Hicks-Boson | 07.10.2011 14:17 | Trojaner fakesysdef.506 eingefangen - jetzt beseitigt oder nicht? Hallo,
Ich versuche, alles genau nach der Anweisung zu machen, kenne mich mit dem ganzen Kram leider nicht gut aus – wenn etwas fehlt oder falsch ist, ist das keine Faulheit oder Frechheit, sondern schlicht Unfähigkeit, tut mir Leid! :schmoll: Das Problem:
ich habe mir gestern anscheinend einen fakesysdef-Trojaner namens fakesysdef.506 eingefangen. Ich vermute, ihr wisst, was das Programm macht; gefakte Fehlermeldungen, ein angebliches Restore-Programm (bei mir hieß es „Data Restore“), versteckte Dateien, schwarzer Desktop. Ich muss gestehen, dass ich zuerst nicht realisiert habe, dass das ein Trojaner ist, sondern das Fake-Programm weitergeklickt habe. Ich habe Windows 7 (64bit) erst seit wenigen Wochen und bin mit der Benutzeroberfläche nicht so vertraut… erst bei der Aufforderung, die kostenpflichtige „Vollversion“ zu laden, hat’s irgendwann geklingelt, dass das eine malware sein könnte :schmoll: Was ich schon unternommen habe:
Nach Internetrecherche habe ich einiges über das Problem gefunden, bin in den abgesicherten Modus gegangen und habe die aktiven Dateien dazu gelöscht, ebenso die Verknüpfung zu dem angeblichen Sicherungsprogramm und den beinhaltenden Ordner dazu (hieß "Data Restore" und hatte ein W7 - Logo). Dadurch war das laufende "sicherungs-"Programm weg und ich konnte den PC erstmal wieder normal nutzen.
Ich habe verschiedentlich gelesen, dass man auch in der Registry etwas löschen muss, die Anleitung (hxxp://www.computerwissen.de/sicherheit/aktuelles/malware-und-spam/artikel/hinterlistiges-schadprogramm-microsoft-warnt-vor-system-defragmenter.html) war aber anscheinend für XP oder für eine ältere malware-Version, denn ich habe komplett andere Pfade. Ich habe nur in den ProgramData gelöscht, weil ich diesen als korrespondierenden Ordner zum XP-Ordner All Users/Application Data gefunden habe.
Ich nutze Avira Antivir Personal und habe den daraufhin noch mal laufen lassen, welches fünf Dateien zu dem Trojaner in die Quarantäne geschoben hat (schon hatte?); TRFakeSysDef.506; vier davon in ProgramData/nxBPpaqQtFIXr.exe, eine in Users\***\AppData\Local\Microsoft\Windows\Temporary internet files\Content.IE5\D4K1N2PF\about[1].exe
Dazu gleich eine Frage: Was mache ich damit? Hab es ans Virenlabor gesendet und nur die schon bekannte Info per Mail gekriegt, dass es sich um malware handelt. Kann/muss/soll ich das jetzt aus der Quarantäne löschen?
Anschließend war das Fake-Programm gestoppt und nicht mehr auffindbar, das desktop konnte ich zurück ändern, und mit dem unhide-tool konnte ich die Dateien wieder normal sichtbar machen. Natürlich wüsste ich jetzt aber gern, ob es das war oder ob der PC immer noch verseucht ist und hoffe sehr, dass ihr mir helfen könnt! :(
Ich habe mir anschließend noch Malwarebytes Antimaleware runtergeladen und dann manuell aktualisiert, laufen lassen und dieses Programm hat auch nichts mehr gefunden (war ein Vollscan). Der Log von Malwarebytes, falls das etwas nutzt (wenn unerwünscht, entschuldigung!): Zitat:
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Datenbank Version: 7894
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
07.10.2011 15:15:52
mbam-log-2011-10-07 (15-15-52).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 325292
Laufzeit: 25 Minute(n), 16 Sekunde(n)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
Infizierte Dateien:
(Keine bösartigen Objekte gefunden)
| Ich habe wie gesagt Windows 7 64bit, es handelt sich um eine Studentenversion, daher möchte ich es ungern neu installieren, weil ich nicht weiß, ob der Product Key dafür unbegrenzt gültig ist. Das wäre für mich eine Notfalloption, ich hoffe, dass es auch ohne geht… Nun zu den Log-Files:
1. defogger von jpshortstuff
Habe ich runtergeladen, als Admin ausgeführt, „Disable“ geklickt und bekam eine Meldung, dass er jetzt was deaktivieren würde, habe das bestätigt, aber der Suchlauf war praktisch sofort beendet (Finished!) ohne Bericht oder Aufforderung zum Neustart, daher fürchte ich, dass das wohl nicht ganz geklappt hat. Daher hier der defogger_disable-Log. Zitat:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 14:06 on 07/10/2011 (Lea)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
| 2. OTL-Log:
OTL Logfile: Code:
OTL logfile created on: 07.10.2011 14:26:20 - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Lea\Desktop
64bit- An unknown product Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,73 Gb Total Physical Memory | 2,50 Gb Available Physical Memory | 67,14% Memory free
7,45 Gb Paging File | 6,09 Gb Available in Paging File | 81,68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 244,14 Gb Total Space | 197,29 Gb Free Space | 80,81% Space Free | Partition Type: NTFS
Drive D: | 488,28 Gb Total Space | 464,79 Gb Free Space | 95,19% Space Free | Partition Type: NTFS
Drive E: | 664,74 Gb Total Space | 664,64 Gb Free Space | 99,98% Space Free | Partition Type: NTFS
