Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-03-05 15:54:58
Windows 5.1.2600 Service Pack 3 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T0L0-17 rev. 465,76GB
Running: Gmer-19357.exe; Driver: C:\DOKUME~1\HERBER~1\LOKALE~1\Temp\kxrdipog.sys
---- System - GMER 2.1 ----
SSDT F623F41C ZwClose
SSDT F623F3D6 ZwCreateKey
SSDT F623F426 ZwCreateSection
SSDT F623F3CC ZwCreateThread
SSDT F623F3DB ZwDeleteKey
SSDT F623F3E5 ZwDeleteValueKey
SSDT F623F417 ZwDuplicateObject
SSDT F623F3EA ZwLoadKey
SSDT F623F3B8 ZwOpenProcess
SSDT F623F3BD ZwOpenThread
SSDT F623F43F ZwQueryValueKey
SSDT F623F3F4 ZwReplaceKey
SSDT F623F430 ZwRequestWaitReplyPort
SSDT F623F3EF ZwRestoreKey
SSDT F623F42B ZwSetContextThread
SSDT F623F435 ZwSetSecurityObject
SSDT F623F3E0 ZwSetValueKey
SSDT F623F43A ZwSystemDebugControl
SSDT F623F3C7 ZwTerminateProcess
INT 0x63 ? FD1932AC
INT 0x73 ? FCF602AC
INT 0x83 ? FCFE02AC
INT 0x84 ? FCF252AC
INT 0x92 ? FC6AC2AC
INT 0x94 ? FCF4E2AC
INT 0xA4 ? FCF582AC
INT 0xB1 ? FD1982AC
INT 0xB4 ? FCF5B2AC
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2E10 E0BCE6F8 4 Bytes JMP 9AF623F3
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF4E9F3C0, 0x70A55A, 0xE8000020]
---- User code sections - GMER 2.1 ----
.text C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE[1496] ole32.dll!OleLoadFromStream 774F988B 5 Bytes JMP 30F144C3 C:\Programme\Gemeinsame Dateien\Microsoft Shared\office11\mso.dll
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, E0, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, E3, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, E0, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, E1, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, E2, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, E1, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, E2, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, E0, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, E1, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, E2, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, E3, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[1760] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
.text C:\Programme\Microsoft Office\OFFICE11\WINWORD.EXE[4560] ole32.dll!OleLoadFromStream 774F988B 5 Bytes JMP 30F144C3 C:\Programme\Gemeinsame Dateien\Microsoft Shared\office11\mso.dll
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 90, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, 93, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 90, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 91, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 92, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 91, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 92, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 90, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 91, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 92, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, 93, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[4844] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 20, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, 23, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 20, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 21, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 22, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 21, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 22, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 20, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 21, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 22, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, 23, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5708] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 88, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, 8B, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 88, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 89, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 8A, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 89, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 8A, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 88, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 89, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 8A, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, 8B, 07, 03]
.text C:\Programme\Opera\20.0.1387.64\opera.exe[5712] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
---- Devices - GMER 2.1 ----
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\ControlSet001\Control\Video\{11CE5BF0-C636-432F-A003-95EDD381F56D}\0000@D3D_\x3332\x3331 2089309684
Reg HKLM\SYSTEM\ControlSet001\Control\Video\{2CBABAB1-8F5B-426C-AD76-90E1BB794460}\0000@D3D_\x3332\x3331 2089309684
Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{11CE5BF0-C636-432F-A003-95EDD381F56D}\0000@D3D_\x3332\x3331 2089309684
Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{2CBABAB1-8F5B-426C-AD76-90E1BB794460}\0000@D3D_\x3332\x3331 2089309684
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher@TracesProcessed 444
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher@TracesSuccessful 306
---- EOF - GMER 2.1 ----
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-03-2014
Ran by Herbert Klinzing (administrator) on HERBERT on 05-03-2014 15:24:05
Running from C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Enigma Software Group USA, LLC.) C:\Programme\Enigma Software Group\SpyHunter\SH4Service.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Programme\ASUS\AXSP\1.00.19\atkexComSvc.exe
(ASUSTeK Computer Inc.) C:\Programme\ASUS\AAHM\1.00.20\aaHMSvc.exe
(ASUSTeK Computer Inc.) C:\Programme\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
(ASUSTeK Computer Inc.) C:\Programme\ASUS\AsusFanControlService\1.01.10\AsusFanControlService.exe
(AVM Berlin) C:\Programme\avmwlanstick\WlanNetService.exe
(AVM Berlin) C:\Programme\FRITZ!Box-Kindersicherung\avmident.exe
