Hallo ich habe mir den BKA Virus eingefangen und wollte im abgesichertem Modus eine Systemwiederherstellung machen. Leider ging der abges. Modi nicht, der Rechner hat sich immer automatisch wieder runtergefahren/abgeschaltet.
Ich habe hier von OLPEnet.exe gelesen und das ausprobiert nun brachte er mir folgendes:OTL Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
OTL logfile created on: 1/15/2013 7:57:45 AM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Windows Vista (TM) Home Premium Service Pack 1 (Version = 6.0.6001) - Type = System
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 459.09 Gb Total Space | 154.47 Gb Free Space | 33.65% Space Free | Partition Type: NTFS
Drive D: | 230.54 Gb Total Space | 89.48 Gb Free Space | 38.81% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV - [2012/12/14 02:26:08 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/12/12 04:57:49 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/10/10 15:15:04 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012/10/02 07:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) [Auto] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012/07/13 06:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011/05/29 02:37:34 | 000,040,960 | ---- | M] () [Auto] -- C:\ProgramData\ScanQuery\scanquery133.exe -- (ScanQuery Service)
SRV - [2010/05/04 05:07:22 | 000,503,080 | ---- | M] (Nero AG) [Auto] -- C:\Program Files\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2009/03/31 03:39:36 | 000,233,472 | ---- | M] (Teruten) [Auto] -- C:\Windows\System32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2008/04/07 03:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008/02/29 07:13:12 | 000,307,200 | ---- | M] (Fujitsu Siemens Computers) [Auto] -- C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler)
SRV - [2008/01/20 21:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/06/04 08:20:38 | 000,065,536 | ---- | M] () [Auto] -- C:\Program Files\Fujitsu Siemens Computers\FSCLounge\FSCWBaseUpdaterService\2\FSCWBaseUpdaterService.exe -- (FSCLBaseUpdaterService)
SRV - [2007/03/06 03:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) [Auto] -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (USBModem)
DRV - File not found [Kernel | On_Demand] -- -- (UsbDiag)
DRV - File not found [Kernel | On_Demand] -- -- (usbbus)
DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand] -- -- (IpInIp)
DRV - File not found [Kernel | On_Demand] -- -- (hwusbdev)
DRV - File not found [Kernel | On_Demand] -- -- (hwdatacard)
DRV - [2012/10/10 15:14:28 | 010,837,352 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/03/31 03:39:36 | 000,036,608 | ---- | M] () [Kernel | On_Demand] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009/03/20 04:01:26 | 000,121,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV - [2009/03/20 04:01:26 | 000,090,112 | ---- | M] (MCCI) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM)
DRV - [2009/03/20 04:01:26 | 000,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter)
DRV - [2008/04/03 07:58:46 | 000,076,688 | ---- | M] (JMicron Technology Corp.) [Kernel | Disabled] -- C:\Windows\system32\drivers\jraid.sys -- (JRAID)
DRV - [2008/02/14 08:56:02 | 000,118,784 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2007/12/19 12:45:00 | 000,170,000 | ---- | M] (AMD Technologies Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\ahcix86s.sys -- (ahcix86s)
DRV - [2007/09/17 09:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007/08/21 03:00:22 | 000,873,472 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WlanGZG.sys -- (XG762_VS)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchfunmoods.com/?f=1&a=ironpub&chnl=ironpub&cd=2XzuyEtN2Y1L1QzutDtDtC0DzytBzzzztD0DtAzytC0F0ByEtN0D0Tzu0CtAtCtCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1105187557
IE - HKLM\..\URLSearchHook: {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files\Winload\tbWinl.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\prxtbsof0.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {ce18769b-c7fa-42d2-860d-17c4662c70ad} - C:\Program Files\MyBabylon-English\tbMyBa.dll (Conduit Ltd.)
