haislbauer | 19.01.2014 17:46 | Firefox, doppelt unterstrichene grüne Werbelinks, popup-Werbefenster öffnen automatisch Hallo zusammen,
ich habe gerade Eure Beiträge durchgestöbert und bemerkt, dass schon mehrere Nutzer mein Problem hatten: im Firefox werden beliebige Wörter einer Webseite doppelt grün und führen zu Werbelinks. Auch öffnen sich automatisch popup-Werbefenster. Woher ich diesen Virus habe, weiß ich nicht.
Ich habe gelesen, dass man zuerst mal einen FRST-Scan machen sollte. Das habe ich bereits gemacht und die beiden Codes angefügt.
Vielen Dank für Eure Hilfe. Ich bin neu hier, darum schon mal danke für Eurer Verständnis, wenn nicht gleich alles so gut klappt bei mir.
Anhang:
FRST.txt Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-01-2014 02
Ran by LEHNER24 (ATTENTION: The logged in user is not administrator) on SC4683 on 19-01-2014 17:29:02
Running from C:\Users\LEHNER24\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(Novell, Inc.) C:\Program Files (x86)\Novell\ZENworks\bin\ZenUserDaemon.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Novell, Inc.) C:\Program Files (x86)\Novell\ZENworks\esm\ZESUser.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe
() C:\Windows\System32\nwtray.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(NTeWORKS) C:\Program Files (x86)\PicPick\picpick.exe
(Updater) C:\ProgramData\Updater\updater.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Novell, Inc.) C:\Program Files (x86)\Novell\ZENworks\bin\ZenNotifyIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(WatchDog) C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe
(WatchDog) C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe
(WatchDog) C:\ProgramData\RHelpers\IeHelper\IeHelper.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Dropbox, Inc.) C:\Users\LEHNER24\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe
(Mozilla Corporation) C:\Users\LEHNER24\AppData\Local\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Users\LEHNER24\AppData\Local\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavMain.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavProgress.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-02-13] (IDT, Inc.)
HKLM\...\Run: [IntelPROSet] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [4756240 2012-03-29] (Intel(R) Corporation)
HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [626552 2012-01-25] (Alps Electric Co., Ltd.)
HKLM\...\Run: [DFEPApplication] - C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe [7078424 2012-05-08] (Dell Inc.)
HKLM\...\Run: [NWTRAY] - C:\Windows\system32\NWTRAY.EXE [38016 2012-07-13] ()
HKLM\...\Run: [nwiz] - C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2747680 2013-12-04] ()
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM-x32\...\Run: [ZenNotifyIcon] - C:\Program Files (x86)\Novell\Zenworks\bin\ZenNotifyIcon.exe [303104 2012-03-01] (Novell, Inc.)
HKLM-x32\...\Run: [NalView] - C:\Program Files (x86)\Novell\ZENworks\bin\nalview.exe [57344 2012-03-01] (Novell, Inc.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation)
HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] - C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [929272 2013-07-17] (Sophos Limited)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1075296 2013-04-25] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-05] (Adobe Systems Inc.)
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKLM-x32\...\Run: [Updater] - C:\ProgramData\Updater\Updater.exe [486264 2013-12-18] (Updater)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LCredMgr: C:\Program Files\Novell\CASA\bin\lcredmgr.dll ()
HKCU\...\Run: [PicPick Start] - C:\Program Files (x86)\PicPick\picpick.exe [11438576 2012-12-21] (NTeWORKS)
HKCU\...\Run: [Luraklp] - C:\Users\LEHNER24\AppData\Roaming\WMSPDMODC.dll [460800 2013-08-12] ()
HKCU\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [486264 2013-12-18] (Updater)
HKCU\...\Run: [AdobeBridge] - [x]
HKCU\...\Run: [NextLive] - C:\Users\Administrator\AppData\Roaming\newnext.me\nengine.dll [1283584 2013-11-14] (NewNextDotMe)
HKCU\...\Policies\Explorer: [NoOnlinePrintsWizard] 1
HKCU\...\Policies\Explorer: [NoPublishingWizard] 1
HKCU\...\Policies\Explorer: [NoStartMenuMyGames] 1
MountPoints2: {e2b7429c-6003-11e3-a087-74e543508e02} - E:\GoWire\MPLauncher.exe
MountPoints2: {e2b742b1-6003-11e3-a087-74e543508e02} - E:\GoWire\MPLauncher.exe
AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL,C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [184048 2013-12-04] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL,C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156256 2013-12-04] (NVIDIA Corporation)
Lsa: [Authentication Packages] msv1_0 ZenV1_0 ncv1_0
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
Startup: C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\LEHNER24\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.uni-passau.de
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.uni-passau.de
URLSearchHook: HKCU - (No Name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File
SearchScopes: HKLM - DefaultScope {60D4D856-18A4-4E6D-9069-F9653AFD4CEA} URL = hxxp://websearch.uni-passau.de/cgi-bin/search.cgi?q={searchTerms}&wm=beg
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {60D4D856-18A4-4E6D-9069-F9653AFD4CEA} URL = hxxp://websearch.uni-passau.de/cgi-bin/search.cgi?q={searchTerms}&wm=beg
SearchScopes: HKLM-x32 - DefaultScope {60D4D856-18A4-4E6D-9069-F9653AFD4CEA} URL = hxxp://websearch.uni-passau.de/cgi-bin/search.cgi?q={searchTerms}&wm=beg
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {60D4D856-18A4-4E6D-9069-F9653AFD4CEA} URL = hxxp://websearch.uni-passau.de/cgi-bin/search.cgi?q={searchTerms}&wm=beg
SearchScopes: HKCU - DefaultScope {9E30C1EF-B8CF-4F7C-A5F8-2044152B4018} URL = hxxp://websearch.uni-passau.de/cgi-bin/search.cgi?q={searchTerms}&wm=beg
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=6A7774E543508E02&affID=119357&tsp=5023
SearchScopes: HKCU - {51398DED-6795-403D-A22D-521C8C22EF16} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=6a77d9b9000000000000000000000000&r=494
SearchScopes: HKCU - {6B259D3B-639A-4360-BCEA-C2C5C4C8AAA5} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {85D9DFED-88CB-4362-B1D7-D01C3D5DE5B1} URL = hxxp://de.wikipedia.org/w/index.php?title=Spezial:Suche&search={searchTerms}
SearchScopes: HKCU - {9E30C1EF-B8CF-4F7C-A5F8-2044152B4018} URL = hxxp://websearch.uni-passau.de/cgi-bin/search.cgi?q={searchTerms}&wm=beg
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office 2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 2010\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: flash-Enhancer - {5A60B6BB-FA81-4EFA-AB9C-A820E2143736} - C:\Program Files (x86)\AmiExt\flashEnhancer\ie\AmiBho.dll ()
BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: No Name - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
ShellExecuteHooks: Softwareverteilung - {763370C4-268E-4308-A60C-D8DA0342BE32} - C:\Program Files (x86)\Novell\ZENworks\bin\NalShell.dll [1427968 2012-03-01] (Novell, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{E25765CE-165D-433D-8786-F1207CE512D2}: [NameServer]62.109.121.1 62.109.121.2
FireFox:
========
FF ProfilePath: C:\Users\LEHNER24\AppData\Roaming\Mozilla\Firefox\Profiles\2ape5dn6.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems)
FF Plugin HKCU: @lightspark.github.com/Lightspark;version=1 - C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll No File
FF HKLM\...\Firefox\Extensions: [{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}] - C:\Program Files\V-bates\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}] - C:\Program Files\V-bates\Firefox
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-12-20]
FF HKLM-x32\...\Firefox\Extensions: [ext@flash-Enhancer.com] - C:\Program Files (x86)\AmiExt\flashEnhancer\ff
FF Extension: flash-Enhancer - C:\Program Files (x86)\AmiExt\flashEnhancer\ff [2014-01-03]
==================== Services (Whitelisted) =================
R2 DFEPService; C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2279960 2012-05-08] (Dell Inc.)
R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-11-08] (Ellora Assets Corp.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-28] (Intel Corporation)
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office 2010\Office14\GROOVE.EXE [50921648 2013-03-09] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-03-29] ()
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 Novell Identity Store; C:\Program Files (x86)\Novell\CASA\bin\micasad.exe [249856 2012-01-06] (Novell, Inc)
R2 Novell ZENworks Agent Service; C:\Program Files (x86)\Novell\ZENworks\bin\ZenworksWindowsService.exe [28672 2012-03-01] (Novell, Inc.)
S2 Novell ZENworks Image-Safe Data Service; C:\Program Files (x86)\Novell\ZENworks\bin\preboot\novell-zisdservice.exe [90112 2012-03-01] ()
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 O2FLASH; C:\Windows\system32\o2flash.exe [244328 2011-11-16] (O2Micro International)
R2 O2SDIOAssist; C:\Windows\SysWOW64\srvany.exe [8192 2003-04-18] ()
S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [14848 2011-12-15] ()
R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [290296 2013-10-21] (Sophos Limited)
R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [206328 2013-10-21] (Sophos Limited)
R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [237048 2013-07-17] (Sophos Limited)
R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [357400 2012-09-17] (Sophos Limited)
R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [3109880 2013-10-21] (Sophos Limited)
S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2012152 2013-10-21] (Sophos Limited)
R2 XTSvcMgr; C:\Program Files\Novell\Client\XTier\Services\XTSvcMgr.exe [20096 2012-07-13] (Novell, Inc.)
S3 ZENPreAgent; C:\Windows\novell\zenworks\bin\ZENPreAgent.exe [233472 2012-08-20] ()
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-03-29] (Intel® Corporation)
R2 ZESService; C:\Program Files (x86)\Novell\ZENworks\esm\ZESService.exe [50344 2012-02-28] (Novell, Inc.)
