Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Backdoorprogramm BDS/Cycbot.176128.56 (https://www.trojaner-board.de/106254-backdoorprogramm-bds-cycbot-176128-56-a.html)

Rheingold 15.12.2011 08:23

Backdoorprogramm BDS/Cycbot.176128.56
 
Hallo,
avira hat heute den Virus BDS/Cycbot.176128.56 bei mir gefunden. Ist jetzt noch in der Quarantäne.
Außerdem habe ich seit gestern das Problem, dass ich wenn ich bei google auf einen link klicke auf eine völlig andere Seite geführt werde.

Wer kann mir helfen?

Habe Windows 7, 64bit. Weitere Angaben folgen noch.

Viele Grüße
Rheingold

kira 15.12.2011 08:51

Hallo und Herzlich Willkommen! :)

Bevor wir unsere Zusammenarbeit beginnen, [Bitte Vollständig lesen]:
Zitat:

  • "Fernbehandlungen/Fernhilfe" und die damit verbundenen Haftungsrisken:
    - da die Fehlerprüfung und Handlung werden über große Entfernungen durchgeführt, besteht keine Haftung unsererseits für die daraus entstehenden Folgen.
    - also, jede Haftung für die daraus entstandene Schäden wird ausgeschlossen, ANWEISUNGEN UND DEREN BEFOLGUNG, ERFOLGT AUF DEINE EIGENE VERANTWORTUNG!
  • Charakteristische Merkmale/Profilinformationen:
    - aus der verwendeten Loglisten oder Logdateien - wie z.B. deinen Realnamen, Seriennummer in Programm etc)- kannst Du herauslöschen oder durch [X] ersetzen
  • Die Systemprüfung und Bereinigung:
    - kann einige Zeit in Anspruch nehmen (je nach Art der Infektion), kann aber sogar so stark kompromittiert sein, so dass eine wirkungsvolle technische Säuberung ist nicht mehr möglich bzw Du es neu installieren musst
  • Ich empfehle Dir die Anweisungen erst einmal komplett durchzulesen, bevor du es anwendest, weil wenn du etwas falsch machst, kann es wirklich gefährlich werden. Wenn du meinen Anweisungen Schritt für Schritt folgst, kann eigentlich nichts schief gehen.
  • Innerhalb der Betreuungszeit:
    - ohne Abspräche bitte nicht auf eigene Faust handeln!- bei Problemen nachfragen.
  • Die Reihenfolge:
    - genau so wie beschrieben bitte einhalten, nicht selbst die Reihenfolge wählen!
  • GECRACKTE SOFTWARE werden hier nicht geduldet!!!!
  • Ansonsten unsere Forumsregeln:
    - Bitte erst lesen, dann posten!-> Für alle Hilfesuchenden! Was muss ich vor der Eröffnung eines Themas beachten?
  • Alle Logfile mit einem vBCode Tag eingefügen, das bietet hier eine gute Übersicht, erleichtert mir die Arbeit! Falls das Logfile zu groß, teile es in mehrere Teile auf.

Sobald Du diesen Einführungstext gelesen hast, kannst Du beginnen:)
► Erster Teil des 3-teiligen Verfahren, werden wir dein System auf Viren untersuchen, bzw nach einem anderen Verursacher suchen:
Für Vista und Win7:
Wichtig: Alle Befehle bitte als Administrator ausführen! rechte Maustaste auf die Eingabeaufforderung und "als Administrator ausführen" auswählen
Auf der angewählten Anwendung einen Rechtsklick (rechte Maustaste) und "Als Administrator ausführen" wählen!

1.
Lade Dir Malwarebytes Anti-Malware von→ malwarebytes.org
  • Installieren und per Doppelklick starten.
  • Deutsch einstellen und gleich mal die Datenbanken zu aktualisieren - online updaten
  • "Komplett Scan durchführen" wählen (überall Haken setzen)
  • wenn der Scanvorgang beendet ist, klicke auf "Zeige Resultate"
  • Alle Funde - falls MBAM meldet in C:\System Volume Information - den Haken bitte entfernen - markieren und auf "Löschen" - "Ausgewähltes entfernen") klicken.
  • Poste das Ergebnis hier in den Thread - den Bericht findest Du unter "Scan-Berichte"
eine bebilderte Anleitung findest Du hier: Anleitung

2.
Systemscan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt - OTL.txt und Extras.txt
  • Poste die Logfiles in Code-Tags hier in den Thread.

3.
Ich würde gerne noch all deine installierten Programme sehen:
Lade dir das Tool CCleaner herunter
Download
installieren (Software-Lizenzvereinbarung lesen, falls angeboten wird "Füge CCleaner Yahoo! Toolbar hinzu" abwählen)→ starten→ Sprache → Deutsch auswählen
dann klick auf "Extra (um die installierten Programme auch anzuzeigen)→ weiter auf "Als Textdatei speichern..."
wird eine Textdatei (*.txt) erstellt, kopiere dazu den Inhalt und füge ihn da ein

4.
Mache bitte ein Rechtsklick auf den AntiVir-Schirm in der Taskleiste → AntiVir startenÜbersicht Ereignisse
jeden Fund markieren → Rechtsklick auf Funde → Ereignis(se) exportieren
und als Ereignisse.txt auf dem Desktop speichern und den Inhalt hier posten.

Zitat:

Damit dein Thread übersichtlicher und schön lesbar bleibt, am besten nutze den Code-Tags für deinen Post:
→ vor dein Log schreibst Du (also am Anfang des Logfiles):[code]
hier kommt dein Logfile rein - z.B OTL-Logfile o. sonstiges
→ dahinter - also am Ende der Logdatei: [/code]

** Möglichst nicht ins internet gehen, kein Online-Banking, File-sharing, Chatprogramme usw
gruß
kira

Rheingold 15.12.2011 10:38

Liebe Kira, vielen Dank für deine Antwort.
1. defogger hat, glaube ich, nicht funktioniert. Hier der defogger disable log:

Code:

defogger_disable by jpshortstuff (23.02.10.1)
Log created at 08:41 on 15/12/2011 (Jasmina)

Rest folgt.

Viele Grüße
Jasmina

Malwarebytes im Anhang
OTL muss ich noch mal laufen lassen, logfilge ist nicht mehr lesbar.


Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-

2. OTL

Rheingold 15.12.2011 11:59

sorry, muss zum job. bis später, jasmina

Rheingold 16.12.2011 09:38

Code:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 8377

Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514

15.12.2011 21:45:19
mbam-log-2011-12-15 (21-45-19).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 479185
Laufzeit: 1 Stunde(n), 2 Minute(n), 29 Sekunde(n)

Infizierte Speicherprozesse: 3
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 2
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 1
Infizierte Dateien: 11

Infizierte Speicherprozesse:
c:\Users\administrator\AppData\Roaming\B8457\6D1A7.exe (Trojan.Dropper.PE4) -> 4112 -> Unloaded process successfully.
c:\program files (x86)\LP\A7CB\737.exe (Trojan.Dropper.PE4) -> 4652 -> Unloaded process successfully.
c:\program files (x86)\57168\lvvm.exe (Trojan.Dropper.PE4) -> 5224 -> Unloaded process successfully.

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\737.exe (Trojan.Dropper.PE4) -> Value: 737.exe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell.Gen) -> Value: Shell -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableConfig (Windows.Tool.Disabled) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
c:\Users\nico.dell-pc.000\m-1-25-5432-6437-5685 (Trojan.Agent.Gen) -> Quarantined and deleted successfully.

Infizierte Dateien:
c:\Users\administrator\AppData\Roaming\B8457\6D1A7.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
c:\program files (x86)\LP\A7CB\737.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
c:\program files (x86)\57168\lvvm.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
c:\Users\Jasmina\AppData\Roaming\firefox.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
c:\Users\Jasmina\AppData\Roaming\57168\lvvm.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
c:\Users\Jasmina\AppData\Roaming\B8457\6D1A7.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
c:\Users\Jasmina\AppData\Roaming\microsoft\A7CB\737.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
c:\Users\nico.dell-pc.000\AppData\Roaming\firefox.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
c:\Users\nico.dell-pc.000\AppData\Roaming\57168\lvvm.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
c:\Users\nico.dell-pc.000\AppData\Roaming\microsoft\A7CB\737.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
c:\Users\nico.dell-pc.000\m-1-25-5432-6437-5685\winmgr.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.


Rheingold 16.12.2011 09:42

Code:

OTL logfile created on: 15.12.2011 19:58:30 - Run 8
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Administrator\Desktop\Virus\OTL
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,90 Gb Total Physical Memory | 2,05 Gb Available Physical Memory | 52,57% Memory free
7,79 Gb Paging File | 5,89 Gb Available in Paging File | 75,64% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 235,24 Gb Total Space | 112,40 Gb Free Space | 47,78% Space Free | Partition Type: NTFS
Drive D: | 215,77 Gb Total Space | 206,35 Gb Free Space | 95,63% Space Free | Partition Type: NTFS
 
Computer Name: DELL-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Administrator\Desktop\Virus\OTL\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\57168\lvvm.exe ()
PRC - C:\Users\Administrator\AppData\Roaming\B8457\6D1A7.exe ()
PRC - C:\Program Files (x86)\LP\A7CB\737.exe ()
PRC - C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (SoftThinks SAS)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
PRC - C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe (DATA BECKER GmbH & Co KG)
PRC - C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe ()
PRC - C:\Windows\tray\wintmr.exe (Salfeld Computer)
PRC - C:\Windows\SysWOW64\cc32\webtmr.exe (Salfeld Computer)
PRC - C:\Windows\SysWOW64\ccsync.exe (Salfeld Computer)
PRC - C:\Windows\SysWOW64\cchservice.exe (Salfeld Computer)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\57168\lvvm.exe ()
MOD - C:\Users\Administrator\AppData\Roaming\B8457\6D1A7.exe ()
MOD - C:\Program Files (x86)\LP\A7CB\737.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\LibXml2.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (TurboBoost) -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel(R) Corporation)
SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (Akamai) -- c:\program files (x86)\common files\akamai/netsession_win_b427739.dll ()
SRV - (NAUpdate) -- C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (Kodak AiO Network Discovery Service) -- C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (Secunia PSI Agent) -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Secunia)
SRV - (Secunia Update Agent) -- C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (Bluetooth OBEX Service) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation)
SRV - (Bluetooth Media Service) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation)
SRV - (Bluetooth Device Monitor) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel Corporation)
SRV - (UNS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (EvtEng) Intel(R) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
SRV - (MyWiFiDHCPDNS) -- C:\Programme\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV - (RegSrvc) Intel(R) -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (RoxWatch12) -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe (Sonic Solutions)
SRV - (RoxMediaDB12OEM) -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe (Sonic Solutions)
SRV - (AdobeActiveFileMonitor9.0) -- C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (NOBU) -- C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe (Dell, Inc.)
SRV - (ksupmgr) -- C:\Windows\SysWOW64\ksupmgr.exe (Salfeld Computer)
SRV - (SftService) -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (SoftThinks SAS)
SRV - (DBService) -- C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe (DATA BECKER GmbH & Co KG)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (AERTFilters) -- C:\Programme\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (NBVol) -- C:\Windows\SysNative\drivers\NBVol.sys (Nero AG)
DRV:64bit: - (NBVolUp) -- C:\Windows\SysNative\drivers\NBVolUp.sys (Nero AG)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (HPub4DE3) USB Mouse Low Filter Driver_4DE3 (WDF Version) -- C:\Windows\SysNative\drivers\HPub4DE3.sys (TPMX Electronics Ltd.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HPMo4DE3) Mouse Suite Driver_4DE3 (WDF Version) -- C:\Windows\SysNative\drivers\HPMo4DE3.sys (TPMX Electronics Ltd.)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (btmaux) -- C:\Windows\SysNative\drivers\btmaux.sys (Intel Corporation)
DRV:64bit: - (iBtFltCoex) -- C:\Windows\SysNative\drivers\iBtFltCoex.sys (Intel Corporation)
DRV:64bit: - (btmhsf) -- C:\Windows\SysNative\drivers\btmhsf.sys (Intel Corporation)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (NETwNs64) ___ Intel(R) -- C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (JMCR) -- C:\Windows\SysNative\drivers\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (Acceler) -- C:\Windows\SysNative\drivers\Accelern.sys (ST Microelectronics)
DRV:64bit: - (NvStUSB) -- C:\Windows\SysNative\drivers\nvstusb.sys ()
DRV:64bit: - (nvpciflt) -- C:\Windows\SysNative\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV:64bit: - (TurboB) -- C:\Windows\SysNative\drivers\TurboB.sys (Intel(R) Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) Intel(R) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel(R) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (PSI) -- C:\Windows\SysNative\drivers\psi_mf.sys (Secunia)
DRV:64bit: - (stdcfltn) -- C:\Windows\SysNative\drivers\stdcfltn.sys (ST Microelectronics)
DRV:64bit: - (CtClsFlt) -- C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (qicflt) -- C:\Windows\SysNative\drivers\qicflt.sys (Quanta Computer)
DRV:64bit: - (AVer7231_x64) -- C:\Windows\SysNative\drivers\AVer7231_x64.sys (AVerMedia TECHNOLOGIES, Inc.)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (Impcd) -- C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (acedrv11) -- C:\Windows\SysNative\drivers\acedrv11.sys (Protect Software GmbH)
DRV:64bit: - (xusb21) -- C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (PDNMp50) -- C:\Windows\SysWOW64\drivers\PDNMp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (PDNSp50) -- C:\Windows\SysWOW64\drivers\PDNSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50263
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "www.google.de"
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50263
FF - prefs.js..network.proxy.type: 1
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF:64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.12.15 11:29:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.11 09:40:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.12.15 11:29:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Components: C:\Program Files (x86)\Mozilla Sunbird\components [2011.12.15 11:29:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Sunbird\plugins [2011.12.15 11:29:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.11.11 18:53:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 
[2011.05.19 12:42:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Extensions
[2011.05.19 12:42:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.09.12 11:27:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\3cers2zs.default\extensions
[2011.11.11 09:40:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.10.01 08:52:30 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.10.17 08:31:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011.10.29 10:21:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011.12.15 11:29:03 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011.11.11 09:40:26 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.10.29 10:21:40 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.09.16 21:59:18 | 000,170,064 | ---- | M] (Tracker Software Products Ltd.) -- C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2011.09.29 02:24:37 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.09.29 02:16:42 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011.09.29 02:24:37 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.09.29 02:24:37 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.29 02:24:37 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.09.29 02:24:37 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011.09.12 21:31:56 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation)
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\SysNative\spool\drivers\x64\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4:64bit: - HKLM..\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [NVHotkey] C:\Windows\SysNative\nvHotkey.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [737.exe] C:\Program Files (x86)\LP\A7CB\737.exe ()
O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ChicoSys] C:\Windows\SysWOW64\cc32\webtmr.exe (Salfeld Computer)
O4 - HKLM..\Run: [Conime] %windir%\system32\conime.exe File not found
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NBAgent] C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [SMSTray] C:\Program Files (x86)\Samsung\EmoDio\SMSTray.exe (SAMSUNG ELECTRONICS)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\.DEFAULT..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-18..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3230886925-126132133-2629391164-500..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background File not found
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O4 - HKU\.DEFAULT..\RunOnce: [KodakHomeCenter] C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O4 - HKU\S-1-5-18..\RunOnce: [KodakHomeCenter] C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O4 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Jasmina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Nico.dell-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Nico.dell-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Überwachungstool für die Intel® Turbo-Boost-Technik 2.0.lnk =  File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Privacy present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C8601AA9-2FCA-424D-B13E-12984594DCE3}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) -C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKU\S-1-5-21-3230886925-126132133-2629391164-500 Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-3230886925-126132133-2629391164-500 Winlogon: Shell - (C:\Users\Administrator\AppData\Roaming\B8457\6D1A7.exe) -C:\Users\Administrator\AppData\Roaming\B8457\6D1A7.exe ()
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - Unable to read "AutoRun" value or value not present!
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
 
 
CREATERESTOREPOINT
Error creating restore point.
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.12.15 11:50:27 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\SoftGrid Client
[2011.12.15 11:50:25 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\SoftGrid Client
[2011.12.15 11:47:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.12.15 11:47:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.12.15 11:35:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.12.15 11:34:51 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.12.15 11:34:50 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011.12.15 11:34:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011.12.15 11:29:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared
[2011.12.15 11:29:01 | 000,198,832 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2011.12.15 11:28:57 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2011.12.15 11:28:57 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2011.12.15 11:28:56 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2011.12.15 11:28:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
[2011.12.15 11:25:22 | 000,713,472 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer.exe
[2011.12.15 11:22:52 | 000,000,000 | -HSD | C] -- C:\Users\Administrator\AppData\Local\4d0d2e25
[2011.12.15 11:19:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\57168
[2011.12.15 11:19:19 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\B8457
[2011.12.15 11:14:51 | 009,852,544 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Program Files (x86)\mbam-setup-1.51.2.1300.exe
[2011.12.15 10:41:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.12.15 10:41:55 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.12.15 10:39:52 | 003,552,208 | ---- | C] (Piriform Ltd) -- C:\Program Files (x86)\ccsetup313.exe
[2011.12.15 08:29:11 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Desktop\Virus
[2011.12.14 23:09:17 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2011.12.14 23:09:17 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2011.12.14 23:09:15 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2011.12.14 08:33:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LP
[2011.12.02 16:28:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Nexon
[2011.12.02 16:25:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon
[2011.12.02 16:22:22 | 000,000,000 | ---D | C] -- C:\ProgramData\NexonEU
[2011.12.02 15:45:54 | 000,000,000 | ---D | C] -- C:\Download
[2011.12.02 15:45:20 | 000,000,000 | ---D | C] -- C:\Nexon
[2011.12.02 15:45:19 | 000,446,464 | ---- | C] (NEXON Inc.) -- C:\Windows\NEXON_EU_DownloaderUpdater.exe
[2011.11.24 09:38:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak
[2011.11.24 09:36:02 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\spool
[2011.11.24 09:23:29 | 012,713,136 | ---- | C] (Eastman Kodak Company) -- C:\Program Files (x86)\aio_install.exe
[2011.11.18 13:07:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011.11.18 10:33:58 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Temp
[2011.10.29 11:49:39 | 039,401,336 | ---- | C] (Apple Inc.) -- C:\Program Files (x86)\QuickTimeInstaller.exe
[2011.10.29 11:04:38 | 010,311,496 | ---- | C] (Opera Software ASA) -- C:\Program Files (x86)\Opera_1152_int_Setup.exe
[2011.10.29 10:10:18 | 000,910,624 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\jxpiinstall.exe
[2011.10.25 12:17:18 | 009,756,672 | ---- | C] ((c) Phoenix Technologies Ltd. ) -- C:\Program Files\L502X_A__06.exe
[2011.10.17 08:29:10 | 001,739,400 | ---- | C] (Secunia) -- C:\Program Files (x86)\PSISetup2003.exe
[2011.10.17 08:05:48 | 013,885,360 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 7.0.1.exe
[2011.09.29 09:11:38 | 022,482,384 | ---- | C] (Salfeld Computer GmbH                                      ) -- C:\Program Files (x86)\kisi2011.exe
[2011.09.24 17:12:36 | 001,291,624 | ---- | C] (Microsoft Corporation) -- C:\Program Files\wlsetup-web__1_.exe
[2011.09.23 14:09:00 | 000,676,624 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer_1406666_de.exe
[2011.09.22 10:34:36 | 003,089,056 | ---- | C] (Adobe Systems, Inc.) -- C:\Program Files (x86)\install_flash_player.exe
[2011.08.28 11:11:15 | 051,975,388 | ---- | C] (Acresso Software Inc.) -- C:\Program Files (x86)\VSX4_Pro_TBYB.exe.part
[2011.08.27 11:56:04 | 001,228,384 | ---- | C] (Adobe Systems Incorporated) -- C:\Program Files (x86)\PremiereElements_9_LS15.exe
[2011.08.25 17:58:21 | 006,716,353 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Sunbird_Setup_1.0_Beta_1.exe
[2011.07.18 15:59:52 | 013,522,064 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 5.0.1.exe
[2011.05.28 13:13:41 | 014,212,584 | ---- | C] (DVDVideoSoft Ltd.                                          ) -- C:\Program Files (x86)\FreeYouTubeToiPodConverter.exe
[2011.05.28 13:11:38 | 014,563,768 | ---- | C] (DVDVideoSoft Ltd.                                          ) -- C:\Program Files (x86)\FreeYouTubeToMP3Converter.exe
[2011.05.22 09:35:05 | 021,255,560 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files (x86)\SkypeSetupFull.exe
[2011.05.19 14:37:24 | 081,797,928 | ---- | C] (Apple Inc.) -- C:\Program Files (x86)\iTunes64Setup.exe
[2011.05.19 14:17:51 | 020,240,744 | ---- | C] (The GIMP Team                                              ) -- C:\Program Files (x86)\gimp-2.6.11-i686-setup.exe
[2011.05.19 14:17:11 | 019,735,256 | ---- | C] (                                                            ) -- C:\Program Files (x86)\gimp-2.6.8-x64-setup.exe
[2011.05.19 14:06:00 | 000,767,064 | ---- | C] (NCH Software) -- C:\Program Files (x86)\wpsetup4.57.exe
[2011.05.19 12:34:44 | 000,568,648 | ---- | C] (Google Inc.) -- C:\Program Files (x86)\GoogleEarthSetup.exe
[2011.05.19 12:26:57 | 009,559,320 | ---- | C] (Opera Software ASA) -- C:\Program Files (x86)\Opera_1111_int_Setup.exe
[2011.05.19 12:26:00 | 009,326,056 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Thunderbird Setup 3.1.10.exe
[2011.05.19 12:25:04 | 012,362,480 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 4.0.1.exe
[10 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.12.15 19:59:33 | 000,055,163 | ---- | M] () -- C:\Windows\SysWow64\ccsync.err
[2011.12.15 19:57:00 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1004UA.job
[2011.12.15 19:45:09 | 000,005,142 | ---- | M] () -- C:\Windows\SysWow64\cchservice.err
[2011.12.15 19:40:42 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.12.15 19:40:42 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.12.15 19:30:21 | 000,001,207 | ---- | M] () -- C:\Windows\SysWow64\excltmp~.dat
[2011.12.15 19:30:16 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.12.15 19:28:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.12.15 19:28:47 | 3137,994,752 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.15 19:06:12 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.12.15 11:47:50 | 000,001,162 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.12.15 11:35:17 | 000,001,836 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.12.15 11:29:09 | 000,001,308 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2011.12.15 11:29:01 | 000,198,832 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2011.12.15 11:28:57 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2011.12.15 11:28:57 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2011.12.15 11:28:56 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2011.12.15 11:27:59 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025UA.job
[2011.12.15 11:25:23 | 000,713,472 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer.exe
[2011.12.15 11:22:41 | 001,500,062 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.12.15 11:22:41 | 000,654,798 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.12.15 11:22:41 | 000,616,640 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.12.15 11:22:41 | 000,130,380 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.12.15 11:22:41 | 000,106,762 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.12.15 11:18:00 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1003UA.job
[2011.12.15 11:14:56 | 009,852,544 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Program Files (x86)\mbam-setup-1.51.2.1300.exe
[2011.12.15 10:41:56 | 000,000,824 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.12.15 10:39:52 | 003,552,208 | ---- | M] (Piriform Ltd) -- C:\Program Files (x86)\ccsetup313.exe
[2011.12.15 08:25:41 | 000,353,408 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.12.15 08:02:34 | 000,000,118 | ---- | M] () -- C:\Windows\SysNative\MRT.INI
[2011.12.14 21:33:43 | 000,000,348 | ---- | M] () -- C:\NET.INI
[2011.12.14 20:28:00 | 000,000,926 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025Core.job
[2011.12.14 20:18:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1003Core.job
[2011.12.14 08:38:37 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011.12.14 08:38:00 | 000,000,390 | ---- | M] () -- C:\Windows\tasks\At2.job
[2011.12.14 08:34:00 | 000,000,408 | ---- | M] () -- C:\Windows\tasks\At1.job
[2011.12.12 16:57:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1004Core.job
[2011.12.02 16:25:10 | 000,001,632 | ---- | M] () -- C:\Users\Public\Desktop\Combat Arms EU.lnk
[2011.12.02 15:45:20 | 000,000,235 | ---- | M] () -- C:\Windows\SysWow64\nxEuUninstall.bat
[2011.12.02 15:45:19 | 000,446,464 | ---- | M] (NEXON Inc.) -- C:\Windows\NEXON_EU_DownloaderUpdater.exe
[2011.11.24 09:39:41 | 000,002,209 | ---- | M] () -- C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
[2011.11.24 09:23:39 | 012,713,136 | ---- | M] (Eastman Kodak Company) -- C:\Program Files (x86)\aio_install.exe
[2011.11.18 13:07:22 | 000,002,265 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[10 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.12.15 18:48:38 | 000,054,813 | ---- | C] () -- C:\Windows\SysWow64\ccsync.err
[2011.12.15 11:47:50 | 000,001,162 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.12.15 11:35:17 | 000,001,836 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.12.15 11:29:09 | 000,001,308 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2011.12.15 10:41:56 | 000,000,824 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.12.15 08:02:34 | 000,000,118 | ---- | C] () -- C:\Windows\SysNative\MRT.INI
[2011.12.14 08:37:13 | 000,000,390 | ---- | C] () -- C:\Windows\tasks\At2.job
[2011.12.14 08:33:19 | 000,000,408 | ---- | C] () -- C:\Windows\tasks\At1.job
[2011.12.02 16:25:10 | 000,001,632 | ---- | C] () -- C:\Users\Public\Desktop\Combat Arms EU.lnk
[2011.12.02 15:45:20 | 000,000,235 | ---- | C] () -- C:\Windows\SysWow64\nxEuUninstall.bat
[2011.11.24 09:39:41 | 000,002,209 | ---- | C] () -- C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
[2011.11.18 13:07:22 | 000,002,265 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2011.11.11 07:32:42 | 001,527,140 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.10.29 09:54:07 | 001,019,816 | ---- | C] () -- C:\Program Files\DELL_DELL-DIGITAL-DELIVERY_A05_R313622.exe
[2011.10.10 16:51:50 | 000,155,536 | ---- | C] () -- C:\Windows\SysWow64\dllcinx.exe
[2011.10.10 16:51:48 | 000,000,600 | ---- | C] () -- C:\Windows\SysWow64\nochook.ini
[2011.10.03 13:41:52 | 000,247,053 | ---- | C] () -- C:\Program Files (x86)\mp3DC213.exe
[2011.09.29 09:19:37 | 000,001,207 | ---- | C] () -- C:\Windows\SysWow64\excltmp~.dat
[2011.09.29 09:18:42 | 000,000,141 | -H-- | C] () -- C:\Windows\SysWow64\ctlsw.ini
[2011.09.29 09:18:42 | 000,000,102 | ---- | C] () -- C:\Windows\SysWow64\SWCTL.DLL
[2011.09.29 09:18:40 | 000,009,368 | ---- | C] () -- C:\Windows\SysWow64\drivers\mchccinj.sys
[2011.09.29 08:11:44 | 000,124,416 | ---- | C] () -- C:\Windows\SysWow64\dXCtrls.dll
[2011.09.29 08:11:43 | 000,544,256 | ---- | C] () -- C:\Windows\SysWow64\janGraphics.dll
[2011.09.29 07:55:01 | 003,103,511 | ---- | C] () -- C:\Program Files (x86)\kcsetup8.exe
[2011.09.23 14:05:53 | 021,073,936 | ---- | C] () -- C:\Program Files (x86)\vlc-1.1.11-win32.exe
[2011.09.23 12:51:28 | 000,003,027 | ---- | C] () -- C:\Program Files (x86)\Français.lng
[2011.09.23 12:51:28 | 000,002,946 | ---- | C] () -- C:\Program Files (x86)\Español.lng
[2011.09.23 12:51:28 | 000,002,920 | ---- | C] () -- C:\Program Files (x86)\Italiano.lng
[2011.09.23 12:51:28 | 000,002,699 | ---- | C] () -- C:\Program Files (x86)\Deutsch.lng
[2011.09.23 12:51:28 | 000,002,553 | ---- | C] () -- C:\Program Files (x86)\Suomi.lng
[2011.09.23 12:40:52 | 023,773,184 | ---- | C] () -- C:\Program Files (x86)\PXCViewer98_x64.msi
[2011.09.23 12:27:47 | 001,376,768 | ---- | C] () -- C:\Program Files (x86)\7z920-x64.msi
[2011.09.16 06:44:01 | 168,166,968 | ---- | C] () -- C:\Program Files (x86)\OOo_3.3.0_Win_x86_install-wJRE_de.exe
[2011.08.28 09:55:59 | 002,466,704 | ---- | C] () -- C:\Program Files (x86)\AdobeDownloadAssistant.exe
[2011.08.27 11:27:07 | 1316,066,539 | ---- | C] () -- C:\Program Files (x86)\PremiereElements_9_LS15.7z
[2011.08.27 11:23:03 | 008,353,800 | ---- | C] () -- C:\Program Files (x86)\Adobe_Premiere_Elements_9-AkamaiDLM.exe
[2011.05.19 14:44:09 | 001,663,693 | ---- | C] () -- C:\Program Files (x86)\winrar-x64-400d.exe
[2011.05.19 14:10:20 | 014,166,016 | ---- | C] () -- C:\Program Files (x86)\wz150gev.msi
[2011.05.19 14:09:07 | 006,088,218 | ---- | C] () -- C:\Program Files (x86)\flash_player.zip
[2011.05.19 13:52:49 | 000,000,056 | ---- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011.05.19 12:39:40 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.05.19 12:28:56 | 052,718,176 | ---- | C] () -- C:\Program Files (x86)\avira_antivir_personal_de.exe
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_89001461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_49001461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_33011461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_8a.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A0F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_8a.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_14001461_61.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_13011461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_110F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_110F1461_8a.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_ca.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_aa.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_8a.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_ca.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_aa.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_8a.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_890F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_2B0f1461_ca.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_29001461_ca.bin
[2011.05.15 06:48:49 | 000,000,412 | ---- | C] () -- C:\Windows\11317231_180F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,412 | ---- | C] () -- C:\Windows\11317231_18071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_11071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_11071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A0F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A031461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A031461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A011461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_09001461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_08071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_060F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_06071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_06071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_03011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_03011461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_02011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_02011461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_010F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_010F1461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_01071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_01071461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_07031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_ca.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03131461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_ca.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_8a.bin
[2011.05.15 06:48:48 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_0B0f1461_ca.bin
[2011.05.15 06:48:48 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_090F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,376 | ---- | C] () -- C:\Windows\11317231_03131461_aa.bin
[2011.05.15 06:48:47 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_00000000_aa.bin
[2011.05.15 06:48:11 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011.05.15 06:47:21 | 000,960,940 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.05.15 06:47:19 | 000,213,332 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.05.15 06:47:17 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.01.19 12:34:42 | 003,003,392 | ---- | C] () -- C:\Program Files (x86)\openofficeorg33.msi
[2011.01.19 12:33:04 | 000,475,016 | ---- | C] () -- C:\Program Files (x86)\setup.exe
[2011.01.19 12:30:10 | 142,700,671 | ---- | C] () -- C:\Program Files (x86)\openofficeorg1.cab
[2011.01.19 11:15:26 | 000,000,290 | ---- | C] () -- C:\Program Files (x86)\setup.ini
[2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009.04.16 12:24:14 | 000,921,600 | ---- | C] () -- C:\Windows\SysWow64\vorbisenc.dll
[2009.04.16 12:24:14 | 000,237,568 | ---- | C] () -- C:\Windows\SysWow64\OggDS.dll
[2009.04.16 12:24:14 | 000,188,416 | ---- | C] () -- C:\Windows\SysWow64\vorbis.dll
[2009.04.16 12:24:14 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\Ogg.dll
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*. >
[2011.09.29 10:09:32 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN
[2011.12.15 11:35:27 | 000,000,000 | ---D | M] -- C:\Config.Msi
[2011.10.29 09:58:05 | 000,000,000 | ---D | M] -- C:\dell
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2011.05.18 15:28:48 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2011.12.02 16:22:22 | 000,000,000 | ---D | M] -- C:\Download
[2011.05.20 16:39:10 | 000,000,000 | ---D | M] -- C:\Drivers
[2011.05.14 21:10:05 | 000,000,000 | ---D | M] -- C:\Intel
[2011.06.21 20:48:05 | 000,000,000 | ---D | M] -- C:\Manual-PCProgram
[2011.05.19 11:18:55 | 000,000,000 | ---D | M] -- C:\Netgear
[2011.12.02 16:22:32 | 000,000,000 | ---D | M] -- C:\Nexon
[2009.07.14 04:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2011.12.15 11:34:51 | 000,000,000 | R--D | M] -- C:\Program Files
[2011.12.15 11:47:46 | 000,000,000 | R--D | M] -- C:\Program Files (x86)
[2011.12.02 16:28:28 | 000,000,000 | ---D | M] -- C:\ProgramData
[2011.05.18 15:28:48 | 000,000,000 | -HSD | M] -- C:\Programme
[2011.05.18 15:33:52 | 000,000,000 | -HSD | M] -- C:\System Recovery
[2011.12.15 11:54:14 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2011.12.15 11:25:57 | 000,000,000 | ---D | M] -- C:\Temp
[2011.09.29 10:09:30 | 000,000,000 | R--D | M] -- C:\Users
[2011.12.02 15:45:19 | 000,000,000 | ---D | M] -- C:\Windows
 
< %PROGRAMFILES%\*.exe >
[2011.08.28 09:56:00 | 002,466,704 | ---- | M] () -- C:\Program Files (x86)\AdobeDownloadAssistant.exe
[2011.08.27 11:23:09 | 008,353,800 | ---- | M] () -- C:\Program Files (x86)\Adobe_Premiere_Elements_9-AkamaiDLM.exe
[2011.11.24 09:23:39 | 012,713,136 | ---- | M] (Eastman Kodak Company) -- C:\Program Files (x86)\aio_install.exe
[2011.05.19 12:28:56 | 052,718,176 | ---- | M] () -- C:\Program Files (x86)\avira_antivir_personal_de.exe
[2011.12.15 10:39:52 | 003,552,208 | ---- | M] (Piriform Ltd) -- C:\Program Files (x86)\ccsetup313.exe
[2011.05.19 12:25:09 | 012,362,480 | ---- | M] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 4.0.1.exe
[2011.07.18 15:59:52 | 013,522,064 | ---- | M] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 5.0.1.exe
[2011.10.17 08:05:48 | 013,885,360 | ---- | M] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 7.0.1.exe
[2011.08.30 15:04:45 | 014,212,584 | ---- | M] (DVDVideoSoft Ltd.                                          ) -- C:\Program Files (x86)\FreeYouTubeToiPodConverter.exe
[2011.08.30 15:06:04 | 014,563,768 | ---- | M] (DVDVideoSoft Ltd.                                          ) -- C:\Program Files (x86)\FreeYouTubeToMP3Converter.exe
[2011.05.19 14:18:22 | 020,240,744 | ---- | M] (The GIMP Team                                              ) -- C:\Program Files (x86)\gimp-2.6.11-i686-setup.exe
[2011.05.19 14:17:51 | 019,735,256 | ---- | M] (                                                            ) -- C:\Program Files (x86)\gimp-2.6.8-x64-setup.exe
[2011.05.19 12:34:45 | 000,568,648 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\GoogleEarthSetup.exe
[2011.09.23 12:31:50 | 003,089,056 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files (x86)\install_flash_player.exe
[2011.05.19 14:39:47 | 081,797,928 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\iTunes64Setup.exe
[2011.10.29 10:17:09 | 000,910,624 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\jxpiinstall.exe
[2011.09.29 07:55:01 | 003,103,511 | ---- | M] () -- C:\Program Files (x86)\kcsetup8.exe
[2011.09.29 09:12:13 | 022,482,384 | ---- | M] (Salfeld Computer GmbH                                      ) -- C:\Program Files (x86)\kisi2011.exe
[2011.12.15 11:14:56 | 009,852,544 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Program Files (x86)\mbam-setup-1.51.2.1300.exe
[2011.10.03 13:40:45 | 000,247,053 | ---- | M] () -- C:\Program Files (x86)\mp3DC213.exe
[2011.09.16 06:47:25 | 168,166,968 | ---- | M] () -- C:\Program Files (x86)\OOo_3.3.0_Win_x86_install-wJRE_de.exe
[2011.05.19 12:27:00 | 009,559,320 | ---- | M] (Opera Software ASA) -- C:\Program Files (x86)\Opera_1111_int_Setup.exe
[2011.10.29 11:04:38 | 010,311,496 | ---- | M] (Opera Software ASA) -- C:\Program Files (x86)\Opera_1152_int_Setup.exe
[2011.08.27 11:56:06 | 001,228,384 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\PremiereElements_9_LS15.exe
[2011.10.17 08:29:10 | 001,739,400 | ---- | M] (Secunia) -- C:\Program Files (x86)\PSISetup2003.exe
[2011.10.29 11:50:28 | 039,401,336 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\QuickTimeInstaller.exe
[2011.12.15 11:25:23 | 000,713,472 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer.exe
[2011.09.23 14:09:00 | 000,676,624 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer_1406666_de.exe
[2011.01.19 12:33:04 | 000,475,016 | ---- | M] () -- C:\Program Files (x86)\setup.exe
[2011.05.22 09:35:19 | 021,255,560 | ---- | M] (Skype Technologies S.A.) -- C:\Program Files (x86)\SkypeSetupFull.exe
[2011.08.25 17:58:22 | 006,716,353 | ---- | M] (Mozilla) -- C:\Program Files (x86)\Sunbird_Setup_1.0_Beta_1.exe
[2011.05.19 12:26:19 | 009,326,056 | ---- | M] (Mozilla) -- C:\Program Files (x86)\Thunderbird Setup 3.1.10.exe
[2011.09.23 14:06:06 | 021,073,936 | ---- | M] () -- C:\Program Files (x86)\vlc-1.1.11-win32.exe
[2011.05.19 14:44:11 | 001,663,693 | ---- | M] () -- C:\Program Files (x86)\winrar-x64-400d.exe
[2011.05.19 14:06:01 | 000,767,064 | ---- | M] (NCH Software) -- C:\Program Files (x86)\wpsetup4.57.exe
 