(Apple Inc.) C:\Programme\Bonjour\mDNSResponder.exe
(C-Dilla Ltd) C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Intel(R) Corporation) C:\Programme\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Programme\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Programme\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Malwarebytes Corporation) C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Panasonic) C:\Programme\Panasonic\TrapMonitor\Trapmnnt.exe
(Microsoft Corporation) C:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Intel Corporation) C:\Programme\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
() C:\Programme\VVW\Update\VVWUpdateDienst.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Panasonic Communications Co., Ltd.) C:\Programme\Panasonic\Panasonic-DMS\Device Monitor\DMWakeup.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
() C:\Programme\Panasonic\Panasonic-DMS\RPT Network Printer Port\Msgsrv.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
(Enigma Software Group USA, LLC.) C:\Programme\Enigma Software Group\SpyHunter\SpyHunter4.exe
(Logitech Inc.) C:\Programme\Logitech\LWS\Webcam Software\LWS.exe
(Apple Inc.) C:\Programme\iTunes\iTunesHelper.exe
(Logitech, Inc.) C:\Programme\Logitech\SetPointP\SetPoint.exe
(Microsoft Corporation) C:\Programme\Microsoft Office\OFFICE11\OUTLOOK.EXE
(RH Computer Software Solutions GmbH) C:\Programme\klickTel\klickTel Herbst 2004\IsdnCall.exe
(Apple Inc.) C:\Programme\iPod\bin\iPodService.exe
(Logitech, Inc.) C:\Programme\Gemeinsame Dateien\LogiShrd\KHAL3\KHALMNPR.EXE
(Panasonic Communications Co., Ltd.) C:\Programme\Panasonic\Panasonic-DMS\LRecvTrap\LRecvTrap.exe
(Panasonic Communications Co., Ltd.) C:\Programme\Panasonic\Panasonic-DMS\Port Controller\Mfpscdl.exe
(Hewlett-Packard Co.) C:\Dokumente und Einstellungen\Herbert Klinzing\Startmenü\Programme\Autostart\hpqtra08.exe
(Microsoft Corporation) C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE
(Hewlett-Packard Co.) C:\Programme\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Programme\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Programme\HP\Digital Imaging\bin\hpqgpc01.exe
(Microsoft Corporation) C:\Programme\Microsoft Office\OFFICE11\WINWORD.EXE
(Avira Operations GmbH & Co. KG) c:\programme\avira\antivir desktop\avscan.exe
(Opera Software) C:\Programme\Opera\20.0.1387.64\opera.exe
() C:\Programme\Opera\20.0.1387.64\opera_crashreporter.exe
(Opera Software) C:\Programme\Opera\20.0.1387.64\opera.exe
(Opera Software) C:\Programme\Opera\20.0.1387.64\opera.exe
(Opera Software) C:\Programme\Opera\20.0.1387.64\opera.exe
(Opera Software) C:\Programme\Opera\20.0.1387.64\opera.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Panasonic Device Monitor Wakeup] - C:\Programme\Panasonic\Panasonic-DMS\Device Monitor\DMWakeup.exe [303104 2006-11-02] (Panasonic Communications Co., Ltd.)
HKLM\...\Run: [APSDaemon] - C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [RTHDCPL] - C:\WINDOWS\RTHDCPL.EXE [20065936 2012-06-06] (Realtek Semiconductor Corp.)
HKLM\...\Run: [RPT Msgsrv] - C:\Programme\Panasonic\Panasonic-DMS\RPT Network Printer Port\Msgsrv.exe [57344 2007-04-11] ()
HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [15664416 2013-02-10] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] - C:\WINDOWS\system32\NvMCTray.dll [223008 2013-02-10] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] - C:\Programme\NVIDIA Corporation\nview\nwiz.exe [1982312 2013-02-10] ()
HKLM\...\Run: [avgnt] - C:\Programme\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-22] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [Firebird] - C:\Programme\Firebird\Firebird_2_1\bin\fbguard.exe [81920 2009-07-22] (Firebird Project)
HKLM\...\Run: [SpyHunter Security Suite] - C:\Programme\Enigma Software Group\SpyHunter\SpyHunter4.exe [6320000 2013-07-08] (Enigma Software Group USA, LLC.)
HKLM\...\Run: [LWS] - C:\Programme\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-12] (Logitech Inc.)
HKLM\...\Run: [iTunesHelper] - C:\Programme\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Programme\QuickTime\qttask.exe [421888 2011-10-24] (Apple Inc.)
HKLM\...\Run: [EvtMgr6] - C:\Programme\Logitech\SetPointP\SetPoint.exe [2296600 2013-07-31] (Logitech, Inc.)
Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
Winlogon\Notify\LBTWlgn: c:\programme\gemeinsame dateien\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKLM\...\Policies\Explorer: [MemCheckBoxInRunDlg] 1
HKU\S-1-5-21-220523388-1965331169-682003330-1003\...\Run: [Microsoft Office Outlook] - C:\Programme\Microsoft Office\OFFICE11\OUTLOOK.EXE [196440 2010-06-23] (Microsoft Corporation)
HKU\S-1-5-21-220523388-1965331169-682003330-1003\...\Run: [ISDN Callwatcher for Windows 32bit] - C:\Programme\klickTel\klickTel Herbst 2004\IsdnCall.exe [884736 2001-09-06] (RH Computer Software Solutions GmbH)
HKU\S-1-5-21-220523388-1965331169-682003330-1003\...\Run: [Skype] - C:\Programme\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-220523388-1965331169-682003330-1003\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x91000000
HKU\S-1-5-21-220523388-1965331169-682003330-1003\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
AppInit_DLLs: nvdesk32.dll => nvdesk32.dll File Not Found
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Basisschnittstelle Office SR V.5.02 Initialisierung.lnk
ShortcutTarget: Basisschnittstelle Office SR V.5.02 Initialisierung.lnk -> C:\DATEV\PROGRAMM\BSoffice\service\OfficeDiag.exe (DATEV eG)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Job Status Utility.lnk
ShortcutTarget: Job Status Utility.lnk -> C:\Programme\Panasonic\Panasonic-DMS\LRecvTrap\LRecvTrap.exe (Panasonic Communications Co., Ltd.)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Panasonic Communications Utility.lnk
ShortcutTarget: Panasonic Communications Utility.lnk -> C:\Programme\Panasonic\Panasonic-DMS\Port Controller\Mfpscdl.exe (Panasonic Communications Co., Ltd.)
