powersearche | 27.06.2010 19:10 | Hallo Larusso,
vielen dank für die schnelle Antwort.
Ich habe/hatte vor meine Daten zu sichern und mir in den nächsten Wochen eine neue Festplatte zu besorgen.
Leider kam mir der Virus ein bißchen zu früh in die Quere und ich weiss nicht ob ich mir beim letzten Backup, auf der externen Festplatte, den Burschen mit gesichert habe.
Anbei die gewünschten Logfiles, ich hoffe ich hab alles richtig gemacht.
Wenn nicht einfach meckern :aufsmaul::lach:
Grüße powersearcher
Ich musste beide Files einzeln posten da sie zu groß sind
OTL Logfile: Code:
OTL logfile created on: 27.06.2010 19:24:25 - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Users\Mark\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 63,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 63,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 269,41 Gb Total Space | 28,68 Gb Free Space | 10,64% Space Free | Partition Type: NTFS
Drive D: | 28,67 Gb Total Space | 21,27 Gb Free Space | 74,21% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive L: | 246,71 Mb Total Space | 118,01 Mb Free Space | 47,83% Space Free | Partition Type: FAT
Computer Name: MARK
Current User Name: Mark
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010.06.27 19:20:03 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\Mark\Downloads\OTL.exe
PRC - [2010.06.19 12:49:24 | 000,864,112 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010.06.19 12:49:23 | 001,352,832 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010.06.10 21:03:08 | 000,144,176 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010.03.28 16:47:30 | 000,246,520 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
PRC - [2010.02.21 05:03:12 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2009.12.09 18:02:38 | 000,017,904 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009.08.18 11:29:22 | 001,529,728 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2009.08.18 11:29:22 | 000,183,152 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2009.08.14 04:15:56 | 000,356,352 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2009.08.14 04:15:28 | 000,172,032 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2009.08.05 21:19:33 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009.07.24 16:05:24 | 000,139,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2009.05.13 16:48:18 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009.04.11 08:27:58 | 001,169,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sdclt.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.03.02 13:08:43 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2009.02.19 00:33:08 | 000,809,488 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2009.02.19 00:28:52 | 000,076,304 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
PRC - [2009.01.26 15:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008.10.24 15:35:44 | 000,128,296 | ---- | M] () -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
PRC - [2008.04.03 20:37:36 | 000,835,584 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe
PRC - [2008.02.19 09:22:08 | 001,089,536 | R--- | M] (Brother Industries, Ltd.) -- C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
PRC - [2008.01.31 18:29:06 | 000,196,608 | R--- | M] (Brother Industries, Ltd.) -- C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe
PRC - [2008.01.22 13:21:44 | 000,259,368 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NeroGadgetCMServer.exe
PRC - [2007.05.12 21:46:38 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2007.02.23 12:17:50 | 001,509,888 | ---- | M] (Buhl Data Service GmbH) -- C:\Program Files\Sceneo\Bonavista\Services\PVR\pvrservice.exe
PRC - [2007.02.08 20:14:26 | 000,299,093 | ---- | M] () -- C:\Program Files\Home Cinema\TV Enhance\Kernel\TV\TVECapSvc.exe
PRC - [2007.02.08 20:14:26 | 000,127,059 | ---- | M] () -- C:\Program Files\Home Cinema\TV Enhance\Kernel\TV\TVESched.exe
PRC - [2006.12.01 14:37:50 | 004,186,112 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2006.10.23 14:50:35 | 000,046,640 | R--- | M] (AOL LLC) -- C:\Program Files\Common Files\aol\acs\AOLacsd.exe
PRC - [2005.04.02 03:51:48 | 000,217,600 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
PRC - [2003.04.30 02:14:00 | 000,264,192 | ---- | M] (SCM Microsystems) -- C:\Windows\SCARDS32.EXE
PRC - [2001.11.12 14:31:48 | 000,020,480 | ---- | M] (X10) -- C:\Program Files\Common Files\X10\Common\X10nets.exe
========== Modules (SafeList) ==========
MOD - [2010.06.27 19:20:03 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\Mark\Downloads\OTL.exe
MOD - [2009.04.11 08:21:38 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008.01.19 09:33:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - [2010.06.19 12:49:23 | 001,352,832 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010.06.10 21:03:08 | 000,144,176 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010.03.28 16:47:30 | 000,246,520 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2010.03.18 13:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.12.09 18:02:38 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2009.09.25 03:27:04 | 000,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009.08.18 11:29:22 | 001,529,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2009.08.14 04:15:28 | 000,172,032 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2009.08.05 21:19:33 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009.07.24 16:05:24 | 000,139,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)