Computer Name: LEASCOMPI | User Name: Lea | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.10.07 14:24:41 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Lea\Desktop\OTL.exe
PRC - [2011.10.07 13:53:22 | 000,059,964 | ---- | M] (Macrovision Europe Ltd.) -- C:\Users\Lea\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001
PRC - [2011.09.15 18:36:59 | 000,079,360 | ---- | M] (Creative Labs) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe
PRC - [2011.09.15 18:35:05 | 004,942,336 | ---- | M] (FNet Co., Ltd.) -- C:\Program Files (x86)\XFastUsb\XFastUsb.exe
PRC - [2011.07.21 12:08:02 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.04.21 07:52:51 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.04.21 07:52:36 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.02.01 13:20:48 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2011.02.01 13:20:46 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.10.26 16:15:48 | 001,699,912 | ---- | M] (Elgato Systems) -- C:\Program Files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe
PRC - [2010.05.14 07:02:56 | 000,075,048 | ---- | M] (cyberlink) -- C:\Program Files (x86)\CyberLink\Shared files\brs.exe
PRC - [2009.12.15 13:47:00 | 000,103,720 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
PRC - [2009.07.08 15:32:50 | 001,233,195 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe
PRC - [2009.07.06 14:22:04 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
PRC - [2009.05.04 19:05:04 | 000,241,789 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe
PRC - [2009.02.23 05:43:56 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
========== Modules (No Company Name) ==========
MOD - [2011.10.07 13:53:22 | 000,697,884 | ---- | M] () -- C:\Users\Lea\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0022\~df394b.tmp
MOD - [2011.10.07 13:53:22 | 000,592,896 | ---- | M] () -- C:\Users\Lea\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0022\~de6248.tmp
MOD - [2011.05.26 13:42:00 | 000,067,872 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2010.04.22 12:42:56 | 007,745,536 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
MOD - [2010.04.22 12:42:54 | 002,121,728 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
MOD - [2010.04.22 12:42:54 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
MOD - [2009.12.15 13:49:20 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
MOD - [2009.12.15 13:46:38 | 000,619,816 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
MOD - [2009.04.20 11:55:58 | 000,148,480 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL
MOD - [2009.02.06 18:52:24 | 000,073,728 | ---- | M] () -- C:\Windows\SysWOW64\CmdRtr.DLL
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2011.09.15 18:37:56 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)
SRV - [2011.09.15 18:37:27 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2011.09.15 18:36:59 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe -- (Sound Blaster X-Fi MB Licensing Service)
SRV - [2011.07.21 12:08:02 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.21 07:52:51 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.02.01 13:20:48 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2011.02.01 13:20:46 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.05.14 14:02:54 | 000,246,256 | ---- | M] (CyberLink) [Auto | Stopped] -- C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe -- (CLKMSVC10_9EC60124)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.02.23 05:43:56 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011.09.15 18:40:20 | 000,031,808 | ---- | M] (FNet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\FNETTBOH_305.SYS -- (FNETTBOH_305)
DRV:64bit: - [2011.09.15 18:35:06 | 000,015,936 | ---- | M] (FNet Co., Ltd.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\FNETURPX.SYS -- (FNETURPX)
DRV:64bit: - [2011.08.31 19:53:22 | 012,306,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011.07.21 12:11:10 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011.07.21 12:11:09 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.02.08 07:30:52 | 000,064,512 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronXHCI.sys -- (EtronXHCI)
DRV:64bit: - [2011.02.08 07:30:52 | 000,039,936 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronHub3.sys -- (EtronHub3)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.10.19 16:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel(R)
DRV:64bit: - [2010.10.19 14:23:18 | 001,179,896 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\y_cx88x.sys -- (cxpl_mhd)
DRV:64bit: - [2010.10.14 18:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV:64bit: - [2010.06.23 11:10:56 | 000,344,680 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010.06.11 14:37:14 | 000,015,368 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\AsrAppCharger.sys -- (AsrAppCharger)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2319825
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C8 C4 20 F5 C7 73 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://www.ecosia.org/"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.10.06 18:16:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.09.15 19:11:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
