leider erstellt OTL nur eine Logfile, vielleicht wg Quick Scan??OTL Logfile: Code:
OTL logfile created on: 12.07.2013 14:55:47 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\***** *******\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,98 Gb Total Physical Memory | 2,39 Gb Available Physical Memory | 80,01% Memory free
4,82 Gb Paging File | 4,27 Gb Available in Paging File | 88,43% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 142,51 Gb Total Space | 17,05 Gb Free Space | 11,97% Space Free | Partition Type: NTFS
Drive F: | 298,09 Gb Total Space | 248,16 Gb Free Space | 83,25% Space Free | Partition Type: NTFS
Computer Name: LENOVO-66E55E6C | User Name: ***** ******* | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Programme\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Dokumente und Einstellungen\***** *******\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\TeamViewer\Version8\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Programme\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Oracle Corporation)
PRC - c:\Programme\Lenovo\System Update\SUService.exe (Lenovo Group Limited)
PRC - C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Programme\RosettaStoneLtdServices\RosettaStoneDaemon.exe (Rosetta Stone Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - c:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\tvtsched.exe (Lenovo Group Limited)
PRC - C:\Programme\Gemeinsame Dateien\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
PRC - C:\Programme\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
PRC - C:\Programme\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe (Lenovo )
PRC - C:\Programme\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
PRC - C:\Programme\ThinkPad\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Programme\Lenovo\Rescue and Recovery\rrpservice.exe ()
PRC - C:\Programme\Gemeinsame Dateien\Lenovo\Logger\logmon.exe ()
PRC - C:\Programme\Lenovo\Rescue and Recovery\ADM\IUService.exe ()
PRC - C:\WINDOWS\system32\IPSSVC.EXE (Lenovo Group Limited)
PRC - C:\Programme\Gemeinsame Dateien\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
PRC - C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\MEGACAM\NTMEGS.EXE ()
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\b22afb5424455b579511b925aa1563c9\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8f3e54440f3742da409131428ad1bce1\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\a1d221960bf7a0cbfd1f355595f77e83\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\16562c54978851e92db8fec6f759bba1\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\b14359470744c840c59fbe4e58034fd6\mscorlib.ni.dll ()
MOD - C:\Programme\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.ServiceProcess.resources.dll ()
MOD - C:\Programme\WinRAR\RarExt.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\Programme\Intel\Wireless\Bin\iWMSProv.dll ()
MOD - C:\Programme\Lenovo\Rescue and Recovery\rrpservice.exe ()
MOD - C:\Programme\Gemeinsame Dateien\Lenovo\Logger\logmon.exe ()
MOD - C:\Programme\Lenovo\Rescue and Recovery\CDRecord.dll ()
MOD - C:\Programme\Lenovo\Rescue and Recovery\ADM\IUService.exe ()
MOD - C:\Programme\Lenovo\HOTKEY\tphklock.dll ()
MOD - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AdistRes.DEU ()
MOD - C:\WINDOWS\system32\elalsp32.tsp ()
MOD - C:\MEGACAM\NTMEGS.EXE ()
MOD - C:\MEGACAM\CC32STZ.DLL ()
========== Services (SafeList) ==========
SRV - (RoxLiveShare9) -- C:\Programme\Gemeinsame Dateien\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe File not found
SRV - (JavaQuickStarterService) -- C:\Programme\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (TeamViewer8) -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (SUService) -- c:\Programme\Lenovo\System Update\SUService.exe (Lenovo Group Limited)
SRV - (Apple Mobile Device) -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (RosettaStoneDaemon) -- C:\Programme\RosettaStoneLtdServices\RosettaStoneDaemon.exe (Rosetta Stone Ltd.)
SRV - (SolidWorks Licensing Service) -- C:\Programme\Gemeinsame Dateien\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (TVT Scheduler) -- c:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\tvtsched.exe (Lenovo Group Limited)
SRV - (NMIndexingService) -- C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (ThinkVantage Registry Monitor Service) -- C:\Programme\Gemeinsame Dateien\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
SRV - (AcPrfMgrSvc) -- C:\Programme\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
SRV - (AcSvc) -- C:\Programme\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
