Hedonist | 26.12.2011 21:45 | 1. Proxyeinstellung hatte ich nicht vorgenommen. Keine Ahnung was das ist. Ist aber nun deaktiviert.
2. Adobe Reader hatte ich bereits vorher auf den neusten Stand gebracht.
3. Alles klar, System mit CCleaner gereinigt.
4. OTL mit Script ausgeführt, Neustart und hier ist das Textdokument: Code:
All processes killed
========== OTL ==========
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully!
Prefs.js: "chr-greentree_ff&type=302398" removed from browser.search.param.yahoo-fr
C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml moved successfully.
C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml moved successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4ff60050-c4ff-11de-a361-001b2464e0f2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4ff60050-c4ff-11de-a361-001b2464e0f2}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4ff60050-c4ff-11de-a361-001b2464e0f2}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4ff60050-c4ff-11de-a361-001b2464e0f2}\ not found.
File H:\Start.exe not found.
ADS C:\ProgramData\TEMP:054B9966 deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Peter
->Temp folder emptied: 1078 bytes
->Temporary Internet Files folder emptied: 262546 bytes
->Java cache emptied: 5153617 bytes
->FireFox cache emptied: 40499985 bytes
->Flash cache emptied: 8114643 bytes
User: Pictures
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 208 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50498 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 52,00 mb
OTL by OldTimer - Version 3.2.31.0 log created on 12242011_101652
Files\Folders moved on Reboot...
C:\Users\Peter\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot... 5. Superantispyware Scan durchgeführt: Code:
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com
Generated 12/24/2011 at 11:24 AM
Application Version : 5.0.1142
Core Rules Database Version : 8087
Trace Rules Database Version: 5899
Scan type : Complete Scan
Total Scan Time : 00:53:32
Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User
Memory items scanned : 712
Memory threats detected : 0
Registry items scanned : 71502
Registry threats detected : 0
File items scanned : 55671
File threats detected : 1
Trojan.Agent/Gen-Sisproc
D:\BG\BGII - SOA\BIG WORLD DOWNLOADS\DEFJAM_V6.EXE 7. ESET Online scan laufen gelasse - nichts gefunden
8. OTL nochmals mit den von dir genannten Einstellungen laufen gelassen. Dabei kam aber nur das OTL log heraus. Kein Extra log. Code:
OTL logfile created on: 24.12.2011 15:07:37 - Run 4
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Peter\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 1,94 Gb Available Physical Memory | 48,40% Memory free
8,00 Gb Paging File | 5,93 Gb Available in Paging File | 74,22% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 105,10 Gb Total Space | 4,76 Gb Free Space | 4,53% Space Free | Partition Type: NTFS
Drive D: | 43,95 Gb Total Space | 4,71 Gb Free Space | 10,73% Space Free | Partition Type: NTFS
Drive E: | 111,78 Gb Total Space | 58,71 Gb Free Space | 52,52% Space Free | Partition Type: NTFS
Drive G: | 3,73 Gb Total Space | 1,27 Gb Free Space | 34,10% Space Free | Partition Type: NTFS
Computer Name: PETER-PC | User Name: Peter | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.12.22 14:19:45 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011.12.22 12:47:16 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
PRC - [2011.12.05 20:17:44 | 024,242,056 | ---- | M] (Dropbox, Inc.) -- C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011.10.24 13:57:25 | 002,078,048 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG9\avgtray.exe
PRC - [2011.10.14 07:01:50 | 000,994,360 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe
PRC - [2011.10.14 07:01:46 | 000,291,896 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
PRC - [2011.06.01 13:44:54 | 002,337,144 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
PRC - [2011.02.22 13:57:34 | 000,378,128 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFTray.exe
PRC - [2011.02.22 13:57:30 | 000,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFService.exe
PRC - [2010.09.05 21:06:17 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
PRC - [2009.09.06 13:38:06 | 000,071,096 | ---- | M] () -- C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
========== Modules (No Company Name) ==========
