nachfolgend das Logfile.OTL Logfile: Code:
OTL logfile created on: 09.10.2013 20:54:10 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = H:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,25 Gb Total Physical Memory | 1,26 Gb Available Physical Memory | 38,72% Memory free
5,09 Gb Paging File | 2,98 Gb Available in Paging File | 58,58% Paging File free
Paging file location(s): H:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = H: | %SystemRoot% = H:\WINDOWS | %ProgramFiles% = H:\Programme
Drive C: | 1,86 Gb Total Space | 1,63 Gb Free Space | 87,74% Space Free | Partition Type: FAT
Drive E: | 638,54 Gb Total Space | 638,43 Gb Free Space | 99,98% Space Free | Partition Type: NTFS
Drive H: | 292,97 Gb Total Space | 232,35 Gb Free Space | 79,31% Space Free | Partition Type: NTFS
Computer Name: RICO-05299AA39C | User Name: Besitzer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.10.09 20:53:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- H:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\Downloads\OTL.exe
PRC - [2013.10.05 17:52:42 | 000,900,456 | ---- | M] (Plus HD) -- h:\Programme\Plus-HD-3.8\Plus-HD-3.8-bg.exe
PRC - [2013.10.03 08:03:07 | 000,844,752 | ---- | M] (Google Inc.) -- H:\Programme\Google\Chrome\Application\chrome.exe
PRC - [2013.09.25 07:19:35 | 003,579,400 | ---- | M] (SafetyNut Inc.) -- H:\Programme\Movies Toolbar\SafetyNut\safetynut.exe
PRC - [2013.09.25 07:19:30 | 003,419,144 | ---- | M] (SafetyNut Inc.) -- H:\Programme\Movies Toolbar\SafetyNut\SafetyNutManager.exe
PRC - [2013.07.27 15:16:24 | 000,709,120 | ---- | M] (Windows Net) -- H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Windows Net Data\net.exe
PRC - [2013.07.02 16:02:30 | 000,539,072 | ---- | M] (F-Secure Corporation) -- H:\Programme\Vodafone-Sicherheitspaket\Anti-Virus\fsav32.exe
PRC - [2013.07.02 16:01:33 | 001,039,296 | ---- | M] (F-Secure Corporation) -- H:\Programme\Vodafone-Sicherheitspaket\Anti-Virus\fssm32.exe
PRC - [2013.07.02 16:01:33 | 000,621,504 | ---- | M] (F-Secure Corporation) -- H:\Programme\Vodafone-Sicherheitspaket\Anti-Virus\fsgk32.exe
PRC - [2013.06.06 19:00:39 | 000,060,352 | ---- | M] (F-Secure Corporation) -- H:\Programme\Vodafone-Sicherheitspaket\ORSP Client\fsorsp.exe
PRC - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- H:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013.04.04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- H:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- H:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2013.04.04 05:32:53 | 000,181,664 | ---- | M] (Oracle Corporation) -- H:\Programme\Java\jre7\bin\jqs.exe
PRC - [2013.03.12 07:32:58 | 000,506,744 | ---- | M] (Oracle Corporation) -- H:\Programme\Gemeinsame Dateien\Java\Java Update\jucheck.exe
PRC - [2013.03.12 07:32:50 | 000,253,816 | ---- | M] (Oracle Corporation) -- H:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
PRC - [2013.02.05 17:48:44 | 000,272,248 | ---- | M] (McAfee, Inc.) -- H:\Programme\McAfee Security Scan\3.0.318\SSScheduler.exe
PRC - [2013.01.29 18:00:00 | 000,685,936 | R--- | M] (WinZip Computing, S.L.) -- H:\Programme\WinZip\WZQKPICK32.EXE
PRC - [2012.12.21 16:27:46 | 000,057,008 | ---- | M] (Apple Inc.) -- H:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2012.12.21 15:05:20 | 000,547,312 | R--- | M] (Alps Electric Co., Ltd.) -- H:\Programme\DellTPad\Apoint.exe
PRC - [2012.12.12 11:28:14 | 000,163,000 | ---- | M] (Geek Software GmbH) -- H:\Programme\PDF24\pdf24.exe
PRC - [2012.10.02 13:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012.09.06 13:08:32 | 000,057,720 | R--- | M] (Alps Electric Co., Ltd.) -- H:\Programme\DellTPad\ApMsgFwd.exe
PRC - [2011.09.09 17:01:16 | 001,804,648 | ---- | M] (Hewlett-Packard Co.) -- H:\Programme\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe
PRC - [2011.09.09 16:49:30 | 000,643,944 | ---- | M] (Hewlett-Packard Co.) -- H:\Programme\HP\HP Officejet 6600\Bin\HPNetworkCommunicator.exe
PRC - [2011.06.15 17:33:20 | 000,249,648 | ---- | M] (Microsoft Corporation) -- H:\Programme\Microsoft\BingBar\SeaPort.EXE
PRC - [2010.09.16 22:14:05 | 000,522,848 | ---- | M] (F-Secure Corporation) -- H:\Programme\Vodafone-Sicherheitspaket\FWES\program\fsdfwd.exe
PRC - [2010.08.19 16:25:00 | 000,272,864 | ---- | M] () -- H:\Programme\NETGEAR\WNDA3100v2\WifiSvc.exe
PRC - [2010.07.07 13:59:22 | 000,054,744 | R--- | M] (Alps Electric Co., Ltd.) -- H:\Programme\DellTPad\hidfind.exe
PRC - [2010.05.31 14:17:06 | 000,054,640 | R--- | M] (Alps Electric Co., Ltd.) -- H:\Programme\DellTPad\ApntEx.exe
PRC - [2009.10.07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- H:\Programme\Gemeinsame Dateien\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2009.09.11 13:33:54 | 000,009,216 | ---- | M] (Vodafone) -- H:\Programme\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
PRC - [2009.08.05 17:58:52 | 000,186,976 | ---- | M] (F-Secure Corporation) -- H:\Programme\Vodafone-Sicherheitspaket\Common\FSMA32.EXE
PRC - [2009.08.05 17:58:50 | 000,199,264 | ---- | M] (F-Secure Corporation) -- H:\Programme\Vodafone-Sicherheitspaket\Common\FSM32.EXE
PRC - [2009.08.05 17:58:50 | 000,088,672 | ---- | M] (F-Secure Corporation) -- H:\Programme\Vodafone-Sicherheitspaket\Common\FSHDLL32.EXE
PRC - [2009.08.05 17:56:10 | 000,215,648 | ---- | M] (F-Secure Corporation) -- H:\Programme\Vodafone-Sicherheitspaket\Anti-Virus\fsgk32st.exe
PRC - [2008.08.18 19:01:52 | 000,203,296 | ---- | M] (NVIDIA Corporation) -- H:\WINDOWS\system32\nvraidservice.exe
PRC - [2008.04.14 14:00:00 | 001,036,800 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\explorer.exe
PRC - [2007.06.21 16:12:03 | 000,054,576 | ---- | M] (AOL, LLC.) -- H:\Programme\AOL 9.0 VRa\shellmon.exe
PRC - [2007.05.24 10:15:27 | 000,039,472 | ---- | M] (AOL, LLC.) -- H:\Programme\AOL 9.0 VRa\waol.exe
PRC - [2007.04.12 23:23:31 | 000,042,032 | ---- | M] (AOL LLC) -- H:\Programme\Gemeinsame Dateien\aol\1243281108\ee\aolsoftware.exe
PRC - [2007.04.02 14:33:32 | 000,063,120 | ---- | M] (AOL LLC) -- H:\Programme\Gemeinsame Dateien\aol\TopSpeed\3.0\aoltpsd3.exe
PRC - [2006.10.23 14:50:35 | 000,046,640 | R--- | M] (AOL LLC) -- H:\Programme\Gemeinsame Dateien\aol\acs\AOLacsd.exe
========== Modules (No Company Name) ==========
MOD - [2013.10.09 20:49:18 | 013,584,776 | ---- | M] () -- H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\PepperFlash\11.9.900.117\pepflashplayer.dll
MOD - [2013.10.09 20:16:37 | 000,425,984 | ---- | M] () -- H:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
MOD - [2013.10.09 20:16:29 | 000,262,144 | ---- | M] () -- H:\WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
MOD - [2013.10.03 08:03:05 | 000,415,184 | ---- | M] () -- H:\Programme\Google\Chrome\Application\30.0.1599.69\ppgooglenaclpluginchrome.dll
MOD - [2013.10.03 08:03:04 | 013,611,984 | ---- | M] () -- H:\Programme\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll
MOD - [2013.10.03 08:03:03 | 004,055,504 | ---- | M] () -- H:\Programme\Google\Chrome\Application\30.0.1599.69\pdf.dll
MOD - [2013.10.03 08:02:12 | 000,698,832 | ---- | M] () -- H:\Programme\Google\Chrome\Application\30.0.1599.69\libglesv2.dll