SRV - (btwdins) -- C:\Programme\ThinkPad\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (TVT Backup Protection Service) -- C:\Programme\Lenovo\Rescue and Recovery\rrpservice.exe ()
SRV - (tvtnetwk) -- C:\Programme\Lenovo\Rescue and Recovery\ADM\IUService.exe ()
SRV - (IPSSVC) -- C:\WINDOWS\system32\IPSSVC.EXE (Lenovo Group Limited)
SRV - (IviRegMgr) -- C:\Programme\Gemeinsame Dateien\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
SRV - (IDriverT) -- C:\Programme\Gemeinsame Dateien\Installshield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (MDM) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (ZDPSp50) -- System32\Drivers\ZDPSp50.sys File not found
DRV - (ZDCndis5) -- C:\WINDOWS\system32\ZDCndis5.SYS File not found
DRV - (WDICA) -- File not found
DRV - (UsbserFilt) -- system32\DRIVERS\usbser_lowerfltj.sys File not found
DRV - (upperdev) -- system32\DRIVERS\usbser_lowerflt.sys File not found
DRV - (UIUSys) -- system32\DRIVERS\UIUSYS.SYS File not found
DRV - (TVTPktFilter) -- system32\DRIVERS\tvtpktfilter.sys File not found
DRV - (Sony_EricssonWWSC) -- system32\DRIVERS\seu4scard.sys File not found
DRV - (SEMCReserved) -- system32\DRIVERS\semcreserved.sys File not found
DRV - (sembwwan) -- system32\DRIVERS\sembwwan.sys File not found
DRV - (sembunic) -- system32\DRIVERS\sembunic.sys File not found
DRV - (sembnd5) -- system32\DRIVERS\sembnd5.sys File not found
DRV - (sembmgmt) -- system32\DRIVERS\sembmgmt.sys File not found
DRV - (sembmdm2) -- system32\DRIVERS\sembmdm2.sys File not found
DRV - (sembmdfl2) -- system32\DRIVERS\sembmdfl2.sys File not found
DRV - (sembcard) -- system32\DRIVERS\sembcard.sys File not found
DRV - (sembbus) -- system32\DRIVERS\sembbus.sys File not found
DRV - (RimUsb) -- System32\Drivers\RimUsb.sys File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (pccsmcfd) -- system32\DRIVERS\pccsmcfd.sys File not found
DRV - (PCANDIS5) -- C:\WINDOWS\system32\PCANDIS5.SYS File not found
DRV - (nmwcdnsuc) -- system32\drivers\nmwcdnsuc.sys File not found
DRV - (nmwcdnsu) -- system32\drivers\nmwcdnsu.sys File not found
DRV - (nmwcdc) -- system32\drivers\ccdcmbo.sys File not found
DRV - (nmwcd) -- system32\drivers\ccdcmb.sys File not found
DRV - (lbrtfdc) -- File not found
DRV - (HPFXFAX) -- system32\drivers\hpfxfax.sys File not found
DRV - (HPFXBULK) -- system32\drivers\hpfxbulk.sys File not found
DRV - (cpuz132) -- C:\DOKUME~1\GEORGL~1\LOKALE~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (Changer) -- File not found
DRV - (catchme) -- C:\ComboFix\catchme.sys File not found
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (avkmgr) -- C:\WINDOWS\system32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (teamviewervpn) -- C:\WINDOWS\system32\drivers\teamviewervpn.sys (TeamViewer GmbH)
DRV - (bfturboh) -- C:\WINDOWS\system32\drivers\bfturboh.sys (BUFFALO INC.)
DRV - (TPPWRIF) -- C:\WINDOWS\system32\drivers\TPPWRIF.SYS ()
DRV - (TSMAPIP) -- C:\WINDOWS\system32\drivers\TSMAPIP.SYS ()
DRV - (Shockprf) -- C:\WINDOWS\system32\drivers\ApsX86.sys (Lenovo.)
DRV - (TPDIGIMN) -- C:\WINDOWS\system32\drivers\ApsHM86.sys (Lenovo.)
DRV - (rimmptsk) -- C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) -- C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) -- C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (TVTI2C) -- C:\WINDOWS\system32\drivers\tvti2c.sys (Lenovo (United States) Inc.)
DRV - (psadd) -- C:\WINDOWS\system32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (NETw4x32) -- C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (hwdatacard) -- C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (LUsbFilt) -- C:\WINDOWS\system32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouFilt) -- C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (IBMTPCHK) -- C:\WINDOWS\system32\drivers\IBMBLDID.sys ()
DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (smihlp) -- C:\Programme\Gemeinsame Dateien\ThinkVantage Fingerprint Software\Drivers\smihlp.sys (UPEK Inc.)
DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (btaudio) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (HSF_DPV) -- C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (btwhid) -- C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (PROCDD) -- C:\WINDOWS\system32\drivers\PROCDD.SYS (Lenovo Group Limited)
DRV - (BTWDNDIS) -- C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (BTDriver) -- C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (DLAUDFAM) -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) -- C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (ANC) -- C:\WINDOWS\system32\drivers\ANC.sys (IBM Corp.)
