Ich war eben schon ein wenig paranoid und musste 2 mal Scannen weil jedes mal die Einstellungen verstellt wurden....
Dies mal habe ich es aber beobachtet und er ist automatisch kurz vor Ende bei Standard-Registrierung von Benutze SafeList auf Alles umgesprungen Code:
OTL logfile created on: 18.03.2013 13:27:14 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Basti\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 1,90 Gb Available Physical Memory | 63,49% Memory free
6,19 Gb Paging File | 5,32 Gb Available in Paging File | 85,89% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 191,47 Gb Total Space | 48,70 Gb Free Space | 25,44% Space Free | Partition Type: NTFS
Drive D: | 8,96 Gb Total Space | 8,59 Gb Free Space | 95,79% Space Free | Partition Type: NTFS
Drive P: | 97,66 Gb Total Space | 34,29 Gb Free Space | 35,11% Space Free | Partition Type: NTFS
Computer Name: BASTI-PC | User Name: Basti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Basti\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corp.)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
PRC - C:\Programme\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Programme\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe (SafeNet, Inc)
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV - (SBSDWSCService) -- P:\Programme\Spybot File not found
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Ad-Aware Service) -- C:\Programme\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
SRV - (SkypeUpdate) -- C:\Programme\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (MBAMService) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SBAMSvc) -- C:\Programme\Ad-Aware Antivirus\SBAMSvc.exe (GFI Software)
SRV - (AdobeARMservice) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (FLEXnet Licensing Service) -- C:\Programme\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software, Inc.)
SRV - (odserv) -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (wlidsvc) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (Autodesk Content Service) -- C:\Programme\Autodesk\Content Service\Connect.Service.ContentService.exe ()
SRV - (Akamai) -- c:\Programme\Common Files\Akamai\netsession_win_dbc0250.dll ()
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (vpnagent) -- C:\Programme\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (STacSV) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (Microsoft Office Groove Audit Service) -- C:\Programme\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (SQLWriter) -- c:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (MSSQL$SQLEXPRESS) -- c:\Programme\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLBrowser) -- c:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper) -- c:\Programme\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (IAANTMON) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (vfsFPService) -- C:\Windows\System32\vfsFPService.exe (Validity Sensors, Inc.)
SRV - (Recovery Service for Windows) -- C:\Windows\SMINST\BLService.exe ()
SRV - (DpHost) -- C:\Programme\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV - (ezSharedSvc) -- C:\Windows\System32\ezsvc7.dll (EasyBits Sofware AS)
SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (CVPND) -- C:\Programme\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (MSSQL$ACCUCHEK360) -- c:\Programme\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (SentinelProtectionServer) -- C:\Programme\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe (SafeNet, Inc)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (Lbd) -- system32\DRIVERS\Lbd.sys File not found
DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (injectDLL) -- P:\Downloads\ProInjector\injectDLL.sys File not found
DRV - (GGSAFERDriver) -- P:\Programme\Garena\safedrv.sys File not found
DRV - (EagleXNt) -- C:\Windows\system32\drivers\EagleXNt.sys File not found
DRV - (EagleNT) -- C:\Windows\system32\drivers\EagleNT.sys File not found
DRV - (DBKDRVR54) -- C:\Program Files\Cheat Engine\dbk32.sys File not found
DRV - (catchme) -- C:\ComboFix\catchme.sys File not found
DRV - (gfibto) -- C:\Windows\System32\drivers\gfibto.sys (GFI Software)
DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (hpdskflt) -- C:\Windows\System32\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV - (Accelerometer) -- C:\Windows\System32\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV - (vpnva) -- C:\Windows\System32\drivers\vpnva.sys (Cisco Systems, Inc.)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (STHDA) -- C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (atksgt) -- C:\Windows\System32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\Windows\System32\drivers\lirsgt.sys ()
DRV - (d3d9) -- C:\Windows\System32\d3d9.dll (Microsoft Corporation)
DRV - (NETw5v32) -- C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (sptd) -- C:\Windows\System32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (tbhsd) -- C:\Windows\System32\drivers\tbhsd.sys (RapidSolution Software AG)
DRV - ({22D78859-9CE9-4B77-BF18-AC83E81A9263}) -- C:\Programme\HP\QuickPlay\000.fcl (Cyberlink Corp.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (JMCR) -- C:\Windows\System32\drivers\jmcr.sys (JMicron Technology Corp.)