< %LOCALAPPDATA%\*.exe >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.manifest /3 >
[10 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
 
 
< MD5 for: AFD.SYS  >
[2011.04.25 03:44:02 | 000,499,712 | ---- | M] (Microsoft Corporation) MD5=6EF20DDF3172E97D69F596FB90602F29 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16802_none_3430bc3977dfec2d\afd.sys
[2009.07.14 00:21:42 | 000,500,224 | ---- | M] (Microsoft Corporation) MD5=B9384E03479D2506BC924C16A3DB87BC -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16385_none_33dd3439781e25f7\afd.sys
[2010.11.20 10:23:34 | 000,499,712 | ---- | M] (Microsoft Corporation) MD5=D31DC7A16DEA4A9BAF179F3D6FBDB38C -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17514_none_360e4801750ca991\afd.sys
[2011.04.25 03:34:03 | 000,499,200 | ---- | M] (Microsoft Corporation) MD5=D5B031C308A409A0A576BFF4CF083D30 -- C:\Windows\SysNative\drivers\afd.sys
[2011.04.25 03:34:03 | 000,499,200 | ---- | M] (Microsoft Corporation) MD5=D5B031C308A409A0A576BFF4CF083D30 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.17603_none_3618198975057170\afd.sys
[2011.04.25 04:09:35 | 000,499,200 | ---- | M] (Microsoft Corporation) MD5=F4AD06143EAC303F55D0E86C40802976 -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.21712_none_3695e61e8e2c13d4\afd.sys
[2011.04.25 03:44:27 | 000,499,712 | ---- | M] (Microsoft Corporation) MD5=FBFF8B7C9D116229E9208A0D1CAEB49B -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.20951_none_3483491e9126fe55\afd.sys
 
< MD5 for: EXPLORER.EXE  >
[2011.05.15 07:01:23 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_b8b0208ee0ce1889\explorer.exe
[2011.02.26 07:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2011.05.15 07:01:33 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\ERDNT\cache86\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.05.15 07:01:23 | 002,868,736 | ---- | M] (Microsoft Corporation) MD5=6D4F9E4B640B413C6F73414327484C80 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_addea9f19345cd81\explorer.exe
[2011.05.15 07:01:29 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2011.05.15 07:01:33 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2011.05.15 07:01:29 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010.11.20 14:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2011.05.15 07:01:33 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2011.05.15 07:01:29 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009.07.14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2011.05.15 07:01:33 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011.05.15 07:01:23 | 002,868,736 | ---- | M] (Microsoft Corporation) MD5=CA17F8620815267DC838E30B68CB5052 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_ae5b763cac6d568e\explorer.exe
[2011.02.26 07:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2011.05.15 07:01:29 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2011.05.15 07:01:23 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_b8335443c7a68f7c\explorer.exe
 
< MD5 for: REGEDIT.EXE  >
[2009.07.14 02:39:29 | 000,427,008 | ---- | M] (Microsoft Corporation) MD5=2E2C937846A0B8789E5E91739284D17A -- C:\Windows\ERDNT\cache86\regedit.exe
[2009.07.14 02:39:29 | 000,427,008 | ---- | M] (Microsoft Corporation) MD5=2E2C937846A0B8789E5E91739284D17A -- C:\Windows\winsxs\amd64_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_5023a70bf589ad3e\regedit.exe
[2009.07.14 02:39:29 | 000,427,008 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\regedit.exe
[2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\SysWOW64\regedit.exe
[2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\winsxs\wow64_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_5a78515e29ea6f39\regedit.exe
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\ERDNT\cache86\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\ERDNT\cache64\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\ERDNT\cache64\wininit.exe
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\ERDNT\cache86\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\ERDNT\cache64\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2011.05.15 07:01:33 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2011.05.15 07:01:33 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >


Rheingold 16.12.2011 09:43

Code:

OTL Extras logfile created on: 15.12.2011 19:58:30 - Run 8
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Administrator\Desktop\Virus\OTL
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,90 Gb Total Physical Memory | 2,05 Gb Available Physical Memory | 52,57% Memory free
7,79 Gb Paging File | 5,89 Gb Available in Paging File | 75,64% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 235,24 Gb Total Space | 112,40 Gb Free Space | 47,78% Space Free | Partition Type: NTFS
Drive D: | 215,77 Gb Total Space | 206,35 Gb Free Space | 95,63% Space Free | Partition Type: NTFS
 
Computer Name: DELL-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
 
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- Reg Error: Key error.
htmlfile [opennew] -- Reg Error: Key error.
htmlfile [print] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error.
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- Reg Error: Key error.
htmlfile [opennew] -- Reg Error: Key error.
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableSR" = 1
"DisableConfig" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableSR" = 1
"DisableConfig" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Nexon\Combat Arms EU\CombatArms.exe" = C:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\Engine.exe" = C:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\CombatArms.exe" = C:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\Engine.exe" = C:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe -- (Nexon)
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe" = [String data over 1000 bytes]
"C:\Nexon\Combat Arms EU\CombatArms.exe" = C:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\Engine.exe" = C:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe -- (Nexon)
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe" = [String data over 1000 bytes]
"C:\Nexon\Combat Arms EU\CombatArms.exe" = C:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\Engine.exe" = C:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe -- (Nexon)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}" = Kodak AIO Printer
"{290D4DB2-F1B4-4B8E-918D-D71EF29A001B}" = Intel(R) PROSet/Wireless WiFi-Software
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90140000-006D-0407-1000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}" = RBVirtualFolder64Inst
"{9ED333F8-3E6C-4A38-BAFA-728454121CDA}" = PDF-XChange Viewer
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 265.94
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 265.94
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 265.94
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.0.9
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}" = Überwachungstool für die Intel® Turbo-Boost-Technik 2.0
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{BE930E38-7BB3-45B6-85B2-5251F374F844}" = 64 Bit HP CIO Components Installer
"{C7B40C35-85AE-4303-9EEA-1A1EA779664D}" = Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D600D357-5CB9-4DE9-8FD4-14E208BD1970}" = Nero Backup Drivers
"{D66F0C3C-24F2-4463-9E2F-4381E5C40A26}" = iTunes
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"CCleaner" = CCleaner
"Dell Support Center" = Dell Support Center
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinGimp-2.0_is1" = GIMP 2.6.8
"WinRAR archiver" = WinRAR 4.00 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01E9B2FF-DAF4-4529-9CC9-2101625517C7}" = nero.prerequisites.msi
"{034DCAF9-96E7-4936-9A07-712F80B5181E}" = Nero RescueAgent 11
"{0713D1F9-DD77-42C1-8C7D-54D479E2E743}" = Nero SoundTrax 11
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D7A4289-99CF-4B8D-B812-86BE50A54552}" = Nero Video 11
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{11D3EF85-63E1-4AE4-A7C1-9241BDB16B51}" = Nero ControlCenter 11
"{1D4EE8FE-F31C-4258-9360-5B8B8309B14B}" = Adobe Premiere Elements 9 Content
"{1D7CE340-70C3-4848-BCCF-215950328A4C}" = Facebook Video Calling 1.0.0.8953
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{25175695-4B20-4298-9F34-C2C57CD277B3}" = Elements STI Installer
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java(TM) 6 Update 29
"{27107EAA-34E0-43BF-B537-7F8EF6880F5A}" = Facebook Video Calling 1.0.0.8177
"{289AC7E0-0AEE-4a7b-913C-709D9803D23E}" = Nexon Game Manager
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2CA7225D-CB12-462A-9DD1-50319E158BA5}" = Nero 11 PiP Effects Basic
"{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5
"{3250260C-7A95-4632-893B-89657EB5545B}" = PhotoShowExpress
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{3443D416-9DAD-4362-BEB1-C213AD9062CD}" = Dell MusicStage
"{376348C2-E372-48BC-A138-E896757BD86A}" = aioscnnr
"{37AB0223-AF54-49C5-92AA-BFC9648CD323}" = Adobe Premiere Elements 9 HD Content 3
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{390757AA-8830-43DC-AEE0-4E5B6F8439EB}" = Nero SoundTrax 11 Help (CHM)
"{3CBBE028-978B-4876-ABC1-EF9ED6C20C4E}" = Adobe Premiere Elements 9 Content 2
"{3EE2F527-F306-49E9-0086-662C337ADD3B}" = FUSSBALL MANAGER 07
"{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C}" = FIFA 11
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{433EACD8-4747-4A6A-826A-FFA9F39B0D40}" = Elements 9 Organizer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50D90C59-4F5C-48BC-AFB2-38475412F0CA}" = Adobe Premiere Elements 9 Content 1
"{53F7746A-96AA-49A5-86B8-59989680DAC5}" = Nero Burning ROM 11 Help (CHM)
"{55C2143E-FBA5-442F-9AFA-726FF068F39D}" = Nero CoverDesigner 11 Help (CHM)
"{56BA241F-580C-43D2-8403-947241AAE633}" = center
"{57F80ECF-E27C-4EEE-AB58-E971BACE2639}" = Nero Recode 11 Help (CHM)
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{5A212B2D-140D-46F4-B625-2D1CA5A00594}" = Nero 11 Kwik Themes Basic
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5F9AAF4A-B9B0-489D-AE67-73470A4714FE}" = Adobe Premiere Elements 9 HD Content 1
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6AB2427E-A18F-4809-9A12-29F5EBABBB3A}" = Nero BackItUp 11 Help (CHM)
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}" = Roxio Creator Starter
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7746BFAA-2B5D-4FFD-A0E8-4558F4668105}" = Roxio Burn
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7DDC3624-C631-49D1-B281-82EC3A27AA7C}" = Adobe Premiere Elements 9 Content 3
"{7EC66A95-AC2D-4127-940B-0445A526AB2F}" = Dell DataSafe Online
"{8014FACB-1D1D-48C2-94AA-E29EE2E6B9CE}" = Nero WaveEditor 11
"{81DD0597-29EB-4FA0-8223-4F41362B2E72}" = NBA 2K11
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{87434D51-51DB-4109-B68F-A829ECDCF380}" = AccelerometerP11
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch
"{9193490D-5229-4FC4-9BB9-A6D63C09574A}" = High-Definition Video Playback
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Sonic CinePlayer Decoder Pack
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet-TV für Windows Media Center
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A7A0BF2E-31CC-49E3-9913-52C503EB969D}" = Nero Audio Pack 1
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AB2BBC64-8AC8-4E66-BBF3-E22D5EACEECA}" = Nero BackItUp 11
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B1846721-A8E6-46C7-83B6-0DCF7ADB4267}" = Nero Burning ROM 11
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B7E01095-8BAA-456E-8AED-504C3CCADBA0}" = Nero 11
"{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"{B9B1BA7F-7E07-49DD-A713-5B397A5BB66B}" = Nero Kwik Media Help (CHM)
"{BE814218-3919-4EA3-868A-2F60BC135CB4}" = Nero Kwik Media
"{BE94C681-68E2-4561-8ABC-8D2E799168B4}" = essentials
"{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components 11
"{BFBCF96F-7361-486A-965C-54B17AC35421}" = ocr
"{C19BE821-89B1-4A96-AC7C-873810C0CB5F}" = ContentSAFER for Wizmax
"{C20CE592-B0F8-4D20-BF31-0151CA6331A6}" = EmoDio
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{CCE210DF-7EEF-4A76-A63C-3EB091FDB992}" = welcome
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D01CE99A-8802-483C-A79F-298B691EB432}" = Nero RescueAgent 11 Help (CHM)
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D2CBEFA4-F2D3-4E97-A171-8BFD6A31A5EC}" = Nero Express 11 Help (CHM)
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4D66270-9147-4BDF-9946-FCA2B303AA8F}" = Nero ControlCenter 11 Help (CHM)
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DC0C5A78-6DBF-3444-0120-0FE8F0134FCD}" = Adobe Download Assistant
"{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK All-in-One Software
"{E10AAE4A-98B8-420A-BD93-E0520C23D624}" = Nero Express 11
"{E240C78D-8F35-456A-8876-15FF6901B7E0}" = Adobe Premiere Elements 9 HD Content 2
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E4335E82-17B3-460F-9E70-39D9BC269DB3}" = Dell PhotoStage
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E51BC4B0-EA5E-49CC-AF3B-93B5C627EC22}" = Nero 11 Effects Basic
"{E9F59205-F128-49A7-9039-4BDFB60EE4A3}" = Dell Stage
"{EB8DED20-A887-4A9C-BB5A-F3E7523DFB44}" = Nero WaveEditor 11 Help (CHM)
"{EB9955F8-467C-47FC-90F8-12CD5DF684C3}" = Adobe Premiere Elements 9
"{EC7FE03D-239A-4E36-9907-0E327922D2A2}" = bpd_scan
"{EF53BFAB-4C10-40DB-A82D-9B07111715C6}" = aioscnnr
"{EF56258E-0326-48C5-A86C-3BAC26FC15DF}" = Roxio Creator Starter
"{F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}" = Roxio Creator Starter
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F302F4F0-588D-6501-1ACF-BE3FDCC9135D}" = Adobe Community Help
"{F3743A2C-5D5F-4456-8F98-5DF36A954C50}" = Nero 11 Image Samples
"{F49EF443-B2BD-4F10-8A46-87AFCDB90EDD}" = Nero 11 Disc Menus Basic
"{F69FB940-5031-4FE8-AFAD-085802D0BF63}" = Nero Recode 11
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FAC3C37E-EDAB-4F3A-A173-A7C70CC88F09}" = Nero Video 11 Help (CHM)
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF44BCE5-5A18-4051-85F0-BC172D7B4695}" = Nero CoverDesigner 11
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Premiere Elements 9 Content" = Adobe Premiere Elements 9 Content
"Adobe Premiere Elements 9 Content 1" = Adobe Premiere Elements 9 Content 1
"Adobe Premiere Elements 9 Content 2" = Adobe Premiere Elements 9 Content 2
"Adobe Premiere Elements 9 Content 3" = Adobe Premiere Elements 9 Content 3
"Adobe Premiere Elements 9 HD Content 1" = Adobe Premiere Elements 9 HD Content 1
"Adobe Premiere Elements 9 HD Content 2" = Adobe Premiere Elements 9 HD Content 2
"Adobe Premiere Elements 9 HD Content 3" = Adobe Premiere Elements 9 HD Content 3
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Akamai" = Akamai NetSession Interface Service
"AVerMedia H339 Hybrid TV Tuner" = AVerMedia H339 Hybrid TV Tuner 2.2.64.64
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BewerbungsGenie 7_is1" = DATA BECKER BewerbungsGenie 7
"BurningWheels" = Cobra 11 - Burning Wheels (remove only)
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"Combat Arms EU" = Combat Arms EU
"Dell Webcam Central" = Dell Webcam Central
"ExpressBurn" = Express Burn Disc Burning Software
"ExpressRip" = Express Rip
"Free YouTube to iPod Converter_is1" = Free YouTube to iPod Converter version 3.10.8.815
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.8.815
"InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5
"InstallShield_{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0
"InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"InstallShield_{C20CE592-B0F8-4D20-BF31-0151CA6331A6}" = EmoDio
"InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"Kindersicherung_is1" = Kindersicherung 2011
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.2.1300
"MixPad" = MixPad Audio Mixer
"Mozilla Firefox 8.0 (x86 de)" = Mozilla Firefox 8.0 (x86 de)
"Mozilla Thunderbird (8.0)" = Mozilla Thunderbird (8.0)
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.Click2Run" = Microsoft Office Klick-und-Los 2010
"Opera 11.52.1100" = Opera 11.52
"PremElem90" = Adobe Premiere Elements 9
"Prism" = Prism Video File Converter
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"RealPlayer 15.0" = RealPlayer
"Secunia PSI" = Secunia PSI (2.0.0.3003)
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.1.11
"WavePad" = WavePad Sound Editor
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
 
========== Last 10 Event Log Errors ==========
 
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
 
< End of report >


Rheingold 16.12.2011 09:45

Hier nun die Ergebnisse von CCleaner:
7-Zip 9.20 (x64 edition) Igor Pavlov 22.09.2011 4,53MB 9.20.00.0
AccelerometerP11 STMicroelectronics 13.05.2011 2.00.11.22
Adobe AIR Adobe Systems Incorporated 11.11.2011 3.1.0.4880
Adobe Community Help Adobe Systems Incorporated 11.09.2011 3.2.1.650
Adobe Download Assistant Adobe Systems Incorporated 30.09.2011 1.0.5
Adobe Flash Player 11 ActiveX Adobe Systems Incorporated 13.12.2011 6,00MB 11.1.102.55
Adobe Flash Player 11 Plugin 64-bit Adobe Systems Incorporated 11.11.2011 6,00MB 11.1.102.55
Adobe Premiere Elements 9 Adobe Systems Incorporated 28.10.2011 1.264MB 9.0
Adobe Premiere Elements 9 Content Adobe Systems Incorporated 28.10.2011 1.264MB 9.0
Advanced Audio FX Engine Creative Technology Ltd 11.09.2011 1.12.05
Akamai NetSession Interface 09.11.2011
Akamai NetSession Interface Service 09.11.2011
Apple Application Support Apple Inc. 17.10.2011 61,1MB 2.1.5
Apple Mobile Device Support Apple Inc. 17.10.2011 24,4MB 4.0.0.96
Apple Software Update Apple Inc. 22.09.2011 2,38MB 2.1.3.127
AVerMedia H339 Hybrid TV Tuner 2.2.64.64 AVerMedia TECHNOLOGIES, Inc. 11.09.2011 2.2.64.64
Avira AntiVir Personal - Free Antivirus Avira GmbH 13.10.2011 70,6MB 10.2.0.704
Bonjour Apple Inc. 17.10.2011 2,00MB 3.0.0.10
CCleaner Piriform 14.12.2011 3.13
Cobra 11 - Burning Wheels (remove only) 11.09.2011
Combat Arms EU 01.12.2011
ContentSAFER for Wizmax 13.05.2011
DATA BECKER BewerbungsGenie 7 DATA BECKER GmbH & Co. KG 30.05.2011 1.130MB 6.0.10.49
Dell DataSafe Local Backup Dell 13.05.2011 9.4.47
Dell DataSafe Local Backup - Support Software Dell 13.05.2011
Dell DataSafe Online Dell 13.05.2011 6,46MB 2.1.19634
Dell Getting Started Guide Dell Inc. 13.05.2011 1.00.0000
Dell MusicStage Fingertapps 11.07.2011 88,7MB 1.5.402.0
Dell PhotoStage ArcSoft 13.05.2011 101,8MB 1.5.0.30
Dell Stage Fingertapps 29.06.2011 82,6MB 1.5.420.0
Dell Support Center Dell Inc. 14.05.2011 3.0.5621.01
Dell VideoStage CyberLink Corp. 13.05.2011 1.1.1.1408
Dell Webcam Central Creative Technology Ltd 11.09.2011 2.00.35
EmoDio SAMSUNG 20.06.2011 7,69MB 1.0
Express Burn Disc Burning Software NCH Software 11.09.2011
Express Rip NCH Software 11.09.2011
Facebook Video Calling 1.0.0.8953 Skype Limited 14.11.2011 7,86MB 1.0.8953
FIFA 11 Electronic Arts 06.11.2011 6.262MB 1.0.0.0
Free YouTube to iPod Converter version 3.10.8.815 DVDVideoSoft Ltd. 30.09.2011 42,9MB
Free YouTube to MP3 Converter version 3.10.8.815 DVDVideoSoft Ltd. 30.09.2011 45,4MB
FUSSBALL MANAGER 07 11.09.2011
GIMP 2.6.8 18.05.2011
Google Earth Google 17.11.2011 92,7MB 6.1.0.5001
Intel(R) Management Engine Components Intel Corporation 15.05.2011 7.0.0.1144
Intel(R) Processor Graphics Intel Corporation 11.09.2011 74,2MB 8.15.10.2291
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology Intel Corporation 13.05.2011 88,6MB 1.0.2.0511
Intel(R) PROSet/Wireless WiFi-Software Intel Corporation 13.05.2011 142,9MB 14.00.1000
Internet-TV für Windows Media Center Microsoft Corporation 02.06.2011 13,7MB 4.2.2.0
iTunes Apple Inc. 17.10.2011 169,9MB 10.5.0.142
Java(TM) 6 Update 22 13.05.2011
Java(TM) 6 Update 29 Oracle 28.10.2011 95,0MB 6.0.290
Kindersicherung 2011 Salfeld Computer GmbH 09.10.2011 64,6MB
KODAK All-in-One Software Eastman Kodak Company 23.11.2011 7.1.6.30
Malwarebytes' Anti-Malware Version 1.51.2.1300 Malwarebytes Corporation 28.10.2011 13,8MB 1.51.2.1300
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 19.05.2011 38,8MB 4.0.30319
Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Corporation 19.05.2011 2,94MB 4.0.30319
Microsoft Office 2010 Microsoft Corporation 13.05.2011 6,31MB 14.0.4763.1000
Microsoft Office Klick-und-Los 2010 Microsoft Corporation 10.11.2011 14.0.4763.1000
Microsoft Office Starter 2010 - Deutsch Microsoft Corporation 10.11.2011 14.0.4763.1000
Microsoft Silverlight Microsoft Corporation 13.10.2011 80,3MB 4.0.60831.0
Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 13.05.2011 1,70MB 3.1.0000
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 23.05.2011 0,25MB 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 15.06.2011 0,29MB 8.0.59193
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 18.05.2011 0,77MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 18.05.2011 0,77MB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 15.06.2011 0,77MB 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 06.11.2011 0,23MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 18.05.2011 0,58MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 18.05.2011 0,57MB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 15.06.2011 0,59MB 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 08.10.2011 13,8MB 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 08.10.2011 15,0MB 10.0.40219
MixPad Audio Mixer NCH Software 11.09.2011
Mozilla Firefox 8.0 (x86 de) Mozilla 10.11.2011 41,3MB 8.0
Mozilla Thunderbird (8.0) Mozilla 10.11.2011 8.0 (de)
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 18.05.2011 1,28MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 18.05.2011 1,33MB 4.20.9876.0
NBA 2K11 2K Sports 17.09.2011 1.0.0
Nero 11 Nero AG 06.10.2011 1.760MB 11.0.10700
Nero Backup Drivers Nero AG 06.10.2011 94,00KB 1.0.10000.1.0
Nexon Game Manager 01.12.2011
NVIDIA 3D Vision Treiber 265.94 NVIDIA Corporation 13.05.2011 265.94
NVIDIA Grafiktreiber 265.94 NVIDIA Corporation 13.05.2011 265.94
OpenOffice.org 3.3 OpenOffice.org 15.09.2011 415MB 3.3.9567
Opera 11.52 Opera Software ASA 28.10.2011 11.52.1100
PDF-XChange Viewer Tracker Software Products Ltd. 22.09.2011 44,7MB 2.5.198.0
PlayReady PC Runtime amd64 Microsoft Corporation 20.05.2011 2,06MB 1.3.0
Prism Video File Converter NCH Software 13.09.2011
Protect Disc License Helper 1.0.125 (IE) Protect Disc 30.05.2011 1.0.125
ProtectDisc Driver, Version 11 ProtectDisc Software GmbH 11.09.2011 11.0.0.14
Quickset64 Dell Inc. 13.05.2011 11.0.10
QuickTime Apple Inc. 28.10.2011 73,3MB 7.71.80.42
RealPlayer RealNetworks 20.10.2011
Realtek High Definition Audio Driver Realtek Semiconductor Corp. 11.09.2011 6.0.1.6267
Roxio Creator Starter Roxio 11.09.2011 1.673MB 12.1.77.0
Secunia PSI (2.0.0.3003) 16.10.2011
Skype Click to Call Skype Technologies S.A. 30.09.2011 14,5MB 5.6.8312
Skype™ 5.5 Skype Technologies S.A. 28.10.2011 17,1MB 5.5.124
SmartSound Common Data SmartSound Software Inc. 16.06.2011 13,5MB 1.1.0
SmartSound Quicktracks 5 SmartSound Software Inc. 16.06.2011 49,2MB 5.1.6
SmartSound Quicktracks for Premiere Elements 9.0 SmartSound Software Inc 26.08.2011 20,1MB 3.12.3090
Synaptics Pointing Device Driver Synaptics Incorporated 14.05.2011 46,4MB 15.2.6.0
Uninstall 1.0.0.1 27.05.2011 11,2MB
VLC media player 1.1.11 VideoLAN 22.09.2011 1.1.11
WavePad Sound Editor NCH Software 11.09.2011
Windows Live Essentials Microsoft Corporation 06.08.2011 15.4.3538.0513
Windows Live Mesh ActiveX control for remote connections Microsoft Corporation 13.05.2011 5,58MB 15.4.5722.2
Windows Media Encoder 9 Series 11.09.2011
WinRAR 4.00 (64-Bit) win.rar GmbH 18.05.2011 4.00.0
Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 Intel 13.05.2011 2.1.23.0

Rheingold 16.12.2011 10:05

Hier die Ereignisse von Avira:
Exportierte Ereignisse:

15.12.2011 18:46 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 18:46 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 11:25 [Scanner] Malware gefunden
Die Datei '#PARAM2#'
enthielt einen Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#].
Durchgeführte Aktion(en):
#PARAM4#

15.12.2011 11:25 [Scanner] Malware gefunden
Die Datei '#PARAM2#'
enthielt einen Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#].
Durchgeführte Aktion(en):
#PARAM4#

15.12.2011 11:22 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 11:22 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 11:22 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 11:22 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 11:22 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 11:19 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 11:19 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 11:19 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 08:35 [Scanner] Malware gefunden
Die Datei '#PARAM2#'
enthielt einen Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#].
Durchgeführte Aktion(en):
#PARAM4#

15.12.2011 08:35 [Scanner] Malware gefunden
Die Datei '#PARAM2#'
enthielt einen Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#].
Durchgeführte Aktion(en):
#PARAM4#

15.12.2011 08:35 [Scanner] Malware gefunden
Die Datei '#PARAM2#'
enthielt einen Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#].
Durchgeführte Aktion(en):
#PARAM4#

15.12.2011 08:31 [Scanner] Malware gefunden
Die Datei '#PARAM2#'
enthielt einen Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#].
Durchgeführte Aktion(en):
#PARAM4#

15.12.2011 08:31 [Scanner] Malware gefunden
Die Datei '#PARAM2#'
enthielt einen Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#].
Durchgeführte Aktion(en):
#PARAM4#

15.12.2011 08:28 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 08:28 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 08:28 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 08:28 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 08:28 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 08:04 [Scanner] Malware gefunden
Die Datei '#PARAM2#'
enthielt einen Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#].
Durchgeführte Aktion(en):
#PARAM4#

15.12.2011 08:02 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 08:00 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 08:00 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

15.12.2011 08:00 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

14.12.2011 08:41 [Scanner] Malware gefunden
Die Datei '#PARAM2#'
enthielt einen Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#].
Durchgeführte Aktion(en):
#PARAM4#

14.12.2011 08:38 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

14.12.2011 08:38 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

14.12.2011 08:38 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

13.12.2011 20:20 [Scanner] Malware gefunden
Die Datei '#PARAM2#'
enthielt einen Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#].
Durchgeführte Aktion(en):
#PARAM4#

13.12.2011 20:17 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

13.12.2011 20:17 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

13.12.2011 20:17 [Guard] Malware gefunden
In der Datei '#PARAM2#'
wurde ein Virus oder unerwünschtes Programm '#PARAM1#' [#PARAM3#] gefunden.
Ausgeführte Aktion: #PARAM4#

Rheingold 16.12.2011 10:08

P.s.: Heute früh ha avira auch noch was gefunden, ist aber nicht unter Ereignisse dokumentiert, aber in der Quarantäne. Die Quarantänte.txt, stelle ich mal mit rein. Viele Grüße, Jasmina

Typ: Datei
Quelle: C:\Users\Nico.dell-PC.000\AppData\Local\temp\jar_cache2940790001441072158.tmp
Status: Infiziert
Quarantäne-Objekt: 659a9f32.qua
Wiederhergestellt: NEIN
Zu Avira hochgeladen: NEIN
Betriebssystem: Windows 2000/XP/VISTA Workstation
Suchengine: 8.02.08.02
Virendefinitionsdatei: 7.11.19.128
Meldung: Enthält Erkennungsmuster des Exploits EXP/CVE-2010-0840.GK
Datum/Uhrzeit: 16.12.2011, 09:57


Typ: Datei
Quelle: C:\Users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\737u.exe
Status: Infiziert
Quarantäne-Objekt: 491aa5ed.qua
Wiederhergestellt: NEIN
Zu Avira hochgeladen: NEIN
Betriebssystem: Windows 2000/XP/VISTA Workstation
Suchengine: 8.02.08.02
Virendefinitionsdatei: 7.11.19.128
Meldung: Enthält ein Erkennungsmuster des (gefährlichen) Backdoorprogrammes BDS/Cycbot.G.196
Datum/Uhrzeit: 16.12.2011, 09:57


Typ: Datei
Quelle: C:\Users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\10F2.tmp
Status: Infiziert
Quarantäne-Objekt: 519e8a57.qua
Wiederhergestellt: NEIN
Zu Avira hochgeladen: NEIN
Betriebssystem: Windows 2000/XP/VISTA Workstation
Suchengine: 8.02.08.02
Virendefinitionsdatei: 7.11.19.128
Meldung: Ist das Trojanische Pferd TR/Drop.Agent.104448.2
Datum/Uhrzeit: 16.12.2011, 09:57


Typ: Datei
Quelle: C:\Users\Nico.dell-PC.000\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9P12EUMN\bleh[1].exe
Status: Infiziert
Quarantäne-Objekt: 5f088066.qua
Wiederhergestellt: NEIN
Zu Avira hochgeladen: NEIN
Betriebssystem: Windows 2000/XP/VISTA Workstation
Suchengine: 8.02.08.02
Virendefinitionsdatei: 7.11.19.128
Meldung: Enthält ein Erkennungsmuster des (gefährlichen) Backdoorprogrammes BDS/Cycbot.G.196
Datum/Uhrzeit: 16.12.2011, 09:57


Typ: Datei
Quelle: C:\Users\Nico.dell-PC.000\AppData\Local\temp\jar_cache3335764138695990157.tmp
Status: Infiziert
Quarantäne-Objekt: 03add0f0.qua
Wiederhergestellt: NEIN
Zu Avira hochgeladen: NEIN
Betriebssystem: Windows 2000/XP/VISTA Workstation
Suchengine: 8.02.08.02
Virendefinitionsdatei: 7.11.19.128
Meldung: Enthält Erkennungsmuster des Exploits EXP/2010-0840.AW
Datum/Uhrzeit: 16.12.2011, 09:57


Typ: Datei
Quelle: C:\Users\Nico.dell-PC.000\AppData\Local\4d0d2e25\X
Status: Infiziert
Quarantäne-Objekt: 6fd8ec26.qua
Wiederhergestellt: NEIN
Zu Avira hochgeladen: NEIN
Betriebssystem: Windows 2000/XP/VISTA Workstation
Suchengine: 8.02.08.02
Virendefinitionsdatei: 7.11.19.128
Meldung: Ist das Trojanische Pferd TR/Downloader.Gen
Datum/Uhrzeit: 16.12.2011, 09:57


Typ: Datei
Quelle: C:\Users\Nico.dell-PC.000\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1WHIKJDB\b[1].exe
Status: Infiziert
Quarantäne-Objekt: 13fcac1d.qua
Wiederhergestellt: NEIN
Zu Avira hochgeladen: NEIN
Betriebssystem: Windows 2000/XP/VISTA Workstation
Suchengine: 8.02.08.02
Virendefinitionsdatei: 7.11.19.128
Meldung: Ist das Trojanische Pferd TR/Offend.KD.474345
Datum/Uhrzeit: 16.12.2011, 09:57


Typ: Datei
Quelle: C:\Users\Nico.dell-PC.000\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9P12EUMN\f[1].exe
Status: Infiziert
Quarantäne-Objekt: 205fb236.qua
Wiederhergestellt: NEIN
Zu Avira hochgeladen: NEIN
Betriebssystem: Windows 2000/XP/VISTA Workstation
Suchengine: 8.02.08.02
Virendefinitionsdatei: 7.11.19.128
Meldung: Ist das Trojanische Pferd TR/Kazy.48489
Datum/Uhrzeit: 16.12.2011, 09:57


Typ: Datei
Quelle: C:\Users\Nico.dell-PC.000\AppData\Local\temp\1951057.exe
Status: Infiziert
Quarantäne-Objekt: 4ada5911.qua
Wiederhergestellt: NEIN
Zu Avira hochgeladen: NEIN
Betriebssystem: Windows 2000/XP/VISTA Workstation
Suchengine: 8.02.08.02
Virendefinitionsdatei: 7.11.19.128
Meldung: Ist das Trojanische Pferd TR/Kazy.48489
Datum/Uhrzeit: 16.12.2011, 09:49


Typ: Datei
Quelle: C:\Program Files (x86)\LP\A7CB\F180.tmp
Status: Infiziert
Quarantäne-Objekt: 499a5915.qua
Wiederhergestellt: NEIN
Zu Avira hochgeladen: NEIN
Betriebssystem: Windows 2000/XP/VISTA Workstation
Suchengine: 8.02.08.02
Virendefinitionsdatei: 7.11.19.128
Meldung: Ist das Trojanische Pferd TR/Spy.Favic.A
Datum/Uhrzeit: 16.12.2011, 09:49

kira 17.12.2011 06:59

1.
Hast Du absichtlich die IP 127.0.0.1:50263 als Proxy eingestellt? Wenn ja, warum? Wenn nein:
wenn du keinen Proxyserver lokal installiert hast, nimm die Proxyeinstellungen aus den Interneteinstellungen raus
im Internet Explorer:
Extras => Internetoptionen => Verbindungen => Lan-Einstellungen
Haken bei Proxyserver für LAN verwenden und Proxyserver für lokale Adressen umgehen entfernen.

Zitat:

IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50263
im Firefox:
Extras => Einstellungen => Erweitert => Netzwerk => Einstellungen.
Dort unter Verbindungs-Einstellungen => Kein Proxy anhaken.