==================== Drivers (Whitelisted) ====================
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [135720 2012-08-20] (Broadcom Corporation.)
R0 NCFilter; C:\Windows\System32\DRIVERS\NCFilter.sys [112256 2012-07-13] ()
R2 NCFSD; C:\Program Files\Novell\Client\XTier\Drivers\ncfsd.sys [108672 2012-07-13] ()
R2 NCIOCTL; C:\Program Files\Novell\Client\XTier\Drivers\ncioctl.sys [90240 2012-07-13] ()
R0 NCRecognizer; C:\Windows\System32\DRIVERS\NCRecognizer.sys [119936 2012-07-13] ()
R0 NCUncFilter; C:\Windows\System32\DRIVERS\NCUncFilter.sys [26240 2012-07-13] ()
R1 NICM; C:\Program Files\Novell\Client\XTier\Drivers\nicm.sys [31360 2012-07-13] (Novell, Inc.)
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [300320 2013-12-04] (NVIDIA Corporation)
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [154952 2013-07-17] (Sophos Limited)
S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [36640 2012-09-17] (Sophos Limited)
S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [25608 2012-09-17] (Sophos Plc)
R3 ST_ACCEL; C:\Windows\System32\DRIVERS\ST_ACCEL.sys [68208 2011-11-04] (STMicroelectronics)
R0 zesdac; C:\Windows\System32\DRIVERS\zesdac.sys [27952 2012-02-28] (Novell, Inc)
S4 ZesDisk; C:\Windows\System32\DRIVERS\ZesDisk.sys [17712 2012-02-28] (Novell, Inc.)
S4 zesds; C:\Windows\System32\DRIVERS\ZesDS.sys [204080 2012-02-28] (Novell, Inc.)
S4 zesdt; C:\Windows\System32\DRIVERS\ZesDT.sys [128816 2012-02-28] (Novell, Inc.)
R0 zesfsfd; C:\Windows\System32\DRIVERS\ZESFSFD.sys [66352 2012-02-28] (Novell, Inc)
R1 ZESFW; C:\Windows\System32\DRIVERS\ZESFW.sys [58160 2011-12-15] (Novell, Inc)
S4 zesocc; C:\Windows\System32\DRIVERS\ZesOCC.sys [488240 2012-02-28] (Novell, Inc.)
R2 zestdi; C:\Windows\System32\DRIVERS\zestdi.sys [46896 2012-02-28] (Novell, Inc)
R1 ZESWIFI; C:\Windows\System32\DRIVERS\ZESWIFI.sys [36656 2011-12-15] (Novell, Inc)
U3 nccache; C:\Program Files\Novell\Client\XTier\Drivers\nccache.sys [34432 2012-07-13] (Novell, Inc.)
U3 nciom; C:\Program Files\Novell\Client\XTier\Drivers\nciom.sys [80000 2012-07-13] (Novell, Inc.)
U3 ncp; C:\Program Files\Novell\Client\XTier\Drivers\ncp.sys [78976 2012-07-13] (Novell, Inc.)
U3 ncpfsp; C:\Program Files\Novell\Client\XTier\Drivers\ncpfsp.sys [100992 2012-07-13] (Novell, Inc.)
U3 ncpl; C:\Program Files\Novell\Client\XTier\Drivers\ncpl.sys [49280 2012-07-13] (Novell, Inc.)
U3 ndm; C:\Program Files\Novell\Client\XTier\Drivers\ndm.sys [19584 2012-07-13] (Novell, Inc.)
U3 ndmndap; C:\Program Files\Novell\Client\XTier\Drivers\ndmndap.sys [83584 2012-07-13] (Novell, Inc.)
U3 niam; C:\Program Files\Novell\Client\XTier\Drivers\niam.sys [39040 2012-07-13] (Novell, Inc.)
U3 nipctl; C:\Program Files\Novell\Client\XTier\Drivers\nipctl.sys [55936 2012-07-13] (Novell, Inc.)
U3 nscm; C:\Program Files\Novell\Client\XTier\Drivers\nscm.sys [36992 2012-07-13] (Novell, Inc.)
U3 nsns; C:\Program Files\Novell\Client\XTier\Drivers\nsns.sys [25216 2012-07-13] (Novell, Inc.)
U3 nsvccost; C:\Program Files\Novell\Client\XTier\Drivers\nsvccost.sys [35968 2012-07-13] (Novell, Inc.)
U3 xtxplat; C:\Program Files\Novell\Client\XTier\Drivers\xtxplat.sys [59520 2012-07-13] (Novell, Inc.)
S4 npf; system32\drivers\npf.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-19 17:29 - 2014-01-19 17:30 - 00023094 _____ C:\Users\LEHNER24\Downloads\FRST.txt
2014-01-19 17:28 - 2014-01-19 17:28 - 02076672 _____ (Farbar) C:\Users\LEHNER24\Downloads\FRST64.exe
2014-01-19 17:28 - 2014-01-19 17:28 - 00000000 ____D C:\FRST
2014-01-19 17:22 - 2014-01-19 17:22 - 00001137 _____ C:\Users\LEHNER24\Desktop\Continue Zip Opener Installation.lnk
2014-01-19 17:13 - 2014-01-19 17:13 - 00001140 _____ C:\Users\Administrator\Desktop\Continue Zip Opener Installation.lnk
2014-01-19 17:11 - 2014-01-19 17:12 - 00680328 _____ ( ) C:\Users\LEHNER24\Downloads\ZipOpenerSetup.exe
2014-01-17 16:06 - 2014-01-19 15:38 - 00000086 _____ C:\Users\LEHNER24\Desktop\Problemmeldung an das RZ.nal
2014-01-17 16:06 - 2014-01-19 15:38 - 00000086 _____ C:\Users\LEHNER24\Desktop\Firefox.nal
2014-01-17 16:06 - 2014-01-17 16:06 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RZ-Support.{763370C4-268E-4308-A60C-D8DA0342BE32}
2014-01-17 16:06 - 2014-01-17 16:06 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RZ-Installationen.{763370C4-268E-4308-A60C-D8DA0342BE32}
2014-01-17 16:06 - 2014-01-17 16:06 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RZ-Anwendungen.{763370C4-268E-4308-A60C-D8DA0342BE32}
2014-01-15 20:28 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 20:28 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 20:28 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 20:28 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 20:28 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 20:28 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 20:28 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 20:28 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 20:28 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-14 10:28 - 2014-01-14 10:28 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\NVIDIA
2014-01-13 10:57 - 2014-01-13 10:57 - 00001524 _____ C:\Users\Public\Desktop\Adobe Application Manager.lnk
2014-01-08 22:52 - 2014-01-08 23:00 - 00000000 ____D C:\Users\LEHNER24\Documents\FalkData
2014-01-08 22:47 - 2014-01-19 13:24 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\newnext.me
2014-01-08 22:47 - 2014-01-08 22:47 - 00000000 ____D C:\ProgramData\Websteroids
2014-01-08 22:41 - 2014-01-08 22:41 - 00000000 ____D C:\Users\Administrator\Documents\FalkData
2014-01-08 22:41 - 2012-03-01 13:43 - 00001340 _____ C:\Windows\SysWOW64\KMLImportPlugin.tlb
2014-01-08 22:40 - 2014-01-08 22:40 - 00001930 _____ C:\Users\Public\Desktop\Falk Navi-Manager classic.lnk
2014-01-08 22:40 - 2014-01-08 22:40 - 00000000 ____D C:\Program Files (x86)\Falk
2014-01-08 22:40 - 2012-03-01 13:45 - 00003600 _____ C:\Windows\SysWOW64\FNMPlugin.tlb
2014-01-08 22:40 - 2012-03-01 13:42 - 01089536 _____ (eHelp Corporation.) C:\Windows\SysWOW64\ROBOEX32.DLL
2014-01-08 22:39 - 2012-05-15 10:33 - 18600878 ____N C:\Users\LEHNER24\Downloads\data2.cab
2014-01-08 22:39 - 2012-05-15 10:33 - 01039399 ____N C:\Users\LEHNER24\Downloads\data1.cab
2014-01-08 22:39 - 2012-05-15 10:33 - 00470282 ____N C:\Users\LEHNER24\Downloads\setup.ibt
2014-01-08 22:39 - 2012-05-15 10:33 - 00226966 ____N C:\Users\LEHNER24\Downloads\setup.inx
2014-01-08 22:39 - 2012-05-15 10:33 - 00034895 ____N C:\Users\LEHNER24\Downloads\data1.hdr
2014-01-08 22:39 - 2012-05-15 10:33 - 00000579 ____N C:\Users\LEHNER24\Downloads\setup.ini
2014-01-08 22:39 - 2012-05-15 10:33 - 00000455 ____N C:\Users\LEHNER24\Downloads\layout.bin
2014-01-08 22:39 - 2012-05-15 09:49 - 00000000 ____D C:\Users\LEHNER24\Downloads\ActiveSync
2014-01-08 22:39 - 2005-04-07 01:39 - 00543481 ____N C:\Users\LEHNER24\Downloads\engine32.cab
2014-01-08 22:39 - 2005-04-07 01:39 - 00121064 ____N (Macrovision Corporation) C:\Users\LEHNER24\Downloads\setup.exe
2014-01-08 22:13 - 2014-01-08 22:14 - 00000000 ____D C:\Windows\WindowsMobile
2014-01-08 22:12 - 2014-01-08 22:36 - 63647153 _____ C:\Users\LEHNER24\Downloads\FaNaMa_2.11_Classic.exe
2014-01-08 21:53 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2014-01-08 21:52 - 2014-01-08 21:53 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-08 21:52 - 2014-01-08 21:53 - 00000000 ____D C:\Program Files\iTunes
2014-01-08 21:52 - 2014-01-08 21:53 - 00000000 ____D C:\Program Files (x86)\iTunes
2014-01-08 21:52 - 2014-01-08 21:52 - 00000000 ____D C:\Program Files\iPod
2014-01-08 21:49 - 2014-01-08 21:49 - 00000000 ____D C:\Program Files\Common Files\Apple
2014-01-08 21:40 - 2014-01-08 21:45 - 100400976 _____ (Apple Inc.) C:\Users\LEHNER24\Downloads\iTunes64Setup.exe
2014-01-06 21:01 - 2014-01-06 21:01 - 00000000 ____D C:\Users\Administrator\Documents\FormatFactory
2014-01-06 20:56 - 2014-01-07 11:58 - 00000000 ____D C:\FFOutput
2014-01-06 20:55 - 2014-01-06 20:55 - 00001204 _____ C:\Users\Administrator\Desktop\Format Factory.lnk
2014-01-06 20:55 - 2014-01-06 20:55 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-01-06 20:55 - 2014-01-06 20:55 - 00000000 ____D C:\Program Files (x86)\FreeTime
2014-01-06 20:42 - 2014-01-06 20:43 - 61746584 _____ (Free Time) C:\Users\LEHNER24\Downloads\FFSetup3.2.1.0.exe
2014-01-06 00:46 - 2014-01-06 00:50 - 00001467 _____ C:\Users\LEHNER24\AppData\Local\RecConfig.xml
2014-01-05 14:04 - 2014-01-05 14:04 - 00001035 _____ C:\Users\LEHNER24\Desktop\No23 Recorder.lnk
2014-01-05 14:04 - 2014-01-05 14:04 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\No23 Recorder
2014-01-05 14:04 - 2014-01-05 14:04 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\No23 Recorder