MOD - [2013.10.03 08:02:11 | 000,099,792 | ---- | M] () -- H:\Programme\Google\Chrome\Application\30.0.1599.69\libegl.dll
MOD - [2013.10.03 08:02:09 | 001,604,560 | ---- | M] () -- H:\Programme\Google\Chrome\Application\30.0.1599.69\ffmpegsumo.dll
MOD - [2013.09.25 07:19:41 | 000,485,384 | ---- | M] () -- H:\Programme\Movies Toolbar\SafetyNut\safetycrt.dll
MOD - [2013.09.25 07:19:32 | 000,018,952 | ---- | M] () -- H:\Programme\Movies Toolbar\SafetyNut\safetyldr.dll
MOD - [2013.08.15 20:07:52 | 000,998,400 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\cf3c9d1496acdcb836853e59fe20223b\System.Management.ni.dll
MOD - [2013.08.15 20:06:53 | 000,212,992 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\15fd2d2f4e709154b44187a6915db244\System.ServiceProcess.ni.dll
MOD - [2013.08.15 20:04:14 | 005,462,016 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\f93600ac836b9140e1df13bb0f6bfccf\System.Xml.ni.dll
MOD - [2013.08.15 20:02:36 | 007,977,984 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\10df39542df7d48462451fc39bce8418\System.ni.dll
MOD - [2013.07.10 20:08:21 | 011,497,984 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\b14359470744c840c59fbe4e58034fd6\mscorlib.ni.dll
MOD - [2013.04.23 20:12:56 | 000,213,048 | ---- | M] () -- H:\Programme\Vodafone-Sicherheitspaket\Spam Control\fsas.dll
MOD - [2011.11.02 00:26:32 | 000,087,912 | ---- | M] () -- H:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\zlib1.dll
MOD - [2011.11.02 00:26:12 | 001,242,472 | ---- | M] () -- H:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\libxml2.dll
MOD - [2011.06.09 18:51:47 | 000,030,888 | ---- | M] () -- H:\Programme\Vodafone-Sicherheitspaket\Anti-Virus\minifilter\hashlib_x86.dll
MOD - [2011.01.20 11:06:30 | 000,323,584 | ---- | M] () -- H:\Programme\NETGEAR\WNDA3100v2\WifiLib.dll
MOD - [2010.09.16 22:14:27 | 000,207,536 | ---- | M] () -- h:\Programme\Vodafone-Sicherheitspaket\DAAS2\daas2.dll
MOD - [2010.08.19 16:25:00 | 000,272,864 | ---- | M] () -- H:\Programme\NETGEAR\WNDA3100v2\WifiSvc.exe
MOD - [2009.08.05 17:59:02 | 000,001,536 | ---- | M] () -- H:\Programme\Vodafone-Sicherheitspaket\FSPC\fspcfsm.eng
MOD - [2009.08.05 17:58:30 | 000,236,128 | ---- | M] () -- \\?\h:\programme\vodafone-sicherheitspaket\hips\fsumi.dll
MOD - [2009.08.05 17:57:04 | 000,081,920 | ---- | M] () -- H:\Programme\Vodafone-Sicherheitspaket\FSGUI\strres.eng
MOD - [2009.08.05 17:56:56 | 000,920,160 | ---- | M] () -- H:\Programme\Vodafone-Sicherheitspaket\FSGUI\gres.dll
MOD - [2009.08.05 17:56:50 | 000,143,360 | ---- | M] () -- H:\Programme\Vodafone-Sicherheitspaket\FSGUI\flyerres.eng
MOD - [2009.08.05 17:56:50 | 000,045,056 | ---- | M] () -- H:\Programme\Vodafone-Sicherheitspaket\FSGUI\fsavures.eng
MOD - [2009.08.05 17:56:32 | 000,838,240 | ---- | M] () -- H:\Programme\Vodafone-Sicherheitspaket\FSGUI\about.dll
MOD - [2009.08.05 17:56:32 | 000,088,672 | ---- | M] () -- H:\Programme\Vodafone-Sicherheitspaket\FSGUI\aboutres.dll
MOD - [2009.08.05 17:56:08 | 000,036,864 | ---- | M] () -- H:\Programme\Vodafone-Sicherheitspaket\Anti-Virus\fsavhres.eng
MOD - [2008.04.14 14:00:00 | 000,014,336 | ---- | M] () -- H:\WINDOWS\system32\msdmo.dll
MOD - [2007.05.24 10:01:26 | 000,090,112 | ---- | M] () -- H:\Programme\AOL 9.0 VRa\components\Tier2Svc.dll
MOD - [2007.05.24 10:01:17 | 000,061,440 | ---- | M] () -- H:\Programme\AOL 9.0 VRa\components\DataSvcs.dll
MOD - [2007.05.24 03:49:40 | 000,131,072 | ---- | M] () -- h:\Programme\Gemeinsame Dateien\aol\1243281108\ee\services\proxyprovider\ver1_0_0_1\proxyprovider.dll
MOD - [2004.01.09 22:02:48 | 000,045,056 | ---- | M] () -- H:\Programme\AOL 9.0 VRa\zlib.dll
MOD - [2002.04.22 23:08:37 | 000,081,920 | ---- | M] () -- H:\Programme\AOL 9.0 VRa\xmltok.dll
MOD - [2002.04.22 23:08:27 | 000,053,248 | ---- | M] () -- H:\Programme\AOL 9.0 VRa\xmlparse.dll
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- H:\WINDOWS\system32\lxbxcoms.exe -- (lxbx_device)
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2013.10.09 20:27:48 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- H:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.09.25 07:19:30 | 003,419,144 | ---- | M] (SafetyNut Inc.) [Auto | Running] -- H:\Programme\Movies Toolbar\SafetyNut\SafetyNutManager.exe -- (SafetyNutManager)
SRV - [2013.07.10 21:28:16 | 000,109,064 | ---- | M] (Wajam) [Disabled | Stopped] -- H:\Programme\Wajam\Updater\WajamUpdater.exe -- (WajamUpdater)
SRV - [2013.06.06 19:00:39 | 000,060,352 | ---- | M] (F-Secure Corporation) [On_Demand | Running] -- H:\Programme\Vodafone-Sicherheitspaket\ORSP Client\fsorsp.exe -- (FSORSPClient)
SRV - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- H:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- H:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013.04.04 05:32:53 | 000,181,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- H:\Programme\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2013.02.05 17:48:00 | 000,235,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- H:\Programme\McAfee Security Scan\3.0.318\McCHSvc.exe -- (McComponentHostService)
SRV - [2012.12.21 16:27:46 | 000,057,008 | ---- | M] (Apple Inc.) [Auto | Running] -- H:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2012.11.09 12:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- H:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.10.02 13:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2011.07.20 06:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- H:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2011.07.07 19:31:08 | 000,195,336 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- H:\Programme\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011.06.15 17:33:20 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- H:\Programme\Microsoft\BingBar\SeaPort.EXE -- (BBUpdate)
SRV - [2010.09.16 22:14:05 | 000,522,848 | ---- | M] (F-Secure Corporation) [On_Demand | Running] -- H:\Programme\Vodafone-Sicherheitspaket\FWES\program\fsdfwd.exe -- (FSDFWD)
SRV - [2010.08.19 16:25:00 | 000,272,864 | ---- | M] () [Auto | Running] -- H:\Programme\NETGEAR\WNDA3100v2\WifiSvc.exe -- (WSWNDA3100)
SRV - [2009.10.07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- H:\Programme\Gemeinsame Dateien\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2009.09.11 13:33:54 | 000,009,216 | ---- | M] (Vodafone) [Auto | Running] -- H:\Programme\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
SRV - [2009.08.05 17:58:52 | 000,186,976 | ---- | M] (F-Secure Corporation) [Auto | Running] -- H:\Programme\Vodafone-Sicherheitspaket\Common\FSMA32.EXE -- (FSMA)
SRV - [2009.08.05 17:56:10 | 000,215,648 | ---- | M] (F-Secure Corporation) [Auto | Running] -- H:\Programme\Vodafone-Sicherheitspaket\Anti-Virus\fsgk32st.exe -- (F-Secure Gatekeeper Handler Starter)