Startup: C:\Dokumente und Einstellungen\Herbert Klinzing\Startmenü\Programme\Autostart\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Dokumente und Einstellungen\Herbert Klinzing\Startmenü\Programme\Autostart\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {56CF4856-ECB4-4E46-A897-A378821F97B9} - No File
DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} hxxp://support.asus.de/common/asusTek_sys_ctrl.cab
DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} hxxp://download.gigabyte.com.tw/object/Dldrv.ocx
DPF: {1F831FA3-42FC-11D4-95A6-0080AD30DCE1} file:///C:/Programme/AutoCAD%202002%20Deu/InstFred.ocx
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1343636624625
DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} file:///C:/Programme/AutoCAD%202002%20Deu/AcDcToday.ocx
DPF: {AE563724-B4F5-11D4-A415-00108302FDFD} file:///C:/Programme/AutoCAD%202002%20Deu/InstBanr.ocx
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F281A59C-7B65-11D3-8617-0010830243BD} file:///C:/Programme/AutoCAD%202002%20Deu/AcPreview.ocx
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 C:\Programme\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\Herbert Klinzing\Anwendungsdaten\Mozilla\Firefox\Profiles\ob026rne.default
FF user.js: detected! => C:\Dokumente und Einstellungen\Herbert Klinzing\Anwendungsdaten\Mozilla\Firefox\Profiles\ob026rne.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Programme\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Programme\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin: @intel-webapi.intel.com/Intel WebAPI updater - C:\Programme\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pages.tvunetworks.com/WebPlayer - C:\WINDOWS\system32\TVUAx\npTVUAx.dll (TVU networks)
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: FRITZ!Box AddOn - C:\Dokumente und Einstellungen\Herbert Klinzing\Anwendungsdaten\Mozilla\Firefox\Profiles\ob026rne.default\Extensions\fb_add_on@avm.de [2013-04-18]
FF Extension: Microsoft .NET Framework Assistant - C:\Dokumente und Einstellungen\Herbert Klinzing\Anwendungsdaten\Mozilla\Firefox\Profiles\ob026rne.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-10-07]
FF Extension: Default Full Zoom Level - C:\Dokumente und Einstellungen\Herbert Klinzing\Anwendungsdaten\Mozilla\Firefox\Profiles\ob026rne.default\Extensions\{D9A7CBEC-DE1A-444f-A092-844461596C4D} [2013-04-29]
FF Extension: PDF Download - C:\Dokumente und Einstellungen\Herbert Klinzing\Anwendungsdaten\Mozilla\Firefox\Profiles\ob026rne.default\Extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.xpi [2011-07-27]
FF Extension: Adblock Plus - C:\Dokumente und Einstellungen\Herbert Klinzing\Anwendungsdaten\Mozilla\Firefox\Profiles\ob026rne.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-07-11]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
========================== Services (Whitelisted) =================
S3 Adobe LM Service; C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-03-12] (Adobe Systems)
S4 AirPrint; C:\Program Files\AirPrint\Airprint.exe [234784 2011-12-01] (Apple Inc.)
R2 AntiVirSchedulerService; C:\Programme\Avira\AntiVir Desktop\sched.exe [440400 2014-02-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Programme\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-22] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device; C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55624 2013-09-07] (Apple Inc.)
R2 asComSvc; C:\Programme\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2012-06-01] ()
R2 asHmComSvc; C:\Programme\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2012-06-01] (ASUSTeK Computer Inc.)
R2 AsSysCtrlService; C:\Programme\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc.)
R2 AsusFanControlService; C:\Programme\ASUS\AsusFanControlService\1.01.10\AsusFanControlService.exe [1475744 2012-05-25] (ASUSTeK Computer Inc.)
S4 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [520192 2006-05-03] ()
S3 Autodesk Licensing Service; C:\Programme\Gemeinsame Dateien\Autodesk Shared\Service\AdskScSrv.exe [77944 2010-10-03] (Autodesk)
R2 AVM WLAN Connection Service; C:\Programme\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin)
R2 avmidentd; C:\Programme\FRITZ!Box-Kindersicherung\avmident.exe [49152 2006-08-21] (AVM Berlin)
R2 Bonjour Service; C:\Programme\Bonjour\mDNSResponder.exe [390504 2011-08-30] (Apple Inc.)
R2 C-DillaSrv; C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [46080 2010-09-27] (C-Dilla Ltd)
S4 DATEV Update-Service; C:\DATEV\PROGRAMM\INSTALL\DvInesASDSvc.Exe [172640 2011-07-25] (DATEV eG)
S4 Datev.Database.Conserve; C:\DATEV\SYSTEM\Datev.Framework.RemoteServiceModel.GenericService2010.exe [10848 2011-09-01] (DATEV eG)
S4 Datev.Framework.RemoteServiceModel.EnablerService; C:\DATEV\SYSTEM\Datev.Framework.RemoteServiceModel.GenericService2010.exe [10848 2011-09-01] (DATEV eG)
S4 Datev.Framework.RemoteServices; C:\DATEV\SYSTEM\Datev.Framework.RemoteServiceModel.GenericService2010.exe [10848 2011-09-01] (DATEV eG)
S4 Datev.Framework.RemoteServices.Messaging.CentralMessagingService; C:\DATEV\SYSTEM\Datev.Framework.RemoteServiceModel.GenericService2010.exe [10848 2011-09-01] (DATEV eG)
S3 gusvc; C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe [136120 2009-12-22] (Google)
R3 hpqcxs08; C:\Programme\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.)
