puky_vs_puky | 25.02.2013 16:58 | Ich bin ein wenig irritiert wegen der Aussage "Poste beide Logs". Habe jetzt eines erstellt nach den obigen Angaben und dann mit den selben Einstellungen noch eines, diesmal aber mit den Custom Scans.
OTL Log ohne Custom Scans: Code:
OTL logfile created on: 2/25/2013 4:02:25 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,015.00 Mb Total Physical Memory | 783.00 Mb Available Physical Memory | 77.00% Memory free
903.00 Mb Paging File | 816.00 Mb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 139.03 Gb Total Space | 118.99 Gb Free Space | 85.59% Space Free | Partition Type: NTFS
Drive H: | 10.00 Gb Total Space | 8.34 Gb Free Space | 83.36% Space Free | Partition Type: NTFS
Drive I: | 14.70 Gb Total Space | 13.72 Gb Free Space | 93.31% Space Free | Partition Type: FAT32
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled] -- -- (HidServ)
SRV - [2013/02/18 03:38:17 | 000,251,248 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2010/08/30 08:17:13 | 000,079,360 | ---- | M] (SolidWorks) [On_Demand] -- C:\Programme\Gemeinsame Dateien\SolidWorks Shared\Service\SolidWorksLicensing.exe -- (SolidWorks Licensing Service)
SRV - [2009/09/25 14:42:00 | 000,593,920 | ---- | M] ( ) [Auto] -- C:\WINDOWS\System32\LMabcoms.exe -- (lmab_device)
SRV - [2007/12/17 03:21:06 | 000,095,480 | ---- | M] () [On_Demand] -- C:\Programme\Lectra\VigiPrint\bin\vpdaemon.exe -- (VPDaemon)
SRV - [2007/12/07 08:27:48 | 000,234,232 | ---- | M] () [Auto] -- C:\Programme\Lectra\IManager\bin\lpdaemon.exe -- (LpDaemon)
SRV - [2007/12/07 08:27:28 | 000,463,096 | ---- | M] () [Auto] -- C:\Programme\Lectra\IManager\bin\fontserver.exe -- (FontServer)
SRV - [2007/09/28 06:13:32 | 000,193,944 | ---- | M] () [Auto] -- C:\Programme\Lectra\Modaservice\modaserv.exe -- (Modaservice)
SRV - [2007/08/07 22:24:30 | 000,800,112 | ---- | M] (Trend Micro Inc.) [Auto] -- C:\Programme\Trend Micro\OfficeScan Client\tmlisten.exe -- (tmlisten)
SRV - [2007/08/07 22:24:28 | 000,771,440 | ---- | M] (Trend Micro Inc.) [Auto] -- C:\Programme\Trend Micro\OfficeScan Client\ntrtscan.exe -- (ntrtscan)
SRV - [2007/04/04 15:35:46 | 000,943,696 | ---- | M] (Trend Micro Inc.) [Disabled] -- C:\Programme\Trend Micro\OfficeScan Client\TmPfw.exe -- (TmPfw)
SRV - [2007/01/04 12:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto] -- C:\Programme\Gemeinsame Dateien\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2000/07/13 07:20:38 | 000,365,568 | ---- | M] () [Auto] -- C:\Programme\Lectra\Lectradmin\Licenses\Bin\wlserv1_3.exe -- (LicenseServ)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (i2omgmt)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - [2011/07/12 03:44:10 | 000,262,416 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- C:\Programme\Trend Micro\OfficeScan Client\tmxpflt.sys -- (TmFilter)
DRV - [2011/07/12 03:43:58 | 000,036,624 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- C:\Programme\Trend Micro\OfficeScan Client\tmpreflt.sys -- (TmPreFilter)
DRV - [2011/07/12 03:09:32 | 001,405,720 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- C:\Programme\Trend Micro\OfficeScan Client\vsapint.sys -- (VSApiNt)
DRV - [2007/12/24 11:37:00 | 000,138,384 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2007/09/24 03:45:49 | 000,047,616 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\Haspnt.sys -- (Haspnt)
DRV - [2007/04/20 11:44:58 | 000,307,984 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\TM_CFW.sys -- (tmcfw)
DRV - [2006/11/22 03:01:48 | 000,693,760 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock)
DRV - [2006/07/04 12:29:18 | 004,306,944 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/05/10 10:00:16 | 000,156,160 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2006/04/07 07:19:32 | 000,067,584 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\baspxp32.sys -- (Blfp)
DRV - [2005/01/07 10:07:16 | 000,145,920 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Hdaudio.sys -- (HdAudAddService)
DRV - [2004/08/03 11:29:50 | 000,019,455 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wVchNTxx.sys -- (iAimFP4)
DRV - [2004/08/03 11:29:48 | 000,012,063 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wSiINTxx.sys -- (iAimFP3)
DRV - [2004/08/03 11:29:46 | 000,025,471 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV10nt.sys -- (iAimTV5)
DRV - [2004/08/03 11:29:46 | 000,023,615 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wCh7xxNT.sys -- (iAimTV4)
DRV - [2004/08/03 11:29:46 | 000,022,271 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV06nt.sys -- (iAimTV6)
DRV - [2004/08/03 11:29:44 | 000,033,599 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV04nt.sys -- (iAimTV3)
DRV - [2004/08/03 11:29:44 | 000,019,551 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV02NT.sys -- (iAimTV1)
DRV - [2004/08/03 11:29:42 | 000,029,311 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV01nt.sys -- (iAimTV0)
DRV - [2004/08/03 11:29:42 | 000,011,871 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV09NT.sys -- (iAimFP7)
DRV - [2004/08/03 11:29:40 | 000,011,807 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV07nt.sys -- (iAimFP5)
DRV - [2004/08/03 11:29:40 | 000,011,295 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV08NT.sys -- (iAimFP6)
DRV - [2004/08/03 11:29:38 | 000,161,020 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x)
DRV - [2004/08/03 11:29:38 | 000,012,415 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV01nt.sys -- (iAimFP0)
DRV - [2004/08/03 11:29:38 | 000,012,127 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV02NT.sys -- (iAimFP1)
DRV - [2004/08/03 11:29:38 | 000,011,775 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV05NT.sys -- (iAimFP2)
DRV - [2002/08/07 12:25:52 | 000,010,352 | ---- | M] (Impact Technologies) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\fitpciuf.sys -- (fitpciuf)
