Hui @.@
Nach fast 4 Stunden scannen kann ich dann auch mal den ESET-Log hier posten: Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=a4e95a9d05254449b6ff74e0cb3f6f2c
# engine=13971
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-06-01 09:43:48
# local_time=2013-06-01 11:43:48 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 20263738 121752878 0 0
# scanned=485218
# found=0
# cleaned=0
# scan_time=14247 Hab zwar nur Hauptfestplatte und unsere zwei externen Festplatten gescannt (für'n USB-Stick gab's keinen USB-Anschluss mehr D: ), aber das sollte schon hinhauen~
Na dann mal ran an SecurityCheck. Hoffentlich dauert das nicht so lang... :'D
EDIT: http://puu.sh/36aDu.png
Nun... das ging schnell xD
Dubdidu, ran an OTL~
EDIT2:
-> Achtung: Kleine Änderung - Ich hab gesehen, dass bei dem Feld "Scanne alle Benutzer" kein Haken drin und hab mir gedacht, dass ich einfach mal einen reinsetze. Es gibt ja 2 Benutzerkonten an diesem PC. Das macht doch nichts aus, oder? <-
OTL.txt Code:
OTL logfile created on: 01.06.2013 23:55:54 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Georg\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
7,98 Gb Total Physical Memory | 4,77 Gb Available Physical Memory | 59,77% Memory free
15,96 Gb Paging File | 12,71 Gb Available in Paging File | 79,61% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 906,34 Gb Total Space | 225,04 Gb Free Space | 24,83% Space Free | Partition Type: NTFS
Drive E: | 931,28 Gb Total Space | 894,31 Gb Free Space | 96,03% Space Free | Partition Type: FAT32
Drive F: | 465,76 Gb Total Space | 185,96 Gb Free Space | 39,93% Space Free | Partition Type: NTFS
Computer Name: GEORG-PC | User Name: Georg | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - File not found
PRC - C:\Users\Georg\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\puush\puush.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
PRC - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
PRC - C:\Users\Georg\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Windows\SysWOW64\UMonit.exe ()
PRC - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
PRC - C:\Windows\jmesoft\JME_LOAD.exe ()
PRC - C:\Windows\jmesoft\hotkey.exe (Lenovo)
PRC - C:\Windows\jmesoft\Service.exe ()
PRC - C:\Programme\Lenovo\Lenovo Brightness System\Lenovo Dynamic Brightness System.exe (Lenovo)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Programme\Lenovo\Lenovo Eye Distance System\Lenovo Eye Distance System.exe (Lenovo)
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Windows\vphc700.exe (Sonix)
PRC - C:\Program Files (x86)\Philips\SPC 700NC PC Camera\TrayMin700.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\windows._cacheinvalidation.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\wx._gdi_.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\wx._misc_.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\pysqlite2._sqlite.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\pythoncom27.dll ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\win32com.shell.shell.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\_elementtree.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\PyWinTypes27.dll ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\win32security.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\win32api.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\_ctypes.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\wx._html2.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\_socket.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\_multiprocessing.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\win32ts.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\win32profile.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\win32crypt.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\wx._core_.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\_ssl.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\wx._windows_.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\_hashlib.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\wx._wizard.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\win32process.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\win32pdh.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\wx._controls_.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\unicodedata.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\pyexpat.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\win32file.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\win32inet.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\win32event.pyd ()