R2 hpqddsvc; C:\Programme\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.)
S3 ICCS; C:\Programme\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160768 2011-05-27] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Programme\Intel\iCLS Client\HeciServer.exe [462048 2012-04-20] (Intel(R) Corporation)
R3 iPod Service; C:\Programme\iPod\bin\iPodService.exe [553288 2013-11-02] (Apple Inc.)
S4 JavaQuickStarterService; C:\Programme\Java\jre7\bin\jqs.exe [181664 2013-05-07] (Oracle Corporation)
R2 jhi_service; C:\Programme\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S3 LBTServ; C:\Programme\Gemeinsame Dateien\LogiShrd\Bluetooth\lbtserv.exe [293144 2013-06-13] (Logitech, Inc.)
R2 LMS; C:\Programme\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [277824 2012-07-17] (Intel Corporation)
S3 MatSvc; C:\Programme\Microsoft Fix it Center\Matsvc.exe [267568 2011-06-13] (Microsoft Corporation)
R2 MBAMScheduler; C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S4 MemeoBackgroundService; C:\Programme\WD\WD Anywhere Backup\MemeoBackgroundService.exe [25824 2008-11-07] (Memeo)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [118896 2014-02-06] (Mozilla Foundation)
S4 msftesql$DATEV_CL_DE01; C:\Programme\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe [91992 2010-03-26] (Microsoft Corporation)
S4 MSSQL$DATEV_CL_DE01; C:\Programme\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
S4 MSSQLServerADHelper; C:\Programme\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
S2 nvUpdatusService; C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [1266464 2013-02-10] (NVIDIA Corporation)
S3 odserv; C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE [440696 2011-07-20] (Microsoft Corporation)
S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [145184 2006-10-26] (Microsoft Corporation)
R2 Panasonic Trap Monitor Service; C:\Programme\Panasonic\TrapMonitor\Trapmnnt.exe [69632 2004-02-24] (Panasonic)
S3 ServiceLayer; C:\Programme\PC Connectivity Solution\ServiceLayer.exe [628736 2010-12-08] (Nokia)
S2 SkypeUpdate; C:\Programme\Skype\Updater\Updater.exe [171680 2013-09-05] (Skype Technologies)
R2 SpyHunter 4 Service; C:\Programme\Enigma Software Group\SpyHunter\SH4Service.exe [769920 2013-01-14] (Enigma Software Group USA, LLC.)
R2 SQLBrowser; C:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe [238944 2010-12-10] (Microsoft Corporation)
R2 SQLWriter; C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe [86880 2010-12-10] (Microsoft Corporation)
S4 TomTomHOMEService; C:\Programme\TomTom HOME 2\TomTomHOMEService.exe [93072 2013-03-22] (TomTom)
S3 TuneUp.Defrag; C:\WINDOWS\System32\TuneUpDefragService.exe [306432 2010-09-27] (TuneUp Software GmbH)
R2 UNS; C:\Programme\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [365376 2012-07-17] (Intel Corporation)
R2 VVWUpdateService; C:\Programme\VVW\Update\VVWUpdateDienst.exe [2013696 2013-07-17] ()
==================== Drivers (Whitelisted) ====================
S3 ALCXSENS; C:\WINDOWS\System32\drivers\ALCXSENS.SYS [400384 2004-02-24] (Sensaura)
S3 ALCXWDM; C:\WINDOWS\System32\drivers\ALCXWDM.SYS [4122368 2008-09-24] (Realtek Semiconductor Corp.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
R1 AsIO; C:\WINDOWS\System32\drivers\AsIO.sys [11456 2010-08-24] ()
R1 Aspi32; C:\WINDOWS\system32\Drivers\Aspi32.sys [17005 2003-05-28] (Adaptec)
R1 AsUpIO; C:\WINDOWS\System32\drivers\AsUpIO.sys [11832 2010-08-03] ()
S3 ATIAVAIW; C:\WINDOWS\System32\DRIVERS\atinavt2.sys [163968 2006-04-05] (ATI Technologies Inc.)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [90400 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [135648 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\System32\DRIVERS\avkmgr.sys [37352 2013-10-07] (Avira Operations GmbH & Co. KG)
R3 AVMCOWAN; C:\WINDOWS\System32\DRIVERS\AVMCOWAN.sys [53248 2004-11-24] (AVM GmbH)
S3 AVMWAN; C:\WINDOWS\System32\DRIVERS\avmwan.sys [37568 2001-08-17] (AVM GmbH)
S3 C-Dilla; C:\WINDOWS\system32\drivers\CDANT.SYS [58160 2010-09-27] (Macrovision)
S3 CardReaderFilter; C:\WINDOWS\system32\Drivers\USBCRFT.SYS [13440 2011-01-21] (ICSI Technology Ltd.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
S3 cpudrv; C:\Programme\SystemRequirementsLab\cpudrv.sys [11336 2011-06-02] ()
R3 esgiguard; C:\Programme\Enigma Software Group\SpyHunter\esgiguard.sys [13904 2011-05-06] ()
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2012-06-22] ()
R3 fpcibase; C:\WINDOWS\System32\DRIVERS\fpcibase.sys [548864 2004-11-24] (AVM Berlin)
S3 FWLANUSB; C:\WINDOWS\System32\DRIVERS\fwlanusb.sys [265088 2010-10-22] (AVM GmbH)
S3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2002-12-31] (Microsoft Corporation)
S3 gdrv; C:\WINDOWS\gdrv.sys [15600 2010-10-01] (Windows (R) 2000 DDK provider)
R3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-01-17] (HP)
R3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-01-17] (HP)
R3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2009-02-25] (HP)
R3 ICCWDT; C:\WINDOWS\System32\DRIVERS\ICCWDT.sys [22040 2012-05-17] (Intel Corporation)
R3 LEqdUsb; C:\WINDOWS\System32\Drivers\LEqdUsb.Sys [42264 2013-05-23] (Logitech, Inc.)