SRV - [2006.10.26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- H:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2006.10.23 14:50:35 | 000,046,640 | R--- | M] (AOL LLC) [Auto | Running] -- H:\Programme\Gemeinsame Dateien\aol\acs\AOLacsd.exe -- (AOL ACS)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\Programme\CPUID\PC Wizard 2010\pcwiz_x32.sys -- (cpuz134)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2013.07.10 19:28:40 | 000,145,856 | ---- | M] (F-Secure Corporation) [Kernel | On_Demand | Running] -- H:\Programme\Vodafone-Sicherheitspaket\Anti-Virus\minifilter\fsgk.sys -- (F-Secure Gatekeeper)
DRV - [2013.07.09 13:58:32 | 000,208,600 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2013.06.25 18:42:38 | 005,467,352 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2013.05.06 18:01:17 | 000,082,120 | ---- | M] (F-Secure Corporation) [Kernel | Boot | Running] -- H:\WINDOWS\system32\drivers\fsdfw.sys -- (FSFW)
DRV - [2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- H:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.12.21 11:44:04 | 000,374,216 | R--- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2012.08.15 15:14:52 | 000,044,240 | ---- | M] () [Kernel | Boot | Running] -- H:\WINDOWS\system32\drivers\fsbts.sys -- (fsbts)
DRV - [2010.12.07 14:12:24 | 000,025,088 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\lgandmodem.sys -- (ANDModem)
DRV - [2010.12.07 14:12:24 | 000,020,096 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\lgandgps.sys -- (AndGps)
DRV - [2010.12.07 14:12:22 | 000,020,736 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\lganddiag.sys -- (AndDiag)
DRV - [2010.12.07 14:12:22 | 000,014,336 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\lgandbus.sys -- (Andbus)
DRV - [2010.10.21 09:45:18 | 000,025,216 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2010.10.21 09:45:16 | 000,020,864 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2010.10.21 09:45:16 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2010.10.06 13:25:40 | 001,024,768 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\bcmwlhigh5.sys -- (BCMH43XX)
DRV - [2010.04.09 02:30:28 | 000,168,040 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- H:\WINDOWS\system32\drivers\nvgts.sys -- (nvgts)
DRV - [2010.04.09 02:30:28 | 000,139,368 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- H:\WINDOWS\system32\drivers\nvrd32.sys -- (nvrd32)
DRV - [2010.03.22 18:29:08 | 000,018,944 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2010.03.04 18:02:10 | 000,013,824 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2010.03.04 18:02:08 | 000,070,912 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2010.02.03 12:20:32 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2009.11.18 07:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009.11.18 07:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2009.10.07 10:49:50 | 000,023,832 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\lvuvcflt.sys -- (FilterService)
DRV - [2009.10.07 10:49:38 | 006,756,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC)
DRV - [2009.10.07 10:47:54 | 000,266,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\lvrs.sys -- (LVRS)
DRV - [2009.10.07 01:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2009.09.29 08:11:22 | 000,012,160 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\lgbtport.sys -- (LgBttPort)
DRV - [2009.09.29 08:11:20 | 000,012,928 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\lgvmodem.sys -- (LGVMODEM)
DRV - [2009.09.29 08:11:20 | 000,010,496 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\lgbtbus.sys -- (lgbusenum)
DRV - [2009.08.05 17:58:30 | 000,068,064 | ---- | M] (F-Secure Corporation) [Kernel | System | Running] -- H:\Programme\Vodafone-Sicherheitspaket\HIPS\drivers\fshs.sys -- (F-Secure HIPS)
DRV - [2009.06.29 19:00:50 | 000,112,640 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2009.06.29 19:00:50 | 000,102,656 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\ewusbfake.sys -- (hwusbfake)
DRV - [2009.05.15 22:13:32 | 000,215,856 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Stopped] -- H:\WINDOWS\System32\drivers\3132R5C.sys -- (3132R5C)
DRV - [2009.05.07 02:01:00 | 000,440,832 | R--- | M] (AVM GmbH) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\fwlanusbn.sys -- (fwlanusbn)
DRV - [2009.05.07 02:01:00 | 000,004,352 | R--- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\avmeject.sys -- (avmeject)
DRV - [2009.04.09 14:38:30 | 000,102,400 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008.12.17 08:01:22 | 000,041,752 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2008.10.09 14:50:08 | 000,022,528 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Unknown] -- H:\WINDOWS\system32\drivers\BMLoad.sys -- (BMLoad)
DRV - [2008.10.09 14:50:04 | 000,018,816 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- H:\WINDOWS\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2007.06.01 17:28:54 | 000,215,856 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- H:\WINDOWS\system32\drivers\Si3132r5.sys -- (Si3132r5)
DRV - [2007.05.25 16:41:00 | 000,017,328 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- H:\WINDOWS\system32\drivers\SiWinAcc.sys -- (SiFilter)
DRV - [2007.05.25 16:40:58 | 000,012,464 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- H:\WINDOWS\system32\drivers\SiRemFil.sys -- (SiRemFil)
DRV - [2004.08.09 13:33:26 | 000,114,016 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- H:\WINDOWS\system32\drivers\prohlp02.sys -- (prohlp02)
DRV - [2004.08.09 13:29:28 | 000,053,920 | ---- | M] (Protection Technology) [Kernel | System | Running] -- H:\WINDOWS\system32\drivers\prodrv06.sys -- (prodrv06)
DRV - [2004.07.19 16:49:54 | 000,007,040 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- H:\WINDOWS\system32\drivers\prosync1.sys -- (prosync1)
DRV - [2003.12.01 17:20:52 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- H:\WINDOWS\system32\drivers\sfhlp01.sys -- (sfhlp01)
DRV - [2003.01.10 23:13:04 | 000,033,588 | R--- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw)
DRV - [2001.05.31 09:44:54 | 000,012,270 | ---- | M] (Palm, Inc.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\PalmUSBD.sys -- (PalmUSBD)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Google
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = about:newtab
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Google
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = Certified-Toolbar Search
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = Certified-Toolbar Search
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = about:newtab
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = about:newtab
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1380988289625&tguid=66920-6787-1380988289625-D95E0F96D31F896CB28C7B7BC6256991&q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1380988289625&tguid=66920-6787-1380988289625-D95E0F96D31F896CB28C7B7BC6256991&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Bing [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = about:newtab
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 12 E6 B7 4B 04 01 CB 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = Certified-Toolbar Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = Certified-Toolbar Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = about:newtab
