Um Missverständnissen vorzubeugen habe ich die "OTL.txt" nun nochmal hier rein gepostet statt als Anhang. Den User habe ich durch *** ersetzt.
Würde mich freuen, wenn mir noch jemand sagen könnte, was ich als nächstes machen muss und warum ich keine "Extra.txt" erhalten habe.
Gruß,
Florian Code:
OTL logfile created on: 3/23/2013 8:35:32 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Windows 7 Enterprise Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 90.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files
Drive C: | 100.00 Mb Total Space | 65.84 Mb Free Space | 65.84% Space Free | Partition Type: NTFS
Drive D: | 7.84 Gb Total Space | 7.82 Gb Free Space | 99.85% Space Free | Partition Type: FAT32
Drive E: | 92.11 Gb Total Space | 8.99 Gb Free Space | 9.76% Space Free | Partition Type: NTFS
Drive F: | 197.09 Gb Total Space | 20.72 Gb Free Space | 10.51% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet002
========== Win32 Services (SafeList) ==========
SRV - [2013/03/14 03:56:45 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- E:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/03/08 09:28:16 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand] -- E:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/12/18 10:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/11/09 06:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto] -- E:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/11/01 22:51:18 | 005,174,392 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- E:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2012/07/17 16:31:18 | 000,116,632 | ---- | M] () [Auto] -- E:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe -- (Motorola Device Manager)
SRV - [2012/02/13 22:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto] -- E:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2011/10/21 10:23:42 | 000,196,176 | ---- | M] (Microsoft Corporation.) [Auto] -- E:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/10/13 12:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (BBUpdate)
SRV - [2011/09/02 11:06:38 | 000,065,657 | ---- | M] (Motorola) [Auto] -- E:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe -- (PST Service)
SRV - [2011/02/25 06:48:06 | 000,087,344 | ---- | M] (Nero AG) [Auto] -- E:\Program Files\Motorola Media Link\NServiceEntry.exe -- (DeviceMonitorService)
SRV - [2010/10/19 08:29:02 | 002,011,944 | ---- | M] (TeamViewer GmbH) [Auto] -- E:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5)
SRV - [2010/10/08 01:18:42 | 000,726,288 | ---- | M] () [Auto] -- E:\Program Files\ShrewSoft\VPN Client\iked.exe -- (iked)
SRV - [2010/10/08 01:18:42 | 000,541,968 | ---- | M] () [Auto] -- E:\Program Files\ShrewSoft\VPN Client\ipsecd.exe -- (ipsecd)
SRV - [2010/10/08 01:18:42 | 000,054,544 | ---- | M] () [Auto] -- E:\Program Files\ShrewSoft\VPN Client\dtpd.exe -- (dtpd)
SRV - [2010/07/22 01:37:50 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2009/07/13 21:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/02/22 03:24:28 | 000,094,208 | ---- | M] (TODO: <公司名稱>) [Auto] -- E:\Program Files\OEM\OSD_1.12\OsdService.exe -- (OsdService)
SRV - [2007/12/16 22:00:00 | 000,143,872 | ---- | M] (SEIKO EPSON CORPORATION) [Auto] -- E:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE -- (EPSON_EB_RPCV4_01) EPSON V5 Service4(01)
SRV - [2007/01/10 22:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) [Auto] -- E:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE -- (EPSON_PM_RPCV4_01) EPSON V3 Service4(01)
SRV - [2006/12/19 12:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) [Auto] -- E:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe -- (EpsonBidirectionalService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (VGPU)
DRV - File not found [Kernel | On_Demand] -- -- (tsusbhub)
DRV - File not found [Kernel | On_Demand] -- -- (Synth3dVsc)
DRV - File not found [Kernel | On_Demand] -- -- (MotDev)
DRV - [2012/12/09 22:28:36 | 000,142,176 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand] -- E:\Windows\System32\drivers\avgidsdriverx.sys -- (AVGIDSDriver)