Zitat:

FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50263
FF - prefs.js..network.proxy.type: 1
2.
Dir bekannte Einträge? (ggf unter "Eigenschaften" nachsehen):
Zitat:

[2011.12.15 08:29:11 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Desktop\Virus
[2011.12.15 11:22:52 | 000,000,000 | -HSD | C] -- C:\Users\Administrator\AppData\Local\4d0d2e25
3.
Zitat:

Achtung wichtig!:
Falls Du selber im Logfile Änderungen vorgenommen hast, musst Du durch die Originalbezeichnung ersetzen und so in Script einfügen! sonst funktioniert nicht!
(Benutzerordner, dein Name oder sonstige Änderungen durch X, Stern oder andere Namen ersetzt)
Fixen mit OTL
  • Starte die OTL.exe.
  • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
  • Kopiere folgendes Skript:
Code:

:OTL
PRC - C:\Program Files (x86)\57168\lvvm.exe ()
PRC - C:\Users\Administrator\AppData\Roaming\B8457\6D1A7.exe ()
PRC - C:\Program Files (x86)\LP\A7CB\737.exe ()
MOD - C:\Program Files (x86)\57168\lvvm.exe ()
MOD - C:\Users\Administrator\AppData\Roaming\B8457\6D1A7.exe ()
MOD - C:\Program Files (x86)\LP\A7CB\737.exe ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
[2011.09.29 02:16:42 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011.09.29 02:24:37 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O4 - HKLM..\Run: [737.exe] C:\Program Files (x86)\LP\A7CB\737.exe ()
O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" File not found
O4 - HKLM..\Run: [Conime] %windir%\system32\conime.exe File not found
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe File not found
O4 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Nico.dell-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Überwachungstool für die Intel® Turbo-Boost-Technik 2.0.lnk =  File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Privacy present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present
[2011.12.15 11:19:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\57168
[2011.12.15 11:19:19 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\B8457
[2011.12.15 19:57:00 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1004UA.job
[2011.12.15 19:30:16 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.12.15 19:06:12 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.12.15 11:18:00 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1003UA.job
[2011.12.14 20:28:00 | 000,000,926 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025Core.job
[2011.12.14 20:18:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1003Core.job
[2011.12.14 08:38:00 | 000,000,390 | ---- | M] () -- C:\Windows\tasks\At2.job
[2011.12.14 08:34:00 | 000,000,408 | ---- | M] () -- C:\Windows\tasks\At1.job
[2011.12.12 16:57:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1004Core.job

:Commands
[purity]
[emptytemp]


4.
reinige dein System mit CCleaner:
  • "Cleaner"→ "Analysieren"→ Klick auf den Button "Start CCleaner"
  • "Registry""Fehler suchen"→ "Fehler beheben"→ "Alle beheben"
  • Starte dein System neu auf

5.
  • lade Dir SUPERAntiSpyware FREE Edition herunter.
  • installiere das Programm und update online.
  • starte SUPERAntiSpyware und klicke auf "Ihren Computer durchsuchen"
  • setze ein Häkchen bei "Kompletter Scan" und klicke auf "Weiter"
  • anschließend alle gefundenen Schadprogramme werden aufgelistet, bei alle Funde Häkchen setzen und mit "OK" bestätigen
  • auf "Weiter" klicken dann "OK" und auf "Fertig stellen"
  • um die Ergebnisse anzuzeigen: auf "Präferenzen" dann auf den "Statistiken und Protokolle" klicken
  • drücke auf "Protokoll anzeigen" - anschließend diesen Bericht bitte speichern und hier posten

6.
Auch auf USB-Sticks, selbstgebrannten Datenträgern, externen Festplatten und anderen Datenträgern können Viren transportiert werden. Man muss daher durch regelmäßige Prüfungen auf Schäden, die durch Malware ("Worm.Win32.Autorun") verursacht worden sein können, überwacht werden. Hierfür sind ser gut geegnet und empfohlen, die auf dem Speichermedium gesicherten Daten, mit Hilfe des kostenlosen Online Scanners zu prüfen.
Schließe jetzt alle externe Datenträgeran (USB Sticks etc) Deinen Rechner an, dabei die Hochstell-Taste [Shift-Taste] gedrückt halten, damit die Autorun-Funktion nicht ausgeführt wird. (So verhindest Du die Ausführung der AUTORUN-Funktion) - Man kann die AUTORUN-Funktion aber auch generell abschalten.►Anleitung

7.
-> Führe dann einen Komplett-Systemcheck mit Eset Online Scanner (NOD32)Kostenlose Online Scanner durch
Achtung!: >>Du sollst nicht die Antivirus-Sicherheitssoftware installieren, sondern dein System nur online scannen<<

8.
erneut einen Scan mit OTL:
  • Doppelklick auf die OTL.exe
  • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
  • Oben findest Du ein Kästchen mit Ausgabe.
    Wähle bitte Standard-Ausgabe
  • Unter Extra-Registrierung wähle bitte Benutze SafeList.
  • Mache Häckchen bei LOP- und Purity-Prüfung.
  • Klicke nun auf Scan links oben.
  • Wenn der Scan beendet wurde werden zwei Logfiles erstellt.
    Du findest die Logfiles auf Deinem Desktop => OTL.txt und Extras.txt
  • Poste die Logfiles in Code-Tags hier in den Thread.

Zitat:

Damit dein Thread übersichtlicher und schön lesbar bleibt, am besten nutze den Code-Tags für deinen Post:
→ vor dein Log schreibst Du (also am Anfang des Logfiles):[code]
hier kommt dein Logfile rein - z.B OTL-Logfile o. sonstiges
→ dahinter - also am Ende der Logdatei: [/code]


Rheingold 18.12.2011 08:03

Hallo Kira,
1.
die IP 127.0.0.1:50263 habe ich nicht als Proxy eingestellt.? Ist mir aber aufgefallen und ich habe die Einstellung schon rausgenommen.


2.
Dir bekannte Einträge? (ggf unter "Eigenschaften" nachsehen):
Zitat:
[2011.12.15 08:29:11 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Desktop\Virus Das ist ein Ordner, den ich angelegt habe.

[2011.12.15 11:22:52 | 000,000,000 | -HSD | C] -- C:\Users\Administrator\AppData\Local\4d0d2e25 Diesen Eintrag kenne ich nicht.


Den Rest stelle ich dann später rein.

Vielen, vielen Dank! :dankeschoen:

Rheingold 18.12.2011 08:25

:
Code:

All processes killed
========== OTL ==========
No active process named Program Files was found!
No active process named 6D1A7.exe was found!
No active process named Program Files was found!
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully.
C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully.
File C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll not found.
C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml moved successfully.
C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml moved successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\737.exe not found.
File C:\Program Files (x86)\LP\A7CB\737.exe not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\AccuWeatherWidget deleted successfully.
C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Conime deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\EKIJ5000StatusMonitor deleted successfully.
Registry value HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
C:\Users\Nico.dell-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Überwachungstool für die Intel® Turbo-Boost-Technik 2.0.lnk moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Privacy\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
C:\Program Files (x86)\57168 folder moved successfully.
C:\Users\Administrator\AppData\Roaming\B8457 folder moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1004UA.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1003UA.job moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025Core.job moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1003Core.job moved successfully.
C:\Windows\Tasks\At2.job moved successfully.
C:\Windows\Tasks\At1.job moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1004Core.job moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 27038607 bytes
->Temporary Internet Files folder emptied: 49440123 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 73987108 bytes
->Opera cache emptied: 1191820 bytes
->Flash cache emptied: 58352 bytes
 
User: All Users
 
User: AppData
->Temp folder emptied: 0 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56475 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Gast
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Jasmina
->Temp folder emptied: 444971 bytes
->Temporary Internet Files folder emptied: 1508823 bytes
->Java cache emptied: 11680 bytes
->FireFox cache emptied: 37421722 bytes
->Flash cache emptied: 57120 bytes
 
User: Jasmina 2
 
User: Nico
 
User: Nico Spiele
 
User: Nico.dell-PC
 
User: Nico.dell-PC.000
->Temp folder emptied: 167157564 bytes
->Temporary Internet Files folder emptied: 16506810 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 43839688 bytes
->Flash cache emptied: 9097 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50635 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 668 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 399,00 mb
 
 
OTL by OldTimer - Version 3.2.31.0 log created on 12182011_081200

Files\Folders moved on Reboot...
C:\Users\Administrator\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...
:


Rheingold 18.12.2011 13:36

:
Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 12/17/2011 at 12:25 PM

Application Version : 5.0.1142

Core Rules Database Version : 8064
Trace Rules Database Version: 5876

Scan type      : Complete Scan
Total Scan Time : 02:31:32

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC Off - Administrator

Memory items scanned      : 719
Memory threats detected  : 0
Registry items scanned    : 76927
Registry threats detected : 0
File items scanned        : 257414
File threats detected    : 220

Adware.Tracking Cookie
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\QM1OTRD9.txt [ /atdmt.com ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\F988I3Z6.txt [ /media6degrees.com ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\O1FN8N2S.txt [ /webmasterplan.com ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\EU6URGFJ.txt [ /perf.overture.com ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\5DJIVMO1.txt [ /www.usenext.de ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\NET4DBKT.txt [ /2o7.net ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\KKIFEF7R.txt [ /account.live.com ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\D3IYFCK0.txt [ /invitemedia.com ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\08H9M60T.txt [ /lucidmedia.com ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\8F6RXOS9.txt [ /doubleclick.net ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\MFYXIJ15.txt [ /ad.yieldmanager.com ]
        C:\USERS\ADMINISTRATOR\Cookies\QM1OTRD9.txt [ Cookie:administrator@atdmt.com/ ]
        C:\USERS\ADMINISTRATOR\Cookies\F988I3Z6.txt [ Cookie:administrator@media6degrees.com/ ]
        C:\USERS\ADMINISTRATOR\Cookies\O1FN8N2S.txt [ Cookie:administrator@webmasterplan.com/ ]
        C:\USERS\ADMINISTRATOR\Cookies\EU6URGFJ.txt [ Cookie:administrator@perf.overture.com/ ]
        C:\USERS\ADMINISTRATOR\Cookies\5DJIVMO1.txt [ Cookie:administrator@www.usenext.de/ ]
        C:\USERS\ADMINISTRATOR\Cookies\NET4DBKT.txt [ Cookie:administrator@2o7.net/ ]
        C:\USERS\ADMINISTRATOR\Cookies\KKIFEF7R.txt [ Cookie:administrator@account.live.com/ ]
        C:\USERS\ADMINISTRATOR\Cookies\08H9M60T.txt [ Cookie:administrator@lucidmedia.com/ ]
        C:\USERS\ADMINISTRATOR\Cookies\8F6RXOS9.txt [ Cookie:administrator@doubleclick.net/ ]
        C:\USERS\ADMINISTRATOR\Cookies\MFYXIJ15.txt [ Cookie:administrator@ad.yieldmanager.com/ ]
        C:\USERS\NICO.DELL-PC.000\AppData\Roaming\Microsoft\Windows\Cookies\Q24G170D.txt [ Cookie:nico@2o7.net/ ]
        C:\USERS\NICO.DELL-PC.000\AppData\Roaming\Microsoft\Windows\Cookies\XZAXDNQD.txt [ Cookie:nico@mediaplex.com/ ]
        C:\USERS\NICO.DELL-PC.000\AppData\Roaming\Microsoft\Windows\Cookies\APQ3BI3N.txt [ Cookie:nico@adfarm1.adition.com/ ]
        C:\USERS\NICO.DELL-PC.000\AppData\Roaming\Microsoft\Windows\Cookies\MZJHPRKM.txt [ Cookie:nico@imrworldwide.com/cgi-bin ]
        C:\USERS\NICO.DELL-PC.000\AppData\Roaming\Microsoft\Windows\Cookies\BPXHXY40.txt [ Cookie:nico@ad2.adfarm1.adition.com/ ]
        C:\USERS\NICO.DELL-PC.000\AppData\Roaming\Microsoft\Windows\Cookies\NF69XBY1.txt [ Cookie:nico@c.atdmt.com/ ]
        C:\USERS\NICO.DELL-PC.000\AppData\Roaming\Microsoft\Windows\Cookies\LFT0E2C5.txt [ Cookie:nico@fastclick.net/ ]
        C:\USERS\NICO.DELL-PC.000\Cookies\Q24G170D.txt [ Cookie:nico@2o7.net/ ]
        C:\USERS\NICO.DELL-PC.000\Cookies\XZAXDNQD.txt [ Cookie:nico@mediaplex.com/ ]
        C:\USERS\NICO.DELL-PC.000\Cookies\APQ3BI3N.txt [ Cookie:nico@adfarm1.adition.com/ ]
        C:\USERS\NICO.DELL-PC.000\Cookies\MZJHPRKM.txt [ Cookie:nico@imrworldwide.com/cgi-bin ]
        C:\USERS\NICO.DELL-PC.000\Cookies\BPXHXY40.txt [ Cookie:nico@ad2.adfarm1.adition.com/ ]
        C:\USERS\NICO.DELL-PC.000\Cookies\NF69XBY1.txt [ Cookie:nico@c.atdmt.com/ ]
        C:\USERS\NICO.DELL-PC.000\Cookies\LFT0E2C5.txt [ Cookie:nico@fastclick.net/ ]
        .invitemedia.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        adserver.trojaner-info.de [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3CERS2ZS.DEFAULT\COOKIES.SQLITE ]
        media.mtvnservices.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\ZDEJBDAE ]
        secure-uk.imrworldwide.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\ZDEJBDAE ]
        secure-us.imrworldwide.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\ZDEJBDAE ]
        www.pornxnx.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\ZDEJBDAE ]
        .questionmarket.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .findextrawork.co.uk [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .findextrawork.co.uk [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .findextrawork.co.uk [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        tracking.dc-storm.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        data.coremetrics.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        tracking.dc-storm.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .olympiaverlag.122.2o7.net [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .clickaider.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .eaeacom.112.2o7.net [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        www.webcountdown.de [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        www.webcountdown.de [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        www.webcountdown.de [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        wstat.wibiya.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .www.tubsex.info [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .pornxnx.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .pornxnx.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .pornxnx.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .pornxnx.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .pornxnx.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .pornxnx.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .lfstmedia.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        e2.emediate.se [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        tracking.mlsat02.de [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        e2.emediate.se [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        .tracking.3gnet.de [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\NICO.DELL-PC.000\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JZT41MZM.DEFAULT\COOKIES.SQLITE ]:


Rheingold 18.12.2011 13:39

Hi Kira,
Antivir kann ich nicht mehr updaten, Windows update kann ich auch nicht ausführen und die Windows Firewall kann ich nicht mehr einstellen, angezeigt wird, dass sie nicht aktiv ist.

Okay, jetzt führe ich die restlichen Scans durch.

Viele Grüße
Jasmina

Rheingold 18.12.2011 16:28

unten nun der file zum eset online scan. was soll ich mit den dateien in der quarantäne machen? noch mal scannen und entfernen lassen?

Rheingold 18.12.2011 16:32

:
Code:

C:\Program Files (x86)\kisi2011.exe        Win32/MCH application        deleted - quarantined
C:\Program Files (x86)\Dell DataSafe Local Backup\hstart.exe        a variant of Win32/HiddenStart.A application        cleaned by deleting - quarantined
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe        a variant of Win32/HiddenStart.A application        cleaned by deleting - quarantined
C:\Users\Nico.dell-PC.000\Documents\SweetImSetup.exe        a variant of Win32/SweetIM.B application        cleaned by deleting - quarantined
C:\Windows\System32\drivers\mchccinj.sys        Win32/MCH application        cleaned by deleting - quarantined
C:\Windows\System32\wdrv\wdrvccin.bin        Win32/MCH application        cleaned by deleting - quarantined
:


Rheingold 18.12.2011 17:47

hi kira,
hier die otl files.

viele grüße
jasmina

Rheingold 18.12.2011 17:50

:
Code:

OTL logfile created on: 18.12.2011 16:36:35 - Run 9
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Administrator\Desktop\Anti-Virus Maßnahmen\OTL
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,90 Gb Total Physical Memory | 1,72 Gb Available Physical Memory | 44,19% Memory free
7,79 Gb Paging File | 5,53 Gb Available in Paging File | 70,95% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 235,24 Gb Total Space | 110,47 Gb Free Space | 46,96% Space Free | Partition Type: NTFS
Drive D: | 215,77 Gb Total Space | 206,35 Gb Free Space | 95,63% Space Free | Partition Type: NTFS
 
Computer Name: DELL-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011.12.15 19:37:19 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Administrator\Desktop\Anti-Virus Maßnahmen\OTL\OTL.exe
PRC - [2011.12.15 11:28:56 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2011.09.23 17:37:42 | 000,641,832 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2011.09.05 17:00:52 | 000,393,648 | ---- | M] (Eastman Kodak Company) -- C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe
PRC - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011.06.29 10:25:28 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.05.30 09:29:22 | 001,719,144 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe
PRC - [2011.05.30 09:29:20 | 002,055,816 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe
PRC - [2011.04.19 07:44:40 | 000,993,848 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe
PRC - [2011.04.19 07:44:40 | 000,399,416 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\sua.exe
PRC - [2011.04.19 07:44:40 | 000,291,896 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
PRC - [2011.03.28 15:15:04 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.03.28 15:14:56 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.01.24 21:34:06 | 000,991,296 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
PRC - [2011.01.24 21:34:04 | 001,298,496 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
PRC - [2011.01.24 21:33:30 | 000,901,184 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
PRC - [2011.01.24 21:33:24 | 000,979,008 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
PRC - [2010.12.21 00:24:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.12.21 00:24:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.12.17 16:25:22 | 000,686,704 | ---- | M] () -- C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
PRC - [2010.11.30 03:04:00 | 001,997,416 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2010.11.29 03:31:42 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2010.11.17 16:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2010.09.30 02:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
PRC - [2010.09.14 05:45:56 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2010.09.14 05:45:44 | 000,508,264 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010.08.21 00:53:08 | 000,689,472 | ---- | M] (SoftThinks SAS) -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
PRC - [2010.08.20 00:06:56 | 000,487,562 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
PRC - [2010.08.12 00:19:16 | 000,781,536 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
PRC - [2010.05.28 15:29:26 | 002,650,112 | ---- | M] (DATA BECKER GmbH & Co KG) -- C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe
PRC - [2009.07.14 00:15:34 | 002,250,640 | ---- | M] (Salfeld Computer) -- C:\Windows\SysWOW64\cchservice.exe
PRC - [2009.04.16 12:23:56 | 000,479,232 | ---- | M] (SAMSUNG ELECTRONICS) -- C:\Program Files (x86)\Samsung\EmoDio\SMSTray.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.06.24 21:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.06.24 21:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011.05.30 09:29:22 | 001,719,144 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe
MOD - [2011.05.30 09:29:20 | 002,055,816 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe
MOD - [2011.05.30 09:25:32 | 007,938,048 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\QtGui4.dll
MOD - [2011.05.30 09:25:32 | 002,225,664 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\QtCore4.dll
MOD - [2010.12.17 16:25:22 | 000,686,704 | ---- | M] () -- C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
MOD - [2010.11.25 04:44:02 | 000,375,280 | ---- | M] () -- c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll
MOD - [2010.11.17 16:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
MOD - [2010.08.12 00:19:34 | 000,077,024 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll
MOD - [2010.08.12 00:19:32 | 000,109,792 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll
MOD - [2010.08.12 00:19:32 | 000,072,928 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll
MOD - [2010.08.12 00:19:30 | 000,232,672 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll
MOD - [2010.08.12 00:19:30 | 000,126,176 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll
MOD - [2010.08.12 00:19:30 | 000,119,008 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll
MOD - [2010.08.12 00:19:26 | 001,121,504 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\LibXml2.dll
MOD - [2010.08.12 00:19:16 | 000,781,536 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2010.11.29 21:00:56 | 000,149,504 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV:64bit: - [2010.09.23 00:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2011.12.14 20:49:17 | 003,316,000 | ---- | M] () [Auto | Running] -- c:\program files (x86)\common files\akamai/netsession_win_b427739.dll -- (Akamai)
SRV - [2011.09.23 17:37:42 | 000,641,832 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011.09.05 17:00:52 | 000,393,648 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe -- (Kodak AiO Network Discovery Service)
SRV - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.06.29 10:25:28 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.19 07:44:40 | 000,993,848 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
SRV - [2011.04.19 07:44:40 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2011.03.28 15:15:04 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.01.24 21:34:06 | 000,991,296 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service)
SRV - [2011.01.24 21:34:04 | 001,298,496 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service)
SRV - [2011.01.24 21:33:30 | 000,901,184 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor)
SRV - [2010.12.21 00:24:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010.12.21 00:24:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.12.17 20:41:32 | 001,515,792 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel(R)
SRV - [2010.12.17 20:28:46 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV - [2010.12.17 20:26:50 | 000,836,880 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel(R)
SRV - [2010.11.30 03:04:00 | 001,997,416 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2010.11.29 03:31:42 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2010.11.25 11:34:18 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12)
SRV - [2010.11.25 11:33:18 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM)
SRV - [2010.09.30 02:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor9.0)
SRV - [2010.09.14 05:45:56 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2010.09.14 05:45:44 | 000,508,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010.08.26 02:28:54 | 002,823,000 | ---- | M] (Dell, Inc.) [Auto | Running] -- C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe -- (NOBU)
SRV - [2010.08.25 08:56:38 | 000,765,592 | ---- | M] (Salfeld Computer) [Auto | Stopped] -- C:\Windows\SysWOW64\ksupmgr.exe -- (ksupmgr)
SRV - [2010.08.21 00:53:08 | 000,689,472 | ---- | M] (SoftThinks SAS) [Auto | Running] -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE -- (SftService)
SRV - [2010.05.28 15:29:26 | 002,650,112 | ---- | M] (DATA BECKER GmbH & Co KG) [Auto | Running] -- C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe -- (DBService)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.11.18 03:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Programme\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2011.08.31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011.07.13 12:59:54 | 000,072,240 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NBVol.sys -- (NBVol)
DRV:64bit: - [2011.07.13 12:59:54 | 000,015,920 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NBVolUp.sys -- (NBVolUp)
DRV:64bit: - [2011.06.29 10:25:28 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011.06.29 10:25:28 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.06.10 05:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.04.12 10:45:50 | 000,018,432 | ---- | M] (TPMX Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HPub4DE3.sys -- (HPub4DE3) USB Mouse Low Filter Driver_4DE3 (WDF Version)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.03.09 09:44:44 | 000,025,088 | ---- | M] (TPMX Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HPMo4DE3.sys -- (HPMo4DE3) Mouse Suite Driver_4DE3 (WDF Version)
DRV:64bit: - [2011.02.10 23:52:34 | 000,181,760 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2011.02.10 23:52:34 | 000,082,432 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2011.01.28 09:57:14 | 012,273,408 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011.01.24 08:24:52 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux)
DRV:64bit: - [2011.01.24 08:22:48 | 000,059,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (iBtFltCoex)
DRV:64bit: - [2011.01.24 07:56:06 | 000,274,944 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf)
DRV:64bit: - [2011.01.13 02:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010.12.22 10:08:48 | 008,505,856 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64) ___ Intel(R)
DRV:64bit: - [2010.12.17 18:06:32 | 001,404,464 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010.12.15 18:02:04 | 000,174,168 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR)
DRV:64bit: - [2010.12.13 18:34:14 | 000,027,760 | ---- | M] (ST Microelectronics) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelern.sys -- (Acceler)
DRV:64bit: - [2010.12.12 15:18:36 | 000,121,960 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvstusb.sys -- (NvStUSB)
DRV:64bit: - [2010.11.30 03:04:00 | 000,025,576 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvpciflt.sys -- (nvpciflt)
DRV:64bit: - [2010.11.29 21:00:04 | 000,016,120 | ---- | M] (Intel(R) Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 10:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010.10.20 01:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel(R)
DRV:64bit: - [2010.10.16 01:28:18 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV:64bit: - [2010.09.14 05:45:52 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2010.09.14 05:45:50 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2010.09.14 05:45:48 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2010.09.14 05:45:44 | 000,760,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2010.09.01 09:30:58 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI)
DRV:64bit: - [2010.08.20 10:05:12 | 000,021,616 | ---- | M] (ST Microelectronics) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\stdcfltn.sys -- (stdcfltn)
DRV:64bit: - [2010.08.12 16:51:30 | 000,175,168 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV:64bit: - [2010.07.13 03:38:06 | 000,029,288 | ---- | M] (Quanta Computer) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qicflt.sys -- (qicflt)
DRV:64bit: - [2010.06.11 17:14:00 | 001,799,808 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVer7231_x64.sys -- (AVer7231_x64)
DRV:64bit: - [2010.03.19 09:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2010.02.27 16:32:14 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010.02.24 11:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11)
DRV:64bit: - [2009.08.13 21:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 01:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2006.11.01 18:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2011.07.22 17:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV - [2011.07.12 22:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2006.11.28 21:46:24 | 000,028,224 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\PDNMp50.sys -- (PDNMp50)
DRV - [2006.11.28 21:46:22 | 000,027,072 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\PDNSp50.sys -- (PDNSp50)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 3C D9 A7 7C 86 BD CC 01  [binary data]
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50263
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "www.google.de"
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50263
FF - prefs.js..network.proxy.type: 0
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF:64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.12.15 11:29:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.11 09:40:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.12.15 11:29:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Components: C:\Program Files (x86)\Mozilla Sunbird\components [2011.12.15 11:29:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Sunbird\plugins [2011.12.15 11:29:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.11.11 18:53:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 
[2011.05.19 12:42:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Extensions
[2011.05.19 12:42:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.09.12 11:27:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\3cers2zs.default\extensions
[2011.11.11 09:40:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.10.01 08:52:30 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.10.17 08:31:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011.10.29 10:21:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011.12.15 11:29:03 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011.11.11 09:40:26 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.10.29 10:21:40 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.09.16 21:59:18 | 000,170,064 | ---- | M] (Tracker Software Products Ltd.) -- C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2011.09.29 02:24:37 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.09.29 02:24:37 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.09.29 02:24:37 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.29 02:24:37 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
 
O1 HOSTS File: ([2011.09.12 21:31:56 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation)
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\SysNative\spool\drivers\x64\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4:64bit: - HKLM..\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [NVHotkey] C:\Windows\SysNative\nvHotkey.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ChicoSys] C:\Windows\SysWOW64\cc32\webtmr.exe (Salfeld Computer)
O4 - HKLM..\Run: [Conime] %windir%\system32\conime.exe File not found
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NBAgent] C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [SMSTray] C:\Program Files (x86)\Samsung\EmoDio\SMSTray.exe (SAMSUNG ELECTRONICS)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\.DEFAULT..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-18..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O4 - HKU\.DEFAULT..\RunOnce: [KodakHomeCenter] C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O4 - HKU\S-1-5-18..\RunOnce: [KodakHomeCenter] C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O4 - Startup: C:\Users\Jasmina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Nico.dell-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C8601AA9-2FCA-424D-B13E-12984594DCE3}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) -C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - Unable to read "AutoRun" value or value not present!
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.12.18 13:56:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2011.12.18 08:32:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011.12.18 08:32:32 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011.12.18 08:06:21 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.12.17 09:35:49 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\SUPERAntiSpyware.com
[2011.12.17 09:35:34 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011.12.16 09:08:32 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\RealNetworks
[2011.12.15 11:50:27 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\SoftGrid Client
[2011.12.15 11:50:25 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\SoftGrid Client
[2011.12.15 11:47:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.12.15 11:47:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.12.15 11:35:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.12.15 11:34:51 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.12.15 11:34:50 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011.12.15 11:34:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011.12.15 11:29:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared
[2011.12.15 11:29:01 | 000,198,832 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2011.12.15 11:28:57 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2011.12.15 11:28:57 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2011.12.15 11:28:56 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2011.12.15 11:28:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
[2011.12.15 11:25:22 | 000,713,472 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer.exe
[2011.12.15 11:22:52 | 000,000,000 | -HSD | C] -- C:\Users\Administrator\AppData\Local\4d0d2e25
[2011.12.15 11:14:51 | 009,852,544 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Program Files (x86)\mbam-setup-1.51.2.1300.exe
[2011.12.15 10:41:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.12.15 10:41:55 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.12.15 10:39:52 | 003,552,208 | ---- | C] (Piriform Ltd) -- C:\Program Files (x86)\ccsetup313.exe
[2011.12.15 08:29:11 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Desktop\Anti-Virus Maßnahmen
[2011.12.14 23:09:17 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2011.12.14 23:09:17 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2011.12.14 23:09:15 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2011.12.14 08:33:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LP
[2011.12.02 16:28:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Nexon
[2011.12.02 16:25:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon
[2011.12.02 16:22:22 | 000,000,000 | ---D | C] -- C:\ProgramData\NexonEU
[2011.12.02 15:45:54 | 000,000,000 | ---D | C] -- C:\Download
[2011.12.02 15:45:20 | 000,000,000 | ---D | C] -- C:\Nexon
[2011.12.02 15:45:19 | 000,446,464 | ---- | C] (NEXON Inc.) -- C:\Windows\NEXON_EU_DownloaderUpdater.exe
[2011.11.24 09:38:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak
[2011.11.24 09:36:02 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\spool
[2011.11.24 09:23:29 | 012,713,136 | ---- | C] (Eastman Kodak Company) -- C:\Program Files (x86)\aio_install.exe
[2011.10.29 11:49:39 | 039,401,336 | ---- | C] (Apple Inc.) -- C:\Program Files (x86)\QuickTimeInstaller.exe
[2011.10.29 11:04:38 | 010,311,496 | ---- | C] (Opera Software ASA) -- C:\Program Files (x86)\Opera_1152_int_Setup.exe
[2011.10.29 10:10:18 | 000,910,624 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\jxpiinstall.exe
[2011.10.25 12:17:18 | 009,756,672 | ---- | C] ((c) Phoenix Technologies Ltd. ) -- C:\Program Files\L502X_A__06.exe
[2011.10.17 08:29:10 | 001,739,400 | ---- | C] (Secunia) -- C:\Program Files (x86)\PSISetup2003.exe
[2011.10.17 08:05:48 | 013,885,360 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 7.0.1.exe
[2011.09.24 17:12:36 | 001,291,624 | ---- | C] (Microsoft Corporation) -- C:\Program Files\wlsetup-web__1_.exe
[2011.09.23 14:09:00 | 000,676,624 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer_1406666_de.exe
[2011.09.22 10:34:36 | 003,089,056 | ---- | C] (Adobe Systems, Inc.) -- C:\Program Files (x86)\install_flash_player.exe
[2011.08.28 11:11:15 | 051,975,388 | ---- | C] (Acresso Software Inc.) -- C:\Program Files (x86)\VSX4_Pro_TBYB.exe.part
[2011.08.27 11:56:04 | 001,228,384 | ---- | C] (Adobe Systems Incorporated) -- C:\Program Files (x86)\PremiereElements_9_LS15.exe
[2011.08.25 17:58:21 | 006,716,353 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Sunbird_Setup_1.0_Beta_1.exe
[2011.07.18 15:59:52 | 013,522,064 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 5.0.1.exe
[2011.05.28 13:13:41 | 014,212,584 | ---- | C] (DVDVideoSoft Ltd.                                          ) -- C:\Program Files (x86)\FreeYouTubeToiPodConverter.exe
[2011.05.28 13:11:38 | 014,563,768 | ---- | C] (DVDVideoSoft Ltd.                                          ) -- C:\Program Files (x86)\FreeYouTubeToMP3Converter.exe
[2011.05.22 09:35:05 | 021,255,560 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files (x86)\SkypeSetupFull.exe
[2011.05.19 14:37:24 | 081,797,928 | ---- | C] (Apple Inc.) -- C:\Program Files (x86)\iTunes64Setup.exe
[2011.05.19 14:17:51 | 020,240,744 | ---- | C] (The GIMP Team                                              ) -- C:\Program Files (x86)\gimp-2.6.11-i686-setup.exe
[2011.05.19 14:17:11 | 019,735,256 | ---- | C] (                                                            ) -- C:\Program Files (x86)\gimp-2.6.8-x64-setup.exe
[2011.05.19 14:06:00 | 000,767,064 | ---- | C] (NCH Software) -- C:\Program Files (x86)\wpsetup4.57.exe
[2011.05.19 12:34:44 | 000,568,648 | ---- | C] (Google Inc.) -- C:\Program Files (x86)\GoogleEarthSetup.exe
[2011.05.19 12:26:57 | 009,559,320 | ---- | C] (Opera Software ASA) -- C:\Program Files (x86)\Opera_1111_int_Setup.exe
[2011.05.19 12:26:00 | 009,326,056 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Thunderbird Setup 3.1.10.exe
[2011.05.19 12:25:04 | 012,362,480 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 4.0.1.exe
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.12.18 14:28:00 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025UA.job
[2011.12.18 14:11:44 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.12.18 14:11:44 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.12.18 14:09:10 | 000,001,963 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.12.18 14:04:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.12.18 14:04:01 | 3137,994,752 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.18 13:43:51 | 000,001,207 | ---- | M] () -- C:\Windows\SysWow64\excltmp~.dat
[2011.12.18 08:07:06 | 000,008,019 | ---- | M] () -- C:\Windows\SysWow64\cchservice.err
[2011.12.18 08:07:00 | 000,000,735 | ---- | M] () -- C:\Windows\SysWow64\ccsync.err
[2011.12.17 12:09:26 | 000,001,595 | ---- | M] () -- C:\Users\Administrator\Desktop\DELL-PC - Verknüpfung.lnk
[2011.12.15 11:47:50 | 000,001,162 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.12.15 11:35:17 | 000,001,836 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.12.15 11:29:01 | 000,198,832 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2011.12.15 11:28:57 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2011.12.15 11:28:57 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2011.12.15 11:28:56 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2011.12.15 11:25:23 | 000,713,472 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer.exe
[2011.12.15 11:22:41 | 001,500,062 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.12.15 11:22:41 | 000,654,798 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.12.15 11:22:41 | 000,616,640 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.12.15 11:22:41 | 000,130,380 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.12.15 11:22:41 | 000,106,762 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.12.15 11:14:56 | 009,852,544 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Program Files (x86)\mbam-setup-1.51.2.1300.exe
[2011.12.15 10:41:56 | 000,000,824 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.12.15 10:39:52 | 003,552,208 | ---- | M] (Piriform Ltd) -- C:\Program Files (x86)\ccsetup313.exe
[2011.12.15 08:25:41 | 000,353,408 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.12.15 08:02:34 | 000,000,118 | ---- | M] () -- C:\Windows\SysNative\MRT.INI
[2011.12.14 21:33:43 | 000,000,348 | ---- | M] () -- C:\NET.INI
[2011.12.14 08:38:37 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011.12.02 16:25:10 | 000,001,632 | ---- | M] () -- C:\Users\Public\Desktop\Combat Arms EU.lnk
[2011.12.02 15:45:20 | 000,000,235 | ---- | M] () -- C:\Windows\SysWow64\nxEuUninstall.bat
[2011.12.02 15:45:19 | 000,446,464 | ---- | M] (NEXON Inc.) -- C:\Windows\NEXON_EU_DownloaderUpdater.exe
[2011.11.24 09:39:41 | 000,002,209 | ---- | M] () -- C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
[2011.11.24 09:23:39 | 012,713,136 | ---- | M] (Eastman Kodak Company) -- C:\Program Files (x86)\aio_install.exe
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.12.18 14:05:28 | 000,001,492 | ---- | C] () -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011.12.18 14:05:28 | 000,001,407 | ---- | C] () -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011.12.18 08:32:34 | 000,001,963 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.12.18 08:06:30 | 000,000,735 | ---- | C] () -- C:\Windows\SysWow64\ccsync.err
[2011.12.17 12:09:26 | 000,001,595 | ---- | C] () -- C:\Users\Administrator\Desktop\DELL-PC - Verknüpfung.lnk
[2011.12.16 10:33:33 | 000,008,019 | ---- | C] () -- C:\Windows\SysWow64\cchservice.err
[2011.12.15 11:47:50 | 000,001,162 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.12.15 11:35:17 | 000,001,836 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.12.15 10:41:56 | 000,000,824 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.12.15 08:02:34 | 000,000,118 | ---- | C] () -- C:\Windows\SysNative\MRT.INI
[2011.12.02 16:25:10 | 000,001,632 | ---- | C] () -- C:\Users\Public\Desktop\Combat Arms EU.lnk
[2011.12.02 15:45:20 | 000,000,235 | ---- | C] () -- C:\Windows\SysWow64\nxEuUninstall.bat
[2011.11.24 09:39:41 | 000,002,209 | ---- | C] () -- C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
[2011.11.11 07:32:42 | 001,527,140 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.10.29 09:54:07 | 001,019,816 | ---- | C] () -- C:\Program Files\DELL_DELL-DIGITAL-DELIVERY_A05_R313622.exe
[2011.10.10 16:51:50 | 000,155,536 | ---- | C] () -- C:\Windows\SysWow64\dllcinx.exe
[2011.10.10 16:51:48 | 000,000,600 | ---- | C] () -- C:\Windows\SysWow64\nochook.ini
[2011.10.03 13:41:52 | 000,247,053 | ---- | C] () -- C:\Program Files (x86)\mp3DC213.exe
[2011.09.29 09:19:37 | 000,001,207 | ---- | C] () -- C:\Windows\SysWow64\excltmp~.dat
[2011.09.29 09:18:42 | 000,000,141 | -H-- | C] () -- C:\Windows\SysWow64\ctlsw.ini
[2011.09.29 09:18:42 | 000,000,102 | ---- | C] () -- C:\Windows\SysWow64\SWCTL.DLL
[2011.09.29 08:11:44 | 000,124,416 | ---- | C] () -- C:\Windows\SysWow64\dXCtrls.dll
[2011.09.29 08:11:43 | 000,544,256 | ---- | C] () -- C:\Windows\SysWow64\janGraphics.dll
[2011.09.29 07:55:01 | 003,103,511 | ---- | C] () -- C:\Program Files (x86)\kcsetup8.exe
[2011.09.23 14:05:53 | 021,073,936 | ---- | C] () -- C:\Program Files (x86)\vlc-1.1.11-win32.exe
[2011.09.23 12:51:28 | 000,003,027 | ---- | C] () -- C:\Program Files (x86)\Français.lng
[2011.09.23 12:51:28 | 000,002,946 | ---- | C] () -- C:\Program Files (x86)\Español.lng
[2011.09.23 12:51:28 | 000,002,920 | ---- | C] () -- C:\Program Files (x86)\Italiano.lng
[2011.09.23 12:51:28 | 000,002,699 | ---- | C] () -- C:\Program Files (x86)\Deutsch.lng
[2011.09.23 12:51:28 | 000,002,553 | ---- | C] () -- C:\Program Files (x86)\Suomi.lng
[2011.09.23 12:40:52 | 023,773,184 | ---- | C] () -- C:\Program Files (x86)\PXCViewer98_x64.msi
[2011.09.23 12:27:47 | 001,376,768 | ---- | C] () -- C:\Program Files (x86)\7z920-x64.msi
[2011.09.16 06:44:01 | 168,166,968 | ---- | C] () -- C:\Program Files (x86)\OOo_3.3.0_Win_x86_install-wJRE_de.exe
[2011.08.28 09:55:59 | 002,466,704 | ---- | C] () -- C:\Program Files (x86)\AdobeDownloadAssistant.exe
[2011.08.27 11:27:07 | 1316,066,539 | ---- | C] () -- C:\Program Files (x86)\PremiereElements_9_LS15.7z
[2011.08.27 11:23:03 | 008,353,800 | ---- | C] () -- C:\Program Files (x86)\Adobe_Premiere_Elements_9-AkamaiDLM.exe
[2011.05.19 14:44:09 | 001,663,693 | ---- | C] () -- C:\Program Files (x86)\winrar-x64-400d.exe
[2011.05.19 14:10:20 | 014,166,016 | ---- | C] () -- C:\Program Files (x86)\wz150gev.msi
[2011.05.19 14:09:07 | 006,088,218 | ---- | C] () -- C:\Program Files (x86)\flash_player.zip
[2011.05.19 13:52:49 | 000,000,056 | ---- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011.05.19 12:39:40 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.05.19 12:28:56 | 052,718,176 | ---- | C] () -- C:\Program Files (x86)\avira_antivir_personal_de.exe
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_89001461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_49001461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_33011461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_8a.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A0F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_8a.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_14001461_61.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_13011461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_110F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_110F1461_8a.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_ca.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_aa.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_8a.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_ca.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_aa.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_8a.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_890F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_2B0f1461_ca.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_29001461_ca.bin
[2011.05.15 06:48:49 | 000,000,412 | ---- | C] () -- C:\Windows\11317231_180F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,412 | ---- | C] () -- C:\Windows\11317231_18071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_11071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_11071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A0F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A031461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A031461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A011461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_09001461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_08071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_060F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_06071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_06071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_03011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_03011461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_02011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_02011461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_010F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_010F1461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_01071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_01071461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_07031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_ca.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03131461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_ca.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_8a.bin
[2011.05.15 06:48:48 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_0B0f1461_ca.bin
[2011.05.15 06:48:48 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_090F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,376 | ---- | C] () -- C:\Windows\11317231_03131461_aa.bin
[2011.05.15 06:48:47 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_00000000_aa.bin
[2011.05.15 06:48:11 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011.05.15 06:47:21 | 000,960,940 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.05.15 06:47:19 | 000,213,332 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.05.15 06:47:17 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.01.19 12:34:42 | 003,003,392 | ---- | C] () -- C:\Program Files (x86)\openofficeorg33.msi
[2011.01.19 12:33:04 | 000,475,016 | ---- | C] () -- C:\Program Files (x86)\setup.exe
[2011.01.19 12:30:10 | 142,700,671 | ---- | C] () -- C:\Program Files (x86)\openofficeorg1.cab
[2011.01.19 11:15:26 | 000,000,290 | ---- | C] () -- C:\Program Files (x86)\setup.ini
[2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009.04.16 12:24:14 | 000,921,600 | ---- | C] () -- C:\Windows\SysWow64\vorbisenc.dll
[2009.04.16 12:24:14 | 000,237,568 | ---- | C] () -- C:\Windows\SysWow64\OggDS.dll
[2009.04.16 12:24:14 | 000,188,416 | ---- | C] () -- C:\Windows\SysWow64\vorbis.dll
[2009.04.16 12:24:14 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\Ogg.dll
 
