Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Allgemeine Fragen... (https://www.trojaner-board.de/97094-allgemeine-fragen.html)

gpa123 03.04.2011 16:40

Allgemeine Fragen...
 
Liste der Anhänge anzeigen (Anzahl: 1)
Hallo,

was das Thema PC angeht bin ich nicht so geschult und habe einige Fragen bezüglich mir unbekannten Sachen.

Da wäre z.B. 1. das beim Start meines Computers immer 2 Fenster auftauchen, Fehler und Windows-Sicherheit. (siehe Anhang)...wie bekomme ich das weg?

2. Bei verschiedenen Programmen ist es so, wenn ich sie minimiere, werden sie nicht wie normalerweise in der Taskleiste abgelegt sondern verschwinden regelrecht. Laufen aber trotzdem noch!...Warum passiert sowas?

3. Taskmanager --> Prozesse Kmymia.exe...was ist das?

cosinus 03.04.2011 17:32

Du hast wahrscheinlich "Gäste" im System. Auf dem Screenshot sieht man Malwarebytes, poste alle Logs davon, die im Reiter Logdateien sichtbar sind.

gpa123 03.04.2011 17:43

Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes

Datenbank Version: 6255

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

03.04.2011 16:58:40
mbam-log-2011-04-03 (16-58-40).txt

Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 163152
Laufzeit: 6 Minute(n), 39 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 3
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 4

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runAPI45 (Backdoor.Agent) -> Value: runAPI45 -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\Windows\System32\winrssrvh.dll (Heuristics.Shuriken) -> Quarantined and deleted successfully.
c:\Users\Gpa\AppData\Roaming\data.dat (Stolen.Data) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully.

cosinus 03.04.2011 17:50

Zitat:

Art des Suchlaufs: Quick-Scan

Bitte routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!

gpa123 03.04.2011 19:21

Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes

Datenbank Version: 6256

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

03.04.2011 20:19:45
mbam-log-2011-04-03 (20-19-38).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Durchsuchte Objekte: 382966
Laufzeit: 1 Stunde(n), 23 Minute(n), 1 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 1
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 2

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> No action taken.

Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> No action taken.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> No action taken.
c:\Windows.old\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> No action taken.

cosinus 03.04.2011 19:40

Warum entfernst du die Funde nicht?

gpa123 03.04.2011 19:46

Ja hab ich, nur erst gerade eben ^_^

cosinus 03.04.2011 19:54

Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.

gpa123 03.04.2011 20:11

OTL Logfile:
Code:

OTL logfile created on: 4/3/2011 8:56:57 PM - Run 1
OTL by OldTimer - Version 3.2.22.3    Folder = C:\Users\Gpa\Downloads
 Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy
 
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 55.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.38 Gb Total Space | 21.99 Gb Free Space | 29.57% Space Free | Partition Type: NTFS
Drive E: | 232.88 Gb Total Space | 152.79 Gb Free Space | 65.61% Space Free | Partition Type: NTFS
 
Computer Name: HORST | User Name: Gpa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Gpa\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\Kmymia.exe ()
PRC - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.)
PRC - C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Programme\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Programme\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
PRC - C:\Programme\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corp.)
PRC - C:\Programme\Windows Media Player\wmplayer.exe (Microsoft Corporation)
PRC - C:\Programme\ICQ6Toolbar\ICQ Service.exe ()
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Gpa\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (TeamViewer6) -- C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (Application Updater) -- C:\Program Files\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (ICQ Service) -- C:\Programme\ICQ6Toolbar\ICQ Service.exe ()
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (truecrypt) -- C:\Windows\System32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (vmbus) -- C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (e1kexpress) Intel(R) -- C:\Windows\System32\drivers\e1k6032.sys (Intel Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
 
FF - user.js..browser.search.selectedEngine: "Google"
FF - user.js..browser.search.order.1: "Google"
FF - user.js..browser.search.defaultenginename: "Google"
FF - user.js..keyword.URL: "hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q="
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/03/28 21:30:03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/03/28 21:30:03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/28 21:36:29 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/03 17:42:32 | 000,000,000 | ---D | M]
 