MOD - [2011.12.22 18:15:43 | 008,527,008 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2011.12.22 14:19:45 | 002,124,760 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2010.08.09 23:01:06 | 000,067,872 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011.08.12 00:38:04 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
SRV:64bit: - [2010.11.26 03:54:12 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2011.12.20 10:36:04 | 000,147,336 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe -- (LMIMaint)
SRV - [2011.12.20 10:35:15 | 000,375,176 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2011.10.14 07:01:50 | 000,994,360 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
SRV - [2011.06.01 13:44:54 | 002,337,144 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2011.02.22 13:57:30 | 000,070,928 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files (x86)\ThreatFire\TFService.exe -- (ThreatFire)
SRV - [2010.11.08 12:04:18 | 000,407,424 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe -- (LogMeIn)
SRV - [2010.09.08 20:46:00 | 003,852,792 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWow64\GameMon.des -- (npggsvc)
SRV - [2010.09.05 21:06:17 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.09.21 16:24:40 | 001,420,560 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel(R)
SRV - [2009.09.21 16:00:44 | 000,831,760 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel(R)
SRV - [2009.09.06 13:38:06 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011.12.20 10:35:17 | 000,087,456 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV:64bit: - [2011.09.11 18:45:22 | 000,035,664 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (AvgMfx64)
DRV:64bit: - [2011.04.13 14:04:38 | 000,045,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:64bit: - [2011.04.12 12:01:38 | 000,052,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (USB)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.02.22 13:57:58 | 000,074,824 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TfSysMon.sys -- (TfSysMon)
DRV:64bit: - [2011.02.22 13:57:56 | 000,041,888 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TfNetMon.sys -- (TfNetMon)
DRV:64bit: - [2011.02.22 13:57:54 | 000,065,072 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TfFsMon.sys -- (TfFsMon)
DRV:64bit: - [2011.02.18 16:36:58 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2010.11.26 05:20:20 | 008,120,320 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2010.11.26 05:20:20 | 008,120,320 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010.11.26 03:16:46 | 000,289,792 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 10:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010.09.05 21:06:13 | 000,269,904 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (AvgLdx64)
DRV:64bit: - [2010.09.01 09:30:58 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI)
DRV:64bit: - [2010.04.29 05:55:42 | 000,032,768 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\androidusb.sys -- (androidusb)
DRV:64bit: - [2009.12.11 00:43:53 | 000,834,544 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2009.11.12 13:48:56 | 000,005,504 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\StarOpen.sys -- (StarOpen)
DRV:64bit: - [2009.10.30 04:09:03 | 000,303,616 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2009.10.30 04:09:00 | 000,035,328 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2009.09.15 12:34:20 | 006,816,256 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5v64.sys -- (netw5v64) Intel(R)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 01:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009.06.10 22:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:64bit: - [2009.06.10 22:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:64bit: - [2009.06.10 22:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2008.08.11 12:40:58 | 000,072,216 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV:64bit: - [2008.08.11 12:40:32 | 000,011,552 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lmimirr.sys -- (lmimirr)
DRV:64bit: - [2007.03.28 07:50:18 | 000,046,592 | ---- | M] (Winbond Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\winbondcir.sys -- (winbondcir)
DRV:64bit: - [2006.11.18 13:07:48 | 000,055,296 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rixdpx64.sys -- (rismxdp)