[2011.09.15 18:56:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lea\AppData\Roaming\mozilla\Extensions
[2011.09.16 17:09:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lea\AppData\Roaming\mozilla\Firefox\Profiles\4tiqbgij.default\extensions
[2011.09.15 18:55:53 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.10.03 22:09:41 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.09.03 02:19:44 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.09.03 02:13:56 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011.09.03 02:19:44 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.09.03 02:19:44 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.03 02:19:44 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.09.03 02:19:44 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\PROGRA~2\TerraTec\TERRAT~1\THCDES~1.DLL (TerraTec Electronic GmbH)
O3 - HKCU\..\Toolbar\WebBrowser: (Winload Toolbar) - {40C3CC16-7269-4B32-9531-17F2950FB06F} - C:\Program Files (x86)\Winload\prxtbWinl.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [CTSyncService] C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files (x86)\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl9] C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePPShortCut] C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [XFastUsb] C:\Program Files (x86)\XFastUsb\XFastUsb.exe (FNet Co., Ltd.)
O4 - HKCU..\Run: [ASRockXTU] File not found
O4 - HKCU..\Run: [Remote Control Editor] C:\Program Files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe (Elgato Systems)
O4 - HKCU..\Run: [zASRockInstantBoot] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB5872B9-2107-4955-B1F7-2CFDFA09C0B2}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\cdo - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{68ca9c7c-dfb8-11e0-8ff1-002522c2fd68}\Shell - "" = AutoRun
O33 - MountPoints2\{68ca9c7c-dfb8-11e0-8ff1-002522c2fd68}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker 2.6
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
MsConfig:64bit - StartUpReg: LGODDFU - hkey= - key= - C:\Program Files (x86)\lg_fwupdate\fwupdate.exe (BitLeader)
MsConfig:64bit - State: "startup" - Reg Error: Key error.
MsConfig:64bit - State: "bootini" - Reg Error: Key error.
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011.10.07 14:24:40 | 000,582,656 | ---- | C] (OldTimer Tools) -- C:\Users\Lea\Desktop\OTL.exe
[2011.10.06 23:21:37 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\ElevatedDiagnostics
[2011.10.06 23:19:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Texmaker
[2011.10.06 23:19:15 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Texmaker
[2011.10.06 23:19:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Texmaker
[2011.10.06 23:04:20 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\MiKTeX
[2011.10.06 21:13:11 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Malwarebytes
[2011.10.06 21:13:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.10.06 21:13:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.10.06 21:13:01 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011.10.06 21:13:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.10.06 21:12:32 | 009,852,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Lea\mbam-setup-1.51.2.1300.exe
[2011.10.06 18:30:12 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2011.10.06 17:29:59 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Avira
[2011.10.03 16:50:50 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\EA Games
[2011.09.29 16:54:02 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Splashtop
[2011.09.26 19:00:52 | 000,000,000 | ---D | C] -- C:\Users\Lea\Documents\My Albums
[2011.09.26 19:00:52 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\ArcSoft
[2011.09.26 08:59:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache
[2011.09.25 11:50:17 | 000,000,000 | R--D | C] -- C:\Users\Lea\AppData\Roaming\Brother
[2011.09.22 20:26:04 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2011.09.22 18:50:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
[2011.09.22 18:49:59 | 001,053,184 | ---- | C] (Cendant Software) -- C:\Windows\SysWow64\SierraNW.dll
[2011.09.22 18:49:59 | 000,231,936 | ---- | C] (Cendant Software) -- C:\Windows\SysWow64\SNWValid.dll
[2011.09.22 18:49:59 | 000,000,000 | ---D | C] -- C:\Windows\solcache
[2011.09.22 18:48:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sierra On-Line
[2011.09.22 18:48:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spiele
[2011.09.22 18:40:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
[2011.09.22 18:39:56 | 000,000,000 | ---D | C] -- C:\Users\Lea\Documents\EA Games
[2011.09.22 18:34:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EA GAMES
[2011.09.22 18:34:33 | 000,442,368 | R--- | C] (On2.com) -- C:\Windows\SysWow64\vp6vfw.dll
[2011.09.20 20:26:54 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\.purple