MOD - C:\Users\Georg\AppData\Local\Temp\_MEI11682\select.pyd ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\af525b4bec3b9941b7be8ffbf813da80\PresentationFramework.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\30e3a21202000677d0a9270572251477\System.Windows.Forms.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7eac0dbe9aa20b55e37235f8ee030e6b\PresentationCore.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\716959df79685a1eae0fc14275a32b0f\WindowsBase.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll ()
MOD - C:\Program Files (x86)\puush\puush.exe ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.DLL ()
MOD - C:\Program Files (x86)\Steam\SDL2.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\7366a39c36523a084bc11c230929ff92\Microsoft.VisualBasic.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\302207b4fa3083899fd8ab4db98cecc5\System.Management.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\SplitMediaLabs\XSplit\swresample-0.dll ()
MOD - C:\Program Files (x86)\SplitMediaLabs\XSplit\avcodec-54.dll ()
MOD - C:\Program Files (x86)\SplitMediaLabs\XSplit\avformat-54.dll ()
MOD - C:\Program Files (x86)\SplitMediaLabs\XSplit\swscale-2.dll ()
MOD - C:\Program Files (x86)\SplitMediaLabs\XSplit\avutil-51.dll ()
MOD - C:\Windows\SysWOW64\UMonit.exe ()
MOD - C:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Programme\Lenovo\Lenovo Brightness System\ddcHelperWraper.dll ()
MOD - C:\Programme\Lenovo\Lenovo Brightness System\KeyStoneAdapter.dll ()
MOD - C:\Programme\Lenovo\Lenovo Eye Distance System\KeyStoneAdapter.dll ()
MOD - C:\Programme\Lenovo\Lenovo Eye Distance System\VideoPlayer.dll ()
MOD - C:\Windows\jmesoft\VistaVolume.dll ()
MOD - C:\Program Files (x86)\Philips\SPC 700NC PC Camera\TrayMin700.exe ()
========== Services (SafeList) ==========
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (BingDesktopUpdate) -- C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (NisSrv) -- c:\Programme\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) -- c:\Programme\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (SolutoLauncherService) -- C:\Programme\Soluto\SolutoLauncherService.exe (Soluto)
SRV - (SolutoService) -- C:\Programme\Soluto\SolutoService.exe (Soluto)
SRV - (Secunia PSI Agent) -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Secunia)
SRV - (Secunia Update Agent) -- C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (STRATO HiDrive Service) -- C:\Program Files (x86)\STRATO AG\STRATO HiDrive\STRATO HiDrive Service.exe (STRATO)
SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (Fabs) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe (MAGIX®)
SRV - (JME Keyboard) -- C:\Windows\jmesoft\Service.exe ()
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Creative Service for CDROM Access) -- C:\Windows\SysWOW64\CTSVCCDA.EXE (Creative Technology Ltd)
========== Driver Services (SafeList) ==========
DRV:64bit: - (NisDrv) -- C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Soluto) -- C:\Windows\SysNative\drivers\Soluto.sys (Soluto LTD.)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (Fs_Rec) -- C:\windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USB28xxBGA) -- C:\Windows\SysNative\drivers\emBDA64.sys (eMPIA Technology, Inc.)
DRV:64bit: - (USB28xxOEM) -- C:\Windows\SysNative\drivers\emOEM64.sys (eMPIA Technology, Inc.)
DRV:64bit: - (emAudio) -- C:\Windows\SysNative\drivers\emAudio64.sys (eMPIA Technology, Inc.)
DRV:64bit: - (PSI) -- C:\Windows\SysNative\drivers\psi_mf.sys (Secunia)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Rovi Corporation)
DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (GeneStor) -- C:\Windows\SysNative\drivers\GeneStor.sys (GenesysLogic)
DRV:64bit: - (tap0901) -- C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (e1cexpress) -- C:\Windows\SysNative\drivers\e1c62x64.sys (Intel Corporation)
DRV:64bit: - (acedrv11) -- C:\Windows\SysNative\drivers\acedrv11.sys (Protect Software GmbH)
DRV:64bit: - (wsvd) -- C:\Windows\SysNative\drivers\wsvd.sys (CyberLink)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (yukonw7) -- C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (WinI2C-DDC) -- C:\Windows\SysNative\drivers\ddcdrv.sys (Nicomsoft Ltd.)
DRV:64bit: - (phc700) -- C:\Windows\SysNative\drivers\phc700.sys ()
DRV - (WinI2C-DDC) -- C:\Windows\SysWOW64\drivers\ddcdrv.sys (Nicomsoft Ltd.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2764890169-2354917355-972681180-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
IE - HKU\S-1-5-21-2764890169-2354917355-972681180-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://de.msn.com/?pc=BB07 [binary data]
IE - HKU\S-1-5-21-2764890169-2354917355-972681180-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com