2014-01-05 14:03 - 2014-01-05 14:03 - 02497825 _____ (No23) C:\Users\LEHNER24\Downloads\No23Recorder2103.exe
2014-01-03 20:16 - 2014-01-03 20:16 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-01-03 20:16 - 2014-01-03 20:16 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-01-03 20:16 - 2014-01-03 20:16 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-01-03 20:16 - 2014-01-03 20:16 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-01-03 20:16 - 2014-01-03 20:16 - 00000000 ____D C:\Program Files\Java
2014-01-03 20:15 - 2014-01-03 20:16 - 30694824 _____ (Oracle Corporation) C:\Users\LEHNER24\Downloads\jre-7u45-windows-x64.exe
2014-01-03 15:52 - 2014-01-03 15:52 - 00000076 _____ C:\extensions.ini
2014-01-03 15:52 - 2014-01-03 15:52 - 00000000 ____D C:\Program Files (x86)\AmiExt
2014-01-03 15:52 - 2014-01-03 15:52 - 00000000 _____ C:\extensions.sqlite
2014-01-03 15:51 - 2014-01-08 22:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\Lollipop
2014-01-03 15:51 - 2014-01-03 21:52 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\newnext.me
2014-01-03 15:51 - 2014-01-03 15:54 - 00000000 ____D C:\Users\Administrator\AppData\Local\Mobogenie
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\Documents\Mobogenie
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\genienext
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\cache
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\.android
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\ProgramData\Updater
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\ProgramData\RHelpers
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 _____ C:\Users\Administrator\daemonprocess.txt
2014-01-03 15:49 - 2014-01-03 15:49 - 00337448 _____ (Amônétízé Ltd) C:\Users\LEHNER24\Downloads\FlashPlayersetup__5047_i230741755_il3.exe
2013-12-23 22:09 - 2014-01-18 14:25 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\com.adobe.WidgetBrowser
2013-12-22 22:37 - 2013-12-22 22:37 - 00915368 _____ (Oracle Corporation) C:\Users\LEHNER24\Downloads\jxpiinstall(2).exe
2013-12-22 22:33 - 2013-12-22 22:33 - 00471568 _____ C:\Users\LEHNER24\Downloads\Java.exe
2013-12-21 22:59 - 2014-01-16 21:26 - 00001456 _____ C:\Users\LEHNER24\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2013-12-21 20:23 - 2013-12-22 00:20 - 00000000 ____D C:\Users\LEHNER24\Documents\Unbenannte Site 2
2013-12-20 22:27 - 2013-12-20 22:27 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\PACE Anti-Piracy
2013-12-20 22:27 - 2013-12-20 22:27 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\PACE Anti-Piracy
2013-12-20 22:27 - 2013-12-20 22:27 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy
2013-12-20 22:11 - 2013-12-20 22:11 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-12-20 21:58 - 2013-12-20 23:00 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-12-20 21:03 - 2013-12-20 21:03 - 00000000 ____D C:\Users\Administrator\Adobe Flash Builder 4.6
2013-12-20 20:48 - 2013-12-20 20:48 - 00002032 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2013-12-20 20:37 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdralw2k.sys
2013-12-20 20:37 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdr4_xp.sys
2013-12-20 20:36 - 2013-12-20 20:36 - 00000000 ____D C:\Program Files (x86)\My Company Name
2013-12-20 19:37 - 2013-12-20 19:55 - 00000000 ____D C:\Users\Administrator\Desktop\Adobe CS6 Master Collection
2013-12-20 16:05 - 2013-12-20 16:21 - 00000000 ____D C:\Users\LEHNER24\Desktop\Adobe CS6 Master Collection
2013-12-20 15:15 - 2013-12-20 16:02 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\Mozilla Firefox
==================== One Month Modified Files and Folders =======
2014-01-19 17:30 - 2014-01-19 17:29 - 00023094 _____ C:\Users\LEHNER24\Downloads\FRST.txt
2014-01-19 17:28 - 2014-01-19 17:28 - 02076672 _____ (Farbar) C:\Users\LEHNER24\Downloads\FRST64.exe
2014-01-19 17:28 - 2014-01-19 17:28 - 00000000 ____D C:\FRST
2014-01-19 17:22 - 2014-01-19 17:22 - 00001137 _____ C:\Users\LEHNER24\Desktop\Continue Zip Opener Installation.lnk
2014-01-19 17:13 - 2014-01-19 17:13 - 00001140 _____ C:\Users\Administrator\Desktop\Continue Zip Opener Installation.lnk
2014-01-19 17:12 - 2014-01-19 17:11 - 00680328 _____ ( ) C:\Users\LEHNER24\Downloads\ZipOpenerSetup.exe
2014-01-19 16:51 - 2013-10-02 09:48 - 00000314 _____ C:\Windows\Tasks\DigitalSite.job
2014-01-19 16:40 - 2012-08-20 09:34 - 01768523 _____ C:\Windows\WindowsUpdate.log
2014-01-19 16:39 - 2012-08-20 12:35 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-19 16:37 - 2012-12-21 12:27 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\Adobe
2014-01-19 15:38 - 2014-01-17 16:06 - 00000086 _____ C:\Users\LEHNER24\Desktop\Problemmeldung an das RZ.nal
2014-01-19 15:38 - 2014-01-17 16:06 - 00000086 _____ C:\Users\LEHNER24\Desktop\Firefox.nal
2014-01-19 13:37 - 2012-08-20 09:45 - 00000000 ____D C:\Windows\system32\Drivers\{4bb8218c-aebf-4113-882f-b10ae15c8218}
2014-01-19 13:24 - 2014-01-08 22:47 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\newnext.me
2014-01-18 14:25 - 2013-12-23 22:09 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\com.adobe.WidgetBrowser
2014-01-18 14:10 - 2012-09-14 12:12 - 00000000 ____D C:\Windows\system32\appmgmt
2014-01-17 16:12 - 2009-07-14 05:45 - 00019136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-17 16:12 - 2009-07-14 05:45 - 00019136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-17 16:07 - 2013-12-04 23:16 - 00000000 ___RD C:\Users\LEHNER24\Dropbox
2014-01-17 16:07 - 2013-12-04 23:11 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Dropbox
2014-01-17 16:06 - 2014-01-17 16:06 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RZ-Support.{763370C4-268E-4308-A60C-D8DA0342BE32}
2014-01-17 16:06 - 2014-01-17 16:06 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RZ-Installationen.{763370C4-268E-4308-A60C-D8DA0342BE32}
2014-01-17 16:06 - 2014-01-17 16:06 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RZ-Anwendungen.{763370C4-268E-4308-A60C-D8DA0342BE32}
2014-01-17 16:06 - 2012-08-20 09:41 - 00082368 _____ C:\Windows\system32\ZCredMgr.LOG
2014-01-17 16:03 - 2012-08-20 09:42 - 00126652 _____ C:\ziswin.hst
2014-01-17 16:02 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-17 16:01 - 2012-08-16 15:46 - 00073713 _____ C:\Windows\setupact.log
2014-01-17 12:20 - 2010-11-21 07:21 - 00696870 _____ C:\Windows\system32\perfh007.dat
2014-01-17 12:20 - 2010-11-21 07:21 - 00148134 _____ C:\Windows\system32\perfc007.dat
2014-01-17 12:20 - 2009-07-14 06:13 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-17 11:15 - 2013-01-09 23:11 - 00000000 ____D C:\Users\LEHNER24\Documents\Any Video Converter
2014-01-17 09:10 - 2009-07-14 05:45 - 03022256 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-16 21:26 - 2013-12-21 22:59 - 00001456 _____ C:\Users\LEHNER24\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2014-01-16 09:27 - 2013-12-05 10:36 - 00000000 ____D C:\Windows\system32\MRT
2014-01-16 09:27 - 2013-12-04 23:16 - 00001032 _____ C:\Users\LEHNER24\Desktop\Dropbox.lnk
2014-01-16 09:27 - 2013-12-04 23:12 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-16 09:27 - 2012-12-21 09:57 - 00000000 ___RD C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-16 09:22 - 2012-08-16 10:30 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-15 23:26 - 2013-03-06 14:02 - 00000000 ____D C:\Users\LEHNER24\Documents\Citavi 3
2014-01-15 22:08 - 2012-12-30 14:29 - 00000187 _____ C:\Users\LEHNER24\AppData\Roaming\default.rss
2014-01-15 00:20 - 2013-07-24 10:40 - 00000000 _____ C:\Windows\system32\vireng.log
2014-01-14 15:11 - 2013-03-16 16:04 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Apple Computer
2014-01-14 11:00 - 2012-12-30 14:28 - 00000000 ____D C:\Users\LEHNER24\Documents\Adobe
2014-01-14 11:00 - 2012-12-21 09:57 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Adobe
2014-01-14 10:28 - 2014-01-14 10:28 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\NVIDIA
2014-01-13 11:34 - 2012-08-20 12:32 - 00000000 ____D C:\Program Files (x86)\Adobe
2014-01-13 11:30 - 2012-12-21 10:20 - 00000000 ____D C:\Program Files\Common Files\Adobe
2014-01-13 11:10 - 2013-01-15 14:14 - 00000000 ____D C:\Program Files\Adobe
2014-01-13 11:06 - 2012-08-20 12:32 - 00000000 ____D C:\ProgramData\Adobe
2014-01-13 10:57 - 2014-01-13 10:57 - 00001524 _____ C:\Users\Public\Desktop\Adobe Application Manager.lnk
2014-01-09 10:47 - 2010-11-21 04:47 - 00036596 _____ C:\Windows\PFRO.log
2014-01-08 23:00 - 2014-01-08 22:52 - 00000000 ____D C:\Users\LEHNER24\Documents\FalkData
2014-01-08 22:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\Lollipop
2014-01-08 22:47 - 2014-01-08 22:47 - 00000000 ____D C:\ProgramData\Websteroids