DRV - (vfs101x) -- C:\Windows\System32\drivers\vfs101x.sys (Validity Sensors, Inc.)
DRV - (enecir) -- C:\Windows\System32\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV - (CVPNDRVA) -- C:\Windows\System32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (HpqRemHid) -- C:\Windows\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HpqKbFiltr) -- C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (ElbyCDFL) -- C:\Windows\System32\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (DNE) -- C:\Windows\System32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (CVirtA) -- C:\Windows\System32\drivers\CVirtA.sys (Cisco Systems, Inc.)
DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvm60x32.sys (NVIDIA Corporation)
DRV - (mirrorv3) -- C:\Windows\System32\drivers\rminiv3.sys (Famatech International Corp.)
DRV - (Sentinel) -- C:\Windows\System32\drivers\sentinel.sys (SafeNet, Inc.)
DRV - (Ser2pl) -- C:\Windows\System32\drivers\ser2pl.sys (Prolific Technology Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{D9A80BB3-B0E4-4B4D-93DF-67B60F57DAC5}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKLM\..\SearchScopes\{DE9FEAA3-5CD2-4DC3-A08D-D2562FDD252F}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 189.80.124.82:3128
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 189.80.124.82:3128
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2481524858-3819154491-4169622046-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-2481524858-3819154491-4169622046-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2481524858-3819154491-4169622046-1000\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-2481524858-3819154491-4169622046-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2481524858-3819154491-4169622046-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-2481524858-3819154491-4169622046-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-2481524858-3819154491-4169622046-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2481524858-3819154491-4169622046-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename,S: S", ""
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.order.1,S: S", ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.selectedEngine,S: S", ""
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..keyword.URL: "hxxp://www.google.de/#hl=de&tbo=d&sclient=psy-ab&q="
FF - prefs.js..network.proxy.backup.ftp: "210.48.147.94"
FF - prefs.js..network.proxy.backup.ftp_port: 80
FF - prefs.js..network.proxy.backup.gopher: "71.59.14.27"
FF - prefs.js..network.proxy.backup.gopher_port: 3128
FF - prefs.js..network.proxy.backup.socks: "210.48.147.94"
FF - prefs.js..network.proxy.backup.socks_port: 80
FF - prefs.js..network.proxy.backup.ssl: "210.48.147.94"
FF - prefs.js..network.proxy.backup.ssl_port: 80
FF - prefs.js..network.proxy.ftp: "64.34.197.103"
FF - prefs.js..network.proxy.ftp_port: 8118
FF - prefs.js..network.proxy.gopher: "194.152.42.153"
FF - prefs.js..network.proxy.gopher_port: 8080
FF - prefs.js..network.proxy.http: "64.79.72.50"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.no_proxies_on: ""
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "64.34.197.103"
FF - prefs.js..network.proxy.socks_port: 8118
FF - prefs.js..network.proxy.ssl: "64.34.197.103"
FF - prefs.js..network.proxy.ssl_port: 8118
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: P:\Programme\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: P:\Programme\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.15.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.15.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.13 21:33:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.03.08 12:19:20 | 000,000,000 | ---D | M]
[2008.11.01 01:18:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Basti\AppData\Roaming\mozilla\Extensions
[2013.03.15 13:08:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\aukokvmq.default\extensions
[2013.03.15 13:08:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Basti\AppData\Roaming\mozilla\Firefox\Profiles\skcfyyzb.Basti\extensions
[2013.03.08 12:19:12 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.03.08 12:19:12 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\䍻䙁䕅䅆ⵃ〰㜱〭〰ⴰ〰㐰䄭䍂䕄䙆䑅䉃絁