DRV - [2012/11/07 22:49:26 | 000,250,080 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] -- E:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2012/08/24 09:43:18 | 000,301,920 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] -- E:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2012/06/11 06:56:32 | 000,020,864 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand] -- E:\Windows\System32\drivers\motccgp.sys -- (motccgp)
DRV - [2012/06/08 11:09:10 | 000,023,808 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand] -- E:\Windows\System32\drivers\Motousbnet.sys -- (Motousbnet)
DRV - [2012/06/08 11:08:52 | 000,006,656 | ---- | M] (Motorola) [Kernel | On_Demand] -- E:\Windows\System32\drivers\motswch.sys -- (MotoSwitchService)
DRV - [2012/06/08 11:08:26 | 000,024,576 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand] -- E:\Windows\System32\drivers\motmodem.sys -- (motmodem)
DRV - [2012/04/18 22:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot] -- E:\Windows\System32\drivers\avgidshx.sys -- (AVGIDSHX)
DRV - [2012/01/30 22:46:50 | 000,031,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot] -- E:\Windows\System32\drivers\avgrkx86.sys -- (Avgrkx86)
DRV - [2012/01/25 09:57:46 | 000,008,448 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand] -- E:\Windows\System32\drivers\motccgpfl.sys -- (motccgpfl)
DRV - [2011/12/23 07:32:14 | 000,041,040 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System] -- E:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/12/23 07:32:08 | 000,017,232 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand] -- E:\Windows\System32\drivers\avgidsshimx.sys -- (AVGIDSShim)
DRV - [2011/12/23 07:32:06 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand] -- E:\Windows\System32\drivers\avgidsfilterx.sys -- (AVGIDSFilter)
DRV - [2011/11/08 08:59:04 | 000,011,008 | ---- | M] (Motorola Inc) [Kernel | On_Demand] -- E:\Windows\System32\drivers\motusbdevice.sys -- (motusbdevice)
DRV - [2010/11/20 08:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot] -- E:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 08:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot] -- E:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 08:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\system32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 06:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 06:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010/11/20 05:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 05:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\system32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 05:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\system32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/11/08 14:56:25 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand] -- E:\Windows\System32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2010/11/08 14:56:25 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand] -- E:\Windows\System32\drivers\ggflt.sys -- (ggflt)
DRV - [2010/09/02 03:18:48 | 000,017,920 | ---- | M] (Shrew Soft Inc) [Kernel | System] -- E:\Windows\System32\drivers\vfilter.sys -- (vflt)
DRV - [2010/09/02 03:18:48 | 000,013,824 | ---- | M] (Shrew Soft Inc) [Kernel | On_Demand] -- E:\Windows\System32\drivers\virtualnet.sys -- (vnet)
DRV - [2010/04/27 11:57:28 | 000,066,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2010/04/27 11:57:28 | 000,015,048 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2010/04/27 11:57:22 | 000,022,856 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2010/04/27 09:01:26 | 000,037,704 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2009/09/01 01:19:18 | 009,825,728 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/07/13 20:18:07 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2009/07/13 20:14:49 | 000,020,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WSDScan.sys -- (WSDScan)
DRV - [2009/07/13 18:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\netw5v32.sys -- (netw5v32) Intel(R)
DRV - [2009/01/29 13:11:20 | 000,006,016 | ---- | M] (Motorola Inc) [Kernel | On_Demand] -- E:\Windows\System32\drivers\motfilt.sys -- (BTCFilterService)