R3 LHidEqd; C:\WINDOWS\System32\Drivers\LHidEqd.Sys [10136 2013-05-23] (Logitech, Inc.)
S3 LHidUsb; C:\WINDOWS\System32\Drivers\LHidUsb.Sys [37887 2003-12-17] (Logitech, Inc.)
R3 LKbdFlt2; C:\WINDOWS\System32\DRIVERS\LKbdFlt2.sys [5838 2001-12-19] (Logitech)
S3 LUsbFilt; C:\WINDOWS\System32\Drivers\LUsbFilt.Sys [28624 2010-08-24] (Logitech, Inc.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 MEI; C:\WINDOWS\System32\DRIVERS\HECI.sys [55104 2012-07-02] (Intel Corporation)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
S3 MPE; C:\WINDOWS\System32\DRIVERS\MPE.sys [15232 2002-12-31] (Microsoft Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2002-12-31] (Microsoft Corporation)
R3 NVHDA; C:\WINDOWS\System32\drivers\nvhda32.sys [128440 2012-12-19] (NVIDIA Corporation)
R3 pfc; C:\WINDOWS\System32\drivers\pfc.sys [9856 2002-09-27] (Padus, Inc.)
S3 PRODIGY; C:\WINDOWS\System32\Drivers\PRODIGY.SYS [32377 2006-08-29] (B-phreaks)
S2 Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [73728 2001-06-21] (Rainbow Technologies, Inc.)
S3 Sntnlusb; C:\WINDOWS\System32\DRIVERS\SNTNLUSB.SYS [20032 2001-06-21] (Rainbow Technologies Inc.)
S4 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [431672 2013-01-15] (Duplex Secure Ltd.)
R1 ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [28520 2013-04-06] (Avira GmbH)
R2 StarOpen; C:\WINDOWS\system32\Drivers\StarOpen.sys [5504 2012-06-03] ()
S3 SynasUSB; C:\WINDOWS\System32\drivers\SynasUSB.sys [23288 2007-10-24] (SIA Syncrosoft)
S3 tap0901; C:\WINDOWS\System32\DRIVERS\tap0901.sys [25216 2010-02-25] (The OpenVPN Project)
S3 yukonwxp; C:\WINDOWS\System32\DRIVERS\yk51x86.sys [299424 2012-01-25] (Marvell)
S3 AtiHDAudioService; system32\drivers\AtihdXP3.sys [X]
S3 RTLVLANMP; system32\DRIVERS\RTLVLAN.SYS [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2002-12-31] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-05 15:16 - 2014-03-05 15:24 - 00027808 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\FRST.txt
2014-03-05 15:16 - 2014-03-05 15:17 - 00092496 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\Addition.txt
2014-03-05 15:15 - 2014-03-05 15:24 - 00000000 ____D () C:\FRST
2014-03-05 15:15 - 2014-03-05 15:15 - 01145344 _____ (Farbar) C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\FRST.exe
2014-03-05 15:01 - 2014-03-05 15:01 - 00002097 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\hjtscanlist.zip
2014-03-05 14:28 - 2014-03-05 14:28 - 03674597 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\SBE_dwg.zip
2014-03-05 09:17 - 2014-03-05 09:18 - 00001910 _____ () C:\AdwCleaner[S14].txt
2014-03-05 09:17 - 2014-03-05 09:17 - 00001847 _____ () C:\AdwCleaner[R30].txt
2014-03-05 09:13 - 2014-03-05 09:14 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\SpyHunter-Installer (1).exe
2014-03-05 09:12 - 2014-03-05 09:12 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\SpyHunter-Installer.exe
2014-03-03 19:04 - 2014-03-03 19:05 - 00000325 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\dimm-killasso.lisp.txt
2014-03-03 18:17 - 2014-03-03 18:17 - 00000000 ____D () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\ADT2006OE
2014-03-03 18:16 - 2014-03-03 18:16 - 06637102 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\ADT2006OE.zip
2014-03-03 18:11 - 2014-03-03 18:11 - 07947856 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\adt2006swlsp1deu.exe
2014-03-03 18:06 - 2014-03-03 18:06 - 01226130 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\MDT2006_OE.zip
2014-03-01 11:22 - 2008-04-14 07:52 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidserv.dll
2014-03-01 11:14 - 2014-03-01 11:14 - 03672832 _____ (Logitech Inc.) C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\setpoint6.61.15_smart.exe
2014-02-25 10:43 - 2014-02-25 10:43 - 00003646 _____ () C:\WINDOWS\KB2916036.log
2014-02-12 10:48 - 2014-02-12 10:48 - 00001066 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Desktop\Verknüpfung mit LVS_Honorarrichtlinie_Berechnungsblatt.xls.lnk
2014-02-11 12:02 - 2014-02-11 12:02 - 00006052 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\Wohnflaeche.zip
2014-02-11 12:02 - 2014-02-11 12:02 - 00006052 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\Wohnflaeche (1).zip
2014-02-11 11:56 - 2014-02-11 11:56 - 00008063 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\Wohnflaechenberechnung_95.zip