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = about:newtab
IE - HKCU\..\URLSearchHook: {1CFFA392-0898-4b1c-89D1-6E98F9D8EF78} - No CLSID value found
IE - HKCU\..\URLSearchHook: {539F76FD-084E-4858-86D5-62F02F54AE86} - H:\Programme\Minibar\Minibar.dll (KangoExtensions)
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {B7A3A4B2-E1D7-424D-96AB-010E7ECD0B8B}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?FORM=VE3D01&q={searchTerms}&src={referrer:source?}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=119370&babsrc=SP_ss&mntrId=314159260000000000000022683bdf72
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=FFD7BBAB-78C1-493F-AD61-5ADAE5CAAE24&apn_sauid=64F8CDC8-1AC6-4520-B306-19E9DDCFB351
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GPEA_de
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.4&ts=1380988289625&tguid=66920-6787-1380988289625-D95E0F96D31F896CB28C7B7BC6256991&q={searchTerms}
IE - HKCU\..\SearchScopes\{B7A3A4B2-E1D7-424D-96AB-010E7ECD0B8B}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: H:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: H:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: H:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: H:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: H:\Programme\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: H:\Programme\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: H:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: H:\Programme\Virtual Earth 3D\ [2010.07.01 20:17:21 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: H:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: H:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: H:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: H:\Programme\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: H:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: H:\Programme\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\ [2009.11.16 19:04:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\litmus-ff@f-secure.com: H:\Programme\Vodafone-Sicherheitspaket\NRS\litmus-ff@f-secure.com [2013.09.17 13:35:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\quickprint@hp.com: H:\Programme\Hewlett-Packard\SmartPrint\QPExtension [2011.01.26 15:27:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: H:\Programme\IB Updater\Firefox
[2011.09.13 20:22:27 | 000,000,000 | ---D | M] (No name found) -- H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Mozilla\Extensions
[2012.12.12 22:11:22 | 000,000,000 | ---D | M] (No name found) -- H:\Programme\Mozilla Firefox\extensions
[2010.09.28 18:14:06 | 000,002,040 | ---- | M] () -- H:\Programme\mozilla firefox\searchplugins\fcmdSrchstonicde.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: Babylon Search
CHR - plugin: Shockwave Flash (Enabled) = H:\Programme\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = H:\Programme\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = H:\Programme\Google\Chrome\Application\30.0.1599.69\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = H:\Programme\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = H:\Programme\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = H:\Programme\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = H:\Programme\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = H:\Programme\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = H:\Programme\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = H:\Programme\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: Microsoft\u00C2\u00AE DRM (Enabled) = H:\Programme\Windows Media Player\npdrmv2.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = H:\Programme\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft\u00C2\u00AE DRM (Enabled) = H:\Programme\Windows Media Player\npwmsdrm.dll
CHR - plugin: RocketLife Secure Plug-In Layer (Enabled) = H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Visan\plugins\npRLSecurePluginLayer.dll
CHR - plugin: Google Earth Plugin (Enabled) = H:\Programme\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = H:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U21 (Enabled) = H:\Programme\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: McAfee Security Scanner + (Enabled) = H:\Programme\McAfee Security Scan\3.0.318\npMcAfeeMss.dll
CHR - plugin: Silverlight Plug-In (Enabled) = H:\Programme\Microsoft Silverlight\5.1.20513.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = H:\Programme\Microsoft\Office Live\npOLW.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = H:\Programme\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: iTunes Application Detector (Enabled) = H:\Programme\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = H:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = H:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - Extension: Movies Toolbar = H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\aaaaimdcedbpbcjjbbnfcbbjcngmomic\21.56058_0\
CHR - Extension: FoxyDeal = H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\aiennapmieppnpfhhogglccgepbdajan\6.2.0_0\
CHR - Extension: Google Docs = H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: HomeTab = H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\bddpogknpjlgfpbboediomaiiaecfajn\4.4_1\
CHR - Extension: YouTube = H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Wetter Europa = H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\gdjjeekgglojebicfpgmiaeaadnhfaol\4.2_0\
CHR - Extension: Cycling the Alps = H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\ihklobncbkangkiiamccfgnlihbmjhlh\4.9.1.0_0\
CHR - Extension: Wajam = H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\
CHR - Extension: WebEnhance = H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\mbegnhpbhfjiaelealfpieodkembdgbj\0.1_1\
CHR - Extension: Chrome In-App Payments service = H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0\
CHR - Extension: Google Mail = H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2008.04.14 14:00:00 | 000,000,820 | ---- | M]) - H:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - H:\Programme\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Plus-HD-3.8) - {11111111-1111-1111-1111-110311901130} - H:\Programme\Plus-HD-3.8\Plus-HD-3.8-bho.dll (Plus HD)
O2 - BHO: (HistoryTriggerBHO Class) - {21A88CB9-84D2-4020-A2D1-B25A21034884} - H:\Programme\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics)
O2 - BHO: (Movies Toolbar (Dist. by Somoto Ltd.)) - {3444c3c5-6c56-4a16-a453-832b05bf6ea4} - H:\Programme\Movies Toolbar\SafetyNut\SRTOOL~1\IE\searchresultsDx.dll ()
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - H:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - H:\Programme\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O2 - BHO: (WebEnhance) - {814664b0-d93b-4da6-9216-722c56179397} - H:\Programme\WebEnhance\webenhance.dll (WebEnhance)
O2 - BHO: (HomeTab) - {a25e7121-3dd8-41b3-855b-756c5bc45449} - H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\HomeTab\HomeTab.dll (Simply Tech Ltd.)