DRV - [2008/10/21 04:22:48 | 000,114,600 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\s0017mdm.sys -- (s0017mdm)
DRV - [2008/10/21 04:22:48 | 000,109,736 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\s0017unic.sys -- (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM)
DRV - [2008/10/21 04:22:48 | 000,108,328 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\s0017mgmt.sys -- (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM)
DRV - [2008/10/21 04:22:48 | 000,104,616 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\s0017obex.sys -- (s0017obex)
DRV - [2008/10/21 04:22:48 | 000,086,824 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\s0017bus.sys -- (s0017bus) Sony Ericsson Device 0017 driver (WDM)
DRV - [2008/10/21 04:22:48 | 000,026,024 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\s0017nd5.sys -- (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS)
DRV - [2008/10/21 04:22:48 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\s0017mdfl.sys -- (s0017mdfl)
DRV - [2008/03/31 06:02:34 | 000,008,192 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand] -- E:\Windows\System32\kbfiltr.sys -- (GpdKbFilter)
DRV - [2007/11/21 04:31:26 | 000,007,168 | ---- | M] () [Kernel | On_Demand] -- E:\Windows\System32\directport.sys -- (GpdDevDPort)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\***_ON_E\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\***_ON_E\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\***_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\***_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\***_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\***_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 10 5E E8 7B 79 11 CB 01 [binary data]
IE - HKU\***_ON_E\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\***_ON_E\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\***_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\***_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 192.168.*.*;*.local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\System32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: E:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: E:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: E:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: E:\Windows\System32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: E:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: E:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: E:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: E:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: E:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: E:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: E:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@phonostar.de/phonostar: E:\Program Files\phonostar-Player\npphonostarDetectNP.dll ( )
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2013/03/06 05:18:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012/07/02 10:27:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/03/08 09:28:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/03/08 09:28:12 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/03/08 09:28:16 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/03/08 09:28:12 | 000,000,000 | ---D | M]
[2010/06/21 15:46:59 | 000,000,000 | ---D | M] (No name found) -- E:\Users\***\AppData\Roaming\Mozilla\Extensions
[2013/03/16 11:30:17 | 000,000,000 | ---D | M] (No name found) -- E:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\rkwhlmqp.default\extensions
[2012/06/06 13:08:04 | 000,000,853 | ---- | M] () -- E:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\rkwhlmqp.default\searchplugins\11-suche.xml
[2012/06/06 13:08:05 | 000,002,209 | ---- | M] () -- E:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\rkwhlmqp.default\searchplugins\englische-ergebnisse.xml
[2012/06/06 13:08:04 | 000,010,506 | ---- | M] () -- E:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\rkwhlmqp.default\searchplugins\gmx-suche.xml
[2012/06/06 13:08:05 | 000,002,368 | ---- | M] () -- E:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\rkwhlmqp.default\searchplugins\lastminute.xml