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Blondy_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchfunmoods.com/?f=1&a=ironpub&chnl=ironpub&cd=2XzuyEtN2Y1L1QzutDtDtC0DzytBzzzztD0DtAzytC0F0ByEtN0D0Tzu0CtAtCtCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1105187557
IE - HKU\Blondy_ON_C\Software\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\Blondy_ON_C\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\Blondy_ON_C\..\URLSearchHook: {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
IE - HKU\Blondy_ON_C\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files\Winload\tbWinl.dll (Conduit Ltd.)
IE - HKU\Blondy_ON_C\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\prxtbsof0.dll (Conduit Ltd.)
IE - HKU\Blondy_ON_C\..\URLSearchHook: {ce18769b-c7fa-42d2-860d-17c4662c70ad} - C:\Program Files\MyBabylon-English\tbMyBa.dll (Conduit Ltd.)
IE - HKU\Blondy_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Blondy_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\NetworkService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..CT2625848.browser.search.defaultthis.engineName: true
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "ST-de3 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2431245&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://searchfunmoods.com/?f=1&a=ironpub&chnl=ironpub&cd=2XzuyEtN2Y1L1QzutDtDtC0DzytBzzzztD0DtAzytC0F0ByEtN0D0Tzu0CtAtCtCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1105187557"
FF - prefs.js..extensions.enabledItems: ffxtlbr@Facemoods.com :1.1.0
FF - prefs.js..extensions.enabledItems: {ce18769b-c7fa-42d2-860d-17c4662c70ad}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: finder@meingutscheincode.de :1.0.2
FF - prefs.js..extensions.enabledItems: {40c3cc16-7269-4b32-9531-17f2950fb06f}:2.7.2.0
FF - prefs.js..extensions.enabledItems: toolbar@ask.com :3.11.3.100013
FF - prefs.js..extensions.enabledItems: engine@conduit.com :3.2.5.2
FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:3.2.5.2
FF - prefs.js..extensions.enabledItems: {DE9265D8-D55D-4286-9DC4-F8D8A0CA2F64}:1.0
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8153
FF - prefs.js..keyword.URL: "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=NRO2&o=15418&locale=de_DE&apn_uid=97F2BA54-59EA-4F35-AD27-3EFB90668674&apn_ptnrs=N9&apn_sauid=66DE45D0-5C4E-492D-BFEA-83EDE8DDEB73&apn_dtid=YYYYYYYYDE&q="
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: ""
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@innoplus.de/ino3DViewer: C:\Program Files\INNOVA-engineering GmbH\3D-Viewer-innoPlus\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\System32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1662: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/11/06 06:17:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}: C:\Program Files\Common Files\DVDVideoSoft\plugins\ff\ [2012/12/05 02:05:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/12/14 02:26:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/12/14 02:26:05 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/12/14 02:26:08 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/12/14 02:26:05 | 000,000,000 | ---D | M]
[2012/11/06 05:43:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Blondy\AppData\Roaming\Mozilla\Extensions
[2013/01/13 12:14:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\extensions
[2010/10/06 00:37:05 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/11/07 02:57:03 | 000,000,000 | ---D | M] (DealPly) -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
[2012/11/06 05:43:54 | 000,000,000 | ---D | M] (Search-Results Toolbar) -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\extensions\{f34c9277-6577-4dff-b2d7-7d58092f272f}
[2012/11/07 02:56:59 | 000,000,000 | ---D | M] (Funmoods.com) -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\extensions\ffxtlbr@funmoods.com
[2012/12/15 11:38:08 | 000,000,000 | ---D | M] (Spartipps von SparPilot.com) -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\extensions\sparpilot@sparpilot.com
[2012/07/02 00:17:51 | 000,000,000 | ---D | M] ("@@toolbarname@@") -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\extensions\toolbar@ask.com
[2012/12/17 03:55:25 | 000,000,911 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\searchplugins\11-suche.xml
[2012/12/13 04:55:13 | 000,002,396 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\searchplugins\askcom.xml
[2010/05/16 12:40:07 | 000,001,819 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\searchplugins\bing.xml