[2013.03.08 12:19:30 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2008.08.16 17:42:02 | 000,070,456 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\CgpCore.dll
[2008.08.16 17:42:12 | 000,091,448 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\confmgr.dll
[2008.08.16 17:42:08 | 000,020,800 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\ctxlogging.dll
[2008.05.21 08:41:08 | 000,479,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\msvcm80.dll
[2008.05.21 08:41:08 | 000,548,864 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\msvcp80.dll
[2008.05.21 08:41:08 | 000,626,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\msvcr80.dll
[2008.08.16 17:44:46 | 000,427,312 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npicaN.dll
[2008.08.16 17:42:04 | 000,023,864 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\TcpPServ.dll
[2012.06.17 19:29:19 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.09.13 11:48:56 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.06.17 19:29:19 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.17 19:29:19 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.17 19:29:19 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.17 19:29:19 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - Extension: SaveByclick = C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijppfghbmeajainbpmmkjfmhehilndgf\1\
Hosts file not found
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [IAAnotif] C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [razertra] P:\Programme\Razer\razertra.exe (Razer Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray.exe (IDT, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2481524858-3819154491-4169622046-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2481524858-3819154491-4169622046-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab (Java Plug-in 1.7.0_04)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 10.15.2)
O16 - DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 vpnweb.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1D7AA3E2-2931-41EE-9555-06444FCB7085}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Basti\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Basti\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.03.18 13:03:43 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.03.18 12:24:19 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Basti\Desktop\OTL.exe
[2013.03.18 10:48:25 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\temp
[2013.03.18 10:45:50 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.03.18 10:19:31 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.03.18 10:19:31 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.03.18 10:19:31 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.03.18 10:18:18 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.03.18 10:17:36 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.03.18 10:17:14 | 005,041,875 | R--- | C] (Swearware) -- C:\Users\Basti\Desktop\ComboFix.exe
[2013.03.17 21:41:16 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{DD9C975A-53C4-43C4-A7C9-6DFC245F4FA2}
[2013.03.17 21:03:31 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Basti\Desktop\tdsskiller.exe
[2013.03.17 16:45:29 | 000,000,000 | ---D | C] -- C:\Users\Basti\Desktop\mbar
[2013.03.16 20:56:19 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{421DB4F4-5DAE-4457-84D7-23E7CC61A15B}
[2013.03.15 23:00:54 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{E345532B-4F57-4277-AAFB-A22DEE6A824C}
[2013.03.15 16:15:52 | 004,732,416 | ---- | C] (AVAST Software) -- C:\Users\Basti\Desktop\aswMBR.exe
[2013.03.15 13:03:14 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013.03.15 13:02:27 | 000,000,000 | ---D | C] -- C:\JRT
[2013.03.15 13:02:01 | 000,550,572 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\Basti\Desktop\JRT.exe
[2013.03.15 11:00:16 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{2FC0E752-D7AE-4B65-A00F-06664B5E792C}