DRV - [2002/08/07 12:25:28 | 000,101,696 | ---- | M] (Impact Technologies) [Kernel | System] -- C:\WINDOWS\system32\drivers\fitpcisr.sys -- (fitpcisr)
DRV - [2002/08/07 12:25:00 | 000,040,080 | ---- | M] (Impact Technologies) [Kernel | System] -- C:\WINDOWS\system32\drivers\fitpcimf.sys -- (fitpcimf)
DRV - [2002/08/07 12:24:36 | 000,009,528 | ---- | M] (Impact Technologies) [Kernel | System] -- C:\WINDOWS\system32\drivers\fitmep.sys -- (fitmep)
DRV - [2002/04/04 00:32:06 | 000,028,416 | R--- | M] (LSI Logic) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\symmpi.sys -- (Symmpi)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.20.10:8080
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.orwell.de/
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 217.7.189.156:8080
IE - HKU\Canfora_ON_C\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://www.leo.org/https://www.gmx.net/ [binary data]
IE - HKU\Canfora_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.linguee.de/
IE - HKU\Canfora_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Canfora_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\Canfora_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.20.10:8080
IE - HKU\lectra.GIACOMO_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
IE - HKU\lectra.GIACOMO_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\lectra_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
IE - HKU\lectra_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
O1 HOSTS File: ([2010/12/10 06:42:17 | 000,001,329 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 192.168.11.83 orwell13
O1 - Hosts: 192.168.11.120 orwell2
O1 - Hosts: 192.168.11.121 orwell3
O1 - Hosts: 192.168.11.122 orwell4
O1 - Hosts: 192.168.11.124 orwell12
O1 - Hosts: 192.168.11.125 topspin
O1 - Hosts: 192.168.11.126 Irion
O1 - Hosts: 192.168.11.128 orwell6
O1 - Hosts: 192.168.11.129 orwell7
O1 - Hosts: 192.168.11.130 orwell9
O1 - Hosts: 192.168.11.132 canfora
O1 - Hosts: 192.168.11.176 orwell1
O1 - Hosts: 192.168.11.249 storage1 STORAGE1
O1 - Hosts: 195.20.247.104 orwell.de
O1 - Hosts: 192.168.11.116 ET0021B7040849
O1 - Hosts: 192.168.11.116 ET0021B7040849.orwell.de
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programme\Google\GoogleToolbar2.dll (Google Germany GmbH)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programme\Google\GoogleToolbar2.dll (Google Germany GmbH)
O3 - HKU\Administrator.GIACOMO_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\GoogleToolbar2.dll (Google Germany GmbH)
O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\GoogleToolbar2.dll (Google Germany GmbH)
O3 - HKU\Canfora_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\GoogleToolbar2.dll (Google Germany GmbH)
O3 - HKU\lectra.GIACOMO_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\GoogleToolbar2.dll (Google Germany GmbH)
O3 - HKU\lectra_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\GoogleToolbar2.dll (Google Germany GmbH)
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [LectraVPDaemon] C:\Programme\Lectra\VigiPrint\bin\vpdaemon.exe ()
O4 - HKLM..\Run: [LectraXCDaemon] C:\Programme\Lectra\XChangCutOut\bin\xcdaemon.exe ()
O4 - HKLM..\Run: [OfficeScanNT Monitor] C:\Programme\Trend Micro\OfficeScan Client\pccntmon.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\CREATOR\Remind_XP.exe ()
O4 - HKLM..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe ()
O4 - HKLM..\Run: [SetRefresh] C:\Programme\Compaq\SetRefresh\SetRefresh.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [Verknüpfung mit der High Definition Audio-Eigenschaftenseite] C:\WINDOWS\System32\HdAShCut.exe (Windows (R) Server 2003 DDK provider)
O4 - HKU\Administrator.GIACOMO_ON_C..\Run: [] File not found
O4 - HKU\Administrator.GIACOMO_ON_C..\Run: [eDial.exe] C:\Programme\Aastra\Office eDial\\eDial.exe ()
O4 - HKU\Canfora_ON_C..\Run: [eDial.exe] C:\Programme\Aastra\Office eDial\eDial.exe (Aastra Telecom Schweiz AG)
O4 - HKU\Canfora_ON_C..\Run: [LMab1err] C:\Programme\Lexmark\ErrorApp\lmab1err.exe ( )
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\ButtonBox.lnk = C:\Programme\Lectra\ButtonBox\bin\microclavier.exe ()
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Digitizer.lnk = C:\Programme\Lectra\Digitizer\bin\digitizer.exe ()
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Printkey.exe.lnk = C:\Programme\Printkey\Printkey.exe (Fred's Software Company)
O7 - HKU\Administrator.GIACOMO_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Canfora_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\lectra.GIACOMO_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\lectra_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} https://192.168.11.143:4343/officescan/console/ClientInstall/WinNTChk.cab (ObjWinNTCheck Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} https://192.168.11.143:4343/officescan/console/ClientInstall/setup.cab (OfficeScan Corp Edition Web-Deployment SetupCtrl Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} https://192.168.11.143:4343/officescan/console/html/AtxEnc.cab (Encrypt Class)
O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} https://192.168.11.143:4343/officescan/console/ClientInstall/RemoveCtrl.cab (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189416100741 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1218106802239 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} hxxp://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://lectra-eu.webex.com/client/T23L/support/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\Canfora_ON_C Winlogon: Shell - (C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\ldr.mcb) - C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\ldr.mcb ()
O20 - HKU\Canfora_ON_C Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O32 - Unable to open key or key not present!