DRV - (ElgTaDrv) -- C:\WINDOWS\system32\drivers\ElgTaDrv.sys (elmeg Kommunikationstechnik)
DRV - (G400) -- C:\WINDOWS\system32\drivers\G400m.sys (Matrox Graphics Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7NDKB_deDE544
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.115.1:3128
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-500\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo.live.com
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-500\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&entrypoint={referrer:source?}&FORM=LENIE
IE - HKU\S-1-5-21-3317598621-2374655837-956553009-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://fritz.box/"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.5.0.8013
FF - prefs.js..network.proxy.ftp: "192.168.115.1"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.gopher: "192.168.115.1"
FF - prefs.js..network.proxy.gopher_port: 3128
FF - prefs.js..network.proxy.http: "192.168.115.1"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "192.168.115.1"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "192.168.115.1"
FF - prefs.js..network.proxy.ssl_port: 3128
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Programme\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Programme\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Programme\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Programme\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2013.07.12 13:29:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2013.07.12 13:32:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins [2013.07.12 13:05:05 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{FCF36B88-1BBA-487f-B64B-D2E8980A9293}: C:\Programme\Lenovo\Client Security Solution\PWM Firefox Extension [2009.04.09 18:45:16 | 000,000,000 | ---D | M]
[2008.10.18 18:00:31 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Mozilla\Extensions
[2008.10.11 21:29:07 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Mozilla\Extensions\home2@tomtom.com
[2012.11.22 15:53:31 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Mozilla\Firefox\Profiles\vsaunozd.default\extensions
[2010.05.10 17:10:18 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Mozilla\Firefox\Profiles\vsaunozd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013.07.12 13:29:39 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\browser\extensions
[2013.07.12 13:29:39 | 000,000,000 | ---D | M] (Default) -- C:\Programme\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ==========
CHR - homepage: hxxp://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: hxxp://www.google.com/
CHR - Extension: YouTube = C:\Dokumente und Einstellungen\***** *******\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Dokumente und Einstellungen\***** *******\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Google Mail = C:\Dokumente und Einstellungen\***** *******\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2013.07.11 15:34:31 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (CPwmIEBrowserHelper Object) - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Programme\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Oracle Corporation)
O4 - HKU\S-1-5-21-3317598621-2374655837-956553009-500..\RunOnce: [NeroHomeFirstStart] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMFirstStart.exe (Nero AG)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 4
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-3317598621-2374655837-956553009-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3317598621-2374655837-956553009-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3317598621-2374655837-956553009-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: An vorhandenes PDF anfügen - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: In Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Senden an &Bluetooth-Gerät... - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra 'Tools' menuitem : ThinkVantage Password Manager... - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Programme\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} hxxp://picasaweb.google.com/s/v/36.18/uploader2.cab (UploadListView Class)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab (DLM Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1343646464212 (MUWebControl Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF947584-005E-4C3A-AC5E-431956F7877B}: DhcpNameServer = 10.0.1.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\psfus: DllName - (C:\WINDOWS\system32\psqlpwd.dll) - C:\WINDOWS\system32\psqlpwd.dll (UPEK Inc.)
O20 - Winlogon\Notify\tpfnf2: DllName - (C:\Programme\Lenovo\HOTKEY\notifyf2.dll) - C:\Programme\Lenovo\HOTKEY\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - (C:\Programme\Lenovo\HOTKEY\tphklock.dll) - C:\Programme\Lenovo\HOTKEY\tphklock.dll ()
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\1680_1050 Think EMEA Map.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\1680_1050 Think EMEA Map.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.01.27 04:18:40 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.07.12 14:18:52 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\HitmanPro
[2013.07.12 14:18:31 | 009,171,472 | ---- | C] (SurfRight B.V.) -- C:\Dokumente und Einstellungen\***** *******\Desktop\HitmanPro.exe
[2013.07.12 13:46:45 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***** *******\Lokale Einstellungen\Anwendungsdaten\Sun
[2013.07.12 13:35:49 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\***** *******\Recent
[2013.07.12 13:29:42 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Maintenance Service