[2011.09.20 20:21:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pidgin
[2011.09.20 20:16:31 | 000,000,000 | ---D | C] -- C:\ProgramData\MiKTeX
[2011.09.20 20:15:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MiKTeX 2.8
[2011.09.20 20:08:47 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2011.09.19 19:09:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft PhotoStudio 5.5
[2011.09.19 19:09:27 | 000,212,480 | ---- | C] (Eastman Kodak) -- C:\Windows\pcdlib32.dll
[2011.09.19 19:09:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ArcSoft
[2011.09.19 19:07:29 | 000,000,000 | ---D | C] -- C:\CanoScan
[2011.09.18 01:40:04 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\WMTools Downloaded Files
[2011.09.18 01:36:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Movie Maker 2.6
[2011.09.16 23:57:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2011.09.16 17:24:06 | 000,000,000 | R--D | C] -- C:\Users\Lea\Videos
[2011.09.16 17:24:06 | 000,000,000 | R--D | C] -- C:\Users\Lea\Pictures
[2011.09.16 17:23:52 | 000,000,000 | ---D | C] -- C:\Users\Lea\Application Data
[2011.09.16 17:02:53 | 000,000,000 | R--D | C] -- C:\Users\Lea\Music
[2011.09.16 16:58:13 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\vlc
[2011.09.16 16:58:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011.09.16 16:58:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VLC Player
[2011.09.16 16:57:16 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Google
[2011.09.16 16:57:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2011.09.16 16:57:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ConduitEngine
[2011.09.16 16:56:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winload
[2011.09.16 16:56:59 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Conduit
[2011.09.16 16:06:19 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Adobe
[2011.09.16 16:01:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
[2011.09.16 16:01:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Designer
[2011.09.16 16:00:46 | 000,000,000 | ---D | C] -- C:\Windows\Msagent
[2011.09.16 16:00:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2011.09.16 15:25:22 | 000,000,000 | ---D | C] -- C:\Users\Lea\Documents\CyberLink
[2011.09.16 15:13:56 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Power2Go
[2011.09.15 22:04:33 | 000,000,000 | ---D | C] -- C:\Temp
[2011.09.15 22:04:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LG Tool Kit
[2011.09.15 22:03:54 | 000,016,384 | ---- | C] (BitLeader) -- C:\Windows\SysWow64\lgfwunis.exe
[2011.09.15 22:03:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\lg_fwupdate
[2011.09.15 19:37:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\CyberLink
[2011.09.15 19:35:44 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\CrashDumps
[2011.09.15 19:35:12 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\CyberLink
[2011.09.15 19:35:11 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Cyberlink
[2011.09.15 19:32:38 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling
[2011.09.15 19:32:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\LightScribe
[2011.09.15 19:32:26 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
[2011.09.15 19:31:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
[2011.09.15 19:31:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CyberLink
[2011.09.15 19:29:54 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
[2011.09.15 19:29:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Temp
[2011.09.15 19:23:40 | 000,000,000 | ---D | C] -- C:\ProgramData\TerraTec
[2011.09.15 19:23:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TerraTec
[2011.09.15 19:23:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TerraTec
[2011.09.15 19:22:49 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\TerraTec
[2011.09.15 19:20:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\TerraTec
[2011.09.15 19:12:50 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2011.09.15 19:12:04 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Apple Computer
[2011.09.15 19:12:04 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Apple Computer
[2011.09.15 19:12:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.09.15 19:11:55 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2011.09.15 19:11:44 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.09.15 19:11:43 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011.09.15 19:11:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011.09.15 19:11:43 | 000,000,000 | ---D | C] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2011.09.15 19:11:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011.09.15 19:11:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2011.09.15 19:11:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2011.09.15 19:11:03 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Apple