[2011/03/29 22:15:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gpa\AppData\Roaming\mozilla\Extensions
[2011/03/28 21:47:36 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011/03/28 21:43:31 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/03/28 21:40:50 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) --
[2011/03/28 21:47:35 | 000,000,000 | ---D | M] (Widgi Toolbar Platform) -- C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM
[2011/03/28 21:43:31 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/03/28 21:40:50 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/03/28 21:47:36 | 000,000,000 | ---D | M] (pdfforge Toolbar) -- C:\PROGRAM FILES\PDFFORGE TOOLBAR\FF
[2011/03/18 19:56:37 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Programme\Mozilla Firefox\components\browsercomps.dll
[2011/01/25 11:55:14 | 000,644,096 | ---- | M] (Synatix GmbH) -- C:\Programme\Mozilla Firefox\Plugins\npmieze.dll
[2010/01/01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010/01/01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\bing.xml
[2010/01/01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2011/04/03 17:42:32 | 000,000,140 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\Google.src
[2010/01/01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010/01/01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010/01/01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009/06/10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Gutscheinmieze) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - C:\Users\Gpa\AppData\Roaming\Gutscheinmieze\toolbar.dll (Synatix GmbH)
O3 - HKCU\..\Toolbar\WebBrowser: (Gutscheinmieze) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - C:\Users\Gpa\AppData\Roaming\Gutscheinmieze\toolbar.dll (Synatix GmbH)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.4\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [IKXGVMFZHI]  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Free YouTube Download - C:\Users\Gpa\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Gpa\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Programme\ICQ7.4\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - Unable to obtain root file information for disk E:\
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011/04/03 17:51:04 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\{295F13A8-D99B-480E-A9C5-C21F05C0784E}
[2011/04/03 17:46:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\appmgmt
[2011/04/03 17:42:26 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Gutscheinmieze
[2011/04/03 16:48:00 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Malwarebytes
[2011/04/03 16:47:53 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/04/03 16:47:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/03 16:47:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/04/03 16:47:50 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/04/03 16:47:49 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2011/04/03 16:30:24 | 000,000,000 | ---D | C] -- C:\Programme\Trend Micro
[2011/04/03 16:30:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis
[2011/04/03 11:55:43 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Xfire
[2011/04/03 11:55:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xfire
[2011/04/03 11:55:40 | 000,000,000 | ---D | C] -- C:\Users\Gpa\Xfire
[2011/04/03 11:55:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Xfire
[2011/04/03 01:08:44 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2011/04/03 00:20:05 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Avira
[2011/04/03 00:05:23 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\gctmp
[2011/04/03 00:05:22 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Xenocode
[2011/04/02 23:28:16 | 000,000,000 | ---D | C] -- C:\ProgramData\NFS Underground
[2011/04/02 22:30:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
[2011/04/02 11:36:38 | 000,000,000 | ---D | C] -- C:\Users\Gpa\Documents\ICQ
[2011/03/31 23:25:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
[2011/03/31 23:25:15 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Blizzard Entertainment
[2011/03/31 23:24:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment
[2011/03/31 23:18:15 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\WinRAR
[2011/03/31 23:17:49 | 000,000,000 | ---D | C] -- C:\plugins
[2011/03/31 20:18:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/03/31 18:25:03 | 000,000,000 | ---D | C] -- C:\Windows\de
[2011/03/31 18:16:16 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft SQL Server Compact Edition
[2011/03/31 18:15:10 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2011/03/31 18:14:07 | 000,000,000 | ---D | C] -- C:\Programme\Windows Live
[2011/03/31 18:10:49 | 002,983,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbon.dll
[2011/03/31 18:10:49 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbonRes.dll
[2011/03/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Windows Live
[2011/03/30 15:52:32 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Adobe
[2011/03/29 22:15:16 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Mozilla
[2011/03/29 22:15:16 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Mozilla
[2011/03/29 19:05:42 | 000,000,000 | ---D | C] -- C:\Programme\Pidgin
[2011/03/29 16:40:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Google
[2011/03/29 16:39:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google SketchUp 8
[2011/03/29 16:39:04 | 000,000,000 | ---D | C] -- C:\Programme\Google
[2011/03/29 14:03:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/03/29 14:03:53 | 000,000,000 | ---D | C] -- C:\Programme\WinRAR
[2011/03/29 05:07:36 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2011/03/29 04:50:11 | 000,000,000 | ---D | C] -- C:\Windows.old
[2011/03/29 04:12:30 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2011/03/29 04:10:04 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2011/03/28 22:15:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
[2011/03/28 22:04:56 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\.minecraft
[2011/03/28 21:53:45 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_43.dll
[2011/03/28 21:53:45 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll
[2011/03/28 21:53:45 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll
[2011/03/28 21:53:45 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll
[2011/03/28 21:53:45 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll
[2011/03/28 21:53:45 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll
[2011/03/28 21:53:45 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll
[2011/03/28 21:53:44 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll
[2011/03/28 21:53:44 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_6.dll
[2011/03/28 21:53:44 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_4.dll
[2011/03/28 21:53:43 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_6.dll
[2011/03/28 21:53:43 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_7.dll
[2011/03/28 21:53:42 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2011/03/28 21:53:42 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2011/03/28 21:53:42 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2011/03/28 21:53:42 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2011/03/28 21:53:41 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_41.dll
[2011/03/28 21:53:41 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2011/03/28 21:53:41 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_41.dll
[2011/03/28 21:53:41 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2011/03/28 21:53:41 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_41.dll
[2011/03/28 21:53:41 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2011/03/28 21:53:40 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_4.dll
[2011/03/28 21:53:40 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2011/03/28 21:53:39 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_40.dll