[2013.07.12 13:29:42 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Mozilla
[2013.07.12 13:27:31 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Sun
[2013.07.12 13:27:30 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Java
[2013.07.12 13:09:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\TeamViewer 8 Host
[2013.07.12 12:58:12 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Google Chrome
[2013.07.12 12:38:41 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2013.07.11 17:05:58 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Malwarebytes
[2013.07.11 17:05:22 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2013.07.11 17:05:22 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2013.07.11 17:05:21 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2013.07.11 17:05:21 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2013.07.11 17:04:21 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Dokumente und Einstellungen\***** *******\Desktop\mbam-setup-1.75.0.1300.exe
[2013.07.11 15:30:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2013.07.11 15:24:01 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013.07.11 14:25:17 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2013.07.11 14:23:00 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2013.07.11 14:23:00 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2013.07.11 14:23:00 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2013.07.11 14:23:00 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2013.07.11 14:22:49 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.07.11 14:22:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2013.07.11 14:07:41 | 005,087,643 | R--- | C] (Swearware) -- C:\Dokumente und Einstellungen\***** *******\Desktop\ComboFix.exe
[2013.07.11 12:53:48 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\***** *******\Desktop\tdsskiller.exe
[2013.07.11 12:28:49 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.07.10 14:03:32 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\***** *******\Desktop\OTL.exe
[2013.07.10 13:38:46 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Avira
[2013.07.09 18:35:18 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Mozilla
[2013.07.09 18:35:17 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\Mozilla
[2009.06.27 11:09:46 | 003,252,640 | ---- | C] (Piriform Ltd) -- C:\Programme\ccsetup221.exe
[2009.06.22 11:56:41 | 000,112,984 | ---- | C] (Elmeg GmbH & Co. KG) -- C:\Programme\elgtaldr.sys
[2009.06.22 11:56:41 | 000,072,704 | ---- | C] (Funkwerk Enterprise Communications) -- C:\Programme\elgtadrv.sys
[2009.06.22 11:56:41 | 000,038,263 | ---- | C] (Elmeg Kommunikationstechnik) -- C:\Programme\elgusb.sys
[2009.06.22 11:56:41 | 000,027,264 | ---- | C] (Microsoft Corporation) -- C:\Programme\rndismpm.sys
[2009.06.22 11:56:41 | 000,027,264 | ---- | C] (Microsoft Corporation) -- C:\Programme\rndismpk.sys
[2009.06.22 11:56:41 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Programme\rndismpw.sys
[2009.06.22 11:56:41 | 000,026,880 | ---- | C] (Microsoft Corporation) -- C:\Programme\rndismp.sys
[2009.06.22 11:56:41 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Programme\usb8023w.sys
[2009.06.22 11:56:41 | 000,011,136 | ---- | C] (Microsoft Corporation) -- C:\Programme\usb8023m.sys
[2009.06.22 11:56:41 | 000,011,136 | ---- | C] (Microsoft Corporation) -- C:\Programme\usb8023k.sys
[2009.06.22 11:56:41 | 000,011,136 | ---- | C] (Microsoft Corporation) -- C:\Programme\usb8023.sys
[2009.05.22 23:52:56 | 001,976,104 | ---- | C] (Skype Technologies S.A.) -- C:\Programme\SkypeSetup.exe
[2009.04.11 20:23:32 | 001,867,776 | ---- | C] (Python Software Foundation) -- C:\Programme\python24.dll
[2009.04.11 20:23:32 | 001,093,632 | ---- | C] (FreeImage) -- C:\Programme\FreeImage.dll
[2009.04.11 20:23:32 | 000,499,712 | ---- | C] (Microsoft Corporation) -- C:\Programme\msvcp71.dll
[2009.04.11 20:23:32 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Programme\msvcr71.dll
[2009.04.11 20:23:32 | 000,258,352 | ---- | C] (Microsoft Corporation) -- C:\Programme\unicows.dll
[2009.04.11 20:23:31 | 000,072,400 | ---- | C] (Microsoft Corporation) -- C:\Programme\DSETUP.dll
[2009.04.11 20:23:25 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Programme\d3dx9_36.dll
[2009.04.11 20:23:25 | 003,031,040 | ---- | C] (NEOACT) -- C:\Programme\carom.exe
[2009.04.11 20:23:25 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Programme\d3dx9_26.dll
[2009.04.11 20:23:25 | 001,683,456 | ---- | C] (NVIDIA Corporation) -- C:\Programme\cg.dll
[2009.02.11 11:27:13 | 013,084,392 | ---- | C] (SolidWorks Corporation ) -- C:\Programme\eDrawingsGerman.exe
========== Files - Modified Within 30 Days ==========
[2013.07.12 14:53:00 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{984E94B7-1E5B-4293-A0EF-52136B1743FE}.job
[2013.07.12 14:35:10 | 000,051,712 | ---- | M] () -- C:\WINDOWS\CC3216AC.exe
[2013.07.12 14:35:10 | 000,000,522 | ---- | M] () -- C:\WINDOWS\CC3216AC.dat
[2013.07.12 14:33:04 | 000,051,712 | ---- | M] () -- C:\WINDOWS\CC3216AB.exe
[2013.07.12 14:33:04 | 000,000,522 | ---- | M] () -- C:\WINDOWS\CC3216AB.dat
[2013.07.12 14:32:34 | 000,051,712 | ---- | M] () -- C:\WINDOWS\CC3216AA.exe
[2013.07.12 14:32:34 | 000,000,522 | ---- | M] () -- C:\WINDOWS\CC3216AA.dat
[2013.07.12 14:23:15 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013.07.12 14:18:37 | 009,171,472 | ---- | M] (SurfRight B.V.) -- C:\Dokumente und Einstellungen\***** *******\Desktop\HitmanPro.exe
[2013.07.12 14:07:00 | 000,001,104 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013.07.12 14:04:05 | 000,025,261 | ---- | M] () -- C:\WINDOWS\System32\PROCDB.INI
[2013.07.12 14:03:47 | 000,029,911 | ---- | M] () -- C:\WINDOWS\System32\nvwsapps.xml