[2012/07/15 11:09:50 | 000,000,915 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\searchplugins\conduit.xml
[2012/12/17 03:55:25 | 000,002,273 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\searchplugins\englische-ergebnisse.xml
[2012/11/07 02:58:26 | 000,009,789 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\searchplugins\Funmoods.xml
[2012/12/17 03:55:25 | 000,010,563 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\searchplugins\gmx-suche.xml
[2013/01/13 12:14:42 | 000,002,251 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\searchplugins\gutscheinsuche.xml
[2012/12/17 03:55:25 | 000,002,432 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\searchplugins\lastminute.xml
[2012/11/06 05:43:52 | 000,002,687 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\searchplugins\Search_Results.xml
[2012/12/12 04:41:11 | 000,003,915 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\searchplugins\sweetim.xml
[2012/12/17 03:55:24 | 000,005,545 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\Mozilla\Firefox\Profiles\g362g0yp.default\searchplugins\webde-suche.xml
[2012/12/14 02:26:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/12/14 02:26:02 | 000,000,000 | ---D | M] (Click to call with Skype) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/12/14 02:26:02 | 000,000,000 | ---D | M] (ScanQuery) -- C:\Program Files\Mozilla Firefox\extensions\{DE9265D8-D55D-4286-9DC4-F8D8A0CA2F64}
File not found (No name found) --
() (No name found) -- C:\USERS\BLONDY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G362G0YP.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}.XPI
() (No name found) -- C:\USERS\BLONDY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G362G0YP.DEFAULT\EXTENSIONS\TOOLBAR@WEB.DE.XPI
[2012/12/14 02:26:08 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/04/12 10:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/08/16 12:40:57 | 000,002,226 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012/10/24 12:50:17 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010/03/28 11:56:18 | 000,002,035 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrchFxt.xml
[2012/10/24 12:50:17 | 000,002,058 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (DVDVideoSoftTB DE Toolbar) - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files\Winload\tbWinl.dll (Conduit Ltd.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.4.8.1\bh\facemoods.dll (facemoods.com BHO)
O2 - BHO: (Funmoods Helper Object) - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\Program Files\Funmoods\1.5.23.22\bh\escort.dll (Funmoods BHO)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (DealPly) - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Program Files\DealPly\DealPlyIE.dll (DealPly Technologies Ltd)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (DataMngr) - {C1ED9DA0-AFD0-4b90-AC6A-D3874F591014} - File not found
O2 - BHO: (ST-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\prxtbsof0.dll (Conduit Ltd.)
O2 - BHO: (MyBabylon-English Toolbar) - {ce18769b-c7fa-42d2-860d-17c4662c70ad} - C:\Program Files\MyBabylon-English\tbMyBa.dll (Conduit Ltd.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O2 - BHO: (Search-Results Toolbar) - {f34c9277-6577-4dff-b2d7-7d58092f272f} - File not found
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB DE Toolbar) - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files\Winload\tbWinl.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (Funmoods Toolbar) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\Program Files\Funmoods\1.5.23.22\escorTlbr.dll (Funmoods)
O3 - HKLM\..\Toolbar: (ST-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\prxtbsof0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (MyBabylon-English Toolbar) - {ce18769b-c7fa-42d2-860d-17c4662c70ad} - C:\Program Files\MyBabylon-English\tbMyBa.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (Search-Results Toolbar) - {f34c9277-6577-4dff-b2d7-7d58092f272f} - File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\Blondy_ON_C\..\Toolbar\WebBrowser: (DVDVideoSoftTB DE Toolbar) - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKU\Blondy_ON_C\..\Toolbar\WebBrowser: (Winload Toolbar) - {40C3CC16-7269-4B32-9531-17F2950FB06F} - C:\Program Files\Winload\tbWinl.dll (Conduit Ltd.)
O3 - HKU\Blondy_ON_C\..\Toolbar\WebBrowser: (ST-de3 Toolbar) - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - C:\Program Files\softonic-de3\prxtbsof0.dll (Conduit Ltd.)
O3 - HKU\Blondy_ON_C\..\Toolbar\WebBrowser: (MyBabylon-English Toolbar) - {CE18769B-C7FA-42D2-860D-17C4662C70AD} - C:\Program Files\MyBabylon-English\tbMyBa.dll (Conduit Ltd.)