2014-02-11 11:38 - 2014-02-11 11:38 - 00040960 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\Wohnflaechenberechnung (3).xls
2014-02-11 11:37 - 2014-02-11 11:37 - 00006129 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\wohnflaechenberechnung.xls
2014-02-11 11:37 - 2014-02-11 11:37 - 00006129 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\wohnflaechenberechnung (2).xls
2014-02-11 11:37 - 2014-02-11 11:37 - 00006129 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\wohnflaechenberechnung (1).xls
2014-02-10 12:04 - 2014-02-10 12:04 - 00595456 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\Leibrenten-2009-2011Internet.xls
2014-02-07 12:53 - 2014-03-02 17:20 - 00078848 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\rechnung 2014.xls
2014-02-06 15:03 - 2014-02-06 15:03 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2914368$
2014-02-06 15:02 - 2014-02-06 15:03 - 00006592 _____ () C:\WINDOWS\KB2914368.log
2014-02-06 08:52 - 2014-03-02 11:12 - 00000000 ____D () C:\Programme\Mozilla Firefox
==================== One Month Modified Files and Folders =======
2014-03-05 15:24 - 2014-03-05 15:16 - 00027808 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\FRST.txt
2014-03-05 15:24 - 2014-03-05 15:15 - 00000000 ____D () C:\FRST
2014-03-05 15:17 - 2014-03-05 15:16 - 00092496 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\Addition.txt
2014-03-05 15:16 - 2002-12-31 13:00 - 00001068 _____ () C:\WINDOWS\win.ini
2014-03-05 15:15 - 2014-03-05 15:15 - 01145344 _____ (Farbar) C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\FRST.exe
2014-03-05 15:05 - 2013-02-19 10:10 - 00015658 _____ () C:\WINDOWS\system32\nvAppTimestamps
2014-03-05 15:01 - 2014-03-05 15:01 - 00002097 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\hjtscanlist.zip
2014-03-05 14:56 - 2012-03-12 19:02 - 00002459 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Desktop\HiJackThis.lnk
2014-03-05 14:28 - 2014-03-05 14:28 - 03674597 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\SBE_dwg.zip
2014-03-05 14:11 - 2013-09-24 19:12 - 00000000 ____D () C:\Dokumente und Einstellungen\Herbert Klinzing\Anwendungsdaten\Skype
2014-03-05 13:58 - 2010-09-25 12:42 - 00000000 ____D () C:\Programme\Opera
2014-03-05 13:05 - 2010-09-26 18:05 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-03-05 09:23 - 2011-09-21 10:00 - 00000434 _____ () C:\WINDOWS\system32\Drivers\etc\hosts.ics
2014-03-05 09:23 - 2002-12-31 13:00 - 00002300 _____ () C:\WINDOWS\system32\wpa.dbl
2014-03-05 09:22 - 2010-09-25 11:35 - 01657722 _____ () C:\WINDOWS\WindowsUpdate.log
2014-03-05 09:21 - 2010-09-25 11:18 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-03-05 09:21 - 2010-09-25 11:18 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2014-03-05 09:20 - 2013-10-14 15:57 - 00000000 _____ () C:\WINDOWS\system32\Drivers\lvuvc.hs
2014-03-05 09:20 - 2010-09-25 11:40 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-03-05 09:19 - 2010-09-25 11:40 - 00032554 _____ () C:\WINDOWS\SchedLgU.Txt
2014-03-05 09:18 - 2014-03-05 09:17 - 00001910 _____ () C:\AdwCleaner[S14].txt
2014-03-05 09:18 - 2010-09-25 11:41 - 00000300 ___SH () C:\Dokumente und Einstellungen\Herbert Klinzing\ntuser.ini
2014-03-05 09:18 - 2010-09-25 11:41 - 00000000 ____D () C:\Dokumente und Einstellungen\Herbert Klinzing
2014-03-05 09:17 - 2014-03-05 09:17 - 00001847 _____ () C:\AdwCleaner[R30].txt
2014-03-05 09:14 - 2014-03-05 09:13 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\SpyHunter-Installer (1).exe
2014-03-05 09:13 - 2010-09-25 11:13 - 00000000 ___RD () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme
2014-03-05 09:12 - 2014-03-05 09:12 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\SpyHunter-Installer.exe
2014-03-05 05:57 - 2010-09-28 15:59 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
2014-03-05 05:51 - 2010-09-25 11:32 - 00000000 ____D () C:\WINDOWS\Registration
2014-03-05 01:10 - 2013-07-08 21:14 - 00000400 _____ () C:\WINDOWS\Tasks\SpyHunter4.job
2014-03-04 18:01 - 2013-07-18 16:47 - 00000000 ____D () C:\Dokumente und Einstellungen\Herbert Klinzing\.dreamstream
2014-03-04 10:09 - 2013-02-18 11:41 - 00851968 _____ () C:\WINDOWS\system32\iuc751.dll
2014-03-04 09:49 - 2010-09-27 16:20 - 00000000 ____D () C:\Programme\PalladioX5
2014-03-04 08:48 - 2012-12-13 05:35 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2653956$