[2013.03.14 16:02:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.03.14 16:02:49 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.03.14 16:02:49 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.03.13 21:55:30 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.03.13 21:55:29 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.03.13 21:55:29 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.03.13 21:55:28 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.03.13 21:55:28 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013.03.13 21:55:27 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013.03.13 21:55:27 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.03.13 21:55:26 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013.03.13 21:45:14 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Roaming\LavasoftStatistics
[2013.03.13 21:41:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Ad-Aware Antivirus
[2013.03.13 21:36:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
[2013.03.13 21:36:46 | 000,000,000 | ---D | C] -- C:\Program Files\Ad-Aware Antivirus
[2013.03.13 21:36:17 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2013.03.13 21:33:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Downloaded Installations
[2013.03.13 21:33:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Ad-Aware Browsing Protection
[2013.03.13 21:33:33 | 000,000,000 | ---D | C] -- C:\Program Files\Toolbar Cleaner
[2013.03.13 21:31:41 | 000,044,424 | ---- | C] (GFI Software) -- C:\Windows\System32\sbbd.exe
[2013.03.13 21:31:41 | 000,013,560 | ---- | C] (GFI Software) -- C:\Windows\System32\drivers\gfibto.sys
[2013.03.13 21:31:41 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Roaming\Ad-Aware Antivirus
[2013.03.13 20:22:47 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MySQL
[2013.03.13 20:11:01 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{2FA42786-F677-4876-B5AD-11EC60DF76E7}
[2013.03.12 22:55:22 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{E43E1612-E4CD-43DD-AC2C-9FBAD0747AF5}
[2013.03.12 22:02:52 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2013.03.11 21:47:54 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{7DF7DEB3-3D6F-49B4-B968-98422EC87FFC}
[2013.03.11 11:17:42 | 000,000,000 | ---D | C] -- C:\RegioprojektCheck
[2013.03.11 09:47:30 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{ADF33BC3-4BDC-44FF-B583-257CD9A98642}
[2013.03.10 13:42:11 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{AAE422AF-8E02-4D3D-A0A8-12B8D4439A33}
[2013.03.09 16:48:04 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{D26412A9-50B9-4C1E-A5C0-498A5C9B2619}
[2013.03.08 23:28:27 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{9084219C-2EDC-4666-A26F-00892C771905}
[2013.03.08 12:19:12 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013.03.08 11:27:38 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{A8E23A8A-89F5-49CA-B4AE-DB8E8006EA12}
[2013.03.07 13:32:40 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{73DB2423-C761-40C5-BD8F-26E80671D141}
[2013.03.06 10:13:38 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{35935447-B316-4B04-8A41-76BEF822B7FD}
[2013.03.05 17:36:34 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{7329F463-C1FA-447B-9280-2B23D0D6C5D4}
[2013.03.04 12:35:06 | 000,000,000 | ---D | C] -- C:\Users\Basti\Documents\Oma_silber
[2013.03.04 12:31:12 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{D93B6735-3620-43B4-89AB-3F12E2FC1928}
[2013.03.03 14:29:22 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{A72CF85F-7944-4894-82F6-1FE9C5024F7A}
[2013.03.02 21:42:29 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Roaming\Easy2Convert
[2013.03.02 18:12:50 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{92A724D6-3210-43B1-9F54-999535D6B387}
[2013.03.01 20:09:13 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{AD0E481F-870B-4465-9CF3-017141BD09A0}
[2013.02.28 13:22:00 | 000,000,000 | ---D | C] -- C:\Users\Basti\DropBox_Hcu
[2013.02.28 13:14:49 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{A04E3D91-FE3D-4CED-BDEA-27EA4B434216}
[2013.02.27 21:21:23 | 000,000,000 | ---D | C] -- C:\Users\Basti\Documents\Bachelorarbeit
[2013.02.27 13:17:59 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{5ABAC6BF-2999-4760-B0DB-F1BCCDCE9185}
[2013.02.26 14:07:29 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{7513401B-6D46-4288-A92A-2A79F716A526}
[2013.02.25 13:21:24 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{CF5882A0-FEF5-4088-8A75-240D789259BF}