DRV - [2011.07.22 17:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV - [2011.07.12 22:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV - [2009.11.12 13:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\SysWow64\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2008.08.11 12:41:00 | 000,015,928 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys -- (LMIInfo)
DRV - [2005.01.03 16:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 05 31 1F C7 EC B1 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.param.yahoo-fr: ""
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/ig"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6.5
FF - prefs.js..extensions.enabledItems: {9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}:3.0.5
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2
FF - prefs.js..extensions.enabledItems: LogMeInClient@logmein.com:1.0.0.608
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.0.3
FF - prefs.js..extensions.enabledItems: {37fa1426-b82d-11db-8314-0800200c9a66}:2.7.7
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {5384767E-00D9-40E9-B72F-9CC39D655D6F}:1.4.1.0
FF - prefs.js..network.proxy.http: "137.226.138.156"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.type: 0
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@logitech.com/HarmonyRemote,version=1.0.0: C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIE6C2~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIE6C2~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.3-rc: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.12.22 14:19:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.11.13 22:07:55 | 000,000,000 | ---D | M]
[2009.10.30 02:59:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Peter\AppData\Roaming\mozilla\Extensions
[2011.12.23 18:02:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\2pgd8y4e.default\extensions
[2011.12.08 23:08:55 | 000,000,000 | ---D | M] (WebMail Notifier) -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\2pgd8y4e.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
[2011.04.05 02:33:52 | 000,000,000 | ---D | M] (EPUBReader) -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\2pgd8y4e.default\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2010.09.05 21:09:10 | 000,000,000 | ---D | M] (CookieSafe) -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\2pgd8y4e.default\extensions\{9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}
[2011.07.05 22:25:35 | 000,000,000 | ---D | M] ("FacebookBlocker") -- C:\Users\Peter\AppData\Roaming\mozilla\Firefox\Profiles\2pgd8y4e.default\extensions\facebookBlocker@webgraph.com
[2011.12.22 15:04:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.10.29 19:30:24 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.12.22 15:04:29 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\PETER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2PGD8Y4E.DEFAULT\EXTENSIONS\{0545B830-F0AA-4D7E-8820-50A4629A56FE}.XPI
() (No name found) -- C:\USERS\PETER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2PGD8Y4E.DEFAULT\EXTENSIONS\{3D7EB24F-2740-49DF-8937-200B1CC08F8A}.XPI
() (No name found) -- C:\USERS\PETER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2PGD8Y4E.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) -- C:\USERS\PETER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2PGD8Y4E.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\PETER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2PGD8Y4E.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) -- C:\USERS\PETER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2PGD8Y4E.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
[2011.12.22 14:19:45 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.11.10 05:54:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.09.20 03:03:43 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.09.20 03:03:43 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.09.20 03:03:43 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.20 03:03:43 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
O1 HOSTS File: ([2009.11.16 21:25:14 | 000,000,863 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.newsleecher.com
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIE6C2~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [ThreatFire] C:\Program Files (x86)\ThreatFire\TFTray.exe (PC Tools)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - Reg Error: Key error. File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6ABAC106-146A-41C0-AF0C-D84549F12A95}: DhcpNameServer = 195.50.140.118 195.50.140.180