O32 - AutoRun File - [2004/04/30 10:01:00 | 000,000,053 | -HS- | M] () - H:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/08/15 06:05:09 | 001,081,480 | ---- | C] (Skype Technologies S.A.) -- C:\Programme\SkypeSetup.exe
[2010/12/10 06:54:06 | 000,401,408 | ---- | C] ( ) -- C:\WINDOWS\System32\lexlog.dll
[2010/12/10 06:53:29 | 001,040,384 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabserv.dll
[2010/12/10 06:53:29 | 000,847,872 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabusb1.dll
[2010/12/10 06:53:29 | 000,647,168 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabpmui.dll
[2010/12/10 06:53:29 | 000,479,232 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabpar1.dll
[2010/12/10 06:53:29 | 000,339,968 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabiesc.dll
[2010/12/10 06:53:28 | 000,905,216 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabip1.dll
[2010/12/10 06:53:28 | 000,593,920 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabcoms.exe
[2010/12/10 06:53:28 | 000,569,344 | ---- | C] ( ) -- C:\WINDOWS\System32\lmablmpm.dll
[2010/12/10 06:53:28 | 000,450,560 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabiobj.dll
[2010/12/10 06:53:28 | 000,364,544 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabinpa.dll
[2010/12/10 06:53:28 | 000,356,352 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabhcp.dll
[2010/12/10 06:53:27 | 000,802,816 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabcomc.dll
[2010/12/10 06:53:27 | 000,372,736 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabcomm.dll
[2010/12/07 08:19:03 | 000,630,784 | ---- | C] ( ) -- C:\WINDOWS\System32\softcoin.dll
[2010/12/07 08:19:01 | 000,425,984 | ---- | C] ( ) -- C:\WINDOWS\System32\gencoin.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/02/25 09:08:10 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/25 08:55:57 | 000,484,094 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2013/02/25 08:55:57 | 000,441,624 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/02/25 08:55:57 | 000,094,492 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2013/02/25 08:55:57 | 000,071,308 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/02/25 08:52:30 | 000,042,137 | ---- | M] () -- C:\WINDOWS\kzlb.mxg
[2013/02/25 08:52:28 | 000,050,844 | ---- | M] () -- C:\WINDOWS\ltqd.ncv
[2013/02/25 08:52:20 | 000,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/25 08:51:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/02/25 08:51:40 | 1064,624,128 | -HS- | M] () -- C:\hiberfil.sys
[2013/02/25 08:37:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/02/25 03:25:28 | 000,088,058 | ---- | M] () -- C:\WINDOWS\uzvjgy.vrn
[2013/02/25 03:24:52 | 000,045,626 | ---- | M] () -- C:\WINDOWS\ertm.rwk
[2013/02/25 03:21:56 | 000,220,149 | ---- | M] () -- C:\WINDOWS\bjupyso.ktj
[2013/02/25 03:19:58 | 000,190,070 | ---- | M] () -- C:\WINDOWS\weqd.zhp
[2013/02/25 02:29:37 | 000,000,021 | ---- | M] () -- C:\tmuninst.ini
[2013/02/25 02:08:53 | 000,012,952 | ---- | M] () -- C:\WINDOWS\cfgall.ini
[2013/02/25 02:07:13 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/02/22 06:26:55 | 000,002,411 | ---- | M] () -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\ModarisV5R2c4.lnk
[2013/02/21 05:46:59 | 000,002,473 | ---- | M] () -- C:\Dokumente und Einstellungen\Canfora\Desktop\Diamino V5R2.lnk
[2013/02/20 05:35:24 | 000,002,433 | ---- | M] () -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\VigiPrint.lnk
[2013/02/20 05:14:22 | 000,002,491 | ---- | M] () -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Diamino V5R2.lnk
[2013/02/19 03:58:31 | 000,002,495 | ---- | M] () -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Microsoft Word.lnk
[2013/02/18 05:21:56 | 000,546,647 | ---- | M] () -- C:\Dokumente und Einstellungen\Canfora\Eigene Dateien\janome 599 naehpark.pdf
[2013/02/18 03:38:16 | 000,697,712 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/02/18 03:38:16 | 000,074,096 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/02/25 03:21:59 | 000,045,626 | ---- | C] () -- C:\WINDOWS\ertm.rwk
[2013/02/25 03:21:59 | 000,042,137 | ---- | C] () -- C:\WINDOWS\kzlb.mxg
[2013/02/25 03:21:56 | 000,220,149 | ---- | C] () -- C:\WINDOWS\bjupyso.ktj
[2013/02/25 03:20:02 | 000,088,058 | ---- | C] () -- C:\WINDOWS\uzvjgy.vrn
[2013/02/25 03:19:58 | 000,190,070 | ---- | C] () -- C:\WINDOWS\weqd.zhp
[2013/02/25 03:19:58 | 000,050,844 | ---- | C] () -- C:\WINDOWS\ltqd.ncv
[2013/02/18 05:21:53 | 000,546,647 | ---- | C] () -- C:\Dokumente und Einstellungen\Canfora\Eigene Dateien\janome 599 naehpark.pdf
[2012/06/06 01:50:00 | 000,178,176 | ---- | C] () -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\ldr.mcb
[2010/11/09 08:15:42 | 000,007,498 | ---- | C] () -- C:\WINDOWS\cfgrs_ex.ini
[2010/11/09 08:15:41 | 000,008,319 | ---- | C] () -- C:\WINDOWS\cfgrs.ini
[2010/11/08 09:21:51 | 000,000,426 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2010/08/30 08:17:53 | 000,160,358 | ---- | C] () -- C:\WINDOWS\CAD Viewer Uninstaller.exe
[2010/08/30 08:17:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\eDrawingOfficeAutomator.INI
[2010/08/04 04:54:04 | 000,184,320 | ---- | C] () -- C:\WINDOWS\System32\EXIT32.DLL
[2008/11/18 06:26:18 | 000,000,028 | ---- | C] () -- C:\WINDOWS\pdf995.ini
[2008/11/18 06:25:59 | 000,000,065 | ---- | C] () -- C:\WINDOWS\wpd99.drv
[2008/11/18 06:25:16 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\pdfmona.dll
[2008/11/18 06:25:16 | 000,051,716 | ---- | C] () -- C:\WINDOWS\System32\pdf995mon.dll
[2008/10/29 05:44:26 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\lectra.GIACOMO\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2008/05/26 15:23:36 | 000,016,834 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2008/05/26 15:23:34 | 000,024,188 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2008/05/26 15:23:32 | 000,016,568 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2008/05/26 14:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 14:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/09 01:09:10 | 000,006,144 | ---- | C] () -- C:\Dokumente und Einstellungen\Canfora\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/15 05:22:09 | 000,000,073 | ---- | C] () -- C:\WINDOWS\PlotterList.ini
[2007/09/24 04:11:00 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\lectra\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2007/09/24 03:52:56 | 000,033,792 | ---- | C] () -- C:\WINDOWS\System32\liblectrafilemt.dll
[2007/09/24 03:52:56 | 000,033,792 | ---- | C] () -- C:\WINDOWS\System32\liblectrafile.dll
[2007/09/24 03:52:56 | 000,031,232 | ---- | C] () -- C:\WINDOWS\System32\liblectrafilest.dll
[2007/09/24 03:52:56 | 000,000,203 | ---- | C] () -- C:\WINDOWS\System32\lsprst.dll
[2007/09/24 03:50:48 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\tclpip80.dll
[2007/09/24 03:45:49 | 000,000,383 | ---- | C] () -- C:\WINDOWS\System32\haspdos.sys
[2007/09/24 03:38:49 | 000,051,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\atnt40k.sys
[2007/09/10 07:36:26 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\Canfora\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2007/09/10 05:56:40 | 000,397,336 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2007/09/10 05:42:00 | 000,000,489 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/09/10 05:41:59 | 000,000,063 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2007/09/10 05:41:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NSREX.INI
