013/07/11 10:10:51 | 000,509,440 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\qedit.dll
[2013/07/11 10:10:50 | 001,887,744 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\WMVDECOD.DLL
[2013/07/11 10:10:50 | 001,620,480 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/11 10:10:41 | 001,643,520 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\DWrite.dll
[2013/07/11 10:10:41 | 001,247,744 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\DWrite.dll
[2013/07/11 09:16:37 | 000,000,000 | ---D | C] -- D:\Users\Master\AppData\Local\roomeon
[2013/07/11 09:16:20 | 000,000,000 | ---D | C] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\roomeon 3D-Planer
[2013/07/11 09:16:18 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\roomeon GmbH
[2013/07/11 09:14:53 | 000,617,312 | ---- | C] (www.download-sponsor.de) -- D:\Users\Master\Desktop\roomeon - CHIP-Downloader.exe
[2013/07/08 06:39:04 | 000,000,000 | ---D | C] -- D:\Users\Master\AppData\Roaming\inkscape
[2013/07/08 06:34:51 | 000,000,000 | ---D | C] -- D:\Program Files (x86)\Inkscape
[1 D:\Windows\SysWow64\*.tmp files -> D:\Windows\SysWow64\*.tmp -> ]
[1 D:\Windows\System32\drivers\*.tmp files -> D:\Windows\System32\drivers\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/07/29 07:43:53 | 000,000,004 | ---- | M] () -- D:\Users\Master\AppData\Roaming\cache.ini
[2013/07/29 07:43:52 | 000,067,584 | --S- | M] () -- D:\Windows\bootstat.dat
[2013/07/29 07:42:32 | 000,001,056 | ---- | M] () -- D:\Windows\tasks\GinyasBrowserCompanion Stats Report.job
[2013/07/29 07:42:32 | 000,000,940 | ---- | M] () -- D:\Windows\tasks\GinyasBrowserCompanion Update Checker.job
[2013/07/29 07:42:12 | 000,001,106 | ---- | M] () -- D:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/29 07:42:11 | 000,001,056 | ---- | M] () -- D:\Windows\tasks\GinyasBrowserCompanion FireFox Watcher.job
[2013/07/29 07:42:11 | 000,001,008 | ---- | M] () -- D:\Windows\tasks\GinyasBrowserCompanion Chrome Watcher.job
[2013/07/29 07:42:10 | 000,000,376 | -H-- | M] () -- D:\Windows\tasks\MagniPicUpdaterTask{94C0F52A-8C97-4DF9-9FFA-B3F293F1FEFE}.job
[2013/07/29 05:48:56 | 000,789,088 | ---- | M] () -- D:\Windows\System32\perfh007.dat
[2013/07/29 05:48:56 | 000,731,824 | ---- | M] () -- D:\Windows\System32\perfh009.dat
[2013/07/29 05:48:56 | 000,183,308 | ---- | M] () -- D:\Windows\System32\perfc007.dat
[2013/07/29 05:48:56 | 000,155,288 | ---- | M] () -- D:\Windows\System32\perfc009.dat
[2013/07/29 05:47:31 | 000,019,296 | -H-- | M] () -- D:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/29 05:47:31 | 000,019,296 | -H-- | M] () -- D:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/29 05:23:56 | 000,001,110 | ---- | M] () -- D:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/29 05:23:38 | 000,000,884 | ---- | M] () -- D:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/26 16:01:43 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X5
[2013/07/26 15:13:55 | 000,000,000 | ---- | M] () -- D:\Photoshop Temp1286644044
[2013/07/26 14:40:04 | 005,223,688 | ---- | M] () -- D:\Windows\System32\FNTCACHE.DAT
[2013/07/26 12:14:40 | 000,001,235 | ---- | M] () -- D:\Users\Master\Desktop\TestZykus9mm 6.75 Intervall.WPW
[2013/07/26 12:14:40 | 000,001,121 | ---- | M] () -- D:\Users\Master\Desktop\TestZykus9mm 6.75 Intervall.WPI
[2013/07/26 02:12:57 | 000,002,220 | ---- | M] () -- D:\Users\Public\Desktop\Google Earth.lnk