[2011.09.15 19:11:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2011.09.15 19:10:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2011.09.15 19:10:41 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011.09.15 19:10:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2011.09.15 19:10:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2011.09.15 19:10:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2011.09.15 19:05:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011.09.15 19:05:23 | 000,123,784 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2011.09.15 19:05:23 | 000,088,288 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2011.09.15 19:05:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011.09.15 19:05:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2011.09.15 19:03:51 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Thunderbird
[2011.09.15 19:03:51 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Thunderbird
[2011.09.15 19:03:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2011.09.15 18:58:35 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2011.09.15 18:55:58 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Mozilla
[2011.09.15 18:55:58 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Mozilla
[2011.09.15 18:55:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2011.09.15 18:51:23 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2011.09.15 18:43:42 | 000,000,000 | ---D | C] -- C:\ProgramData\DeviceVM
[2011.09.15 18:42:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2011.09.15 18:40:49 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2011.09.15 18:40:41 | 000,000,000 | ---D | C] -- C:\ProgramData\{8533ADFA-85F0-4dc1-946A-2A0BA58E78E3}
[2011.09.15 18:40:40 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\DeviceVm
[2011.09.15 18:40:20 | 000,031,808 | ---- | C] (FNet Co., Ltd.) -- C:\Windows\SysNative\drivers\FNETTBOH_305.SYS
[2011.09.15 18:38:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Creative
[2011.09.15 18:38:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Creative Installation Information
[2011.09.15 18:37:58 | 002,873,822 | ---- | C] (Creative) -- C:\Windows\SysWow64\Sens_oal.dll
[2011.09.15 18:37:58 | 001,910,272 | ---- | C] (Creative) -- C:\Windows\SysNative\Sens_oal.dll
[2011.09.15 18:37:58 | 000,466,456 | ---- | C] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2011.09.15 18:37:58 | 000,444,952 | ---- | C] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2011.09.15 18:37:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
[2011.09.15 18:37:22 | 000,000,000 | ---D | C] -- C:\Program Files\Creative
[2011.09.15 18:36:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Creative Labs Shared
[2011.09.15 18:36:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Creative
[2011.09.15 18:36:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Creative
[2011.09.15 18:36:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2011.09.15 18:36:14 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Macromedia
[2011.09.15 18:36:14 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Adobe
[2011.09.15 18:35:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2011.09.15 18:35:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2011.09.15 18:35:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2011.09.15 18:35:06 | 000,015,936 | ---- | C] (FNet Co., Ltd.) -- C:\Windows\SysNative\drivers\FNETURPX.SYS
[2011.09.15 18:35:06 | 000,000,000 | ---D | C] -- C:\ProgramData\FNET
[2011.09.15 18:35:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\XFastUsb
[2011.09.15 18:35:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XFast USB
[2011.09.15 18:34:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ASRock Utility
[2011.09.15 18:34:46 | 000,015,368 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\Windows\SysNative\drivers\AsrAppCharger.sys
[2011.09.15 18:34:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility
[2011.09.15 18:34:46 | 000,000,000 | ---D | C] -- C:\Program Files\ASRock Utility
[2011.09.15 18:34:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Etron Technology
[2011.09.15 18:34:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
[2011.09.15 18:34:05 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2011.09.15 18:32:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\postureAgent
[2011.09.15 18:32:25 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\InstallShield
[2011.09.15 18:31:59 | 000,344,680 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys
[2011.09.15 18:31:17 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
[2011.09.15 18:31:17 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2011.09.15 18:31:10 | 002,601,816 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib.dll
[2011.09.15 18:31:10 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
[2011.09.15 18:31:10 | 000,372,936 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
[2011.09.15 18:31:10 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
[2011.09.15 18:31:10 | 000,201,928 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
[2011.09.15 18:31:10 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
[2011.09.15 18:31:10 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