O3 - HKU\Blondy_ON_C\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\Blondy_ON_C\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DATAMNGR] File not found
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [Sweetpacks Communicator] C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\.DEFAULT..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (Fujitsu Siemens Computers)
O4 - HKU\Blondy_ON_C..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKU\Blondy_ON_C..\Run: [EPSON BX305 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIGJE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\Blondy_ON_C..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe (PC Utilities Pro)
O4 - HKU\LocalService_ON_C..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\NetworkService_ON_C..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\UpdatusUser_ON_C..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Blondy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PMB Medien-Prüfung.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
O7 - HKU\Blondy_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Free YouTube Download - C:\Users\Blondy\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Blondy\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} hxxp://www.navigram.com/engine/v1111/Navigram.cab (Navigram Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\SEARCH~1\Datamngr\datamngr.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\SEARCH~1\Datamngr\IEBHO.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKU\Blondy_ON_C Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKU\Blondy_ON_C Winlogon: Shell - (C:\Users\Blondy\AppData\Roaming\skype.dat) - C:\Users\Blondy\AppData\Roaming\skype.dat ()
O24 - Desktop WallPaper: D:\Yvonne_Rechner\Pictures\Yvonne Ron Ansicht\bearbeitet\11_2.jpg
O24 - Desktop BackupWallPaper: D:\Yvonne_Rechner\Pictures\Yvonne Ron Ansicht\bearbeitet\11_2.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{65606e37-93ef-11e0-b6a3-001d92880d39}\Shell - "" = AutoRun
O33 - MountPoints2\{65606e37-93ef-11e0-b6a3-001d92880d39}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{65606e44-93ef-11e0-b6a3-001d92880d39}\Shell - "" = AutoRun
O33 - MountPoints2\{65606e44-93ef-11e0-b6a3-001d92880d39}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{87a66985-6106-11df-b329-001d92880d39}\Shell\AutoRun\command - "" = F:\Get_Started_for_Win.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2013/01/05 13:45:06 | 000,090,624 | ---- | C] (Nokia) -- C:\Windows\System32\nmwcdcls.dll
[2013/01/05 13:45:02 | 000,021,632 | ---- | C] (Nokia) -- C:\Windows\System32\drivers\pccsmcfd.sys
[2013/01/05 13:44:27 | 000,121,856 | ---- | C] (MCCI Corporation) -- C:\Windows\System32\drivers\ss_bmdm.sys
[2013/01/05 13:44:27 | 000,090,112 | ---- | C] (MCCI) -- C:\Windows\System32\drivers\ss_bbus.sys
[2013/01/05 13:44:27 | 000,014,976 | ---- | C] (MCCI Corporation) -- C:\Windows\System32\drivers\ss_bmdfl.sys
[2013/01/05 13:44:27 | 000,012,160 | ---- | C] (MCCI Corporation) -- C:\Windows\System32\drivers\ss_bwhnt.sys
[2013/01/05 13:44:27 | 000,012,160 | ---- | C] (MCCI Corporation) -- C:\Windows\System32\drivers\ss_bwh.sys
[2013/01/05 13:44:27 | 000,012,160 | ---- | C] (MCCI Corporation) -- C:\Windows\System32\drivers\ss_bcmnt.sys
[2013/01/05 13:44:27 | 000,012,160 | ---- | C] (MCCI Corporation) -- C:\Windows\System32\drivers\ss_bcm.sys
[2013/01/05 13:43:31 | 000,000,000 | ---D | C] -- C:\Windows\System32\Samsung_USB_Drivers
[2013/01/05 13:43:25 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
[2013/01/05 13:43:02 | 000,233,472 | ---- | C] (Teruten) -- C:\Windows\System32\FsUsbExService.Exe
[2013/01/05 13:43:00 | 000,000,000 | ---D | C] -- C:\Users\Blondy\Documents\My NPS Files
[2013/01/05 13:42:13 | 000,000,000 | ---D | C] -- C:\Users\Blondy\AppData\Roaming\Samsung