[2012/06/06 13:08:03 | 000,005,489 | ---- | M] () -- E:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\rkwhlmqp.default\searchplugins\webde-suche.xml
[2013/03/08 09:28:12 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
[2012/07/02 10:27:12 | 000,000,000 | ---D | M] (AVG Do Not Track) -- E:\PROGRAM FILES\AVG\AVG2012\FIREFOX\DONOTTRACK
[2013/03/08 09:28:16 | 000,263,064 | ---- | M] (Mozilla Foundation) -- E:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/02/02 16:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- E:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/07/20 15:20:55 | 000,001,392 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/09/02 13:29:31 | 000,002,465 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/07/20 15:20:55 | 000,001,153 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012/07/20 15:20:55 | 000,006,805 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/07/20 15:20:55 | 000,001,178 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/07/20 15:20:55 | 000,001,105 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - E:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - E:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - E:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - E:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - E:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - E:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKU\***_ON_E\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] E:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] E:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DeskUpdateNotifier] E:\Program Files\Fujitsu\DeskUpdate\DeskUpdateNotifier.exe (Fujitsu Technology Solutions)
O4 - HKLM..\Run: [EEventManager] E:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [mumservice] E:\Program Files\Motorola\Software Update\mumservice.exe (Motorola)
O4 - HKLM..\Run: [NeroFilterCheck] E:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] E:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PDFPrint] E:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [Start WingMan Profiler] E:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKU\***_ON_E..\Run: [EPSON SX510W Series] E:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIFIE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\***_ON_E..\Run: [EPSON8830CF] E:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIFIE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\***_ON_E..\Run: [MobileDocuments] File not found
O4 - HKU\***_ON_E..\Run: [phonostar-PlayerTimer] E:\Program Files\phonostar-Player\phonostarTimer.exe ()
O4 - HKU\***_ON_E..\Run: [phonostarTimer] E:\Program Files\phonostar-Player\phonostarTimer.exe ()
O4 - HKU\LocalService_ON_E..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_E..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: E:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Add to Google Photos Screensa&ver - E:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - E:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - E:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} hxxp://www.navigram.com/engine/v1111/Navigram.cab (Navigram Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKU\***_ON_E Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKU\***_ON_E Winlogon: Shell - (C:\Users\***\AppData\Roaming\AltShell.dat) - E:\Users\***\AppData\Roaming\AltShell.dat ()
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - E:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart) - E:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2013/03/22 17:46:44 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/03/22 17:19:17 | 000,000,000 | ---D | C] -- E:\Users\***\AppData\Roaming\Ygdui
[2013/03/22 17:19:17 | 000,000,000 | ---D | C] -- E:\Users\***\AppData\Roaming\Ersu
[2013/03/22 17:19:17 | 000,000,000 | ---D | C] -- E:\Users\***\AppData\Roaming\Awla
[2013/03/14 04:12:44 | 002,382,848 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\mshtml.tlb
[2013/03/14 04:12:44 | 000,420,864 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\vbscript.dll
[2013/03/14 04:12:43 | 000,607,744 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\msfeeds.dll