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - H:\Programme\Wajam\IE\priam_bho.dll (Wajam)
O2 - BHO: (MinibarBHO) - {AA74D58F-ACD0-450D-A85E-6C04B171C044} - H:\Programme\Minibar\Minibar.dll (KangoExtensions)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - H:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - H:\Programme\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
O2 - BHO: (FoxyDeal Plugin) - {C4B89A95-34DD-4206-A36F-AD64335A9D09} - H:\Programme\foxydeal\F0xy_D3al.dll (R&E Media GmbH)
O2 - BHO: (Browsing Protection Class) - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - H:\Programme\Vodafone-Sicherheitspaket\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - H:\Programme\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - H:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Browsing Protection Toolbar) - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - H:\Programme\Vodafone-Sicherheitspaket\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (Movies Toolbar (Dist. by Somoto Ltd.)) - {3444c3c5-6c56-4a16-a453-832b05bf6ea4} - H:\Programme\Movies Toolbar\SafetyNut\SRTOOL~1\IE\searchresultsDx.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - H:\Programme\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (HomeTab) - {a25e7121-3dd8-41b3-855b-756c5bc45449} - H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\HomeTab\HomeTab.dll (Simply Tech Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - H:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - H:\Programme\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - H:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - H:\Programme\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe ARM] H:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] H:\Programme\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AppleSyncNotifier] H:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [APSDaemon] H:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [B2C_AGENT] H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKLM..\Run: [F-Secure Manager] H:\Programme\Vodafone-Sicherheitspaket\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] H:\Programme\Vodafone-Sicherheitspaket\FSGUI\TNBUtil.exe (F-Secure Corporation)
O4 - HKLM..\Run: [HostManager] H:\Programme\Gemeinsame Dateien\aol\1243281108\ee\aolsoftware.exe (AOL LLC)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [NvCplDaemon] H:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] H:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVRaidService] H:\WINDOWS\system32\nvraidservice.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] H:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PDFPrint] H:\Programme\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [SunJavaUpdateSched] H:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Oracle Corporation)
O4 - HKCU..\Run: [AppsHat] H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\WebPlayer\AppsHat\WebPlayer.exe ()
O4 - HKCU..\Run: [HP Officejet 6600 (NET)] H:\Programme\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [HP Officejet 6600 (NET) #2] H:\Programme\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [LG LinkAir] File not found
O4 - Startup: H:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\McAfee Security Scan Plus.lnk = H:\Programme\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: H:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\WinZip Quick Pick.lnk = H:\Programme\WinZip\WZQKPICK32.EXE (WinZip Computing, S.L.)
O4 - Startup: H:\Dokumente und Einstellungen\Besitzer\Startmenü\Programme\Autostart\net.lnk = H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Windows Net Data\net.exe (Windows Net)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = FF 00 00 00 [binary data]
O8 - Extra context menu item: &AOL Toolbar-Suche - h:\Programme\AOL\AOL Toolbar 4.0\resources\de-DE\local\search.html ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O9 - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - H:\Programme\Hewlett-Packard\SmartPrint\smartprintsetup.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - H:\Programme\Hewlett-Packard\SmartPrint\smartprintsetup.exe (Hewlett-Packard)
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - H:\Programme\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - H:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Visit AppsHat.com - {AAA38851-3CFF-475F-B5E0-720D3645E4A5} - H:\Programme\Minibar\Minibar.dll (KangoExtensions)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - H:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab (GameHouse Games Player)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} hxxp://news.beograd.com/AxisCamControl.ocx (CamImage Class)
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game.zylom.com/activex/zylomgamesplayer.cab (Zylom Games Player)
O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} https://as.photoprintit.de/ips-opdata/layout/default_cms01/activex/IPSUploader4.cab (IPSUploader4 Control)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{98D7D9D2-1F2C-40AC-BD12-0292E3DD8438}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CAD7E670-0CEE-4F8E-8F4E-D968A50988AD}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - H:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - H:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - H:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - H:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - H:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - H:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (H:\DOKUME~1\ALLUSE~1\ANWEND~1\Wincert\WIN32C~1.DLL) - H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Wincert\win32cert.dll ()
O20 - AppInit_DLLs: (H:\PROGRA~1\MOVIES~1\SAFETY~1\SAFETY~2.DLL) - H:\Programme\Movies Toolbar\SafetyNut\safetyldr.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - H:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (H:\WINDOWS\system32\userinit.exe) - H:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: H:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O24 - Desktop BackupWallPaper: H:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O27 - HKLM IFEO\bitguard.exe: Debugger - File not found
O27 - HKLM IFEO\bprotect.exe: Debugger - File not found
O27 - HKLM IFEO\browsemngr.exe: Debugger - File not found
O27 - HKLM IFEO\browserdefender.exe: Debugger - File not found
O27 - HKLM IFEO\browsermngr.exe: Debugger - File not found
O27 - HKLM IFEO\browserprotect.exe: Debugger - File not found
O27 - HKLM IFEO\bundlesweetimsetup.exe: Debugger - File not found
O27 - HKLM IFEO\cltmngsvc.exe: Debugger - File not found
O27 - HKLM IFEO\delta babylon.exe: Debugger - File not found
O27 - HKLM IFEO\delta tb.exe: Debugger - File not found
O27 - HKLM IFEO\delta2.exe: Debugger - File not found
O27 - HKLM IFEO\deltainstaller.exe: Debugger - File not found
O27 - HKLM IFEO\deltasetup.exe: Debugger - File not found
O27 - HKLM IFEO\deltatb.exe: Debugger - File not found
O27 - HKLM IFEO\deltatb_2501-c733154b.exe: Debugger - File not found
O27 - HKLM IFEO\iminentsetup.exe: Debugger - File not found
O27 - HKLM IFEO\rjatydimofu.exe: Debugger - File not found