[2011.09.15 18:31:10 | 000,099,016 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
[2011.09.15 18:31:10 | 000,076,488 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
[2011.09.15 18:31:09 | 002,197,264 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ.dll
[2011.09.15 18:31:09 | 000,338,336 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
[2011.09.15 18:31:09 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
[2011.09.15 18:31:09 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
[2011.09.15 18:31:09 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
[2011.09.15 18:31:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Temp
[2011.09.15 18:31:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2011.09.15 18:31:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2011.09.15 18:31:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2011.09.15 18:30:32 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
[2011.09.15 18:30:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel
[2011.09.15 18:30:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Intel
[2011.09.15 18:30:00 | 000,004,096 | ---- | C] ( ) -- C:\Windows\SysNative\IGFXDEVLib.dll
[2011.09.15 18:28:00 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\SysWow64\CSVer.dll
[2011.09.15 18:28:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel
[2011.09.15 18:27:58 | 000,000,000 | ---D | C] -- C:\Intel
[2011.09.15 18:24:44 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Diagnostics
[2011.09.15 18:20:59 | 000,000,000 | R--D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011.09.15 18:20:59 | 000,000,000 | R--D | C] -- C:\Users\Lea\Searches
[2011.09.15 18:20:59 | 000,000,000 | R--D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011.09.15 18:20:48 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Identities
[2011.09.15 18:20:46 | 000,000,000 | R--D | C] -- C:\Users\Lea\Contacts
[2011.09.15 18:20:44 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\VirtualStore
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Vorlagen
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\AppData\Local\Verlauf
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\AppData\Local\Temporary Internet Files
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Startmenü
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\SendTo
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Recent
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Netzwerkumgebung
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Lokale Einstellungen
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Documents\Eigene Videos
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Documents\Eigene Musik
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Eigene Dateien
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Documents\Eigene Bilder
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Druckumgebung
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Cookies
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\AppData\Local\Anwendungsdaten
[2011.09.15 18:20:35 | 000,000,000 | -HSD | C] -- C:\Users\Lea\Anwendungsdaten
[2011.09.15 18:20:34 | 000,000,000 | --SD | C] -- C:\Users\Lea\AppData\Roaming\Microsoft
[2011.09.15 18:20:34 | 000,000,000 | R--D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011.09.15 18:20:34 | 000,000,000 | R--D | C] -- C:\Users\Lea\Links
[2011.09.15 18:20:34 | 000,000,000 | R--D | C] -- C:\Users\Lea\Favorites
[2011.09.15 18:20:34 | 000,000,000 | R--D | C] -- C:\Users\Lea\Downloads
[2011.09.15 18:20:34 | 000,000,000 | R--D | C] -- C:\Users\Lea\Documents
[2011.09.15 18:20:34 | 000,000,000 | R--D | C] -- C:\Users\Lea\Desktop
[2011.09.15 18:20:34 | 000,000,000 | R--D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011.09.15 18:20:34 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Temp
[2011.09.15 18:20:34 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\Microsoft
[2011.09.15 18:20:34 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Media Center Programs
[2011.09.15 18:20:34 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData
[2011.09.15 18:20:28 | 000,000,000 | -HSD | C] -- C:\Recovery
[2011.09.15 18:20:28 | 000,000,000 | -HSD | C] -- C:\Programme
[2011.09.15 18:20:28 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2011.09.15 18:20:28 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2011.09.15 18:20:28 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2011.09.15 18:20:27 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2011.09.15 18:20:27 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2011.09.15 18:20:27 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2011.09.15 18:20:27 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2011.09.15 18:20:27 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2011.09.15 18:20:27 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2011.09.15 18:20:27 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2011.09.15 18:16:11 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2011.09.15 18:14:02 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2011.09.15 18:13:22 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011.10.07 14:24:41 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Lea\Desktop\OTL.exe