2014-01-08 22:41 - 2014-01-08 22:41 - 00000000 ____D C:\Users\Administrator\Documents\FalkData
2014-01-08 22:40 - 2014-01-08 22:40 - 00001930 _____ C:\Users\Public\Desktop\Falk Navi-Manager classic.lnk
2014-01-08 22:40 - 2014-01-08 22:40 - 00000000 ____D C:\Program Files (x86)\Falk
2014-01-08 22:40 - 2012-08-20 10:14 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2014-01-08 22:36 - 2014-01-08 22:12 - 63647153 _____ C:\Users\LEHNER24\Downloads\FaNaMa_2.11_Classic.exe
2014-01-08 22:14 - 2014-01-08 22:13 - 00000000 ____D C:\Windows\WindowsMobile
2014-01-08 21:53 - 2014-01-08 21:52 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-08 21:53 - 2014-01-08 21:52 - 00000000 ____D C:\Program Files\iTunes
2014-01-08 21:53 - 2014-01-08 21:52 - 00000000 ____D C:\Program Files (x86)\iTunes
2014-01-08 21:53 - 2013-11-21 19:45 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\Apple Computer
2014-01-08 21:52 - 2014-01-08 21:52 - 00000000 ____D C:\Program Files\iPod
2014-01-08 21:52 - 2013-03-09 10:38 - 00000000 ____D C:\ProgramData\Apple Computer
2014-01-08 21:49 - 2014-01-08 21:49 - 00000000 ____D C:\Program Files\Common Files\Apple
2014-01-08 21:49 - 2013-03-09 10:37 - 00000000 ____D C:\ProgramData\Apple
2014-01-08 21:45 - 2014-01-08 21:40 - 100400976 _____ (Apple Inc.) C:\Users\LEHNER24\Downloads\iTunes64Setup.exe
2014-01-07 11:58 - 2014-01-06 20:56 - 00000000 ____D C:\FFOutput
2014-01-06 21:01 - 2014-01-06 21:01 - 00000000 ____D C:\Users\Administrator\Documents\FormatFactory
2014-01-06 20:55 - 2014-01-06 20:55 - 00001204 _____ C:\Users\Administrator\Desktop\Format Factory.lnk
2014-01-06 20:55 - 2014-01-06 20:55 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-01-06 20:55 - 2014-01-06 20:55 - 00000000 ____D C:\Program Files (x86)\FreeTime
2014-01-06 20:43 - 2014-01-06 20:42 - 61746584 _____ (Free Time) C:\Users\LEHNER24\Downloads\FFSetup3.2.1.0.exe
2014-01-06 00:50 - 2014-01-06 00:46 - 00001467 _____ C:\Users\LEHNER24\AppData\Local\RecConfig.xml
2014-01-05 14:04 - 2014-01-05 14:04 - 00001035 _____ C:\Users\LEHNER24\Desktop\No23 Recorder.lnk
2014-01-05 14:04 - 2014-01-05 14:04 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\No23 Recorder
2014-01-05 14:04 - 2014-01-05 14:04 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\No23 Recorder
2014-01-05 14:03 - 2014-01-05 14:03 - 02497825 _____ (No23) C:\Users\LEHNER24\Downloads\No23Recorder2103.exe
2014-01-03 21:52 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\newnext.me
2014-01-03 20:27 - 2012-12-21 10:18 - 00000000 ____D C:\Users\Administrator\AppData\Local\Adobe
2014-01-03 20:22 - 2012-08-20 12:35 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-01-03 20:22 - 2012-08-20 12:35 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-03 20:17 - 2013-12-05 10:43 - 00000000 ____D C:\ProgramData\Oracle
2014-01-03 20:16 - 2014-01-03 20:16 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-01-03 20:16 - 2014-01-03 20:16 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-01-03 20:16 - 2014-01-03 20:16 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-01-03 20:16 - 2014-01-03 20:16 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-01-03 20:16 - 2014-01-03 20:16 - 00000000 ____D C:\Program Files\Java
2014-01-03 20:16 - 2014-01-03 20:15 - 30694824 _____ (Oracle Corporation) C:\Users\LEHNER24\Downloads\jre-7u45-windows-x64.exe
2014-01-03 15:54 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\Mobogenie
2014-01-03 15:52 - 2014-01-03 15:52 - 00000076 _____ C:\extensions.ini
2014-01-03 15:52 - 2014-01-03 15:52 - 00000000 ____D C:\Program Files (x86)\AmiExt
2014-01-03 15:52 - 2014-01-03 15:52 - 00000000 _____ C:\extensions.sqlite
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\Documents\Mobogenie
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\genienext
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\cache
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\.android
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\ProgramData\Updater
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\ProgramData\RHelpers
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 _____ C:\Users\Administrator\daemonprocess.txt
2014-01-03 15:51 - 2013-12-19 21:57 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Mozilla
2014-01-03 15:51 - 2012-08-20 09:38 - 00000000 ____D C:\Users\Administrator
2014-01-03 15:49 - 2014-01-03 15:49 - 00337448 _____ (Amônétízé Ltd) C:\Users\LEHNER24\Downloads\FlashPlayersetup__5047_i230741755_il3.exe
2013-12-24 10:38 - 2012-08-20 10:10 - 00404601 _____ C:\Windows\system32\ZenNotify.log
2013-12-24 10:37 - 2012-08-20 10:10 - 00003257 _____ C:\Windows\system32\ZENLGN.LOG
2013-12-22 22:37 - 2013-12-22 22:37 - 00915368 _____ (Oracle Corporation) C:\Users\LEHNER24\Downloads\jxpiinstall(2).exe
2013-12-22 22:33 - 2013-12-22 22:33 - 00471568 _____ C:\Users\LEHNER24\Downloads\Java.exe
2013-12-22 00:20 - 2013-12-21 20:23 - 00000000 ____D C:\Users\LEHNER24\Documents\Unbenannte Site 2
2013-12-20 23:00 - 2013-12-20 21:58 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-12-20 22:36 - 2012-08-20 13:19 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2013-12-20 22:27 - 2013-12-20 22:27 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\PACE Anti-Piracy
2013-12-20 22:27 - 2013-12-20 22:27 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\PACE Anti-Piracy
2013-12-20 22:27 - 2013-12-20 22:27 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy
2013-12-20 22:11 - 2013-12-20 22:11 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-12-20 21:42 - 2012-12-21 09:58 - 00111480 _____ C:\Users\LEHNER24\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-20 21:03 - 2013-12-20 21:03 - 00000000 ____D C:\Users\Administrator\Adobe Flash Builder 4.6
2013-12-20 20:48 - 2013-12-20 20:48 - 00002032 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2013-12-20 20:36 - 2013-12-20 20:36 - 00000000 ____D C:\Program Files (x86)\My Company Name
2013-12-20 19:55 - 2013-12-20 19:37 - 00000000 ____D C:\Users\Administrator\Desktop\Adobe CS6 Master Collection
2013-12-20 19:35 - 2012-08-20 09:55 - 00113096 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-20 16:21 - 2013-12-20 16:05 - 00000000 ____D C:\Users\LEHNER24\Desktop\Adobe CS6 Master Collection
2013-12-20 16:02 - 2013-12-20 15:15 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\Mozilla Firefox
Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\AskPIP_FF_.exe
C:\Users\Administrator\AppData\Local\Temp\BackupSetup.exe
C:\Users\Administrator\AppData\Local\Temp\FreemakeVideoDownloader_3.6.1.0.exe
C:\Users\Administrator\AppData\Local\Temp\ICReinstall_ZipOpenerSetup.exe
C:\Users\Administrator\AppData\Local\Temp\IMsetup.exe
C:\Users\Administrator\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Administrator\AppData\Local\Temp\uninst1.exe
C:\Users\Administrator\AppData\Local\Temp\v-bates.exe
C:\Users\Administrator\AppData\Local\Temp\vcredist_x64.exe
C:\Users\LEHNER24\AppData\Local\Temp\Creative Cloud Helper.exe
C:\Users\LEHNER24\AppData\Local\Temp\firefoxjre_exe.exe
C:\Users\LEHNER24\AppData\Local\Temp\ICReinstall_ZipOpenerSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================ Addition.txt Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-01-2014 02
Ran by LEHNER24 (ATTENTION: The logged in user is not administrator) on SC4683 on 19-01-2014 17:29:02
Running from C:\Users\LEHNER24\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(Novell, Inc.) C:\Program Files (x86)\Novell\ZENworks\bin\ZenUserDaemon.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Novell, Inc.) C:\Program Files (x86)\Novell\ZENworks\esm\ZESUser.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe
() C:\Windows\System32\nwtray.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(NTeWORKS) C:\Program Files (x86)\PicPick\picpick.exe
(Updater) C:\ProgramData\Updater\updater.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Novell, Inc.) C:\Program Files (x86)\Novell\ZENworks\bin\ZenNotifyIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(WatchDog) C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe
(WatchDog) C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe
(WatchDog) C:\ProgramData\RHelpers\IeHelper\IeHelper.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Dropbox, Inc.) C:\Users\LEHNER24\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe
(Mozilla Corporation) C:\Users\LEHNER24\AppData\Local\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Users\LEHNER24\AppData\Local\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavMain.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavProgress.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-02-13] (IDT, Inc.)