SRV - [2009.06.02 10:10:08 | 000,637,952 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2009.05.13 16:48:18 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2009.02.19 00:30:20 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008.10.24 15:35:44 | 000,128,296 | ---- | M] () [Auto | Running] -- C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe -- (AAV UpdateService)
SRV - [2008.01.19 09:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.02.23 12:17:50 | 001,509,888 | ---- | M] (Buhl Data Service GmbH) [Auto | Running] -- C:\Program Files\Sceneo\Bonavista\Services\PVR\pvrservice.exe -- (srvcPVR)
SRV - [2007.02.08 20:14:26 | 000,299,093 | ---- | M] () [Auto | Running] -- C:\Program Files\Home Cinema\TV Enhance\Kernel\TV\TVECapSvc.exe -- (TVECapSvc) TVEnhance Background Capture Service (TBCS)
SRV - [2007.02.08 20:14:26 | 000,127,059 | ---- | M] () [Auto | Running] -- C:\Program Files\Home Cinema\TV Enhance\Kernel\TV\TVESched.exe -- (TVESched) TVEnhance Task Scheduler (TTS))
SRV - [2006.10.23 14:50:35 | 000,046,640 | R--- | M] (AOL LLC) [Auto | Running] -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe -- (AOL ACS)
SRV - [2005.11.17 15:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\ALDI Sued Foto Service\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2005.04.02 03:51:48 | 000,217,600 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe -- (StarWindService)
SRV - [2003.04.30 02:14:00 | 000,264,192 | ---- | M] (SCM Microsystems) [Auto | Running] -- C:\Windows\SCARDS32.EXE -- (TWKSCARDSRV)
SRV - [2001.11.12 14:31:48 | 000,020,480 | ---- | M] (X10) [Auto | Running] -- C:\Program Files\Common Files\X10\Common\X10nets.exe -- (x10nets)
========== Driver Services (SafeList) ==========
DRV - [2010.06.19 12:49:34 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2009.12.07 22:32:26 | 000,056,816 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009.12.02 15:23:40 | 000,149,040 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\MpFilter.sys -- (MpFilter)
DRV - [2009.12.02 15:23:40 | 000,042,368 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\MpNWMon.sys -- (MpNWMon)
DRV - [2009.09.30 16:31:46 | 000,103,440 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2009.08.14 06:29:28 | 005,172,224 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2009.08.14 06:29:28 | 005,172,224 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2009.07.24 20:28:50 | 000,030,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nx6000.sys -- (MSHUSBVideo)
DRV - [2009.07.19 11:28:31 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2009.07.19 11:28:31 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2009.05.11 10:12:20 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.04.11 06:42:54 | 000,073,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\USBAUDIO.sys -- (usbaudio) USB-Audiotreiber (WDM)
DRV - [2009.03.30 10:33:03 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2009.02.13 12:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009.02.09 08:37:56 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2009.02.09 08:37:48 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2009.02.09 08:37:46 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2009.02.09 08:37:46 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2009.01.27 16:37:01 | 000,101,376 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\ACEDRV07.sys -- (ACEDRV07)
DRV - [2008.12.18 23:44:00 | 000,028,816 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2008.12.18 23:43:48 | 000,037,392 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2008.12.18 23:43:40 | 000,035,472 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2008.12.16 16:48:40 | 000,021,144 | ---- | M] (VIA Technologies,Inc) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\xfilt.sys -- (xfilt)
DRV - [2008.12.16 16:47:00 | 000,013,976 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\videX32.sys -- (videX32)
DRV - [2008.10.31 09:11:02 | 000,027,184 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VL807.sys -- (VL807)
DRV - [2008.10.31 09:11:02 | 000,018,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\GWHid.sys -- (GWHid)
DRV - [2008.10.23 19:50:01 | 000,018,816 | ---- | M] (RIF) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dvd43llh.sys -- (dvd43llh)
DRV - [2008.09.17 09:55:00 | 007,379,872 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008.08.26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.07.30 07:51:30 | 000,277,736 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2008.02.20 21:42:36 | 000,020,520 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2008.02.20 21:42:36 | 000,013,352 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggflt.sys -- (ggflt)
DRV - [2008.01.19 07:53:31 | 000,045,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\61883.sys -- (61883)
DRV - [2008.01.19 07:53:31 | 000,040,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\avc.sys -- (Avc)
DRV - [2008.01.19 07:53:28 | 000,052,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\msdv.sys -- (MSDV)