IE - HKU\S-1-5-21-2764890169-2354917355-972681180-1001\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-2764890169-2354917355-972681180-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com
IE - HKU\S-1-5-21-2764890169-2354917355-972681180-1001\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2764890169-2354917355-972681180-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-2764890169-2354917355-972681180-1001\..\SearchScopes\{C88215D9-8C4C-4C02-BD96-C2F219F35ED5}: "URL" = hxxp://www.bing.com/search?FORM=BB07DF&PC=BB07&q={searchTerms}&src=IE-SearchBox
IE - HKU\S-1-5-21-2764890169-2354917355-972681180-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "hxxp://www.bing.com/search?FORM=BB07DF&PC=BB07&q="
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/firefox"
FF - prefs.js..extensions.enabledAddons: %7B59c81df5-4b7a-477b-912d-4e0fdf64e5f2%7D:0.9.90
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130402
FF - prefs.js..extensions.enabledAddons: youtubeunblocker%40unblocker.yt:0.4.2
FF - prefs.js..extensions.enabledAddons: stefanvandamme%40stefanvd.net:2.2.0.2
FF - prefs.js..extensions.enabledAddons: %7Bc0c588b6-b11d-4898-af00-079fed05aa32%7D:20.1
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.10
FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q="
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeExManDetect: C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeExManDetect: C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Georg\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Georg\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\PROGRAM FILES\ESET\ESET SMART SECURITY\MOZILLA THUNDERBIRD
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.05.20 19:17:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.05.16 17:19:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013.05.15 17:52:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.05.20 19:17:57 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.05.16 17:19:49 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013.05.15 17:52:52 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
[2012.08.30 12:10:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Georg\AppData\Roaming\Mozilla\Extensions
[2012.08.30 12:10:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Georg\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013.05.04 08:50:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Georg\AppData\Roaming\Mozilla\Firefox\Profiles\00tp9q8u.default\extensions
[2013.03.03 16:39:50 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\Georg\AppData\Roaming\Mozilla\Firefox\Profiles\00tp9q8u.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2013.05.04 07:46:02 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Georg\AppData\Roaming\Mozilla\Firefox\Profiles\00tp9q8u.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013.05.04 08:50:20 | 000,651,215 | ---- | M] () (No name found) -- C:\Users\Georg\AppData\Roaming\Mozilla\Firefox\Profiles\00tp9q8u.default\extensions\stefanvandamme@stefanvd.net.xpi
[2013.05.04 08:50:20 | 000,008,023 | ---- | M] () (No name found) -- C:\Users\Georg\AppData\Roaming\Mozilla\Firefox\Profiles\00tp9q8u.default\extensions\youtubeunblocker@unblocker.yt.xpi
[2013.05.04 08:50:20 | 003,242,364 | ---- | M] () (No name found) -- C:\Users\Georg\AppData\Roaming\Mozilla\Firefox\Profiles\00tp9q8u.default\extensions\{c0c588b6-b11d-4898-af00-079fed05aa32}.xpi
[2013.03.20 19:10:00 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Georg\AppData\Roaming\Mozilla\Firefox\Profiles\00tp9q8u.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012.09.08 13:56:06 | 000,001,832 | ---- | M] () -- C:\Users\Georg\AppData\Roaming\Mozilla\Firefox\Profiles\00tp9q8u.default\searchplugins\bing.xml
[2013.05.20 19:17:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
[2013.05.20 19:17:58 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010.01.06 03:04:02 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2764890169-2354917355-972681180-1001\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [phc700] C:\Windows\vphc700.exe (Sonix)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [UMonit] C:\Windows\SysWOW64\UMonit.exe ()
O4:64bit: - HKLM..\Run: [WrtMon.exe] C:\Windows\SysNative\spool\drivers\x64\3\WrtMon.exe ()
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (Microsoft Corp.)
O4 - HKLM..\Run: [jmekey] C:\Windows\jmesoft\hotkey.exe (Lenovo)
O4 - HKLM..\Run: [jmesoft] C:\Windows\jmesoft\ServiceLoader.exe ()
O4 - HKLM..\Run: [Lenovo Dynamic Brightness System] C:\Program Files\Lenovo\Lenovo Brightness System\Lenovo Dynamic Brightness System.exe (Lenovo)