[2013.07.12 14:03:46 | 000,179,177 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
[2013.07.12 14:02:02 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013.07.12 14:02:01 | 000,001,100 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013.07.12 14:01:11 | 000,000,380 | ---- | M] () -- C:\WINDOWS\System32\IPSCtrl.INI
[2013.07.12 14:00:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.07.12 14:00:55 | 3202,658,304 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.12 13:45:07 | 000,662,345 | ---- | M] () -- C:\Dokumente und Einstellungen\***** *******\Desktop\adwcleaner.exe
[2013.07.12 13:32:43 | 000,001,639 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Thunderbird.lnk
[2013.07.12 13:29:43 | 000,000,703 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2013.07.12 13:09:44 | 000,000,794 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\TeamViewer 8 Host.lnk
[2013.07.12 13:05:05 | 000,001,721 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader XI.lnk
[2013.07.12 12:58:12 | 000,001,784 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Google Chrome.lnk
[2013.07.12 03:40:42 | 001,801,216 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013.07.12 03:19:40 | 000,488,260 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2013.07.12 03:19:40 | 000,444,902 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013.07.12 03:19:40 | 000,096,086 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2013.07.12 03:19:40 | 000,072,778 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013.07.11 17:39:00 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013.07.11 17:05:23 | 000,000,763 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013.07.11 17:04:27 | 010,285,040 | ---- | M] (Malwarebytes Corporation ) -- C:\Dokumente und Einstellungen\***** *******\Desktop\mbam-setup-1.75.0.1300.exe
[2013.07.11 15:34:31 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2013.07.11 14:25:22 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2013.07.11 14:07:47 | 005,087,643 | R--- | M] (Swearware) -- C:\Dokumente und Einstellungen\***** *******\Desktop\ComboFix.exe
[2013.07.11 12:53:55 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\***** *******\Desktop\tdsskiller.exe
[2013.07.10 14:03:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\***** *******\Desktop\OTL.exe
[2013.07.10 11:23:05 | 002,092,792 | ---- | M] () -- C:\Dokumente und Einstellungen\***** *******\Eigene Dateien\avira_free_antivirus.exe
[2013.07.10 10:35:57 | 000,000,316 | ---- | M] () -- C:\WINDOWS\tasks\PMTask.job
[2013.07.09 17:49:15 | 000,179,177 | ---- | M] () -- C:\WINDOWS\System32\nvModes.dat
[2013.07.09 17:27:41 | 001,963,614 | ---- | M] () -- C:\Dokumente und Einstellungen\***** *******\Eigene Dateien\cc_20130709_172609.reg
[2013.06.20 12:33:57 | 000,040,448 | ---- | M] () -- C:\Dokumente und Einstellungen\***** *******\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== Files Created - No Company Name ==========
[2013.07.12 14:35:10 | 000,051,712 | ---- | C] () -- C:\WINDOWS\CC3216AC.exe
[2013.07.12 14:35:10 | 000,000,522 | ---- | C] () -- C:\WINDOWS\CC3216AC.dat
[2013.07.12 14:33:04 | 000,051,712 | ---- | C] () -- C:\WINDOWS\CC3216AB.exe
[2013.07.12 14:33:04 | 000,000,522 | ---- | C] () -- C:\WINDOWS\CC3216AB.dat
[2013.07.12 14:32:34 | 000,051,712 | ---- | C] () -- C:\WINDOWS\CC3216AA.exe
[2013.07.12 14:32:34 | 000,000,522 | ---- | C] () -- C:\WINDOWS\CC3216AA.dat
[2013.07.12 13:44:57 | 000,662,345 | ---- | C] () -- C:\Dokumente und Einstellungen\***** *******\Desktop\adwcleaner.exe
[2013.07.12 13:32:43 | 000,001,645 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Mozilla Thunderbird.lnk
[2013.07.12 13:32:43 | 000,001,639 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Thunderbird.lnk
[2013.07.12 13:29:43 | 000,000,709 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Mozilla Firefox.lnk
[2013.07.12 13:29:43 | 000,000,703 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2013.07.12 13:09:44 | 000,000,794 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\TeamViewer 8 Host.lnk
[2013.07.12 13:05:05 | 000,001,804 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Adobe Reader XI.lnk
[2013.07.12 13:05:05 | 000,001,721 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader XI.lnk
[2013.07.12 12:58:12 | 000,001,784 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Google Chrome.lnk
[2013.07.12 12:56:10 | 000,000,884 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013.07.11 17:05:23 | 000,000,763 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013.07.11 14:25:22 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2013.07.11 14:25:18 | 000,262,448 | RHS- | C] () -- C:\cmldr
[2013.07.11 14:23:00 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2013.07.11 14:23:00 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2013.07.11 14:23:00 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2013.07.11 14:23:00 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2013.07.11 14:23:00 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2013.07.10 11:23:04 | 002,092,792 | ---- | C] () -- C:\Dokumente und Einstellungen\***** *******\Eigene Dateien\avira_free_antivirus.exe
[2013.07.10 11:02:46 | 3202,658,304 | -HS- | C] () -- C:\hiberfil.sys
[2013.07.09 17:27:16 | 001,963,614 | ---- | C] () -- C:\Dokumente und Einstellungen\***** *******\Eigene Dateien\cc_20130709_172609.reg
[2013.02.14 11:44:17 | 000,051,712 | ---- | C] () -- C:\WINDOWS\CC3216KR.exe
[2013.01.11 13:02:48 | 000,051,712 | ---- | C] () -- C:\WINDOWS\CC3216KO.exe
[2012.11.22 13:22:42 | 000,051,712 | ---- | C] () -- C:\WINDOWS\CC3216KL.exe