[2013.02.24 20:24:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013.02.24 20:24:11 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013.02.24 20:24:09 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013.02.24 20:24:09 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013.02.24 18:03:46 | 000,000,000 | ---D | C] -- C:\Users\Basti\Documents\Krankenkasse
[2013.02.24 13:24:38 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{AFA46DB8-4CBB-4DAA-A05D-36CA098B6C97}
[2013.02.23 13:23:08 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{72C21F51-23E0-4141-BAC1-58B132102A7E}
[2013.02.22 13:38:52 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{5FCC6DBA-9A65-4B39-AF1C-A2B07F2DE6BF}
[2013.02.21 16:15:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2013.02.21 16:14:58 | 000,262,560 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2013.02.21 16:14:38 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013.02.21 16:14:38 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2013.02.21 16:14:38 | 000,094,112 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013.02.21 12:54:01 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{7BB84EFE-2E55-43D3-8B58-535A82B5608C}
[2013.02.20 18:05:03 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{102FF5FB-5AD6-4670-A61C-855B5FCB2AC9}
[2013.02.18 09:22:18 | 000,884,072 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvhdagenco3220103.dll
[2013.02.18 09:22:18 | 000,149,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvhda32v.sys
[2013.02.18 09:22:18 | 000,067,432 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvapo32v.dll
[2013.02.18 09:22:18 | 000,028,008 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvhdap32.dll
[2013.02.16 16:50:49 | 000,000,000 | ---D | C] -- C:\Users\Basti\AppData\Local\{939C9AB4-81F2-44A4-A676-5059540594BD}
[1 C:\Users\Basti\AppData\Local\*.tmp files -> C:\Users\Basti\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.03.18 13:25:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.03.18 13:05:19 | 000,603,210 | ---- | M] () -- C:\ProgramData\nvModes.001
[2013.03.18 13:05:12 | 000,603,210 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2013.03.18 13:05:06 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.03.18 13:05:06 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.03.18 13:05:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.03.18 13:04:56 | 3218,296,832 | -HS- | M] () -- C:\hiberfil.sys
[2013.03.18 12:24:25 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Basti\Desktop\OTL.exe
[2013.03.18 12:19:20 | 000,609,993 | ---- | M] () -- C:\Users\Basti\Desktop\adwcleaner.exe
[2013.03.18 10:14:31 | 005,041,875 | R--- | M] (Swearware) -- C:\Users\Basti\Desktop\ComboFix.exe
[2013.03.17 21:30:49 | 000,000,512 | ---- | M] () -- C:\Users\Basti\Desktop\MBR.dat
[2013.03.17 21:03:40 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Basti\Desktop\tdsskiller.exe
[2013.03.17 16:43:35 | 000,377,856 | ---- | M] () -- C:\Users\Basti\Desktop\gmer_2.1.19155.exe
[2013.03.15 21:12:30 | 000,000,510 | ---- | M] () -- C:\Windows\WORDPAD.INI
[2013.03.15 16:17:14 | 004,732,416 | ---- | M] (AVAST Software) -- C:\Users\Basti\Desktop\aswMBR.exe
[2013.03.15 13:02:01 | 000,550,572 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\Basti\Desktop\JRT.exe
[2013.03.14 16:17:17 | 000,613,264 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.03.14 16:02:51 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.03.14 15:48:27 | 000,012,585 | ---- | M] () -- C:\Users\Basti\Desktop\Desktop.7z
[2013.03.14 14:40:05 | 405,404,546 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2013.03.14 13:49:58 | 000,000,020 | ---- | M] () -- C:\Users\Basti\defogger_reenable
[2013.03.14 11:07:22 | 000,778,878 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.03.14 11:07:22 | 000,728,700 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.03.14 11:07:22 | 000,187,184 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.03.14 11:07:22 | 000,155,194 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.03.13 21:48:26 | 000,001,737 | ---- | M] () -- C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2013.03.13 21:31:41 | 000,044,424 | ---- | M] (GFI Software) -- C:\Windows\System32\sbbd.exe
[2013.03.13 21:31:41 | 000,013,560 | ---- | M] (GFI Software) -- C:\Windows\System32\drivers\gfibto.sys