O4 - HKLM..\Run: [Lenovo Eye Distance System] C:\Program Files\Lenovo\Lenovo Eye Distance System\Lenovo Eye Distance System.exe (Lenovo)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [phc700] C:\windows\system32\vphc700.exe File not found
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TrayServer] C:\PROGRA~2\MAGIX\VIDEO_~1\TrayServer_de.exe (MAGIX AG)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2764890169-2354917355-972681180-1001..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-21-2764890169-2354917355-972681180-1001..\Run: [Facebook Update] C:\Users\Georg\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-2764890169-2354917355-972681180-1001..\Run: [puush] C:\Program Files (x86)\puush\puush.exe ()
O4 - HKU\S-1-5-21-2764890169-2354917355-972681180-1001..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Georg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Georg\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-2764890169-2354917355-972681180-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2764890169-2354917355-972681180-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-2764890169-2354917355-972681180-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Georg\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm File not found
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Georg\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O8 - Extra context menu item: Free YouTube Download - C:\Users\Georg\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm File not found
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Georg\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1369826421840 (MUCatalogWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B2938FA1-8998-4697-B61C-3E7448CF269D}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Program Files\Soluto\soluto.exe /userinit) - C:\Program Files\Soluto\soluto.exe (Soluto)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011.09.15 06:12:14 | 000,000,080 | ---- | M] () - F:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.06.01 23:56:08 | 000,000,000 | ---D | C] -- C:\Users\Georg\Desktop\archiv2
[2013.06.01 19:35:28 | 002,347,384 | ---- | C] (ESET) -- C:\Users\Georg\Desktop\esetsmartinstaller_enu.exe
[2013.06.01 19:13:56 | 000,000,000 | ---D | C] -- C:\windows\ERUNT
[2013.06.01 19:10:43 | 000,000,000 | ---D | C] -- C:\JRT
[2013.06.01 19:10:02 | 000,545,954 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\Georg\Desktop\JRT.exe
[2013.06.01 18:55:50 | 000,000,000 | ---D | C] -- C:\Users\Georg\Desktop\archiv
[2013.06.01 13:31:02 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Georg\Desktop\OTL.exe
[2013.05.29 18:08:46 | 000,000,000 | --SD | C] -- C:\Users\Georg\Google Drive
[2013.05.29 18:07:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
[2013.05.29 13:22:46 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\cscapi.dll
[2013.05.29 13:22:46 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\cscdll.dll
[2013.05.29 13:22:44 | 000,166,400 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\inetpp.dll
[2013.05.29 13:22:44 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\tcpmib.dll
[2013.05.29 13:22:44 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\tcpmib.dll
[2013.05.29 13:22:44 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\sscore.dll
[2013.05.29 13:22:42 | 000,225,792 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dhcpcore6.dll
[2013.05.29 13:22:42 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dhcpcore6.dll
[2013.05.29 13:22:42 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\davclnt.dll
[2013.05.29 13:22:42 | 000,054,784 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dhcpcsvc6.dll
[2013.05.29 13:22:41 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ncsi.dll
[2013.05.29 13:22:41 | 000,190,824 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\storport.sys
[2013.05.29 13:22:41 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ncsi.dll
[2013.05.29 13:22:41 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\tcpmonui.dll
[2013.05.29 13:22:41 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\tcpmonui.dll
[2013.05.29 13:22:40 | 000,275,456 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\rdpdd.dll
[2013.05.29 13:22:40 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dot3dlg.dll
[2013.05.29 13:22:39 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\gpprnext.dll
[2013.05.29 13:22:39 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\gpprnext.dll
[2013.05.29 13:22:38 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\hidclass.sys
[2013.05.29 13:22:37 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\svchost.exe
[2013.05.29 13:22:36 | 000,698,880 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\netlogon.dll