[2012.11.16 18:02:40 | 000,051,712 | ---- | C] () -- C:\WINDOWS\CC3216KI.exe
[2012.10.01 18:30:56 | 000,051,712 | ---- | C] () -- C:\WINDOWS\CC3216KF.exe
[2012.06.25 16:07:13 | 000,051,712 | ---- | C] () -- C:\WINDOWS\CC3216KC.exe
[2012.04.20 13:39:14 | 000,051,712 | ---- | C] () -- C:\WINDOWS\CC3216JZ.exe
[2012.03.15 15:08:02 | 000,051,712 | ---- | C] () -- C:\WINDOWS\CC3216JW.exe
[2012.02.16 20:51:21 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011.12.20 17:45:21 | 000,051,712 | ---- | C] () -- C:\WINDOWS\CC3216JS.exe
[2011.11.11 16:17:34 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\FileOps.exe
[2011.11.04 16:48:31 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\***** *******\Ÿ9Ÿ9
[2011.09.06 12:54:55 | 000,051,712 | ---- | C] () -- C:\WINDOWS\CC3216JM.exe
[2011.08.09 14:13:16 | 000,051,712 | ---- | C] () -- C:\WINDOWS\CC3216JI.exe
[2010.09.06 22:39:09 | 000,000,074 | ---- | C] () -- C:\Dokumente und Einstellungen\***** *******\default.pls
[2009.08.27 12:57:40 | 000,000,256 | ---- | C] () -- C:\Dokumente und Einstellungen\***** *******\pool.bin
[2009.08.01 19:11:51 | 000,038,470 | ---- | C] () -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Microsoft Excel.ADR
[2009.06.22 11:56:41 | 000,006,608 | ---- | C] () -- C:\Programme\FecTxxx.inf
[2009.06.22 11:56:41 | 000,005,591 | ---- | C] () -- C:\Programme\fecusb.inf
[2009.06.22 11:56:41 | 000,005,497 | ---- | C] () -- C:\Programme\elmegnet.inf
[2009.06.22 11:56:41 | 000,003,275 | ---- | C] () -- C:\Programme\elgusb.inf
[2009.06.19 15:38:46 | 000,700,784 | ---- | C] () -- C:\Programme\GoogleCalendarSync_Installer.exe
[2009.04.11 20:23:32 | 002,702,848 | ---- | C] () -- C:\Programme\OgreMain.dll
[2009.04.11 20:23:32 | 000,364,544 | ---- | C] () -- C:\Programme\OgrePlatform.dll
[2009.04.11 20:23:32 | 000,327,680 | ---- | C] () -- C:\Programme\RenderSystem_Direct3D9.dll
[2009.04.11 20:23:32 | 000,097,792 | ---- | C] () -- C:\Programme\Plugin_ParticleFX.dll
[2009.04.11 20:23:32 | 000,061,440 | ---- | C] () -- C:\Programme\ILU.dll
[2009.04.11 20:23:32 | 000,055,808 | ---- | C] () -- C:\Programme\zlib1.dll
[2009.04.11 20:23:32 | 000,036,864 | ---- | C] () -- C:\Programme\Plugin_CgProgramManager.dll
[2009.04.11 20:23:32 | 000,000,176 | ---- | C] () -- C:\Programme\[Ogre]Plugins.cfg
[2009.04.11 20:23:32 | 000,000,043 | ---- | C] () -- C:\Programme\[Ogre]ogre.cfg
[2009.04.11 20:23:31 | 000,757,760 | ---- | C] () -- C:\Programme\DevIL.dll
[2009.04.11 20:23:31 | 000,193,158 | ---- | C] () -- C:\Programme\end.dle
[2008.11.19 08:06:05 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\$_hpcst$.hpc
[2008.06.24 16:23:10 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\***** *******\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2008.06.24 11:58:25 | 000,040,448 | ---- | C] () -- C:\Dokumente und Einstellungen\***** *******\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.06.24 11:55:45 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\$_hpcst$.hpc
========== ZeroAccess Check ==========
[2006.01.27 19:19:56 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 04:22:25 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.02.09 12:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008.04.14 04:22:32 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2008.06.24 16:55:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Lenovo
[2008.07.29 23:15:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avery
[2010.08.29 12:27:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\BDNM
[2008.09.27 15:23:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\BIFAB
[2008.08.22 15:58:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\BTrieve
[2013.07.12 14:26:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\HitmanPro
[2010.10.23 23:20:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Installations
[2010.05.27 15:58:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Lenovo
[2008.08.22 15:58:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Lexware
[2010.02.23 21:58:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MSScanAppDataDir
[2008.12.16 20:17:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Nokia
[2010.03.04 23:36:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\OviInstallerCache
[2010.05.23 12:00:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Drivers HeadQuarters
[2008.12.16 15:12:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Suite
[2009.01.26 19:59:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PixelPlanet
[2009.06.08 23:22:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\RosettaStoneLtdServices
[2009.12.12 22:43:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Save Data
[2008.10.11 21:29:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TomTom
[2008.05.21 22:50:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\UIB
[2009.04.02 09:38:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2008.05.21 22:58:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[2010.04.10 11:25:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009.11.03 11:55:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009.04.29 17:34:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008.06.24 16:55:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Default User\Anwendungsdaten\Lenovo
[2008.08.07 11:22:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\artec technologies ag
[2008.08.31 15:39:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\DataDesign
[2008.06.24 12:31:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Destinator
[2008.06.24 23:48:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Leadertech
[2010.05.27 15:58:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Lenovo