[2013.03.12 19:25:28 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013.03.12 19:25:28 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013.02.24 20:24:52 | 000,001,664 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013.02.22 17:38:14 | 000,000,064 | ---- | M] () -- C:\Windows\System32\rp_stats.dat
[2013.02.22 17:38:14 | 000,000,044 | ---- | M] () -- C:\Windows\System32\rp_rules.dat
[2013.02.21 16:14:26 | 000,094,112 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013.02.21 16:14:24 | 000,262,560 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2013.02.21 16:14:24 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013.02.21 16:14:24 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2013.02.21 16:14:23 | 000,861,088 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2013.02.21 16:14:23 | 000,782,240 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2013.02.20 00:17:49 | 000,003,204 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2013.02.18 09:22:18 | 000,884,072 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvhdagenco3220103.dll
[2013.02.18 09:22:18 | 000,149,352 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvhda32v.sys
[2013.02.18 09:22:18 | 000,067,432 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvapo32v.dll
[2013.02.18 09:22:18 | 000,028,008 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvhdap32.dll
[2013.02.16 16:03:26 | 000,446,065 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20130313-215437.backup
[2013.02.16 16:03:26 | 000,446,065 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.20130313-215716.backup
[2013.02.16 16:03:26 | 000,446,065 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.20130313-215525.backup
[1 C:\Users\Basti\AppData\Local\*.tmp files -> C:\Users\Basti\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.03.18 12:19:18 | 000,609,993 | ---- | C] () -- C:\Users\Basti\Desktop\adwcleaner.exe
[2013.03.18 10:19:31 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.03.18 10:19:31 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.03.18 10:19:31 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.03.18 10:19:31 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.03.18 10:19:31 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.03.17 21:30:49 | 000,000,512 | ---- | C] () -- C:\Users\Basti\Desktop\MBR.dat
[2013.03.17 19:50:28 | 3218,296,832 | -HS- | C] () -- C:\hiberfil.sys
[2013.03.17 16:43:34 | 000,377,856 | ---- | C] () -- C:\Users\Basti\Desktop\gmer_2.1.19155.exe
[2013.03.14 16:02:51 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.03.14 15:48:27 | 000,012,585 | ---- | C] () -- C:\Users\Basti\Desktop\Desktop.7z
[2013.03.14 13:49:42 | 000,000,020 | ---- | C] () -- C:\Users\Basti\defogger_reenable
[2013.03.13 21:36:49 | 000,001,737 | ---- | C] () -- C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2013.02.24 20:24:52 | 000,001,664 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.11.30 11:44:24 | 000,000,020 | -HS- | C] () -- C:\Users\Basti\AppData\Roaming\App4870.ConfCollection.bin
[2012.10.19 22:45:31 | 000,000,888 | ---- | C] () -- C:\Users\Basti\recStudio.ini
[2012.10.19 22:40:48 | 000,000,263 | ---- | C] () -- C:\Windows\w32demo8.ini
[2012.09.17 15:32:31 | 000,000,130 | ---- | C] () -- C:\Users\Basti\.bash_history
[2012.09.17 14:30:44 | 000,000,094 | ---- | C] () -- C:\Users\Basti\.gitconfig
[2012.06.29 12:04:08 | 000,024,576 | ---- | C] () -- C:\Windows\System32\ZyDelReg.exe
[2012.06.29 12:04:01 | 000,061,440 | ---- | C] () -- C:\Windows\System32\ZDTRLib.DLL
[2012.06.29 12:04:01 | 000,057,344 | ---- | C] () -- C:\Windows\System32\ZD12APP.dll
[2012.06.29 12:04:01 | 000,040,960 | ---- | C] () -- C:\Windows\System32\PassAPP.dll
[2012.06.29 12:04:01 | 000,028,672 | ---- | C] () -- C:\Windows\System32\INSAPP.dll
[2012.06.29 12:04:01 | 000,011,776 | ---- | C] () -- C:\Windows\System32\InsDrvZD.dll
[2012.03.25 19:37:24 | 000,110,080 | ---- | C] () -- C:\Windows\System32\pywintypes26.dll
[2012.03.25 19:37:24 | 000,008,192 | ---- | C] () -- C:\Windows\System32\pythoncomloader26.dll
[2012.03.25 19:37:23 | 000,358,912 | ---- | C] () -- C:\Windows\System32\pythoncom26.dll
[2012.02.21 23:49:42 | 000,000,715 | ---- | C] () -- C:\Users\Basti\untitled13_MAS.bak
[2012.02.21 23:49:33 | 000,000,715 | ---- | C] () -- C:\Users\Basti\untitled12_MAS.bak
[2012.02.18 16:11:35 | 000,000,510 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2011.12.10 13:05:43 | 000,000,000 | ---- | C] () -- C:\Users\Basti\Programme