2014-03-03 19:05 - 2014-03-03 19:04 - 00000325 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\dimm-killasso.lisp.txt
2014-03-03 18:17 - 2014-03-03 18:17 - 00000000 ____D () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\ADT2006OE
2014-03-03 18:17 - 2010-10-04 09:31 - 00000000 ____D () C:\Programme\Autodesk Architectural Desktop 2006
2014-03-03 18:17 - 2010-09-27 14:58 - 00000000 ____D () C:\Programme\Gemeinsame Dateien\Autodesk Shared
2014-03-03 18:16 - 2014-03-03 18:16 - 06637102 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\ADT2006OE.zip
2014-03-03 18:11 - 2014-03-03 18:11 - 07947856 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\adt2006swlsp1deu.exe
2014-03-03 18:06 - 2014-03-03 18:06 - 01226130 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\MDT2006_OE.zip
2014-03-02 17:20 - 2014-02-07 12:53 - 00078848 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\rechnung 2014.xls
2014-03-02 16:13 - 2010-09-26 09:30 - 00002537 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Desktop\Microsoft Office Excel 2003.lnk
2014-03-02 11:12 - 2014-02-06 08:52 - 00000000 ____D () C:\Programme\Mozilla Firefox
2014-03-01 11:48 - 2010-09-26 09:30 - 00002509 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Desktop\Microsoft Office Word 2003.lnk
2014-03-01 11:22 - 2013-11-15 17:40 - 00061218 _____ () C:\WINDOWS\setupapi.log
2014-03-01 11:22 - 2010-11-23 12:38 - 00011779 _____ () C:\WINDOWS\LkmdfCoInst.log
2014-03-01 11:22 - 2010-09-25 11:12 - 00120008 _____ () C:\WINDOWS\setupact.log
2014-03-01 11:19 - 2010-11-23 12:37 - 00105943 _____ () C:\WINDOWS\LDPINST.LOG
2014-03-01 11:19 - 2010-11-23 12:37 - 00000000 ____D () C:\Programme\Gemeinsame Dateien\LogiShrd
2014-03-01 11:19 - 2010-09-25 11:54 - 00000000 ____D () C:\WINDOWS\system32\ReinstallBackups
2014-03-01 11:18 - 2010-11-23 12:38 - 00016400 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys
2014-03-01 11:18 - 2010-11-23 12:37 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Logishrd
2014-03-01 11:18 - 2010-10-07 13:00 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Logitech
2014-03-01 11:18 - 2010-10-07 12:59 - 00000000 ____D () C:\Programme\Logitech
2014-03-01 11:14 - 2014-03-01 11:14 - 03672832 _____ (Logitech Inc.) C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\setpoint6.61.15_smart.exe
2014-02-28 17:15 - 2012-03-25 14:35 - 00000410 _____ () C:\WINDOWS\Tasks\Automatische Wartung.job
2014-02-27 21:51 - 2011-06-04 11:55 - 00000276 _____ () C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2014-02-26 17:04 - 2010-09-26 10:03 - 00001867 _____ () C:\WINDOWS\CIPERT.INI
2014-02-25 10:43 - 2014-02-25 10:43 - 00003646 _____ () C:\WINDOWS\KB2916036.log
2014-02-25 09:53 - 2010-09-29 10:34 - 00000000 ____D () C:\SFIRM32_xp
2014-02-25 09:39 - 2012-07-29 16:51 - 00002607 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Desktop\Microsoft Office Outlook 2003.lnk
2014-02-25 09:28 - 2010-11-26 20:46 - 00000000 __SHD () C:\WINDOWS\CSC
2014-02-25 09:28 - 2010-09-25 11:12 - 00373672 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-02-24 19:47 - 2010-09-25 12:32 - 00109312 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT
2014-02-24 19:42 - 2010-09-25 13:27 - 00000000 ____D () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\Bauantragsformulare 2010+
2014-02-24 18:12 - 2013-01-18 13:47 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft Help
2014-02-24 18:11 - 2013-01-18 13:58 - 00002503 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Desktop\Microsoft Office Word 2007.lnk
2014-02-24 16:32 - 2010-09-28 10:02 - 00000116 _____ () C:\WINDOWS\NeroDigital.ini
2014-02-24 15:29 - 2010-09-28 16:09 - 00000162 _____ () C:\WINDOWS\ccolwiz.ini
2014-02-23 18:30 - 2013-04-11 17:44 - 00000222 _____ () C:\mb.err
2014-02-23 16:56 - 2011-02-22 15:12 - 00000000 ____D () C:\Dokumente und Einstellungen\Herbert Klinzing\Desktop\Scan
2014-02-23 10:13 - 2010-09-30 17:37 - 00000195 _____ () C:\WINDOWS\hpbafd.ini
2014-02-23 10:13 - 2010-09-25 11:41 - 00000000 ___HD () C:\Dokumente und Einstellungen\Herbert Klinzing\Netzwerkumgebung
2014-02-22 11:50 - 2010-10-03 15:47 - 3725127680 _____ () C:\WINDOWS\MEMORY.DMP
2014-02-13 14:35 - 2013-09-24 19:12 - 00002243 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Skype.lnk
2014-02-12 10:48 - 2014-02-12 10:48 - 00001066 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Desktop\Verknüpfung mit LVS_Honorarrichtlinie_Berechnungsblatt.xls.lnk