[2007/09/10 04:33:09 | 000,012,952 | ---- | C] () -- C:\WINDOWS\cfgall.ini
[2007/09/09 15:16:49 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2007/08/12 00:25:39 | 000,348,880 | ---- | C] () -- C:\WINDOWS\System32\igmedkrn.dll
[2007/08/12 00:25:39 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4642.dll
[2007/08/12 00:24:30 | 000,000,962 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2007/08/11 15:48:22 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2007/08/11 15:39:15 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2007/08/11 15:39:15 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2007/08/11 15:39:15 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2007/08/11 15:39:15 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2007/08/11 15:39:15 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2007/08/11 15:39:15 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2007/08/11 15:38:23 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2007/08/11 15:38:23 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2007/08/11 15:33:55 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2007/03/05 06:34:28 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2006/06/21 05:40:59 | 000,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
[2006/05/04 16:14:44 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/05/04 15:53:24 | 000,484,094 | ---- | C] () -- C:\WINDOWS\System32\perfh007.dat
[2006/05/04 15:53:24 | 000,441,624 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/05/04 15:53:24 | 000,094,492 | ---- | C] () -- C:\WINDOWS\System32\perfc007.dat
[2006/05/04 15:53:24 | 000,071,308 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/05/04 15:49:18 | 000,281,336 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2006/05/04 15:41:52 | 000,004,335 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/05/04 15:36:58 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/02/27 21:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/02/27 21:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/02/27 21:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\perfi007.dat
[2006/02/27 21:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/02/27 21:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/02/27 21:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\perfd007.dat
[2006/02/27 21:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/02/27 21:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/02/27 21:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2006/02/27 21:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2002/05/28 02:55:42 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2002/05/28 02:54:40 | 000,004,605 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[1999/01/22 13:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2011/08/08 04:02:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\Aastra Telecom Schweiz AG
[2010/08/30 08:17:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\DassaultSystemes
[2010/08/30 08:17:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\EDrawings
[2008/02/15 05:21:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\Lectra
[2007/09/10 06:42:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\OfficeUpdate12
[2007/09/10 00:01:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\SampleView
[2008/08/07 06:56:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\Windows Desktop Search
[2008/08/07 07:00:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\Windows Search
[2007/09/10 00:01:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\SampleView
[2011/01/25 10:04:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Aastra Telecom Schweiz AG
[2010/09/21 03:04:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\DassaultSystemes
[2010/09/21 03:04:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\EDrawings
[2008/12/08 07:14:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\InterVideo
[2013/02/21 05:48:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Lectra
[2008/11/18 06:26:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\pdf995
[2007/09/10 00:01:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\SampleView
[2010/12/10 06:02:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\TeamViewer
[2008/11/18 06:31:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Windows Desktop Search
[2008/08/11 02:32:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Windows Search
[2008/10/29 05:44:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\lectra.GIACOMO\Anwendungsdaten\Lectra
[2007/09/10 00:01:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\lectra.GIACOMO\Anwendungsdaten\SampleView
[2008/08/20 01:58:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\lectra\Anwendungsdaten\Lectra
[2007/09/10 00:01:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\lectra\Anwendungsdaten\SampleView
[2010/09/21 03:04:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DassaultSystemes
[2008/08/20 02:06:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Lectra
[2013/02/22 09:40:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\pdf995
========== Purity Check ==========
< End of report > OTL Log mit Custom Scans: Code:
OTL logfile created on: 2/25/2013 4:38:13 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,015.00 Mb Total Physical Memory | 787.00 Mb Available Physical Memory | 78.00% Memory free
903.00 Mb Paging File | 822.00 Mb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 139.03 Gb Total Space | 118.99 Gb Free Space | 85.59% Space Free | Partition Type: NTFS
Drive H: | 10.00 Gb Total Space | 8.34 Gb Free Space | 83.36% Space Free | Partition Type: NTFS
Drive I: | 14.70 Gb Total Space | 13.72 Gb Free Space | 93.31% Space Free | Partition Type: FAT32
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled] -- -- (HidServ)
SRV - [2013/02/18 03:38:17 | 000,251,248 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2010/08/30 08:17:13 | 000,079,360 | ---- | M] (SolidWorks) [On_Demand] -- C:\Programme\Gemeinsame Dateien\SolidWorks Shared\Service\SolidWorksLicensing.exe -- (SolidWorks Licensing Service)
SRV - [2009/09/25 14:42:00 | 000,593,920 | ---- | M] ( ) [Auto] -- C:\WINDOWS\System32\LMabcoms.exe -- (lmab_device)
SRV - [2007/12/17 03:21:06 | 000,095,480 | ---- | M] () [On_Demand] -- C:\Programme\Lectra\VigiPrint\bin\vpdaemon.exe -- (VPDaemon)
SRV - [2007/12/07 08:27:48 | 000,234,232 | ---- | M] () [Auto] -- C:\Programme\Lectra\IManager\bin\lpdaemon.exe -- (LpDaemon)
SRV - [2007/12/07 08:27:28 | 000,463,096 | ---- | M] () [Auto] -- C:\Programme\Lectra\IManager\bin\fontserver.exe -- (FontServer)
SRV - [2007/09/28 06:13:32 | 000,193,944 | ---- | M] () [Auto] -- C:\Programme\Lectra\Modaservice\modaserv.exe -- (Modaservice)
SRV - [2007/08/07 22:24:30 | 000,800,112 | ---- | M] (Trend Micro Inc.) [Auto] -- C:\Programme\Trend Micro\OfficeScan Client\tmlisten.exe -- (tmlisten)
SRV - [2007/08/07 22:24:28 | 000,771,440 | ---- | M] (Trend Micro Inc.) [Auto] -- C:\Programme\Trend Micro\OfficeScan Client\ntrtscan.exe -- (ntrtscan)
SRV - [2007/04/04 15:35:46 | 000,943,696 | ---- | M] (Trend Micro Inc.) [Disabled] -- C:\Programme\Trend Micro\OfficeScan Client\TmPfw.exe -- (TmPfw)
SRV - [2007/01/04 12:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto] -- C:\Programme\Gemeinsame Dateien\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2000/07/13 07:20:38 | 000,365,568 | ---- | M] () [Auto] -- C:\Programme\Lectra\Lectradmin\Licenses\Bin\wlserv1_3.exe -- (LicenseServ)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (i2omgmt)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - [2011/07/12 03:44:10 | 000,262,416 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- C:\Programme\Trend Micro\OfficeScan Client\tmxpflt.sys -- (TmFilter)