========== LOP Check ==========
 
[2011.05.23 15:49:56 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\CheckPoint
[2011.05.19 12:45:49 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.09.10 15:33:36 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Fingertapps
[2011.05.19 14:07:13 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\NCH Swift Sound
[2011.05.19 13:04:35 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\OpenOffice.org
[2011.10.29 11:10:08 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Opera
[2011.12.18 08:37:34 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\SoftGrid Client
[2011.11.18 10:33:58 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Temp
[2011.05.21 10:57:03 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Thunderbird
[2011.09.13 07:51:26 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Temp
[2011.09.13 07:51:26 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Temp
[2011.07.15 14:23:05 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\2K Sports
[2011.12.15 21:45:19 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\57168
[2011.12.15 21:45:19 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\B8457
[2011.09.01 18:51:14 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011.05.23 16:30:23 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\CheckPoint
[2011.08.28 09:58:29 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011.09.10 14:11:11 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\DriverFinder
[2011.10.01 08:51:21 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\DVDVideoSoft
[2011.10.01 08:51:16 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.06.30 08:10:18 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Fingertapps
[2011.06.20 07:07:01 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\go
[2011.12.16 12:46:12 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\gtk-2.0
[2011.11.07 19:23:04 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Leadertech
[2011.10.07 10:12:34 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\mp3DirectCut
[2011.06.24 07:34:10 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\NCH Swift Sound
[2011.05.20 17:29:32 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\OpenOffice.org
[2011.10.04 20:00:10 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Opera
[2011.05.31 06:51:05 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\ProtectDisc
[2011.09.20 10:55:01 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\QuickScan
[2011.07.06 19:23:10 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Temp
[2011.05.21 12:10:22 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Thunderbird
[2011.11.11 07:33:12 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\TP
[2011.07.17 14:24:06 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Ulead Systems
[2011.09.07 10:57:41 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Uniblue
[2011.10.09 13:43:13 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\2K Sports
[2011.12.15 21:45:19 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\57168
[2011.12.15 08:04:04 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\B8457
[2011.10.27 10:01:00 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\DVDVideoSoft
[2011.09.29 09:43:26 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Fingertapps
[2011.10.27 10:57:32 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\MusicNet
[2011.10.18 19:17:26 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\OpenOffice.org
[2011.11.07 19:36:36 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Origin
[2011.09.13 07:51:26 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Temp
[2011.09.29 09:59:09 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Thunderbird
[2011.12.18 14:28:00 | 000,000,948 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025UA.job
[2011.12.04 15:25:34 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 

< End of report >
:


Rheingold 18.12.2011 17:53

:
Code:

OTL logfile created on: 18.12.2011 16:36:35 - Run 9
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Administrator\Desktop\Anti-Virus Maßnahmen\OTL
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,90 Gb Total Physical Memory | 1,72 Gb Available Physical Memory | 44,19% Memory free
7,79 Gb Paging File | 5,53 Gb Available in Paging File | 70,95% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 235,24 Gb Total Space | 110,47 Gb Free Space | 46,96% Space Free | Partition Type: NTFS
Drive D: | 215,77 Gb Total Space | 206,35 Gb Free Space | 95,63% Space Free | Partition Type: NTFS
 
Computer Name: DELL-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011.12.15 19:37:19 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Administrator\Desktop\Anti-Virus Maßnahmen\OTL\OTL.exe
PRC - [2011.12.15 11:28:56 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2011.09.23 17:37:42 | 000,641,832 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2011.09.05 17:00:52 | 000,393,648 | ---- | M] (Eastman Kodak Company) -- C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe
PRC - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011.06.29 10:25:28 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.05.30 09:29:22 | 001,719,144 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe
PRC - [2011.05.30 09:29:20 | 002,055,816 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe
PRC - [2011.04.19 07:44:40 | 000,993,848 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe
PRC - [2011.04.19 07:44:40 | 000,399,416 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\sua.exe
PRC - [2011.04.19 07:44:40 | 000,291,896 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
PRC - [2011.03.28 15:15:04 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.03.28 15:14:56 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.01.24 21:34:06 | 000,991,296 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
PRC - [2011.01.24 21:34:04 | 001,298,496 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
PRC - [2011.01.24 21:33:30 | 000,901,184 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
PRC - [2011.01.24 21:33:24 | 000,979,008 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
PRC - [2010.12.21 00:24:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.12.21 00:24:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.12.17 16:25:22 | 000,686,704 | ---- | M] () -- C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
PRC - [2010.11.30 03:04:00 | 001,997,416 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2010.11.29 03:31:42 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2010.11.17 16:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2010.09.30 02:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
PRC - [2010.09.14 05:45:56 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2010.09.14 05:45:44 | 000,508,264 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010.08.21 00:53:08 | 000,689,472 | ---- | M] (SoftThinks SAS) -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
PRC - [2010.08.20 00:06:56 | 000,487,562 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
PRC - [2010.08.12 00:19:16 | 000,781,536 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
PRC - [2010.05.28 15:29:26 | 002,650,112 | ---- | M] (DATA BECKER GmbH & Co KG) -- C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe
PRC - [2009.07.14 00:15:34 | 002,250,640 | ---- | M] (Salfeld Computer) -- C:\Windows\SysWOW64\cchservice.exe
PRC - [2009.04.16 12:23:56 | 000,479,232 | ---- | M] (SAMSUNG ELECTRONICS) -- C:\Program Files (x86)\Samsung\EmoDio\SMSTray.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.06.24 21:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.06.24 21:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011.05.30 09:29:22 | 001,719,144 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe
MOD - [2011.05.30 09:29:20 | 002,055,816 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe
MOD - [2011.05.30 09:25:32 | 007,938,048 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\QtGui4.dll
MOD - [2011.05.30 09:25:32 | 002,225,664 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\QtCore4.dll
MOD - [2010.12.17 16:25:22 | 000,686,704 | ---- | M] () -- C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
MOD - [2010.11.25 04:44:02 | 000,375,280 | ---- | M] () -- c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll
MOD - [2010.11.17 16:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
MOD - [2010.08.12 00:19:34 | 000,077,024 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll
MOD - [2010.08.12 00:19:32 | 000,109,792 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll
MOD - [2010.08.12 00:19:32 | 000,072,928 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll
MOD - [2010.08.12 00:19:30 | 000,232,672 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll
MOD - [2010.08.12 00:19:30 | 000,126,176 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll
MOD - [2010.08.12 00:19:30 | 000,119,008 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll
MOD - [2010.08.12 00:19:26 | 001,121,504 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\LibXml2.dll
MOD - [2010.08.12 00:19:16 | 000,781,536 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2010.11.29 21:00:56 | 000,149,504 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV:64bit: - [2010.09.23 00:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2011.12.14 20:49:17 | 003,316,000 | ---- | M] () [Auto | Running] -- c:\program files (x86)\common files\akamai/netsession_win_b427739.dll -- (Akamai)
SRV - [2011.09.23 17:37:42 | 000,641,832 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011.09.05 17:00:52 | 000,393,648 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe -- (Kodak AiO Network Discovery Service)
SRV - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.06.29 10:25:28 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.19 07:44:40 | 000,993,848 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
SRV - [2011.04.19 07:44:40 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2011.03.28 15:15:04 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.01.24 21:34:06 | 000,991,296 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service)
SRV - [2011.01.24 21:34:04 | 001,298,496 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service)
SRV - [2011.01.24 21:33:30 | 000,901,184 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor)
SRV - [2010.12.21 00:24:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010.12.21 00:24:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.12.17 20:41:32 | 001,515,792 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel(R)
SRV - [2010.12.17 20:28:46 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV - [2010.12.17 20:26:50 | 000,836,880 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel(R)
SRV - [2010.11.30 03:04:00 | 001,997,416 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2010.11.29 03:31:42 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2010.11.25 11:34:18 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12)
SRV - [2010.11.25 11:33:18 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM)
SRV - [2010.09.30 02:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor9.0)
SRV - [2010.09.14 05:45:56 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2010.09.14 05:45:44 | 000,508,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010.08.26 02:28:54 | 002,823,000 | ---- | M] (Dell, Inc.) [Auto | Running] -- C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe -- (NOBU)
SRV - [2010.08.25 08:56:38 | 000,765,592 | ---- | M] (Salfeld Computer) [Auto | Stopped] -- C:\Windows\SysWOW64\ksupmgr.exe -- (ksupmgr)
SRV - [2010.08.21 00:53:08 | 000,689,472 | ---- | M] (SoftThinks SAS) [Auto | Running] -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE -- (SftService)
SRV - [2010.05.28 15:29:26 | 002,650,112 | ---- | M] (DATA BECKER GmbH & Co KG) [Auto | Running] -- C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe -- (DBService)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.11.18 03:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Programme\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2011.08.31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011.07.13 12:59:54 | 000,072,240 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NBVol.sys -- (NBVol)
DRV:64bit: - [2011.07.13 12:59:54 | 000,015,920 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NBVolUp.sys -- (NBVolUp)
DRV:64bit: - [2011.06.29 10:25:28 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011.06.29 10:25:28 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.06.10 05:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.04.12 10:45:50 | 000,018,432 | ---- | M] (TPMX Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HPub4DE3.sys -- (HPub4DE3) USB Mouse Low Filter Driver_4DE3 (WDF Version)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.03.09 09:44:44 | 000,025,088 | ---- | M] (TPMX Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HPMo4DE3.sys -- (HPMo4DE3) Mouse Suite Driver_4DE3 (WDF Version)
DRV:64bit: - [2011.02.10 23:52:34 | 000,181,760 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2011.02.10 23:52:34 | 000,082,432 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2011.01.28 09:57:14 | 012,273,408 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011.01.24 08:24:52 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux)
DRV:64bit: - [2011.01.24 08:22:48 | 000,059,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (iBtFltCoex)
DRV:64bit: - [2011.01.24 07:56:06 | 000,274,944 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf)
DRV:64bit: - [2011.01.13 02:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010.12.22 10:08:48 | 008,505,856 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64) ___ Intel(R)
DRV:64bit: - [2010.12.17 18:06:32 | 001,404,464 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010.12.15 18:02:04 | 000,174,168 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR)
DRV:64bit: - [2010.12.13 18:34:14 | 000,027,760 | ---- | M] (ST Microelectronics) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelern.sys -- (Acceler)
DRV:64bit: - [2010.12.12 15:18:36 | 000,121,960 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvstusb.sys -- (NvStUSB)
DRV:64bit: - [2010.11.30 03:04:00 | 000,025,576 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvpciflt.sys -- (nvpciflt)
DRV:64bit: - [2010.11.29 21:00:04 | 000,016,120 | ---- | M] (Intel(R) Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 10:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010.10.20 01:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel(R)
DRV:64bit: - [2010.10.16 01:28:18 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV:64bit: - [2010.09.14 05:45:52 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2010.09.14 05:45:50 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2010.09.14 05:45:48 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2010.09.14 05:45:44 | 000,760,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2010.09.01 09:30:58 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI)
DRV:64bit: - [2010.08.20 10:05:12 | 000,021,616 | ---- | M] (ST Microelectronics) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\stdcfltn.sys -- (stdcfltn)
DRV:64bit: - [2010.08.12 16:51:30 | 000,175,168 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV:64bit: - [2010.07.13 03:38:06 | 000,029,288 | ---- | M] (Quanta Computer) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qicflt.sys -- (qicflt)
DRV:64bit: - [2010.06.11 17:14:00 | 001,799,808 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVer7231_x64.sys -- (AVer7231_x64)
DRV:64bit: - [2010.03.19 09:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2010.02.27 16:32:14 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010.02.24 11:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11)
DRV:64bit: - [2009.08.13 21:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 01:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2006.11.01 18:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2011.07.22 17:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV - [2011.07.12 22:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2006.11.28 21:46:24 | 000,028,224 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\PDNMp50.sys -- (PDNMp50)
DRV - [2006.11.28 21:46:22 | 000,027,072 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\PDNSp50.sys -- (PDNSp50)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 3C D9 A7 7C 86 BD CC 01  [binary data]
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50263
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "www.google.de"
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50263
FF - prefs.js..network.proxy.type: 0
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF:64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.12.15 11:29:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.11 09:40:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.12.15 11:29:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Components: C:\Program Files (x86)\Mozilla Sunbird\components [2011.12.15 11:29:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Sunbird\plugins [2011.12.15 11:29:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.11.11 18:53:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 
[2011.05.19 12:42:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Extensions
[2011.05.19 12:42:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.09.12 11:27:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\3cers2zs.default\extensions
[2011.11.11 09:40:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.10.01 08:52:30 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.10.17 08:31:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011.10.29 10:21:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011.12.15 11:29:03 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011.11.11 09:40:26 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.10.29 10:21:40 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.09.16 21:59:18 | 000,170,064 | ---- | M] (Tracker Software Products Ltd.) -- C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2011.09.29 02:24:37 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.09.29 02:24:37 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.09.29 02:24:37 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.29 02:24:37 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
 
O1 HOSTS File: ([2011.09.12 21:31:56 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation)
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\SysNative\spool\drivers\x64\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4:64bit: - HKLM..\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [NVHotkey] C:\Windows\SysNative\nvHotkey.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ChicoSys] C:\Windows\SysWOW64\cc32\webtmr.exe (Salfeld Computer)
O4 - HKLM..\Run: [Conime] %windir%\system32\conime.exe File not found
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NBAgent] C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [SMSTray] C:\Program Files (x86)\Samsung\EmoDio\SMSTray.exe (SAMSUNG ELECTRONICS)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\.DEFAULT..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-18..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O4 - HKU\.DEFAULT..\RunOnce: [KodakHomeCenter] C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O4 - HKU\S-1-5-18..\RunOnce: [KodakHomeCenter] C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O4 - Startup: C:\Users\Jasmina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Nico.dell-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C8601AA9-2FCA-424D-B13E-12984594DCE3}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) -C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - Unable to read "AutoRun" value or value not present!
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.12.18 13:56:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2011.12.18 08:32:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011.12.18 08:32:32 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011.12.18 08:06:21 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.12.17 09:35:49 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\SUPERAntiSpyware.com
[2011.12.17 09:35:34 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011.12.16 09:08:32 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\RealNetworks
[2011.12.15 11:50:27 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\SoftGrid Client
[2011.12.15 11:50:25 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\SoftGrid Client
[2011.12.15 11:47:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.12.15 11:47:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.12.15 11:35:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.12.15 11:34:51 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.12.15 11:34:50 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011.12.15 11:34:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011.12.15 11:29:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared
[2011.12.15 11:29:01 | 000,198,832 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2011.12.15 11:28:57 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2011.12.15 11:28:57 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2011.12.15 11:28:56 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2011.12.15 11:28:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
[2011.12.15 11:25:22 | 000,713,472 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer.exe
[2011.12.15 11:22:52 | 000,000,000 | -HSD | C] -- C:\Users\Administrator\AppData\Local\4d0d2e25
[2011.12.15 11:14:51 | 009,852,544 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Program Files (x86)\mbam-setup-1.51.2.1300.exe
[2011.12.15 10:41:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.12.15 10:41:55 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.12.15 10:39:52 | 003,552,208 | ---- | C] (Piriform Ltd) -- C:\Program Files (x86)\ccsetup313.exe
[2011.12.15 08:29:11 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Desktop\Anti-Virus Maßnahmen
[2011.12.14 23:09:17 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2011.12.14 23:09:17 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2011.12.14 23:09:15 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2011.12.14 08:33:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LP
[2011.12.02 16:28:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Nexon
[2011.12.02 16:25:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon
[2011.12.02 16:22:22 | 000,000,000 | ---D | C] -- C:\ProgramData\NexonEU
[2011.12.02 15:45:54 | 000,000,000 | ---D | C] -- C:\Download
[2011.12.02 15:45:20 | 000,000,000 | ---D | C] -- C:\Nexon
[2011.12.02 15:45:19 | 000,446,464 | ---- | C] (NEXON Inc.) -- C:\Windows\NEXON_EU_DownloaderUpdater.exe
[2011.11.24 09:38:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak
[2011.11.24 09:36:02 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\spool
[2011.11.24 09:23:29 | 012,713,136 | ---- | C] (Eastman Kodak Company) -- C:\Program Files (x86)\aio_install.exe
[2011.10.29 11:49:39 | 039,401,336 | ---- | C] (Apple Inc.) -- C:\Program Files (x86)\QuickTimeInstaller.exe
[2011.10.29 11:04:38 | 010,311,496 | ---- | C] (Opera Software ASA) -- C:\Program Files (x86)\Opera_1152_int_Setup.exe
[2011.10.29 10:10:18 | 000,910,624 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\jxpiinstall.exe
[2011.10.25 12:17:18 | 009,756,672 | ---- | C] ((c) Phoenix Technologies Ltd. ) -- C:\Program Files\L502X_A__06.exe
[2011.10.17 08:29:10 | 001,739,400 | ---- | C] (Secunia) -- C:\Program Files (x86)\PSISetup2003.exe
[2011.10.17 08:05:48 | 013,885,360 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 7.0.1.exe
[2011.09.24 17:12:36 | 001,291,624 | ---- | C] (Microsoft Corporation) -- C:\Program Files\wlsetup-web__1_.exe
[2011.09.23 14:09:00 | 000,676,624 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer_1406666_de.exe
[2011.09.22 10:34:36 | 003,089,056 | ---- | C] (Adobe Systems, Inc.) -- C:\Program Files (x86)\install_flash_player.exe
[2011.08.28 11:11:15 | 051,975,388 | ---- | C] (Acresso Software Inc.) -- C:\Program Files (x86)\VSX4_Pro_TBYB.exe.part
[2011.08.27 11:56:04 | 001,228,384 | ---- | C] (Adobe Systems Incorporated) -- C:\Program Files (x86)\PremiereElements_9_LS15.exe
[2011.08.25 17:58:21 | 006,716,353 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Sunbird_Setup_1.0_Beta_1.exe
[2011.07.18 15:59:52 | 013,522,064 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 5.0.1.exe
[2011.05.28 13:13:41 | 014,212,584 | ---- | C] (DVDVideoSoft Ltd.                                          ) -- C:\Program Files (x86)\FreeYouTubeToiPodConverter.exe
[2011.05.28 13:11:38 | 014,563,768 | ---- | C] (DVDVideoSoft Ltd.                                          ) -- C:\Program Files (x86)\FreeYouTubeToMP3Converter.exe
[2011.05.22 09:35:05 | 021,255,560 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files (x86)\SkypeSetupFull.exe
[2011.05.19 14:37:24 | 081,797,928 | ---- | C] (Apple Inc.) -- C:\Program Files (x86)\iTunes64Setup.exe
[2011.05.19 14:17:51 | 020,240,744 | ---- | C] (The GIMP Team                                              ) -- C:\Program Files (x86)\gimp-2.6.11-i686-setup.exe
[2011.05.19 14:17:11 | 019,735,256 | ---- | C] (                                                            ) -- C:\Program Files (x86)\gimp-2.6.8-x64-setup.exe
[2011.05.19 14:06:00 | 000,767,064 | ---- | C] (NCH Software) -- C:\Program Files (x86)\wpsetup4.57.exe
[2011.05.19 12:34:44 | 000,568,648 | ---- | C] (Google Inc.) -- C:\Program Files (x86)\GoogleEarthSetup.exe
[2011.05.19 12:26:57 | 009,559,320 | ---- | C] (Opera Software ASA) -- C:\Program Files (x86)\Opera_1111_int_Setup.exe
[2011.05.19 12:26:00 | 009,326,056 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Thunderbird Setup 3.1.10.exe
[2011.05.19 12:25:04 | 012,362,480 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 4.0.1.exe
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.12.18 14:28:00 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025UA.job
[2011.12.18 14:11:44 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.12.18 14:11:44 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.12.18 14:09:10 | 000,001,963 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.12.18 14:04:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.12.18 14:04:01 | 3137,994,752 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.18 13:43:51 | 000,001,207 | ---- | M] () -- C:\Windows\SysWow64\excltmp~.dat
[2011.12.18 08:07:06 | 000,008,019 | ---- | M] () -- C:\Windows\SysWow64\cchservice.err
[2011.12.18 08:07:00 | 000,000,735 | ---- | M] () -- C:\Windows\SysWow64\ccsync.err
[2011.12.17 12:09:26 | 000,001,595 | ---- | M] () -- C:\Users\Administrator\Desktop\DELL-PC - Verknüpfung.lnk
[2011.12.15 11:47:50 | 000,001,162 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.12.15 11:35:17 | 000,001,836 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.12.15 11:29:01 | 000,198,832 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2011.12.15 11:28:57 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2011.12.15 11:28:57 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2011.12.15 11:28:56 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2011.12.15 11:25:23 | 000,713,472 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer.exe
[2011.12.15 11:22:41 | 001,500,062 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.12.15 11:22:41 | 000,654,798 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.12.15 11:22:41 | 000,616,640 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.12.15 11:22:41 | 000,130,380 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.12.15 11:22:41 | 000,106,762 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.12.15 11:14:56 | 009,852,544 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Program Files (x86)\mbam-setup-1.51.2.1300.exe
[2011.12.15 10:41:56 | 000,000,824 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.12.15 10:39:52 | 003,552,208 | ---- | M] (Piriform Ltd) -- C:\Program Files (x86)\ccsetup313.exe
[2011.12.15 08:25:41 | 000,353,408 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.12.15 08:02:34 | 000,000,118 | ---- | M] () -- C:\Windows\SysNative\MRT.INI
[2011.12.14 21:33:43 | 000,000,348 | ---- | M] () -- C:\NET.INI
[2011.12.14 08:38:37 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011.12.02 16:25:10 | 000,001,632 | ---- | M] () -- C:\Users\Public\Desktop\Combat Arms EU.lnk
[2011.12.02 15:45:20 | 000,000,235 | ---- | M] () -- C:\Windows\SysWow64\nxEuUninstall.bat
[2011.12.02 15:45:19 | 000,446,464 | ---- | M] (NEXON Inc.) -- C:\Windows\NEXON_EU_DownloaderUpdater.exe
[2011.11.24 09:39:41 | 000,002,209 | ---- | M] () -- C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
[2011.11.24 09:23:39 | 012,713,136 | ---- | M] (Eastman Kodak Company) -- C:\Program Files (x86)\aio_install.exe
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.12.18 14:05:28 | 000,001,492 | ---- | C] () -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011.12.18 14:05:28 | 000,001,407 | ---- | C] () -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011.12.18 08:32:34 | 000,001,963 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.12.18 08:06:30 | 000,000,735 | ---- | C] () -- C:\Windows\SysWow64\ccsync.err
[2011.12.17 12:09:26 | 000,001,595 | ---- | C] () -- C:\Users\Administrator\Desktop\DELL-PC - Verknüpfung.lnk
[2011.12.16 10:33:33 | 000,008,019 | ---- | C] () -- C:\Windows\SysWow64\cchservice.err
[2011.12.15 11:47:50 | 000,001,162 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.12.15 11:35:17 | 000,001,836 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.12.15 10:41:56 | 000,000,824 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.12.15 08:02:34 | 000,000,118 | ---- | C] () -- C:\Windows\SysNative\MRT.INI
[2011.12.02 16:25:10 | 000,001,632 | ---- | C] () -- C:\Users\Public\Desktop\Combat Arms EU.lnk
[2011.12.02 15:45:20 | 000,000,235 | ---- | C] () -- C:\Windows\SysWow64\nxEuUninstall.bat
[2011.11.24 09:39:41 | 000,002,209 | ---- | C] () -- C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
[2011.11.11 07:32:42 | 001,527,140 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.10.29 09:54:07 | 001,019,816 | ---- | C] () -- C:\Program Files\DELL_DELL-DIGITAL-DELIVERY_A05_R313622.exe
[2011.10.10 16:51:50 | 000,155,536 | ---- | C] () -- C:\Windows\SysWow64\dllcinx.exe
[2011.10.10 16:51:48 | 000,000,600 | ---- | C] () -- C:\Windows\SysWow64\nochook.ini
[2011.10.03 13:41:52 | 000,247,053 | ---- | C] () -- C:\Program Files (x86)\mp3DC213.exe
[2011.09.29 09:19:37 | 000,001,207 | ---- | C] () -- C:\Windows\SysWow64\excltmp~.dat
[2011.09.29 09:18:42 | 000,000,141 | -H-- | C] () -- C:\Windows\SysWow64\ctlsw.ini
[2011.09.29 09:18:42 | 000,000,102 | ---- | C] () -- C:\Windows\SysWow64\SWCTL.DLL
[2011.09.29 08:11:44 | 000,124,416 | ---- | C] () -- C:\Windows\SysWow64\dXCtrls.dll
[2011.09.29 08:11:43 | 000,544,256 | ---- | C] () -- C:\Windows\SysWow64\janGraphics.dll
[2011.09.29 07:55:01 | 003,103,511 | ---- | C] () -- C:\Program Files (x86)\kcsetup8.exe
[2011.09.23 14:05:53 | 021,073,936 | ---- | C] () -- C:\Program Files (x86)\vlc-1.1.11-win32.exe
[2011.09.23 12:51:28 | 000,003,027 | ---- | C] () -- C:\Program Files (x86)\Français.lng
[2011.09.23 12:51:28 | 000,002,946 | ---- | C] () -- C:\Program Files (x86)\Español.lng
[2011.09.23 12:51:28 | 000,002,920 | ---- | C] () -- C:\Program Files (x86)\Italiano.lng
[2011.09.23 12:51:28 | 000,002,699 | ---- | C] () -- C:\Program Files (x86)\Deutsch.lng
[2011.09.23 12:51:28 | 000,002,553 | ---- | C] () -- C:\Program Files (x86)\Suomi.lng
[2011.09.23 12:40:52 | 023,773,184 | ---- | C] () -- C:\Program Files (x86)\PXCViewer98_x64.msi
[2011.09.23 12:27:47 | 001,376,768 | ---- | C] () -- C:\Program Files (x86)\7z920-x64.msi
[2011.09.16 06:44:01 | 168,166,968 | ---- | C] () -- C:\Program Files (x86)\OOo_3.3.0_Win_x86_install-wJRE_de.exe
[2011.08.28 09:55:59 | 002,466,704 | ---- | C] () -- C:\Program Files (x86)\AdobeDownloadAssistant.exe
[2011.08.27 11:27:07 | 1316,066,539 | ---- | C] () -- C:\Program Files (x86)\PremiereElements_9_LS15.7z
[2011.08.27 11:23:03 | 008,353,800 | ---- | C] () -- C:\Program Files (x86)\Adobe_Premiere_Elements_9-AkamaiDLM.exe
[2011.05.19 14:44:09 | 001,663,693 | ---- | C] () -- C:\Program Files (x86)\winrar-x64-400d.exe
[2011.05.19 14:10:20 | 014,166,016 | ---- | C] () -- C:\Program Files (x86)\wz150gev.msi
[2011.05.19 14:09:07 | 006,088,218 | ---- | C] () -- C:\Program Files (x86)\flash_player.zip
[2011.05.19 13:52:49 | 000,000,056 | ---- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011.05.19 12:39:40 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.05.19 12:28:56 | 052,718,176 | ---- | C] () -- C:\Program Files (x86)\avira_antivir_personal_de.exe
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_89001461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_49001461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_33011461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_8a.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A0F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_8a.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_14001461_61.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_13011461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_110F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_110F1461_8a.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_ca.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_aa.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_8a.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_ca.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_aa.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_8a.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_890F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_2B0f1461_ca.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_29001461_ca.bin
[2011.05.15 06:48:49 | 000,000,412 | ---- | C] () -- C:\Windows\11317231_180F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,412 | ---- | C] () -- C:\Windows\11317231_18071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_11071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_11071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A0F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A031461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A031461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A011461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_09001461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_08071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_060F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_06071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_06071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_03011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_03011461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_02011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_02011461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_010F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_010F1461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_01071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_01071461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_07031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_ca.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03131461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_ca.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_8a.bin
[2011.05.15 06:48:48 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_0B0f1461_ca.bin
[2011.05.15 06:48:48 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_090F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,376 | ---- | C] () -- C:\Windows\11317231_03131461_aa.bin
[2011.05.15 06:48:47 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_00000000_aa.bin
[2011.05.15 06:48:11 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011.05.15 06:47:21 | 000,960,940 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.05.15 06:47:19 | 000,213,332 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.05.15 06:47:17 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.01.19 12:34:42 | 003,003,392 | ---- | C] () -- C:\Program Files (x86)\openofficeorg33.msi
[2011.01.19 12:33:04 | 000,475,016 | ---- | C] () -- C:\Program Files (x86)\setup.exe
[2011.01.19 12:30:10 | 142,700,671 | ---- | C] () -- C:\Program Files (x86)\openofficeorg1.cab
[2011.01.19 11:15:26 | 000,000,290 | ---- | C] () -- C:\Program Files (x86)\setup.ini
[2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009.04.16 12:24:14 | 000,921,600 | ---- | C] () -- C:\Windows\SysWow64\vorbisenc.dll
[2009.04.16 12:24:14 | 000,237,568 | ---- | C] () -- C:\Windows\SysWow64\OggDS.dll
[2009.04.16 12:24:14 | 000,188,416 | ---- | C] () -- C:\Windows\SysWow64\vorbis.dll
[2009.04.16 12:24:14 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\Ogg.dll
 