O27 - HKLM IFEO\sweetimsetup.exe: Debugger - File not found
O27 - HKLM IFEO\tbdelta.exetoolbar783881609.exe: Debugger - File not found
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{2ff97368-de35-11e0-a7da-001f3f08c25a}\Shell - "" = AutoRun
O33 - MountPoints2\{2ff97368-de35-11e0-a7da-001f3f08c25a}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2ff97368-de35-11e0-a7da-001f3f08c25a}\Shell\AutoRun\command - "" = K:\autorun.exe
O33 - MountPoints2\{44ba61b9-f603-11de-a4d4-0022683bdf72}\Shell - "" = AutoRun
O33 - MountPoints2\{44ba61b9-f603-11de-a4d4-0022683bdf72}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{44ba61b9-f603-11de-a4d4-0022683bdf72}\Shell\AutoRun\command - "" = I:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{9308fd32-d2d1-11de-a484-0022683bdf72}\Shell - "" = AutoRun
O33 - MountPoints2\{9308fd32-d2d1-11de-a484-0022683bdf72}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9308fd32-d2d1-11de-a484-0022683bdf72}\Shell\AutoRun\command - "" = I:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{9308fd33-d2d1-11de-a484-0022683bdf72}\Shell - "" = AutoRun
O33 - MountPoints2\{9308fd33-d2d1-11de-a484-0022683bdf72}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9308fd33-d2d1-11de-a484-0022683bdf72}\Shell\AutoRun\command - "" = K:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O36 - AppCertDlls: x64 - (h:\programme\movies toolbar\safetynut\x64\safetycrt.dll) - File not found
O36 - AppCertDlls: x86 - (H:\Programme\Movies Toolbar\SafetyNut\safetycrt.dll) - H:\Programme\Movies Toolbar\SafetyNut\safetycrt.dll ()
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.10.09 19:58:31 | 000,000,000 | ---D | C] -- H:\FRST
[2013.10.09 19:50:31 | 000,025,088 | ---- | C] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\hidparse.sys
[2013.10.09 19:48:12 | 000,005,376 | ---- | C] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\usbd.sys
[2013.10.09 19:48:11 | 000,144,128 | ---- | C] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\usbport.sys
[2013.10.09 19:48:11 | 000,030,336 | ---- | C] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\usbehci.sys
[2013.10.08 20:54:00 | 000,000,000 | RH-D | C] -- H:\Dokumente und Einstellungen\Besitzer\Recent
[2013.10.07 20:12:09 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Malwarebytes
[2013.10.07 20:12:06 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2013.10.07 20:12:05 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2013.10.07 20:12:03 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- H:\WINDOWS\System32\drivers\mbam.sys
[2013.10.07 20:12:03 | 000,000,000 | ---D | C] -- H:\Programme\Malwarebytes' Anti-Malware
[2013.10.06 11:10:51 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\AppData
[2013.10.06 11:09:53 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Minibar
[2013.10.06 11:09:35 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\HomeTab
[2013.10.05 19:03:53 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\ElevatedDiagnostics
[2013.10.05 19:03:31 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Windows PowerShell 1.0
[2013.10.05 19:03:22 | 000,000,000 | ---D | C] -- H:\WINDOWS\System32\windowspowershell
[2013.10.05 18:26:15 | 000,000,000 | ---D | C] -- H:\WINDOWS\System32\sda
[2013.10.05 18:26:10 | 000,208,600 | ---- | C] (Realtek Semiconductor Corp.) -- H:\WINDOWS\System32\drivers\RtsUStor.sys
[2013.10.05 18:26:09 | 009,888,840 | ---- | C] (Realtek Semiconductor Corp.) -- H:\WINDOWS\System32\RtsUStoricon.dll
[2013.10.05 18:21:54 | 000,359,016 | ---- | C] (Realtek Semiconductor Crop.) -- H:\WINDOWS\vncutil.exe
[2013.10.05 18:21:53 | 000,129,640 | ---- | C] (Realtek Semiconductor) -- H:\WINDOWS\RtkAudioService.exe
[2013.10.05 18:21:53 | 000,085,208 | ---- | C] (Realtek Semiconductor Corp.) -- H:\WINDOWS\System32\RtkCoInstIIXP.dll
[2013.10.05 18:21:53 | 000,011,368 | ---- | C] (Realtek Semiconductor Corp.) -- H:\WINDOWS\System32\RtkCoLDRXP.dll
[2013.10.05 18:21:51 | 001,395,800 | ---- | C] (Creative Technology Ltd.) -- H:\WINDOWS\System32\drivers\Monfilt.sys
[2013.10.05 18:21:49 | 001,691,480 | ---- | C] (Creative) -- H:\WINDOWS\System32\drivers\Ambfilt.sys
[2013.10.05 18:21:49 | 000,000,000 | ---D | C] -- H:\Programme\Realtek
[2013.10.05 18:21:45 | 002,080,472 | ---- | C] (Realtek Semiconductor Corp.) -- H:\WINDOWS\RtlExUpd.dll
[2013.10.05 18:20:43 | 000,374,216 | R--- | C] (Alps Electric Co., Ltd.) -- H:\WINDOWS\System32\drivers\Apfiltr.sys
[2013.10.05 18:20:43 | 000,121,392 | R--- | C] (Alps Electric Co., Ltd.) -- H:\WINDOWS\System32\Vxdif.dll
[2013.10.05 18:20:43 | 000,000,000 | ---D | C] -- H:\Programme\DellTPad
[2013.10.05 18:17:30 | 000,755,200 | ---- | C] (NVIDIA Corporation) -- H:\WINDOWS\System32\cohelper.dll
[2013.10.05 18:17:16 | 000,000,000 | ---D | C] -- H:\Programme\NVIDIA Corporation
[2013.10.05 17:53:14 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\Freemium Driver Utilities
[2013.10.05 17:53:13 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DriversGalaxy
[2013.10.05 17:52:47 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Windows Net Data
[2013.10.05 17:52:30 | 000,000,000 | ---D | C] -- H:\Programme\Plus-HD-3.8
[2013.10.05 17:52:02 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Startmenü\Programme\HomeTab
[2013.10.05 17:52:01 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\SimplyTech
[2013.10.05 17:51:59 | 000,000,000 | ---D | C] -- H:\Programme\HomeTab
[2013.10.05 17:51:59 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\HomeTab
[2013.10.05 17:51:29 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\SimplyTech
[2013.10.05 17:51:18 | 000,000,000 | ---D | C] -- H:\Programme\SoftwareUpdater
[2013.10.05 17:51:18 | 000,000,000 | ---D | C] -- H:\Programme\Covus Freemium
[2013.10.05 17:51:18 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Covus Freemium
[2013.10.05 17:51:03 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\GutscheinCodes
[2013.10.05 17:51:02 | 000,000,000 | ---D | C] -- H:\Programme\WebEnhance
[2013.10.05 17:50:56 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Package Cache
[2013.10.05 17:49:59 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\DownloadGuide
[2013.10.04 22:05:38 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\AppsHat Mobile Apps
[2013.10.04 22:05:38 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Startmenü\Programme\AppsHat
[2013.10.04 22:05:37 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\WebPlayer
[2013.10.04 22:05:36 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Local Settings
[2013.10.04 22:05:25 | 000,000,000 | ---D | C] -- H:\Programme\Minibar
[2013.10.04 22:05:25 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Minibar
[2013.10.04 22:04:28 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Startmenü\Programme\Wajam
[2013.10.04 22:04:28 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\Wajam
[2013.10.04 22:04:26 | 000,000,000 | ---D | C] -- H:\Programme\Wajam
[2013.10.04 22:03:56 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Wincert
[2013.10.04 22:03:47 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\somotomoviestoolbar1
[2013.10.04 22:03:41 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\somotomoviestoolbar1