[2011.10.07 14:05:26 | 000,000,000 | ---- | M] () -- C:\Users\Lea\defogger_reenable
[2011.10.07 14:03:28 | 000,050,477 | ---- | M] () -- C:\Users\Lea\Desktop\Defogger.exe
[2011.10.07 14:00:32 | 000,022,000 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.10.07 14:00:32 | 000,022,000 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.10.07 14:00:18 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.10.07 14:00:18 | 000,643,628 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.10.07 14:00:18 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.10.07 14:00:18 | 000,126,188 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.10.07 14:00:18 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.10.07 13:53:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.10.07 13:53:07 | 3001,565,184 | -HS- | M] () -- C:\hiberfil.sys
[2011.10.06 21:12:34 | 009,852,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Lea\mbam-setup-1.51.2.1300.exe
[2011.10.06 20:49:59 | 000,001,921 | ---- | M] () -- C:\Users\Lea\Desktop\Sims2EP8 - Verknüpfung.lnk
[2011.09.26 16:20:54 | 000,015,428 | ---- | M] () -- C:\Users\Lea\RefEdit.exd
[2011.09.25 11:32:45 | 000,296,160 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.09.22 19:05:06 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2011.09.22 19:05:05 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2011.09.22 18:50:34 | 000,001,654 | ---- | M] () -- C:\Windows\wininit.ini
[2011.09.22 18:50:34 | 000,000,151 | ---- | M] () -- C:\Windows\tmpcpyis.bat
[2011.09.22 18:50:34 | 000,000,122 | ---- | M] () -- C:\Windows\tmpdelis.bat
[2011.09.22 18:50:34 | 000,000,026 | ---- | M] () -- C:\Windows\winstart.bat
[2011.09.22 18:50:17 | 000,001,369 | ---- | M] () -- C:\Users\Lea\Desktop\Caesar 3.lnk
[2011.09.22 18:50:07 | 000,000,403 | ---- | M] () -- C:\Windows\SIERRA.INI
[2011.09.22 14:06:12 | 000,000,343 | ---- | M] () -- C:\Windows\lgfwup.ini
[2011.09.20 20:08:46 | 310,217,089 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011.09.18 01:38:19 | 000,003,584 | ---- | M] () -- C:\Users\Lea\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.09.16 17:14:41 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011.09.16 16:01:40 | 000,000,400 | ---- | M] () -- C:\Windows\ODBC.INI
[2011.09.15 22:05:17 | 000,016,384 | ---- | M] (BitLeader) -- C:\Windows\SysWow64\lgfwunis.exe
[2011.09.15 19:14:16 | 000,000,425 | ---- | M] () -- C:\Windows\BRWMARK.INI
[2011.09.15 19:14:16 | 000,000,027 | ---- | M] () -- C:\Windows\BRPP2KA.INI
[2011.09.15 19:13:36 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011.09.15 18:40:20 | 000,031,808 | ---- | M] (FNet Co., Ltd.) -- C:\Windows\SysNative\drivers\FNETTBOH_305.SYS
[2011.09.15 18:38:03 | 000,000,159 | R--- | M] () -- C:\Windows\ctfile.rfc
[2011.09.15 18:37:58 | 000,466,456 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2011.09.15 18:37:58 | 000,444,952 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2011.09.15 18:35:06 | 000,015,936 | ---- | M] (FNet Co., Ltd.) -- C:\Windows\SysNative\drivers\FNETURPX.SYS
[2011.09.15 18:34:09 | 000,018,340 | ---- | M] () -- C:\Windows\SysNative\results.xml
[2011.09.15 18:16:49 | 000,177,271 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2011.09.15 18:16:49 | 000,177,271 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011.10.07 14:05:26 | 000,000,000 | ---- | C] () -- C:\Users\Lea\defogger_reenable
[2011.10.07 14:02:42 | 000,050,477 | ---- | C] () -- C:\Users\Lea\Desktop\Defogger.exe
[2011.10.06 20:49:59 | 000,001,921 | ---- | C] () -- C:\Users\Lea\Desktop\Sims2EP8 - Verknüpfung.lnk
[2011.09.26 16:20:54 | 000,015,428 | ---- | C] () -- C:\Users\Lea\RefEdit.exd
[2011.09.22 19:05:06 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2011.09.22 19:05:05 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2011.09.22 18:50:34 | 000,001,654 | ---- | C] () -- C:\Windows\wininit.ini
[2011.09.22 18:50:34 | 000,000,151 | ---- | C] () -- C:\Windows\tmpcpyis.bat
[2011.09.22 18:50:34 | 000,000,122 | ---- | C] () -- C:\Windows\tmpdelis.bat
[2011.09.22 18:50:34 | 000,000,026 | ---- | C] () -- C:\Windows\winstart.bat
[2011.09.22 18:50:17 | 000,001,369 | ---- | C] () -- C:\Users\Lea\Desktop\Caesar 3.lnk
[2011.09.22 18:47:26 | 000,000,403 | ---- | C] () -- C:\Windows\SIERRA.INI
[2011.09.20 20:08:46 | 310,217,089 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011.09.19 19:09:27 | 000,000,021 | ---- | C] () -- C:\Windows\PS_setup.ini
[2011.09.18 01:38:19 | 000,003,584 | ---- | C] () -- C:\Users\Lea\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.09.16 17:14:41 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011.09.16 16:01:40 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2011.09.15 22:04:00 | 000,000,343 | ---- | C] () -- C:\Windows\lgfwup.ini