DRV - [2008.01.14 12:06:32 | 000,021,632 | ---- | M] (ManyCam LLC.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ManyCam.sys -- (ManyCam)
DRV - [2007.10.03 20:55:38 | 000,639,224 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2007.07.27 12:46:06 | 000,251,680 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acehlp10.sys -- (acehlp10)
DRV - [2007.07.27 10:13:08 | 000,330,144 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\ACEDRV10.sys -- (acedrv10)
DRV - [2007.05.17 09:45:51 | 000,079,488 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k750obex.sys -- (k750obex)
DRV - [2007.05.17 09:45:50 | 000,081,728 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k750mgmt.sys -- (k750mgmt)
DRV - [2007.05.17 09:45:49 | 000,089,872 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k750mdm.sys -- (k750mdm)
DRV - [2007.05.17 09:45:49 | 000,006,576 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k750mdfl.sys -- (k750mdfl)
DRV - [2007.05.11 17:40:42 | 000,329,728 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netr73.sys -- (netr73)
DRV - [2007.04.11 16:33:06 | 000,079,376 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouKE.Sys -- (LMouKE)
DRV - [2007.04.11 16:32:38 | 000,063,248 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\L8042mou.Sys -- (L8042mou)
DRV - [2007.04.11 16:32:30 | 000,020,496 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2007.04.03 11:43:28 | 001,131,136 | ---- | M] (Philips Semiconductors GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Ph3xIB32.sys -- (Ph3xIB32)
DRV - [2007.01.08 19:43:40 | 001,136,600 | ---- | M] (Philips Semiconductors GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\3xHybrid.sys -- (3xHybrid)
DRV - [2006.12.01 14:38:58 | 001,655,464 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006.11.30 16:18:18 | 000,027,416 | ---- | M] (X10 Wireless Technology, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\x10ufx2.sys -- (XUIF)
DRV - [2006.11.30 00:24:57 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - [2006.11.17 11:31:04 | 000,013,976 | ---- | M] (X10 Wireless Technology, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\x10hid.sys -- (X10Hid)
DRV - [2006.11.02 11:51:45 | 000,900,712 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2006.11.02 11:51:38 | 000,420,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2006.11.02 11:51:34 | 000,316,520 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2006.11.02 11:51:32 | 000,297,576 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2006.11.02 11:51:25 | 000,235,112 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2006.11.02 11:51:00 | 000,147,048 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2006.11.02 11:50:45 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2006.11.02 11:50:41 | 000,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2006.11.02 11:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006.11.02 11:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006.11.02 11:50:35 | 000,098,408 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2006.11.02 11:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2006.11.02 11:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006.11.02 11:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006.11.02 11:50:16 | 000,071,784 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2006.11.02 11:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006.11.02 11:50:10 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2006.11.02 11:50:10 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2006.11.02 11:50:10 | 000,038,504 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2)
DRV - [2006.11.02 11:50:10 | 000,037,480 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2006.11.02 11:50:09 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2006.11.02 11:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006.11.02 11:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006.11.02 11:50:05 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2006.11.02 11:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006.11.02 11:50:04 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2006.11.02 11:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006.11.02 11:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006.11.02 11:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006.11.02 11:49:53 | 000,028,776 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2006.11.02 11:49:30 | 000,017,512 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2006.11.02 11:49:28 | 000,016,488 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2006.11.02 11:49:20 | 000,014,952 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2006.11.02 10:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006.11.02 10:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006.11.02 10:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006.11.02 10:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006.11.02 10:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006.11.02 10:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006.11.02 09:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006.11.02 09:30:54 | 000,117,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R)