[2013/07/26 02:12:57 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/07/24 09:01:50 | 000,000,000 | R--D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablett
[2013/07/15 14:32:53 | 001,836,466 | ---- | M] () -- D:\Windows\SysWow64\PerfStringBackup.INI
[2013/07/11 09:16:20 | 000,002,623 | ---- | M] () -- D:\Users\Public\Desktop\roomeon Portal.lnk
[2013/07/11 09:16:20 | 000,002,623 | ---- | M] () -- D:\Users\Public\Desktop\roomeon 3D-Planer.lnk
[2013/07/11 09:16:20 | 000,000,000 | ---D | M] -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\roomeon 3D-Planer
[2013/07/11 09:14:49 | 000,617,312 | ---- | M] (www.download-sponsor.de) -- D:\Users\Master\Desktop\roomeon - CHIP-Downloader.exe
[2013/07/08 07:09:48 | 000,001,284 | ---- | M] () -- D:\Users\Master\AppData\Local\recently-used.xbel
[2013/07/08 06:38:48 | 000,001,059 | ---- | M] () -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inkscape.lnk
[2013/07/08 06:38:21 | 000,001,039 | ---- | M] () -- D:\Users\Master\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Inkscape.lnk
[2013/07/08 06:38:21 | 000,001,015 | ---- | M] () -- D:\Users\Public\Desktop\Inkscape.lnk
[1 D:\Windows\SysWow64\*.tmp files -> D:\Windows\SysWow64\*.tmp -> ]
[1 D:\Windows\System32\drivers\*.tmp files -> D:\Windows\System32\drivers\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/07/29 05:59:08 | 000,000,004 | ---- | C] () -- D:\Users\Master\AppData\Roaming\cache.ini
[2013/07/26 15:13:55 | 000,000,000 | ---- | C] () -- D:\Photoshop Temp1286644044
[2013/07/26 14:39:50 | 005,223,688 | ---- | C] () -- D:\Windows\System32\FNTCACHE.DAT
[2013/07/26 02:12:57 | 000,002,220 | ---- | C] () -- D:\Users\Public\Desktop\Google Earth.lnk
[2013/07/24 09:01:45 | 001,744,515 | ---- | C] () -- D:\Windows\System32\WacomTablet.znc
[2013/07/11 09:16:20 | 000,002,623 | ---- | C] () -- D:\Users\Public\Desktop\roomeon Portal.lnk
[2013/07/11 09:16:20 | 000,002,623 | ---- | C] () -- D:\Users\Public\Desktop\roomeon 3D-Planer.lnk
[2013/07/08 07:09:48 | 000,001,284 | ---- | C] () -- D:\Users\Master\AppData\Local\recently-used.xbel
[2013/07/08 06:38:48 | 000,001,059 | ---- | C] () -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inkscape.lnk
[2013/07/08 06:38:21 | 000,001,039 | ---- | C] () -- D:\Users\Master\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Inkscape.lnk
[2013/07/08 06:38:21 | 000,001,015 | ---- | C] () -- D:\Users\Public\Desktop\Inkscape.lnk
[2013/06/28 06:10:42 | 000,000,452 | ---- | C] () -- D:\Windows\pcis-win.ini
[2013/06/27 04:47:38 | 000,034,776 | ---- | C] () -- D:\Windows\SysWow64\ClientPropertyPageLIB.dll
[2013/06/14 06:54:57 | 000,000,085 | ---- | C] () -- D:\Windows\wininit.ini
[2013/04/27 15:22:19 | 000,114,176 | ---- | C] () -- D:\Users\Master\AppData\Roaming\BabMaint.exe
[2013/04/18 12:24:43 | 000,000,059 | ---- | C] () -- D:\Windows\LTRDF14N.INI
[2013/04/16 07:06:12 | 000,017,408 | ---- | C] () -- D:\Users\Master\AppData\Local\WebpageIcons.db
[2013/04/02 09:25:37 | 000,000,193 | ---- | C] () -- D:\Windows\WORDPAD.INI
[2012/12/15 13:34:26 | 000,001,456 | ---- | C] () -- D:\Users\Master\AppData\Local\Adobe Für Web speichern 12.0 Prefs
[2012/12/13 11:59:41 | 000,007,605 | ---- | C] () -- D:\Users\Master\AppData\Local\Resmon.ResmonCfg
[2012/09/07 10:09:39 | 000,000,104 | ---- | C] () -- D:\Windows\InstallDE.ini
[2012/09/07 10:04:21 | 000,043,520 | ---- | C] () -- D:\Windows\SysWow64\CBNDLL.DLL