[2011.09.15 19:14:16 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2011.09.15 19:14:16 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2011.09.15 19:13:36 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011.09.15 18:38:15 | 000,005,037 | ---- | C] () -- C:\Windows\SysNative\cfgfx.ini
[2011.09.15 18:38:15 | 000,002,265 | ---- | C] () -- C:\Windows\FF08_Render_Spk_Hp.ini
[2011.09.15 18:38:15 | 000,001,650 | ---- | C] () -- C:\Windows\FF08_Capture.ini
[2011.09.15 18:38:15 | 000,001,540 | ---- | C] () -- C:\Windows\FF08_Render.ini
[2011.09.15 18:38:03 | 000,191,488 | ---- | C] () -- C:\Windows\SysNative\APOMgr64.DLL
[2011.09.15 18:38:03 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2011.09.15 18:38:03 | 000,089,088 | ---- | C] () -- C:\Windows\SysNative\CmdRtr64.DLL
[2011.09.15 18:38:03 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2011.09.15 18:38:03 | 000,000,159 | R--- | C] () -- C:\Windows\ctfile.rfc
[2011.09.15 18:34:09 | 000,018,340 | ---- | C] () -- C:\Windows\SysNative\results.xml
[2011.09.15 18:32:37 | 000,008,192 | ---- | C] () -- C:\Windows\SysNative\drivers\IntelMEFWVer.dll
[2011.09.15 18:31:59 | 000,074,272 | ---- | C] () -- C:\Windows\SysNative\RtNicProp64.dll
[2011.09.15 18:30:00 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.09.15 18:30:00 | 000,145,804 | ---- | C] () -- C:\Windows\SysNative\igcompkrng600.bin
[2011.09.15 18:30:00 | 000,094,208 | ---- | C] () -- C:\Windows\SysNative\IccLibDll_x64.dll
[2011.09.15 18:30:00 | 000,000,151 | ---- | C] () -- C:\Windows\SysNative\GfxUI.exe.config
[2011.09.15 18:22:09 | 000,001,409 | ---- | C] () -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011.09.15 18:22:06 | 000,001,443 | ---- | C] () -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011.09.15 18:13:22 | 3001,565,184 | -HS- | C] () -- C:\hiberfil.sys
[2011.08.31 19:51:16 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.08.31 19:51:16 | 000,216,000 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.08.31 19:46:00 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2011.08.31 19:26:20 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2009.07.14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011.09.27 22:04:34 | 000,000,000 | ---D | M] -- C:\Users\Lea\AppData\Roaming\.purple
[2011.09.15 18:51:21 | 000,000,000 | ---D | M] -- C:\Users\Lea\AppData\Roaming\DeviceVm
[2011.09.29 17:05:31 | 000,000,000 | ---D | M] -- C:\Users\Lea\AppData\Roaming\Splashtop
[2011.10.06 18:16:06 | 000,000,000 | ---D | M] -- C:\Users\Lea\AppData\Roaming\TerraTec
[2011.10.06 18:16:06 | 000,000,000 | ---D | M] -- C:\Users\Lea\AppData\Roaming\Thunderbird
[2009.07.14 07:08:49 | 000,016,254 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*. >
[2011.09.15 18:20:45 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2011.09.19 19:07:29 | 000,000,000 | ---D | M] -- C:\CanoScan
[2009.07.14 07:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2011.09.15 18:20:27 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2011.09.15 18:29:32 | 000,000,000 | ---D | M] -- C:\Intel
[2009.07.14 05:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2011.09.15 19:11:44 | 000,000,000 | R--D | M] -- C:\Program Files
[2011.10.06 23:19:15 | 000,000,000 | R--D | M] -- C:\Program Files (x86)
[2011.10.06 22:57:31 | 000,000,000 | ---D | M] -- C:\ProgramData
[2011.09.15 18:20:28 | 000,000,000 | -HSD | M] -- C:\Programme
[2011.09.15 18:20:28 | 000,000,000 | -HSD | M] -- C:\Recovery
[2011.10.07 14:27:44 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2011.09.15 22:05:18 | 000,000,000 | ---D | M] -- C:\Temp
[2011.09.15 18:20:34 | 000,000,000 | R--D | M] -- C:\Users
[2011.10.06 18:31:04 | 000,000,000 | ---D | M] -- C:\Windows
< %PROGRAMFILES%\*.exe >
< %LOCALAPPDATA%\*.exe >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.manifest /3 >
< MD5 for: EXPLORER.EXE >
[2011.02.26 07:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 08:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 05:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 05:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: REGEDIT.EXE >
[2009.07.14 03:39:29 | 000,427,008 | ---- | M] (Microsoft Corporation) MD5=2E2C937846A0B8789E5E91739284D17A -- C:\Windows\winsxs\amd64_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_5023a70bf589ad3e\regedit.exe
[2009.07.14 03:39:29 | 000,427,008 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\regedit.exe
[2009.07.14 03:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\SysWOW64\regedit.exe
[2009.07.14 03:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\winsxs\wow64_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_5a78515e29ea6f39\regedit.exe
< MD5 for: USERINIT.EXE >
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WININIT.EXE >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
< MD5 for: WINLOGON.EXE >
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report > --- --- ---
Der andere Extra-Log befindet sich wie gewünscht im Anhang.
Schritt 3 habe ich nicht durchgeführt, da ich ein 64 bit - System habe.
Ich hoffe, dass mir jemand helfen kann und möchte, dafür schonmal herzlichen Dank!!!
Liebe Grüße,
Lea |