DRV - [2006.08.28 15:48:46 | 000,004,352 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\TF0801.sys -- (TF0801)
DRV - [2006.08.11 15:47:13 | 000,059,776 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfsync04.sys -- (sfsync04) StarForce Protection Synchronization Driver (version 4.x)
DRV - [2006.07.05 14:46:06 | 000,063,352 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfdrv01a.sys -- (sfdrv01a) StarForce Protection Environment Driver (version 1.x.a)
DRV - [2006.06.14 16:56:56 | 000,013,680 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2005.09.19 03:07:00 | 000,035,275 | ---- | M] (SCM Microsystems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TwkUsb2K.sys -- (CHIPDRIVE USB SmartCardReader)
DRV - [2005.02.11 11:19:20 | 000,055,216 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k750bus.sys -- (k750bus) Sony Ericsson 750 driver (WDM)
DRV - [2004.08.25 15:06:00 | 000,185,611 | ---- | M] (SCM Microsystems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TWKSER2K.sys -- (TWKSER2K)
DRV - [2003.04.30 02:14:00 | 000,011,676 | ---- | M] (Towitoko AG) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\TWKPCSC.SYS -- (TwkPCSC)
DRV - [2003.04.30 02:14:00 | 000,005,550 | ---- | M] (Towitoko AG) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TWKPNP.SYS -- (TWKPNP)
DRV - [2003.04.30 02:14:00 | 000,004,828 | ---- | M] (Towitoko AG) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\TWKMS.SYS -- (TwkMs)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.arcor.de/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://start.icq.com/"
FF - prefs.js..extensions.enabledItems: pagehacker-nico@nc:1.2
FF - prefs.js..extensions.enabledItems: fastYoutubeDownloader@yevgenyandrov.net:1.1
FF - prefs.js..extensions.enabledItems: smarterwiki@wikiatic.com:4.0.3
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - HKLM\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009.10.18 22:48:23 | 000,000,000 | ---D | M]
[2010.05.08 16:32:19 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\mozilla\Extensions
[2010.05.08 18:24:02 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\mozilla\Firefox\Profiles\a6mz7ae3.default\extensions
[2010.05.08 16:34:43 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Mark\AppData\Roaming\mozilla\Firefox\Profiles\a6mz7ae3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.05.08 18:22:00 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\mozilla\Firefox\Profiles\a6mz7ae3.default\extensions\fastYoutubeDownloader@yevgenyandrov.net
[2010.05.08 18:14:03 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\mozilla\Firefox\Profiles\a6mz7ae3.default\extensions\pagehacker-nico@nc
[2010.05.08 18:24:00 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\mozilla\Firefox\Profiles\a6mz7ae3.default\extensions\smarterwiki@wikiatic.com
[2010.02.03 15:37:50 | 000,000,947 | ---- | M] () -- C:\Users\Mark\AppData\Roaming\Mozilla\FireFox\Profiles\a6mz7ae3.default\searchplugins\icqplugin.xml
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: &AOL Toolbar-Suche - c:\Program Files\AOL\AOL Toolbar 4.0\resources\de-DE\local\search.html ()
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: eBay - Der weltweite Online-Marktplatz - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - File not found
O9 - Extra 'Tools' menuitem : eBay - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - File not found
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/jordan-canvasx.cab (JordanUploader Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27-0.cab (EPUImageControl Class)
O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} https://as.photoprintit.de/ips-opdata/layout/default_cms01/activex/IPSUploader4.cab (IPSUploader4 Control)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D441AB53-A39C-42AE-AB79-3C05B7298F34} hxxp://aolsvc.aol.com/onlinegames/free-trial-astro-avenger-ii/AstroAvenger2Loader.cab (AstroAvengerLoader Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img36.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img36.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0698e888-1677-11dc-813b-0019db5a3837}\Shell - "" = AutoRun
O33 - MountPoints2\{0698e888-1677-11dc-813b-0019db5a3837}\Shell\AutoRun\command - "" = K:\Autorun.exe -- File not found
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\pcwstart.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008.03.19 22:16:58 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
MsConfig - StartUpFolder: C:^Users^Mark^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Media Player.lnk - C:\PROGRA~1\ADOBEM~1\ADOBEM~1.EXE - File not found
MsConfig - StartUpReg: swg - hkey= - key= - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 90 Days ==========
[2010.06.27 08:22:59 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010.06.27 08:18:12 | 000,000,000 | ---D | C] -- C:\Windows\LastGood.Tmp
[2010.06.27 08:16:33 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010.06.27 08:13:11 | 000,000,000 | ---D | C] -- C:\Program Files\Safari
[2010.06.27 08:12:02 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2010.06.27 06:14:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2010.06.27 06:14:54 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010.06.26 19:37:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010.06.19 12:50:00 | 000,064,288 | ---- | C] (Lavasoft AB) -- C:\Windows\System32\drivers\Lbd.sys