[2012/09/07 09:32:43 | 000,152,563 | ---- | C] () -- D:\Windows\SysWow64\EPSUI64W_000.dat
[2012/08/25 08:22:08 | 000,081,920 | ---- | C] () -- D:\Windows\SysWow64\GkSui20.EXE
[2012/06/28 04:11:20 | 001,367,040 | ---- | C] () -- D:\Windows\SysWow64\VitaminCtrl.dll
[2012/02/16 08:04:04 | 000,006,656 | ---- | C] () -- D:\Users\Master\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/18 00:44:00 | 010,920,984 | ---- | C] () -- D:\Windows\SysWow64\LogiDPP.dll
[2012/01/18 00:44:00 | 000,336,408 | ---- | C] () -- D:\Windows\SysWow64\DevManagerCore.dll
[2012/01/18 00:44:00 | 000,104,472 | ---- | C] () -- D:\Windows\SysWow64\LogiDPPApp.exe
[2012/01/17 12:32:15 | 000,081,920 | ---- | C] () -- D:\Users\Master\AppData\Roaming\cache.dat
[2012/01/09 08:07:09 | 001,836,466 | ---- | C] () -- D:\Windows\SysWow64\PerfStringBackup.INI
[2011/11/02 18:03:14 | 001,514,016 | ---- | C] () -- D:\Windows\SysWow64\nView.dll
[2011/11/02 18:03:14 | 001,108,512 | ---- | C] () -- D:\Windows\SysWow64\nvwimg.dll
[2011/10/14 19:54:52 | 000,321,856 | ---- | C] () -- D:\Windows\SysWow64\nvStreaming.exe
[2011/08/01 11:21:38 | 000,852,264 | ---- | C] () -- D:\Windows\SysWow64\wodCertificate.dll
[2011/01/15 18:36:18 | 000,252,928 | ---- | C] () -- D:\Windows\SysWow64\DShowRdpFilter.dll
[2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- D:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- D:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- D:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- D:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- D:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 18:25:04 | 000,197,632 | ---- | C] () -- D:\Windows\SysWow64\ir32_32.dll
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- D:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- D:\Windows\SysWow64\mlang.dat
[2007/04/10 20:06:00 | 000,000,110 | ---- | C] () -- D:\Windows\SysWow64\E_ADDNET.DAT
[2005/01/17 03:10:16 | 000,045,056 | ---- | C] () -- D:\Windows\SysWow64\BRTCPCON.DLL
[2004/08/09 03:00:42 | 000,000,114 | ---- | C] () -- D:\Windows\SysWow64\BRLMW03A.INI
========== LOP Check ==========
[2011/11/03 07:37:03 | 000,000,000 | ---D | M] -- D:\ProgramData\Acronis
[2011/11/02 17:29:37 | 000,000,000 | -HSD | M] -- D:\ProgramData\Anwendungsdaten
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Application Data
[2013/06/13 08:19:18 | 000,000,000 | ---D | M] -- D:\ProgramData\Astroburn Lite
[2013/05/15 13:02:31 | 000,000,000 | ---D | M] -- D:\ProgramData\Autodesk
[2013/04/18 11:35:44 | 000,000,000 | ---D | M] -- D:\ProgramData\Babylon
[2012/02/19 13:20:44 | 000,000,000 | ---D | M] -- D:\ProgramData\Binarysense
[2011/11/13 16:22:11 | 000,000,000 | ---D | M] -- D:\ProgramData\boost_interprocess
[2013/06/06 08:58:45 | 000,000,000 | ---D | M] -- D:\ProgramData\BrowserProtect
[2013/02/03 11:58:45 | 000,000,000 | ---D | M] -- D:\ProgramData\Canon IJ Network Tool
[2013/02/03 11:18:26 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonBJ
[2013/02/03 12:01:17 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonEPP
[2013/02/03 12:01:17 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonIJEPPEX2
[2013/02/03 12:01:13 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonIJMyPrinter
[2013/03/09 12:51:43 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonIJScan
[2013/02/03 12:01:19 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonIJSolutionMenuEX
[2013/02/03 11:51:15 | 000,000,000 | ---D | M] -- D:\ProgramData\CanonIJWSpt