[2013/01/05 13:40:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung New PC Studio
[2013/01/05 13:40:50 | 000,000,000 | ---D | C] -- C:\Program Files\MarkAny
[2013/01/05 13:40:49 | 000,000,000 | ---D | C] -- C:\Program Files\PC Connectivity Solution
[2013/01/05 13:40:21 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
[2013/01/05 13:37:11 | 000,000,000 | ---D | C] -- C:\Users\Blondy\AppData\Local\Downloaded Installations
[2012/12/19 09:29:33 | 000,000,000 | ---D | C] -- C:\Users\Blondy\Documents\Küchenkalender_Weihnachten-Dateien
[2012/12/18 03:38:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/12/18 03:37:46 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/12/18 03:37:40 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/12/18 03:37:40 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2010/10/04 23:49:16 | 007,760,687 | ---- | C] (Boraxsoft) -- C:\Users\Blondy\AppData\Roaming\SetupGFD.exe
[2010/10/04 23:48:54 | 005,243,208 | ---- | C] ( ) -- C:\Users\Blondy\AppData\Roaming\AvsP.exe
[2010/10/04 23:48:34 | 004,284,535 | ---- | C] (ffdshow ) -- C:\Users\Blondy\AppData\Roaming\ffdshow.exe
[2010/10/04 23:48:30 | 000,642,685 | ---- | C] (Xvid team ) -- C:\Users\Blondy\AppData\Roaming\xvid.exe
[2010/10/04 23:48:20 | 002,169,915 | ---- | C] (LIGHTNING UK!) -- C:\Users\Blondy\AppData\Roaming\Imgburn.exe
[2010/10/04 23:48:02 | 004,182,178 | ---- | C] (The Public) -- C:\Users\Blondy\AppData\Roaming\Avisynth.exe
[2010/05/16 11:14:33 | 001,041,920 | ---- | C] (Atheros Communications, Inc.) -- C:\Program Files\WlanGZGV64.sys
[2010/05/16 11:14:03 | 000,873,472 | ---- | C] (Atheros Communications, Inc.) -- C:\Program Files\WlanGZGV32.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/01/14 14:56:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/01/14 14:56:11 | 000,000,004 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\skype.ini
[2013/01/14 14:55:46 | 000,000,680 | ---- | M] () -- C:\Users\Blondy\AppData\Local\d3d9caps.dat
[2013/01/14 14:55:31 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/14 14:55:31 | 000,000,380 | ---- | M] () -- C:\Windows\tasks\RNUpgradeHelperLogonPrompt_Blondy.job
[2013/01/14 14:55:00 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/14 14:55:00 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/14 14:54:53 | 3488,866,304 | -HS- | M] () -- C:\hiberfil.sys
[2013/01/13 11:57:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/13 11:26:11 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/13 09:01:58 | 000,628,504 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013/01/13 09:01:58 | 000,595,798 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/01/13 09:01:58 | 000,126,248 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013/01/13 09:01:58 | 000,103,872 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/01/10 22:02:41 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\ReclaimerUpdateXML_Blondy.job
[2013/01/10 01:38:00 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\ReclaimerUpdateFiles_Blondy.job
[2013/01/05 13:45:12 | 000,001,913 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung New PC Studio.lnk
[2013/01/05 13:45:11 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung New PC Studio
[2013/01/05 13:42:19 | 000,002,528 | ---- | M] () -- C:\Users\Blondy\AppData\Roaming\$_hpcst$.hpc
[2013/01/05 13:40:53 | 000,001,989 | ---- | M] () -- C:\Users\Public\Desktop\Samsung New PC Studio.lnk
[2012/12/21 08:05:39 | 000,048,640 | ---- | M] () -- C:\Users\Blondy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/12/21 07:54:43 | 487,190,975 | ---- | M] () -- C:\Users\Blondy\Desktop\YvoGitarre.rar
[2012/12/19 09:47:02 | 000,578,294 | ---- | M] () -- C:\Users\Blondy\Documents\Küchenkalender_Weihnachten.pcf
[2012/12/18 13:55:47 | 000,013,213 | ---- | M] () -- C:\Users\Blondy\Documents\NowOneNows.odt