[2013/03/14 04:12:43 | 000,176,640 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ieui.dll
[2013/03/14 04:12:43 | 000,142,848 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ieUnatt.exe
[2013/03/14 04:12:43 | 000,065,024 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jsproxy.dll
[2013/03/14 04:12:42 | 001,800,704 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jscript9.dll
[2013/03/14 04:12:42 | 000,717,824 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jscript.dll
[2013/03/14 04:12:42 | 000,231,936 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\url.dll
[2013/03/14 04:12:41 | 001,427,968 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\inetcpl.cpl
[2013/03/08 09:28:11 | 000,000,000 | ---D | C] -- E:\Program Files\Mozilla Firefox
[2013/03/07 14:33:13 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/03/07 14:32:12 | 000,000,000 | ---D | C] -- E:\Program Files\iTunes
[2013/03/07 14:32:12 | 000,000,000 | ---D | C] -- E:\Program Files\iPod
[2013/03/07 14:32:12 | 000,000,000 | ---D | C] -- E:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/03/06 05:18:50 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/02/27 16:55:17 | 000,187,392 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\UIAnimation.dll
[2013/02/27 16:55:07 | 000,417,792 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\WMPhoto.dll
[2013/02/27 16:55:04 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/02/27 16:55:04 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/02/27 16:55:04 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/02/27 16:55:03 | 000,364,544 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\XpsGdiConverter.dll
[2013/02/27 16:55:03 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/02/27 16:55:03 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/02/27 16:55:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/02/27 16:55:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/02/27 16:55:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/02/27 16:55:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/02/27 16:55:02 | 001,988,096 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\d3d10warp.dll
[2013/02/27 16:55:01 | 002,284,544 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\msmpeg2vdec.dll
[2013/02/27 16:55:01 | 001,504,768 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\d3d11.dll
[2013/02/27 16:55:01 | 000,604,160 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\d3d10level9.dll
[2013/02/27 16:55:01 | 000,293,376 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\dxgi.dll
[2013/02/27 16:55:01 | 000,249,856 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\d3d10_1core.dll
[2013/02/27 16:55:01 | 000,220,160 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\d3d10core.dll
[2013/02/27 16:55:01 | 000,161,792 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\d3d10_1.dll
[2013/02/27 16:55:00 | 001,247,744 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\DWrite.dll
[2013/02/27 16:55:00 | 001,158,144 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\XpsPrint.dll
[2013/02/27 16:55:00 | 001,080,832 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\d3d10.dll
[2013/02/27 16:55:00 | 000,207,872 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\WindowsCodecsExt.dll
[2013/02/27 16:54:58 | 003,419,136 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\d2d1.dll
[1 E:\Users\***\Documents\*.tmp files -> E:\Users\***\Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/03/23 09:58:36 | 000,067,584 | --S- | M] () -- E:\Windows\bootstat.dat
[2013/03/23 09:57:56 | 000,000,004 | ---- | M] () -- E:\Users\***\AppData\Roaming\AltShell.ini
[2013/03/23 09:56:42 | 000,001,092 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/23 09:56:34 | 2411,708,416 | -HS- | M] () -- E:\hiberfil.sys
[2013/03/23 09:55:42 | 000,015,808 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/23 09:55:42 | 000,015,808 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/22 18:41:00 | 000,001,096 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/22 17:56:00 | 000,000,884 | ---- | M] () -- E:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/22 17:46:44 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/03/22 12:30:03 | 114,143,242 | ---- | M] () -- E:\Windows\System32\drivers\AVG\incavi.avm