[2013/01/22 06:49:13 | 000,000,000 | ---D | M] -- D:\ProgramData\CheckPoint
[2013/03/13 04:28:41 | 000,000,000 | ---D | M] -- D:\ProgramData\CLSoft LTD
[2013/02/26 13:53:42 | 000,000,000 | ---D | M] -- D:\ProgramData\DAEMON Tools Lite
[2012/08/27 04:34:00 | 000,000,000 | ---D | M] -- D:\ProgramData\DassaultSystemes
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Desktop
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Documents
[2011/11/02 17:29:37 | 000,000,000 | -HSD | M] -- D:\ProgramData\Dokumente
[2012/09/07 10:25:19 | 000,000,000 | ---D | M] -- D:\ProgramData\EFI
[2012/09/07 09:29:44 | 000,000,000 | ---D | M] -- D:\ProgramData\EPSON
[2011/11/02 17:29:37 | 000,000,000 | -HSD | M] -- D:\ProgramData\Favoriten
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Favorites
[2013/07/29 07:42:11 | 000,000,000 | ---D | M] -- D:\ProgramData\GinyasBrowserCompanion
[2013/06/26 06:43:53 | 000,000,000 | ---D | M] -- D:\ProgramData\Helicon
[2013/04/18 11:35:55 | 000,000,000 | ---D | M] -- D:\ProgramData\IBUpdaterService
[2013/06/26 05:47:42 | 000,000,000 | ---D | M] -- D:\ProgramData\InstallMate
[2012/01/09 08:57:48 | 000,000,000 | ---D | M] -- D:\ProgramData\Lenovo
[2013/06/26 05:47:42 | 000,000,000 | ---D | M] -- D:\ProgramData\MaganiPiec
[2013/04/18 12:23:01 | 000,000,000 | ---D | M] -- D:\ProgramData\PCStitch 10
[2013/06/28 06:29:53 | 000,000,000 | ---D | M] -- D:\ProgramData\regid.1986-12.com.adobe
[2013/04/13 11:41:02 | 000,000,000 | ---D | M] -- D:\ProgramData\regid.1991-06.com.microsoft
[2011/11/02 18:07:40 | 000,000,000 | ---D | M] -- D:\ProgramData\Roaming
[2013/01/07 08:57:03 | 000,000,000 | ---D | M] -- D:\ProgramData\Samsung
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Start Menu
[2011/11/02 17:29:37 | 000,000,000 | -HSD | M] -- D:\ProgramData\Startmenü
[2013/04/27 13:01:43 | 000,000,000 | ---D | M] -- D:\ProgramData\Tarma Installer
[2013/02/26 16:02:20 | 000,000,000 | ---D | M] -- D:\ProgramData\TEMP
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Templates
[2011/11/02 17:29:37 | 000,000,000 | -HSD | M] -- D:\ProgramData\Vorlagen
[2012/03/28 08:19:42 | 000,000,000 | ---D | M] -- D:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2013/07/29 07:42:11 | 000,001,008 | ---- | M] () -- D:\Windows\Tasks\GinyasBrowserCompanion Chrome Watcher.job
[2013/07/29 07:42:11 | 000,001,056 | ---- | M] () -- D:\Windows\Tasks\GinyasBrowserCompanion FireFox Watcher.job
[2013/07/29 07:42:32 | 000,001,056 | ---- | M] () -- D:\Windows\Tasks\GinyasBrowserCompanion Stats Report.job
[2013/07/29 07:42:32 | 000,000,940 | ---- | M] () -- D:\Windows\Tasks\GinyasBrowserCompanion Update Checker.job
[2013/07/29 07:42:10 | 000,000,376 | -H-- | M] () -- D:\Windows\Tasks\MagniPicUpdaterTask{94C0F52A-8C97-4DF9-9FFA-B3F293F1FEFE}.job
[2013/04/17 03:05:04 | 000,032,640 | ---- | M] () -- D:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 400 bytes -> D:\Users\Master\AppData\Local\desktop.ini:3a96398c0f384e4adf5faa1736aeaf96
@Alternate Data Stream - 224 bytes -> D:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 116 bytes -> D:\ProgramData\TEMP:5974EE7C
@Alternate Data Stream - 114 bytes -> D:\ProgramData\TEMP:A1EDB939
< End of report > --- --- ---
Ich hoffe mir kann jemand helfen, bin der Verzweiflung nahe:heulen:
Ich kann die Datei leider nicht als Anhang hochladen, da keine USB Sticks erkannt werden und ich auf keines der Laufwerke schreiben kann.
Hoffe es geht auch so |