[2013.10.04 22:03:33 | 000,000,000 | ---D | C] -- H:\Programme\Movies Toolbar
[2013.10.04 22:03:32 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SafetyNut
[2013.09.29 17:28:27 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\Urlaub 2013
[2013.09.22 14:22:28 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\IPhone Bilder
[2013.09.21 12:47:27 | 000,000,000 | ---D | C] -- H:\Programme\Microsoft.NET
[2013.09.21 12:46:16 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\SIEN SA
[2013.09.21 12:46:07 | 000,000,000 | ---D | C] -- H:\Programme\IminentToolbar
[2013.09.21 12:46:04 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\iminent
[2013.09.21 12:45:20 | 000,000,000 | ---D | C] -- H:\Programme\foxydeal
[2013.09.21 12:43:19 | 041,404,760 | ---- | C] (Apple Inc.) -- H:\Dokumente und Einstellungen\Besitzer\Desktop\QuickTimeInstaller.exe
[2010.01.29 23:43:12 | 001,162,240 | ---- | C] (Roedel) -- H:\Programme\DTB2006.exe
[2009.10.19 18:00:41 | 036,502,448 | ---- | C] (Lexmark International, Inc. ) -- H:\Programme\cjb7100GE.exe
[2009.10.12 20:37:44 | 033,944,496 | ---- | C] (Logitech Inc. ) -- H:\Programme\qc848deu.exe
[3 H:\WINDOWS\*.tmp files -> H:\WINDOWS\*.tmp -> ]
[1 H:\WINDOWS\System32\*.tmp files -> H:\WINDOWS\System32\*.tmp -> ]
[1 H:\Programme\*.tmp files -> H:\Programme\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2099.11.04 14:46:24 | 000,000,424 | -H-- | M] () -- H:\WINDOWS\tasks\User_Feed_Synchronization-{C67C429B-868F-4674-B6ED-36C07B2BD3E2}.job
[2013.10.09 20:47:00 | 000,001,090 | ---- | M] () -- H:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013.10.09 20:47:00 | 000,001,086 | ---- | M] () -- H:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013.10.09 20:40:19 | 000,000,440 | ---- | M] () -- H:\WINDOWS\tasks\At2.job
[2013.10.09 20:39:39 | 000,229,488 | ---- | M] () -- H:\WINDOWS\System32\NvApps.xml
[2013.10.09 20:39:34 | 000,002,048 | --S- | M] () -- H:\WINDOWS\bootstat.dat
[2013.10.09 20:39:32 | 000,199,344 | ---- | M] () -- H:\WINDOWS\System32\FNTCACHE.DAT
[2013.10.09 20:39:27 | 000,000,000 | ---- | M] () -- H:\WINDOWS\System32\drivers\lvuvc.hs
[2013.10.09 20:39:24 | 000,000,000 | ---- | M] () -- H:\WINDOWS\System32\drivers\logiflt.iad
[2013.10.09 20:38:20 | 000,000,498 | ---- | M] () -- H:\WINDOWS\tasks\HP Photo Creations Communicator.job
[2013.10.09 20:29:00 | 000,000,440 | ---- | M] () -- H:\WINDOWS\tasks\At3.job
[2013.10.09 20:27:49 | 000,000,884 | ---- | M] () -- H:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013.10.09 20:27:46 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- H:\WINDOWS\System32\FlashPlayerApp.exe
[2013.10.09 20:27:46 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- H:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013.10.09 20:16:48 | 000,546,132 | ---- | M] () -- H:\WINDOWS\System32\perfh007.dat
[2013.10.09 20:16:48 | 000,518,992 | ---- | M] () -- H:\WINDOWS\System32\perfh009.dat
[2013.10.09 20:16:48 | 000,114,446 | ---- | M] () -- H:\WINDOWS\System32\perfc007.dat
[2013.10.09 20:16:48 | 000,095,692 | ---- | M] () -- H:\WINDOWS\System32\perfc009.dat
[2013.10.09 20:14:02 | 000,001,374 | ---- | M] () -- H:\WINDOWS\imsins.BAK
[2013.10.09 19:47:02 | 000,000,530 | ---- | M] () -- H:\WINDOWS\tasks\Scheduled scanning task.job
[2013.10.07 22:44:46 | 000,060,928 | ---- | M] () -- H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.10.07 20:12:06 | 000,000,756 | ---- | M] () -- H:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013.10.07 19:29:36 | 000,013,646 | ---- | M] () -- H:\WINDOWS\System32\wpa.dbl
[2013.10.06 23:52:17 | 000,000,366 | ---- | M] () -- H:\WINDOWS\tasks\Browser Updater.job
[2013.10.06 23:52:02 | 000,001,870 | ---- | M] () -- H:\WINDOWS\tasks\Plus-HD-3.8-chromeinstaller.job
[2013.10.06 23:52:01 | 000,001,276 | ---- | M] () -- H:\WINDOWS\tasks\Plus-HD-3.8-updater.job
[2013.10.06 23:52:01 | 000,001,182 | ---- | M] () -- H:\WINDOWS\tasks\Plus-HD-3.8-codedownloader.job
[2013.10.06 23:52:01 | 000,001,080 | ---- | M] () -- H:\WINDOWS\tasks\Plus-HD-3.8-enabler.job
[2013.10.06 14:00:00 | 000,000,440 | ---- | M] () -- H:\WINDOWS\tasks\At4.job
[2013.10.05 22:51:06 | 000,001,777 | ---- | M] () -- H:\Dokumente und Einstellungen\All Users\Desktop\Google Chrome.lnk
[2013.10.05 18:41:17 | 000,394,034 | ---- | M] () -- H:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\Ernährungstagebuch -September2013.pdf
[2013.10.05 18:20:46 | 000,000,000 | -H-- | M] () -- H:\WINDOWS\System32\drivers\Msft_Kernel_Apfiltr_01009.Wdf
[2013.10.05 17:53:14 | 000,000,334 | ---- | M] () -- H:\WINDOWS\tasks\FreeDriverScout.job
[2013.10.05 17:53:10 | 000,002,409 | ---- | M] () -- H:\Dokumente und Einstellungen\All Users\Desktop\Free Driver Scout.lnk
[2013.10.05 17:52:51 | 000,001,795 | ---- | M] () -- H:\Dokumente und Einstellungen\Besitzer\Startmenü\Programme\Autostart\net.lnk
[2013.10.05 17:52:07 | 000,000,276 | ---- | M] () -- H:\WINDOWS\tasks\Protected Search.job
[2013.10.04 22:05:38 | 000,002,266 | ---- | M] () -- H:\Dokumente und Einstellungen\Besitzer\Desktop\AppsHat.lnk
[2013.10.04 01:45:53 | 000,000,139 | ---- | M] () -- H:\error.fstmp
[2013.10.04 01:35:42 | 000,000,000 | ---- | M] () -- H:\infect.fstmp
[2013.09.30 19:10:43 | 000,023,948 | ---- | M] () -- H:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\cc_20130930_191036.reg
[2013.09.29 21:46:30 | 000,959,386 | ---- | M] () -- H:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\Fußgängerroute mit dem Ziel Ancona, Italien - Google Maps.pdf
[2013.09.23 23:36:50 | 000,174,592 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\ie4uinit.exe
[2013.09.23 23:36:50 | 000,174,592 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\ie4uinit.exe
[2013.09.23 20:23:39 | 001,215,488 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\urlmon.dll
[2013.09.23 20:23:39 | 000,920,064 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\wininet.dll
[2013.09.23 20:23:39 | 000,759,296 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\vgx.dll
[2013.09.23 20:23:38 | 006,017,536 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\mshtml.dll
[2013.09.23 20:23:38 | 000,611,840 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\mstime.dll
[2013.09.23 20:23:38 | 000,611,840 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\mstime.dll
[2013.09.23 20:23:38 | 000,206,848 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\occache.dll
[2013.09.23 20:23:38 | 000,105,984 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\url.dll
[2013.09.23 20:23:38 | 000,105,984 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\url.dll
[2013.09.23 20:23:38 | 000,067,072 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\mshtmled.dll
[2013.09.23 20:23:37 | 002,006,016 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\iertutil.dll
[2013.09.23 20:23:37 | 001,469,440 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\inetcpl.cpl
[2013.09.23 20:23:37 | 001,469,440 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\inetcpl.cpl
[2013.09.23 20:23:37 | 000,630,272 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\msfeeds.dll
[2013.09.23 20:23:37 | 000,630,272 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\msfeeds.dll
[2013.09.23 20:23:37 | 000,522,240 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\jsdbgui.dll