DRV - [2011/07/12 03:43:58 | 000,036,624 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- C:\Programme\Trend Micro\OfficeScan Client\tmpreflt.sys -- (TmPreFilter)
DRV - [2011/07/12 03:09:32 | 001,405,720 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- C:\Programme\Trend Micro\OfficeScan Client\vsapint.sys -- (VSApiNt)
DRV - [2007/12/24 11:37:00 | 000,138,384 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2007/09/24 03:45:49 | 000,047,616 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\Haspnt.sys -- (Haspnt)
DRV - [2007/04/20 11:44:58 | 000,307,984 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\TM_CFW.sys -- (tmcfw)
DRV - [2006/11/22 03:01:48 | 000,693,760 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock)
DRV - [2006/07/04 12:29:18 | 004,306,944 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/05/10 10:00:16 | 000,156,160 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2006/04/07 07:19:32 | 000,067,584 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\baspxp32.sys -- (Blfp)
DRV - [2005/01/07 10:07:16 | 000,145,920 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Hdaudio.sys -- (HdAudAddService)
DRV - [2004/08/03 11:29:50 | 000,019,455 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wVchNTxx.sys -- (iAimFP4)
DRV - [2004/08/03 11:29:48 | 000,012,063 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wSiINTxx.sys -- (iAimFP3)
DRV - [2004/08/03 11:29:46 | 000,025,471 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV10nt.sys -- (iAimTV5)
DRV - [2004/08/03 11:29:46 | 000,023,615 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wCh7xxNT.sys -- (iAimTV4)
DRV - [2004/08/03 11:29:46 | 000,022,271 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV06nt.sys -- (iAimTV6)
DRV - [2004/08/03 11:29:44 | 000,033,599 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV04nt.sys -- (iAimTV3)
DRV - [2004/08/03 11:29:44 | 000,019,551 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV02NT.sys -- (iAimTV1)
DRV - [2004/08/03 11:29:42 | 000,029,311 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV01nt.sys -- (iAimTV0)
DRV - [2004/08/03 11:29:42 | 000,011,871 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV09NT.sys -- (iAimFP7)
DRV - [2004/08/03 11:29:40 | 000,011,807 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV07nt.sys -- (iAimFP5)
DRV - [2004/08/03 11:29:40 | 000,011,295 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV08NT.sys -- (iAimFP6)
DRV - [2004/08/03 11:29:38 | 000,161,020 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x)
DRV - [2004/08/03 11:29:38 | 000,012,415 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV01nt.sys -- (iAimFP0)
DRV - [2004/08/03 11:29:38 | 000,012,127 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV02NT.sys -- (iAimFP1)
DRV - [2004/08/03 11:29:38 | 000,011,775 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV05NT.sys -- (iAimFP2)
DRV - [2002/08/07 12:25:52 | 000,010,352 | ---- | M] (Impact Technologies) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\fitpciuf.sys -- (fitpciuf)
DRV - [2002/08/07 12:25:28 | 000,101,696 | ---- | M] (Impact Technologies) [Kernel | System] -- C:\WINDOWS\system32\drivers\fitpcisr.sys -- (fitpcisr)
DRV - [2002/08/07 12:25:00 | 000,040,080 | ---- | M] (Impact Technologies) [Kernel | System] -- C:\WINDOWS\system32\drivers\fitpcimf.sys -- (fitpcimf)
DRV - [2002/08/07 12:24:36 | 000,009,528 | ---- | M] (Impact Technologies) [Kernel | System] -- C:\WINDOWS\system32\drivers\fitmep.sys -- (fitmep)
DRV - [2002/04/04 00:32:06 | 000,028,416 | R--- | M] (LSI Logic) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\symmpi.sys -- (Symmpi)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\Administrator.GIACOMO_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.20.10:8080
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.orwell.de/
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 217.7.189.156:8080
IE - HKU\Canfora_ON_C\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://www.leo.org/https://www.gmx.net/ [binary data]
IE - HKU\Canfora_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.linguee.de/
IE - HKU\Canfora_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Canfora_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\Canfora_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.20.10:8080
IE - HKU\lectra.GIACOMO_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
IE - HKU\lectra.GIACOMO_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\lectra_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
IE - HKU\lectra_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
O1 HOSTS File: ([2010/12/10 06:42:17 | 000,001,329 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 192.168.11.83 orwell13
O1 - Hosts: 192.168.11.120 orwell2
O1 - Hosts: 192.168.11.121 orwell3
O1 - Hosts: 192.168.11.122 orwell4
O1 - Hosts: 192.168.11.124 orwell12
O1 - Hosts: 192.168.11.125 topspin
O1 - Hosts: 192.168.11.126 Irion
O1 - Hosts: 192.168.11.128 orwell6
O1 - Hosts: 192.168.11.129 orwell7
O1 - Hosts: 192.168.11.130 orwell9
O1 - Hosts: 192.168.11.132 canfora
O1 - Hosts: 192.168.11.176 orwell1
O1 - Hosts: 192.168.11.249 storage1 STORAGE1
O1 - Hosts: 195.20.247.104 orwell.de
O1 - Hosts: 192.168.11.116 ET0021B7040849
O1 - Hosts: 192.168.11.116 ET0021B7040849.orwell.de
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programme\Google\GoogleToolbar2.dll (Google Germany GmbH)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programme\Google\GoogleToolbar2.dll (Google Germany GmbH)
O3 - HKU\Administrator.GIACOMO_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\GoogleToolbar2.dll (Google Germany GmbH)
O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\GoogleToolbar2.dll (Google Germany GmbH)
O3 - HKU\Canfora_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\GoogleToolbar2.dll (Google Germany GmbH)
O3 - HKU\lectra.GIACOMO_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\GoogleToolbar2.dll (Google Germany GmbH)
O3 - HKU\lectra_ON_C\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\GoogleToolbar2.dll (Google Germany GmbH)
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [LectraVPDaemon] C:\Programme\Lectra\VigiPrint\bin\vpdaemon.exe ()
O4 - HKLM..\Run: [LectraXCDaemon] C:\Programme\Lectra\XChangCutOut\bin\xcdaemon.exe ()
O4 - HKLM..\Run: [OfficeScanNT Monitor] C:\Programme\Trend Micro\OfficeScan Client\pccntmon.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\CREATOR\Remind_XP.exe ()
O4 - HKLM..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe ()
O4 - HKLM..\Run: [SetRefresh] C:\Programme\Compaq\SetRefresh\SetRefresh.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [Verknüpfung mit der High Definition Audio-Eigenschaftenseite] C:\WINDOWS\System32\HdAShCut.exe (Windows (R) Server 2003 DDK provider)
O4 - HKU\Administrator.GIACOMO_ON_C..\Run: [] File not found
O4 - HKU\Administrator.GIACOMO_ON_C..\Run: [eDial.exe] C:\Programme\Aastra\Office eDial\\eDial.exe ()
O4 - HKU\Canfora_ON_C..\Run: [eDial.exe] C:\Programme\Aastra\Office eDial\eDial.exe (Aastra Telecom Schweiz AG)
O4 - HKU\Canfora_ON_C..\Run: [LMab1err] C:\Programme\Lexmark\ErrorApp\lmab1err.exe ( )