[2011.09.15 01:11:16 | 001,048,576 | ---- | C] () -- C:\Windows\System32\syndata.bin
[2011.08.30 12:54:49 | 000,000,041 | -HS- | C] () -- C:\ProgramData\.zreglib
[2011.05.05 17:16:59 | 000,000,064 | ---- | C] () -- C:\Windows\System32\rp_stats.dat
[2011.05.05 17:16:59 | 000,000,044 | ---- | C] () -- C:\Windows\System32\rp_rules.dat
[2011.03.22 11:27:59 | 000,041,890 | ---- | C] () -- C:\Users\Basti\AppData\Roaming\room.dat
[2009.07.31 17:54:45 | 000,000,600 | ---- | C] () -- C:\Users\Basti\AppData\Local\PUTTY.RND
[2009.03.26 22:24:34 | 000,000,600 | ---- | C] () -- C:\Users\Basti\AppData\Roaming\winscp.rnd
[2009.02.15 01:31:22 | 000,022,328 | ---- | C] () -- C:\Users\Basti\AppData\Roaming\PnkBstrK.sys
[2008.12.28 18:44:48 | 000,000,032 | ---- | C] () -- C:\ProgramData\ezsid.dat
[2008.11.16 20:52:34 | 000,000,142 | ---- | C] () -- C:\Users\Basti\AppData\Roaming\wklnhst.dat
[2008.11.11 09:52:45 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2008.11.04 11:32:49 | 000,024,206 | ---- | C] () -- C:\Users\Basti\AppData\Roaming\UserTile.png
[2008.11.02 21:13:01 | 000,000,680 | ---- | C] () -- C:\Users\Basti\AppData\Local\d3d9caps.dat
[2008.11.01 19:11:10 | 000,010,240 | ---- | C] () -- C:\Users\Basti\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.09.10 00:46:41 | 000,603,210 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2008.09.10 00:46:41 | 000,603,210 | ---- | C] () -- C:\ProgramData\nvModes.001
========== ZeroAccess Check ==========
[2006.11.02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012.10.14 13:28:46 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\.minecraft
[2013.03.14 00:01:05 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\Ad-Aware Antivirus
[2012.05.20 14:44:08 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\AnvSoft
[2013.02.02 20:16:59 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\Autodesk
[2010.11.28 11:02:58 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\avidemux
[2009.04.21 19:34:09 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\concept design
[2008.12.03 20:56:13 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\cPicture
[2008.11.14 23:18:57 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\DAEMON Tools
[2009.02.20 19:46:46 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\Datarescue
[2008.10.31 21:26:35 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\DigitalPersona
[2012.07.01 16:32:53 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\DVDVideoSoft
[2013.03.02 21:42:29 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\Easy2Convert
[2012.10.04 21:28:03 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\ESRI
[2013.02.24 22:14:18 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\GitHub
[2012.01.23 16:51:07 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\ICAClient
[2013.01.26 21:55:19 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\ICQ
[2013.01.27 21:40:43 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\JavaEditor
[2012.06.28 11:25:43 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\LucasArts
[2012.11.24 20:20:35 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\Mael
[2008.11.03 08:26:52 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\Magic Academy
[2009.01.15 14:16:49 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\MuPAD
[2010.11.28 11:49:32 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\OpenOffice.org
[2011.11.09 10:54:38 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\postgresql
[2009.01.02 21:12:34 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\Red Alert 3
[2009.04.10 20:23:07 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\Resource Tuner
[2013.03.08 09:30:35 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\TeamViewer
[2009.12.18 17:41:20 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\Template
[2013.01.13 21:46:24 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\TS3Client
[2008.12.03 21:37:26 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\Tunebite
[2009.07.10 21:32:26 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\Ubisoft
[2011.08.08 21:36:38 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\WindSolutions
[2012.07.28 17:31:22 | 000,000,000 | ---D | M] -- C:\Users\Basti\AppData\Roaming\yWorks
========== Purity Check ==========
< End of report > |