[2013.09.23 20:23:37 | 000,055,296 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\msfeedsbs.dll
[2013.09.23 20:23:37 | 000,055,296 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2013.09.23 20:23:37 | 000,043,520 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\licmgr10.dll
[2013.09.23 20:23:37 | 000,043,520 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\licmgr10.dll
[2013.09.23 20:23:37 | 000,025,600 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\jsproxy.dll
[2013.09.23 20:23:37 | 000,025,600 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\jsproxy.dll
[2013.09.23 20:23:36 | 011,113,472 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\ieframe.dll
[2013.09.23 20:23:36 | 000,184,320 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\iepeers.dll
[2013.09.23 20:23:36 | 000,184,320 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\iepeers.dll
[2013.09.23 20:23:35 | 000,743,424 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\iedvtool.dll
[2013.09.23 20:23:35 | 000,387,584 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\iedkcs32.dll
[2013.09.23 20:23:35 | 000,387,584 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\iedkcs32.dll
[2013.09.23 20:23:35 | 000,018,944 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\dllcache\corpol.dll
[2013.09.23 20:23:35 | 000,018,944 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\corpol.dll
[2013.09.23 20:06:48 | 000,385,024 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\html.iec
[2013.09.21 22:54:47 | 000,000,838 | ---- | M] () -- H:\WINDOWS\System32\InstallUtil.InstallLog
[2013.09.21 12:45:03 | 000,001,584 | ---- | M] () -- H:\Dokumente und Einstellungen\All Users\Desktop\QuickTime Player.lnk
[2013.09.21 12:44:17 | 041,404,760 | ---- | M] (Apple Inc.) -- H:\Dokumente und Einstellungen\Besitzer\Desktop\QuickTimeInstaller.exe
[3 H:\WINDOWS\*.tmp files -> H:\WINDOWS\*.tmp -> ]
[1 H:\WINDOWS\System32\*.tmp files -> H:\WINDOWS\System32\*.tmp -> ]
[1 H:\Programme\*.tmp files -> H:\Programme\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.10.09 20:05:30 | 000,001,374 | ---- | C] () -- H:\WINDOWS\imsins.BAK
[2013.10.07 20:12:06 | 000,000,756 | ---- | C] () -- H:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013.10.05 18:41:17 | 000,394,034 | ---- | C] () -- H:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\Ernährungstagebuch -September2013.pdf
[2013.10.05 18:21:57 | 000,001,332 | ---- | C] () -- H:\WINDOWS\System32\drivers\DTSU2P.DAT
[2013.10.05 18:21:51 | 000,025,816 | ---- | C] () -- H:\WINDOWS\System32\drivers\RTAIODAT.DAT
[2013.10.05 18:20:46 | 000,000,000 | -H-- | C] () -- H:\WINDOWS\System32\drivers\Msft_Kernel_Apfiltr_01009.Wdf
[2013.10.05 17:53:13 | 000,000,334 | ---- | C] () -- H:\WINDOWS\tasks\FreeDriverScout.job
[2013.10.05 17:52:51 | 000,001,795 | ---- | C] () -- H:\Dokumente und Einstellungen\Besitzer\Startmenü\Programme\Autostart\net.lnk
[2013.10.05 17:52:44 | 000,001,276 | ---- | C] () -- H:\WINDOWS\tasks\Plus-HD-3.8-updater.job
[2013.10.05 17:52:42 | 000,001,080 | ---- | C] () -- H:\WINDOWS\tasks\Plus-HD-3.8-enabler.job
[2013.10.05 17:52:40 | 000,001,182 | ---- | C] () -- H:\WINDOWS\tasks\Plus-HD-3.8-codedownloader.job
[2013.10.05 17:52:31 | 000,001,870 | ---- | C] () -- H:\WINDOWS\tasks\Plus-HD-3.8-chromeinstaller.job
[2013.10.05 17:52:09 | 000,000,366 | ---- | C] () -- H:\WINDOWS\tasks\Browser Updater.job
[2013.10.05 17:52:06 | 000,000,276 | ---- | C] () -- H:\WINDOWS\tasks\Protected Search.job
[2013.10.05 17:52:00 | 000,032,328 | ---- | C] () -- H:\WINDOWS\Launcher.exe
[2013.10.05 17:51:18 | 000,002,409 | ---- | C] () -- H:\Dokumente und Einstellungen\All Users\Desktop\Free Driver Scout.lnk
[2013.10.04 22:05:38 | 000,002,266 | ---- | C] () -- H:\Dokumente und Einstellungen\Besitzer\Desktop\AppsHat.lnk
[2013.09.30 19:10:40 | 000,023,948 | ---- | C] () -- H:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\cc_20130930_191036.reg
[2013.09.29 21:46:30 | 000,959,386 | ---- | C] () -- H:\Dokumente und Einstellungen\Besitzer\Eigene Dateien\Fußgängerroute mit dem Ziel Ancona, Italien - Google Maps.pdf
[2013.09.21 21:06:51 | 000,179,350 | ---- | C] () -- H:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-S-1-5-21-448539723-839522115-1177238915-1003-0.dat
[2013.09.21 21:06:50 | 000,179,350 | ---- | C] () -- H:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-System.dat
[2013.09.21 13:10:32 | 000,000,838 | ---- | C] () -- H:\WINDOWS\System32\InstallUtil.InstallLog
[2013.09.21 12:45:03 | 000,001,584 | ---- | C] () -- H:\Dokumente und Einstellungen\All Users\Desktop\QuickTime Player.lnk
[2012.11.17 21:27:18 | 000,000,057 | ---- | C] () -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ament.ini
[2012.02.19 00:22:13 | 000,053,299 | ---- | C] () -- H:\WINDOWS\System32\pthreadVC.dll
[2012.01.22 12:41:25 | 000,053,248 | ---- | C] () -- H:\WINDOWS\System32\CommonDL.dll
[2012.01.22 12:41:25 | 000,002,413 | ---- | C] () -- H:\WINDOWS\System32\lgAxconfig.ini
[2010.02.18 18:53:57 | 000,000,141 | ---- | C] () -- H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2010.01.29 23:43:12 | 000,156,921 | ---- | C] () -- H:\Programme\DTB_DTB.dbf
[2010.01.29 23:43:12 | 000,045,056 | ---- | C] () -- H:\Programme\NRGNAME.NDX
[2010.01.29 23:43:12 | 000,034,908 | ---- | C] () -- H:\Programme\DTB_NRG.dbf
[2010.01.29 23:43:12 | 000,013,312 | ---- | C] () -- H:\Programme\AKTNAME.NDX
[2010.01.29 23:43:12 | 000,007,416 | ---- | C] () -- H:\Programme\DTB_AKT.dbf
[2010.01.29 23:43:12 | 000,006,384 | ---- | C] () -- H:\Programme\DTB_XTB.dbf
[2010.01.29 23:43:12 | 000,001,625 | ---- | C] () -- H:\Programme\DTB_REG.dbf
[2010.01.29 23:43:12 | 000,000,500 | ---- | C] () -- H:\Programme\DTB_NTB.dbf
[2010.01.29 23:43:12 | 000,000,162 | ---- | C] () -- H:\Programme\DTB_FTB.dbf
[2009.11.23 16:46:41 | 005,327,380 | ---- | C] () -- H:\Programme\Handbuch_Designer20.pdf
[2009.11.23 16:42:28 | 005,327,380 | ---- | C] () -- H:\Programme\Handbuch_Designer20 fotobuch.pdf
[2009.10.19 18:04:03 | 032,077,824 | ---- | C] () -- H:\Programme\FXH7100AL.exe
[2009.09.30 19:16:20 | 000,000,760 | ---- | C] () -- H:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\setup_ldm.iss
[2009.06.24 18:05:46 | 000,060,928 | ---- | C] () -- H:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.06.16 14:25:02 | 000,121,512 | R--- | C] () -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DeviceManager.xml.rc4
[2009.05.28 22:33:30 | 000,579,720 | ---- | C] () -- H:\Programme\Atlantis2.exe
[2009.05.25 22:47:03 | 009,055,249 | ---- | C] () -- H:\Programme\CCU_DE_4_3_38_1.exe
========== ZeroAccess Check ==========
[2009.11.16 19:03:19 | 000,000,227 | RHS- | M] () -- H:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2009.03.03 01:10:15 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = H:\WINDOWS\system32\wbem\fastprox.dll -- [2009.02.09 12:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = H:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 14:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Alternate Data Streams ==========
@Alternate Data Stream - 143 bytes -> H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:C3A4217C
< End of report > --- --- ---
Ich hoffe, es ist okay so
Jacky65 |