[2010.06.19 12:45:52 | 000,000,000 | -H-D | C] -- C:\ProgramData\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010.06.19 10:48:48 | 000,095,024 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2010.06.19 10:42:32 | 097,364,760 | ---- | C] (Lavasoft ) -- C:\Users\Mark\Desktop\Ad-AwareInstaller.exe
[2010.06.19 10:24:08 | 000,000,000 | ---D | C] -- C:\Program Files\CodeStuff
[2010.05.20 17:33:02 | 000,000,000 | R--D | C] -- C:\Users\Mark\AppData\Roaming\Brother
[2010.05.14 19:45:38 | 000,000,000 | ---D | C] -- C:\Users\Mark\Documents\Meine empfangenen Dateien
[2010.05.14 19:06:46 | 000,000,000 | ---D | C] -- C:\Users\Mark\Tracing
[2010.05.14 19:05:54 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
[2010.05.14 19:05:34 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2010.05.14 18:21:55 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ6Toolbar
[2010.05.14 18:21:46 | 000,000,000 | ---D | C] -- C:\ProgramData\ICQ
[2010.05.14 18:21:32 | 000,000,000 | ---D | C] -- C:\Users\MarkAppData\Roaming\ICQ
[2010.05.14 18:21:23 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ7.1
[2010.05.08 21:00:56 | 003,879,288 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Users\Mark\Desktop\procexp.exe
[2010.05.08 16:32:14 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\Mozilla
[2010.05.08 13:20:53 | 000,000,000 | ---D | C] -- C:\Users\Mark\Desktop\zerstörer
[2010.04.28 13:32:45 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010.04.28 13:28:54 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010.04.19 20:24:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010.04.19 20:24:10 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 90 Days ==========
[2010.06.27 19:26:00 | 000,000,436 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{F1A883CC-8CB1-4FC9-AFF7-A13F8DC58013}.job
[2010.06.27 19:25:24 | 004,718,592 | -HS- | M] () -- C:\Users\Mark\ntuser.dat
[2010.06.27 19:24:07 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010.06.27 19:24:07 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010.06.27 19:17:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.06.27 17:40:56 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.06.27 17:40:56 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.06.27 10:23:53 | 000,012,466 | ---- | M] () -- C:\Users\Mark\Documents\hijackthis2
[2010.06.27 09:45:37 | 000,638,510 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2010.06.27 09:45:37 | 000,604,126 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010.06.27 09:45:37 | 000,107,562 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010.06.27 09:45:36 | 001,472,290 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010.06.27 09:45:36 | 000,130,462 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2010.06.27 09:41:17 | 000,000,328 | ---- | M] () -- C:\Windows\scardsrv.ini
[2010.06.27 09:41:11 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2010.06.27 09:40:56 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.06.27 09:40:23 | 2145,902,592 | -HS- | M] () -- C:\hiberfil.sys
[2010.06.27 09:38:36 | 000,524,288 | -HS- | M] () -- C:\Users\Mark\ntuser.dat{b12478a5-4b05-11df-8729-00038a000015}.TMContainer00000000000000000001.regtrans-ms
[2010.06.27 09:38:36 | 000,065,536 | -HS- | M] () -- C:\Users\Mark\ntuser.dat{b12478a5-4b05-11df-8729-00038a000015}.TM.blf
[2010.06.27 09:38:33 | 006,291,456 | -H-- | M] () -- C:\Users\Mark\AppData\Local\IconCache.db
[2010.06.27 08:23:57 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010.06.27 08:13:20 | 000,001,854 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
[2010.06.27 06:15:37 | 000,001,019 | ---- | M] () -- C:\Users\Mark\Desktop\Spybot - Search & Destroy.lnk
[2010.06.27 06:15:33 | 000,126,464 | ---- | M] () -- C:\Users\Mark\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.06.26 19:37:56 | 000,000,904 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010.06.19 12:49:54 | 000,015,880 | ---- | M] () -- C:\Windows\System32\lsdelete.exe
[2010.06.19 12:49:34 | 000,064,288 | ---- | M] (Lavasoft AB) -- C:\Windows\System32\drivers\Lbd.sys
[2010.06.19 12:45:50 | 000,000,979 | ---- | M] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2010.06.19 11:25:08 | 000,031,858 | ---- | M] () -- C:\Users\Mark\Documents\cc_20100619_112435.reg
[2010.06.19 10:48:46 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2010.06.19 10:42:37 | 097,364,760 | ---- | M] (Lavasoft ) -- C:\Users\Mark\Desktop\Ad-AwareInstaller.exe
[2010.06.19 10:24:08 | 000,001,828 | ---- | M] () -- C:\Users\Mark\Desktop\CodeStuff Starter.lnk
[2010.06.19 10:23:34 | 000,680,340 | ---- | M] () -- C:\Users\Mark\Desktop\StarterSetup5629.zip
[2010.06.18 15:45:59 | 006,049,493 | ---- | M] () -- C:\Users\Mark\Desktop\K'naan - Wavin flag (WM 2010).mp3
[2010.06.18 15:41:35 | 004,910,972 | ---- | M] () -- C:\Users\Mar\Desktop\Shakira - waka waka.mp3
[2010.06.18 15:38:04 | 003,998,149 | ---- | M] () -- C:\Users\Mark\Desktop\Bushido feat. Kay One - Fackeln im Wind.mp3
[2010.06.10 21:23:15 | 000,419,040 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010.06.09 20:58:49 | 000,021,478 | ---- | M] () -- C:\Users\Mark\Documents\Trainingsplan Juni. 10.xlsx
[2010.06.02 20:43:27 | 000,036,864 | ---- | M] () -- C:\Users\Mark\Documents\Trainingsplan Apr. 10.xls