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Administrator.GIACOMO_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Canfora_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\lectra.GIACOMO_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\lectra_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} https://192.168.11.143:4343/officescan/console/ClientInstall/WinNTChk.cab (ObjWinNTCheck Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} https://192.168.11.143:4343/officescan/console/ClientInstall/setup.cab (OfficeScan Corp Edition Web-Deployment SetupCtrl Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} https://192.168.11.143:4343/officescan/console/html/AtxEnc.cab (Encrypt Class)
O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} https://192.168.11.143:4343/officescan/console/ClientInstall/RemoveCtrl.cab (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189416100741 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1218106802239 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} hxxp://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://lectra-eu.webex.com/client/T23L/support/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = orwell.de
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\Canfora_ON_C Winlogon: Shell - (C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\ldr.mcb) - C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\ldr.mcb ()
O20 - HKU\Canfora_ON_C Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/30 10:01:00 | 000,000,053 | -HS- | M] () - H:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Programme\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
ActiveX: {8D1D0E9A-C799-4D28-9E29-0061D1E66E43} - Microsoft .NET Framework 1.1 Hotfix (KB928366)
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E78BFA60-5393-4C38-82AB-E8019E464EB4} - .NET Framework
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {ECD292A0-0347-4244-8C24-5DBCE990FB40} - Hotfix for Microsoft .NET Framework 3.0 (KB932471)
ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
ActiveX: Microsoft Base Smart Card Crypto Provider Package -
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: WmdmPmSp - File not found
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: SDMSSplash - hkey= - key= - C:\Programme\HP_SDMS\SDMSSplash\launcher.exe ()
MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Programme\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
MsConfig - StartUpReg: swg - hkey= - key= - C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2
========== Files/Folders - Created Within 30 Days ==========
[2011/08/15 06:05:09 | 001,081,480 | ---- | C] (Skype Technologies S.A.) -- C:\Programme\SkypeSetup.exe
[2010/12/10 06:54:06 | 000,401,408 | ---- | C] ( ) -- C:\WINDOWS\System32\lexlog.dll
[2010/12/10 06:53:29 | 001,040,384 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabserv.dll
[2010/12/10 06:53:29 | 000,847,872 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabusb1.dll
[2010/12/10 06:53:29 | 000,647,168 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabpmui.dll
[2010/12/10 06:53:29 | 000,479,232 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabpar1.dll
[2010/12/10 06:53:29 | 000,339,968 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabiesc.dll
[2010/12/10 06:53:28 | 000,905,216 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabip1.dll
[2010/12/10 06:53:28 | 000,593,920 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabcoms.exe
[2010/12/10 06:53:28 | 000,569,344 | ---- | C] ( ) -- C:\WINDOWS\System32\lmablmpm.dll
[2010/12/10 06:53:28 | 000,450,560 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabiobj.dll
[2010/12/10 06:53:28 | 000,364,544 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabinpa.dll
[2010/12/10 06:53:28 | 000,356,352 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabhcp.dll
[2010/12/10 06:53:27 | 000,802,816 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabcomc.dll
[2010/12/10 06:53:27 | 000,372,736 | ---- | C] ( ) -- C:\WINDOWS\System32\lmabcomm.dll
[2010/12/07 08:19:03 | 000,630,784 | ---- | C] ( ) -- C:\WINDOWS\System32\softcoin.dll
[2010/12/07 08:19:01 | 000,425,984 | ---- | C] ( ) -- C:\WINDOWS\System32\gencoin.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/02/25 09:08:10 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/25 08:55:57 | 000,484,094 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2013/02/25 08:55:57 | 000,441,624 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/02/25 08:55:57 | 000,094,492 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2013/02/25 08:55:57 | 000,071,308 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/02/25 08:52:30 | 000,042,137 | ---- | M] () -- C:\WINDOWS\kzlb.mxg
[2013/02/25 08:52:28 | 000,050,844 | ---- | M] () -- C:\WINDOWS\ltqd.ncv
[2013/02/25 08:52:20 | 000,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/25 08:51:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/02/25 08:51:40 | 1064,624,128 | -HS- | M] () -- C:\hiberfil.sys
[2013/02/25 08:37:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/02/25 03:25:28 | 000,088,058 | ---- | M] () -- C:\WINDOWS\uzvjgy.vrn
[2013/02/25 03:24:52 | 000,045,626 | ---- | M] () -- C:\WINDOWS\ertm.rwk
[2013/02/25 03:21:56 | 000,220,149 | ---- | M] () -- C:\WINDOWS\bjupyso.ktj
[2013/02/25 03:19:58 | 000,190,070 | ---- | M] () -- C:\WINDOWS\weqd.zhp
[2013/02/25 02:29:37 | 000,000,021 | ---- | M] () -- C:\tmuninst.ini
[2013/02/25 02:08:53 | 000,012,952 | ---- | M] () -- C:\WINDOWS\cfgall.ini
[2013/02/25 02:07:13 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/02/22 06:26:55 | 000,002,411 | ---- | M] () -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\ModarisV5R2c4.lnk
[2013/02/21 05:46:59 | 000,002,473 | ---- | M] () -- C:\Dokumente und Einstellungen\Canfora\Desktop\Diamino V5R2.lnk
[2013/02/20 05:35:24 | 000,002,433 | ---- | M] () -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\VigiPrint.lnk
[2013/02/20 05:14:22 | 000,002,491 | ---- | M] () -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Diamino V5R2.lnk
[2013/02/19 03:58:31 | 000,002,495 | ---- | M] () -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Microsoft Word.lnk
[2013/02/18 05:21:56 | 000,546,647 | ---- | M] () -- C:\Dokumente und Einstellungen\Canfora\Eigene Dateien\janome 599 naehpark.pdf
[2013/02/18 03:38:16 | 000,697,712 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/02/18 03:38:16 | 000,074,096 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/02/25 03:21:59 | 000,045,626 | ---- | C] () -- C:\WINDOWS\ertm.rwk
[2013/02/25 03:21:59 | 000,042,137 | ---- | C] () -- C:\WINDOWS\kzlb.mxg
[2013/02/25 03:21:56 | 000,220,149 | ---- | C] () -- C:\WINDOWS\bjupyso.ktj
[2013/02/25 03:20:02 | 000,088,058 | ---- | C] () -- C:\WINDOWS\uzvjgy.vrn
[2013/02/25 03:19:58 | 000,190,070 | ---- | C] () -- C:\WINDOWS\weqd.zhp
[2013/02/25 03:19:58 | 000,050,844 | ---- | C] () -- C:\WINDOWS\ltqd.ncv
[2013/02/18 05:21:53 | 000,546,647 | ---- | C] () -- C:\Dokumente und Einstellungen\Canfora\Eigene Dateien\janome 599 naehpark.pdf
[2012/06/06 01:50:00 | 000,178,176 | ---- | C] () -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\ldr.mcb
[2010/11/09 08:15:42 | 000,007,498 | ---- | C] () -- C:\WINDOWS\cfgrs_ex.ini
[2010/11/09 08:15:41 | 000,008,319 | ---- | C] () -- C:\WINDOWS\cfgrs.ini
[2010/11/08 09:21:51 | 000,000,426 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2010/08/30 08:17:53 | 000,160,358 | ---- | C] () -- C:\WINDOWS\CAD Viewer Uninstaller.exe
[2010/08/30 08:17:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\eDrawingOfficeAutomator.INI
[2010/08/04 04:54:04 | 000,184,320 | ---- | C] () -- C:\WINDOWS\System32\EXIT32.DLL