HKLM\...\Run: [IntelPROSet] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [4756240 2012-03-29] (Intel(R) Corporation)
HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [626552 2012-01-25] (Alps Electric Co., Ltd.)
HKLM\...\Run: [DFEPApplication] - C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe [7078424 2012-05-08] (Dell Inc.)
HKLM\...\Run: [NWTRAY] - C:\Windows\system32\NWTRAY.EXE [38016 2012-07-13] ()
HKLM\...\Run: [nwiz] - C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2747680 2013-12-04] ()
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM-x32\...\Run: [ZenNotifyIcon] - C:\Program Files (x86)\Novell\Zenworks\bin\ZenNotifyIcon.exe [303104 2012-03-01] (Novell, Inc.)
HKLM-x32\...\Run: [NalView] - C:\Program Files (x86)\Novell\ZENworks\bin\nalview.exe [57344 2012-03-01] (Novell, Inc.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation)
HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] - C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [929272 2013-07-17] (Sophos Limited)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1075296 2013-04-25] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-05] (Adobe Systems Inc.)
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKLM-x32\...\Run: [Updater] - C:\ProgramData\Updater\Updater.exe [486264 2013-12-18] (Updater)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LCredMgr: C:\Program Files\Novell\CASA\bin\lcredmgr.dll ()
HKCU\...\Run: [PicPick Start] - C:\Program Files (x86)\PicPick\picpick.exe [11438576 2012-12-21] (NTeWORKS)
HKCU\...\Run: [Luraklp] - C:\Users\LEHNER24\AppData\Roaming\WMSPDMODC.dll [460800 2013-08-12] ()
HKCU\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [486264 2013-12-18] (Updater)
HKCU\...\Run: [AdobeBridge] - [x]
HKCU\...\Run: [NextLive] - C:\Users\Administrator\AppData\Roaming\newnext.me\nengine.dll [1283584 2013-11-14] (NewNextDotMe)
HKCU\...\Policies\Explorer: [NoOnlinePrintsWizard] 1
HKCU\...\Policies\Explorer: [NoPublishingWizard] 1
HKCU\...\Policies\Explorer: [NoStartMenuMyGames] 1
MountPoints2: {e2b7429c-6003-11e3-a087-74e543508e02} - E:\GoWire\MPLauncher.exe
MountPoints2: {e2b742b1-6003-11e3-a087-74e543508e02} - E:\GoWire\MPLauncher.exe
AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL,C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [184048 2013-12-04] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL,C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156256 2013-12-04] (NVIDIA Corporation)
Lsa: [Authentication Packages] msv1_0 ZenV1_0 ncv1_0
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
Startup: C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\LEHNER24\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.uni-passau.de
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.uni-passau.de
URLSearchHook: HKCU - (No Name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File
SearchScopes: HKLM - DefaultScope {60D4D856-18A4-4E6D-9069-F9653AFD4CEA} URL = hxxp://websearch.uni-passau.de/cgi-bin/search.cgi?q={searchTerms}&wm=beg
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {60D4D856-18A4-4E6D-9069-F9653AFD4CEA} URL = hxxp://websearch.uni-passau.de/cgi-bin/search.cgi?q={searchTerms}&wm=beg
SearchScopes: HKLM-x32 - DefaultScope {60D4D856-18A4-4E6D-9069-F9653AFD4CEA} URL = hxxp://websearch.uni-passau.de/cgi-bin/search.cgi?q={searchTerms}&wm=beg
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {60D4D856-18A4-4E6D-9069-F9653AFD4CEA} URL = hxxp://websearch.uni-passau.de/cgi-bin/search.cgi?q={searchTerms}&wm=beg
SearchScopes: HKCU - DefaultScope {9E30C1EF-B8CF-4F7C-A5F8-2044152B4018} URL = hxxp://websearch.uni-passau.de/cgi-bin/search.cgi?q={searchTerms}&wm=beg
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=6A7774E543508E02&affID=119357&tsp=5023
SearchScopes: HKCU - {51398DED-6795-403D-A22D-521C8C22EF16} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=6a77d9b9000000000000000000000000&r=494
SearchScopes: HKCU - {6B259D3B-639A-4360-BCEA-C2C5C4C8AAA5} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {85D9DFED-88CB-4362-B1D7-D01C3D5DE5B1} URL = hxxp://de.wikipedia.org/w/index.php?title=Spezial:Suche&search={searchTerms}
SearchScopes: HKCU - {9E30C1EF-B8CF-4F7C-A5F8-2044152B4018} URL = hxxp://websearch.uni-passau.de/cgi-bin/search.cgi?q={searchTerms}&wm=beg
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office 2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 2010\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: flash-Enhancer - {5A60B6BB-FA81-4EFA-AB9C-A820E2143736} - C:\Program Files (x86)\AmiExt\flashEnhancer\ie\AmiBho.dll ()
BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: No Name - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
ShellExecuteHooks: Softwareverteilung - {763370C4-268E-4308-A60C-D8DA0342BE32} - C:\Program Files (x86)\Novell\ZENworks\bin\NalShell.dll [1427968 2012-03-01] (Novell, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{E25765CE-165D-433D-8786-F1207CE512D2}: [NameServer]62.109.121.1 62.109.121.2
FireFox:
========
FF ProfilePath: C:\Users\LEHNER24\AppData\Roaming\Mozilla\Firefox\Profiles\2ape5dn6.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems)
FF Plugin HKCU: @lightspark.github.com/Lightspark;version=1 - C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll No File
FF HKLM\...\Firefox\Extensions: [{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}] - C:\Program Files\V-bates\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}] - C:\Program Files\V-bates\Firefox
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-12-20]
FF HKLM-x32\...\Firefox\Extensions: [ext@flash-Enhancer.com] - C:\Program Files (x86)\AmiExt\flashEnhancer\ff
FF Extension: flash-Enhancer - C:\Program Files (x86)\AmiExt\flashEnhancer\ff [2014-01-03]
==================== Services (Whitelisted) =================
R2 DFEPService; C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2279960 2012-05-08] (Dell Inc.)
R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-11-08] (Ellora Assets Corp.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-28] (Intel Corporation)
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office 2010\Office14\GROOVE.EXE [50921648 2013-03-09] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-03-29] ()
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 Novell Identity Store; C:\Program Files (x86)\Novell\CASA\bin\micasad.exe [249856 2012-01-06] (Novell, Inc)
R2 Novell ZENworks Agent Service; C:\Program Files (x86)\Novell\ZENworks\bin\ZenworksWindowsService.exe [28672 2012-03-01] (Novell, Inc.)
S2 Novell ZENworks Image-Safe Data Service; C:\Program Files (x86)\Novell\ZENworks\bin\preboot\novell-zisdservice.exe [90112 2012-03-01] ()
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 O2FLASH; C:\Windows\system32\o2flash.exe [244328 2011-11-16] (O2Micro International)
R2 O2SDIOAssist; C:\Windows\SysWOW64\srvany.exe [8192 2003-04-18] ()
S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [14848 2011-12-15] ()
R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [290296 2013-10-21] (Sophos Limited)
R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [206328 2013-10-21] (Sophos Limited)
R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [237048 2013-07-17] (Sophos Limited)
R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [357400 2012-09-17] (Sophos Limited)
R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [3109880 2013-10-21] (Sophos Limited)
S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2012152 2013-10-21] (Sophos Limited)
R2 XTSvcMgr; C:\Program Files\Novell\Client\XTier\Services\XTSvcMgr.exe [20096 2012-07-13] (Novell, Inc.)
S3 ZENPreAgent; C:\Windows\novell\zenworks\bin\ZENPreAgent.exe [233472 2012-08-20] ()
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-03-29] (Intel® Corporation)
R2 ZESService; C:\Program Files (x86)\Novell\ZENworks\esm\ZESService.exe [50344 2012-02-28] (Novell, Inc.)
==================== Drivers (Whitelisted) ====================
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [135720 2012-08-20] (Broadcom Corporation.)