2014-02-11 12:02 - 2014-02-11 12:02 - 00006052 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\Wohnflaeche.zip
2014-02-11 12:02 - 2014-02-11 12:02 - 00006052 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\Wohnflaeche (1).zip
2014-02-11 11:56 - 2014-02-11 11:56 - 00008063 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\Wohnflaechenberechnung_95.zip
2014-02-11 11:38 - 2014-02-11 11:38 - 00040960 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\Wohnflaechenberechnung (3).xls
2014-02-11 11:37 - 2014-02-11 11:37 - 00006129 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\wohnflaechenberechnung.xls
2014-02-11 11:37 - 2014-02-11 11:37 - 00006129 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\wohnflaechenberechnung (2).xls
2014-02-11 11:37 - 2014-02-11 11:37 - 00006129 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\wohnflaechenberechnung (1).xls
2014-02-10 17:20 - 2010-09-25 13:49 - 00000000 ____D () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\Eigene Scans
2014-02-10 12:04 - 2014-02-10 12:04 - 00595456 _____ () C:\Dokumente und Einstellungen\Herbert Klinzing\Eigene Dateien\Leibrenten-2009-2011Internet.xls
2014-02-07 16:06 - 2011-01-14 17:56 - 00002375 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Projekt-Manager 2008.lnk
2014-02-06 15:12 - 2012-04-26 10:04 - 00000000 ____D () C:\Programme\Mozilla Maintenance Service
2014-02-06 15:09 - 2013-12-11 09:09 - 00021308 _____ () C:\WINDOWS\KB2898785-IE8.log
2014-02-06 15:06 - 2013-07-26 02:00 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-02-06 15:03 - 2014-02-06 15:03 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2914368$
2014-02-06 15:03 - 2014-02-06 15:02 - 00006592 _____ () C:\WINDOWS\KB2914368.log
2014-02-06 15:03 - 2010-09-25 12:32 - 83425928 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-02-06 15:03 - 2010-09-25 11:14 - 04404689 _____ () C:\WINDOWS\FaxSetup.log
2014-02-06 15:03 - 2010-09-25 11:14 - 02236090 _____ () C:\WINDOWS\ocgen.log
2014-02-06 15:03 - 2010-09-25 11:14 - 02078360 _____ () C:\WINDOWS\tsoc.log
2014-02-06 15:03 - 2010-09-25 11:14 - 01526970 _____ () C:\WINDOWS\iis6.log
2014-02-06 15:03 - 2010-09-25 11:14 - 01445248 _____ () C:\WINDOWS\msmqinst.log
2014-02-06 15:03 - 2010-09-25 11:14 - 00877725 _____ () C:\WINDOWS\ntdtcsetup.log
2014-02-06 15:03 - 2010-09-25 11:14 - 00771218 _____ () C:\WINDOWS\netfxocm.log
2014-02-06 15:03 - 2010-09-25 11:14 - 00390432 _____ () C:\WINDOWS\comsetup.log
2014-02-06 15:03 - 2010-09-25 11:14 - 00315496 _____ () C:\WINDOWS\MedCtrOC.log
2014-02-06 15:03 - 2010-09-25 11:14 - 00225803 _____ () C:\WINDOWS\ocmsn.log
2014-02-06 15:03 - 2010-09-25 11:14 - 00223219 _____ () C:\WINDOWS\msgsocm.log
2014-02-06 15:03 - 2010-09-25 11:14 - 00222116 _____ () C:\WINDOWS\tabletoc.log
2014-02-06 15:03 - 2010-09-25 11:14 - 00001355 _____ () C:\WINDOWS\imsins.log
2014-02-06 08:53 - 2010-09-25 11:14 - 00000000 ___RD () C:\Programme
Files to move or delete:
====================
C:\Dokumente und Einstellungen\Herbert Klinzing\preV14.dll
C:\Dokumente und Einstellungen\Herbert Klinzing\preV93.dll
Some content of TEMP:
====================
C:\Dokumente und Einstellungen\Herbert Klinzing\Lokale Einstellungen\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe
[2002-12-31 13:00] - [2002-12-31 13:00] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\WINDOWS\system32\winlogon.exe
[2002-12-31 13:00] - [2002-12-31 13:00] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\WINDOWS\system32\svchost.exe
[2002-12-31 13:00] - [2002-12-31 13:00] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\WINDOWS\system32\services.exe
[2002-12-31 13:00] - [2009-02-09 12:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\WINDOWS\system32\User32.dll
[2002-12-31 13:00] - [2002-12-31 13:00] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\WINDOWS\system32\userinit.exe
[2002-12-31 13:00] - [2002-12-31 13:00] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\WINDOWS\system32\rpcss.dll
[2002-12-31 13:00] - [2009-02-09 11:51] - 0401408 ____A (Microsoft Corporation) 3127afbf2c1ed0ab14a1bbb7aaecb85b
ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected.
C:\WINDOWS\system32\Drivers\volsnap.sys
[2002-12-31 13:00] - [2002-12-31 13:00] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================ --- --- --- |