[2011/03/28 21:53:39 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_4.dll
[2011/03/28 21:53:39 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_6.dll
[2011/03/28 21:53:38 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_40.dll
[2011/03/28 21:53:38 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2011/03/28 21:53:38 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2011/03/28 21:53:37 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2011/03/28 21:53:37 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll
[2011/03/28 21:53:37 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2011/03/28 21:53:36 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll
[2011/03/28 21:53:36 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll
[2011/03/28 21:53:36 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll
[2011/03/28 21:53:36 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_1.dll
[2011/03/28 21:53:36 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll
[2011/03/28 21:53:36 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll
[2011/03/28 21:53:36 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_0.dll
[2011/03/28 21:53:35 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_38.dll
[2011/03/28 21:53:35 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_38.dll
[2011/03/28 21:53:35 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_0.dll
[2011/03/28 21:53:35 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_38.dll
[2011/03/28 21:53:35 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_1.dll
[2011/03/28 21:53:35 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_4.dll
[2011/03/28 21:53:34 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_0.dll
[2011/03/28 21:53:33 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_37.dll
[2011/03/28 21:53:33 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_37.dll
[2011/03/28 21:53:33 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_36.dll
[2011/03/28 21:53:33 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_37.dll
[2011/03/28 21:53:33 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_36.dll
[2011/03/28 21:53:33 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_10.dll
[2011/03/28 21:53:33 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_3.dll
[2011/03/28 21:53:32 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_36.dll
[2011/03/28 21:53:32 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_9.dll
[2011/03/28 21:53:31 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_35.dll
[2011/03/28 21:53:31 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_34.dll
[2011/03/28 21:53:31 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_35.dll
[2011/03/28 21:53:31 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_34.dll
[2011/03/28 21:53:31 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_35.dll
[2011/03/28 21:53:31 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_34.dll
[2011/03/28 21:53:31 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_8.dll
[2011/03/28 21:53:31 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_3.dll
[2011/03/28 21:53:31 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_2.dll
[2011/03/28 21:53:30 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_33.dll
[2011/03/28 21:53:30 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_33.dll
[2011/03/28 21:53:30 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_33.dll
[2011/03/28 21:53:30 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_7.dll
[2011/03/28 21:53:29 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_6.dll
[2011/03/28 21:53:29 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_5.dll
[2011/03/28 21:53:28 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_32.dll
[2011/03/28 21:53:28 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_31.dll
[2011/03/28 21:53:28 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10.dll
[2011/03/28 21:53:28 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_4.dll
[2011/03/28 21:53:28 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_1.dll
[2011/03/28 21:53:27 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_3.dll
[2011/03/28 21:53:27 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_2.dll
[2011/03/28 21:53:26 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_2.dll
[2011/03/28 21:53:26 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_1.dll
[2011/03/28 21:53:25 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_1.dll
[2011/03/28 21:53:18 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_30.dll
[2011/03/28 21:53:18 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_0.dll
[2011/03/28 21:53:18 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_0.dll
[2011/03/28 21:53:17 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_29.dll
[2011/03/28 21:53:17 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_28.dll
[2011/03/28 21:53:17 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_27.dll
[2011/03/28 21:53:17 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_26.dll
[2011/03/28 21:53:16 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_25.dll
[2011/03/28 21:53:16 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_24.dll
[2011/03/28 21:51:22 | 000,034,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lhacm.acm
[2011/03/28 21:51:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Teamspeak2 RC2
[2011/03/28 21:51:19 | 000,000,000 | ---D | C] -- C:\Programme\Teamspeak2_RC2
[2011/03/28 21:50:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
[2011/03/28 21:50:17 | 000,000,000 | ---D | C] -- C:\Programme\TeamSpeak 3 Client
[2011/03/28 21:49:17 | 000,231,248 | ---- | C] (TrueCrypt Foundation) -- C:\Windows\System32\drivers\truecrypt.sys
[2011/03/28 21:49:08 | 000,000,000 | ---D | C] -- C:\Programme\TrueCrypt
[2011/03/28 21:48:22 | 000,000,000 | ---D | C] -- C:\Programme\TeamViewer
[2011/03/28 21:47:35 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Spigot
[2011/03/28 21:47:35 | 000,000,000 | ---D | C] -- C:\Programme\pdfforge Toolbar
[2011/03/28 21:47:35 | 000,000,000 | ---D | C] -- C:\Programme\Application Updater
[2011/03/28 21:47:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
[2011/03/28 21:47:12 | 000,137,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSMAPI32.OCX
[2011/03/28 21:47:10 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCMCDE.DLL
[2011/03/28 21:47:10 | 000,125,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6DE.DLL
[2011/03/28 21:47:10 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCC2DE.DLL
[2011/03/28 21:47:10 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSMPIDE.DLL
[2011/03/28 21:47:10 | 000,000,000 | ---D | C] -- C:\Programme\PDFCreator
[2011/03/28 21:45:59 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.3
[2011/03/28 21:44:09 | 000,000,000 | ---D | C] -- C:\Programme\OpenOffice.org 3
[2011/03/28 21:43:31 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011/03/28 21:43:31 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011/03/28 21:43:31 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011/03/28 21:41:37 | 000,000,000 | ---D | C] -- C:\Programme\Miranda IM
[2011/03/28 21:41:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2011/03/28 21:41:05 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Java
[2011/03/28 21:40:49 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2011/03/28 21:40:38 | 000,000,000 | ---D | C] -- C:\Programme\Java
[2011/03/28 21:38:29 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Apple Computer
[2011/03/28 21:38:29 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Apple Computer
[2011/03/28 21:38:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/03/28 21:38:05 | 000,107,368 | ---- | C] (GEAR Software Inc.) -- C:\Windows\System32\GEARAspi.dll
[2011/03/28 21:38:05 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2011/03/28 21:37:36 | 000,000,000 | ---D | C] -- C:\Programme\iPod
[2011/03/28 21:37:35 | 000,000,000 | ---D | C] -- C:\Programme\iTunes
[2011/03/28 21:37:35 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/03/28 21:36:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/03/28 21:36:21 | 000,000,000 | ---D | C] -- C:\Programme\QuickTime