R0 NCFilter; C:\Windows\System32\DRIVERS\NCFilter.sys [112256 2012-07-13] ()
R2 NCFSD; C:\Program Files\Novell\Client\XTier\Drivers\ncfsd.sys [108672 2012-07-13] ()
R2 NCIOCTL; C:\Program Files\Novell\Client\XTier\Drivers\ncioctl.sys [90240 2012-07-13] ()
R0 NCRecognizer; C:\Windows\System32\DRIVERS\NCRecognizer.sys [119936 2012-07-13] ()
R0 NCUncFilter; C:\Windows\System32\DRIVERS\NCUncFilter.sys [26240 2012-07-13] ()
R1 NICM; C:\Program Files\Novell\Client\XTier\Drivers\nicm.sys [31360 2012-07-13] (Novell, Inc.)
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [300320 2013-12-04] (NVIDIA Corporation)
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [154952 2013-07-17] (Sophos Limited)
S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [36640 2012-09-17] (Sophos Limited)
S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [25608 2012-09-17] (Sophos Plc)
R3 ST_ACCEL; C:\Windows\System32\DRIVERS\ST_ACCEL.sys [68208 2011-11-04] (STMicroelectronics)
R0 zesdac; C:\Windows\System32\DRIVERS\zesdac.sys [27952 2012-02-28] (Novell, Inc)
S4 ZesDisk; C:\Windows\System32\DRIVERS\ZesDisk.sys [17712 2012-02-28] (Novell, Inc.)
S4 zesds; C:\Windows\System32\DRIVERS\ZesDS.sys [204080 2012-02-28] (Novell, Inc.)
S4 zesdt; C:\Windows\System32\DRIVERS\ZesDT.sys [128816 2012-02-28] (Novell, Inc.)
R0 zesfsfd; C:\Windows\System32\DRIVERS\ZESFSFD.sys [66352 2012-02-28] (Novell, Inc)
R1 ZESFW; C:\Windows\System32\DRIVERS\ZESFW.sys [58160 2011-12-15] (Novell, Inc)
S4 zesocc; C:\Windows\System32\DRIVERS\ZesOCC.sys [488240 2012-02-28] (Novell, Inc.)
R2 zestdi; C:\Windows\System32\DRIVERS\zestdi.sys [46896 2012-02-28] (Novell, Inc)
R1 ZESWIFI; C:\Windows\System32\DRIVERS\ZESWIFI.sys [36656 2011-12-15] (Novell, Inc)
U3 nccache; C:\Program Files\Novell\Client\XTier\Drivers\nccache.sys [34432 2012-07-13] (Novell, Inc.)
U3 nciom; C:\Program Files\Novell\Client\XTier\Drivers\nciom.sys [80000 2012-07-13] (Novell, Inc.)
U3 ncp; C:\Program Files\Novell\Client\XTier\Drivers\ncp.sys [78976 2012-07-13] (Novell, Inc.)
U3 ncpfsp; C:\Program Files\Novell\Client\XTier\Drivers\ncpfsp.sys [100992 2012-07-13] (Novell, Inc.)
U3 ncpl; C:\Program Files\Novell\Client\XTier\Drivers\ncpl.sys [49280 2012-07-13] (Novell, Inc.)
U3 ndm; C:\Program Files\Novell\Client\XTier\Drivers\ndm.sys [19584 2012-07-13] (Novell, Inc.)
U3 ndmndap; C:\Program Files\Novell\Client\XTier\Drivers\ndmndap.sys [83584 2012-07-13] (Novell, Inc.)
U3 niam; C:\Program Files\Novell\Client\XTier\Drivers\niam.sys [39040 2012-07-13] (Novell, Inc.)
U3 nipctl; C:\Program Files\Novell\Client\XTier\Drivers\nipctl.sys [55936 2012-07-13] (Novell, Inc.)
U3 nscm; C:\Program Files\Novell\Client\XTier\Drivers\nscm.sys [36992 2012-07-13] (Novell, Inc.)
U3 nsns; C:\Program Files\Novell\Client\XTier\Drivers\nsns.sys [25216 2012-07-13] (Novell, Inc.)
U3 nsvccost; C:\Program Files\Novell\Client\XTier\Drivers\nsvccost.sys [35968 2012-07-13] (Novell, Inc.)
U3 xtxplat; C:\Program Files\Novell\Client\XTier\Drivers\xtxplat.sys [59520 2012-07-13] (Novell, Inc.)
S4 npf; system32\drivers\npf.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-19 17:29 - 2014-01-19 17:30 - 00023094 _____ C:\Users\LEHNER24\Downloads\FRST.txt
2014-01-19 17:28 - 2014-01-19 17:28 - 02076672 _____ (Farbar) C:\Users\LEHNER24\Downloads\FRST64.exe
2014-01-19 17:28 - 2014-01-19 17:28 - 00000000 ____D C:\FRST
2014-01-19 17:22 - 2014-01-19 17:22 - 00001137 _____ C:\Users\LEHNER24\Desktop\Continue Zip Opener Installation.lnk
2014-01-19 17:13 - 2014-01-19 17:13 - 00001140 _____ C:\Users\Administrator\Desktop\Continue Zip Opener Installation.lnk
2014-01-19 17:11 - 2014-01-19 17:12 - 00680328 _____ ( ) C:\Users\LEHNER24\Downloads\ZipOpenerSetup.exe
2014-01-17 16:06 - 2014-01-19 15:38 - 00000086 _____ C:\Users\LEHNER24\Desktop\Problemmeldung an das RZ.nal
2014-01-17 16:06 - 2014-01-19 15:38 - 00000086 _____ C:\Users\LEHNER24\Desktop\Firefox.nal
2014-01-17 16:06 - 2014-01-17 16:06 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RZ-Support.{763370C4-268E-4308-A60C-D8DA0342BE32}
2014-01-17 16:06 - 2014-01-17 16:06 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RZ-Installationen.{763370C4-268E-4308-A60C-D8DA0342BE32}
2014-01-17 16:06 - 2014-01-17 16:06 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RZ-Anwendungen.{763370C4-268E-4308-A60C-D8DA0342BE32}
2014-01-15 20:28 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 20:28 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 20:28 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 20:28 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 20:28 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 20:28 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 20:28 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 20:28 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 20:28 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-14 10:28 - 2014-01-14 10:28 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\NVIDIA
2014-01-13 10:57 - 2014-01-13 10:57 - 00001524 _____ C:\Users\Public\Desktop\Adobe Application Manager.lnk
2014-01-08 22:52 - 2014-01-08 23:00 - 00000000 ____D C:\Users\LEHNER24\Documents\FalkData
2014-01-08 22:47 - 2014-01-19 13:24 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\newnext.me
2014-01-08 22:47 - 2014-01-08 22:47 - 00000000 ____D C:\ProgramData\Websteroids
2014-01-08 22:41 - 2014-01-08 22:41 - 00000000 ____D C:\Users\Administrator\Documents\FalkData
2014-01-08 22:41 - 2012-03-01 13:43 - 00001340 _____ C:\Windows\SysWOW64\KMLImportPlugin.tlb
2014-01-08 22:40 - 2014-01-08 22:40 - 00001930 _____ C:\Users\Public\Desktop\Falk Navi-Manager classic.lnk
2014-01-08 22:40 - 2014-01-08 22:40 - 00000000 ____D C:\Program Files (x86)\Falk
2014-01-08 22:40 - 2012-03-01 13:45 - 00003600 _____ C:\Windows\SysWOW64\FNMPlugin.tlb
2014-01-08 22:40 - 2012-03-01 13:42 - 01089536 _____ (eHelp Corporation.) C:\Windows\SysWOW64\ROBOEX32.DLL
2014-01-08 22:39 - 2012-05-15 10:33 - 18600878 ____N C:\Users\LEHNER24\Downloads\data2.cab
2014-01-08 22:39 - 2012-05-15 10:33 - 01039399 ____N C:\Users\LEHNER24\Downloads\data1.cab
2014-01-08 22:39 - 2012-05-15 10:33 - 00470282 ____N C:\Users\LEHNER24\Downloads\setup.ibt
2014-01-08 22:39 - 2012-05-15 10:33 - 00226966 ____N C:\Users\LEHNER24\Downloads\setup.inx
2014-01-08 22:39 - 2012-05-15 10:33 - 00034895 ____N C:\Users\LEHNER24\Downloads\data1.hdr
2014-01-08 22:39 - 2012-05-15 10:33 - 00000579 ____N C:\Users\LEHNER24\Downloads\setup.ini
2014-01-08 22:39 - 2012-05-15 10:33 - 00000455 ____N C:\Users\LEHNER24\Downloads\layout.bin
2014-01-08 22:39 - 2012-05-15 09:49 - 00000000 ____D C:\Users\LEHNER24\Downloads\ActiveSync
2014-01-08 22:39 - 2005-04-07 01:39 - 00543481 ____N C:\Users\LEHNER24\Downloads\engine32.cab
2014-01-08 22:39 - 2005-04-07 01:39 - 00121064 ____N (Macrovision Corporation) C:\Users\LEHNER24\Downloads\setup.exe
2014-01-08 22:13 - 2014-01-08 22:14 - 00000000 ____D C:\Windows\WindowsMobile
2014-01-08 22:12 - 2014-01-08 22:36 - 63647153 _____ C:\Users\LEHNER24\Downloads\FaNaMa_2.11_Classic.exe
2014-01-08 21:53 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2014-01-08 21:52 - 2014-01-08 21:53 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-08 21:52 - 2014-01-08 21:53 - 00000000 ____D C:\Program Files\iTunes
2014-01-08 21:52 - 2014-01-08 21:53 - 00000000 ____D C:\Program Files (x86)\iTunes
2014-01-08 21:52 - 2014-01-08 21:52 - 00000000 ____D C:\Program Files\iPod
2014-01-08 21:49 - 2014-01-08 21:49 - 00000000 ____D C:\Program Files\Common Files\Apple
2014-01-08 21:40 - 2014-01-08 21:45 - 100400976 _____ (Apple Inc.) C:\Users\LEHNER24\Downloads\iTunes64Setup.exe
2014-01-06 21:01 - 2014-01-06 21:01 - 00000000 ____D C:\Users\Administrator\Documents\FormatFactory
2014-01-06 20:56 - 2014-01-07 11:58 - 00000000 ____D C:\FFOutput
2014-01-06 20:55 - 2014-01-06 20:55 - 00001204 _____ C:\Users\Administrator\Desktop\Format Factory.lnk
2014-01-06 20:55 - 2014-01-06 20:55 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-01-06 20:55 - 2014-01-06 20:55 - 00000000 ____D C:\Program Files (x86)\FreeTime
2014-01-06 20:42 - 2014-01-06 20:43 - 61746584 _____ (Free Time) C:\Users\LEHNER24\Downloads\FFSetup3.2.1.0.exe