[2008/11/18 06:26:18 | 000,000,028 | ---- | C] () -- C:\WINDOWS\pdf995.ini
[2008/11/18 06:25:59 | 000,000,065 | ---- | C] () -- C:\WINDOWS\wpd99.drv
[2008/11/18 06:25:16 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\pdfmona.dll
[2008/11/18 06:25:16 | 000,051,716 | ---- | C] () -- C:\WINDOWS\System32\pdf995mon.dll
[2008/10/29 05:44:26 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\lectra.GIACOMO\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2008/05/26 15:23:36 | 000,016,834 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2008/05/26 15:23:34 | 000,024,188 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2008/05/26 15:23:32 | 000,016,568 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2008/05/26 14:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 14:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/09 01:09:10 | 000,006,144 | ---- | C] () -- C:\Dokumente und Einstellungen\Canfora\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/15 05:22:09 | 000,000,073 | ---- | C] () -- C:\WINDOWS\PlotterList.ini
[2007/09/24 04:11:00 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\lectra\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2007/09/24 03:52:56 | 000,033,792 | ---- | C] () -- C:\WINDOWS\System32\liblectrafilemt.dll
[2007/09/24 03:52:56 | 000,033,792 | ---- | C] () -- C:\WINDOWS\System32\liblectrafile.dll
[2007/09/24 03:52:56 | 000,031,232 | ---- | C] () -- C:\WINDOWS\System32\liblectrafilest.dll
[2007/09/24 03:52:56 | 000,000,203 | ---- | C] () -- C:\WINDOWS\System32\lsprst.dll
[2007/09/24 03:50:48 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\tclpip80.dll
[2007/09/24 03:45:49 | 000,000,383 | ---- | C] () -- C:\WINDOWS\System32\haspdos.sys
[2007/09/24 03:38:49 | 000,051,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\atnt40k.sys
[2007/09/10 07:36:26 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\Canfora\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2007/09/10 05:56:40 | 000,397,336 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2007/09/10 05:42:00 | 000,000,489 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/09/10 05:41:59 | 000,000,063 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2007/09/10 05:41:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NSREX.INI
[2007/09/10 04:33:09 | 000,012,952 | ---- | C] () -- C:\WINDOWS\cfgall.ini
[2007/09/09 15:16:49 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2007/08/12 00:25:39 | 000,348,880 | ---- | C] () -- C:\WINDOWS\System32\igmedkrn.dll
[2007/08/12 00:25:39 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4642.dll
[2007/08/12 00:24:30 | 000,000,962 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2007/08/11 15:48:22 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2007/08/11 15:39:15 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2007/08/11 15:39:15 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2007/08/11 15:39:15 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2007/08/11 15:39:15 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2007/08/11 15:39:15 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2007/08/11 15:39:15 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2007/08/11 15:38:23 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2007/08/11 15:38:23 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2007/08/11 15:33:55 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2007/03/05 06:34:28 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2006/06/21 05:40:59 | 000,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
[2006/05/04 16:14:44 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/05/04 15:53:24 | 000,484,094 | ---- | C] () -- C:\WINDOWS\System32\perfh007.dat
[2006/05/04 15:53:24 | 000,441,624 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/05/04 15:53:24 | 000,094,492 | ---- | C] () -- C:\WINDOWS\System32\perfc007.dat
[2006/05/04 15:53:24 | 000,071,308 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/05/04 15:49:18 | 000,281,336 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2006/05/04 15:41:52 | 000,004,335 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/05/04 15:36:58 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/02/27 21:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/02/27 21:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/02/27 21:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\perfi007.dat
[2006/02/27 21:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/02/27 21:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/02/27 21:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\perfd007.dat
[2006/02/27 21:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/02/27 21:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/02/27 21:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2006/02/27 21:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2002/05/28 02:55:42 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2002/05/28 02:54:40 | 000,004,605 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[1999/01/22 13:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2007/09/10 00:01:58 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config\systemprofile\Anwendungsdaten\SampleView
[2011/08/08 04:02:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\Aastra Telecom Schweiz AG
[2010/08/30 08:17:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\DassaultSystemes
[2010/08/30 08:17:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\EDrawings
[2008/02/15 05:21:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\Lectra
[2007/09/10 06:42:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\OfficeUpdate12
[2007/09/10 00:01:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\SampleView
[2008/08/07 06:56:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\Windows Desktop Search
[2008/08/07 07:00:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator.GIACOMO\Anwendungsdaten\Windows Search
[2007/09/10 00:01:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\SampleView
[2011/01/25 10:04:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Aastra Telecom Schweiz AG
[2010/09/21 03:04:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\DassaultSystemes
[2010/09/21 03:04:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\EDrawings
[2008/12/08 07:14:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\InterVideo
[2013/02/21 05:48:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Lectra
[2008/11/18 06:26:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\pdf995
[2007/09/10 00:01:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\SampleView
[2010/12/10 06:02:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\TeamViewer
[2008/11/18 06:31:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Windows Desktop Search
[2008/08/11 02:32:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Canfora\Anwendungsdaten\Windows Search
[2008/10/29 05:44:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\lectra.GIACOMO\Anwendungsdaten\Lectra
[2007/09/10 00:01:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\lectra.GIACOMO\Anwendungsdaten\SampleView
[2008/08/20 01:58:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\lectra\Anwendungsdaten\Lectra
[2007/09/10 00:01:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\lectra\Anwendungsdaten\SampleView
[2010/09/21 03:04:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DassaultSystemes
[2008/08/20 02:06:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Lectra