[2011/03/28 21:36:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2011/03/28 21:36:14 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Apple
[2011/03/28 21:36:13 | 000,000,000 | ---D | C] -- C:\Programme\Apple Software Update
[2011/03/28 21:35:56 | 000,000,000 | ---D | C] -- C:\Programme\Bonjour
[2011/03/28 21:35:51 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Apple
[2011/03/28 21:35:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2011/03/28 21:34:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICQ7.4
[2011/03/28 21:34:42 | 000,000,000 | ---D | C] -- C:\Programme\ICQ6Toolbar
[2011/03/28 21:34:42 | 000,000,000 | ---D | C] -- C:\ProgramData\ICQ
[2011/03/28 21:34:41 | 000,000,000 | -H-D | C] -- C:\Programme\InstallShield Installation Information
[2011/03/28 21:34:31 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\ICQ
[2011/03/28 21:34:27 | 000,000,000 | ---D | C] -- C:\Programme\ICQ7.4
[2011/03/28 21:33:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP
[2011/03/28 21:33:17 | 000,000,000 | ---D | C] -- C:\Programme\GIMP-2.0
[2011/03/28 21:32:17 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/03/28 21:32:17 | 000,000,000 | ---D | C] -- C:\Users\Gpa\Documents\DVDVideoSoft
[2011/03/28 21:32:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
[2011/03/28 21:32:11 | 000,000,000 | ---D | C] -- C:\Programme\DVDVideoSoft
[2011/03/28 21:32:11 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\DVDVideoSoft
[2011/03/28 21:31:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2011/03/28 21:31:05 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox
[2011/03/28 21:31:01 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\DDMSettings
[2011/03/28 21:29:47 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\DivX
[2011/03/28 21:29:38 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\PX Storage Engine
[2011/03/28 21:29:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus
[2011/03/28 21:29:16 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\DivX Shared
[2011/03/28 21:27:15 | 000,000,000 | ---D | C] -- C:\Programme\DivX
[2011/03/28 21:26:30 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[2011/03/28 21:26:05 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner
[2011/03/28 21:23:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011/03/28 21:23:08 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2011/03/28 21:23:07 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011/03/28 21:23:07 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011/03/28 21:23:07 | 000,000,000 | ---D | C] -- C:\Programme\Avira
[2011/03/28 21:23:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011/03/28 21:16:29 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Adobe
[2011/03/28 21:16:29 | 000,000,000 | ---D | C] -- C:\Programme\Adobe
[2011/03/28 21:15:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2011/03/28 21:07:30 | 000,000,000 | ---D | C] -- C:\Windows\de-DE
[2011/03/28 21:07:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\XPSViewer
[2011/03/28 21:07:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\de-DE
[2011/03/28 21:07:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\de
[2011/03/28 21:07:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\0407
[2011/03/28 21:02:19 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\volsnap.sys.mui
[2011/03/28 21:02:19 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\usbport.sys.mui
[2011/03/28 21:02:19 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\vhdmp.sys.mui
[2011/03/28 21:02:19 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\portcls.sys.mui
[2011/03/28 21:02:19 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\wd.sys.mui
[2011/03/28 21:02:18 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\usbhub.sys.mui
[2011/03/28 21:02:18 | 000,004,096 | ---- | C] (SCM Microsystems, Inc.) -- C:\Windows\System32\drivers\de-DE\pscr.sys.mui
[2011/03/28 21:02:18 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\tpm.sys.mui
[2011/03/28 21:02:18 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\umbus.sys.mui
[2011/03/28 21:02:18 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\serscan.sys.mui
[2011/03/28 21:02:14 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\pcmcia.sys.mui
[2011/03/28 21:02:14 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\vwifibus.sys.mui
[2011/03/28 21:02:13 | 000,033,280 | ---- | C] (Marvell) -- C:\Windows\System32\drivers\de-DE\yk62x86.sys.mui
[2011/03/28 21:02:13 | 000,013,312 | ---- | C] (Broadcom Corporation) -- C:\Windows\System32\drivers\de-DE\k57nd60x.sys.mui
[2011/03/28 21:02:13 | 000,003,072 | ---- | C] (VIA Technologies, Inc.              ) -- C:\Windows\System32\drivers\de-DE\getn62.sys.mui
[2011/03/28 21:02:13 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\rndismpx.sys.mui
[2011/03/28 21:02:13 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\rndismp6.sys.mui
[2011/03/28 21:02:12 | 000,025,088 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e1y6032.sys.mui
[2011/03/28 21:02:12 | 000,025,088 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e1e6032.sys.mui
[2011/03/28 21:02:12 | 000,022,016 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\E1G60I32.sys.mui
[2011/03/28 21:02:12 | 000,013,312 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e1q6032.sys.mui
[2011/03/28 21:02:12 | 000,013,312 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e1k6032.sys.mui
[2011/03/28 21:02:12 | 000,013,312 | ---- | C] (Broadcom Corporation) -- C:\Windows\System32\drivers\de-DE\b57nd60x.sys.mui
[2011/03/28 21:02:12 | 000,006,144 | ---- | C] (Broadcom Corporation) -- C:\Windows\System32\drivers\de-DE\bcm4sbxp.sys.mui
[2011/03/28 21:02:12 | 000,005,120 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e100b325.sys.mui
[2011/03/28 21:02:10 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\serial.sys.mui
[2011/03/28 21:02:10 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\sermouse.sys.mui
[2011/03/28 21:02:10 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mouclass.sys.mui
[2011/03/28 21:02:10 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\parport.sys.mui
[2011/03/28 21:02:10 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\parvdm.sys.mui
[2011/03/28 21:02:10 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mouhid.sys.mui
[2011/03/28 21:02:10 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\MTConfig.sys.mui
[2011/03/28 21:02:09 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\i8042prt.sys.mui
[2011/03/28 21:02:09 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\msdsm.sys.mui
[2011/03/28 21:02:09 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ataport.sys.mui
[2011/03/28 21:02:09 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\amdide.sys.mui
[2011/03/28 21:02:08 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mpio.sys.mui
[2011/03/28 21:02:08 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\scsiport.sys.mui
[2011/03/28 21:02:06 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\afd.sys.mui
[2011/03/28 21:02:04 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\tcpip.sys.mui
[2011/03/28 21:02:04 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\bfe.dll.mui
[2011/03/28 21:02:04 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\tunnel.sys.mui
[2011/03/28 21:02:04 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\modem.sys.mui
[2011/03/28 21:02:04 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\wdf01000.sys.mui
[2011/03/28 21:02:04 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ws2ifsl.sys.mui
[2011/03/28 21:02:04 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\usbrpm.sys.mui
[2011/03/28 21:02:02 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\fvevol.sys.mui
[2011/03/28 21:02:02 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\srv.sys.mui
[2011/03/28 21:02:02 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\scfilter.sys.mui
[2011/03/28 21:01:59 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\pacer.sys.mui