[2008.08.22 15:59:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Lexware
[2010.07.21 19:46:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\mresreg
[2010.03.05 00:04:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Nokia
[2010.03.05 00:04:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Nokia Ovi Suite
[2009.07.20 22:27:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\PC Suite
[2009.10.10 15:48:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\ProtectDisc
[2008.08.22 20:11:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\SAD
[2010.02.01 21:41:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Serif
[2010.05.27 16:16:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\TeamViewer
[2013.07.12 13:32:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Thunderbird
[2010.12.14 00:03:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\TomTom
[2008.12.15 17:40:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Windows Desktop Search
[2008.12.15 17:53:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***** *******\Anwendungsdaten\Windows Search
[2009.08.26 23:33:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\TeamViewer
[2008.06.24 16:55:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\TEMP\Anwendungsdaten\Lenovo
[2008.06.24 16:55:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\TEMP.LENOVO-66E55E6C\Anwendungsdaten\Lenovo
[2008.06.24 16:55:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\TEMP.LENOVO-66E55E6C.000\Anwendungsdaten\Lenovo
[2008.06.24 16:55:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\TEMP.LENOVO-66E55E6C.001\Anwendungsdaten\Lenovo
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*. >
[2009.04.02 06:37:36 | 000,000,000 | ---D | M] -- C:\4423e9c29b2997e022c28e6ee1
[2013.07.11 14:25:22 | 000,000,000 | RHSD | M] -- C:\cmdcons
[2013.07.11 15:41:43 | 000,000,000 | ---D | M] -- C:\ComboFix
[2013.07.12 13:57:12 | 000,000,000 | ---D | M] -- C:\Config.Msi
[2010.08.18 23:13:07 | 000,000,000 | ---D | M] -- C:\Daten Firma
[2010.11.14 16:50:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen
[2009.07.06 08:26:52 | 000,000,000 | ---D | M] -- C:\drivers
[2008.06.24 16:24:28 | 000,000,000 | ---D | M] -- C:\I386
[2009.02.02 18:32:24 | 000,000,000 | ---D | M] -- C:\Icons
[2012.10.24 12:31:17 | 000,000,000 | ---D | M] -- C:\Install
[2008.08.07 11:22:00 | 000,000,000 | ---D | M] -- C:\LiveViewer
[2013.06.07 11:49:59 | 000,000,000 | ---D | M] -- C:\MEGACAM
[2008.05.21 23:03:58 | 000,000,000 | ---D | M] -- C:\MFGFLOW
[2008.08.05 14:35:04 | 000,000,000 | R--D | M] -- C:\MINSTALL.T
[2008.06.24 11:17:24 | 000,000,000 | R--D | M] -- C:\MSOCache
[2011.01.21 11:44:02 | 000,000,000 | ---D | M] -- C:\My_Outlook_Files
[2009.02.02 18:32:26 | 000,000,000 | ---D | M] -- C:\Norton Commander
[2009.04.11 16:21:04 | 000,000,000 | ---D | M] -- C:\Program Files
[2013.07.12 13:49:25 | 000,000,000 | ---D | M] -- C:\Programme
[2013.07.11 15:41:42 | 000,000,000 | ---D | M] -- C:\Qoobox
[2013.07.12 12:38:41 | 000,000,000 | -HSD | M] -- C:\RECYCLER
[2008.11.20 19:12:03 | 000,000,000 | RHSD | M] -- C:\RRbackups
[2012.07.30 13:12:35 | 000,000,000 | ---D | M] -- C:\spoolerlogs
[2008.05.22 05:57:09 | 000,000,000 | ---D | M] -- C:\SUPPORT
[2013.07.10 17:26:00 | 000,000,000 | ---D | M] -- C:\SWSHARE
[2008.06.24 16:23:21 | 000,000,000 | ---D | M] -- C:\SWTOOLS
[2012.10.24 11:48:21 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2011.11.18 18:49:42 | 000,000,000 | ---D | M] -- C:\TomTom
[2009.06.28 09:45:40 | 000,000,000 | ---D | M] -- C:\VALUEADD
[2009.06.27 22:27:25 | 000,000,000 | ---D | M] -- C:\WBEHRENS
[2013.07.12 14:35:10 | 000,000,000 | ---D | M] -- C:\WINDOWS
[2013.07.11 12:45:45 | 000,000,000 | ---D | M] -- C:\_OTL
< %PROGRAMFILES%\*.exe >
[2009.02.04 13:52:22 | 003,031,040 | ---- | M] (NEOACT) -- C:\Programme\carom.exe
[2009.06.27 11:09:48 | 003,252,640 | ---- | M] (Piriform Ltd) -- C:\Programme\ccsetup221.exe
[2008.03.05 16:34:04 | 013,084,392 | ---- | M] (SolidWorks Corporation ) -- C:\Programme\eDrawingsGerman.exe
[2009.06.22 10:25:36 | 000,700,784 | ---- | M] () -- C:\Programme\GoogleCalendarSync_Installer.exe
[2009.05.22 23:53:02 | 001,976,104 | ---- | M] (Skype Technologies S.A.) -- C:\Programme\SkypeSetup.exe
Invalid Environment Variable: LOCALAPPDATA
< %systemroot%\*. /mp /s >
< C:\Windows\system32\*.tsp >
[2003.11.27 15:27:54 | 000,171,008 | ---- | M] () -- C:\Windows\system32\elalsp32.tsp
[2007.09.03 15:04:10 | 000,393,216 | ---- | M] (Funkwerk Enterprise Communications) -- C:\Windows\system32\fphonesp.TSP
[2008.04.14 04:23:08 | 000,266,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\h323.tsp
[2008.04.14 04:23:08 | 000,029,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp
[2008.04.14 04:23:08 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ipconf.tsp
[2008.04.14 04:23:08 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp
[2008.04.14 04:23:08 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp
[2008.04.14 04:23:08 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp
[2008.04.14 04:23:08 | 000,207,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp
[2006.01.27 03:01:12 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2006.01.27 04:25:59 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2008.05.21 22:22:25 | 000,000,316 | ---- | C] () -- C:\WINDOWS\Tasks\PMTask.job
[2009.06.30 09:19:44 | 000,000,434 | -H-- | C] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{984E94B7-1E5B-4293-A0EF-52136B1743FE}.job
[2009.09.07 16:41:18 | 000,000,276 | ---- | C] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2010.04.05 19:59:36 | 000,001,100 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2010.04.05 19:59:36 | 000,001,104 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2013.07.12 12:56:10 | 000,000,884 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
