Jollepisch | 11.06.2013 17:38 | AdwCleaner Logfile: Code:
# AdwCleaner v2.303 - Logfile created 06/11/2013 at 18:22:55
# Updated 08/06/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : <username> - <computername>
# Boot Mode : Normal
# Running from : C:\Documents and Settings\<username>\Desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
***** [Registry] *****
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
[OK] Registry is clean.
-\\ Opera v [Unable to get version]
File : C:\Documents and Settings\<username>\Application Data\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [1218 octets] - [29/04/2013 20:31:30]
AdwCleaner[R2].txt - [933 octets] - [29/04/2013 20:43:20]
AdwCleaner[R3].txt - [1229 octets] - [04/05/2013 14:58:17]
AdwCleaner[S1].txt - [1286 octets] - [29/04/2013 20:32:47]
AdwCleaner[S2].txt - [1293 octets] - [04/05/2013 15:40:51]
AdwCleaner[S3].txt - [985 octets] - [11/06/2013 18:22:55]
########## EOF - C:\AdwCleaner[S3].txt - [1044 octets] ########## --- --- --- Zitat:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Microsoft Windows XP x86
Ran by Michael on 11.06.2013 at 18:32:43,35
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 11.06.2013 at 18:36:35,01
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
Gruß
OTL Logfile: Code:
OTL logfile created on: 11.06.2013 18:39:18 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\<username>\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy
1022,72 Mb Total Physical Memory | 370,41 Mb Available Physical Memory | 36,22% Memory free
2,40 Gb Paging File | 1,82 Gb Available in Paging File | 75,72% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34,18 Gb Total Space | 19,56 Gb Free Space | 57,22% Space Free | Partition Type: NTFS
Drive D: | 7,45 Gb Total Space | 6,85 Gb Free Space | 91,89% Space Free | Partition Type: FAT32
Drive E: | 14,65 Gb Total Space | 11,40 Gb Free Space | 77,82% Space Free | Partition Type: NTFS
Drive F: | 70,92 Gb Total Space | 70,33 Gb Free Space | 99,17% Space Free | Partition Type: NTFS
Drive H: | 97,65 Gb Total Space | 39,62 Gb Free Space | 40,57% Space Free | Partition Type: NTFS
Drive M: | 97,65 Gb Total Space | 58,33 Gb Free Space | 59,74% Space Free | Partition Type: NTFS
Drive N: | 241,16 Gb Total Space | 240,79 Gb Free Space | 99,85% Space Free | Partition Type: NTFS
Drive P: | 29,29 Gb Total Space | 29,19 Gb Free Space | 99,66% Space Free | Partition Type: NTFS
Drive S: | 29,29 Gb Total Space | 29,19 Gb Free Space | 99,66% Space Free | Partition Type: NTFS
Computer Name: <PC name> | User Name: <username> | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\<username>\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\<username>\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - E:\Programme\Internet\Opera\opera.exe (Opera Software)
PRC - E:\Programme\Sicherheit\Avast\AvastUI.exe (AVAST Software)
PRC - E:\Programme\Sicherheit\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\VMware\VMware View\Client\bin\wsnm_usbctrl.exe (VMware, Inc.)
PRC - C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe (VMware, Inc.)
PRC - E:\Programme\Sicherheit\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Hama\Common\RaUI.exe (Hama GmbH & Co KG)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Modules (No Company Name) ==========
MOD - E:\Programme\Sicherheit\Avast\defs\13061100\algo.dll ()
MOD - C:\Documents and Settings\<username>\Application Data\Dropbox\bin\libcef.dll ()
MOD - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.DEU ()
MOD - C:\Documents and Settings\<username>\Application Data\Dropbox\bin\wxmsw28uh_vc.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\Program Files\Hama\Common\acAuth.dll ()
========== Services (SafeList) ==========
SRV - (avast! Antivirus) -- E:\Programme\Sicherheit\Avast\AvastSvc.exe (AVAST Software)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (wsnm_usbctrl) -- C:\Program Files\VMware\VMware View\Client\bin\wsnm_usbctrl.exe (VMware, Inc.)
SRV - (wsnm) -- C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe (VMware, Inc.)
SRV - (SoundMAX Agent Service (default) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Driver Services (SafeList) ==========
DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (catchme) -- C:\ComboFix\catchme.sys File not found
DRV - (aswSnx) -- C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) -- C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswVmm) -- C:\WINDOWS\System32\drivers\aswVmm.sys ()
DRV - (aswTdi) -- C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (AswRdr) -- C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswRvrt) -- C:\WINDOWS\System32\drivers\aswRvrt.sys ()
DRV - (aswMonFlt) -- C:\WINDOWS\system32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (aswKbd) -- C:\WINDOWS\System32\drivers\aswKbd.sys (AVAST Software)
DRV - (vmwvusb) -- C:\WINDOWS\system32\drivers\vmwvusb.sys (VMware, Inc.)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (rt2870) -- C:\WINDOWS\system32\drivers\rt2870.sys (Ralink Technology, Corp.)
DRV - (yukonwxp) -- C:\WINDOWS\system32\drivers\yukonwxp.sys (Marvell Semiconductor Inc.)
DRV - (fasttx2k) -- C:\WINDOWS\system32\drivers\Fasttx2k.sys (Promise Technology, Inc.)