[2011/03/28 21:01:59 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\rdbss.sys.mui
[2011/03/28 21:01:59 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\RNDISMP.sys.mui
[2011/03/28 21:01:59 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\qwavedrv.sys.mui
[2011/03/28 21:01:59 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\partmgr.sys.mui
[2011/03/28 21:01:55 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ntfs.sys.mui
[2011/03/28 21:01:55 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\nwifi.sys.mui
[2011/03/28 21:01:54 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ndis.sys.mui
[2011/03/28 21:01:54 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ndisuio.sys.mui
[2011/03/28 21:01:51 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ndiscap.sys.mui
[2011/03/28 21:01:49 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mountmgr.sys.mui
[2011/03/28 21:01:48 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\luafv.sys.mui
[2011/03/28 21:01:48 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ipnat.sys.mui
[2011/03/28 21:01:47 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\http.sys.mui
[2011/03/28 21:01:44 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\fltmgr.sys.mui
[2011/03/28 21:01:42 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\volmgrx.sys.mui
[2011/03/28 21:01:36 | 000,011,776 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\de-DE\BrSerIb.sys.mui
[2011/03/28 21:01:36 | 000,010,752 | ---- | C] (Agere Systems) -- C:\Windows\System32\drivers\de-DE\ltmdmnt.sys.mui
[2011/03/28 21:01:36 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\pci.sys.mui
[2011/03/28 21:01:36 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\IPMIDrv.sys.mui
[2011/03/28 21:01:36 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\kbdclass.sys.mui
[2011/03/28 21:01:36 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\vdrvroot.sys.mui
[2011/03/28 21:01:36 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\isapnp.sys.mui
[2011/03/28 21:01:36 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mssmbios.sys.mui
[2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\VIAAGP.SYS.mui
[2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ULIAGPKX.SYS.mui
[2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\SISAGP.SYS.mui
[2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\pnpmem.sys.mui
[2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\NV_AGP.SYS.mui
[2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\kbdhid.sys.mui
[2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\AMDAGP.SYS.mui
[2011/03/28 21:01:36 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\AGP440.sys.mui
[2011/03/28 21:01:35 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\viac7.sys.mui
[2011/03/28 21:01:35 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\processr.sys.mui
[2011/03/28 21:01:35 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\intelppm.sys.mui
[2011/03/28 21:01:35 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\amdppm.sys.mui
[2011/03/28 21:01:35 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\amdk8.sys.mui
[2011/03/28 21:01:35 | 000,011,776 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\de-DE\BrSerId.sys.mui
[2011/03/28 21:01:35 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\battc.sys.mui
[2011/03/28 21:01:35 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\bthport.sys.mui
[2011/03/28 21:01:35 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\bthpan.sys.mui
[2011/03/28 21:01:35 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\wacompen.sys.mui
[2011/03/28 21:01:35 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\hdaudbus.sys.mui
[2011/03/28 21:01:35 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\HdAudio.sys.mui
[2011/03/28 21:01:35 | 000,003,584 | ---- | C] (ATI Technologies Inc.) -- C:\Windows\System32\drivers\de-DE\atikmdag.sys.mui
[2011/03/28 21:01:35 | 000,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\hidbth.sys.mui
[2011/03/28 21:01:35 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\UAGP35.SYS.mui
[2011/03/28 21:01:35 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\GAGP30KX.SYS.mui
[2011/03/28 21:01:35 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\Dot4usb.sys.mui
[2011/03/28 21:01:35 | 000,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\BTHUSB.SYS.mui
[2011/03/28 21:01:35 | 000,002,560 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\de-DE\BrParwdm.sys.mui
[2011/03/28 21:01:35 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\disk.sys.mui
[2011/03/28 21:01:35 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\cdrom.sys.mui
[2011/03/28 21:01:35 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\bthenum.sys.mui
[2011/03/28 21:01:34 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ohci1394.sys.mui
[2011/03/28 21:01:34 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\1394ohci.sys.mui
[2011/03/28 21:01:34 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\acpi.sys.mui
[2011/03/28 20:50:49 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft.NET
[2011/03/28 20:19:48 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2011/03/28 20:19:48 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2011/03/28 20:19:48 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll
[2011/03/28 20:13:07 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browserchoice.exe
[2011/03/28 20:11:55 | 000,222,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2011/03/28 20:11:42 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ks.sys
[2011/03/28 20:10:31 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2011/03/28 20:10:31 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011/03/28 20:10:31 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2011/03/28 20:10:31 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2011/03/28 20:10:30 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2011/03/28 20:10:30 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2011/03/28 20:10:29 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011/03/28 20:10:29 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2011/03/28 20:10:29 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2011/03/28 20:10:18 | 001,320,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertEnroll.dll
[2011/03/28 20:10:18 | 000,507,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winload.exe
[2011/03/28 20:10:18 | 000,442,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winresume.exe
[2011/03/28 20:10:15 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbc32.dll
[2011/03/28 20:10:06 | 000,294,400 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2011/03/28 20:10:06 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2011/03/28 20:10:06 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2011/03/28 20:10:02 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40.dll
[2011/03/28 20:10:02 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc40u.dll
[2011/03/28 20:09:58 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2011/03/28 20:09:58 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdri.dll
[2011/03/28 20:09:58 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2011/03/28 20:09:45 | 001,037,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lsasrv.dll
[2011/03/28 20:09:42 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2011/03/28 20:09:41 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2011/03/28 20:09:39 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2011/03/28 20:09:38 | 000,850,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
[2011/03/28 20:09:38 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2011/03/28 20:09:38 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2011/03/28 20:09:29 | 000,496,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskschd.dll
[2011/03/28 20:09:29 | 000,351,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmicmiplugin.dll
[2011/03/28 20:09:29 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskcomp.dll