[2013/03/22 04:47:00 | 000,000,240 | ---- | M] () -- E:\Windows\tasks\Epson Printer Software Downloader.job
[2013/03/17 14:45:31 | 000,657,910 | ---- | M] () -- E:\Windows\System32\perfh007.dat
[2013/03/17 14:45:31 | 000,619,146 | ---- | M] () -- E:\Windows\System32\perfh009.dat
[2013/03/17 14:45:31 | 000,131,250 | ---- | M] () -- E:\Windows\System32\perfc007.dat
[2013/03/17 14:45:31 | 000,107,466 | ---- | M] () -- E:\Windows\System32\perfc009.dat
[2013/03/16 12:20:23 | 000,270,923 | ---- | M] () -- E:\Windows\System32\drivers\AVG\iavichjg.avm
[2013/03/14 04:13:55 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/03/14 03:56:43 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- E:\Windows\System32\FlashPlayerApp.exe
[2013/03/14 03:56:43 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- E:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/03/09 03:18:51 | 000,001,994 | ---- | M] () -- E:\Users\***\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/03/07 14:33:13 | 000,001,753 | ---- | M] () -- E:\Users\Public\Desktop\iTunes.lnk
[2013/03/07 14:33:13 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/03/06 09:46:09 | 000,023,090 | ---- | M] () -- E:\Users\***\Desktop\Chuggington-5.jpg
[2013/03/06 05:18:50 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[1 E:\Users\***\Documents\*.tmp files -> E:\Users\***\Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/03/22 18:44:14 | 000,000,004 | ---- | C] () -- E:\Users\***\AppData\Roaming\AltShell.ini
[2013/03/07 14:33:13 | 000,001,753 | ---- | C] () -- E:\Users\Public\Desktop\iTunes.lnk
[2013/03/06 09:46:08 | 000,023,090 | ---- | C] () -- E:\Users\***\Desktop\Chuggington-5.jpg
[2012/01/11 09:33:30 | 000,031,232 | ---- | C] () -- E:\Users\***\AppData\Roaming\AltShell.dat
[2011/11/09 15:37:17 | 000,000,859 | ---- | C] () -- E:\Users\***\AppData\Roaming\coreavc.ini
[2011/06/10 01:34:52 | 000,080,416 | ---- | C] () -- E:\Windows\System32\RtNicProp32.dll
[2011/03/04 15:41:56 | 000,080,896 | ---- | C] () -- E:\Windows\System32\RDVGHelper.exe
[2011/03/04 15:41:20 | 000,252,928 | ---- | C] () -- E:\Windows\System32\DShowRdpFilter.dll
[2011/03/04 15:39:42 | 000,066,048 | ---- | C] () -- E:\Windows\System32\PrintBrmUi.exe
[2010/11/06 15:10:44 | 000,007,605 | ---- | C] () -- E:\Users\***\AppData\Local\Resmon.ResmonCfg
[2010/09/04 10:31:17 | 000,000,056 | -H-- | C] () -- E:\ProgramData\ezsidmv.dat
[2010/08/31 03:50:15 | 000,111,932 | ---- | C] () -- E:\Windows\System32\EPPICPrinterDB.dat
[2010/08/31 03:50:15 | 000,031,053 | ---- | C] () -- E:\Windows\System32\EPPICPattern131.dat
[2010/08/31 03:50:15 | 000,027,417 | ---- | C] () -- E:\Windows\System32\EPPICPattern121.dat
[2010/08/31 03:50:15 | 000,026,154 | ---- | C] () -- E:\Windows\System32\EPPICPattern1.dat
[2010/08/31 03:50:15 | 000,024,903 | ---- | C] () -- E:\Windows\System32\EPPICPattern3.dat
[2010/08/31 03:50:15 | 000,021,390 | ---- | C] () -- E:\Windows\System32\EPPICPattern5.dat
[2010/08/31 03:50:15 | 000,020,148 | ---- | C] () -- E:\Windows\System32\EPPICPattern2.dat
[2010/08/31 03:50:15 | 000,011,811 | ---- | C] () -- E:\Windows\System32\EPPICPattern4.dat
[2010/08/31 03:50:15 | 000,004,943 | ---- | C] () -- E:\Windows\System32\EPPICPattern6.dat
[2010/08/31 03:50:15 | 000,001,146 | ---- | C] () -- E:\Windows\System32\EPPICPresetData_DU.dat
[2010/08/31 03:50:15 | 000,001,139 | ---- | C] () -- E:\Windows\System32\EPPICPresetData_PT.dat
[2010/08/31 03:50:15 | 000,001,139 | ---- | C] () -- E:\Windows\System32\EPPICPresetData_BP.dat
[2010/08/31 03:50:15 | 000,001,136 | ---- | C] () -- E:\Windows\System32\EPPICPresetData_ES.dat
[2010/08/31 03:50:15 | 000,001,129 | ---- | C] () -- E:\Windows\System32\EPPICPresetData_FR.dat
[2010/08/31 03:50:15 | 000,001,129 | ---- | C] () -- E:\Windows\System32\EPPICPresetData_CF.dat
[2010/08/31 03:50:15 | 000,001,120 | ---- | C] () -- E:\Windows\System32\EPPICPresetData_IT.dat
[2010/08/31 03:50:15 | 000,001,107 | ---- | C] () -- E:\Windows\System32\EPPICPresetData_GE.dat