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E4A4A2F8-9C69-4EB0-BB85-29558E84B414}: NameServer = 195.50.140.118 195.50.140.180
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.12.24 10:29:59 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\SUPERAntiSpyware.com
[2011.12.24 10:25:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011.12.24 10:24:59 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011.12.24 10:24:59 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011.12.24 10:16:52 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.12.22 20:06:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2011.12.22 20:05:28 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Peter\Desktop\esetsmartinstaller_enu.exe
[2011.12.22 19:02:21 | 001,917,952 | ---- | C] (AVAST Software) -- C:\Users\Peter\Desktop\aswMBR.exe
[2011.12.22 18:18:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011.12.22 16:27:47 | 004,348,461 | ---- | C] (Swearware) -- C:\Users\Peter\Desktop\ComboFix.exe
[2011.12.22 15:04:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011.12.22 15:04:27 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2011.12.22 15:04:27 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2011.12.22 15:04:26 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2011.12.22 14:59:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2011.12.22 14:56:44 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Local\Secunia PSI
[2011.12.22 14:56:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Secunia
[2011.12.22 12:47:12 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
[2011.12.22 12:44:59 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Malwarebytes
[2011.12.22 12:44:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.12.22 12:44:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.12.22 12:44:47 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011.12.22 12:44:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.12.22 12:19:06 | 000,414,368 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011.12.22 12:18:50 | 000,000,000 | -HSD | C] -- C:\Users\Peter\AppData\Local\edbc5963
[2011.12.21 11:03:07 | 000,000,000 | ---D | C] -- C:\ElsterFormular
[2011.12.17 23:06:30 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\dvdcss
[2011.12.15 22:40:30 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\AKVIS
[2011.12.15 22:40:27 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2011.12.15 22:40:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AKVIS
[2011.12.15 22:40:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AKVIS
[2011.12.14 14:13:42 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011.12.14 14:13:41 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011.12.14 14:13:40 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011.12.14 14:13:40 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2011.12.14 14:13:40 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011.12.14 14:13:40 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011.12.14 14:13:38 | 002,309,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011.12.14 14:13:38 | 001,493,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2011.12.14 14:13:38 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2011.12.14 14:13:38 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011.12.14 14:13:38 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011.12.14 10:56:22 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2011.12.14 10:55:56 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2011.12.14 10:55:56 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2011.12.08 23:08:25 | 000,000,000 | ---D | C] -- C:\Users\Peter\ElsterFormular
[2011.12.08 21:10:04 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\elsterformular
[2011.12.08 21:02:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ElsterFormular
[2011.12.08 21:02:02 | 000,000,000 | ---D | C] -- C:\ProgramData\elsterformular
[2011.12.08 21:01:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ElsterFormular
[2011.12.04 11:39:51 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Local\Elo
[2011.12.04 11:30:50 | 000,887,808 | ---- | C] (ELO Digital Office GmbH) -- C:\Windows\SysNative\EloPrinterX64Cfg.dll
[2011.12.04 11:29:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ELOoffice
[2011.12.04 11:28:45 | 000,600,064 | ---- | C] (ELO Digital Office GmbH) -- C:\Windows\SysWow64\ELOHTML.ocx