[2012/12/18 03:38:30 | 000,001,630 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/12/18 03:38:30 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/12/17 03:43:36 | 000,013,636 | ---- | M] () -- C:\Users\Blondy\Documents\WeihnachtenInFamilie_Text.odt
[2012/12/17 03:35:06 | 000,012,229 | ---- | M] () -- C:\Users\Blondy\Documents\LilaWolken_Gitarre.odt
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/01/14 14:54:52 | 3488,866,304 | -HS- | C] () -- C:\hiberfil.sys
[2013/01/13 12:18:50 | 000,000,004 | ---- | C] () -- C:\Users\Blondy\AppData\Roaming\skype.ini
[2013/01/05 13:45:12 | 000,001,913 | ---- | C] () -- C:\Users\Blondy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung New PC Studio.lnk
[2013/01/05 13:43:02 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2013/01/05 13:43:02 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2013/01/05 13:42:19 | 000,002,528 | ---- | C] () -- C:\Users\Blondy\AppData\Roaming\$_hpcst$.hpc
[2013/01/05 13:40:53 | 000,001,989 | ---- | C] () -- C:\Users\Public\Desktop\Samsung New PC Studio.lnk
[2012/12/20 04:31:33 | 000,000,380 | ---- | C] () -- C:\Windows\tasks\RNUpgradeHelperLogonPrompt_Blondy.job
[2012/12/20 04:31:31 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\ReclaimerUpdateFiles_Blondy.job
[2012/12/20 04:31:28 | 000,000,370 | ---- | C] () -- C:\Windows\tasks\ReclaimerUpdateXML_Blondy.job
[2012/12/19 09:29:32 | 000,578,294 | ---- | C] () -- C:\Users\Blondy\Documents\Küchenkalender_Weihnachten.pcf
[2012/12/18 13:55:45 | 000,013,213 | ---- | C] () -- C:\Users\Blondy\Documents\NowOneNows.odt
[2012/12/17 03:43:34 | 000,013,636 | ---- | C] () -- C:\Users\Blondy\Documents\WeihnachtenInFamilie_Text.odt
[2012/12/17 03:35:03 | 000,012,229 | ---- | C] () -- C:\Users\Blondy\Documents\LilaWolken_Gitarre.odt
[2012/11/07 02:57:03 | 000,290,500 | ---- | C] () -- C:\Users\Blondy\AppData\Local\funmoods-speeddial_sf.crx
[2012/11/07 02:57:02 | 000,031,465 | ---- | C] () -- C:\Users\Blondy\AppData\Local\funmoods.crx
[2011/09/26 23:26:54 | 000,000,275 | ---- | C] () -- C:\Users\Blondy\AppData\Local\HamsterVideoConverterSettings.cfg
[2011/02/21 09:14:18 | 000,028,672 | ---- | C] () -- C:\Windows\System32\msidle32.dll
[2011/02/10 01:15:23 | 000,058,880 | ---- | C] () -- C:\Users\Blondy\AppData\Roaming\skype.dat
[2010/12/02 14:06:06 | 000,019,456 | ---- | C] () -- C:\Users\Blondy\AppData\Local\WebpageIcons.db
[2010/10/24 06:26:27 | 000,005,108 | ---- | C] () -- C:\ProgramData\drctchbl.xvi
[2010/10/24 06:26:26 | 000,004,099 | ---- | C] () -- C:\ProgramData\xqkcebzs.dik
[2010/10/22 04:21:45 | 000,000,000 | ---- | C] () -- C:\Users\Blondy\AppData\Roaming\chrtmp
[2010/10/02 10:24:31 | 000,178,176 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010/10/02 10:24:30 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2010/10/02 10:24:28 | 000,815,104 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2010/10/02 10:24:28 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010/10/02 10:24:28 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2010/09/25 08:28:44 | 000,026,624 | -H-- | C] () -- C:\Users\Blondy\AppData\Roaming\audiohd.exe
[2010/09/19 10:54:41 | 000,198,656 | -H-- | C] () -- C:\Users\Blondy\AppData\Roaming\Svchost.bat
[2010/08/16 23:53:47 | 000,210,456 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2010/08/16 23:53:47 | 000,206,360 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2010/08/16 23:53:47 | 000,198,168 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2010/08/16 23:53:47 | 000,198,168 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2010/08/16 23:53:47 | 000,194,072 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2010/08/16 23:53:47 | 000,026,136 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2010/06/07 13:20:52 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2010/06/07 12:40:53 | 000,053,248 | ---- | C] () -- C:\Windows\System32\CommonDL.dll