2014-01-06 00:46 - 2014-01-06 00:50 - 00001467 _____ C:\Users\LEHNER24\AppData\Local\RecConfig.xml
2014-01-05 14:04 - 2014-01-05 14:04 - 00001035 _____ C:\Users\LEHNER24\Desktop\No23 Recorder.lnk
2014-01-05 14:04 - 2014-01-05 14:04 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\No23 Recorder
2014-01-05 14:04 - 2014-01-05 14:04 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\No23 Recorder
2014-01-05 14:03 - 2014-01-05 14:03 - 02497825 _____ (No23) C:\Users\LEHNER24\Downloads\No23Recorder2103.exe
2014-01-03 20:16 - 2014-01-03 20:16 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-01-03 20:16 - 2014-01-03 20:16 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-01-03 20:16 - 2014-01-03 20:16 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-01-03 20:16 - 2014-01-03 20:16 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-01-03 20:16 - 2014-01-03 20:16 - 00000000 ____D C:\Program Files\Java
2014-01-03 20:15 - 2014-01-03 20:16 - 30694824 _____ (Oracle Corporation) C:\Users\LEHNER24\Downloads\jre-7u45-windows-x64.exe
2014-01-03 15:52 - 2014-01-03 15:52 - 00000076 _____ C:\extensions.ini
2014-01-03 15:52 - 2014-01-03 15:52 - 00000000 ____D C:\Program Files (x86)\AmiExt
2014-01-03 15:52 - 2014-01-03 15:52 - 00000000 _____ C:\extensions.sqlite
2014-01-03 15:51 - 2014-01-08 22:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\Lollipop
2014-01-03 15:51 - 2014-01-03 21:52 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\newnext.me
2014-01-03 15:51 - 2014-01-03 15:54 - 00000000 ____D C:\Users\Administrator\AppData\Local\Mobogenie
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\Documents\Mobogenie
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\genienext
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\cache
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\.android
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\ProgramData\Updater
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\ProgramData\RHelpers
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 _____ C:\Users\Administrator\daemonprocess.txt
2014-01-03 15:49 - 2014-01-03 15:49 - 00337448 _____ (Amônétízé Ltd) C:\Users\LEHNER24\Downloads\FlashPlayersetup__5047_i230741755_il3.exe
2013-12-23 22:09 - 2014-01-18 14:25 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\com.adobe.WidgetBrowser
2013-12-22 22:37 - 2013-12-22 22:37 - 00915368 _____ (Oracle Corporation) C:\Users\LEHNER24\Downloads\jxpiinstall(2).exe
2013-12-22 22:33 - 2013-12-22 22:33 - 00471568 _____ C:\Users\LEHNER24\Downloads\Java.exe
2013-12-21 22:59 - 2014-01-16 21:26 - 00001456 _____ C:\Users\LEHNER24\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2013-12-21 20:23 - 2013-12-22 00:20 - 00000000 ____D C:\Users\LEHNER24\Documents\Unbenannte Site 2
2013-12-20 22:27 - 2013-12-20 22:27 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\PACE Anti-Piracy
2013-12-20 22:27 - 2013-12-20 22:27 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\PACE Anti-Piracy
2013-12-20 22:27 - 2013-12-20 22:27 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy
2013-12-20 22:11 - 2013-12-20 22:11 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-12-20 21:58 - 2013-12-20 23:00 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-12-20 21:03 - 2013-12-20 21:03 - 00000000 ____D C:\Users\Administrator\Adobe Flash Builder 4.6
2013-12-20 20:48 - 2013-12-20 20:48 - 00002032 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2013-12-20 20:37 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdralw2k.sys
2013-12-20 20:37 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdr4_xp.sys
2013-12-20 20:36 - 2013-12-20 20:36 - 00000000 ____D C:\Program Files (x86)\My Company Name
2013-12-20 19:37 - 2013-12-20 19:55 - 00000000 ____D C:\Users\Administrator\Desktop\Adobe CS6 Master Collection
2013-12-20 16:05 - 2013-12-20 16:21 - 00000000 ____D C:\Users\LEHNER24\Desktop\Adobe CS6 Master Collection
2013-12-20 15:15 - 2013-12-20 16:02 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\Mozilla Firefox
==================== One Month Modified Files and Folders =======
2014-01-19 17:30 - 2014-01-19 17:29 - 00023094 _____ C:\Users\LEHNER24\Downloads\FRST.txt
2014-01-19 17:28 - 2014-01-19 17:28 - 02076672 _____ (Farbar) C:\Users\LEHNER24\Downloads\FRST64.exe
2014-01-19 17:28 - 2014-01-19 17:28 - 00000000 ____D C:\FRST
2014-01-19 17:22 - 2014-01-19 17:22 - 00001137 _____ C:\Users\LEHNER24\Desktop\Continue Zip Opener Installation.lnk
2014-01-19 17:13 - 2014-01-19 17:13 - 00001140 _____ C:\Users\Administrator\Desktop\Continue Zip Opener Installation.lnk
2014-01-19 17:12 - 2014-01-19 17:11 - 00680328 _____ ( ) C:\Users\LEHNER24\Downloads\ZipOpenerSetup.exe
2014-01-19 16:51 - 2013-10-02 09:48 - 00000314 _____ C:\Windows\Tasks\DigitalSite.job
2014-01-19 16:40 - 2012-08-20 09:34 - 01768523 _____ C:\Windows\WindowsUpdate.log
2014-01-19 16:39 - 2012-08-20 12:35 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-19 16:37 - 2012-12-21 12:27 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\Adobe
2014-01-19 15:38 - 2014-01-17 16:06 - 00000086 _____ C:\Users\LEHNER24\Desktop\Problemmeldung an das RZ.nal
2014-01-19 15:38 - 2014-01-17 16:06 - 00000086 _____ C:\Users\LEHNER24\Desktop\Firefox.nal
2014-01-19 13:37 - 2012-08-20 09:45 - 00000000 ____D C:\Windows\system32\Drivers\{4bb8218c-aebf-4113-882f-b10ae15c8218}
2014-01-19 13:24 - 2014-01-08 22:47 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\newnext.me
2014-01-18 14:25 - 2013-12-23 22:09 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\com.adobe.WidgetBrowser
2014-01-18 14:10 - 2012-09-14 12:12 - 00000000 ____D C:\Windows\system32\appmgmt
2014-01-17 16:12 - 2009-07-14 05:45 - 00019136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-17 16:12 - 2009-07-14 05:45 - 00019136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-17 16:07 - 2013-12-04 23:16 - 00000000 ___RD C:\Users\LEHNER24\Dropbox
2014-01-17 16:07 - 2013-12-04 23:11 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Dropbox
2014-01-17 16:06 - 2014-01-17 16:06 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RZ-Support.{763370C4-268E-4308-A60C-D8DA0342BE32}
2014-01-17 16:06 - 2014-01-17 16:06 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RZ-Installationen.{763370C4-268E-4308-A60C-D8DA0342BE32}
2014-01-17 16:06 - 2014-01-17 16:06 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RZ-Anwendungen.{763370C4-268E-4308-A60C-D8DA0342BE32}
2014-01-17 16:06 - 2012-08-20 09:41 - 00082368 _____ C:\Windows\system32\ZCredMgr.LOG
2014-01-17 16:03 - 2012-08-20 09:42 - 00126652 _____ C:\ziswin.hst
2014-01-17 16:02 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-17 16:01 - 2012-08-16 15:46 - 00073713 _____ C:\Windows\setupact.log
2014-01-17 12:20 - 2010-11-21 07:21 - 00696870 _____ C:\Windows\system32\perfh007.dat
2014-01-17 12:20 - 2010-11-21 07:21 - 00148134 _____ C:\Windows\system32\perfc007.dat
2014-01-17 12:20 - 2009-07-14 06:13 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-17 11:15 - 2013-01-09 23:11 - 00000000 ____D C:\Users\LEHNER24\Documents\Any Video Converter
2014-01-17 09:10 - 2009-07-14 05:45 - 03022256 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-16 21:26 - 2013-12-21 22:59 - 00001456 _____ C:\Users\LEHNER24\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2014-01-16 09:27 - 2013-12-05 10:36 - 00000000 ____D C:\Windows\system32\MRT
2014-01-16 09:27 - 2013-12-04 23:16 - 00001032 _____ C:\Users\LEHNER24\Desktop\Dropbox.lnk
2014-01-16 09:27 - 2013-12-04 23:12 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-16 09:27 - 2012-12-21 09:57 - 00000000 ___RD C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-16 09:22 - 2012-08-16 10:30 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-15 23:26 - 2013-03-06 14:02 - 00000000 ____D C:\Users\LEHNER24\Documents\Citavi 3
2014-01-15 22:08 - 2012-12-30 14:29 - 00000187 _____ C:\Users\LEHNER24\AppData\Roaming\default.rss
2014-01-15 00:20 - 2013-07-24 10:40 - 00000000 _____ C:\Windows\system32\vireng.log
2014-01-14 15:11 - 2013-03-16 16:04 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Apple Computer
2014-01-14 11:00 - 2012-12-30 14:28 - 00000000 ____D C:\Users\LEHNER24\Documents\Adobe