[2011.12.04 11:28:45 | 000,212,480 | ---- | C] (Eastman Kodak) -- C:\Windows\SysWow64\PCDLIB32.DLL
[2011.12.04 11:28:43 | 001,347,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvbvm50.dll
[2011.12.04 11:28:43 | 000,064,432 | ---- | C] (Sheridan Software Systems, Inc.) -- C:\Windows\SysWow64\threed.vbx
[2011.12.04 11:28:43 | 000,026,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbc16gt.dll
[2011.12.04 11:28:43 | 000,011,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccp32.cpl
[2011.12.04 11:28:42 | 000,253,952 | ---- | C] (Apex Software Corporation) -- C:\Windows\SysWow64\grdkrn32.dll
[2011.12.04 11:28:42 | 000,005,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ds16gt.dll
[2011.12.04 11:28:40 | 000,385,100 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSVCRTD.DLL
[2011.12.04 11:28:36 | 000,929,844 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFC42D.DLL
[2011.12.04 11:28:36 | 000,322,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFC30.DLL
[2011.12.04 11:26:46 | 001,248,768 | ---- | C] (Softek Software Ltd) -- C:\Windows\SysWow64\SoftekBarcode.dll
[2011.12.04 11:26:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ELOoffice
[2011.12.04 11:26:31 | 000,000,000 | ---D | C] -- C:\ProgramData\ELO Digital Office
[2011.12.02 23:20:37 | 000,000,000 | R--D | C] -- C:\Users\Peter\Dropbox
[2011.12.02 23:19:21 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2011.12.02 23:11:01 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Dropbox
[2011.11.26 12:31:49 | 000,000,000 | ---D | C] -- C:\Users\Peter\Documents\Scans
[2011.11.26 12:29:43 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonIJScan
[2011.11.26 12:29:01 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Canon
[2011.03.24 23:05:42 | 000,018,944 | ---- | C] ( ) -- C:\Windows\SysWow64\Implode.dll
========== Files - Modified Within 30 Days ==========
[2011.12.24 11:35:36 | 000,013,456 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.12.24 11:35:36 | 000,013,456 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.12.24 11:27:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.12.24 11:27:13 | 3219,988,480 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.24 10:25:03 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.12.24 09:35:25 | 090,827,720 | ---- | M] () -- C:\Windows\SysNative\drivers\Avg\incavi.avm
[2011.12.23 15:23:31 | 000,002,002 | -H-- | M] () -- C:\Users\Peter\Documents\Default.rdp
[2011.12.22 22:34:54 | 000,018,141 | ---- | M] () -- C:\Users\Peter\Desktop\OTL.zip
[2011.12.22 22:20:59 | 000,000,188 | ---- | M] () -- C:\Users\Peter\defogger_reenable
[2011.12.22 21:00:36 | 000,050,477 | ---- | M] () -- C:\Users\Peter\Desktop\Defogger.exe
[2011.12.22 20:05:46 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Peter\Desktop\esetsmartinstaller_enu.exe
[2011.12.22 20:05:36 | 000,000,512 | ---- | M] () -- C:\Users\Peter\Desktop\MBR.dat
[2011.12.22 19:02:35 | 001,917,952 | ---- | M] (AVAST Software) -- C:\Users\Peter\Desktop\aswMBR.exe
[2011.12.22 18:18:11 | 000,001,258 | ---- | M] () -- C:\Users\Peter\Desktop\Spybot - Search & Destroy.lnk
[2011.12.22 18:15:43 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011.12.22 16:28:23 | 004,348,461 | ---- | M] (Swearware) -- C:\Users\Peter\Desktop\ComboFix.exe
[2011.12.22 14:56:37 | 000,001,106 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2011.12.22 14:53:57 | 000,002,014 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011.12.22 14:15:56 | 000,196,608 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
[2011.12.22 12:47:16 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Peter\Desktop\OTL.exe
[2011.12.22 12:44:51 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.12.21 11:10:34 | 000,001,476 | ---- | M] () -- C:\Users\Peter\Desktop\2006.06
[2011.12.21 11:03:48 | 000,000,730 | ---- | M] () -- C:\Users\Public\Desktop\ElsterFormular 2006-2007.lnk
[2011.12.20 10:35:17 | 000,087,456 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIRfsClientNP.dll
[2011.12.20 10:35:16 | 000,080,768 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIinit.dll
[2011.12.20 10:35:16 | 000,034,688 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIport.dll