< MD5 for: AGP440.SYS >
[2004.08.04 14:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\I386\sp2.cab:AGP440.sys
[2004.08.04 14:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.07.24 21:38:22 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.07.24 21:38:22 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\erdnt\cache\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004.08.04 09:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2004.08.04 14:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\I386\sp2.cab:atapi.sys
[2004.08.04 14:00:00 | 018,782,319 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.07.24 21:38:22 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.07.24 21:38:22 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2007.04.03 12:39:42 | 000,096,384 | ---- | M] (Microsoft Corporation) MD5=2218E3FD674DC284CE98C807086CAB14 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\erdnt\cache\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\erdnt\cache\eventlog.dll
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\system32\eventlog.dll
[2007.03.14 22:20:18 | 000,033,280 | ---- | M] (UPEK Inc.) MD5=683FB3F8B7B40317BE7362CF86BFA998 -- C:\Programme\ThinkVantage Fingerprint Software\eventlog.dll
[2004.08.04 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2004.08.04 14:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=22FE1BE02EADDE1632E478E4125639E0 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007.06.13 15:10:08 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=331ED93570BAF3CFE30340298762CD56 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2008.04.14 04:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E -- C:\WINDOWS\erdnt\cache\explorer.exe
[2008.04.14 04:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E -- C:\WINDOWS\explorer.exe
[2008.04.14 04:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007.06.13 15:21:45 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=64D320C0E301EEDC5A4ADBBDC5024F7F -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: IASTOR.SYS >
[2007.02.12 06:36:54 | 000,277,784 | ---- | M] (Intel Corporation) MD5=FD7F9D74C2B35DBDA400804A3F5ED5D8 -- C:\drivers\other\iastor.sys
[2007.02.12 06:36:54 | 000,277,784 | ---- | M] (Intel Corporation) MD5=FD7F9D74C2B35DBDA400804A3F5ED5D8 -- C:\SWTOOLS\DRIVERS\IMSM\iastor.sys
[2007.02.12 19:36:54 | 000,277,784 | ---- | M] (Intel Corporation) MD5=FD7F9D74C2B35DBDA400804A3F5ED5D8 -- C:\WINDOWS\system32\drivers\iaStor.sys
< MD5 for: NETLOGON.DLL >
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\erdnt\cache\netlogon.dll
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\system32\netlogon.dll
[2004.08.04 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\erdnt\cache\scecli.dll
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\system32\scecli.dll
[2004.08.04 14:00:00 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
< MD5 for: USER32.DLL >
[2005.03.02 20:09:46 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=3751D7CF0E0A113D84414992146BCE6A -- C:\I386\user32.dll
[2005.03.02 19:09:46 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=3751D7CF0E0A113D84414992146BCE6A -- C:\WINDOWS\$NtUninstallKB890859$\user32.dll
[2005.03.02 20:19:56 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
[2005.03.02 20:19:56 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS\$NtUninstallKB925902$\user32.dll
[2007.03.08 17:48:39 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=78785EFF8CB90CEC1862A4CCFD9A3C3A -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\erdnt\cache\user32.dll
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll
< MD5 for: USERINIT.EXE >
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\erdnt\cache\userinit.exe
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\system32\userinit.exe
[2004.08.04 14:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: WINLOGON.EXE >
[2005.04.01 20:33:14 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=B0B3908F5432F9DBBCD83CA4C33F0D82 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2013.04.04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Programme\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\erdnt\cache\winlogon.exe
[2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2IFSL.SYS >
[2004.08.04 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2006.01.26 20:08:21 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2006.01.26 20:08:21 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2006.01.26 20:08:20 | 000,417,792 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
< %USERPROFILE%\*.* >
[2011.10.28 16:36:33 | 000,000,074 | ---- | M] () -- C:\Dokumente und Einstellungen\***** *******\default.pls
[2013.07.12 14:00:05 | 013,631,488 | -H-- | M] () -- C:\Dokumente und Einstellungen\***** *******\NTUSER.DAT
[2013.07.12 14:57:26 | 000,001,024 | -H-- | M] () -- C:\Dokumente und Einstellungen\***** *******\ntuser.dat.LOG
[2013.07.12 13:59:47 | 000,000,300 | -HS- | M] () -- C:\Dokumente und Einstellungen\***** *******\ntuser.ini
[2009.08.27 12:57:40 | 000,000,256 | ---- | M] () -- C:\Dokumente und Einstellungen\***** *******\pool.bin
[2011.11.04 16:48:31 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\***** *******\Ÿ9Ÿ9
< %USERPROFILE%\Local Settings\Temp\*.exe >
< %USERPROFILE%\Local Settings\Temp\*.dll >
< %USERPROFILE%\Application Data\*.exe >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Kmode: %SystemRoot%\system32\win32k.sys [2013.06.05 11:08:28 | 001,876,864 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
< >
< End of report > --- --- --- |