[2010.05.20 22:10:56 | 039,109,498 | ---- | M] () -- C:\Users\Mark\Documents\Jahresprogramm_webPDF.pdf
[2010.05.20 17:05:02 | 000,002,591 | ---- | M] () -- C:\Users\Mark\Desktop\Microsoft Office Word 2007.lnk
[2010.05.18 21:41:06 | 000,967,680 | ---- | M] () -- C:\Users\Mark\Desktop\.doc
[2010.05.14 18:19:53 | 000,000,033 | ---- | M] () -- C:\Users\Mark\Desktop\cmd.php
[2010.05.08 21:00:49 | 001,728,943 | ---- | M] () -- C:\Users\Mark\Desktop\ProcessExplorer.zip
[2010.05.08 20:56:30 | 000,000,953 | ---- | M] () -- C:\Users\Mark\Desktop\Internet Explorer.lnk
[2010.05.08 13:46:40 | 214,923,128 | ---- | M] () -- C:\Users\Mark\Desktop\clip0028.avi
[2010.05.08 13:44:04 | 010,238,098 | ---- | M] () -- C:\Users\Mark\Desktop\clip0027.avi
[2010.05.08 13:43:30 | 350,131,300 | ---- | M] () -- C:\Users\Mark\Desktop\clip0026.avi
[2010.05.08 13:35:28 | 274,192,286 | ---- | M] () -- C:\Users\Mark\Documents\clip0026.avi
[2010.05.08 13:31:10 | 129,251,592 | ---- | M] () -- C:\Users\Mark\Documents\clip0025.avi
[2010.05.05 14:48:12 | 000,002,032 | ---- | M] () -- C:\Users\Mark\AppData\Local\d3d9caps.dat
[2010.04.28 13:29:13 | 000,001,690 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010.04.26 07:49:17 | 194,934,412 | ---- | M] () -- C:\Users\Mark\Documents\clip0024.avi
[2010.04.25 17:59:47 | 062,061,190 | ---- | M] () -- C:\Users\Mark\Documents\clip0023.avi
[2010.04.25 17:58:48 | 158,577,058 | ---- | M] () -- C:\Users\Mark\Documents\clip0022.avi
[2010.04.25 10:02:03 | 000,000,094 | ---- | M] () -- C:\Users\Mark\Documents\PDVD_MediaDisc.PlayList
[2010.04.25 08:14:44 | 417,536,496 | ---- | M] () -- C:\Users\Mark\Documents\clip0021.avi
[2010.04.25 08:10:26 | 007,971,076 | ---- | M] () -- C:\Users\Mark\Documents\clip0020.avi
[2010.04.25 08:07:35 | 001,464,918 | ---- | M] () -- C:\Users\Mark\Documents\clip0019.avi
[2010.04.24 21:19:15 | 016,297,776 | ---- | M] () -- C:\Users\Mark\Documents\clip0018.avi
[2010.04.24 21:18:35 | 037,861,808 | ---- | M] () -- C:\Users\Mark\Documents\clip0017.avi
[2010.04.24 21:17:50 | 120,898,346 | ---- | M] () -- C:\Users\Mark\Documents\clip0016.avi
[2010.04.24 21:16:39 | 002,547,616 | ---- | M] () -- C:\Users\Mark\Documents\clip0015.avi
[2010.04.24 21:16:37 | 001,362,646 | ---- | M] () -- C:\Users\Mark\Documents\clip0014.avi
[2010.04.24 21:16:36 | 000,533,100 | ---- | M] () -- C:\Users\Mark\Documents\clip0013.avi
[2010.04.24 21:16:36 | 000,509,656 | ---- | M] () -- C:\Users\Mark\Documents\clip0012.avi
[2010.04.24 21:16:30 | 138,336,402 | ---- | M] () -- C:\Users\Mark\Documents\clip0011.avi
[2010.04.24 21:14:54 | 014,959,376 | ---- | M] () -- C:\Users\Mark\Documents\clip0010.avi
[2010.04.24 13:49:14 | 039,281,058 | ---- | M] () -- C:\Users\Mark\Documents\clip0009.avi
[2010.04.24 13:01:18 | 418,863,908 | ---- | M] () -- C:\Users\Mark\Documents\clip0008.avi
[2010.04.18 23:13:15 | 000,524,288 | -HS- | M] () -- C:\Users\Mark\ntuser.dat{b12478a5-4b05-11df-8729-00038a000015}.TMContainer00000000000000000002.regtrans-ms
[2010.04.18 00:27:13 | 000,524,288 | -HS- | M] () -- C:\Users\Mark\ntuser.dat{52714324-ee21-11dd-a5af-00038a000015}.TMContainer00000000000000000001.regtrans-ms
[2010.04.18 00:27:13 | 000,065,536 | -HS- | M] () -- C:\Users\Mark\ntuser.dat{52714324-ee21-11dd-a5af-00038a000015}.TM.blf
[2010.04.15 08:01:04 | 003,879,288 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Users\Mark\Desktop\procexp.exe
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.06.27 10:23:53 | 000,012,466 | ---- | C] () -- C:\Users\Mark\Documents\hijackthis2
[2010.06.27 08:23:57 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010.06.27 08:13:20 | 000,001,854 | ---- | C] () -- C:\Users\Public\Desktop\Safari.lnk
[2010.06.27 06:15:37 | 000,001,019 | ---- | C] () -- C:\Users\Mark\Desktop\Spybot - Search & Destroy.lnk
[2010.06.26 19:37:56 | 000,000,904 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010.06.19 17:56:29 | 000,015,880 | ---- | C] () -- C:\Windows\System32\lsdelete.exe
[2010.06.19 12:45:50 | 000,000,979 | ---- | C] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2010.06.19 11:24:40 | 000,031,858 | ---- | C] () -- C:\Users\Mark\Documents\cc_20100619_112435.reg
[2010.06.19 10:24:08 | 000,001,828 | ---- | C] () -- C:\Users\Mark\Desktop\CodeStuff Starter.lnk
[2010.06.19 10:23:32 | 000,680,340 | ---- | C] () -- C:\Users\Mark\Desktop\StarterSetup5629.zip
[2010.06.18 15:45:59 | 006,049,493 | ---- | C] () -- C:\Users\Mark\Desktop\K'naan - Wavin flag (WM 2010).mp3
[2010.06.18 15:41:35 | 004,910,972 | ---- | C] () -- C:\Users\Mark\Desktop\Shakira - waka waka.mp3
[2010.06.18 15:38:04 | 003,998,149 | ---- | C] () -- C:\Users\Mark\Desktop\Bushido feat. Kay One - Fackeln im Wind.mp3
[2010.06.02 20:43:56 | 000,021,478 | ---- | C] () -- C:\Users\Mark\Documents\Trainingsplan Juni. 10.xlsx
[2010.05.24 10:18:58 | 000,036,864 | ---- | C] () -- C:\Users\Mark\Documents\Trainingsplan Apr. 10.xls
[2010.05.20 22:10:50 | 039,109,498 | ---- | C] () -- C:\Users\Mark\Documents\Jahresprogramm_webPDF.pdf
[2010.05.18 21:33:27 | 000,967,680 | ---- | C] () -- C:\Users\Mark\Desktop\.doc
[2010.05.14 18:19:49 | 000,000,033 | ---- | C] () -- C:\Users\Mark\Desktop\cmd.php
[2010.05.08 21:00:34 | 001,728,943 | ---- | C] () -- C:\Users\Mark\Desktop\ProcessExplorer.zip
[2010.05.08 20:56:30 | 000,000,953 | ---- | C] () -- C:\Users\Mark\Desktop\Internet Explorer.lnk