DRV - (fpcibase) -- C:\WINDOWS\system32\drivers\fpcibase.sys (AVM GmbH)
DRV - (AVMWAN) -- C:\WINDOWS\system32\drivers\avmwan.sys (AVM GmbH)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = Bing
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\Programme\Multimedia\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2013.06.10 19:30:01 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Programme\Sicherheit\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Programme\Sicherheit\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Programme\Sicherheit\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [avast] E:\Programme\Sicherheit\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Ptipbmf] C:\WINDOWS\System32\ptipbmf.dll (Promise Technology, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] E:\Programme\Sicherheit\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Hama Wireless LAN Utility.lnk = C:\Program Files\Hama\Common\RaUI.exe (Hama GmbH & Co KG)
O4 - Startup: C:\Documents and Settings\<username>\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\<username>\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - E:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Programme\Sicherheit\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1364316029000 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{29326270-2E47-4B02-BF33-A197A2AD039B}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\<username>\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\<username>\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Security Packages - (wsauth) - C:\WINDOWS\System32\wsauth.dll (VMware, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.01.22 18:56:15 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.06.11 18:32:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2013.06.11 18:32:35 | 000,000,000 | ---D | C] -- C:\JRT
[2013.06.11 18:21:34 | 000,545,954 | ---- | C] (Oleg N. Scherbakov) -- C:\Documents and Settings\<username>\Desktop\JRT.exe
[2013.06.10 19:27:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2013.06.10 19:18:48 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2013.06.10 19:16:51 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2013.06.10 19:16:51 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2013.06.10 19:16:51 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2013.06.10 19:16:51 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2013.06.10 19:16:25 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.06.10 19:16:20 | 000,000,000 | R--D | C] -- H:\My Videos
[2013.06.10 19:16:20 | 000,000,000 | R--D | C] -- H:\My Pictures
[2013.06.10 19:16:19 | 000,000,000 | R--D | C] -- H:\My Music
[2013.06.10 19:16:19 | 000,000,000 | R--D | C] -- C:\Documents and Settings\<username>\Start Menu\Programs\Administrative Tools
[2013.06.10 19:16:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2013.06.10 19:14:11 | 005,078,680 | R--- | C] (Swearware) -- C:\Documents and Settings\<username>\Desktop\ComboFix.exe
[2013.06.09 19:12:37 | 000,000,000 | ---D | C] -- C:\Program Files\Dropbox
[2013.06.05 17:47:24 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\<username>\Desktop\OTL.exe
[2013.05.15 20:12:50 | 000,000,000 | ---D | C] -- H:\PersBackup
[2013.05.15 20:12:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\<username>\Application Data\PersBackup5
[2013.05.15 20:12:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Personal Backup
[2013.05.15 20:12:41 | 000,000,000 | ---D | C] -- C:\Program Files\Personal Backup 5
[2013.05.15 20:12:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\<username>\Application Data\FreeFileSync
[2013.05.15 20:12:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\FreeFileSync
[2013.05.15 20:12:04 | 000,000,000 | ---D | C] -- C:\Program Files\FreeFileSync
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.06.11 18:26:27 | 000,000,348 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2013.06.11 18:24:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.06.11 18:24:46 | 1072,472,064 | -HS- | M] () -- C:\hiberfil.sys
[2013.06.11 18:21:37 | 000,545,954 | ---- | M] (Oleg N. Scherbakov) -- C:\Documents and Settings\<username>\Desktop\JRT.exe
[2013.06.11 18:21:24 | 000,648,201 | ---- | M] () -- C:\Documents and Settings\<username>\Desktop\adwcleaner.exe
[2013.06.10 19:30:01 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2013.06.10 19:18:55 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2013.06.10 19:14:41 | 005,078,680 | R--- | M] (Swearware) -- C:\Documents and Settings\<username>\Desktop\ComboFix.exe
[2013.06.09 19:13:08 | 000,001,034 | ---- | M] () -- C:\Documents and Settings\<username>\Start Menu\Programs\Startup\Dropbox.lnk
[2013.06.09 19:02:32 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013.06.05 17:47:25 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\<username>\Desktop\OTL.exe
[2013.05.15 20:49:19 | 000,026,112 | ---- | M] () -- C:\Documents and Settings\<username>\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.05.13 20:10:38 | 000,000,280 | ---- | M] () -- C:\Documents and Settings\<username>\Desktop\Shortcut to Musik (M).lnk
[2013.05.13 20:09:46 | 000,000,370 | ---- | M] () -- C:\Documents and Settings\<username>\Desktop\Shortcut to Bilder.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.06.11 18:21:24 | 000,648,201 | ---- | C] () -- C:\Documents and Settings\<username>\Desktop\adwcleaner.exe
[2013.06.10 19:18:55 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2013.06.10 19:18:51 | 000,262,448 | RHS- | C] () -- C:\cmldr
[2013.06.10 19:16:51 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2013.06.10 19:16:51 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2013.06.10 19:16:51 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2013.06.10 19:16:51 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2013.06.10 19:16:51 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2013.05.13 20:10:38 | 000,000,280 | ---- | C] () -- C:\Documents and Settings\<username>\Desktop\Shortcut to Musik (M).lnk
[2013.05.13 20:09:46 | 000,000,370 | ---- | C] () -- C:\Documents and Settings\<username>\Desktop\Shortcut to Bilder.lnk
[2013.05.06 19:54:12 | 000,232,802 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-861567501-1450960922-1177238915-1003-0.dat
[2013.05.04 01:21:58 | 000,232,802 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2013.03.09 11:52:52 | 000,164,736 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2013.03.09 11:52:51 | 000,049,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys
[2012.08.16 18:11:30 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.08.02 05:52:53 | 000,026,112 | ---- | C] () -- C:\Documents and Settings\<username>\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.07.31 06:13:46 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012.07.31 05:58:41 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012.07.30 22:29:21 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012.07.30 22:26:55 | 000,255,864 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
========== ZeroAccess Check ==========
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 19:00:00 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.02.09 14:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008.04.14 19:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report > --- --- ---
... |