[2011/03/28 20:09:29 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\schtasks.exe
[2011/03/28 20:09:25 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2011/03/28 20:09:25 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2011/03/28 20:09:22 | 002,329,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011/03/28 20:09:17 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL
[2011/03/28 20:09:16 | 001,328,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2011/03/28 20:09:16 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\avifil32.dll
[2011/03/28 20:09:16 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciavi32.dll
[2011/03/28 20:09:12 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2011/03/28 20:09:03 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll
[2011/03/28 20:09:00 | 000,197,632 | ---- | C] (Intel(R) Corporation) -- C:\Windows\System32\ir32_32.dll
[2011/03/28 20:09:00 | 000,082,944 | ---- | C] (Radius Inc.) -- C:\Windows\System32\iccvid.dll
[2011/03/28 20:08:58 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rtutils.dll
[2011/03/28 20:08:45 | 001,170,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2011/03/28 20:08:44 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
[2011/03/28 20:08:44 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
[2011/03/28 20:08:44 | 001,074,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2011/03/28 20:08:44 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2011/03/28 20:08:43 | 001,495,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ExplorerFrame.dll
[2011/03/28 20:08:43 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2011/03/28 20:08:43 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
[2011/03/28 20:08:43 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2011/03/28 20:08:43 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
[2011/03/28 20:08:38 | 002,614,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2011/03/28 20:08:37 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\asycfilt.dll
[2011/03/28 20:08:36 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll
[2011/03/28 20:08:34 | 000,026,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Diskdump.sys
[2011/03/28 20:08:20 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\upnp.dll
[2011/03/28 20:08:19 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011/03/28 20:08:19 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\davclnt.dll
[2011/03/28 20:08:19 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wscapi.dll
[2011/03/28 20:08:19 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011/03/28 20:08:19 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\slwga.dll
[2011/03/28 20:08:16 | 003,957,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2011/03/28 20:08:16 | 003,901,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2011/03/28 20:08:15 | 000,369,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc.dll
[2011/03/28 20:08:15 | 000,365,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_isv.dll
[2011/03/28 20:08:15 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_isv.exe
[2011/03/28 20:08:15 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate.exe
[2011/03/28 20:08:15 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp.exe
[2011/03/28 20:08:15 | 000,277,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp_isv.exe
[2011/03/28 20:08:15 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp_isv.dll
[2011/03/28 20:08:15 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp.dll
[2011/03/28 20:08:14 | 000,101,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\consent.exe
[2011/03/28 20:08:12 | 000,738,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpmde.dll
[2011/03/28 20:01:54 | 000,219,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys
[2011/03/28 20:01:54 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2011/03/28 19:51:23 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\vlc
[2011/03/28 19:51:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/03/28 19:50:44 | 000,000,000 | ---D | C] -- C:\Programme\VideoLAN
[2011/03/28 19:45:55 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Macromedia
[2011/03/28 19:45:55 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Adobe
[2011/03/28 19:44:15 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/03/28 19:42:38 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Google
[2011/03/28 19:42:12 | 000,000,000 | ---D | C] -- C:\Programme\Intel
[2011/03/28 19:37:33 | 000,000,000 | ---D | C] -- C:\Windows\System32\vmm32
[2011/03/28 19:37:33 | 000,000,000 | ---D | C] -- C:\Programme\Dell
[2011/03/28 19:37:05 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2011/03/28 19:34:16 | 000,000,000 | R--D | C] -- C:\Users\Gpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/03/28 19:34:16 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Searches
[2011/03/28 19:34:16 | 000,000,000 | R--D | C] -- C:\Users\Gpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/03/28 19:34:16 | 000,000,000 | -H-D | C] -- C:\Users\Gpa\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/03/28 19:34:04 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Identities
[2011/03/28 19:33:59 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Contacts
[2011/03/28 19:33:39 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\VirtualStore
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\AppData\Local\Temporary Internet Files
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Templates
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Start Menu
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\SendTo
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Recent
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\PrintHood
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\NetHood
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Documents\My Videos
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Documents\My Pictures
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Documents\My Music
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\My Documents
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Local Settings
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\AppData\Local\History
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Cookies
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\Application Data
[2011/03/28 19:33:36 | 000,000,000 | -HSD | C] -- C:\Users\Gpa\AppData\Local\Application Data
[2011/03/28 19:33:35 | 000,000,000 | --SD | C] -- C:\Users\Gpa\AppData\Roaming\Microsoft
[2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Videos
[2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Saved Games
[2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Pictures
[2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Music
[2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Links
[2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Favorites
[2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Downloads
[2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Documents
[2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\Desktop
[2011/03/28 19:33:35 | 000,000,000 | R--D | C] -- C:\Users\Gpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/03/28 19:33:35 | 000,000,000 | -H-D | C] -- C:\Users\Gpa\AppData
[2011/03/28 19:33:35 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Temp
[2011/03/28 19:33:35 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\Microsoft
[2011/03/28 19:33:35 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Media Center Programs
[2011/03/28 19:32:14 | 000,000,000 | -HSD | C] -- C:\Recovery
[2011/03/27 02:31:17 | 000,000,000 | -HSD | C] -- C:\Boot
[2011/03/26 19:55:05 | 000,000,000 | ---D | C] -- C:\Intel
[2011/03/26 18:57:59 | 000,000,000 | ---D | C] -- C:\dell
[2011/03/26 17:50:34 | 000,000,000 | -HSD | C] -- C:\Programme
[2011/03/26 17:50:34 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2011/03/26 17:32:18 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2010/08/25 18:59:08 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
 