[2011.12.19 12:23:06 | 001,498,506 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.12.19 12:23:06 | 000,654,188 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.12.19 12:23:06 | 000,616,030 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.12.19 12:23:06 | 000,130,028 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.12.19 12:23:06 | 000,106,410 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.12.16 21:14:42 | 000,002,125 | ---- | M] () -- C:\Users\Peter\Desktop\Peter 2008.08
[2011.12.15 22:40:06 | 000,000,941 | ---- | M] () -- C:\Users\Public\Desktop\AKVIS Sketch.lnk
[2011.12.15 13:33:57 | 000,171,924 | ---- | M] () -- C:\Users\Peter\Desktop\Mail Slip - 170723495493.pdf
[2011.12.14 17:15:44 | 000,351,976 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.12.08 22:05:07 | 000,001,336 | ---- | M] () -- C:\Users\Public\Desktop\ElsterFormular 2008-2009.lnk
[2011.12.08 21:18:03 | 000,004,153 | ---- | M] () -- C:\Users\Peter\Documents\ESt2009_Venne_Peter.elfo
[2011.12.08 21:02:02 | 000,001,229 | ---- | M] () -- C:\Users\Public\Desktop\ElsterFormular.lnk
[2011.12.08 08:03:06 | 000,000,997 | ---- | M] () -- C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2011.12.08 08:03:05 | 000,001,017 | ---- | M] () -- C:\Users\Peter\Desktop\Dropbox.lnk
[2011.12.04 11:32:14 | 000,008,608 | ---- | M] () -- C:\Windows\SysWow64\sx_p2d.tlb
[2011.12.04 11:29:44 | 000,001,879 | ---- | M] () -- C:\Users\Public\Desktop\ELOoffice.lnk
[2011.12.04 11:28:53 | 000,000,209 | ---- | M] () -- C:\Windows\ODBCINST.INI
[2011.12.04 11:26:33 | 000,000,000 | ---- | M] () -- C:\Windows\FULINST.INI
[2011.12.02 20:13:12 | 000,112,216 | ---- | M] () -- C:\Users\Peter\Desktop\KHT_Bescheinigung.pdf
[2011.11.29 21:48:55 | 001,011,182 | ---- | M] () -- C:\Users\Peter\Desktop\9363652.pdf
[2011.11.29 13:56:56 | 001,788,147 | ---- | M] () -- C:\Users\Peter\Desktop\Arbeitszeugnis EXG.pdf
[2011.11.29 13:45:04 | 005,988,121 | ---- | M] () -- C:\Users\Peter\Desktop\PeterV - Unterlagen.pdf
[2011.11.26 12:24:00 | 000,002,095 | ---- | M] () -- C:\Users\Public\Desktop\Canon MP Navigator EX 3.1.lnk
[2011.11.24 21:23:38 | 000,107,781 | ---- | M] () -- C:\Users\Peter\Desktop\Lebenslauf - 2011 - Rev1.pdf
========== Files Created - No Company Name ==========
[2011.12.24 10:25:03 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.12.22 22:34:54 | 000,018,141 | ---- | C] () -- C:\Users\Peter\Desktop\OTL.zip
[2011.12.22 22:20:59 | 000,000,188 | ---- | C] () -- C:\Users\Peter\defogger_reenable
[2011.12.22 21:00:35 | 000,050,477 | ---- | C] () -- C:\Users\Peter\Desktop\Defogger.exe
[2011.12.22 20:05:36 | 000,000,512 | ---- | C] () -- C:\Users\Peter\Desktop\MBR.dat
[2011.12.22 18:18:11 | 000,001,258 | ---- | C] () -- C:\Users\Peter\Desktop\Spybot - Search & Destroy.lnk
[2011.12.22 14:56:37 | 000,001,106 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2011.12.22 14:56:37 | 000,001,069 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2011.12.22 14:53:57 | 000,002,014 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011.12.22 12:44:51 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.12.21 11:10:34 | 000,001,476 | ---- | C] () -- C:\Users\Peter\Desktop\2006.06
[2011.12.21 11:03:48 | 000,000,730 | ---- | C] () -- C:\Users\Public\Desktop\ElsterFormular 2006-2007.lnk
[2011.12.16 12:04:17 | 000,002,125 | ---- | C] () -- C:\Users\Peter\Desktop\Peter 2008.08
[2011.12.15 22:40:05 | 000,000,941 | ---- | C] () -- C:\Users\Public\Desktop\AKVIS Sketch.lnk
[2011.12.15 13:33:57 | 000,171,924 | ---- | C] () -- C:\Users\Peter\Desktop\Mail Slip - 170723495493.pdf
[2011.12.08 22:05:07 | 000,001,336 | ---- | C] () -- C:\Users\Public\Desktop\ElsterFormular 2008-2009.lnk
[2011.12.08 21:17:59 | 000,004,153 | ---- | C] () -- C:\Users\Peter\Documents\ESt2009_Venne_Peter.elfo
[2011.12.08 21:02:02 | 000,001,229 | ---- | C] () -- C:\Users\Public\Desktop\ElsterFormular.lnk
[2011.12.04 11:32:14 | 000,008,608 | ---- | C] () -- C:\Windows\SysWow64\sx_p2d.tlb
[2011.12.04 11:29:44 | 000,001,879 | ---- | C] () -- C:\Users\Public\Desktop\ELOoffice.lnk
[2011.12.04 11:28:53 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011.12.04 11:28:45 | 000,350,208 | ---- | C] () -- C:\Windows\SysWow64\EloOpenOffice.dll
[2011.12.04 11:28:45 | 000,163,160 | ---- | C] () -- C:\Windows\SysWow64\ELOComRes.dll
[2011.12.04 11:28:42 | 000,005,632 | ---- | C] () -- C:\Windows\SysWow64\fteh006n.dll
[2011.12.04 11:26:33 | 000,000,000 | ---- | C] () -- C:\Windows\FULINST.INI
[2011.12.02 23:20:37 | 000,001,017 | ---- | C] () -- C:\Users\Peter\Desktop\Dropbox.lnk
[2011.12.02 23:19:32 | 000,000,997 | ---- | C] () -- C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2011.12.02 20:12:51 | 000,112,216 | ---- | C] () -- C:\Users\Peter\Desktop\KHT_Bescheinigung.pdf