[2010.05.08 13:44:43 | 214,923,128 | ---- | C] () -- C:\Users\Mark\Desktop\clip0028.avi
[2010.05.08 13:43:58 | 010,238,098 | ---- | C] () -- C:\Users\Mark\Desktop\clip0027.avi
[2010.05.08 13:40:49 | 350,131,300 | ---- | C] () -- C:\Users\Mark\Desktop\clip0026.avi
[2010.05.08 13:31:55 | 274,192,286 | ---- | C] () -- C:\Users\Mark\Documents\clip0026.avi
[2010.05.08 13:30:17 | 129,251,592 | ---- | C] () -- C:\Users\Mark\Documents\clip0025.avi
[2010.04.28 13:29:13 | 000,001,690 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010.04.26 07:47:57 | 194,934,412 | ---- | C] () -- C:\Users\Mark\Documents\clip0024.avi
[2010.04.25 17:59:24 | 062,061,190 | ---- | C] () -- C:\Users\Mark\Documents\clip0023.avi
[2010.04.25 17:57:48 | 158,577,058 | ---- | C] () -- C:\Users\Mark\Documents\clip0022.avi
[2010.04.25 08:12:17 | 417,536,496 | ---- | C] () -- C:\Users\Mark\Documents\clip0021.avi
[2010.04.25 08:10:23 | 007,971,076 | ---- | C] () -- C:\Users\Mark\Documents\clip0020.avi
[2010.04.25 08:07:34 | 001,464,918 | ---- | C] () -- C:\Users\Mark\Documents\clip0019.avi
[2010.04.24 21:19:09 | 016,297,776 | ---- | C] () -- C:\Users\Mark\Documents\clip0018.avi
[2010.04.24 21:18:20 | 037,861,808 | ---- | C] () -- C:\Users\Mark\Documents\clip0017.avi
[2010.04.24 21:17:08 | 120,898,346 | ---- | C] () -- C:\Users\Mark\Documents\clip0016.avi
[2010.04.24 21:16:37 | 002,547,616 | ---- | C] () -- C:\Users\Mark\Documents\clip0015.avi
[2010.04.24 21:16:36 | 001,362,646 | ---- | C] () -- C:\Users\Mark\Documents\clip0014.avi
[2010.04.24 21:16:36 | 000,533,100 | ---- | C] () -- C:\Users\Mark\Documents\clip0013.avi
[2010.04.24 21:16:35 | 000,509,656 | ---- | C] () -- C:\Users\Mark\Documents\clip0012.avi
[2010.04.24 21:14:56 | 138,336,402 | ---- | C] () -- C:\Users\Mark\Documents\clip0011.avi
[2010.04.24 21:14:49 | 014,959,376 | ---- | C] () -- C:\Users\Mark\Documents\clip0010.avi
[2010.04.24 13:48:42 | 039,281,058 | ---- | C] () -- C:\Users\Mark\Documents\clip0009.avi
[2010.04.24 12:58:57 | 418,863,908 | ---- | C] () -- C:\Users\Mark\Documents\clip0008.avi
[2010.04.18 18:18:43 | 000,524,288 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{b12478a5-4b05-11df-8729-00038a000015}.TMContainer00000000000000000002.regtrans-ms
[2010.04.18 18:18:43 | 000,524,288 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{b12478a5-4b05-11df-8729-00038a000015}.TMContainer00000000000000000001.regtrans-ms
[2010.04.18 18:18:42 | 000,065,536 | -HS- | C] () -- C:\Users\Mark\ntuser.dat{b12478a5-4b05-11df-8729-00038a000015}.TM.blf
[2010.04.12 21:32:33 | 000,065,536 | ---- | C] () -- C:\Windows\System32\Ikeext.etl
[2010.04.09 22:12:19 | 000,001,096 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010.04.09 22:12:15 | 000,001,092 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010.02.27 11:03:57 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2010.02.27 11:03:57 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2010.02.27 10:55:24 | 000,031,664 | ---- | C] () -- C:\Windows\maxlink.ini
[2010.01.30 11:12:55 | 000,004,352 | ---- | C] () -- C:\Windows\System32\drivers\TF0801.sys
[2009.12.07 18:26:12 | 000,000,020 | ---- | C] () -- C:\Windows\TTN.INI
[2009.08.18 20:47:02 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.08.03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009.07.07 15:46:44 | 000,819,200 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009.07.07 15:46:44 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009.02.08 08:22:19 | 000,027,184 | ---- | C] () -- C:\Windows\System32\drivers\VL807.sys
[2009.02.08 08:21:53 | 000,064,048 | ---- | C] () -- C:\Windows\System32\Hidhlp.dll
[2009.02.08 08:21:53 | 000,055,856 | ---- | C] () -- C:\Windows\System32\iFT7195.dll
[2009.02.05 19:06:55 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2008.12.12 08:43:43 | 000,000,160 | ---- | C] () -- C:\Windows\asrapi.ini
[2008.12.12 08:43:03 | 000,081,920 | ---- | C] () -- C:\Windows\asr3232.dll
[2008.10.15 19:30:20 | 000,069,632 | ---- | C] () -- C:\Windows\System32\xmltok.dll
[2008.10.15 19:30:20 | 000,036,864 | ---- | C] () -- C:\Windows\System32\xmlparse.dll
[2008.10.10 20:50:02 | 000,000,065 | ---- | C] () -- C:\Windows\WININIT.INI
[2008.05.07 21:04:51 | 000,001,025 | ---- | C] () -- C:\Windows\System32\sysprs7.dll
[2008.05.07 21:04:51 | 000,001,025 | ---- | C] () -- C:\Windows\System32\clauth2.dll
[2008.05.07 21:04:51 | 000,001,025 | ---- | C] () -- C:\Windows\System32\clauth1.dll
[2008.05.07 21:04:51 | 000,000,205 | ---- | C] () -- C:\Windows\System32\lsprst7.dll
[2008.05.07 21:04:51 | 000,000,073 | ---- | C] () -- C:\Windows\System32\ssprs.dll
[2007.10.03 20:55:38 | 000,639,224 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2007.05.26 15:51:54 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2007.05.26 15:51:51 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2007.05.14 20:58:55 | 000,000,015 | ---- | C] () -- C:\Windows\PUST2.ini
[2007.05.08 18:45:59 | 000,000,000 | ---- | C] () -- C:\Windows\TCLOG.INI
[2007.05.07 18:16:07 | 000,000,328 | ---- | C] () -- C:\Windows\scardsrv.ini
[2007.05.06 20:46:01 | 000,000,610 | ---- | C] () -- C:\Windows\HBCIKRNL.INI
[2007.02.26 18:14:35 | 000,299,008 | ---- | C] () -- C:\Windows\System32\midas.dll
[2007.02.26 18:14:35 | 000,120,320 | ---- | C] () -- C:\Windows\System32\UnzDll.dll