[2010/06/07 12:40:53 | 000,002,413 | ---- | C] () -- C:\Windows\System32\lgAxconfig.ini
[2010/06/02 12:42:48 | 000,048,640 | ---- | C] () -- C:\Users\Blondy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/24 03:19:42 | 000,126,976 | ---- | C] () -- C:\Windows\System32\EEBAPI.dll
[2010/05/24 03:19:42 | 000,094,208 | ---- | C] () -- C:\Windows\System32\EEBDSCVR.dll
[2010/05/24 03:19:42 | 000,049,152 | ---- | C] () -- C:\Windows\System32\EBAPI.dll
[2010/05/20 00:41:31 | 000,000,680 | ---- | C] () -- C:\Users\Blondy\AppData\Local\d3d9caps.dat
[2010/05/18 00:19:30 | 000,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010/05/18 00:19:30 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/05/16 11:14:39 | 000,050,601 | ---- | C] () -- C:\Program Files\G-220_v2_Vista 2 0 2 12_Release_Note.pdf
[2010/05/16 11:14:28 | 000,006,960 | ---- | C] () -- C:\Program Files\WlanGZGV64.inf
[2010/05/16 11:14:23 | 000,010,764 | ---- | C] () -- C:\Program Files\WlanGZGV64.cat
[2010/05/16 11:14:17 | 000,006,930 | ---- | C] () -- C:\Program Files\WlanGZGV32.inf
[2010/05/16 11:14:12 | 000,010,764 | ---- | C] () -- C:\Program Files\WlanGZGV32.cat
[2010/05/16 10:17:18 | 000,000,342 | ---- | C] () -- C:\Windows\{9A3BC157-B94F-4EFD-ABA9-1E56DEB00655}_WiseFW.ini
[2008/05/26 19:32:09 | 000,000,479 | ---- | C] () -- C:\Program Files\- manual -.lnk
[2008/02/29 07:13:14 | 000,012,288 | ---- | C] () -- C:\Windows\System32\EvOnlDiag.dll
[2008/01/21 02:15:58 | 000,628,504 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008/01/21 02:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008/01/21 02:15:58 | 000,126,248 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008/01/21 02:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2007/10/25 11:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2007/07/23 02:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2007/07/23 02:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2007/07/23 02:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2007/07/23 02:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2007/07/23 02:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2007/07/23 02:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2007/07/23 02:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2007/07/23 02:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2007/07/23 02:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2007/03/12 12:59:00 | 000,299,008 | ---- | C] () -- C:\Program Files\navigram_register.exe
[2006/11/02 07:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,275,552 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,595,798 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,103,872 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 05:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
========== LOP Check ==========
[2012/07/23 12:34:56 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\.k3d
[2010/11/12 02:19:27 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\Amazon
[2011/03/27 03:18:51 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\ASCON Installer
[2011/02/04 03:15:30 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\Canneverbe Limited
[2012/10/28 10:40:23 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\DVDVideoSoft
[2012/10/28 10:40:19 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\DVDVideoSoftIEHelpers
[2012/02/22 02:42:06 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\Epson
[2011/09/20 12:58:01 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\FreeFox
[2012/12/19 04:57:02 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\gtk-2.0
[2010/10/05 01:00:06 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\ImgBurn
[2011/02/25 04:00:32 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\innoPlus
[2010/06/07 13:14:51 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\LG Electronics