[2013.05.29 13:22:36 | 000,115,200 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dot3msm.dll
[2013.05.29 13:22:35 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dot3msm.dll
[2013.05.29 13:22:35 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dot3api.dll
[2013.05.29 13:22:35 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dot3gpclnt.dll
[2013.05.29 13:22:35 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dot3gpclnt.dll
[2013.05.29 13:22:33 | 001,065,984 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\Display.dll
[2013.05.29 13:22:33 | 001,039,872 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\Display.dll
[2013.05.29 13:22:33 | 000,876,544 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\advapi32.dll
[2013.05.29 13:22:33 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\FWPUCLNT.DLL
[2013.05.29 13:22:32 | 000,965,120 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\localspl.dll
[2013.05.29 13:22:32 | 000,832,000 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\nshwfp.dll
[2013.05.29 13:22:32 | 000,657,920 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\nshwfp.dll
[2013.05.29 13:22:32 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\FWPUCLNT.DLL
[2013.05.29 13:22:32 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wpnpinst.exe
[2013.05.26 13:26:38 | 000,000,000 | ---D | C] -- C:\Users\Georg\AppData\Local\Facebook
[2013.05.25 21:27:30 | 000,000,000 | ---D | C] -- C:\Users\Georg\Lucia
[2013.05.21 15:30:30 | 000,000,000 | ---D | C] -- C:\Users\Georg\AppData\Roaming\TS3Client
[2013.05.21 15:19:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
[2013.05.21 15:19:29 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client
[2013.05.20 13:46:46 | 000,000,000 | ---D | C] -- C:\Users\Georg\AppData\Local\Craften_Dev_Team
[2013.05.20 13:46:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Craften Terminal
[2013.05.20 13:46:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Craften Terminal
[2013.05.16 22:18:40 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieui.dll
[2013.05.16 22:18:40 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieui.dll
[2013.05.16 22:18:40 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ie4uinit.exe
[2013.05.16 22:18:39 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\iesysprep.dll
[2013.05.16 22:18:39 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\iesysprep.dll
[2013.05.16 22:18:39 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\RegisterIEPKEYs.exe
[2013.05.16 22:18:39 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\RegisterIEPKEYs.exe
[2013.05.16 22:18:39 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\iesetup.dll
[2013.05.16 22:18:39 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\iesetup.dll
[2013.05.16 22:18:39 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\iernonce.dll
[2013.05.16 22:18:39 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\iernonce.dll
[2013.05.16 22:18:38 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msfeeds.dll
[2013.05.16 22:18:37 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript.dll
[2013.05.16 22:18:36 | 003,958,784 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript9.dll
[2013.05.16 22:18:36 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\jscript.dll
[2013.05.16 17:12:10 | 000,265,064 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\dxgmms1.sys
[2013.05.16 17:12:10 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\cdd.dll
[2013.05.16 17:11:59 | 001,931,776 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\authui.dll
[2013.05.16 17:11:59 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\authui.dll
[2013.05.16 17:11:59 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\shdocvw.dll
[2013.05.16 17:11:59 | 000,111,976 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\consent.exe
[2013.05.16 17:11:52 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wwanprotdim.dll
[2013.05.15 18:01:06 | 000,000,000 | ---D | C] -- C:\Users\Georg\Documents\Adobe
[2013.05.15 17:59:59 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Adobe
[2013.05.15 17:52:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2013.05.15 17:50:20 | 000,056,208 | ---- | C] (Rovi Corporation) -- C:\windows\SysNative\drivers\PxHlpa64.sys
[2013.05.15 17:50:20 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\windows\SysNative\drivers\cdralw2k.sys
[2013.05.15 17:50:20 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\windows\SysNative\drivers\cdr4_xp.sys
[2013.05.15 17:50:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared
[2013.05.15 17:50:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2013.05.15 17:50:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\My Company Name
[2013.05.15 17:39:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AnalogX
[2013.05.13 17:25:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DVDVideoSoft
[2013.05.13 17:25:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DVDVideoSoft
[2013.05.05 19:21:16 | 000,000,000 | ---D | C] -- C:\Users\Georg\AppData\Roaming\LOVE
[2013.05.04 08:18:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012.03.21 14:37:20 | 001,914,000 | ---- | C] (Adobe Systems Incorporated) -- C:\ProgramData\flashax10.exe
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.06.01 23:51:06 | 000,890,839 | ---- | M] () -- C:\Users\Georg\Desktop\SecurityCheck.exe
[2013.06.01 23:45:05 | 000,001,124 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.06.01 23:34:02 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2013.06.01 22:31:03 | 000,000,928 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-2764890169-2354917355-972681180-1001UA.job
[2013.06.01 19:45:30 | 001,613,996 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2013.06.01 19:45:30 | 000,697,064 | ---- | M] () -- C:\windows\SysNative\perfh007.dat
[2013.06.01 19:45:30 | 000,652,382 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2013.06.01 19:45:30 | 000,148,102 | ---- | M] () -- C:\windows\SysNative\perfc007.dat
[2013.06.01 19:45:30 | 000,121,056 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2013.06.01 19:35:30 | 002,347,384 | ---- | M] (ESET) -- C:\Users\Georg\Desktop\esetsmartinstaller_enu.exe
[2013.06.01 19:13:17 | 000,020,480 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.06.01 19:13:17 | 000,020,480 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.06.01 19:10:08 | 000,545,954 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\Georg\Desktop\JRT.exe
[2013.06.01 19:01:13 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2013.06.01 19:01:07 | 2133,630,975 | -HS- | M] () -- C:\hiberfil.sys
[2013.06.01 18:59:39 | 000,001,286 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013.06.01 18:59:39 | 000,001,148 | ---- | M] () -- C:\Users\Georg\Desktop\Internet Explorer.lnk
[2013.06.01 18:59:39 | 000,001,049 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013.06.01 18:56:38 | 000,632,031 | ---- | M] () -- C:\Users\Georg\Desktop\adwcleaner.exe
[2013.06.01 13:31:04 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Georg\Desktop\OTL.exe
[2013.06.01 13:31:00 | 000,000,906 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-2764890169-2354917355-972681180-1001Core.job
[2013.05.31 20:34:43 | 000,001,103 | ---- | M] () -- C:\Users\Public\Desktop\Craften Terminal.lnk
[2013.05.31 15:09:25 | 002,456,832 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2013.05.30 21:01:44 | 000,420,944 | ---- | M] (Microsoft Corporation) -- C:\windows\SysWow64\msvcp100.dll
[2013.05.29 18:08:47 | 000,001,713 | ---- | M] () -- C:\Users\Georg\Desktop\Google Drive.lnk
[2013.05.23 17:39:06 | 000,009,384 | ---- | M] () -- C:\Users\Georg\AppData\Local\recently-used.xbel
[2013.05.21 15:19:35 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2013.05.20 12:42:17 | 000,263,186 | ---- | M] () -- C:\Users\Georg\Desktop\Minecraft.exe
[2013.05.18 13:55:30 | 018,444,678 | ---- | M] () -- C:\Users\Georg\Desktop\cave story osu.mp4
[2013.05.18 00:06:12 | 000,170,858 | ---- | M] () -- C:\Users\Georg\Desktop\Der 2-2 Blues.pdf
[2013.05.17 19:46:17 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.05.17 19:36:53 | 007,153,538 | ---- | M] () -- C:\Users\Georg\Desktop\HASHTAGYOLOSWAG.exe
[2013.05.15 21:59:15 | 000,000,871 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2013.05.15 21:22:31 | 000,087,330 | ---- | M] () -- C:\Users\Georg\Desktop\Peach_and_Bowser_Wedding_by_EmperorTokijin.jpg
[2013.05.15 21:22:27 | 000,028,682 | ---- | M] () -- C:\Users\Georg\Desktop\600px-Prince_Mario_and_Princess_Peach.jpg
[2013.05.15 21:22:18 | 000,275,465 | ---- | M] () -- C:\Users\Georg\Desktop\marioandpeachvgloungecom1.jpg
[2013.05.15 19:34:40 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerApp.exe
[2013.05.15 19:34:40 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.05.15 17:47:06 | 000,001,518 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Application Manager.lnk
[2013.05.13 17:25:40 | 000,001,302 | ---- | M] () -- C:\Users\Public\Desktop\Free YouTube Download.lnk
[2013.05.09 00:42:01 | 000,002,634 | ---- | M] () -- C:\Users\Georg\Desktop\My Movie_mp4.HDP
[2013.05.05 20:55:26 | 007,140,191 | ---- | M] () -- C:\Users\Georg\Desktop\My Movie.mp4
[2013.05.05 20:40:35 | 048,569,695 | ---- | M] () -- C:\Users\Georg\Desktop\magix at its best ... not.mp4