[2007.02.10 17:17:37 | 000,007,119 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2007.02.09 16:43:52 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2007.02.09 15:12:31 | 000,003,072 | ---- | C] () -- C:\Windows\System32\34CoInstaller.dll
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.09.20 08:34:10 | 000,000,114 | ---- | C] () -- C:\Windows\Buhl.ini
[1997.06.14 10:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll
========== LOP Check ==========
[2009.11.27 22:38:08 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Any Video Converter
[2009.11.27 20:26:18 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Any Video Converter Professional
[2009.01.17 15:04:14 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Bayer04 Publisher
[2008.05.18 10:13:45 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Buhl Data Service
[2009.08.06 18:59:06 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Buhl Data Service GmbH
[2007.05.07 19:06:24 | 000,000,000 | ---D | M] -- C:\Users\Marku\AppData\Roaming\DataDesign
[2008.03.14 21:20:31 | 000,000,000 | ---D | M] -- C:\Users\Marku\AppData\Roaming\dp3d
[2007.10.02 23:01:41 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Engelmann Media
[2009.11.27 18:00:39 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\FreeVideoConverter
[2010.05.18 18:53:36 | 000,000,000 | ---D | M] -- C:\Users\Marku\AppData\Roaming\ICQ
[2008.12.13 23:27:33 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Imperium Romanum
[2010.02.01 15:47:12 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\LetsTrade
[2009.06.21 12:54:41 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\MAGIX
[2010.02.23 17:40:06 | 000,000,000 | ---D | M] -- C:\Users\MarkAppData\Roaming\ManyCam
[2009.05.11 17:42:08 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\MuldeR
[2007.11.26 20:59:44 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\My Games
[2009.10.19 16:52:07 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Nokia
[2009.01.03 12:51:21 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\OpenOffice.org
[2008.11.30 17:47:01 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\PC Suite
[2007.05.25 21:29:23 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\PeerNetworking
[2009.02.05 19:21:34 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\ProtectDisc
[2009.10.07 19:55:26 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Robots
[2008.03.21 14:31:44 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Teleca
[2007.05.06 22:16:33 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Template
[2010.05.26 22:46:39 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Teup
[2009.11.24 19:24:36 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\TVcentral-Core
[2010.03.23 22:00:13 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Ubisoft
[2007.05.12 09:38:43 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Ulead Systems
[2010.05.28 19:26:59 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Uxfov
[2010.06.27 09:38:55 | 000,032,584 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010.06.27 19:26:00 | 000,000,436 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{F1A883CC-8CB1-4FC9-AFF7-A13F8DC58013}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010.06.27 09:40:21 | 000,002,012 | ---- | M] () -- C:\aaw7boot.log
[2008.10.11 15:08:19 | 000,000,000 | ---- | M] () -- C:\AILog.txt
[2006.09.18 23:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2009.04.11 08:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
[2007.02.09 14:38:35 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2006.09.18 23:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2010.06.27 09:40:23 | 2145,902,592 | -HS- | M] () -- C:\hiberfil.sys
[2007.02.10 17:20:15 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2008.02.15 23:52:30 | 000,000,905 | -H-- | M] () -- C:\IPH.PH
[2007.02.10 17:20:15 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010.06.27 09:40:21 | 2459,705,344 | -HS- | M] () -- C:\pagefile.sys
[2006.11.29 23:29:40 | 000,000,512 | ---- | M] () -- C:\TVE.iss
[1 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009.08.14 04:16:22 | 000,446,464 | ---- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 -- C:\Windows\System32\ATIDEMGX.dll
[2009.04.11 08:27:47 | 000,241,128 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\rsaenh.dll
[2009.04.11 08:28:23 | 000,228,352 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\SLC.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2006.11.02 12:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %systemroot%\system32\drivers\*.sys /90 >
[2010.06.19 12:49:34 | 000,064,288 | ---- | M] (Lavasoft AB) -- C:\Windows\System32\drivers\Lbd.sys
[2010.06.19 10:48:46 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2010.04.19 20:47:42 | 000,041,984 | ---- | M] (Apple, Inc.) -- C:\Windows\System32\drivers\usbaapl.sys
< %systemroot%\system32\user32.dll /md5 >
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
< %systemroot%\system32\ws2_32.dll /md5 >
[2008.01.19 09:37:09 | 000,179,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\ws2_32.dll
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList|helpassistant /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:661DFA1C
< End of report > --- --- --- |