[2010/06/07 12:24:17 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\Music Editor Free
[2012/12/05 02:05:02 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\OpenCandy
[2010/05/21 00:07:55 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\OpenOffice.org
[2012/12/15 11:48:21 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\Optimizer Pro
[2012/12/18 02:11:22 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\PhotoMania
[2013/01/05 13:42:13 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\Samsung
[2010/09/04 03:17:15 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\SecondLife
[2011/06/11 01:05:30 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\T-Mobile
[2011/06/11 01:23:29 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\T-Mobile Internet Manager
[2012/12/05 02:06:36 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\TuneUp Software
[2010/08/17 00:21:26 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\Ulead Systems
[2010/10/02 12:24:56 | 000,000,000 | ---D | M] -- C:\Users\Blondy\AppData\Roaming\Video DVD Maker FREE
[2012/12/18 03:38:22 | 000,000,000 | ---D | M] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2010/05/16 10:03:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2012/11/07 02:13:08 | 000,000,000 | ---D | M] -- C:\ProgramData\boost_interprocess
[2011/02/04 03:15:30 | 000,000,000 | ---D | M] -- C:\ProgramData\Canneverbe Limited
[2012/07/24 01:30:11 | 000,000,000 | -H-D | M] -- C:\ProgramData\Common Files
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2010/05/16 10:03:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
[2012/02/22 02:25:13 | 000,000,000 | ---D | M] -- C:\ProgramData\EPSON
[2010/05/16 10:03:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2010/10/05 00:12:29 | 000,000,000 | ---D | M] -- C:\ProgramData\Fighters
[2012/12/14 05:13:13 | 000,000,000 | ---D | M] -- C:\ProgramData\fotokasten comfort
[2010/05/16 10:10:31 | 000,000,000 | ---D | M] -- C:\ProgramData\fsc-reg
[2010/08/16 23:53:51 | 000,000,000 | ---D | M] -- C:\ProgramData\InterVideo
[2010/06/07 12:41:22 | 000,000,000 | ---D | M] -- C:\ProgramData\LGMOBILEAX
[2012/05/05 11:18:56 | 000,000,000 | ---D | M] -- C:\ProgramData\PopCap Games
[2011/05/29 04:53:31 | 000,000,000 | ---D | M] -- C:\ProgramData\ScanQuery
[2012/09/06 01:39:28 | 000,000,000 | ---D | M] -- C:\ProgramData\SmartSound Software Inc
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2010/05/16 10:03:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
[2012/12/12 04:41:19 | 000,000,000 | ---D | M] -- C:\ProgramData\SweetIM
[2006/11/02 08:02:04 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2012/12/05 02:06:36 | 000,000,000 | ---D | M] -- C:\ProgramData\TuneUp Software
[2012/02/22 02:29:53 | 000,000,000 | ---D | M] -- C:\ProgramData\UDL
[2010/08/17 00:01:15 | 000,000,000 | ---D | M] -- C:\ProgramData\Ulead Systems
[2010/05/16 10:03:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
[2012/07/24 01:30:11 | 000,000,000 | -HSD | M] -- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2010/05/16 12:52:45 | 000,000,000 | ---D | M] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/12/05 02:06:27 | 000,000,000 | -HSD | M] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2013/01/10 01:38:00 | 000,000,374 | ---- | M] () -- C:\Windows\Tasks\ReclaimerUpdateFiles_Blondy.job
[2013/01/10 22:02:41 | 000,000,370 | ---- | M] () -- C:\Windows\Tasks\ReclaimerUpdateXML_Blondy.job
[2013/01/14 14:55:31 | 000,000,380 | ---- | M] () -- C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Blondy.job
[2013/01/14 14:56:35 | 000,032,534 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >
Wie verfahre ich jetzt weiter??? Ich habe gelesen das man bei Scan fix etwas reinkopieren soll, aber was? Bitte um Hilfe ich brauche meinen Rechner ganz dringend....Vielen Dank schon mal