========== LOP Check ==========
 
[2011.05.23 15:49:56 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\CheckPoint
[2011.05.19 12:45:49 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.09.10 15:33:36 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Fingertapps
[2011.05.19 14:07:13 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\NCH Swift Sound
[2011.05.19 13:04:35 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\OpenOffice.org
[2011.10.29 11:10:08 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Opera
[2011.12.18 08:37:34 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\SoftGrid Client
[2011.11.18 10:33:58 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Temp
[2011.05.21 10:57:03 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Thunderbird
[2011.09.13 07:51:26 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Temp
[2011.09.13 07:51:26 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Temp
[2011.07.15 14:23:05 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\2K Sports
[2011.12.15 21:45:19 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\57168
[2011.12.15 21:45:19 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\B8457
[2011.09.01 18:51:14 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011.05.23 16:30:23 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\CheckPoint
[2011.08.28 09:58:29 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011.09.10 14:11:11 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\DriverFinder
[2011.10.01 08:51:21 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\DVDVideoSoft
[2011.10.01 08:51:16 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.06.30 08:10:18 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Fingertapps
[2011.06.20 07:07:01 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\go
[2011.12.16 12:46:12 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\gtk-2.0
[2011.11.07 19:23:04 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Leadertech
[2011.10.07 10:12:34 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\mp3DirectCut
[2011.06.24 07:34:10 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\NCH Swift Sound
[2011.05.20 17:29:32 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\OpenOffice.org
[2011.10.04 20:00:10 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Opera
[2011.05.31 06:51:05 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\ProtectDisc
[2011.09.20 10:55:01 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\QuickScan
[2011.07.06 19:23:10 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Temp
[2011.05.21 12:10:22 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Thunderbird
[2011.11.11 07:33:12 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\TP
[2011.07.17 14:24:06 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Ulead Systems
[2011.09.07 10:57:41 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Uniblue
[2011.10.09 13:43:13 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\2K Sports
[2011.12.15 21:45:19 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\57168
[2011.12.15 08:04:04 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\B8457
[2011.10.27 10:01:00 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\DVDVideoSoft
[2011.09.29 09:43:26 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Fingertapps
[2011.10.27 10:57:32 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\MusicNet
[2011.10.18 19:17:26 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\OpenOffice.org
[2011.11.07 19:36:36 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Origin
[2011.09.13 07:51:26 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Temp
[2011.09.29 09:59:09 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Thunderbird
[2011.12.18 14:28:00 | 000,000,948 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025UA.job
[2011.12.04 15:25:34 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
< End of report >:


Rheingold 18.12.2011 17:57

:
Code:

OTL logfile created on: 18.12.2011 16:36:35 - Run 9
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Administrator\Desktop\Anti-Virus Maßnahmen\OTL
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,90 Gb Total Physical Memory | 1,72 Gb Available Physical Memory | 44,19% Memory free
7,79 Gb Paging File | 5,53 Gb Available in Paging File | 70,95% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 235,24 Gb Total Space | 110,47 Gb Free Space | 46,96% Space Free | Partition Type: NTFS
Drive D: | 215,77 Gb Total Space | 206,35 Gb Free Space | 95,63% Space Free | Partition Type: NTFS
 
Computer Name: DELL-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011.12.15 19:37:19 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Administrator\Desktop\Anti-Virus Maßnahmen\OTL\OTL.exe
PRC - [2011.12.15 11:28:56 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2011.09.23 17:37:42 | 000,641,832 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2011.09.05 17:00:52 | 000,393,648 | ---- | M] (Eastman Kodak Company) -- C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe
PRC - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011.06.29 10:25:28 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.05.30 09:29:22 | 001,719,144 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe
PRC - [2011.05.30 09:29:20 | 002,055,816 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe
PRC - [2011.04.19 07:44:40 | 000,993,848 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe
PRC - [2011.04.19 07:44:40 | 000,399,416 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\sua.exe
PRC - [2011.04.19 07:44:40 | 000,291,896 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
PRC - [2011.03.28 15:15:04 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.03.28 15:14:56 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.01.24 21:34:06 | 000,991,296 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
PRC - [2011.01.24 21:34:04 | 001,298,496 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
PRC - [2011.01.24 21:33:30 | 000,901,184 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
PRC - [2011.01.24 21:33:24 | 000,979,008 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
PRC - [2010.12.21 00:24:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.12.21 00:24:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.12.17 16:25:22 | 000,686,704 | ---- | M] () -- C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
PRC - [2010.11.30 03:04:00 | 001,997,416 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2010.11.29 03:31:42 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2010.11.17 16:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2010.09.30 02:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
PRC - [2010.09.14 05:45:56 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2010.09.14 05:45:44 | 000,508,264 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010.08.21 00:53:08 | 000,689,472 | ---- | M] (SoftThinks SAS) -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
PRC - [2010.08.20 00:06:56 | 000,487,562 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
PRC - [2010.08.12 00:19:16 | 000,781,536 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
PRC - [2010.05.28 15:29:26 | 002,650,112 | ---- | M] (DATA BECKER GmbH & Co KG) -- C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe
PRC - [2009.07.14 00:15:34 | 002,250,640 | ---- | M] (Salfeld Computer) -- C:\Windows\SysWOW64\cchservice.exe
PRC - [2009.04.16 12:23:56 | 000,479,232 | ---- | M] (SAMSUNG ELECTRONICS) -- C:\Program Files (x86)\Samsung\EmoDio\SMSTray.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.06.24 21:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.06.24 21:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011.05.30 09:29:22 | 001,719,144 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe
MOD - [2011.05.30 09:29:20 | 002,055,816 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe
MOD - [2011.05.30 09:25:32 | 007,938,048 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\QtGui4.dll
MOD - [2011.05.30 09:25:32 | 002,225,664 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\QtCore4.dll
MOD - [2010.12.17 16:25:22 | 000,686,704 | ---- | M] () -- C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
MOD - [2010.11.25 04:44:02 | 000,375,280 | ---- | M] () -- c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll
MOD - [2010.11.17 16:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
MOD - [2010.08.12 00:19:34 | 000,077,024 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll
MOD - [2010.08.12 00:19:32 | 000,109,792 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll
MOD - [2010.08.12 00:19:32 | 000,072,928 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll
MOD - [2010.08.12 00:19:30 | 000,232,672 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll
MOD - [2010.08.12 00:19:30 | 000,126,176 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll
MOD - [2010.08.12 00:19:30 | 000,119,008 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll
MOD - [2010.08.12 00:19:26 | 001,121,504 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\LibXml2.dll
MOD - [2010.08.12 00:19:16 | 000,781,536 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2010.11.29 21:00:56 | 000,149,504 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV:64bit: - [2010.09.23 00:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2011.12.14 20:49:17 | 003,316,000 | ---- | M] () [Auto | Running] -- c:\program files (x86)\common files\akamai/netsession_win_b427739.dll -- (Akamai)
SRV - [2011.09.23 17:37:42 | 000,641,832 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011.09.05 17:00:52 | 000,393,648 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe -- (Kodak AiO Network Discovery Service)
SRV - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.06.29 10:25:28 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.19 07:44:40 | 000,993,848 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
SRV - [2011.04.19 07:44:40 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2011.03.28 15:15:04 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.01.24 21:34:06 | 000,991,296 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service)
SRV - [2011.01.24 21:34:04 | 001,298,496 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service)
SRV - [2011.01.24 21:33:30 | 000,901,184 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor)
SRV - [2010.12.21 00:24:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010.12.21 00:24:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.12.17 20:41:32 | 001,515,792 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel(R)
SRV - [2010.12.17 20:28:46 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV - [2010.12.17 20:26:50 | 000,836,880 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel(R)
SRV - [2010.11.30 03:04:00 | 001,997,416 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2010.11.29 03:31:42 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2010.11.25 11:34:18 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12)
SRV - [2010.11.25 11:33:18 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM)
SRV - [2010.09.30 02:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor9.0)
SRV - [2010.09.14 05:45:56 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2010.09.14 05:45:44 | 000,508,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010.08.26 02:28:54 | 002,823,000 | ---- | M] (Dell, Inc.) [Auto | Running] -- C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe -- (NOBU)
SRV - [2010.08.25 08:56:38 | 000,765,592 | ---- | M] (Salfeld Computer) [Auto | Stopped] -- C:\Windows\SysWOW64\ksupmgr.exe -- (ksupmgr)
SRV - [2010.08.21 00:53:08 | 000,689,472 | ---- | M] (SoftThinks SAS) [Auto | Running] -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE -- (SftService)
SRV - [2010.05.28 15:29:26 | 002,650,112 | ---- | M] (DATA BECKER GmbH & Co KG) [Auto | Running] -- C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe -- (DBService)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.11.18 03:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Programme\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2011.08.31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011.07.13 12:59:54 | 000,072,240 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NBVol.sys -- (NBVol)
DRV:64bit: - [2011.07.13 12:59:54 | 000,015,920 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NBVolUp.sys -- (NBVolUp)
DRV:64bit: - [2011.06.29 10:25:28 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011.06.29 10:25:28 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.06.10 05:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.04.12 10:45:50 | 000,018,432 | ---- | M] (TPMX Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HPub4DE3.sys -- (HPub4DE3) USB Mouse Low Filter Driver_4DE3 (WDF Version)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.03.09 09:44:44 | 000,025,088 | ---- | M] (TPMX Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HPMo4DE3.sys -- (HPMo4DE3) Mouse Suite Driver_4DE3 (WDF Version)
DRV:64bit: - [2011.02.10 23:52:34 | 000,181,760 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2011.02.10 23:52:34 | 000,082,432 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2011.01.28 09:57:14 | 012,273,408 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011.01.24 08:24:52 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux)
DRV:64bit: - [2011.01.24 08:22:48 | 000,059,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (iBtFltCoex)
DRV:64bit: - [2011.01.24 07:56:06 | 000,274,944 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf)
DRV:64bit: - [2011.01.13 02:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010.12.22 10:08:48 | 008,505,856 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64) ___ Intel(R)
DRV:64bit: - [2010.12.17 18:06:32 | 001,404,464 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010.12.15 18:02:04 | 000,174,168 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR)
DRV:64bit: - [2010.12.13 18:34:14 | 000,027,760 | ---- | M] (ST Microelectronics) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelern.sys -- (Acceler)
DRV:64bit: - [2010.12.12 15:18:36 | 000,121,960 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvstusb.sys -- (NvStUSB)
DRV:64bit: - [2010.11.30 03:04:00 | 000,025,576 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvpciflt.sys -- (nvpciflt)
DRV:64bit: - [2010.11.29 21:00:04 | 000,016,120 | ---- | M] (Intel(R) Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 10:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010.10.20 01:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel(R)
DRV:64bit: - [2010.10.16 01:28:18 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV:64bit: - [2010.09.14 05:45:52 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2010.09.14 05:45:50 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2010.09.14 05:45:48 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2010.09.14 05:45:44 | 000,760,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2010.09.01 09:30:58 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI)
DRV:64bit: - [2010.08.20 10:05:12 | 000,021,616 | ---- | M] (ST Microelectronics) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\stdcfltn.sys -- (stdcfltn)
DRV:64bit: - [2010.08.12 16:51:30 | 000,175,168 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV:64bit: - [2010.07.13 03:38:06 | 000,029,288 | ---- | M] (Quanta Computer) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qicflt.sys -- (qicflt)
DRV:64bit: - [2010.06.11 17:14:00 | 001,799,808 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVer7231_x64.sys -- (AVer7231_x64)
DRV:64bit: - [2010.03.19 09:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2010.02.27 16:32:14 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010.02.24 11:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11)
DRV:64bit: - [2009.08.13 21:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 01:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2006.11.01 18:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2011.07.22 17:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV - [2011.07.12 22:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2006.11.28 21:46:24 | 000,028,224 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\PDNMp50.sys -- (PDNMp50)
DRV - [2006.11.28 21:46:22 | 000,027,072 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\PDNSp50.sys -- (PDNSp50)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 3C D9 A7 7C 86 BD CC 01  [binary data]
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50263
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "www.google.de"
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50263
FF - prefs.js..network.proxy.type: 0
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF:64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.12.15 11:29:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.11 09:40:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.12.15 11:29:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Components: C:\Program Files (x86)\Mozilla Sunbird\components [2011.12.15 11:29:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Sunbird\plugins [2011.12.15 11:29:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.11.11 18:53:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 
[2011.05.19 12:42:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Extensions
[2011.05.19 12:42:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.09.12 11:27:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\3cers2zs.default\extensions
[2011.11.11 09:40:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.10.01 08:52:30 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.10.17 08:31:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011.10.29 10:21:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011.12.15 11:29:03 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011.11.11 09:40:26 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.10.29 10:21:40 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.09.16 21:59:18 | 000,170,064 | ---- | M] (Tracker Software Products Ltd.) -- C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2011.09.29 02:24:37 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.09.29 02:24:37 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.09.29 02:24:37 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.29 02:24:37 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
 
O1 HOSTS File: ([2011.09.12 21:31:56 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation)
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\SysNative\spool\drivers\x64\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4:64bit: - HKLM..\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [NVHotkey] C:\Windows\SysNative\nvHotkey.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ChicoSys] C:\Windows\SysWOW64\cc32\webtmr.exe (Salfeld Computer)
O4 - HKLM..\Run: [Conime] %windir%\system32\conime.exe File not found
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NBAgent] C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [SMSTray] C:\Program Files (x86)\Samsung\EmoDio\SMSTray.exe (SAMSUNG ELECTRONICS)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\.DEFAULT..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-18..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O4 - HKU\.DEFAULT..\RunOnce: [KodakHomeCenter] C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O4 - HKU\S-1-5-18..\RunOnce: [KodakHomeCenter] C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O4 - Startup: C:\Users\Jasmina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Nico.dell-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C8601AA9-2FCA-424D-B13E-12984594DCE3}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) -C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - Unable to read "AutoRun" value or value not present!
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.12.18 13:56:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2011.12.18 08:32:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011.12.18 08:32:32 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011.12.18 08:06:21 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.12.17 09:35:49 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\SUPERAntiSpyware.com
[2011.12.17 09:35:34 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011.12.16 09:08:32 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\RealNetworks
[2011.12.15 11:50:27 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\SoftGrid Client
[2011.12.15 11:50:25 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\SoftGrid Client
[2011.12.15 11:47:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.12.15 11:47:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.12.15 11:35:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.12.15 11:34:51 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.12.15 11:34:50 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011.12.15 11:34:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011.12.15 11:29:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared
[2011.12.15 11:29:01 | 000,198,832 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2011.12.15 11:28:57 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2011.12.15 11:28:57 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2011.12.15 11:28:56 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2011.12.15 11:28:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
[2011.12.15 11:25:22 | 000,713,472 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer.exe
[2011.12.15 11:22:52 | 000,000,000 | -HSD | C] -- C:\Users\Administrator\AppData\Local\4d0d2e25
[2011.12.15 11:14:51 | 009,852,544 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Program Files (x86)\mbam-setup-1.51.2.1300.exe
[2011.12.15 10:41:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.12.15 10:41:55 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.12.15 10:39:52 | 003,552,208 | ---- | C] (Piriform Ltd) -- C:\Program Files (x86)\ccsetup313.exe
[2011.12.15 08:29:11 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Desktop\Anti-Virus Maßnahmen
[2011.12.14 23:09:17 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2011.12.14 23:09:17 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2011.12.14 23:09:15 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2011.12.14 08:33:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LP
[2011.12.02 16:28:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Nexon
[2011.12.02 16:25:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon
[2011.12.02 16:22:22 | 000,000,000 | ---D | C] -- C:\ProgramData\NexonEU
[2011.12.02 15:45:54 | 000,000,000 | ---D | C] -- C:\Download
[2011.12.02 15:45:20 | 000,000,000 | ---D | C] -- C:\Nexon
[2011.12.02 15:45:19 | 000,446,464 | ---- | C] (NEXON Inc.) -- C:\Windows\NEXON_EU_DownloaderUpdater.exe
[2011.11.24 09:38:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak
[2011.11.24 09:36:02 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\spool
[2011.11.24 09:23:29 | 012,713,136 | ---- | C] (Eastman Kodak Company) -- C:\Program Files (x86)\aio_install.exe
[2011.10.29 11:49:39 | 039,401,336 | ---- | C] (Apple Inc.) -- C:\Program Files (x86)\QuickTimeInstaller.exe
[2011.10.29 11:04:38 | 010,311,496 | ---- | C] (Opera Software ASA) -- C:\Program Files (x86)\Opera_1152_int_Setup.exe
[2011.10.29 10:10:18 | 000,910,624 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\jxpiinstall.exe
[2011.10.25 12:17:18 | 009,756,672 | ---- | C] ((c) Phoenix Technologies Ltd. ) -- C:\Program Files\L502X_A__06.exe
[2011.10.17 08:29:10 | 001,739,400 | ---- | C] (Secunia) -- C:\Program Files (x86)\PSISetup2003.exe
[2011.10.17 08:05:48 | 013,885,360 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 7.0.1.exe
[2011.09.24 17:12:36 | 001,291,624 | ---- | C] (Microsoft Corporation) -- C:\Program Files\wlsetup-web__1_.exe
[2011.09.23 14:09:00 | 000,676,624 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer_1406666_de.exe
[2011.09.22 10:34:36 | 003,089,056 | ---- | C] (Adobe Systems, Inc.) -- C:\Program Files (x86)\install_flash_player.exe
[2011.08.28 11:11:15 | 051,975,388 | ---- | C] (Acresso Software Inc.) -- C:\Program Files (x86)\VSX4_Pro_TBYB.exe.part
[2011.08.27 11:56:04 | 001,228,384 | ---- | C] (Adobe Systems Incorporated) -- C:\Program Files (x86)\PremiereElements_9_LS15.exe
[2011.08.25 17:58:21 | 006,716,353 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Sunbird_Setup_1.0_Beta_1.exe
[2011.07.18 15:59:52 | 013,522,064 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 5.0.1.exe
[2011.05.28 13:13:41 | 014,212,584 | ---- | C] (DVDVideoSoft Ltd.                                          ) -- C:\Program Files (x86)\FreeYouTubeToiPodConverter.exe
[2011.05.28 13:11:38 | 014,563,768 | ---- | C] (DVDVideoSoft Ltd.                                          ) -- C:\Program Files (x86)\FreeYouTubeToMP3Converter.exe
[2011.05.22 09:35:05 | 021,255,560 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files (x86)\SkypeSetupFull.exe
[2011.05.19 14:37:24 | 081,797,928 | ---- | C] (Apple Inc.) -- C:\Program Files (x86)\iTunes64Setup.exe
[2011.05.19 14:17:51 | 020,240,744 | ---- | C] (The GIMP Team                                              ) -- C:\Program Files (x86)\gimp-2.6.11-i686-setup.exe
[2011.05.19 14:17:11 | 019,735,256 | ---- | C] (                                                            ) -- C:\Program Files (x86)\gimp-2.6.8-x64-setup.exe
[2011.05.19 14:06:00 | 000,767,064 | ---- | C] (NCH Software) -- C:\Program Files (x86)\wpsetup4.57.exe
[2011.05.19 12:34:44 | 000,568,648 | ---- | C] (Google Inc.) -- C:\Program Files (x86)\GoogleEarthSetup.exe
[2011.05.19 12:26:57 | 009,559,320 | ---- | C] (Opera Software ASA) -- C:\Program Files (x86)\Opera_1111_int_Setup.exe
[2011.05.19 12:26:00 | 009,326,056 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Thunderbird Setup 3.1.10.exe
[2011.05.19 12:25:04 | 012,362,480 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 4.0.1.exe
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.12.18 14:28:00 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025UA.job
[2011.12.18 14:11:44 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.12.18 14:11:44 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.12.18 14:09:10 | 000,001,963 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.12.18 14:04:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.12.18 14:04:01 | 3137,994,752 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.18 13:43:51 | 000,001,207 | ---- | M] () -- C:\Windows\SysWow64\excltmp~.dat
[2011.12.18 08:07:06 | 000,008,019 | ---- | M] () -- C:\Windows\SysWow64\cchservice.err
[2011.12.18 08:07:00 | 000,000,735 | ---- | M] () -- C:\Windows\SysWow64\ccsync.err
[2011.12.17 12:09:26 | 000,001,595 | ---- | M] () -- C:\Users\Administrator\Desktop\DELL-PC - Verknüpfung.lnk
[2011.12.15 11:47:50 | 000,001,162 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.12.15 11:35:17 | 000,001,836 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.12.15 11:29:01 | 000,198,832 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2011.12.15 11:28:57 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2011.12.15 11:28:57 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2011.12.15 11:28:56 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2011.12.15 11:25:23 | 000,713,472 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer.exe
[2011.12.15 11:22:41 | 001,500,062 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.12.15 11:22:41 | 000,654,798 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.12.15 11:22:41 | 000,616,640 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.12.15 11:22:41 | 000,130,380 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.12.15 11:22:41 | 000,106,762 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.12.15 11:14:56 | 009,852,544 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Program Files (x86)\mbam-setup-1.51.2.1300.exe
[2011.12.15 10:41:56 | 000,000,824 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.12.15 10:39:52 | 003,552,208 | ---- | M] (Piriform Ltd) -- C:\Program Files (x86)\ccsetup313.exe
[2011.12.15 08:25:41 | 000,353,408 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.12.15 08:02:34 | 000,000,118 | ---- | M] () -- C:\Windows\SysNative\MRT.INI
[2011.12.14 21:33:43 | 000,000,348 | ---- | M] () -- C:\NET.INI
[2011.12.14 08:38:37 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011.12.02 16:25:10 | 000,001,632 | ---- | M] () -- C:\Users\Public\Desktop\Combat Arms EU.lnk
[2011.12.02 15:45:20 | 000,000,235 | ---- | M] () -- C:\Windows\SysWow64\nxEuUninstall.bat
[2011.12.02 15:45:19 | 000,446,464 | ---- | M] (NEXON Inc.) -- C:\Windows\NEXON_EU_DownloaderUpdater.exe
[2011.11.24 09:39:41 | 000,002,209 | ---- | M] () -- C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
[2011.11.24 09:23:39 | 012,713,136 | ---- | M] (Eastman Kodak Company) -- C:\Program Files (x86)\aio_install.exe
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.12.18 14:05:28 | 000,001,492 | ---- | C] () -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011.12.18 14:05:28 | 000,001,407 | ---- | C] () -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011.12.18 08:32:34 | 000,001,963 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.12.18 08:06:30 | 000,000,735 | ---- | C] () -- C:\Windows\SysWow64\ccsync.err
[2011.12.17 12:09:26 | 000,001,595 | ---- | C] () -- C:\Users\Administrator\Desktop\DELL-PC - Verknüpfung.lnk
[2011.12.16 10:33:33 | 000,008,019 | ---- | C] () -- C:\Windows\SysWow64\cchservice.err
[2011.12.15 11:47:50 | 000,001,162 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.12.15 11:35:17 | 000,001,836 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.12.15 10:41:56 | 000,000,824 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.12.15 08:02:34 | 000,000,118 | ---- | C] () -- C:\Windows\SysNative\MRT.INI
[2011.12.02 16:25:10 | 000,001,632 | ---- | C] () -- C:\Users\Public\Desktop\Combat Arms EU.lnk
[2011.12.02 15:45:20 | 000,000,235 | ---- | C] () -- C:\Windows\SysWow64\nxEuUninstall.bat
[2011.11.24 09:39:41 | 000,002,209 | ---- | C] () -- C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
[2011.11.11 07:32:42 | 001,527,140 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.10.29 09:54:07 | 001,019,816 | ---- | C] () -- C:\Program Files\DELL_DELL-DIGITAL-DELIVERY_A05_R313622.exe
[2011.10.10 16:51:50 | 000,155,536 | ---- | C] () -- C:\Windows\SysWow64\dllcinx.exe
[2011.10.10 16:51:48 | 000,000,600 | ---- | C] () -- C:\Windows\SysWow64\nochook.ini
[2011.10.03 13:41:52 | 000,247,053 | ---- | C] () -- C:\Program Files (x86)\mp3DC213.exe
[2011.09.29 09:19:37 | 000,001,207 | ---- | C] () -- C:\Windows\SysWow64\excltmp~.dat
[2011.09.29 09:18:42 | 000,000,141 | -H-- | C] () -- C:\Windows\SysWow64\ctlsw.ini
[2011.09.29 09:18:42 | 000,000,102 | ---- | C] () -- C:\Windows\SysWow64\SWCTL.DLL
[2011.09.29 08:11:44 | 000,124,416 | ---- | C] () -- C:\Windows\SysWow64\dXCtrls.dll
[2011.09.29 08:11:43 | 000,544,256 | ---- | C] () -- C:\Windows\SysWow64\janGraphics.dll
[2011.09.29 07:55:01 | 003,103,511 | ---- | C] () -- C:\Program Files (x86)\kcsetup8.exe
[2011.09.23 14:05:53 | 021,073,936 | ---- | C] () -- C:\Program Files (x86)\vlc-1.1.11-win32.exe
[2011.09.23 12:51:28 | 000,003,027 | ---- | C] () -- C:\Program Files (x86)\Français.lng
[2011.09.23 12:51:28 | 000,002,946 | ---- | C] () -- C:\Program Files (x86)\Español.lng
[2011.09.23 12:51:28 | 000,002,920 | ---- | C] () -- C:\Program Files (x86)\Italiano.lng
[2011.09.23 12:51:28 | 000,002,699 | ---- | C] () -- C:\Program Files (x86)\Deutsch.lng
[2011.09.23 12:51:28 | 000,002,553 | ---- | C] () -- C:\Program Files (x86)\Suomi.lng
[2011.09.23 12:40:52 | 023,773,184 | ---- | C] () -- C:\Program Files (x86)\PXCViewer98_x64.msi
[2011.09.23 12:27:47 | 001,376,768 | ---- | C] () -- C:\Program Files (x86)\7z920-x64.msi
[2011.09.16 06:44:01 | 168,166,968 | ---- | C] () -- C:\Program Files (x86)\OOo_3.3.0_Win_x86_install-wJRE_de.exe
[2011.08.28 09:55:59 | 002,466,704 | ---- | C] () -- C:\Program Files (x86)\AdobeDownloadAssistant.exe
[2011.08.27 11:27:07 | 1316,066,539 | ---- | C] () -- C:\Program Files (x86)\PremiereElements_9_LS15.7z
[2011.08.27 11:23:03 | 008,353,800 | ---- | C] () -- C:\Program Files (x86)\Adobe_Premiere_Elements_9-AkamaiDLM.exe
[2011.05.19 14:44:09 | 001,663,693 | ---- | C] () -- C:\Program Files (x86)\winrar-x64-400d.exe
[2011.05.19 14:10:20 | 014,166,016 | ---- | C] () -- C:\Program Files (x86)\wz150gev.msi
[2011.05.19 14:09:07 | 006,088,218 | ---- | C] () -- C:\Program Files (x86)\flash_player.zip
[2011.05.19 13:52:49 | 000,000,056 | ---- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011.05.19 12:39:40 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.05.19 12:28:56 | 052,718,176 | ---- | C] () -- C:\Program Files (x86)\avira_antivir_personal_de.exe
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_89001461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_49001461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_33011461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_8a.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A0F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_8a.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_14001461_61.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_13011461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_110F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_110F1461_8a.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_ca.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_aa.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_8a.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_ca.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_aa.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_8a.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_890F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_2B0f1461_ca.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_29001461_ca.bin
[2011.05.15 06:48:49 | 000,000,412 | ---- | C] () -- C:\Windows\11317231_180F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,412 | ---- | C] () -- C:\Windows\11317231_18071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_11071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_11071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A0F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A031461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A031461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A011461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_09001461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_08071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_060F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_06071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_06071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_03011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_03011461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_02011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_02011461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_010F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_010F1461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_01071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_01071461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_07031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_ca.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03131461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_ca.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_8a.bin
[2011.05.15 06:48:48 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_0B0f1461_ca.bin
[2011.05.15 06:48:48 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_090F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,376 | ---- | C] () -- C:\Windows\11317231_03131461_aa.bin
[2011.05.15 06:48:47 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_00000000_aa.bin
[2011.05.15 06:48:11 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011.05.15 06:47:21 | 000,960,940 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.05.15 06:47:19 | 000,213,332 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.05.15 06:47:17 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.01.19 12:34:42 | 003,003,392 | ---- | C] () -- C:\Program Files (x86)\openofficeorg33.msi
[2011.01.19 12:33:04 | 000,475,016 | ---- | C] () -- C:\Program Files (x86)\setup.exe
[2011.01.19 12:30:10 | 142,700,671 | ---- | C] () -- C:\Program Files (x86)\openofficeorg1.cab
[2011.01.19 11:15:26 | 000,000,290 | ---- | C] () -- C:\Program Files (x86)\setup.ini
[2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009.04.16 12:24:14 | 000,921,600 | ---- | C] () -- C:\Windows\SysWow64\vorbisenc.dll
[2009.04.16 12:24:14 | 000,237,568 | ---- | C] () -- C:\Windows\SysWow64\OggDS.dll
[2009.04.16 12:24:14 | 000,188,416 | ---- | C] () -- C:\Windows\SysWow64\vorbis.dll
[2009.04.16 12:24:14 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\Ogg.dll
 
========== LOP Check ==========
 
[2011.05.23 15:49:56 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\CheckPoint
[2011.05.19 12:45:49 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.09.10 15:33:36 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Fingertapps
[2011.05.19 14:07:13 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\NCH Swift Sound
[2011.05.19 13:04:35 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\OpenOffice.org
[2011.10.29 11:10:08 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Opera
[2011.12.18 08:37:34 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\SoftGrid Client
[2011.11.18 10:33:58 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Temp
[2011.05.21 10:57:03 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Thunderbird
[2011.09.13 07:51:26 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Temp
[2011.09.13 07:51:26 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Temp
[2011.07.15 14:23:05 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\2K Sports
[2011.12.15 21:45:19 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\57168
[2011.12.15 21:45:19 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\B8457
[2011.09.01 18:51:14 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011.05.23 16:30:23 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\CheckPoint
[2011.08.28 09:58:29 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011.09.10 14:11:11 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\DriverFinder
[2011.10.01 08:51:21 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\DVDVideoSoft
[2011.10.01 08:51:16 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.06.30 08:10:18 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Fingertapps
[2011.06.20 07:07:01 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\go
[2011.12.16 12:46:12 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\gtk-2.0
[2011.11.07 19:23:04 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Leadertech
[2011.10.07 10:12:34 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\mp3DirectCut
[2011.06.24 07:34:10 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\NCH Swift Sound
[2011.05.20 17:29:32 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\OpenOffice.org
[2011.10.04 20:00:10 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Opera
[2011.05.31 06:51:05 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\ProtectDisc
[2011.09.20 10:55:01 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\QuickScan
[2011.07.06 19:23:10 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Temp
[2011.05.21 12:10:22 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Thunderbird
[2011.11.11 07:33:12 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\TP
[2011.07.17 14:24:06 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Ulead Systems
[2011.09.07 10:57:41 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Uniblue
[2011.10.09 13:43:13 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\2K Sports
[2011.12.15 21:45:19 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\57168
[2011.12.15 08:04:04 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\B8457
[2011.10.27 10:01:00 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\DVDVideoSoft
[2011.09.29 09:43:26 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Fingertapps
[2011.10.27 10:57:32 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\MusicNet
[2011.10.18 19:17:26 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\OpenOffice.org
[2011.11.07 19:36:36 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Origin
[2011.09.13 07:51:26 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Temp
[2011.09.29 09:59:09 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Thunderbird
[2011.12.18 14:28:00 | 000,000,948 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025UA.job
[2011.12.04 15:25:34 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
< End of report >:


Rheingold 18.12.2011 17:58

:
Code:

OTL Extras logfile created on: 18.12.2011 16:36:35 - Run 9
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Administrator\Desktop\Anti-Virus Maßnahmen\OTL
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,90 Gb Total Physical Memory | 1,72 Gb Available Physical Memory | 44,19% Memory free
7,79 Gb Paging File | 5,53 Gb Available in Paging File | 70,95% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 235,24 Gb Total Space | 110,47 Gb Free Space | 46,96% Space Free | Partition Type: NTFS
Drive D: | 215,77 Gb Total Space | 206,35 Gb Free Space | 95,63% Space Free | Partition Type: NTFS
 