[2010/08/31 03:50:15 | 000,001,104 | ---- | C] () -- E:\Windows\System32\EPPICPresetData_EN.dat
[2010/08/31 03:50:15 | 000,000,097 | ---- | C] () -- E:\Windows\System32\PICSDK.ini
[2009/07/14 05:04:11 | 000,657,910 | ---- | C] () -- E:\Windows\System32\perfh007.dat
[2009/07/14 05:04:11 | 000,295,922 | ---- | C] () -- E:\Windows\System32\perfi007.dat
[2009/07/14 05:04:11 | 000,131,250 | ---- | C] () -- E:\Windows\System32\perfc007.dat
[2009/07/14 05:04:11 | 000,038,104 | ---- | C] () -- E:\Windows\System32\perfd007.dat
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,410,064 | ---- | C] () -- E:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,619,146 | ---- | C] () -- E:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- E:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,107,466 | ---- | C] () -- E:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- E:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- E:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- E:\Windows\System32\dssec.dat
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- E:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- E:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- E:\Windows\System32\mlang.dat
[2007/11/21 04:31:26 | 000,007,168 | ---- | C] () -- E:\Windows\System32\directport.sys
[2007/03/12 13:59:00 | 000,299,008 | ---- | C] () -- E:\Program Files\navigram_register.exe
========== LOP Check ==========
[2013/03/07 14:33:02 | 000,000,000 | ---D | M] -- E:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2010/06/21 15:33:38 | 000,000,000 | -HSD | M] -- E:\ProgramData\Anwendungsdaten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data
[2011/04/14 14:26:25 | 000,000,000 | ---D | M] -- E:\ProgramData\Avanquest
[2013/01/21 10:14:02 | 000,000,000 | ---D | M] -- E:\ProgramData\AVG January 2013 Campaign
[2012/02/09 13:43:05 | 000,000,000 | ---D | M] -- E:\ProgramData\AVG10
[2013/03/22 17:22:46 | 000,000,000 | ---D | M] -- E:\ProgramData\AVG2012
[2010/11/13 07:30:55 | 000,000,000 | ---D | M] -- E:\ProgramData\avg9
[2011/12/04 15:25:35 | 000,000,000 | ---D | M] -- E:\ProgramData\Big Fish Games
[2012/08/13 14:41:23 | 000,000,000 | ---D | M] -- E:\ProgramData\boost_interprocess
[2010/11/08 14:51:25 | 000,000,000 | ---D | M] -- E:\ProgramData\BVRP Software
[2011/08/20 03:01:43 | 000,000,000 | -H-D | M] -- E:\ProgramData\CanonBJ
[2010/11/14 08:06:24 | 000,000,000 | -H-D | M] -- E:\ProgramData\Common Files
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents
[2010/06/21 15:33:38 | 000,000,000 | -HSD | M] -- E:\ProgramData\Dokumente
[2012/01/11 15:50:20 | 000,000,000 | ---D | M] -- E:\ProgramData\elsterformular
[2013/01/20 01:57:26 | 000,000,000 | ---D | M] -- E:\ProgramData\eMule
[2010/08/31 03:55:59 | 000,000,000 | ---D | M] -- E:\ProgramData\EPSON
[2010/06/21 15:33:38 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favoriten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites
[2010/09/04 10:43:04 | 000,000,000 | ---D | M] -- E:\ProgramData\Fujitsu
[2013/03/06 05:19:07 | 000,000,000 | ---D | M] -- E:\ProgramData\MFAData
[2012/11/18 09:22:23 | 000,000,000 | ---D | M] -- E:\ProgramData\motorola
[2010/07/20 16:31:09 | 000,000,000 | ---D | M] -- E:\ProgramData\PDF Writer
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu
[2010/06/21 15:33:38 | 000,000,000 | -HSD | M] -- E:\ProgramData\Startmenü
[2012/11/18 16:50:22 | 000,000,000 | ---D | M] -- E:\ProgramData\TEMP
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates
[2010/12/15 09:24:28 | 000,000,000 | ---D | M] -- E:\ProgramData\tmp
[2010/08/31 03:54:44 | 000,000,000 | ---D | M] -- E:\ProgramData\UDL
[2010/06/21 15:33:38 | 000,000,000 | -HSD | M] -- E:\ProgramData\Vorlagen
[2011/03/19 12:19:48 | 000,000,000 | ---D | M] -- E:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2013/03/22 04:47:00 | 000,000,240 | ---- | M] () -- E:\Windows\Tasks\Epson Printer Software Downloader.job
[2013/01/21 13:54:24 | 000,000,298 | ---- | M] () -- E:\Windows\Tasks\ROC_REG_JAN_DELETE.job
[2013/02/19 04:37:36 | 000,032,632 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 208 bytes -> E:\ProgramData\TEMP:6D192E3A
< End of report > |