2014-01-14 11:00 - 2012-12-21 09:57 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Adobe
2014-01-14 10:28 - 2014-01-14 10:28 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\NVIDIA
2014-01-13 11:34 - 2012-08-20 12:32 - 00000000 ____D C:\Program Files (x86)\Adobe
2014-01-13 11:30 - 2012-12-21 10:20 - 00000000 ____D C:\Program Files\Common Files\Adobe
2014-01-13 11:10 - 2013-01-15 14:14 - 00000000 ____D C:\Program Files\Adobe
2014-01-13 11:06 - 2012-08-20 12:32 - 00000000 ____D C:\ProgramData\Adobe
2014-01-13 10:57 - 2014-01-13 10:57 - 00001524 _____ C:\Users\Public\Desktop\Adobe Application Manager.lnk
2014-01-09 10:47 - 2010-11-21 04:47 - 00036596 _____ C:\Windows\PFRO.log
2014-01-08 23:00 - 2014-01-08 22:52 - 00000000 ____D C:\Users\LEHNER24\Documents\FalkData
2014-01-08 22:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\Lollipop
2014-01-08 22:47 - 2014-01-08 22:47 - 00000000 ____D C:\ProgramData\Websteroids
2014-01-08 22:41 - 2014-01-08 22:41 - 00000000 ____D C:\Users\Administrator\Documents\FalkData
2014-01-08 22:40 - 2014-01-08 22:40 - 00001930 _____ C:\Users\Public\Desktop\Falk Navi-Manager classic.lnk
2014-01-08 22:40 - 2014-01-08 22:40 - 00000000 ____D C:\Program Files (x86)\Falk
2014-01-08 22:40 - 2012-08-20 10:14 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2014-01-08 22:36 - 2014-01-08 22:12 - 63647153 _____ C:\Users\LEHNER24\Downloads\FaNaMa_2.11_Classic.exe
2014-01-08 22:14 - 2014-01-08 22:13 - 00000000 ____D C:\Windows\WindowsMobile
2014-01-08 21:53 - 2014-01-08 21:52 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-08 21:53 - 2014-01-08 21:52 - 00000000 ____D C:\Program Files\iTunes
2014-01-08 21:53 - 2014-01-08 21:52 - 00000000 ____D C:\Program Files (x86)\iTunes
2014-01-08 21:53 - 2013-11-21 19:45 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\Apple Computer
2014-01-08 21:52 - 2014-01-08 21:52 - 00000000 ____D C:\Program Files\iPod
2014-01-08 21:52 - 2013-03-09 10:38 - 00000000 ____D C:\ProgramData\Apple Computer
2014-01-08 21:49 - 2014-01-08 21:49 - 00000000 ____D C:\Program Files\Common Files\Apple
2014-01-08 21:49 - 2013-03-09 10:37 - 00000000 ____D C:\ProgramData\Apple
2014-01-08 21:45 - 2014-01-08 21:40 - 100400976 _____ (Apple Inc.) C:\Users\LEHNER24\Downloads\iTunes64Setup.exe
2014-01-07 11:58 - 2014-01-06 20:56 - 00000000 ____D C:\FFOutput
2014-01-06 21:01 - 2014-01-06 21:01 - 00000000 ____D C:\Users\Administrator\Documents\FormatFactory
2014-01-06 20:55 - 2014-01-06 20:55 - 00001204 _____ C:\Users\Administrator\Desktop\Format Factory.lnk
2014-01-06 20:55 - 2014-01-06 20:55 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-01-06 20:55 - 2014-01-06 20:55 - 00000000 ____D C:\Program Files (x86)\FreeTime
2014-01-06 20:43 - 2014-01-06 20:42 - 61746584 _____ (Free Time) C:\Users\LEHNER24\Downloads\FFSetup3.2.1.0.exe
2014-01-06 00:50 - 2014-01-06 00:46 - 00001467 _____ C:\Users\LEHNER24\AppData\Local\RecConfig.xml
2014-01-05 14:04 - 2014-01-05 14:04 - 00001035 _____ C:\Users\LEHNER24\Desktop\No23 Recorder.lnk
2014-01-05 14:04 - 2014-01-05 14:04 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\No23 Recorder
2014-01-05 14:04 - 2014-01-05 14:04 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\No23 Recorder
2014-01-05 14:03 - 2014-01-05 14:03 - 02497825 _____ (No23) C:\Users\LEHNER24\Downloads\No23Recorder2103.exe
2014-01-03 21:52 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\newnext.me
2014-01-03 20:27 - 2012-12-21 10:18 - 00000000 ____D C:\Users\Administrator\AppData\Local\Adobe
2014-01-03 20:22 - 2012-08-20 12:35 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-01-03 20:22 - 2012-08-20 12:35 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-03 20:17 - 2013-12-05 10:43 - 00000000 ____D C:\ProgramData\Oracle
2014-01-03 20:16 - 2014-01-03 20:16 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-01-03 20:16 - 2014-01-03 20:16 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-01-03 20:16 - 2014-01-03 20:16 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-01-03 20:16 - 2014-01-03 20:16 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-01-03 20:16 - 2014-01-03 20:16 - 00000000 ____D C:\Program Files\Java
2014-01-03 20:16 - 2014-01-03 20:15 - 30694824 _____ (Oracle Corporation) C:\Users\LEHNER24\Downloads\jre-7u45-windows-x64.exe
2014-01-03 15:54 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\Mobogenie
2014-01-03 15:52 - 2014-01-03 15:52 - 00000076 _____ C:\extensions.ini
2014-01-03 15:52 - 2014-01-03 15:52 - 00000000 ____D C:\Program Files (x86)\AmiExt
2014-01-03 15:52 - 2014-01-03 15:52 - 00000000 _____ C:\extensions.sqlite
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\Documents\Mobogenie
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\genienext
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\cache
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\Users\Administrator\.android
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\ProgramData\Updater
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 ____D C:\ProgramData\RHelpers
2014-01-03 15:51 - 2014-01-03 15:51 - 00000000 _____ C:\Users\Administrator\daemonprocess.txt
2014-01-03 15:51 - 2013-12-19 21:57 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Mozilla
2014-01-03 15:51 - 2012-08-20 09:38 - 00000000 ____D C:\Users\Administrator
2014-01-03 15:49 - 2014-01-03 15:49 - 00337448 _____ (Amônétízé Ltd) C:\Users\LEHNER24\Downloads\FlashPlayersetup__5047_i230741755_il3.exe
2013-12-24 10:38 - 2012-08-20 10:10 - 00404601 _____ C:\Windows\system32\ZenNotify.log
2013-12-24 10:37 - 2012-08-20 10:10 - 00003257 _____ C:\Windows\system32\ZENLGN.LOG
2013-12-22 22:37 - 2013-12-22 22:37 - 00915368 _____ (Oracle Corporation) C:\Users\LEHNER24\Downloads\jxpiinstall(2).exe
2013-12-22 22:33 - 2013-12-22 22:33 - 00471568 _____ C:\Users\LEHNER24\Downloads\Java.exe
2013-12-22 00:20 - 2013-12-21 20:23 - 00000000 ____D C:\Users\LEHNER24\Documents\Unbenannte Site 2
2013-12-20 23:00 - 2013-12-20 21:58 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-12-20 22:36 - 2012-08-20 13:19 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2013-12-20 22:27 - 2013-12-20 22:27 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\PACE Anti-Piracy
2013-12-20 22:27 - 2013-12-20 22:27 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\PACE Anti-Piracy
2013-12-20 22:27 - 2013-12-20 22:27 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy
2013-12-20 22:11 - 2013-12-20 22:11 - 00000000 ____D C:\Users\LEHNER24\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-12-20 21:42 - 2012-12-21 09:58 - 00111480 _____ C:\Users\LEHNER24\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-20 21:03 - 2013-12-20 21:03 - 00000000 ____D C:\Users\Administrator\Adobe Flash Builder 4.6
2013-12-20 20:48 - 2013-12-20 20:48 - 00002032 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2013-12-20 20:36 - 2013-12-20 20:36 - 00000000 ____D C:\Program Files (x86)\My Company Name
2013-12-20 19:55 - 2013-12-20 19:37 - 00000000 ____D C:\Users\Administrator\Desktop\Adobe CS6 Master Collection
2013-12-20 19:35 - 2012-08-20 09:55 - 00113096 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-20 16:21 - 2013-12-20 16:05 - 00000000 ____D C:\Users\LEHNER24\Desktop\Adobe CS6 Master Collection
2013-12-20 16:02 - 2013-12-20 15:15 - 00000000 ____D C:\Users\LEHNER24\AppData\Local\Mozilla Firefox
Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\AskPIP_FF_.exe
C:\Users\Administrator\AppData\Local\Temp\BackupSetup.exe
C:\Users\Administrator\AppData\Local\Temp\FreemakeVideoDownloader_3.6.1.0.exe
C:\Users\Administrator\AppData\Local\Temp\ICReinstall_ZipOpenerSetup.exe
C:\Users\Administrator\AppData\Local\Temp\IMsetup.exe
C:\Users\Administrator\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Administrator\AppData\Local\Temp\uninst1.exe
C:\Users\Administrator\AppData\Local\Temp\v-bates.exe
C:\Users\Administrator\AppData\Local\Temp\vcredist_x64.exe
C:\Users\LEHNER24\AppData\Local\Temp\Creative Cloud Helper.exe
C:\Users\LEHNER24\AppData\Local\Temp\firefoxjre_exe.exe
C:\Users\LEHNER24\AppData\Local\Temp\ICReinstall_ZipOpenerSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================ |