[2013.05.05 16:29:04 | 000,063,690 | ---- | M] () -- C:\Users\Georg\Desktop\Kuendigungsformular.pdf
[2013.05.04 07:23:27 | 000,001,120 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.06.01 23:51:03 | 000,890,839 | ---- | C] () -- C:\Users\Georg\Desktop\SecurityCheck.exe
[2013.06.01 18:56:34 | 000,632,031 | ---- | C] () -- C:\Users\Georg\Desktop\adwcleaner.exe
[2013.05.29 18:08:47 | 000,001,713 | ---- | C] () -- C:\Users\Georg\Desktop\Google Drive.lnk
[2013.05.26 13:26:43 | 000,000,928 | ---- | C] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-2764890169-2354917355-972681180-1001UA.job
[2013.05.26 13:26:42 | 000,000,906 | ---- | C] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-2764890169-2354917355-972681180-1001Core.job
[2013.05.23 17:39:06 | 000,009,384 | ---- | C] () -- C:\Users\Georg\AppData\Local\recently-used.xbel
[2013.05.21 15:19:35 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2013.05.20 13:46:23 | 000,001,103 | ---- | C] () -- C:\Users\Public\Desktop\Craften Terminal.lnk
[2013.05.20 12:42:12 | 000,263,186 | ---- | C] () -- C:\Users\Georg\Desktop\Minecraft.exe
[2013.05.18 13:52:21 | 018,444,678 | ---- | C] () -- C:\Users\Georg\Desktop\cave story osu.mp4
[2013.05.18 00:06:10 | 000,170,858 | ---- | C] () -- C:\Users\Georg\Desktop\Der 2-2 Blues.pdf
[2013.05.17 19:36:50 | 007,153,538 | ---- | C] () -- C:\Users\Georg\Desktop\HASHTAGYOLOSWAG.exe
[2013.05.15 21:22:29 | 000,087,330 | ---- | C] () -- C:\Users\Georg\Desktop\Peach_and_Bowser_Wedding_by_EmperorTokijin.jpg
[2013.05.15 21:22:25 | 000,028,682 | ---- | C] () -- C:\Users\Georg\Desktop\600px-Prince_Mario_and_Princess_Peach.jpg
[2013.05.15 21:22:17 | 000,275,465 | ---- | C] () -- C:\Users\Georg\Desktop\marioandpeachvgloungecom1.jpg
[2013.05.15 17:51:50 | 000,001,245 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Audition CS6.lnk
[2013.05.13 17:25:40 | 000,001,302 | ---- | C] () -- C:\Users\Public\Desktop\Free YouTube Download.lnk
[2013.05.05 21:04:08 | 000,002,634 | ---- | C] () -- C:\Users\Georg\Desktop\My Movie_mp4.HDP
[2013.05.05 20:51:18 | 007,140,191 | ---- | C] () -- C:\Users\Georg\Desktop\My Movie.mp4
[2013.05.05 20:36:49 | 048,569,695 | ---- | C] () -- C:\Users\Georg\Desktop\magix at its best ... not.mp4
[2013.05.05 16:29:03 | 000,063,690 | ---- | C] () -- C:\Users\Georg\Desktop\Kuendigungsformular.pdf
[2013.03.20 19:30:18 | 002,075,362 | ---- | C] () -- C:\Users\Georg\wmah.png
[2013.03.08 21:46:09 | 000,500,934 | ---- | C] () -- C:\Users\Georg\YT-2013-Channel-Layout.psd
[2013.03.07 20:11:38 | 000,286,787 | ---- | C] () -- C:\Users\Georg\Mario and Luigi_ Partners in Time Music - Time Hole (To Past).mp3
[2013.03.07 20:11:37 | 000,265,856 | ---- | C] () -- C:\Users\Georg\Mario & Luigi_ Partners In Time Music_ Time Hole (To Present).mp3
[2013.03.03 13:32:03 | 000,017,479 | ---- | C] () -- C:\Users\Georg\README.html
[2013.03.03 13:31:16 | 015,962,145 | ---- | C] () -- C:\Users\Georg\OpenHexagonV1.7.7z
[2013.02.28 18:25:23 | 000,003,584 | ---- | C] () -- C:\Users\Georg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.02.27 20:04:25 | 027,885,892 | ---- | C] () -- C:\Users\Georg\2013-02-27 - viedoe.mp4
[2013.02.27 19:59:47 | 000,096,120 | ---- | C] () -- C:\Users\Georg\2013-02-27 - 0002.JPG
[2013.02.27 19:57:32 | 000,090,108 | ---- | C] () -- C:\Users\Georg\2013-02-27 - 0001.JPG
[2013.02.05 21:23:41 | 371,802,536 | ---- | C] () -- C:\Users\Georg\OIO-v3.4.0.2724.zip
[2013.01.18 17:01:47 | 001,056,534 | ---- | C] () -- C:\Users\Georg\TK Brief Seite 2.pdf
[2013.01.18 17:01:47 | 000,528,162 | ---- | C] () -- C:\Users\Georg\TK Brief Seite 1.pdf
[2013.01.02 16:41:05 | 000,004,342 | ---- | C] () -- C:\Users\Georg\Ein_kleines_Dankeschön_für_ELSA_Ihr_10_Gutschein.eml
[2013.01.02 10:54:52 | 000,339,394 | ---- | C] () -- C:\Users\Georg\OptiFine_1.4.6_HD_U_A2.zip
[2012.11.16 20:52:58 | 000,325,327 | ---- | C] () -- C:\Users\Georg\OptiFine Mod 1.4.4.zip
[2012.10.29 21:47:52 | 000,000,098 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2012.10.20 23:03:45 | 000,011,351 | -HS- | C] () -- C:\Users\Georg\Folder.jpg
[2012.10.20 23:03:45 | 000,011,351 | -HS- | C] () -- C:\Users\Georg\AlbumArt_{F083D7D6-D194-444E-AD61-1A2F2DCADD22}_Large.jpg
[2012.10.20 23:03:45 | 000,002,936 | -HS- | C] () -- C:\Users\Georg\AlbumArtSmall.jpg
[2012.10.20 23:03:45 | 000,002,936 | -HS- | C] () -- C:\Users\Georg\AlbumArt_{F083D7D6-D194-444E-AD61-1A2F2DCADD22}_Small.jpg
[2012.10.20 23:03:05 | 138,968,261 | ---- | C] () -- C:\Users\Georg\News _ Infos zum Nintendo 3DS - Die dritte Dimension in der Hosentasche [HD].mp4
[2012.10.20 23:03:04 | 003,023,829 | ---- | C] () -- C:\Users\Georg\Lemon Tree with Lyrics_ By Fool's Garden (HD).mp3
[2012.10.20 23:01:33 | 000,651,923 | ---- | C] () -- C:\Users\Georg\talent.wmv