[2011.11.29 21:48:49 | 001,011,182 | ---- | C] () -- C:\Users\Peter\Desktop\9363652.pdf
[2011.11.29 13:56:53 | 001,788,147 | ---- | C] () -- C:\Users\Peter\Desktop\Arbeitszeugnis EXG.pdf
[2011.11.29 13:43:16 | 005,988,121 | ---- | C] () -- C:\Users\Peter\Desktop\PeterV - Unterlagen.pdf
[2011.11.26 12:24:00 | 000,002,095 | ---- | C] () -- C:\Users\Public\Desktop\Canon MP Navigator EX 3.1.lnk
[2011.11.24 21:18:51 | 000,107,781 | ---- | C] () -- C:\Users\Peter\Desktop\Lebenslauf - 2011 - Rev1.pdf
[2011.09.28 04:44:27 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2011.09.28 04:42:38 | 000,107,520 | RHS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.dll
[2011.07.02 19:18:19 | 000,000,600 | ---- | C] () -- C:\Users\Peter\AppData\Roaming\winscp.rnd
[2011.05.26 02:51:13 | 000,000,255 | ---- | C] () -- C:\Windows\Brpfx04a.ini
[2011.05.26 02:51:13 | 000,000,094 | ---- | C] () -- C:\Windows\brpcfx.ini
[2011.05.26 02:50:54 | 000,000,419 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.03.24 23:05:43 | 000,139,776 | ---- | C] () -- C:\Windows\SysWow64\UserEdit.dll
[2011.03.24 23:05:21 | 000,100,352 | ---- | C] () -- C:\Windows\SysWow64\pg32conv.dll
[2011.03.24 23:05:19 | 000,016,384 | ---- | C] () -- C:\Windows\SysWow64\tempautoupsys.exe
[2011.03.24 23:05:17 | 000,786,432 | ---- | C] () -- C:\Windows\SysWow64\QXSync.exe
[2010.12.09 04:42:34 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.09.17 20:17:00 | 000,002,888 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2009.11.20 05:10:31 | 000,000,877 | ---- | C] () -- C:\Users\Peter\AppData\Roaming\coreavc.ini
[2009.10.30 03:00:23 | 000,007,168 | ---- | C] () -- C:\Windows\SysWow64\drivers\StarOpen.sys
[2009.10.30 02:57:11 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009.10.30 02:50:35 | 000,000,095 | ---- | C] () -- C:\Windows\winamp.ini
[2009.10.30 02:49:59 | 000,819,200 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2009.10.30 02:49:59 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2002.10.15 23:54:04 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
========== LOP Check ==========
[2010.09.30 18:36:36 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\.minecraft
[2011.09.02 19:30:37 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Ahnenblatt
[2011.07.09 18:09:24 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\avidemux
[2011.08.22 02:43:38 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\calibre
[2010.09.17 12:37:39 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Canneverbe Limited
[2011.11.26 12:29:44 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Canon
[2011.12.24 09:46:26 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\DAEMON Tools Lite
[2011.01.16 23:22:37 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\DirectoryListPrintPro
[2011.12.24 11:29:07 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Dropbox
[2011.02.10 15:34:04 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.12.08 21:10:05 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\elsterformular
[2010.09.06 15:52:49 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\GrabIt
[2011.08.07 21:56:41 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\gtk-2.0
[2009.10.30 02:58:30 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\IrfanView
[2010.09.14 16:27:45 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\LolClient
[2010.09.08 02:48:35 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\mkvtoolnix
[2010.10.02 02:57:32 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\My Games
[2009.11.16 21:45:33 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\NewsLeecher
[2011.01.16 23:52:43 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Personal Video Database
[2010.09.10 02:57:14 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\SharePod
[2011.06.04 19:25:05 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\TeamViewer
[2010.09.07 13:01:06 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\Teleca
[2011.12.24 09:46:25 | 000,000,000 | ---D | M] -- C:\Users\Peter\AppData\Roaming\uTorrent
[2011.12.22 08:45:19 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report > 9. Den Punkt verstehe ich nicht. Soll ich combofix ausführen? Bislang habe ich diesbezüglich immer den "Mach das bloß nicht einfach so" disclaimer gesehen.
Vielen Dank schon mal! Ich hoffe wir kommen dem Problem "näher" :applaus: |