========== Files - Modified Within 30 Days ==========
 
[2011/04/03 20:47:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1001UA.job
[2011/04/03 20:31:10 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/03 20:31:10 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/03 20:24:12 | 000,000,242 | -H-- | M] () -- C:\Windows\tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job
[2011/04/03 20:24:04 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/03 20:24:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1003UA.job
[2011/04/03 20:23:52 | 000,000,306 | -HS- | M] () -- C:\Windows\tasks\SQBLFMXO.job
[2011/04/03 20:23:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/04/03 20:23:36 | 1556,828,160 | -HS- | M] () -- C:\hiberfil.sys
[2011/04/03 20:22:01 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/03 19:47:01 | 000,001,058 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1001Core.job
[2011/04/03 17:30:52 | 000,289,938 | ---- | M] () -- C:\Users\Gpa\Desktop\Unbenannt.jpg
[2011/04/03 16:47:54 | 000,001,063 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/03 16:30:24 | 000,002,035 | ---- | M] () -- C:\Users\Gpa\Desktop\HijackThis.lnk
[2011/04/03 11:55:41 | 000,000,781 | ---- | M] () -- C:\Users\Public\Desktop\Xfire.lnk
[2011/04/03 00:24:00 | 000,001,058 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1003Core.job
[2011/04/03 00:17:04 | 000,163,328 | ---- | M] () -- C:\Windows\Kmymia.exe
[2011/04/02 22:30:25 | 000,000,757 | ---- | M] () -- C:\Users\Gpa\Desktop\GTA San Andreas.lnk
[2011/04/01 16:52:17 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/03/31 23:49:49 | 000,007,168 | ---- | M] () -- C:\Users\Gpa\AppData\Roaming\clean2.exe
[2011/03/31 23:27:41 | 000,000,809 | ---- | M] () -- C:\Users\Public\Desktop\World of Warcraft.lnk
[2011/03/31 23:18:38 | 000,000,000 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\short.zip
[2011/03/31 23:18:37 | 000,000,000 | ---- | M] () -- C:\h.zip
[2011/03/30 15:55:35 | 000,348,685 | ---- | M] () -- C:\Users\Gpa\Desktop\Auftragsbestaetigung_186068.pdf
[2011/03/30 15:53:43 | 000,011,801 | ---- | M] () -- C:\Users\Gpa\Desktop\__www.handytick.de_konto_auftrag_pdf_186068_Auftragsbestaetigung_186068.pdf
[2011/03/29 12:10:01 | 000,653,928 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011/03/29 12:10:01 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/03/29 12:10:01 | 000,129,800 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011/03/29 12:10:01 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/03/29 12:05:31 | 000,292,696 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/03/29 05:07:31 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2011/03/29 04:13:57 | 000,042,045 | ---- | M] () -- C:\Windows\System32\license.rtf
[2011/03/28 22:15:03 | 000,000,991 | ---- | M] () -- C:\Users\Gpa\Desktop\Minecraft.lnk
[2011/03/28 21:54:47 | 000,000,509 | ---- | M] () -- C:\Users\Gpa\Desktop\Lokaler Datenträger (E).lnk
[2011/03/28 21:51:22 | 000,034,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\lhacm.acm
[2011/03/28 21:49:17 | 000,231,248 | ---- | M] (TrueCrypt Foundation) -- C:\Windows\System32\drivers\truecrypt.sys
[2011/03/28 21:40:40 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011/03/28 21:40:40 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011/03/28 21:40:40 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011/03/28 21:40:39 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2011/03/28 21:34:47 | 000,001,790 | ---- | M] () -- C:\Users\Gpa\Application Data\Microsoft\Internet Explorer\Quick Launch\ICQ7.4.lnk
[2011/03/28 21:07:11 | 000,295,922 | ---- | M] () -- C:\Windows\System32\perfi007.dat
[2011/03/28 21:07:11 | 000,038,104 | ---- | M] () -- C:\Windows\System32\perfd007.dat
[2011/03/28 19:46:00 | 000,407,526 | RHS- | M] () -- C:\LKWJR
[2011/03/28 19:46:00 | 000,000,020 | RHS- | M] () -- C:\win7.ld
[2011/03/28 19:38:38 | 000,001,403 | ---- | M] () -- C:\Users\Gpa\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/03/11 13:33:52 | 000,036,352 | ---- | M] () -- C:\Windows\System32\xfcodec.dll
 
========== Files Created - No Company Name ==========
 
[2011/04/03 17:30:51 | 000,289,938 | ---- | C] () -- C:\Users\Gpa\Desktop\Unbenannt.jpg
[2011/04/03 16:47:54 | 000,001,063 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/03 16:30:24 | 000,002,035 | ---- | C] () -- C:\Users\Gpa\Desktop\HijackThis.lnk
[2011/04/03 11:55:41 | 000,000,781 | ---- | C] () -- C:\Users\Public\Desktop\Xfire.lnk
[2011/04/03 00:17:09 | 000,163,328 | ---- | C] () -- C:\Windows\Kmymia.exe
[2011/04/03 00:17:06 | 000,000,242 | -H-- | C] () -- C:\Windows\tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job
[2011/04/03 00:17:03 | 000,000,306 | -HS- | C] () -- C:\Windows\tasks\SQBLFMXO.job
[2011/04/02 22:30:25 | 000,000,757 | ---- | C] () -- C:\Users\Gpa\Desktop\GTA San Andreas.lnk
[2011/04/01 16:52:17 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/03/31 23:49:49 | 000,007,168 | ---- | C] () -- C:\Users\Gpa\AppData\Roaming\clean2.exe
[2011/03/31 23:25:15 | 000,000,809 | ---- | C] () -- C:\Users\Public\Desktop\World of Warcraft.lnk
[2011/03/31 23:18:38 | 000,000,000 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\short.zip
[2011/03/31 23:18:37 | 000,000,000 | ---- | C] () -- C:\h.zip
[2011/03/31 20:17:36 | 000,001,090 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/31 20:17:34 | 000,001,086 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/31 18:21:18 | 000,001,251 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011/03/31 18:16:30 | 000,001,320 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011/03/30 15:55:35 | 000,348,685 | ---- | C] () -- C:\Users\Gpa\Desktop\Auftragsbestaetigung_186068.pdf
[2011/03/30 15:53:43 | 000,011,801 | ---- | C] () -- C:\Users\Gpa\Desktop\__www.handytick.de_konto_auftrag_pdf_186068_Auftragsbestaetigung_186068.pdf
[2011/03/29 19:38:59 | 000,000,991 | ---- | C] () -- C:\Users\Gpa\Desktop\Minecraft.lnk
[2011/03/29 19:05:57 | 000,000,945 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pidgin.lnk
[2011/03/29 04:13:47 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/03/29 04:13:37 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/03/29 04:08:25 | 1556,828,160 | -HS- | C] () -- C:\hiberfil.sys
[2011/03/29 00:19:53 | 000,001,110 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1003UA.job
[2011/03/29 00:19:51 | 000,001,058 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1003Core.job
[2011/03/28 21:54:47 | 000,000,509 | ---- | C] () -- C:\Users\Gpa\Desktop\Lokaler Datenträger (E).lnk
[2011/03/28 21:48:26 | 000,001,128 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 6.lnk
[2011/03/28 21:47:11 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2011/03/28 21:36:14 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/03/28 21:34:47 | 000,001,790 | ---- | C] () -- C:\Users\Gpa\Application Data\Microsoft\Internet Explorer\Quick Launch\ICQ7.4.lnk
[2011/03/28 21:31:06 | 000,001,100 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/03/28 21:17:22 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/03/28 21:08:27 | 000,653,928 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2011/03/28 21:08:27 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2011/03/28 21:08:27 | 000,129,800 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2011/03/28 21:08:27 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2011/03/28 19:46:00 | 000,000,020 | RHS- | C] () -- C:\win7.ld
[2011/03/28 19:45:59 | 000,407,526 | RHS- | C] () -- C:\LKWJR
[2011/03/28 19:42:41 | 000,001,110 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1001UA.job
[2011/03/28 19:42:39 | 000,001,058 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1001Core.job
[2011/03/28 19:38:37 | 000,001,403 | ---- | C] () -- C:\Users\Gpa\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/03/28 19:34:19 | 000,001,409 | ---- | C] () -- C:\Users\Gpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/03/28 19:33:36 | 000,000,290 | ---- | C] () -- C:\Users\Gpa\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/03/28 19:33:36 | 000,000,272 | ---- | C] () -- C:\Users\Gpa\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/03/27 02:31:18 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK
[2011/03/27 02:31:17 | 000,383,562 | RHS- | C] () -- C:\bootmgr
[2011/03/11 13:33:52 | 000,036,352 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
[2010/08/25 19:30:02 | 000,439,308 | ---- | C] () -- C:\Windows\System32\igcompkrng500.bin
[2010/08/25 19:30:00 | 000,982,240 | ---- | C] () -- C:\Windows\System32\igkrng500.bin
[2010/08/25 19:30:00 | 000,092,356 | ---- | C] () -- C:\Windows\System32\igfcg500m.bin
[2010/08/25 18:57:00 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config
[2010/08/25 18:52:00 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll
[2010/08/25 18:52:00 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll
[2009/07/14 06:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 06:33:53 | 000,292,696 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 04:05:48 | 000,615,810 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/14 04:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/14 04:05:48 | 000,106,190 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/14 04:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/14 04:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/14 04:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/14 02:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 01:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/07/14 00:09:19 | 000,139,824 | ---- | C] () -- C:\Windows\System32\igfcg500.bin
[2009/06/10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat

< End of report >

--- --- ---

cosinus 04.04.2011 08:27

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
PRC - C:\Windows\Kmymia.exe ()
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Programme\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Gutscheinmieze) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - C:\Users\Gpa\AppData\Roaming\Gutscheinmieze\toolbar.dll (Synatix GmbH)
O3 - HKCU\..\Toolbar\WebBrowser: (Gutscheinmieze) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - C:\Users\Gpa\AppData\Roaming\Gutscheinmieze\toolbar.dll (Synatix GmbH)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKCU..\Run: [IKXGVMFZHI]  File not found
[2011/04/03 17:51:04 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\{295F13A8-D99B-480E-A9C5-C21F05C0784E}
[2011/04/03 17:42:26 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Roaming\Gutscheinmieze
[2011/04/03 00:05:23 | 000,000,000 | ---D | C] -- C:\Users\Gpa\AppData\Local\gctmp
[2011/03/28 21:37:35 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
:Files
C:\Windows\tasks\*.job
C:\Windows\Kmymia.exe
C:\Users\Gpa\AppData\Roaming\clean2.exe
C:\h.zip
:Commands
[purity]
[resethosts]
[emptytemp]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

gpa123 04.04.2011 12:57

Als ich den Fix ausgeführt habe wurden automatisch alle Programme geschlossen bzw. es war nur noch der Bildschirm zu sehen, keine Taskleiste etc. Ist/war das normal? Es hat sich kein Logfile geöffnet!

cosinus 04.04.2011 13:04

Ja das ist durchaus normal. Starte Windows neu und schau mal in den Ordner C:\_OTL - da sollte das Fixlog zu sehen sein.

gpa123 04.04.2011 13:11

All processes killed
========== OTL ==========
No active process named Kmymia.exe was found!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ deleted successfully.
C:\Programme\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ deleted successfully.
C:\Programme\ICQ6Toolbar\ICQToolBar.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{B922D405-6D13-4A2B-AE89-08A030DA4402} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ not found.
File C:\Programme\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27}\ deleted successfully.
C:\Users\Gpa\AppData\Roaming\Gutscheinmieze\toolbar.dll moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27}\ not found.
File C:\Users\Gpa\AppData\Roaming\Gutscheinmieze\toolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings deleted successfully.
C:\Programme\Common Files\Spigot\Search Settings\SearchSettings.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\IKXGVMFZHI deleted successfully.
C:\Users\Gpa\AppData\Local\{295F13A8-D99B-480E-A9C5-C21F05C0784E} folder moved successfully.
C:\Users\Gpa\AppData\Roaming\Gutscheinmieze folder moved successfully.
C:\Users\Gpa\AppData\Local\gctmp folder moved successfully.
C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\x86 folder moved successfully.
C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86 folder moved successfully.
C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521} folder moved successfully.
========== FILES ==========
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1001Core.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1001UA.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1003Core.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3113050104-23283863-569165781-1003UA.job moved successfully.
C:\Windows\tasks\SQBLFMXO.job moved successfully.
C:\Windows\tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job moved successfully.
C:\Windows\Kmymia.exe moved successfully.
C:\Users\Gpa\AppData\Roaming\clean2.exe moved successfully.
C:\h.zip moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Gpa
->Temp folder emptied: 2101308 bytes
->Temporary Internet Files folder emptied: 42235887 bytes
->Java cache emptied: 1864694 bytes
->FireFox cache emptied: 128835662 bytes
->Google Chrome cache emptied: 254435757 bytes
->Flash cache emptied: 4864 bytes

User: psx
->Temp folder emptied: 93720428 bytes
->Temporary Internet Files folder emptied: 52892773 bytes
->Java cache emptied: 604 bytes
->Google Chrome cache emptied: 320866170 bytes
->Flash cache emptied: 7124 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1425 bytes
RecycleBin emptied: 15611664 bytes

Total Files Cleaned = 870.00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 04042011_135002

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

cosinus 04.04.2011 13:19

Ich brauch den Quarantäneordner von OTL. Bitte folgendes machen:

1.) GANZ WICHTIG!! Virenscanner deaktivieren, der darf da nicht rummurksen!
2.) Ordner C:\_OTL in eine Datei zippen
3.) Die erstellte ZIP-Datei hier hochladen => http://www.trojaner-board.de/54791-a...ner-board.html
4.) Wenns erfolgreich war Bescheid sagen
5.) Erst dann wieder den Virenscanner einschalten

gpa123 04.04.2011 13:31

Das zippen funktioniert nicht. Mir wird der Zugriff verweigert.


Alle Zeitangaben in WEZ +1. Es ist jetzt 09:29 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131