Computer Name: DELL-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
 
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableSR" = 1
"DisableConfig" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableSR" = 1
"DisableConfig" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Nexon\Combat Arms EU\CombatArms.exe" = C:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\Engine.exe" = C:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\CombatArms.exe" = C:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\Engine.exe" = C:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe -- (Nexon)
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe" = [String data over 1000 bytes]
"C:\Nexon\Combat Arms EU\CombatArms.exe" = C:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\Engine.exe" = C:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe -- (Nexon)
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe" = [String data over 1000 bytes]
"C:\Nexon\Combat Arms EU\CombatArms.exe" = C:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\Engine.exe" = C:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe -- (Nexon)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}" = Kodak AIO Printer
"{290D4DB2-F1B4-4B8E-918D-D71EF29A001B}" = Intel(R) PROSet/Wireless WiFi-Software
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90140000-006D-0407-1000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}" = RBVirtualFolder64Inst
"{9ED333F8-3E6C-4A38-BAFA-728454121CDA}" = PDF-XChange Viewer
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 265.94
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 265.94
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 265.94
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.0.9
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}" = Überwachungstool für die Intel® Turbo-Boost-Technik 2.0
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{BE930E38-7BB3-45B6-85B2-5251F374F844}" = 64 Bit HP CIO Components Installer
"{C7B40C35-85AE-4303-9EEA-1A1EA779664D}" = Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D600D357-5CB9-4DE9-8FD4-14E208BD1970}" = Nero Backup Drivers
"{D66F0C3C-24F2-4463-9E2F-4381E5C40A26}" = iTunes
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"CCleaner" = CCleaner
"Dell Support Center" = Dell Support Center
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinGimp-2.0_is1" = GIMP 2.6.8
"WinRAR archiver" = WinRAR 4.00 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01E9B2FF-DAF4-4529-9CC9-2101625517C7}" = nero.prerequisites.msi
"{034DCAF9-96E7-4936-9A07-712F80B5181E}" = Nero RescueAgent 11
"{0713D1F9-DD77-42C1-8C7D-54D479E2E743}" = Nero SoundTrax 11
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D7A4289-99CF-4B8D-B812-86BE50A54552}" = Nero Video 11
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{11D3EF85-63E1-4AE4-A7C1-9241BDB16B51}" = Nero ControlCenter 11
"{1D4EE8FE-F31C-4258-9360-5B8B8309B14B}" = Adobe Premiere Elements 9 Content
"{1D7CE340-70C3-4848-BCCF-215950328A4C}" = Facebook Video Calling 1.0.0.8953
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{25175695-4B20-4298-9F34-C2C57CD277B3}" = Elements STI Installer
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java(TM) 6 Update 29
"{27107EAA-34E0-43BF-B537-7F8EF6880F5A}" = Facebook Video Calling 1.0.0.8177
"{289AC7E0-0AEE-4a7b-913C-709D9803D23E}" = Nexon Game Manager
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2CA7225D-CB12-462A-9DD1-50319E158BA5}" = Nero 11 PiP Effects Basic
"{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5
"{3250260C-7A95-4632-893B-89657EB5545B}" = PhotoShowExpress
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{3443D416-9DAD-4362-BEB1-C213AD9062CD}" = Dell MusicStage
"{376348C2-E372-48BC-A138-E896757BD86A}" = aioscnnr
"{37AB0223-AF54-49C5-92AA-BFC9648CD323}" = Adobe Premiere Elements 9 HD Content 3
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{390757AA-8830-43DC-AEE0-4E5B6F8439EB}" = Nero SoundTrax 11 Help (CHM)
"{3CBBE028-978B-4876-ABC1-EF9ED6C20C4E}" = Adobe Premiere Elements 9 Content 2
"{3EE2F527-F306-49E9-0086-662C337ADD3B}" = FUSSBALL MANAGER 07
"{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C}" = FIFA 11
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{433EACD8-4747-4A6A-826A-FFA9F39B0D40}" = Elements 9 Organizer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50D90C59-4F5C-48BC-AFB2-38475412F0CA}" = Adobe Premiere Elements 9 Content 1
"{53F7746A-96AA-49A5-86B8-59989680DAC5}" = Nero Burning ROM 11 Help (CHM)
"{55C2143E-FBA5-442F-9AFA-726FF068F39D}" = Nero CoverDesigner 11 Help (CHM)
"{56BA241F-580C-43D2-8403-947241AAE633}" = center
"{57F80ECF-E27C-4EEE-AB58-E971BACE2639}" = Nero Recode 11 Help (CHM)
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{5A212B2D-140D-46F4-B625-2D1CA5A00594}" = Nero 11 Kwik Themes Basic
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5F9AAF4A-B9B0-489D-AE67-73470A4714FE}" = Adobe Premiere Elements 9 HD Content 1
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6AB2427E-A18F-4809-9A12-29F5EBABBB3A}" = Nero BackItUp 11 Help (CHM)
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}" = Roxio Creator Starter
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7746BFAA-2B5D-4FFD-A0E8-4558F4668105}" = Roxio Burn
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7DDC3624-C631-49D1-B281-82EC3A27AA7C}" = Adobe Premiere Elements 9 Content 3
"{7EC66A95-AC2D-4127-940B-0445A526AB2F}" = Dell DataSafe Online
"{8014FACB-1D1D-48C2-94AA-E29EE2E6B9CE}" = Nero WaveEditor 11
"{81DD0597-29EB-4FA0-8223-4F41362B2E72}" = NBA 2K11
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{87434D51-51DB-4109-B68F-A829ECDCF380}" = AccelerometerP11
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch
"{9193490D-5229-4FC4-9BB9-A6D63C09574A}" = High-Definition Video Playback
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Sonic CinePlayer Decoder Pack
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet-TV für Windows Media Center
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A7A0BF2E-31CC-49E3-9913-52C503EB969D}" = Nero Audio Pack 1
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AB2BBC64-8AC8-4E66-BBF3-E22D5EACEECA}" = Nero BackItUp 11
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B1846721-A8E6-46C7-83B6-0DCF7ADB4267}" = Nero Burning ROM 11
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B7E01095-8BAA-456E-8AED-504C3CCADBA0}" = Nero 11
"{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"{B9B1BA7F-7E07-49DD-A713-5B397A5BB66B}" = Nero Kwik Media Help (CHM)
"{BE814218-3919-4EA3-868A-2F60BC135CB4}" = Nero Kwik Media
"{BE94C681-68E2-4561-8ABC-8D2E799168B4}" = essentials
"{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components 11
"{BFBCF96F-7361-486A-965C-54B17AC35421}" = ocr
"{C19BE821-89B1-4A96-AC7C-873810C0CB5F}" = ContentSAFER for Wizmax
"{C20CE592-B0F8-4D20-BF31-0151CA6331A6}" = EmoDio
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{CCE210DF-7EEF-4A76-A63C-3EB091FDB992}" = welcome
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D01CE99A-8802-483C-A79F-298B691EB432}" = Nero RescueAgent 11 Help (CHM)
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D2CBEFA4-F2D3-4E97-A171-8BFD6A31A5EC}" = Nero Express 11 Help (CHM)
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4D66270-9147-4BDF-9946-FCA2B303AA8F}" = Nero ControlCenter 11 Help (CHM)
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DC0C5A78-6DBF-3444-0120-0FE8F0134FCD}" = Adobe Download Assistant
"{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK All-in-One Software
"{E10AAE4A-98B8-420A-BD93-E0520C23D624}" = Nero Express 11
"{E240C78D-8F35-456A-8876-15FF6901B7E0}" = Adobe Premiere Elements 9 HD Content 2
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E4335E82-17B3-460F-9E70-39D9BC269DB3}" = Dell PhotoStage
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E51BC4B0-EA5E-49CC-AF3B-93B5C627EC22}" = Nero 11 Effects Basic
"{E9F59205-F128-49A7-9039-4BDFB60EE4A3}" = Dell Stage
"{EB8DED20-A887-4A9C-BB5A-F3E7523DFB44}" = Nero WaveEditor 11 Help (CHM)
"{EB9955F8-467C-47FC-90F8-12CD5DF684C3}" = Adobe Premiere Elements 9
"{EC7FE03D-239A-4E36-9907-0E327922D2A2}" = bpd_scan
"{EF53BFAB-4C10-40DB-A82D-9B07111715C6}" = aioscnnr
"{EF56258E-0326-48C5-A86C-3BAC26FC15DF}" = Roxio Creator Starter
"{F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}" = Roxio Creator Starter
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F302F4F0-588D-6501-1ACF-BE3FDCC9135D}" = Adobe Community Help
"{F3743A2C-5D5F-4456-8F98-5DF36A954C50}" = Nero 11 Image Samples
"{F49EF443-B2BD-4F10-8A46-87AFCDB90EDD}" = Nero 11 Disc Menus Basic
"{F69FB940-5031-4FE8-AFAD-085802D0BF63}" = Nero Recode 11
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FAC3C37E-EDAB-4F3A-A173-A7C70CC88F09}" = Nero Video 11 Help (CHM)
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF44BCE5-5A18-4051-85F0-BC172D7B4695}" = Nero CoverDesigner 11
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Premiere Elements 9 Content" = Adobe Premiere Elements 9 Content
"Adobe Premiere Elements 9 Content 1" = Adobe Premiere Elements 9 Content 1
"Adobe Premiere Elements 9 Content 2" = Adobe Premiere Elements 9 Content 2
"Adobe Premiere Elements 9 Content 3" = Adobe Premiere Elements 9 Content 3
"Adobe Premiere Elements 9 HD Content 1" = Adobe Premiere Elements 9 HD Content 1
"Adobe Premiere Elements 9 HD Content 2" = Adobe Premiere Elements 9 HD Content 2
"Adobe Premiere Elements 9 HD Content 3" = Adobe Premiere Elements 9 HD Content 3
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Akamai" = Akamai NetSession Interface Service
"AVerMedia H339 Hybrid TV Tuner" = AVerMedia H339 Hybrid TV Tuner 2.2.64.64
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BewerbungsGenie 7_is1" = DATA BECKER BewerbungsGenie 7
"BurningWheels" = Cobra 11 - Burning Wheels (remove only)
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"Combat Arms EU" = Combat Arms EU
"Dell Webcam Central" = Dell Webcam Central
"ESET Online Scanner" = ESET Online Scanner v3
"ExpressBurn" = Express Burn Disc Burning Software
"ExpressRip" = Express Rip
"Free YouTube to iPod Converter_is1" = Free YouTube to iPod Converter version 3.10.8.815
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.8.815
"InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5
"InstallShield_{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0
"InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"InstallShield_{C20CE592-B0F8-4D20-BF31-0151CA6331A6}" = EmoDio
"InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"Kindersicherung_is1" = Kindersicherung 2011
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.2.1300
"MixPad" = MixPad Audio Mixer
"Mozilla Firefox 8.0 (x86 de)" = Mozilla Firefox 8.0 (x86 de)
"Mozilla Thunderbird (8.0)" = Mozilla Thunderbird (8.0)
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.Click2Run" = Microsoft Office Klick-und-Los 2010
"Opera 11.52.1100" = Opera 11.52
"PremElem90" = Adobe Premiere Elements 9
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"Secunia PSI" = Secunia PSI (2.0.0.3003)
"VLC media player" = VLC media player 1.1.11
"WavePad" = WavePad Sound Editor
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
 
========== Last 10 Event Log Errors ==========
 
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
 
< End of report >:


Rheingold 18.12.2011 18:03

:kloppen:sorry, den otl file habe ich mehrfach reingesetzt.

kira 19.12.2011 08:48

1.
Zitat:

Achtung wichtig!:
Falls Du selber im Logfile Änderungen vorgenommen hast, musst Du durch die Originalbezeichnung ersetzen und so in Script einfügen! sonst funktioniert nicht!
(Benutzerordner, dein Name oder sonstige Änderungen durch X, Stern oder andere Namen ersetzt)
Fixen mit OTL
  • Starte die OTL.exe.
  • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
  • Kopiere folgendes Skript:
Code:

:OTL
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50263
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50263
FF - prefs.js..network.proxy.type: 0

:Commands
[purity]
[emptytemp]


2.
reinige dein System mit CCleaner:
  • "Cleaner"→ "Analysieren"→ Klick auf den Button "Start CCleaner"
  • "Registry""Fehler suchen"→ "Fehler beheben"→ "Alle beheben"
  • Starte dein System neu auf

3.
erneut einen Scan mit OTL:
  • Doppelklick auf die OTL.exe
  • Vista und Windows 7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen.
  • Oben findest Du ein Kästchen mit Ausgabe.
    Wähle bitte Standard-Ausgabe
  • Unter Extra-Registrierung wähle bitte Benutze SafeList.
  • Mache Häckchen bei LOP- und Purity-Prüfung.
  • Klicke nun auf Scan links oben.
  • Wenn der Scan beendet wurde werden zwei Logfiles erstellt.
    Du findest die Logfiles auf Deinem Desktop => OTL.txt und Extras.txt
  • Poste die Logfiles in Code-Tags hier in den Thread.

4.
TDSSKiller von Kaspersky
  • Lade den TDSSKiller und entpacke das Archiv auf Deinen Desktop.
  • Vergewissere Dich, dass die TDSSKiller.exe direkt auf dem Desktop liegt (nicht in einem Ordner auf dem Desktop).
  • deaktiviere vorübergehend dein AntiVirus-Programm
  • Starte die TDSSKiller.exe durch Doppelklick.
  • Nach Beendigung der Arbeit schlägt das Tool vor, das System neu zu starten.
    Bestätige das ggfs. mit Y(es).
    Beim Hochfahren des Systems führt der Treiber alle geplanten Operationen aus löscht sich danach.
  • Poste mir den Inhalt von C:\TDSSKiller<random>.txt hier in den Thread.
Hier findest Du eine ausführlichere Anleitung.

► berichte erneut über den Zustand des Computers. Ob noch Probleme auftreten, wenn ja, welche?

Rheingold 19.12.2011 15:20

Hallo Kira,
vielen Dank für deine Antwort,
werde alles so machen, wie du gesagt hast. An den logfiles habe ich keine Änderungen vorgenommen.

Viele Grüße
Jasmina

Rheingold 19.12.2011 17:58

Hallo Kira,
den otl scan habe ich durchgeführt. w-lan war aber verbunden. ist das richtig so?
Jasmina

:
Code:

All processes killed
========== OTL ==========
HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Prefs.js: "127.0.0.1" removed from network.proxy.http
Prefs.js: 50263 removed from network.proxy.http_port
Prefs.js: 0 removed from network.proxy.type
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 3956140 bytes
->Temporary Internet Files folder emptied: 39383025 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 42610391 bytes
->Flash cache emptied: 1132 bytes
 
User: All Users
 
User: AppData
->Temp folder emptied: 0 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Gast
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Jasmina
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Jasmina 2
 
User: Nico
 
User: Nico Spiele
 
User: Nico.dell-PC
 
User: Nico.dell-PC.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 66885 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
RecycleBin emptied: 0 bytes:

Total Files Cleaned = 82,00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 12192011_173519

Files\Folders moved on Reboot...
C:\Users\Administrator\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

Rheingold 19.12.2011 21:23

Hier der nächste OTl Scan:
1. otl-text
:
Code:

OTL logfile created on: 19.12.2011 21:10:01 - Run 11
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Administrator\Desktop\Anti-Virus Maßnahmen\OTL
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,90 Gb Total Physical Memory | 2,06 Gb Available Physical Memory | 52,88% Memory free
7,79 Gb Paging File | 5,73 Gb Available in Paging File | 73,50% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 235,24 Gb Total Space | 110,36 Gb Free Space | 46,92% Space Free | Partition Type: NTFS
Drive D: | 215,77 Gb Total Space | 206,35 Gb Free Space | 95,63% Space Free | Partition Type: NTFS
 
Computer Name: DELL-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011.12.15 19:37:19 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Administrator\Desktop\Anti-Virus Maßnahmen\OTL\OTL.exe
PRC - [2011.12.15 11:28:56 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2011.09.23 17:37:42 | 000,641,832 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2011.09.05 17:00:52 | 000,393,648 | ---- | M] (Eastman Kodak Company) -- C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe
PRC - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011.06.29 10:25:28 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.05.30 09:29:22 | 001,719,144 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe
PRC - [2011.05.30 09:29:20 | 002,055,816 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe
PRC - [2011.04.19 07:44:40 | 000,993,848 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe
PRC - [2011.04.19 07:44:40 | 000,399,416 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\sua.exe
PRC - [2011.04.19 07:44:40 | 000,291,896 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
PRC - [2011.03.28 15:15:04 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.03.28 15:14:56 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.01.24 21:34:06 | 000,991,296 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
PRC - [2011.01.24 21:34:04 | 001,298,496 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
PRC - [2011.01.24 21:33:30 | 000,901,184 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
PRC - [2011.01.24 21:33:24 | 000,979,008 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
PRC - [2010.12.21 00:24:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.12.21 00:24:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.12.17 16:25:22 | 000,686,704 | ---- | M] () -- C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
PRC - [2010.11.30 03:04:00 | 001,997,416 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2010.11.29 03:31:42 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2010.11.17 16:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2010.09.30 02:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
PRC - [2010.08.21 00:53:08 | 000,689,472 | ---- | M] (SoftThinks SAS) -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
PRC - [2010.08.20 00:06:56 | 000,487,562 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
PRC - [2010.08.12 00:19:16 | 000,781,536 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
PRC - [2010.05.28 15:29:26 | 002,650,112 | ---- | M] (DATA BECKER GmbH & Co KG) -- C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe
PRC - [2009.07.14 00:15:34 | 002,559,888 | ---- | M] (Salfeld Computer) -- C:\Windows\SysWOW64\ccsync.exe
PRC - [2009.07.14 00:15:34 | 002,250,640 | ---- | M] (Salfeld Computer) -- C:\Windows\SysWOW64\cchservice.exe
PRC - [2009.04.16 12:23:56 | 000,479,232 | ---- | M] (SAMSUNG ELECTRONICS) -- C:\Program Files (x86)\Samsung\EmoDio\SMSTray.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.06.24 21:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.06.24 21:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011.05.30 09:29:22 | 001,719,144 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe
MOD - [2011.05.30 09:29:20 | 002,055,816 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe
MOD - [2011.05.30 09:25:32 | 007,938,048 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\QtGui4.dll
MOD - [2011.05.30 09:25:32 | 002,225,664 | ---- | M] () -- C:\Program Files (x86)\Dell Stage\Dell Stage\QtCore4.dll
MOD - [2010.12.17 16:25:22 | 000,686,704 | ---- | M] () -- C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
MOD - [2010.11.25 04:44:02 | 000,375,280 | ---- | M] () -- c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll
MOD - [2010.11.17 16:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
MOD - [2010.08.12 00:19:34 | 000,077,024 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll
MOD - [2010.08.12 00:19:32 | 000,109,792 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll
MOD - [2010.08.12 00:19:32 | 000,072,928 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll
MOD - [2010.08.12 00:19:30 | 000,232,672 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll
MOD - [2010.08.12 00:19:30 | 000,126,176 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll
MOD - [2010.08.12 00:19:30 | 000,119,008 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll
MOD - [2010.08.12 00:19:26 | 001,121,504 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\LibXml2.dll
MOD - [2010.08.12 00:19:16 | 000,781,536 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2010.11.29 21:00:56 | 000,149,504 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV:64bit: - [2010.09.23 00:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2011.12.14 20:49:17 | 003,316,000 | ---- | M] () [Auto | Running] -- c:\program files (x86)\common files\akamai/netsession_win_b427739.dll -- (Akamai)
SRV - [2011.09.23 17:37:42 | 000,641,832 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011.09.05 17:00:52 | 000,393,648 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe -- (Kodak AiO Network Discovery Service)
SRV - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.06.29 10:25:28 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.19 07:44:40 | 000,993,848 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
SRV - [2011.04.19 07:44:40 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2011.03.28 15:15:04 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.01.24 21:34:06 | 000,991,296 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service)
SRV - [2011.01.24 21:34:04 | 001,298,496 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service)
SRV - [2011.01.24 21:33:30 | 000,901,184 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor)
SRV - [2010.12.21 00:24:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010.12.21 00:24:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.12.17 20:41:32 | 001,515,792 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel(R)
SRV - [2010.12.17 20:28:46 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV - [2010.12.17 20:26:50 | 000,836,880 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel(R)
SRV - [2010.11.30 03:04:00 | 001,997,416 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2010.11.29 03:31:42 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2010.11.25 11:34:18 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12)
SRV - [2010.11.25 11:33:18 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM)
SRV - [2010.09.30 02:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor9.0)
SRV - [2010.08.26 02:28:54 | 002,823,000 | ---- | M] (Dell, Inc.) [Auto | Running] -- C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe -- (NOBU)
SRV - [2010.08.25 08:56:38 | 000,765,592 | ---- | M] (Salfeld Computer) [Auto | Stopped] -- C:\Windows\SysWOW64\ksupmgr.exe -- (ksupmgr)
SRV - [2010.08.21 00:53:08 | 000,689,472 | ---- | M] (SoftThinks SAS) [Auto | Running] -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE -- (SftService)
SRV - [2010.05.28 15:29:26 | 002,650,112 | ---- | M] (DATA BECKER GmbH & Co KG) [Auto | Running] -- C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe -- (DBService)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.11.18 03:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Programme\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2011.08.31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011.07.13 12:59:54 | 000,072,240 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NBVol.sys -- (NBVol)
DRV:64bit: - [2011.07.13 12:59:54 | 000,015,920 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NBVolUp.sys -- (NBVolUp)
DRV:64bit: - [2011.06.29 10:25:28 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011.06.29 10:25:28 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.06.10 05:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.04.12 10:45:50 | 000,018,432 | ---- | M] (TPMX Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HPub4DE3.sys -- (HPub4DE3) USB Mouse Low Filter Driver_4DE3 (WDF Version)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.03.09 09:44:44 | 000,025,088 | ---- | M] (TPMX Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HPMo4DE3.sys -- (HPMo4DE3) Mouse Suite Driver_4DE3 (WDF Version)
DRV:64bit: - [2011.02.10 23:52:34 | 000,181,760 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2011.02.10 23:52:34 | 000,082,432 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2011.01.28 09:57:14 | 012,273,408 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011.01.24 08:24:52 | 000,058,128 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux)
DRV:64bit: - [2011.01.24 08:22:48 | 000,059,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (iBtFltCoex)
DRV:64bit: - [2011.01.24 07:56:06 | 000,274,944 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf)
DRV:64bit: - [2011.01.13 02:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010.12.22 10:08:48 | 008,505,856 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64) ___ Intel(R)
DRV:64bit: - [2010.12.17 18:06:32 | 001,404,464 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010.12.15 18:02:04 | 000,174,168 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR)
DRV:64bit: - [2010.12.13 18:34:14 | 000,027,760 | ---- | M] (ST Microelectronics) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelern.sys -- (Acceler)
DRV:64bit: - [2010.12.12 15:18:36 | 000,121,960 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvstusb.sys -- (NvStUSB)
DRV:64bit: - [2010.11.30 03:04:00 | 000,025,576 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvpciflt.sys -- (nvpciflt)
DRV:64bit: - [2010.11.29 21:00:04 | 000,016,120 | ---- | M] (Intel(R) Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 10:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010.10.20 01:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel(R)
DRV:64bit: - [2010.10.16 01:28:18 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV:64bit: - [2010.09.01 09:30:58 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI)
DRV:64bit: - [2010.08.20 10:05:12 | 000,021,616 | ---- | M] (ST Microelectronics) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\stdcfltn.sys -- (stdcfltn)
DRV:64bit: - [2010.08.12 16:51:30 | 000,175,168 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV:64bit: - [2010.07.13 03:38:06 | 000,029,288 | ---- | M] (Quanta Computer) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qicflt.sys -- (qicflt)
DRV:64bit: - [2010.06.11 17:14:00 | 001,799,808 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVer7231_x64.sys -- (AVer7231_x64)
DRV:64bit: - [2010.03.19 09:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2010.02.27 16:32:14 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010.02.24 11:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11)
DRV:64bit: - [2009.08.13 21:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 01:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2006.11.01 18:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2011.07.22 17:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV - [2011.07.12 22:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2006.11.28 21:46:24 | 000,028,224 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\PDNMp50.sys -- (PDNMp50)
DRV - [2006.11.28 21:46:22 | 000,027,072 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\PDNSp50.sys -- (PDNSp50)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 3C D9 A7 7C 86 BD CC 01  [binary data]
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "www.google.de"
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.12.15 11:29:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.11 09:40:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.12.15 11:29:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Components: C:\Program Files (x86)\Mozilla Sunbird\components [2011.12.15 11:29:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Sunbird\plugins [2011.12.15 11:29:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.11.11 18:53:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 
[2011.05.19 12:42:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Extensions
[2011.05.19 12:42:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.09.12 11:27:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\3cers2zs.default\extensions
[2011.11.11 09:40:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.10.01 08:52:30 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.10.17 08:31:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011.10.29 10:21:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011.12.15 11:29:03 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011.11.11 09:40:26 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.10.29 10:21:40 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.09.16 21:59:18 | 000,170,064 | ---- | M] (Tracker Software Products Ltd.) -- C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2011.09.29 02:24:37 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.09.29 02:24:37 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.09.29 02:24:37 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.29 02:24:37 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
 
O1 HOSTS File: ([2011.12.19 09:36:14 | 000,438,446 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        www.0scan.com
O1 - Hosts: 127.0.0.1        0scan.com
O1 - Hosts: 127.0.0.1        1000gratisproben.com
O1 - Hosts: 127.0.0.1        www.1000gratisproben.com
O1 - Hosts: 127.0.0.1        1001namen.com
O1 - Hosts: 127.0.0.1        www.1001namen.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        www.1-2005-search.com
O1 - Hosts: 127.0.0.1        1-2005-search.com
O1 - Hosts: 15105 more lines...
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation)
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\SysNative\spool\drivers\x64\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4:64bit: - HKLM..\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [NVHotkey] C:\Windows\SysNative\nvHotkey.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ChicoSys] C:\Windows\SysWOW64\cc32\webtmr.exe (Salfeld Computer)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NBAgent] C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [SMSTray] C:\Program Files (x86)\Samsung\EmoDio\SMSTray.exe (SAMSUNG ELECTRONICS)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\.DEFAULT..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-18..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O4 - HKU\.DEFAULT..\RunOnce: [KodakHomeCenter] C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O4 - HKU\S-1-5-18..\RunOnce: [KodakHomeCenter] C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O4 - Startup: C:\Users\Jasmina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Nico.dell-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C8601AA9-2FCA-424D-B13E-12984594DCE3}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) -C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - Unable to read "AutoRun" value or value not present!
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.12.19 13:21:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.12.19 13:21:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.12.19 13:21:18 | 009,852,544 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Users\Administrator\Desktop\mbam-setup-1.51.2.1300.exe
[2011.12.19 10:13:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011.12.19 10:13:13 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2011.12.19 10:12:24 | 013,072,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\Silverlight_x64.exe
[2011.12.19 10:10:37 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2011.12.19 10:10:37 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2011.12.19 10:10:37 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011.12.19 10:10:37 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2011.12.19 10:10:37 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2011.12.19 10:10:37 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011.12.19 10:10:37 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011.12.19 10:10:37 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2011.12.19 10:10:37 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2011.12.19 10:10:37 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2011.12.19 10:10:37 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2011.12.19 10:10:37 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll
[2011.12.19 10:10:37 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2011.12.19 10:10:37 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2011.12.19 10:10:37 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2011.12.19 10:10:37 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2011.12.19 10:10:37 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011.12.19 10:10:37 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2011.12.19 10:10:37 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
[2011.12.19 10:10:37 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011.12.19 10:10:37 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2011.12.19 10:10:37 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2011.12.19 10:10:37 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2011.12.19 10:10:37 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2011.12.19 10:10:37 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2011.12.19 10:10:37 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2011.12.19 10:10:37 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2011.12.19 10:10:36 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2011.12.19 10:10:36 | 002,309,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011.12.19 10:10:36 | 001,493,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2011.12.19 10:10:36 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011.12.19 10:10:36 | 000,697,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2011.12.19 10:10:36 | 000,603,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2011.12.19 10:10:36 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2011.12.19 10:10:36 | 000,452,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2011.12.19 10:10:36 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2011.12.19 10:10:36 | 000,282,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2011.12.19 10:10:36 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieaksie.dll
[2011.12.19 10:10:36 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011.12.19 10:10:36 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2011.12.19 10:10:36 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
[2011.12.19 10:10:36 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2011.12.19 10:10:36 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2011.12.19 10:10:36 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2011.12.19 10:10:36 | 000,165,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2011.12.19 10:10:36 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll
[2011.12.19 10:10:36 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieakui.dll
[2011.12.19 10:10:36 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2011.12.19 10:10:36 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieakeng.dll
[2011.12.19 10:10:36 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2011.12.19 10:10:36 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2011.12.19 10:10:36 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2011.12.19 10:10:36 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2011.12.19 10:10:36 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\admparse.dll
[2011.12.19 10:10:36 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2011.12.19 10:10:36 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2011.12.19 10:10:36 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll
[2011.12.19 10:10:36 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011.12.19 10:10:36 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2011.12.19 10:10:36 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2011.12.19 10:10:36 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2011.12.19 10:10:36 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2011.12.19 10:10:36 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2011.12.19 10:10:36 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2011.12.19 10:10:36 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2011.12.19 10:10:36 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2011.12.19 10:10:36 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2011.12.19 10:10:36 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2011.12.19 10:10:36 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2011.12.19 10:10:36 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2011.12.19 09:00:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011.12.19 09:00:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2011.12.18 13:56:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2011.12.18 08:32:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011.12.18 08:32:32 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011.12.18 08:06:21 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.12.17 09:35:49 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\SUPERAntiSpyware.com
[2011.12.17 09:35:34 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011.12.16 09:08:32 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\RealNetworks
[2011.12.15 11:50:27 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\SoftGrid Client
[2011.12.15 11:50:25 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\SoftGrid Client
[2011.12.15 11:35:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.12.15 11:34:51 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.12.15 11:34:50 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011.12.15 11:34:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011.12.15 11:29:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared
[2011.12.15 11:29:01 | 000,198,832 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2011.12.15 11:28:57 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2011.12.15 11:28:57 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2011.12.15 11:28:56 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2011.12.15 11:28:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
[2011.12.15 11:25:22 | 000,713,472 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer.exe
[2011.12.15 11:22:52 | 000,000,000 | -HSD | C] -- C:\Users\Administrator\AppData\Local\4d0d2e25
[2011.12.15 11:14:51 | 009,852,544 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Program Files (x86)\mbam-setup-1.51.2.1300.exe
[2011.12.15 10:41:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.12.15 10:41:55 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.12.15 10:39:52 | 003,552,208 | ---- | C] (Piriform Ltd) -- C:\Program Files (x86)\ccsetup313.exe
[2011.12.15 08:29:11 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Desktop\Anti-Virus Maßnahmen
[2011.12.14 23:09:17 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2011.12.14 23:09:17 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2011.12.14 23:09:15 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2011.12.14 08:33:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LP
[2011.12.02 16:28:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Nexon
[2011.12.02 16:25:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon
[2011.12.02 16:22:22 | 000,000,000 | ---D | C] -- C:\ProgramData\NexonEU
[2011.12.02 15:45:54 | 000,000,000 | ---D | C] -- C:\Download
[2011.12.02 15:45:20 | 000,000,000 | ---D | C] -- C:\Nexon
[2011.12.02 15:45:19 | 000,446,464 | ---- | C] (NEXON Inc.) -- C:\Windows\NEXON_EU_DownloaderUpdater.exe
[2011.11.24 09:38:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak
[2011.11.24 09:36:02 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\spool
[2011.11.24 09:23:29 | 012,713,136 | ---- | C] (Eastman Kodak Company) -- C:\Program Files (x86)\aio_install.exe
[2011.10.29 11:49:39 | 039,401,336 | ---- | C] (Apple Inc.) -- C:\Program Files (x86)\QuickTimeInstaller.exe
[2011.10.29 10:10:18 | 000,910,624 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\jxpiinstall.exe
[2011.10.25 12:17:18 | 009,756,672 | ---- | C] ((c) Phoenix Technologies Ltd. ) -- C:\Program Files\L502X_A__06.exe
[2011.10.17 08:29:10 | 001,739,400 | ---- | C] (Secunia) -- C:\Program Files (x86)\PSISetup2003.exe
[2011.10.17 08:05:48 | 013,885,360 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 7.0.1.exe
[2011.09.24 17:12:36 | 001,291,624 | ---- | C] (Microsoft Corporation) -- C:\Program Files\wlsetup-web__1_.exe
[2011.09.23 14:09:00 | 000,676,624 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer_1406666_de.exe
[2011.09.22 10:34:36 | 003,089,056 | ---- | C] (Adobe Systems, Inc.) -- C:\Program Files (x86)\install_flash_player.exe
[2011.08.28 11:11:15 | 051,975,388 | ---- | C] (Acresso Software Inc.) -- C:\Program Files (x86)\VSX4_Pro_TBYB.exe.part
[2011.08.27 11:56:04 | 001,228,384 | ---- | C] (Adobe Systems Incorporated) -- C:\Program Files (x86)\PremiereElements_9_LS15.exe
[2011.08.25 17:58:21 | 006,716,353 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Sunbird_Setup_1.0_Beta_1.exe
[2011.07.18 15:59:52 | 013,522,064 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 5.0.1.exe
[2011.05.28 13:13:41 | 014,212,584 | ---- | C] (DVDVideoSoft Ltd.                                          ) -- C:\Program Files (x86)\FreeYouTubeToiPodConverter.exe
[2011.05.28 13:11:38 | 014,563,768 | ---- | C] (DVDVideoSoft Ltd.                                          ) -- C:\Program Files (x86)\FreeYouTubeToMP3Converter.exe
[2011.05.22 09:35:05 | 021,255,560 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files (x86)\SkypeSetupFull.exe
[2011.05.19 14:37:24 | 081,797,928 | ---- | C] (Apple Inc.) -- C:\Program Files (x86)\iTunes64Setup.exe
[2011.05.19 14:17:51 | 020,240,744 | ---- | C] (The GIMP Team                                              ) -- C:\Program Files (x86)\gimp-2.6.11-i686-setup.exe
[2011.05.19 14:17:11 | 019,735,256 | ---- | C] (                                                            ) -- C:\Program Files (x86)\gimp-2.6.8-x64-setup.exe
[2011.05.19 14:06:00 | 000,767,064 | ---- | C] (NCH Software) -- C:\Program Files (x86)\wpsetup4.57.exe
[2011.05.19 12:34:44 | 000,568,648 | ---- | C] (Google Inc.) -- C:\Program Files (x86)\GoogleEarthSetup.exe
[2011.05.19 12:26:00 | 009,326,056 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Thunderbird Setup 3.1.10.exe
[2011.05.19 12:25:04 | 012,362,480 | ---- | C] (Mozilla) -- C:\Program Files (x86)\Firefox Setup 4.0.1.exe
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.12.19 21:09:56 | 000,001,207 | ---- | M] () -- C:\Windows\SysWow64\excltmp~.dat
[2011.12.19 21:07:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.12.19 21:07:30 | 3137,994,752 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.19 20:28:00 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025UA.job
[2011.12.19 18:17:37 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.12.19 18:17:37 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.12.19 18:13:46 | 000,000,759 | ---- | M] () -- C:\Windows\SysWow64\ccsync.err
[2011.12.19 18:07:40 | 000,007,922 | ---- | M] () -- C:\Windows\SysWow64\cchservice.err
[2011.12.19 13:21:58 | 000,001,162 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.12.19 13:21:19 | 009,852,544 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Users\Administrator\Desktop\mbam-setup-1.51.2.1300.exe
[2011.12.19 10:19:27 | 000,654,346 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.12.19 10:19:27 | 000,616,188 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.12.19 10:19:27 | 000,130,186 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.12.19 10:19:27 | 000,106,568 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.12.19 10:12:25 | 013,072,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\Silverlight_x64.exe
[2011.12.19 10:10:37 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2011.12.19 10:10:37 | 001,427,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2011.12.19 10:10:37 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011.12.19 10:10:37 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2011.12.19 10:10:37 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2011.12.19 10:10:37 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011.12.19 10:10:37 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011.12.19 10:10:37 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2011.12.19 10:10:37 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2011.12.19 10:10:37 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2011.12.19 10:10:37 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2011.12.19 10:10:37 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll
[2011.12.19 10:10:37 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2011.12.19 10:10:37 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2011.12.19 10:10:37 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2011.12.19 10:10:37 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2011.12.19 10:10:37 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011.12.19 10:10:37 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2011.12.19 10:10:37 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
[2011.12.19 10:10:37 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2011.12.19 10:10:37 | 000,072,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011.12.19 10:10:37 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2011.12.19 10:10:37 | 000,063,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2011.12.19 10:10:37 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2011.12.19 10:10:37 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2011.12.19 10:10:37 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2011.12.19 10:10:37 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2011.12.19 10:10:37 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2011.12.19 10:10:36 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2011.12.19 10:10:36 | 002,309,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011.12.19 10:10:36 | 001,493,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2011.12.19 10:10:36 | 000,818,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011.12.19 10:10:36 | 000,697,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2011.12.19 10:10:36 | 000,603,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2011.12.19 10:10:36 | 000,534,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2011.12.19 10:10:36 | 000,452,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2011.12.19 10:10:36 | 000,448,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2011.12.19 10:10:36 | 000,282,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2011.12.19 10:10:36 | 000,267,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieaksie.dll
[2011.12.19 10:10:36 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011.12.19 10:10:36 | 000,237,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2011.12.19 10:10:36 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
[2011.12.19 10:10:36 | 000,222,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2011.12.19 10:10:36 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2011.12.19 10:10:36 | 000,173,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2011.12.19 10:10:36 | 000,165,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2011.12.19 10:10:36 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll
[2011.12.19 10:10:36 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieakui.dll
[2011.12.19 10:10:36 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2011.12.19 10:10:36 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieakeng.dll
[2011.12.19 10:10:36 | 000,149,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2011.12.19 10:10:36 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2011.12.19 10:10:36 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2011.12.19 10:10:36 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2011.12.19 10:10:36 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\admparse.dll
[2011.12.19 10:10:36 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2011.12.19 10:10:36 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2011.12.19 10:10:36 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll
[2011.12.19 10:10:36 | 000,096,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011.12.19 10:10:36 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2011.12.19 10:10:36 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2011.12.19 10:10:36 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2011.12.19 10:10:36 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2011.12.19 10:10:36 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2011.12.19 10:10:36 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2011.12.19 10:10:36 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2011.12.19 10:10:36 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2011.12.19 10:10:36 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2011.12.19 10:10:36 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2011.12.19 10:10:36 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2011.12.19 10:10:36 | 000,012,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2011.12.19 10:10:36 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2011.12.19 09:36:14 | 000,438,446 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011.12.18 14:09:10 | 000,001,963 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.12.15 11:35:17 | 000,001,836 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.12.15 11:29:01 | 000,198,832 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2011.12.15 11:28:57 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2011.12.15 11:28:57 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2011.12.15 11:28:56 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2011.12.15 11:25:23 | 000,713,472 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealPlayer.exe
[2011.12.15 11:22:41 | 001,500,062 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.12.15 11:14:56 | 009,852,544 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Program Files (x86)\mbam-setup-1.51.2.1300.exe
[2011.12.15 10:41:56 | 000,000,824 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.12.15 10:39:52 | 003,552,208 | ---- | M] (Piriform Ltd) -- C:\Program Files (x86)\ccsetup313.exe
[2011.12.15 08:25:41 | 000,353,408 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.12.15 08:02:34 | 000,000,118 | ---- | M] () -- C:\Windows\SysNative\MRT.INI
[2011.12.14 21:33:43 | 000,000,348 | ---- | M] () -- C:\NET.INI
[2011.12.14 08:38:37 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011.12.02 16:25:10 | 000,001,632 | ---- | M] () -- C:\Users\Public\Desktop\Combat Arms EU.lnk
[2011.12.02 15:45:20 | 000,000,235 | ---- | M] () -- C:\Windows\SysWow64\nxEuUninstall.bat
[2011.12.02 15:45:19 | 000,446,464 | ---- | M] (NEXON Inc.) -- C:\Windows\NEXON_EU_DownloaderUpdater.exe
[2011.11.24 09:39:41 | 000,002,209 | ---- | M] () -- C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
[2011.11.24 09:23:39 | 012,713,136 | ---- | M] (Eastman Kodak Company) -- C:\Program Files (x86)\aio_install.exe
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.12.19 18:07:40 | 000,000,759 | ---- | C] () -- C:\Windows\SysWow64\ccsync.err
[2011.12.19 13:21:58 | 000,001,162 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.12.19 10:10:37 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2011.12.19 10:10:36 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2011.12.18 08:32:34 | 000,001,963 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.12.16 10:33:33 | 000,007,922 | ---- | C] () -- C:\Windows\SysWow64\cchservice.err
[2011.12.15 11:35:17 | 000,001,836 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.12.15 10:41:56 | 000,000,824 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.12.15 08:02:34 | 000,000,118 | ---- | C] () -- C:\Windows\SysNative\MRT.INI
[2011.12.02 16:25:10 | 000,001,632 | ---- | C] () -- C:\Users\Public\Desktop\Combat Arms EU.lnk
[2011.12.02 15:45:20 | 000,000,235 | ---- | C] () -- C:\Windows\SysWow64\nxEuUninstall.bat
[2011.11.24 09:39:41 | 000,002,209 | ---- | C] () -- C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
[2011.11.11 07:32:42 | 001,527,140 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.10.29 09:54:07 | 001,019,816 | ---- | C] () -- C:\Program Files\DELL_DELL-DIGITAL-DELIVERY_A05_R313622.exe
[2011.10.10 16:51:50 | 000,155,536 | ---- | C] () -- C:\Windows\SysWow64\dllcinx.exe
[2011.10.10 16:51:48 | 000,000,600 | ---- | C] () -- C:\Windows\SysWow64\nochook.ini
[2011.10.03 13:41:52 | 000,247,053 | ---- | C] () -- C:\Program Files (x86)\mp3DC213.exe
[2011.09.29 09:19:37 | 000,001,207 | ---- | C] () -- C:\Windows\SysWow64\excltmp~.dat
[2011.09.29 09:18:42 | 000,000,141 | -H-- | C] () -- C:\Windows\SysWow64\ctlsw.ini
[2011.09.29 09:18:42 | 000,000,102 | ---- | C] () -- C:\Windows\SysWow64\SWCTL.DLL
[2011.09.29 08:11:44 | 000,124,416 | ---- | C] () -- C:\Windows\SysWow64\dXCtrls.dll
[2011.09.29 08:11:43 | 000,544,256 | ---- | C] () -- C:\Windows\SysWow64\janGraphics.dll
[2011.09.29 07:55:01 | 003,103,511 | ---- | C] () -- C:\Program Files (x86)\kcsetup8.exe
[2011.09.23 14:05:53 | 021,073,936 | ---- | C] () -- C:\Program Files (x86)\vlc-1.1.11-win32.exe
[2011.09.23 12:51:28 | 000,003,027 | ---- | C] () -- C:\Program Files (x86)\Français.lng
[2011.09.23 12:51:28 | 000,002,946 | ---- | C] () -- C:\Program Files (x86)\Español.lng
[2011.09.23 12:51:28 | 000,002,920 | ---- | C] () -- C:\Program Files (x86)\Italiano.lng
[2011.09.23 12:51:28 | 000,002,699 | ---- | C] () -- C:\Program Files (x86)\Deutsch.lng
[2011.09.23 12:51:28 | 000,002,553 | ---- | C] () -- C:\Program Files (x86)\Suomi.lng
[2011.09.23 12:40:52 | 023,773,184 | ---- | C] () -- C:\Program Files (x86)\PXCViewer98_x64.msi
[2011.09.23 12:27:47 | 001,376,768 | ---- | C] () -- C:\Program Files (x86)\7z920-x64.msi
[2011.09.16 06:44:01 | 168,166,968 | ---- | C] () -- C:\Program Files (x86)\OOo_3.3.0_Win_x86_install-wJRE_de.exe
[2011.08.28 09:55:59 | 002,466,704 | ---- | C] () -- C:\Program Files (x86)\AdobeDownloadAssistant.exe
[2011.08.27 11:27:07 | 1316,066,539 | ---- | C] () -- C:\Program Files (x86)\PremiereElements_9_LS15.7z
[2011.08.27 11:23:03 | 008,353,800 | ---- | C] () -- C:\Program Files (x86)\Adobe_Premiere_Elements_9-AkamaiDLM.exe
[2011.05.19 14:44:09 | 001,663,693 | ---- | C] () -- C:\Program Files (x86)\winrar-x64-400d.exe
[2011.05.19 14:10:20 | 014,166,016 | ---- | C] () -- C:\Program Files (x86)\wz150gev.msi
[2011.05.19 14:09:07 | 006,088,218 | ---- | C] () -- C:\Program Files (x86)\flash_player.zip
[2011.05.19 13:52:49 | 000,000,056 | ---- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011.05.19 12:39:40 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.05.19 12:28:56 | 052,718,176 | ---- | C] () -- C:\Program Files (x86)\avira_antivir_personal_de.exe
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_89001461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_49001461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_33011461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2B071461_8a.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A0F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_2A071461_8a.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_14001461_61.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_13011461_aa.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_110F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_110F1461_8a.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_ca.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_aa.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_A3031461_8a.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_ca.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_aa.bin
[2011.05.15 06:48:49 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_83231461_8a.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_890F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_2B0f1461_ca.bin
[2011.05.15 06:48:49 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_29001461_ca.bin
[2011.05.15 06:48:49 | 000,000,412 | ---- | C] () -- C:\Windows\11317231_180F1461_ca.bin
[2011.05.15 06:48:49 | 000,000,412 | ---- | C] () -- C:\Windows\11317231_18071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_11071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_11071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0B071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A0F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A031461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A031461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A011461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_0A011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_09001461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_08071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_060F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_06071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_06071461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_03011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_03011461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_02011461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_02011461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_010F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_010F1461_8a.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_01071461_aa.bin
[2011.05.15 06:48:48 | 000,000,502 | ---- | C] () -- C:\Windows\11317231_01071461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_07031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_ca.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03231461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03131461_8a.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_03031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_ca.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_aa.bin
[2011.05.15 06:48:48 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_02031461_8a.bin
[2011.05.15 06:48:48 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_0B0f1461_ca.bin
[2011.05.15 06:48:48 | 000,000,434 | ---- | C] () -- C:\Windows\11317231_090F1461_ca.bin
[2011.05.15 06:48:48 | 000,000,376 | ---- | C] () -- C:\Windows\11317231_03131461_aa.bin
[2011.05.15 06:48:47 | 000,000,461 | ---- | C] () -- C:\Windows\11317231_00000000_aa.bin
[2011.05.15 06:48:11 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011.05.15 06:47:21 | 000,960,940 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.05.15 06:47:19 | 000,213,332 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.05.15 06:47:17 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.01.19 12:34:42 | 003,003,392 | ---- | C] () -- C:\Program Files (x86)\openofficeorg33.msi
[2011.01.19 12:33:04 | 000,475,016 | ---- | C] () -- C:\Program Files (x86)\setup.exe
[2011.01.19 12:30:10 | 142,700,671 | ---- | C] () -- C:\Program Files (x86)\openofficeorg1.cab
[2011.01.19 11:15:26 | 000,000,290 | ---- | C] () -- C:\Program Files (x86)\setup.ini
[2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009.04.16 12:24:14 | 000,921,600 | ---- | C] () -- C:\Windows\SysWow64\vorbisenc.dll
[2009.04.16 12:24:14 | 000,237,568 | ---- | C] () -- C:\Windows\SysWow64\OggDS.dll
[2009.04.16 12:24:14 | 000,188,416 | ---- | C] () -- C:\Windows\SysWow64\vorbis.dll
[2009.04.16 12:24:14 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\Ogg.dll
 