[2013/02/22 09:40:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\pdf995
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*. >
[2007/09/10 00:01:58 | 000,000,000 | ---D | M] -- C:\compaq
[2008/10/29 05:44:25 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen
[2007/09/24 02:50:11 | 000,000,000 | ---D | M] -- C:\DPlus230SB-InfICMFiles
[2007/09/10 05:15:58 | 000,000,000 | ---D | M] -- C:\f671326ecf3e5194f88898d59de5cb
[2007/09/10 00:02:05 | 000,000,000 | ---D | M] -- C:\i386
[2010/08/04 04:54:32 | 000,000,000 | ---D | M] -- C:\Lectra
[2007/09/24 03:48:01 | 000,000,000 | ---D | M] -- C:\MICRODST
[2007/09/24 03:48:00 | 000,000,000 | ---D | M] -- C:\MICROSRC
[2007/09/10 00:02:05 | 000,000,000 | ---D | M] -- C:\Novadigm
[2012/01/26 13:26:51 | 000,000,000 | ---D | M] -- C:\pdf995
[2013/02/20 03:03:30 | 000,000,000 | R--D | M] -- C:\Programme
[2013/02/25 03:18:39 | 000,000,000 | -HSD | M] -- C:\RECYCLER
[2008/02/07 10:16:24 | 000,000,000 | ---D | M] -- C:\spoolerlogs
[2011/01/19 11:27:17 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2007/09/09 15:10:34 | 000,000,000 | -H-D | M] -- C:\system.sav
[2012/12/17 07:59:42 | 000,000,000 | ---D | M] -- C:\Temp
[2013/02/25 06:32:56 | 000,000,000 | ---D | M] -- C:\WINDOWS
< %PROGRAMFILES%\*.exe >
[2011/08/15 06:05:09 | 001,081,480 | ---- | M] (Skype Technologies S.A.) -- C:\Programme\SkypeSetup.exe
Invalid Environment Variable: %LOCALAPPDATA%\*.exe
< %systemroot%\*. /mp /s >
< MD5 for: AGP440.SYS >
[2006/02/28 02:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\i386\sp2.cab:AGP440.sys
[2006/02/27 21:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/14 01:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/04/14 01:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 17:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 17:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: AHCIX86.SYS >
[2006/09/20 07:48:00 | 000,120,320 | ---- | M] (ATI Technologies Inc.) MD5=E62E600A73141039A19601A97DB75989 -- C:\compaq\HPBackup\update\DRIVERS\STORAGE\ahcix86.sys
[2006/09/20 07:48:00 | 000,120,320 | ---- | M] (ATI Technologies Inc.) MD5=E62E600A73141039A19601A97DB75989 -- C:\WINDOWS\DRIVERS\STORAGE\ahcix86.sys
< MD5 for: ATAPI.SYS >
[2006/02/28 02:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\i386\sp2.cab:atapi.sys
[2006/02/27 21:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/14 01:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 01:03:54 | 020,108,202 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 17:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 17:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 15:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/03 10:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys
[2004/08/03 15:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/14 00:52:12 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 00:52:12 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll
[2006/02/27 21:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2006/02/27 21:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=22FE1BE02EADDE1632E478E4125639E0 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007/06/13 08:10:08 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=331ED93570BAF3CFE30340298762CD56 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2008/04/14 00:52:46 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E -- C:\WINDOWS\explorer.exe
[2008/04/14 00:52:46 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 08:21:45 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=64D320C0E301EEDC5A4ADBBDC5024F7F -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: NETLOGON.DLL >
[2008/04/14 00:52:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 00:52:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll
[2006/02/27 21:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2008/04/14 00:52:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 00:52:24 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll
[2006/02/27 21:00:00 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
< MD5 for: USER32.DLL >
[2005/03/02 13:19:56 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS\$NtUninstallKB925902$\user32.dll
[2006/02/27 21:00:00 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=56785FD5236D7B22CF471A6DA9DB46D8 -- C:\WINDOWS\$NtUninstallKB890859$\user32.dll
[2007/03/08 10:48:39 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=78785EFF8CB90CEC1862A4CCFD9A3C3A -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll
[2008/04/14 00:52:32 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008/04/14 00:52:32 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll
< MD5 for: USERINIT.EXE >
[2008/04/14 00:53:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 00:53:04 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe
[2006/02/27 21:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: WINLOGON.EXE >
[2006/02/27 21:00:00 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/09/07 10:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Programme\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 00:53:06 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 00:53:06 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2IFSL.SYS >
[2006/02/27 21:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2006/05/04 17:27:28 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2006/05/04 17:27:28 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2006/05/04 17:27:28 | 000,405,504 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[2006/10/18 14:47:08 | 000,276,992 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\audiodev.dll
[2008/04/14 00:52:08 | 001,025,024 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\browseui.dll
[2008/04/14 00:52:10 | 000,102,912 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\cscdll.dll
[2008/04/14 00:52:10 | 000,334,848 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\cscui.dll
[2008/06/20 12:46:10 | 000,147,968 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dnsapi.dll
[2012/07/02 16:09:28 | 011,111,424 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\ieframe.dll
[2012/07/02 12:39:27 | 002,000,384 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\iertutil.dll
[2008/04/14 00:52:20 | 000,280,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\mstask.dll
[2008/04/14 00:52:22 | 000,067,072 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\ntdsapi.dll
[2006/10/18 14:47:18 | 000,284,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\PortableDeviceApi.dll
[2008/04/14 00:52:26 | 001,499,136 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\shdocvw.dll
[2008/04/14 00:52:26 | 008,502,272 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\shell32.dll
[2008/04/14 00:52:26 | 000,068,096 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\shgina.dll
[2007/10/25 02:28:30 | 000,222,720 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\wmasf.dll
[2006/10/18 14:47:22 | 002,450,944 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\wmvcore.dll
[2006/10/18 14:47:22 | 002,603,008 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\WpdShext.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
Invalid Environment Variable: %USERPROFILE%\*.*
Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.exe
Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.dll
Invalid Environment Variable: %USERPROFILE%\Application Data\*.exe
< End of report > Vielen Dank vorab für die Hilfestellung!
Gruß Sam |