[2012.10.13 12:23:16 | 000,586,255 | ---- | C] () -- C:\Users\Georg\bank.jpg
[2012.10.12 10:59:18 | 000,331,339 | ---- | C] () -- C:\Users\Georg\Löwenzahn.pdf
[2012.10.11 14:27:18 | 005,904,128 | ---- | C] () -- C:\Users\Georg\IKS Brief.pdf
[2012.10.11 14:27:18 | 000,846,537 | ---- | C] () -- C:\Users\Georg\IKS-Brief Ergänzung.pdf
[2012.10.01 20:57:55 | 001,662,976 | ---- | C] () -- C:\Users\Georg\alexibexi klingelton.mpg
[2012.10.01 20:57:55 | 000,101,146 | ---- | C] () -- C:\Users\Georg\AlexiBexi Klingelton - I'm a scat man!.MP3
[2012.10.01 20:53:13 | 002,891,416 | ---- | C] () -- C:\Users\Georg\Kanal Screenshot.png
[2012.10.01 20:53:13 | 000,191,205 | ---- | C] () -- C:\Users\Georg\Kanaldesign.PNG
[2012.10.01 20:53:13 | 000,140,762 | ---- | C] () -- C:\Users\Georg\Kanaldesign (Küken, Name, Farbverlauf).png
[2012.10.01 20:53:13 | 000,138,319 | ---- | C] () -- C:\Users\Georg\Kanaldesign (nur Küken und Name).png
[2012.10.01 20:49:59 | 003,426,304 | ---- | C] () -- C:\Users\Georg\Schaumparty.mpg
[2012.10.01 20:49:59 | 002,118,375 | ---- | C] () -- C:\Users\Georg\Präsentation Gewitter.odp
[2012.10.01 20:49:59 | 002,118,274 | ---- | C] () -- C:\Users\Georg\Präsentation Gewitter für mich.odp
[2012.10.01 20:49:59 | 000,748,152 | ---- | C] () -- C:\Users\Georg\Schaumparty.mp4
[2012.10.01 20:49:59 | 000,052,289 | ---- | C] () -- C:\Users\Georg\Schaumparty.MP3
[2012.10.01 20:49:58 | 002,118,375 | ---- | C] () -- C:\Users\Georg\Präsentation Gewitter für Jakob.odp
[2012.09.16 15:42:31 | 000,001,229 | ---- | C] () -- C:\Users\Georg\Cave Story - Einfach Optionen.lnk
[2012.09.16 15:42:31 | 000,001,222 | ---- | C] () -- C:\Users\Georg\Cave Story - Musik.lnk
[2012.09.11 17:38:26 | 000,014,678 | ---- | C] () -- C:\Users\Georg\Informatik AB Variablen Aufgabe.odt
[2012.09.11 17:19:42 | 001,590,954 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012.09.09 21:39:42 | 000,000,052 | -H-- | C] () -- C:\windows\popcreg.dat
[2012.09.09 21:39:42 | 000,000,014 | ---- | C] () -- C:\windows\popcinfot.dat
[2012.09.08 21:23:35 | 000,275,916 | ---- | C] () -- C:\Users\Georg\OptiFine_1.3.2_HD_B3.zip
[2012.09.08 15:55:19 | 000,015,488 | ---- | C] () -- C:\windows\phc700.ini
[2012.09.04 18:36:05 | 000,000,538 | ---- | C] () -- C:\Users\Georg\stern.py
[2012.09.04 18:34:02 | 000,001,463 | ---- | C] () -- C:\Users\Georg\IPI-TurtleGrafikV3.lnk
[2012.09.03 19:10:18 | 000,000,680 | RHS- | C] () -- C:\Users\Georg\ntuser.pol
[2012.09.03 18:45:34 | 000,188,803 | ---- | C] () -- C:\Users\Georg\englisch australische schilder.odt
[2012.08.31 20:21:56 | 000,000,043 | ---- | C] () -- C:\windows\popcinfo.dat
[2012.08.30 14:32:22 | 000,263,186 | ---- | C] () -- C:\Users\Georg\Minecraft.exe
[2012.08.30 12:10:37 | 000,000,000 | ---- | C] () -- C:\windows\nsreg.dat
[2012.08.30 11:39:16 | 000,011,776 | ---- | C] () -- C:\windows\SysWow64\pmsbfn32.dll
[2012.08.30 11:37:26 | 000,000,424 | ---- | C] () -- C:\windows\MAXLINK.INI
[2012.03.21 14:54:41 | 000,201,728 | ---- | C] () -- C:\windows\SetDrive.exe
[2012.03.21 14:54:40 | 000,036,864 | ---- | C] () -- C:\windows\WinWait.exe
[2012.03.21 14:04:51 | 000,139,264 | ---- | C] () -- C:\windows\SysWow64\ustor.dll
[2012.03.21 14:04:51 | 000,049,152 | ---- | C] () -- C:\windows\SysWow64\UMonit.exe
[2012.03.21 14:04:48 | 000,172,097 | ---- | C] () -- C:\windows\SysWow64\NoMSGuninstall.exe
[2012.03.21 14:04:48 | 000,001,591 | ---- | C] () -- C:\windows\SysWow64\_IconCfg0.ini
[2012.03.21 14:04:48 | 000,000,840 | ---- | C] () -- C:\windows\SysWow64\ProductName.ini
[2012.03.21 14:04:48 | 000,000,187 | ---- | C] () -- C:\windows\SysWow64\IconCfg0.ini
[2012.03.21 14:01:39 | 000,008,192 | ---- | C] () -- C:\windows\SysWow64\drivers\IntelMEFWVer.dll
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:23:59 | 014,176,768 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:27:31 | 012,875,776 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012.08.21 15:11:31 | 000,857,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012.08.21 15:37:44 | 000,636,928 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012.08.21 15:08:38 | 000,453,120 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== Files - Unicode (All) ==========
[2012.10.01 21:00:46 | 000,000,000 | ---D | M](C:\Users\Georg\??????? ???????????) -- C:\Users\Georg\Русские мультфильмы
[2012.10.01 21:00:46 | 000,000,000 | ---D | M](C:\Users\Georg\??????? ???????????) -- C:\Users\Georg\Русские мультфильмы
(C:\Users\Georg\??????? ???????????) -- C:\Users\Georg\Русские мультфильмы
========== Alternate Data Streams ==========
@Alternate Data Stream - 1105 bytes -> C:\Users\Georg\Ein_kleines_Dankeschön_für_ELSA_Ihr_10_Gutschein.eml:OECustomProperty
< End of report > |