========== LOP Check ==========
 
[2011.05.23 15:49:56 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\CheckPoint
[2011.05.19 12:45:49 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.09.10 15:33:36 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Fingertapps
[2011.05.19 14:07:13 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\NCH Swift Sound
[2011.05.19 13:04:35 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\OpenOffice.org
[2011.12.19 10:01:11 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Opera
[2011.12.19 10:19:17 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\SoftGrid Client
[2011.11.18 10:33:58 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Temp
[2011.05.21 10:57:03 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Thunderbird
[2011.09.13 07:51:26 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Temp
[2011.09.13 07:51:26 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Temp
[2011.07.15 14:23:05 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\2K Sports
[2011.12.15 21:45:19 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\57168
[2011.12.15 21:45:19 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\B8457
[2011.09.01 18:51:14 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011.05.23 16:30:23 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\CheckPoint
[2011.08.28 09:58:29 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011.09.10 14:11:11 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\DriverFinder
[2011.10.01 08:51:21 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\DVDVideoSoft
[2011.10.01 08:51:16 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.06.30 08:10:18 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Fingertapps
[2011.06.20 07:07:01 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\go
[2011.12.16 12:46:12 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\gtk-2.0
[2011.11.07 19:23:04 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Leadertech
[2011.10.07 10:12:34 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\mp3DirectCut
[2011.06.24 07:34:10 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\NCH Swift Sound
[2011.05.20 17:29:32 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\OpenOffice.org
[2011.10.04 20:00:10 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Opera
[2011.05.31 06:51:05 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\ProtectDisc
[2011.09.20 10:55:01 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\QuickScan
[2011.07.06 19:23:10 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Temp
[2011.05.21 12:10:22 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Thunderbird
[2011.11.11 07:33:12 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\TP
[2011.07.17 14:24:06 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Ulead Systems
[2011.09.07 10:57:41 | 000,000,000 | ---D | M] -- C:\Users\Jasmina\AppData\Roaming\Uniblue
[2011.10.09 13:43:13 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\2K Sports
[2011.12.15 21:45:19 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\57168
[2011.12.15 08:04:04 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\B8457
[2011.10.27 10:01:00 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\DVDVideoSoft
[2011.09.29 09:43:26 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Fingertapps
[2011.10.27 10:57:32 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\MusicNet
[2011.10.18 19:17:26 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\OpenOffice.org
[2011.11.07 19:36:36 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Origin
[2011.09.13 07:51:26 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Temp
[2011.09.29 09:59:09 | 000,000,000 | ---D | M] -- C:\Users\Nico.dell-PC.000\AppData\Roaming\Thunderbird
[2011.12.19 20:28:00 | 000,000,948 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025UA.job
[2011.12.04 15:25:34 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
< End of report >
:


Rheingold 19.12.2011 21:25

2. otl-Extras
:
Code:

OTL Extras logfile created on: 19.12.2011 21:10:01 - Run 11
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Administrator\Desktop\Anti-Virus Maßnahmen\OTL
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,90 Gb Total Physical Memory | 2,06 Gb Available Physical Memory | 52,88% Memory free
7,79 Gb Paging File | 5,73 Gb Available in Paging File | 73,50% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 235,24 Gb Total Space | 110,36 Gb Free Space | 46,92% Space Free | Partition Type: NTFS
Drive D: | 215,77 Gb Total Space | 206,35 Gb Free Space | 95,63% Space Free | Partition Type: NTFS
 
Computer Name: DELL-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- Reg Error: Key error. File not found
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- Reg Error: Key error. File not found
 
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- Reg Error: Key error.
htmlfile [opennew] -- Reg Error: Key error.
htmlfile [print] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" -nohome
https [open] -- "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" -nohome
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error.
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- Reg Error: Key error.
htmlfile [opennew] -- Reg Error: Key error.
http [open] -- "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" -nohome
https [open] -- "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" -nohome
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableSR" = 1
"DisableConfig" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableSR" = 1
"DisableConfig" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Nexon\Combat Arms EU\CombatArms.exe" = C:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\Engine.exe" = C:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\CombatArms.exe" = C:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\Engine.exe" = C:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe -- (Nexon)
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe" = [String data over 1000 bytes]
"C:\Nexon\Combat Arms EU\CombatArms.exe" = C:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\Engine.exe" = C:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe -- (Nexon)
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe" = [String data over 1000 bytes]
"C:\Nexon\Combat Arms EU\CombatArms.exe" = C:\Nexon\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms EU\Engine.exe" = C:\Nexon\Combat Arms EU\Engine.exe:*Enabled:Engine.exe -- (Nexon)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}" = Kodak AIO Printer
"{290D4DB2-F1B4-4B8E-918D-D71EF29A001B}" = Intel(R) PROSet/Wireless WiFi-Software
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}" = RBVirtualFolder64Inst
"{9ED333F8-3E6C-4A38-BAFA-728454121CDA}" = PDF-XChange Viewer
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 265.94
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 265.94
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 265.94
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.0.9
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}" = Überwachungstool für die Intel® Turbo-Boost-Technik 2.0
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{BE930E38-7BB3-45B6-85B2-5251F374F844}" = 64 Bit HP CIO Components Installer
"{C7B40C35-85AE-4303-9EEA-1A1EA779664D}" = Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D600D357-5CB9-4DE9-8FD4-14E208BD1970}" = Nero Backup Drivers
"{D66F0C3C-24F2-4463-9E2F-4381E5C40A26}" = iTunes
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"CCleaner" = CCleaner
"Dell Support Center" = Dell Support Center
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinGimp-2.0_is1" = GIMP 2.6.8
"WinRAR archiver" = WinRAR 4.00 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01E9B2FF-DAF4-4529-9CC9-2101625517C7}" = nero.prerequisites.msi
"{034DCAF9-96E7-4936-9A07-712F80B5181E}" = Nero RescueAgent 11
"{0713D1F9-DD77-42C1-8C7D-54D479E2E743}" = Nero SoundTrax 11
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D7A4289-99CF-4B8D-B812-86BE50A54552}" = Nero Video 11
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{11D3EF85-63E1-4AE4-A7C1-9241BDB16B51}" = Nero ControlCenter 11
"{1D4EE8FE-F31C-4258-9360-5B8B8309B14B}" = Adobe Premiere Elements 9 Content
"{1D7CE340-70C3-4848-BCCF-215950328A4C}" = Facebook Video Calling 1.0.0.8953
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{25175695-4B20-4298-9F34-C2C57CD277B3}" = Elements STI Installer
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java(TM) 6 Update 29
"{27107EAA-34E0-43BF-B537-7F8EF6880F5A}" = Facebook Video Calling 1.0.0.8177
"{289AC7E0-0AEE-4a7b-913C-709D9803D23E}" = Nexon Game Manager
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2CA7225D-CB12-462A-9DD1-50319E158BA5}" = Nero 11 PiP Effects Basic
"{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5
"{3250260C-7A95-4632-893B-89657EB5545B}" = PhotoShowExpress
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{3443D416-9DAD-4362-BEB1-C213AD9062CD}" = Dell MusicStage
"{376348C2-E372-48BC-A138-E896757BD86A}" = aioscnnr
"{37AB0223-AF54-49C5-92AA-BFC9648CD323}" = Adobe Premiere Elements 9 HD Content 3
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{390757AA-8830-43DC-AEE0-4E5B6F8439EB}" = Nero SoundTrax 11 Help (CHM)
"{3CBBE028-978B-4876-ABC1-EF9ED6C20C4E}" = Adobe Premiere Elements 9 Content 2
"{3EE2F527-F306-49E9-0086-662C337ADD3B}" = FUSSBALL MANAGER 07
"{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C}" = FIFA 11
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{433EACD8-4747-4A6A-826A-FFA9F39B0D40}" = Elements 9 Organizer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50D90C59-4F5C-48BC-AFB2-38475412F0CA}" = Adobe Premiere Elements 9 Content 1
"{53F7746A-96AA-49A5-86B8-59989680DAC5}" = Nero Burning ROM 11 Help (CHM)
"{55C2143E-FBA5-442F-9AFA-726FF068F39D}" = Nero CoverDesigner 11 Help (CHM)
"{56BA241F-580C-43D2-8403-947241AAE633}" = center
"{57F80ECF-E27C-4EEE-AB58-E971BACE2639}" = Nero Recode 11 Help (CHM)
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{5A212B2D-140D-46F4-B625-2D1CA5A00594}" = Nero 11 Kwik Themes Basic
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5F9AAF4A-B9B0-489D-AE67-73470A4714FE}" = Adobe Premiere Elements 9 HD Content 1
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6AB2427E-A18F-4809-9A12-29F5EBABBB3A}" = Nero BackItUp 11 Help (CHM)
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}" = Roxio Creator Starter
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7746BFAA-2B5D-4FFD-A0E8-4558F4668105}" = Roxio Burn
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7DDC3624-C631-49D1-B281-82EC3A27AA7C}" = Adobe Premiere Elements 9 Content 3
"{7EC66A95-AC2D-4127-940B-0445A526AB2F}" = Dell DataSafe Online
"{8014FACB-1D1D-48C2-94AA-E29EE2E6B9CE}" = Nero WaveEditor 11
"{81DD0597-29EB-4FA0-8223-4F41362B2E72}" = NBA 2K11
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{87434D51-51DB-4109-B68F-A829ECDCF380}" = AccelerometerP11
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{9193490D-5229-4FC4-9BB9-A6D63C09574A}" = High-Definition Video Playback
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Sonic CinePlayer Decoder Pack
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet-TV für Windows Media Center
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A7A0BF2E-31CC-49E3-9913-52C503EB969D}" = Nero Audio Pack 1
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AB2BBC64-8AC8-4E66-BBF3-E22D5EACEECA}" = Nero BackItUp 11
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B1846721-A8E6-46C7-83B6-0DCF7ADB4267}" = Nero Burning ROM 11
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B7E01095-8BAA-456E-8AED-504C3CCADBA0}" = Nero 11
"{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"{B9B1BA7F-7E07-49DD-A713-5B397A5BB66B}" = Nero Kwik Media Help (CHM)
"{BE814218-3919-4EA3-868A-2F60BC135CB4}" = Nero Kwik Media
"{BE94C681-68E2-4561-8ABC-8D2E799168B4}" = essentials
"{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components 11
"{BFBCF96F-7361-486A-965C-54B17AC35421}" = ocr
"{C19BE821-89B1-4A96-AC7C-873810C0CB5F}" = ContentSAFER for Wizmax
"{C20CE592-B0F8-4D20-BF31-0151CA6331A6}" = EmoDio
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{CCE210DF-7EEF-4A76-A63C-3EB091FDB992}" = welcome
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D01CE99A-8802-483C-A79F-298B691EB432}" = Nero RescueAgent 11 Help (CHM)
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D2CBEFA4-F2D3-4E97-A171-8BFD6A31A5EC}" = Nero Express 11 Help (CHM)
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4D66270-9147-4BDF-9946-FCA2B303AA8F}" = Nero ControlCenter 11 Help (CHM)
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DC0C5A78-6DBF-3444-0120-0FE8F0134FCD}" = Adobe Download Assistant
"{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK All-in-One Software
"{E10AAE4A-98B8-420A-BD93-E0520C23D624}" = Nero Express 11
"{E240C78D-8F35-456A-8876-15FF6901B7E0}" = Adobe Premiere Elements 9 HD Content 2
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E4335E82-17B3-460F-9E70-39D9BC269DB3}" = Dell PhotoStage
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E51BC4B0-EA5E-49CC-AF3B-93B5C627EC22}" = Nero 11 Effects Basic
"{E9F59205-F128-49A7-9039-4BDFB60EE4A3}" = Dell Stage
"{EB8DED20-A887-4A9C-BB5A-F3E7523DFB44}" = Nero WaveEditor 11 Help (CHM)
"{EB9955F8-467C-47FC-90F8-12CD5DF684C3}" = Adobe Premiere Elements 9
"{EC7FE03D-239A-4E36-9907-0E327922D2A2}" = bpd_scan
"{EF53BFAB-4C10-40DB-A82D-9B07111715C6}" = aioscnnr
"{EF56258E-0326-48C5-A86C-3BAC26FC15DF}" = Roxio Creator Starter
"{F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}" = Roxio Creator Starter
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F302F4F0-588D-6501-1ACF-BE3FDCC9135D}" = Adobe Community Help
"{F3743A2C-5D5F-4456-8F98-5DF36A954C50}" = Nero 11 Image Samples
"{F49EF443-B2BD-4F10-8A46-87AFCDB90EDD}" = Nero 11 Disc Menus Basic
"{F69FB940-5031-4FE8-AFAD-085802D0BF63}" = Nero Recode 11
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FAC3C37E-EDAB-4F3A-A173-A7C70CC88F09}" = Nero Video 11 Help (CHM)
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF44BCE5-5A18-4051-85F0-BC172D7B4695}" = Nero CoverDesigner 11
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Premiere Elements 9 Content" = Adobe Premiere Elements 9 Content
"Adobe Premiere Elements 9 Content 1" = Adobe Premiere Elements 9 Content 1
"Adobe Premiere Elements 9 Content 2" = Adobe Premiere Elements 9 Content 2
"Adobe Premiere Elements 9 Content 3" = Adobe Premiere Elements 9 Content 3
"Adobe Premiere Elements 9 HD Content 1" = Adobe Premiere Elements 9 HD Content 1
"Adobe Premiere Elements 9 HD Content 2" = Adobe Premiere Elements 9 HD Content 2
"Adobe Premiere Elements 9 HD Content 3" = Adobe Premiere Elements 9 HD Content 3
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Akamai" = Akamai NetSession Interface Service
"AVerMedia H339 Hybrid TV Tuner" = AVerMedia H339 Hybrid TV Tuner 2.2.64.64
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BewerbungsGenie 7_is1" = DATA BECKER BewerbungsGenie 7
"BurningWheels" = Cobra 11 - Burning Wheels (remove only)
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"Combat Arms EU" = Combat Arms EU
"Dell Webcam Central" = Dell Webcam Central
"ESET Online Scanner" = ESET Online Scanner v3
"ExpressBurn" = Express Burn Disc Burning Software
"ExpressRip" = Express Rip
"Free YouTube to iPod Converter_is1" = Free YouTube to iPod Converter version 3.10.8.815
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.8.815
"InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5
"InstallShield_{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0
"InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"InstallShield_{C20CE592-B0F8-4D20-BF31-0151CA6331A6}" = EmoDio
"InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"Kindersicherung_is1" = Kindersicherung 2011
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.2.1300
"MixPad" = MixPad Audio Mixer
"Mozilla Firefox 8.0 (x86 de)" = Mozilla Firefox 8.0 (x86 de)
"Mozilla Thunderbird (8.0)" = Mozilla Thunderbird (8.0)
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"PremElem90" = Adobe Premiere Elements 9
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"Secunia PSI" = Secunia PSI (2.0.0.3003)
"VLC media player" = VLC media player 1.1.11
"WavePad" = WavePad Sound Editor
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
 
========== Last 10 Event Log Errors ==========
 
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
 
< End of report >
:


Rheingold 19.12.2011 21:27

hatte ich das schon geschrieben? - avira und windows update laufen wieder.

beste grüße
jasmina

Rheingold 20.12.2011 10:32

Hallo Kira,
TDSSKiller hat keine Funde gehabt.
Ich habe noch mal mit Malewarbytes gescannt und der hat dann scheinbar noch was gefunden. Den logfile poste ich hier. Ansonsten kann ich die Windows Firewall nicht aktivieren.

Viele Grüße
Jasmina

:
Code:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 8401

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

20.12.2011 10:21:53
mbam-log-2011-12-20 (10-21-53).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 477500
Laufzeit: 1 Stunde(n), 15 Minute(n), 22 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableConfig (Windows.Tool.Disabled) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden):


kira 20.12.2011 12:37

1.
Vor dem nächsten Schritt, also bevor wir weitermachen:
Da jederzeit etwas passieren kann, wenn du wichtige Daten hast die Du sichern möchtest, empfehle ich Dir es jetzt machen (wie Bilder, Musik usw)
Achte darauf: Die sicherten Daten sollen keine "Ausführbare Dateien" enthalten! - Dateiendungen - Dies ist eine Liste von Dateiendungen, die Dateien mit ausführbarem Code bezeichnen können.
Unabhängig von einem Befall (weil ja kann eine Festplatte auch kaputt gehen, oder es gibt andere technische Probleme ), sollte man regelmäßig Sicherung machen und an einem sicheren Ort bewahren, wie CD und DVD, externe Festplatten oder/und USB-Sticks
Mache das jetzt bitte!


2.
Lade Combofix von einem der folgenden Download-Spiegel herunter:

BleepingComputer.com - ForoSpyware.com

und speichere das Programm auf den Desktop, nicht woanders hin, das ist wichtig!
Beachte die ausführliche Original-Anleitung.

Zurzeit ist Combofix auf folgenden Windows-Versionen lauffähig:
  • Windows XP (nur 32-bit)
  • Windows 2000 (nur 32-bit)
  • Windows Vista (32-bit/64-bit)
  • Windows 7 (32-bit/64-bit)

Vorbereitung und wichtige Hinweise
  • Bitte während des Scans mit Combofix Antiviren- sowie Antispy-Programme, die Firewall und evtl. vorhandenes Skript-Blocking (Norton) deaktivieren.
  • Liste der zu deaktivierenden Programme.
    Bei Unklarheiten bitte vorher fragen.
  • Bitte während des Laufs von Combofix nicht in das Combofix-Fenster klicken.
  • Das könnte Dein System einfrieren oder hängen bleiben lassen.
  • Es kann circa eine Viertelstunde dauern, bis der Scan fertig ist.
  • ComboFix wird Deine Einstellungen in Bezug auf den Bildschirmschoner zurücksetzen.
  • Diese Einstellungen kannst Du nach Beendigung unserer Bereinigung wieder ändern.
  • Mache nichts anderes, wenn es Dir nicht gelungen ist, Combofix laufen zu lassen.
  • Teile uns das mit und warte auf unsere Anweisungen.

Kurzanleitung zur Installation der Wiederherstellungskonsole unter XP
  • Doppelklicke auf die ComboFix.exe und folge den Anweisungen.
  • Akzeptiere die Bedingungen (Disclaimer) mit "Ja".
  • ComboFix wird schauen, ob die Microsoft-Windows-Wiederherstellungskonsole installiert ist.
    Dies ist Teil des Prozesses. Angesichts der Art von Malware Infizierungen, die es heute gibt, wird dringend empfohlen, diese Wiederherstellungskonsole auf dem PC installiert zu haben, bevor jegliche Reinigung von Malware durchgeführt wird.
  • Folge den Anweisungen, um ComboFix das Herunterladen und Installieren der Wiederherstellungskonsole zu ermöglichen und stimme dem Lizenzvertrag (EULA) zu, sobald Du dazu aufgefordert wirst.
** Zur Information: Sollte die Wiederherstellungskonsole schon installiert sein, so wird ComboFix seine Malware-Entfernungsprozedur normal fortfahren.

http://i94.photobucket.com/albums/l8...eWHKonsole.jpg

Sobald die Wiederherstellungskonsole durch ComboFix installiert wurde, solltest Du folgende Nachricht sehen:

http://i94.photobucket.com/albums/l8...nstalliert.jpg

Klicke "Ja", um mit dem Suchlauf nach Malware fortzufahren.

Wenn ComboFix fertig ist, wird es ein Log erstellen (bitte warten, das dauert einen Moment).
Unbedingt warten, bis sich das Combofix-Fenster geschlossen hat und das Logfile im Editor erscheint.
Bitte poste die Log-Dateien C:\ComboFix.txt und C:\Qoobox\Add-Remove Programs.txt in Code-Tags hier in den Thread.

Hinweis: Combofix macht aus verschiedenen Gründen den Internet Explorer zum Standard-Browser und erstellt ein IE-Icon auf dem Desktop.
Das IE-Desktop-Icon kannst Du nach der Bereinigung wieder löschen und Deinen bevorzugten Browser wieder als Standard-Browser einstellen.

Combofix nicht auf eigene Faust einsetzen. Wenn keine entsprechende Infektion vorliegt, kann das den Rechner lahmlegen und/oder nachhaltig schädigen!

Rheingold 20.12.2011 21:16

Liebe Kira,
vielen Dank für die Anweisungen! Echt, alleine wäre ich aufgeschmissen!
Combofix kann ich erst morgen abend durchführen, u.a. weil ich meine Daten erst mal wieder neu sichern muss.

Ich habe heute auch festgestellt, dass das avira update auf meinem eigenen Account (auch ein Admin Konto) nicht funktioniert. Aber vielleicht kriege ich das mit deiner Hilfe wieder hin.

Viele Grüße und 1.000 Dank,
Jasmina

Rheingold 21.12.2011 08:46

:
Code:

ComboFix 11-12-20.04 - Administrator 21.12.2011  8:27.2.8 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3990.2146 [GMT 1:00]
ausgeführt von:: c:\users\Administrator\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\LP
c:\program files (x86)\LP\A7CB\6FA5.tmp
c:\program files (x86)\LP\A7CB\897.tmp
c:\program files (x86)\LP\A7CB\A7A3.tmp
c:\program files (x86)\LP\A7CB\DE11.tmp
c:\program files (x86)\LP\A7CB\ED79.tmp
c:\program files (x86)\mbam-setup-1.51.2.1300.exe
c:\program files (x86)\PSISetup2003.exe
c:\program files (x86)\RealPlayer_1406666_de.exe
c:\program files (x86)\Setup.exe
c:\users\ADMINI~1\AppData\Local\Temp\SASF93E.tmp
c:\users\Administrator\AppData\Local\Temp\SASF93E.tmp
c:\users\Jasmina\FacebookVideoCallSetup_v1.2.203.0.exe
c:\users\Jasmina\fbookbot.exe
c:\users\Jasmina\mp3DC213.exe
c:\windows\assembly\tmp\U
c:\windows\SysWow64\SWCTL.DLL
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-11-21 bis 2011-12-21  ))))))))))))))))))))))))))))))
.
.
2011-12-21 07:33 . 2011-12-21 07:33        --------        d-----w-        c:\users\UpdatusUser\AppData\Local\temp
2011-12-21 07:33 . 2011-12-21 07:33        --------        d-----w-        c:\users\Public\AppData\Local\temp
2011-12-21 07:33 . 2011-12-21 07:33        --------        d-----w-        c:\users\Nico.dell-PC.000\AppData\Local\temp
2011-12-19 12:21 . 2011-12-19 12:21        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2011-12-19 09:30 . 2011-12-19 09:30        --------        d-----w-        c:\windows\SysWow64\wbem\en-US
2011-12-19 09:30 . 2011-12-19 09:30        --------        d-----w-        c:\windows\system32\wbem\en-US
2011-12-19 09:13 . 2011-12-19 09:13        --------        d-----w-        c:\program files\Microsoft Silverlight
2011-12-19 09:12 . 2011-12-19 09:12        13072536        ----a-w-        c:\windows\Silverlight_x64.exe
2011-12-19 08:00 . 2011-12-19 08:50        --------        d-----w-        c:\program files (x86)\Spybot - Search & Destroy
2011-12-19 08:00 . 2011-12-19 08:50        --------        d-----w-        c:\programdata\Spybot - Search & Destroy
2011-12-18 12:56 . 2011-12-18 12:56        --------        d-----w-        c:\program files (x86)\ESET
2011-12-18 07:06 . 2011-12-18 07:06        --------        d-----w-        C:\_OTL
2011-12-16 08:08 . 2011-12-16 08:08        --------        d-----w-        c:\users\Administrator\AppData\Roaming\RealNetworks
2011-12-15 10:50 . 2011-12-15 10:50        --------        d-----w-        c:\users\Administrator\AppData\Local\SoftGrid Client
2011-12-15 10:50 . 2011-12-19 09:19        --------        d-----w-        c:\users\Administrator\AppData\Roaming\SoftGrid Client
2011-12-15 10:34 . 2011-12-15 10:34        --------        d-----w-        c:\program files\iPod
2011-12-15 10:34 . 2011-12-15 10:35        --------        d-----w-        c:\program files\iTunes
2011-12-15 10:34 . 2011-12-15 10:35        --------        d-----w-        c:\program files (x86)\iTunes
2011-12-15 10:29 . 2011-12-15 10:29        11776        ----a-w-        c:\program files (x86)\Mozilla Firefox\plugins\nprjplug.dll
2011-12-15 10:29 . 2011-12-15 10:29        --------        d-----w-        c:\program files (x86)\Common Files\xing shared
2011-12-15 10:29 . 2011-12-15 10:29        150696        ----a-w-        c:\program files (x86)\Mozilla Firefox\plugins\nppl3260.dll
2011-12-15 10:28 . 2011-12-15 10:28        108544        ----a-w-        c:\program files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
2011-12-15 10:28 . 2011-12-15 10:28        499712        ----a-w-        c:\windows\SysWow64\msvcp71.dll
2011-12-15 10:28 . 2011-12-15 10:28        348160        ----a-w-        c:\windows\SysWow64\msvcr71.dll
2011-12-15 10:25 . 2011-12-15 10:25        713472        ----a-w-        c:\program files (x86)\RealPlayer.exe
2011-12-15 10:22 . 2011-12-15 10:25        --------        d-sh--w-        c:\users\Administrator\AppData\Local\4d0d2e25
2011-12-15 09:41 . 2011-12-15 09:41        --------        d-----w-        c:\program files\CCleaner
2011-12-15 09:39 . 2011-12-15 09:39        3552208        ----a-w-        c:\program files (x86)\ccsetup313.exe
2011-12-14 22:09 . 2011-10-15 06:31        723456        ----a-w-        c:\windows\system32\EncDec.dll
2011-12-14 22:09 . 2011-10-15 05:38        534528        ----a-w-        c:\windows\SysWow64\EncDec.dll
2011-12-14 22:09 . 2011-10-26 05:21        43520        ----a-w-        c:\windows\system32\csrsrv.dll
2011-12-14 22:09 . 2011-11-24 04:52        3145216        ----a-w-        c:\windows\system32\win32k.sys
2011-12-14 21:58 . 2011-11-05 05:32        2048        ----a-w-        c:\windows\system32\tzres.dll
2011-12-14 21:58 . 2011-11-05 04:26        2048        ----a-w-        c:\windows\SysWow64\tzres.dll
2011-12-14 18:58 . 2011-12-14 18:58        163        ----a-w-        c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl593131_64.bat
2011-12-14 07:38 . 2011-12-14 07:38        --------        d-sh--w-        c:\users\Jasmina\AppData\Local\4d0d2e25
2011-12-14 07:35 . 2011-12-15 20:45        --------        d-----w-        c:\users\Jasmina\AppData\Roaming\57168
2011-12-14 07:34 . 2011-12-15 20:45        --------        d-----w-        c:\users\Jasmina\AppData\Roaming\B8457
2011-12-13 19:19 . 2011-12-13 19:19        181        ----a-w-        c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl1265152_64.bat
2011-12-13 19:18 . 2011-12-13 19:18        163        ----a-w-        c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl1246260_64.bat
2011-12-13 19:18 . 2011-12-13 19:18        163        ----a-w-        c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl1208336_64.bat
2011-12-13 19:17 . 2011-12-16 08:57        --------        d-sh--w-        c:\users\Nico.dell-PC.000\AppData\Local\4d0d2e25
2011-12-13 19:17 . 2011-12-13 19:17        165        ----a-w-        c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl1172004_64.bat
2011-12-13 19:14 . 2011-12-15 20:45        --------        d-----w-        c:\users\Nico.dell-PC.000\AppData\Roaming\57168
2011-12-13 19:14 . 2011-12-15 07:04        --------        d-----w-        c:\users\Nico.dell-PC.000\AppData\Roaming\B8457
2011-12-08 18:59 . 2011-12-08 18:59        --------        d-----w-        c:\users\Nico.dell-PC.000\AppData\Local\Apple
2011-12-02 15:28 . 2011-12-02 15:28        --------        d-----w-        c:\programdata\Nexon
2011-12-02 14:45 . 2011-12-02 15:22        --------        d-----w-        C:\Download
2011-12-02 14:45 . 2011-12-02 15:22        --------        d-----w-        C:\Nexon
2011-12-02 14:45 . 2011-12-02 14:45        235        ----a-w-        c:\windows\SysWow64\nxEuUninstall.bat
2011-12-02 14:45 . 2011-12-02 14:45        446464        ----a-w-        c:\windows\NEXON_EU_DownloaderUpdater.exe
2011-11-28 19:37 . 2011-11-29 08:07        --------        d-----w-        c:\users\Nico.dell-PC.000\AppData\Local\Windows Live
2011-11-24 08:40 . 2011-06-16 16:53        232960        ----a-w-        c:\windows\system32\Spool\prtprocs\x64\EKIJ5000PPR.dll
2011-11-24 08:36 . 2011-11-24 08:36        --------        d-----w-        c:\windows\SysWow64\spool
2011-11-24 08:23 . 2011-11-24 08:23        12713136        ----a-w-        c:\program files (x86)\aio_install.exe
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-19 08:53 . 2011-05-23 11:19        2300696        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2011-12-19 08:53 . 2011-05-23 11:19        42776        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2011-12-17 08:14 . 2011-05-21 18:35        2300696        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-12-17 08:14 . 2011-05-21 18:35        42776        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-12-14 07:38 . 2011-05-19 13:13        414368        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-29 10:50 . 2011-10-29 10:49        39401336        ----a-w-        c:\program files (x86)\QuickTimeInstaller.exe
2011-10-29 09:21 . 2011-05-15 03:21        472808        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2011-10-29 09:17 . 2011-10-29 09:10        910624        ----a-w-        c:\program files (x86)\jxpiinstall.exe
2011-10-29 08:54 . 2011-10-29 08:54        1019816        ----a-w-        c:\program files\DELL_DELL-DIGITAL-DELIVERY_A05_R313622.exe
2011-10-25 11:17 . 2011-10-25 11:17        9756672        ----a-w-        c:\program files\L502X_A__06.exe
2011-10-24 12:29 . 2011-10-24 12:29        94208        ----a-w-        c:\windows\SysWow64\QuickTimeVR.qtx
2011-10-24 12:29 . 2011-10-24 12:29        69632        ----a-w-        c:\windows\SysWow64\QuickTime.qts
2011-10-17 07:05 . 2011-10-17 07:05        13885360        ----a-w-        c:\program files (x86)\Firefox Setup 7.0.1.exe
2011-10-17 06:07 . 2011-10-17 06:07        1739400        ----a-w-        c:\users\Jasmina\PSISetup2003.exe
2011-10-13 06:08 . 2011-10-13 06:08        292184        ----a-w-        c:\users\Jasmina\dxwebsetup.exe
2011-10-07 15:06 . 2011-10-07 14:58        384512408        ----a-w-        c:\users\Jasmina\Nero-11.0.10700_trial.exe
2011-10-04 18:36 . 2011-10-04 18:36        10308272        ----a-w-        c:\users\Jasmina\Opera_1151_int_Setup.exe
2011-10-03 12:40 . 2011-10-03 12:41        247053        ----a-w-        c:\program files (x86)\mp3DC213.exe
2011-10-01 07:43 . 2011-10-01 07:43        6727840        ----a-w-        c:\users\Jasmina\SkypeClicktoCall.exe
2011-09-29 16:29 . 2011-11-09 07:00        1923952        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2011-09-29 06:55 . 2011-09-29 06:55        3103511        ----a-w-        c:\program files (x86)\kcsetup8.exe
2011-09-24 16:12 . 2011-09-24 16:12        1291624        ----a-w-        c:\program files\wlsetup-web__1_.exe
2011-09-23 13:20 . 2011-05-15 03:22        525544        ----a-w-        c:\windows\system32\deployJava1.dll
2011-09-23 13:06 . 2011-09-23 13:05        21073936        ----a-w-        c:\program files (x86)\vlc-1.1.11-win32.exe
2011-09-23 11:41 . 2011-09-23 11:40        23773184        ----a-w-        c:\program files (x86)\PXCViewer98_x64.msi
2011-09-23 11:31 . 2011-09-22 09:34        3089056        ----a-w-        c:\program files (x86)\install_flash_player.exe
2011-09-23 11:27 . 2011-09-23 11:27        1376768        ----a-w-        c:\program files (x86)\7z920-x64.msi
2011-09-16 05:47 . 2011-09-16 05:44        168166968        ----a-w-        c:\program files (x86)\OOo_3.3.0_Win_x86_install-wJRE_de.exe
2011-08-30 14:06 . 2011-05-28 12:11        14563768        ----a-w-        c:\program files (x86)\FreeYouTubeToMP3Converter.exe
2011-08-30 14:04 . 2011-05-28 12:13        14212584        ----a-w-        c:\program files (x86)\FreeYouTubeToiPodConverter.exe
2011-08-28 10:12 . 2011-08-28 10:11        51975388        ----a-w-        c:\program files (x86)\VSX4_Pro_TBYB.exe.part
2011-08-28 08:56 . 2011-08-28 08:55        2466704        ----a-w-        c:\program files (x86)\AdobeDownloadAssistant.exe
2011-08-27 10:56 . 2011-08-27 10:56        1228384        ----a-w-        c:\program files (x86)\PremiereElements_9_LS15.exe
2011-08-27 10:23 . 2011-08-27 10:23        8353800        ----a-w-        c:\program files (x86)\Adobe_Premiere_Elements_9-AkamaiDLM.exe
2011-08-25 16:58 . 2011-08-25 16:58        6716353        ----a-w-        c:\program files (x86)\Sunbird_Setup_1.0_Beta_1.exe
2011-07-18 14:59 . 2011-07-18 14:59        13522064        ----a-w-        c:\program files (x86)\Firefox Setup 5.0.1.exe
2011-05-22 08:35 . 2011-05-22 08:35        21255560        ----a-w-        c:\program files (x86)\SkypeSetupFull.exe
2011-05-19 13:44 . 2011-05-19 13:44        1663693        ----a-w-        c:\program files (x86)\winrar-x64-400d.exe
2011-05-19 13:39 . 2011-05-19 13:37        81797928        ----a-w-        c:\program files (x86)\iTunes64Setup.exe
2011-05-19 13:18 . 2011-05-19 13:17        20240744        ----a-w-        c:\program files (x86)\gimp-2.6.11-i686-setup.exe
2011-05-19 13:17 . 2011-05-19 13:17        19735256        ----a-w-        c:\program files (x86)\gimp-2.6.8-x64-setup.exe
2011-05-19 13:10 . 2011-05-19 13:10        14166016        ----a-w-        c:\program files (x86)\wz150gev.msi
2011-05-19 13:06 . 2011-05-19 13:06        767064        ----a-w-        c:\program files (x86)\wpsetup4.57.exe
2011-05-19 11:34 . 2011-05-19 11:34        568648        ----a-w-        c:\program files (x86)\GoogleEarthSetup.exe
2011-05-19 11:28 . 2011-05-19 11:28        52718176        ----a-w-        c:\program files (x86)\avira_antivir_personal_de.exe
2011-05-19 11:26 . 2011-05-19 11:26        9326056        ----a-w-        c:\program files (x86)\Thunderbird Setup 3.1.10.exe
2011-05-19 11:25 . 2011-05-19 11:25        12362480        ----a-w-        c:\program files (x86)\Firefox Setup 4.0.1.exe
2011-01-19 11:34 . 2011-01-19 11:34        3003392        ----a-w-        c:\program files (x86)\openofficeorg33.msi
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2010-08-19 487562]
"Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544]
"SMSTray"="c:\program files (x86)\Samsung\EmoDio\SMSTray.exe" [2009-04-16 479232]
"NBAgent"="c:\program files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 1493288]
"ChicoSys"="c:\windows\SysWOW64\cc32\webtmr.exe" [2009-07-13 5635736]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2011-12-15 296056]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-12-08 421736]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe" [2011-06-16 2922496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe" [2010-08-11 163040]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CCWinTray"="c:\windows\tray\wintmr.exe" [2009-07-13 5975704]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"KodakHomeCenter"="c:\program files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe" [2011-09-05 2232752]
.
c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\users\Jasmina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-4-19 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"HideFastUserSwitching"= 1 (0x1)
"EnableLinkedConnections"= 1 (0x1)
"EnableLUA"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableClock"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ksupmgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-01-24 991296]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-19 136176]
R2 ksupmgr;File-/Update Service;c:\windows\SysWOW64\ksupmgr.exe [2010-08-25 765592]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-01-24 1298496]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-19 136176]
R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys [x]
R3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [x]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys [x]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x]
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-01-24 901184]
S2 DBService;DATA BECKER Update Service;c:\program files (x86)\Common Files\DATA BECKER Shared\DBService.exe [2010-05-28 2650112]
S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files (x86)\Kodak\AiO\Center\EKAiOHostService.exe [2011-09-05 393648]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-09-23 641832]
S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2010-11-30 1997416]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [x]
S3 AVer7231_x64;AVerMedia 7231 capture service;c:\windows\system32\DRIVERS\AVer7231_x64.sys [x]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [x]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [x]
S3 HPMo4DE3;Mouse Suite Driver_4DE3 (WDF Version);c:\windows\system32\DRIVERS\HPMo4DE3.sys [x]
S3 HPub4DE3;USB Mouse Low Filter Driver_4DE3 (WDF Version);c:\windows\system32\Drivers\HPub4DE3.sys [x]
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - avipbb
*Deregistered* - Chico
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai        REG_MULTI_SZ          Akamai
.
Inhalt des "geplante Tasks" Ordners
.
2011-12-21 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025UA.job
- c:\users\Nico.dell-PC.000\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-10 19:23]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2010-12-14 6561384]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-12-11 2186856]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2010-11-29 312936]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-12 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-12 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-12 418328]
"FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-01-24 10355200]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-12-17 1933584]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-05-30 2055816]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-07-28 497648]
"EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe" [2011-06-16 2922496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Free YouTube to iPod Converter - c:\users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm
IE: Free YouTube to MP3 Converter - c:\users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\3cers2zs.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - www.google.de
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-Conime - c:\windows\system32\conime.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_b427739.dll"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ce,9e,47,77,90,b8,f8,4f,8e,46,72,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ce,9e,47,77,90,b8,f8,4f,8e,46,72,\
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.123\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.csv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dbf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dot\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ThunderbirdEML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hwp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.log\UserChoice]
@Denied: (2) (Administrator)
"Progid"="txtfile"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarMathDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpdp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="NCH.MixPad.mpdp"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odb\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.DatabaseDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.MathDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.DrawDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.WriterDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.ImpressDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ods\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.CalcDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.WriterDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.otg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.DrawDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.oth\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.WriterDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.otp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.ImpressDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ott\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.WriterDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.oxt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="office.Extension.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pot\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pps\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rtf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.slk\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.stc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.std\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarDrawTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sti\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.stw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarDrawDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarMathDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.URL"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdseml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ThunderbirdEML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wk1\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wks\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="NCH.WavePad.wpp"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xls\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsb\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2011-12-21  08:36:50
ComboFix-quarantined-files.txt  2011-12-21 07:36
.
Vor Suchlauf: 17 Verzeichnis(se), 118.534.037.504 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 118.229.495.808 Bytes frei
.
- - End Of File - - 349A187C0E2F5F539931BA904FBE7AB5:


Rheingold 21.12.2011 08:50

Code:

AccelerometerP11
Adobe AIR
Adobe Community Help
Adobe Download Assistant
Adobe Flash Player 11 ActiveX
Adobe Premiere Elements 9
Adobe Premiere Elements 9 Content
Adobe Premiere Elements 9 Content 1
Adobe Premiere Elements 9 Content 2
Adobe Premiere Elements 9 Content 3
Adobe Premiere Elements 9 HD Content 1
Adobe Premiere Elements 9 HD Content 2
Adobe Premiere Elements 9 HD Content 3
Advanced Audio FX Engine
aioscnnr
Akamai NetSession Interface Service
Apple Application Support
Apple Software Update
AVerMedia H339 Hybrid TV Tuner 2.2.64.64
bpd_scan
center
Cobra 11 - Burning Wheels (remove only)
Combat Arms EU
ContentSAFER for Wizmax
D3DX10
DATA BECKER BewerbungsGenie 7
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell DataSafe Online
Dell Getting Started Guide
Dell MusicStage
Dell PhotoStage
Dell Stage
Dell VideoStage
Dell Webcam Central
DirectX 9 Runtime
Elements 9 Organizer
Elements STI Installer
EmoDio
ESET Online Scanner v3
essentials
Express Burn Disc Burning Software
Express Rip
Facebook Video Calling 1.0.0.8177
Facebook Video Calling 1.0.0.8953
FIFA 11
Free YouTube to iPod Converter version 3.10.8.815
Free YouTube to MP3 Converter version 3.10.8.815
FUSSBALL MANAGER 07
Google Earth
Google Update Helper
High-Definition Video Playback
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Internet-TV für Windows Media Center
Java Auto Updater
Java(TM) 6 Update 29
Junk Mail filter update
Kindersicherung 2011
KODAK All-in-One Software
Malwarebytes' Anti-Malware Version 1.51.2.1300
Mesh Runtime
Microsoft Office 2010
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
MixPad Audio Mixer
Mozilla Firefox 8.0 (x86 de)
Mozilla Thunderbird (8.0)
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NBA 2K11
Nero 11
Nero 11 Disc Menus Basic
Nero 11 Effects Basic
Nero 11 Image Samples
Nero 11 Kwik Themes Basic
Nero 11 PiP Effects Basic
Nero Audio Pack 1
Nero BackItUp 11
Nero BackItUp 11 Help (CHM)
Nero Burning ROM 11
Nero Burning ROM 11 Help (CHM)
Nero ControlCenter 11
Nero ControlCenter 11 Help (CHM)
Nero Core Components 11
Nero CoverDesigner 11
Nero CoverDesigner 11 Help (CHM)
Nero Express 11
Nero Express 11 Help (CHM)
Nero Kwik Media
Nero Kwik Media Help (CHM)
Nero Recode 11
Nero Recode 11 Help (CHM)
Nero RescueAgent 11
Nero RescueAgent 11 Help (CHM)
Nero SoundTrax 11
Nero SoundTrax 11 Help (CHM)
Nero Update
Nero Video 11
Nero Video 11 Help (CHM)
Nero WaveEditor 11
Nero WaveEditor 11 Help (CHM)
nero.prerequisites.msi
Nexon Game Manager
NVIDIA Stereoscopic 3D Driver
ocr
OpenOffice.org 3.3
PhotoShowExpress
PreReq
ProtectDisc Driver, Version 11
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
Realtek High Definition Audio Driver
RealUpgrade 1.1
Roxio Activation Module
Roxio BackOnTrack
Roxio Burn
Roxio Creator Starter
Roxio Express Labeler 3
Secunia PSI (2.0.0.3003)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870)
Skype Click to Call
Skype™ 5.5
SmartSound Common Data
SmartSound Quicktracks 5
SmartSound Quicktracks for Premiere Elements 9.0
Sonic CinePlayer Decoder Pack
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
VLC media player 1.1.11
WavePad Sound Editor
welcome
Windows Live Communications Platform
Windows Live Essentials
Windows Live Fotogalerie
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX control for remote connections
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Media Encoder 9 Series


Rheingold 21.12.2011 08:53

Liebe Kira,
1. ich habe die combo-fix.exe mit "als Adminstrator ausführen" gestartet. Ist das schlimm bzw. soll ich den scan wiederholen?

2. avira und antispyware musste ich deinstallieren, da von combofix die nachricht kam, die programm seien noch aktiv, obwohl ich sie geschlossen hatte.

3. während des scans waren skype und dell stage aktiv, hatte ich vergessen zu schließen.

Viele Grüße
Jasmina

kira 22.12.2011 07:08

Zitat:

Zitat von Rheingold (Beitrag 738687)

2. avira und antispyware musste ich deinstallieren,

stehst Du jetzt ohne Antivirenlösung da?

Rheingold 22.12.2011 08:14

nein, ich habe mir nach combofix avira premium testversion runtergeladen und ausgeführt. avira hat keinen fund angezeigt.
jasmina

Rheingold 22.12.2011 08:28

Dann habe ich noch mal mit Anti-Malware gescannt und dort wurde immer noch ein Infizierung in der Registrierung gefunden. Was soll ich da machen?

Viele Grüße
Jasmina

Code:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 911122103

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

21.12.2011 19:37:28
mbam-log-2011-12-21 (19-37-09).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 490908
Laufzeit: 1 Stunde(n), 11 Minute(n), 48 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableConfig (Windows.Tool.Disabled) -> Bad: (1) Good: (0) -> No action taken.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)


Rheingold 22.12.2011 09:50

P.s.: Auch die Windows Firewall lässt sich nicht aktivieren.
Firewall ein- oder ausschalten - Empfohlene Einstellungen: Einige der Einstellungen können von der Windows Firewall nicht geändert werden. Fehlercode: 0x80070424

Erweiterte Einstellungen: Das Snap-in Windows Firewall mit Erweiterten Einstellungen konnte nicht geladen werden. Fehlercode: 0x6D9

kira 22.12.2011 15:56

1.
unter Dienste aktiviert/gestartet?:
Windows-Taste + R gleichzeitig
- schreib services.msc rein und klicke auf OK

2.
wenn Du damit kein Erfolg hast..
versuche mit "Fixit von Microsoft:
Firewall reparieren mit "Fixit":-> Automatische Diagnose und Korrektur von Problemen mit dem Windows-Firewalldienst
Firewall reparieren

Rheingold 22.12.2011 16:31

Nein, unter Dienste ist sie nicht aufgeführt und bei fixit kommt beim Ladevorgang die rückmeldung, dass der service zurzeit nicht ausgeführt werden kann. ?
J.

kira 23.12.2011 04:35

unter Dienste..."Basisfiltermodul" "gestartet"?

versuche die Tipps hier zu befolgen:-> Windows-Firewall per Kommandozeile (cmd) aktivieren und deaktivieren.

Rheingold 24.12.2011 14:28

Hi Kira,
1. unter System und Sicherheit - Verwaltung - Dienste, gibt es Basisfiltermodul nicht.
2. bei cmd kommt die meldung:" fehler beim herstellen der verbindugn mit windows-firewall dienst. stellen sie sicher, dass der dienst ausgeführt wird."

Ich wünsche dir / euch schöne Weihnachten ... und viele Geschenke! ;-)
Jasmina

kira 25.12.2011 03:08

1.
Die combofix.exe befindet sich noch auf Deinem Desktop?
Den folgenden Text in den Editor (Start - Zubehör - Editor) kopieren und als cfscript.txt mit "Speichern unter" auf dem Desktop. Gib an "Alle Dateien" - Speichern:
Code:

KILLALL::

File::
c:\users\Jasmina\AppData\Roaming\57168
c:\users\Jasmina\AppData\Roaming\B8457
c:\users\Nico.dell-PC.000\AppData\Roaming\57168
c:\users\Nico.dell-PC.000\AppData\Roaming\B8457

solltest Du dann auf dem Desktop diese Datei cfscript.txt finden
http://img.photobucket.com/albums/v7...FScriptB-4.gif
in bezug auf das obige bild, ziehe das CFScript in die combofix.exe hinein. wenn CF fertig ist, wird es eine Logdatei unter C:\ComboFix.txt erstellen, poste den inhalt.
Wenn ComboFix fertig ist, wird es ein Log erstellen, C:\ComboFix.txt - Warte, bis sich das Combofix-Fenster geschlossen hat und das Logfile im Editor erscheint!
Bitte füge es hier als nächste Antwort ein.

2.
Mach bitte einen Rechtsklick auf die im folgenden genannten Dateien (mit der Maus), schau dir an, was unter Eigenschaften steht, kopiere diese Angaben (Datei Version, Beschreibung der Datei, Copyright bei wem? FirmenName) hier in deinen Thread von diesen Anwendungen (bebilderte Anleitung *hier*:
Zitat:

2011-12-14 07:38 . 2011-12-14 07:38 -------- d-sh--w- c:\users\Jasmina\AppData\Local\4d0d2e25
2011-12-13 19:17 . 2011-12-16 08:57 -------- d-sh--w- c:\users\Nico.dell-PC.000\AppData\Local\4d0d2e25
► Hast du die Probleme immer noch?

Rheingold 25.12.2011 08:50

Hallo Kira,
die log datei ist zu groß, deshalb in zwei Etappen.

Code:

ComboFix 11-12-20.04 - Administrator 25.12.2011  8:20.3.8 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3990.2266 [GMT 1:00]
ausgeführt von:: c:\users\Administrator\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Administrator\Desktop\cfscript.txt
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
FILE ::
"c:\users\Jasmina\AppData\Roaming\57168"
"c:\users\Jasmina\AppData\Roaming\B8457"
"c:\users\Nico.dell-PC.000\AppData\Roaming\57168"
"c:\users\Nico.dell-PC.000\AppData\Roaming\B8457"
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Default\AppData\Roaming\DPInst.exe
c:\users\Default\AppData\Roaming\gacutil.exe
c:\users\Default\AppData\Roaming\PnPutil.exe
c:\windows\SysWow64\SWCTL.DLL
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-11-25 bis 2011-12-25  ))))))))))))))))))))))))))))))
.
.
2011-12-25 07:28 . 2011-12-25 07:28        --------        d-----w-        c:\users\UpdatusUser\AppData\Local\temp
2011-12-25 07:28 . 2011-12-25 07:28        --------        d-----w-        c:\users\Public\AppData\Local\temp
2011-12-25 07:28 . 2011-12-25 07:28        --------        d-----w-        c:\users\Nico\AppData\Local\temp
2011-12-25 07:28 . 2011-12-25 07:28        --------        d-----w-        c:\users\Nico.dell-PC\AppData\Local\temp
2011-12-25 07:28 . 2011-12-25 07:28        --------        d-----w-        c:\users\Nico.dell-PC.000\AppData\Local\temp
2011-12-25 07:28 . 2011-12-25 07:28        --------        d-----w-        c:\users\Nico Spiele\AppData\Local\temp
2011-12-25 07:28 . 2011-12-25 07:28        --------        d-----w-        c:\users\Jasmina\AppData\Local\temp
2011-12-25 07:28 . 2011-12-25 07:28        --------        d-----w-        c:\users\Jasmina 2\AppData\Local\temp
2011-12-25 07:28 . 2011-12-25 07:28        --------        d-----w-        c:\users\Gast\AppData\Local\temp
2011-12-25 07:28 . 2011-12-25 07:28        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-12-25 07:28 . 2011-12-25 07:28        --------        d-----w-        c:\users\AppData\AppData\Local\temp
2011-12-23 08:51 . 2011-12-23 08:51        41272        ----a-w-        c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-12-22 08:57 . 2011-12-22 08:57        --------        d-----w-        c:\users\Jasmina\AppData\Roaming\Avira
2011-12-21 09:26 . 2011-12-21 09:26        --------        d-----w-        c:\users\Administrator\AppData\Roaming\Avira
2011-12-21 09:25 . 2011-12-22 07:07        130760        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2011-12-21 09:25 . 2011-10-11 14:06        27760        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2011-12-21 09:25 . 2011-10-11 14:06        97312        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2011-12-21 09:25 . 2011-12-21 09:25        --------        d-----w-        c:\programdata\Avira
2011-12-21 09:25 . 2011-12-21 09:25        --------        d-----w-        c:\program files (x86)\Avira
2011-12-21 09:23 . 2011-12-21 09:23        --------        d-sh--w-        c:\windows\SysWow64\%APPDATA%
2011-12-21 08:50 . 2011-12-21 08:52        81313744        ----a-w-        c:\program files (x86)\avira_antivirus_premium_de.exe
2011-12-19 12:21 . 2011-12-19 12:21        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2011-12-19 09:30 . 2011-12-19 09:30        --------        d-----w-        c:\windows\SysWow64\wbem\en-US
2011-12-19 09:30 . 2011-12-19 09:30        --------        d-----w-        c:\windows\system32\wbem\en-US
2011-12-19 09:13 . 2011-12-19 09:13        --------        d-----w-        c:\program files\Microsoft Silverlight
2011-12-19 09:12 . 2011-12-19 09:12        13072536        ----a-w-        c:\windows\Silverlight_x64.exe
2011-12-19 08:00 . 2011-12-19 08:50        --------        d-----w-        c:\program files (x86)\Spybot - Search & Destroy
2011-12-19 08:00 . 2011-12-19 08:50        --------        d-----w-        c:\programdata\Spybot - Search & Destroy
2011-12-18 12:56 . 2011-12-18 12:56        --------        d-----w-        c:\program files (x86)\ESET
2011-12-18 07:06 . 2011-12-18 07:06        --------        d-----w-        C:\_OTL
2011-12-16 08:08 . 2011-12-16 08:08        --------        d-----w-        c:\users\Administrator\AppData\Roaming\RealNetworks
2011-12-15 10:50 . 2011-12-15 10:50        --------        d-----w-        c:\users\Administrator\AppData\Local\SoftGrid Client
2011-12-15 10:50 . 2011-12-19 09:19        --------        d-----w-        c:\users\Administrator\AppData\Roaming\SoftGrid Client
2011-12-15 10:34 . 2011-12-15 10:34        --------        d-----w-        c:\program files\iPod
2011-12-15 10:34 . 2011-12-15 10:35        --------        d-----w-        c:\program files\iTunes
2011-12-15 10:34 . 2011-12-15 10:35        --------        d-----w-        c:\program files (x86)\iTunes
2011-12-15 10:29 . 2011-12-15 10:29        11776        ----a-w-        c:\program files (x86)\Mozilla Firefox\plugins\nprjplug.dll
2011-12-15 10:29 . 2011-12-15 10:29        --------        d-----w-        c:\program files (x86)\Common Files\xing shared
2011-12-15 10:29 . 2011-12-15 10:29        150696        ----a-w-        c:\program files (x86)\Mozilla Firefox\plugins\nppl3260.dll
2011-12-15 10:28 . 2011-12-15 10:28        108544        ----a-w-        c:\program files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
2011-12-15 10:28 . 2011-12-15 10:28        499712        ----a-w-        c:\windows\SysWow64\msvcp71.dll
2011-12-15 10:28 . 2011-12-15 10:28        348160        ----a-w-        c:\windows\SysWow64\msvcr71.dll
2011-12-15 10:25 . 2011-12-15 10:25        713472        ----a-w-        c:\program files (x86)\RealPlayer.exe
2011-12-15 10:22 . 2011-12-15 10:25        --------        d-sh--w-        c:\users\Administrator\AppData\Local\4d0d2e25
2011-12-15 09:41 . 2011-12-15 09:41        --------        d-----w-        c:\program files\CCleaner
2011-12-15 09:39 . 2011-12-15 09:39        3552208        ----a-w-        c:\program files (x86)\ccsetup313.exe
2011-12-14 22:09 . 2011-10-15 06:31        723456        ----a-w-        c:\windows\system32\EncDec.dll
2011-12-14 22:09 . 2011-10-15 05:38        534528        ----a-w-        c:\windows\SysWow64\EncDec.dll
2011-12-14 22:09 . 2011-10-26 05:21        43520        ----a-w-        c:\windows\system32\csrsrv.dll
2011-12-14 22:09 . 2011-11-24 04:52        3145216        ----a-w-        c:\windows\system32\win32k.sys
2011-12-14 21:58 . 2011-11-05 05:32        2048        ----a-w-        c:\windows\system32\tzres.dll
2011-12-14 21:58 . 2011-11-05 04:26        2048        ----a-w-        c:\windows\SysWow64\tzres.dll
2011-12-14 18:58 . 2011-12-14 18:58        163        ----a-w-        c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl593131_64.bat
2011-12-14 07:38 . 2011-12-14 07:38        --------        d-sh--w-        c:\users\Jasmina\AppData\Local\4d0d2e25
2011-12-14 07:35 . 2011-12-15 20:45        --------        d-----w-        c:\users\Jasmina\AppData\Roaming\57168
2011-12-14 07:34 . 2011-12-15 20:45        --------        d-----w-        c:\users\Jasmina\AppData\Roaming\B8457
2011-12-13 19:19 . 2011-12-13 19:19        181        ----a-w-        c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl1265152_64.bat
2011-12-13 19:18 . 2011-12-13 19:18        163        ----a-w-        c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl1246260_64.bat
2011-12-13 19:18 . 2011-12-13 19:18        163        ----a-w-        c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl1208336_64.bat
2011-12-13 19:17 . 2011-12-16 08:57        --------        d-sh--w-        c:\users\Nico.dell-PC.000\AppData\Local\4d0d2e25
2011-12-13 19:17 . 2011-12-13 19:17        165        ----a-w-        c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl1172004_64.bat
2011-12-13 19:14 . 2011-12-15 20:45        --------        d-----w-        c:\users\Nico.dell-PC.000\AppData\Roaming\57168
2011-12-13 19:14 . 2011-12-15 07:04        --------        d-----w-        c:\users\Nico.dell-PC.000\AppData\Roaming\B8457
2011-12-08 18:59 . 2011-12-08 18:59        --------        d-----w-        c:\users\Nico.dell-PC.000\AppData\Local\Apple
2011-12-02 15:28 . 2011-12-02 15:28        --------        d-----w-        c:\programdata\Nexon
2011-12-02 14:45 . 2011-12-02 15:22        --------        d-----w-        C:\Download
2011-12-02 14:45 . 2011-12-02 15:22        --------        d-----w-        C:\Nexon
2011-12-02 14:45 . 2011-12-02 14:45        235        ----a-w-        c:\windows\SysWow64\nxEuUninstall.bat
2011-12-02 14:45 . 2011-12-02 14:45        446464        ----a-w-        c:\windows\NEXON_EU_DownloaderUpdater.exe
2011-11-28 19:37 . 2011-11-29 08:07        --------        d-----w-        c:\users\Nico.dell-PC.000\AppData\Local\Windows Live
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-19 08:53 . 2011-05-23 11:19        2300696        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2011-12-19 08:53 . 2011-05-23 11:19        42776        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2011-12-17 08:14 . 2011-05-21 18:35        2300696        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-12-17 08:14 . 2011-05-21 18:35        42776        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-12-14 07:38 . 2011-05-19 13:13        414368        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-24 08:23 . 2011-11-24 08:23        12713136        ----a-w-        c:\program files (x86)\aio_install.exe
2011-10-29 10:50 . 2011-10-29 10:49        39401336        ----a-w-        c:\program files (x86)\QuickTimeInstaller.exe
2011-10-29 09:21 . 2011-05-15 03:21        472808        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2011-10-29 09:17 . 2011-10-29 09:10        910624        ----a-w-        c:\program files (x86)\jxpiinstall.exe
2011-10-29 08:54 . 2011-10-29 08:54        1019816        ----a-w-        c:\program files\DELL_DELL-DIGITAL-DELIVERY_A05_R313622.exe
2011-10-25 11:17 . 2011-10-25 11:17        9756672        ----a-w-        c:\program files\L502X_A__06.exe
2011-10-24 12:29 . 2011-10-24 12:29        94208        ----a-w-        c:\windows\SysWow64\QuickTimeVR.qtx
2011-10-24 12:29 . 2011-10-24 12:29        69632        ----a-w-        c:\windows\SysWow64\QuickTime.qts
2011-10-17 07:05 . 2011-10-17 07:05        13885360        ----a-w-        c:\program files (x86)\Firefox Setup 7.0.1.exe
2011-10-17 06:07 . 2011-10-17 06:07        1739400        ----a-w-        c:\users\Jasmina\PSISetup2003.exe
2011-10-13 06:08 . 2011-10-13 06:08        292184        ----a-w-        c:\users\Jasmina\dxwebsetup.exe
2011-10-07 15:06 . 2011-10-07 14:58        384512408        ----a-w-        c:\users\Jasmina\Nero-11.0.10700_trial.exe
2011-10-03 12:40 . 2011-10-03 12:41        247053        ----a-w-        c:\program files (x86)\mp3DC213.exe
2011-10-01 07:43 . 2011-10-01 07:43        6727840        ----a-w-        c:\users\Jasmina\SkypeClicktoCall.exe
2011-09-29 16:29 . 2011-11-09 07:00        1923952        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2011-09-29 06:55 . 2011-09-29 06:55        3103511        ----a-w-        c:\program files (x86)\kcsetup8.exe
2011-09-24 16:12 . 2011-09-24 16:12        1291624        ----a-w-        c:\program files\wlsetup-web__1_.exe
2011-09-23 13:06 . 2011-09-23 13:05        21073936        ----a-w-        c:\program files (x86)\vlc-1.1.11-win32.exe
2011-09-23 11:41 . 2011-09-23 11:40        23773184        ----a-w-        c:\program files (x86)\PXCViewer98_x64.msi
2011-09-23 11:31 . 2011-09-22 09:34        3089056        ----a-w-        c:\program files (x86)\install_flash_player.exe
2011-09-23 11:27 . 2011-09-23 11:27        1376768        ----a-w-        c:\program files (x86)\7z920-x64.msi
2011-09-16 05:47 . 2011-09-16 05:44        168166968        ----a-w-        c:\program files (x86)\OOo_3.3.0_Win_x86_install-wJRE_de.exe
2011-08-30 14:06 . 2011-05-28 12:11        14563768        ----a-w-        c:\program files (x86)\FreeYouTubeToMP3Converter.exe
2011-08-30 14:04 . 2011-05-28 12:13        14212584        ----a-w-        c:\program files (x86)\FreeYouTubeToiPodConverter.exe
2011-08-28 10:12 . 2011-08-28 10:11        51975388        ----a-w-        c:\program files (x86)\VSX4_Pro_TBYB.exe.part
2011-08-28 08:56 . 2011-08-28 08:55        2466704        ----a-w-        c:\program files (x86)\AdobeDownloadAssistant.exe
2011-08-27 10:56 . 2011-08-27 10:56        1228384        ----a-w-        c:\program files (x86)\PremiereElements_9_LS15.exe
2011-08-27 10:23 . 2011-08-27 10:23        8353800        ----a-w-        c:\program files (x86)\Adobe_Premiere_Elements_9-AkamaiDLM.exe
2011-08-25 16:58 . 2011-08-25 16:58        6716353        ----a-w-        c:\program files (x86)\Sunbird_Setup_1.0_Beta_1.exe
2011-07-18 14:59 . 2011-07-18 14:59        13522064        ----a-w-        c:\program files (x86)\Firefox Setup 5.0.1.exe
2011-05-22 08:35 . 2011-05-22 08:35        21255560        ----a-w-        c:\program files (x86)\SkypeSetupFull.exe
2011-05-19 13:44 . 2011-05-19 13:44        1663693        ----a-w-        c:\program files (x86)\winrar-x64-400d.exe
2011-05-19 13:39 . 2011-05-19 13:37        81797928        ----a-w-        c:\program files (x86)\iTunes64Setup.exe
2011-05-19 13:18 . 2011-05-19 13:17        20240744        ----a-w-        c:\program files (x86)\gimp-2.6.11-i686-setup.exe
2011-05-19 13:17 . 2011-05-19 13:17        19735256        ----a-w-        c:\program files (x86)\gimp-2.6.8-x64-setup.exe
2011-05-19 13:10 . 2011-05-19 13:10        14166016        ----a-w-        c:\program files (x86)\wz150gev.msi
2011-05-19 13:06 . 2011-05-19 13:06        767064        ----a-w-        c:\program files (x86)\wpsetup4.57.exe
2011-05-19 11:34 . 2011-05-19 11:34        568648        ----a-w-        c:\program files (x86)\GoogleEarthSetup.exe
2011-05-19 11:26 . 2011-05-19 11:26        9326056        ----a-w-        c:\program files (x86)\Thunderbird Setup 3.1.10.exe
2011-05-19 11:25 . 2011-05-19 11:25        12362480        ----a-w-        c:\program files (x86)\Firefox Setup 4.0.1.exe
2011-01-19 11:34 . 2011-01-19 11:34        3003392        ----a-w-        c:\program files (x86)\openofficeorg33.msi
.
.
(((((((((((((((((((((((((((((  SnapShot@2011-12-21_07.33.48  )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-02 14:52 . 2011-11-02 14:52        98304              c:\windows\twain_32\kodak\kds_aioesp\ksImage.dll
- 2011-01-27 08:59 . 2011-01-27 08:59        98304              c:\windows\twain_32\kodak\kds_aioesp\ksImage.dll
+ 2011-11-02 14:52 . 2011-11-02 14:52        98304              c:\windows\twain_32\kodak\kds_aio5000\ksImage.dll
- 2011-01-27 08:59 . 2011-01-27 08:59        98304              c:\windows\twain_32\kodak\kds_aio5000\ksImage.dll
- 2011-08-19 01:39 . 2011-08-19 01:39        98304              c:\windows\twain_32\kodak\kds_aio2esp\ksImage.dll
+ 2011-07-15 06:50 . 2011-07-15 06:50        98304              c:\windows\twain_32\kodak\kds_aio2esp\ksImage.dll
- 2011-05-23 16:39 . 2011-12-21 07:13        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2011-05-23 16:39 . 2011-12-25 07:29        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2011-10-12 18:49 . 2011-12-20 08:19        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
+ 2011-10-12 18:49 . 2011-12-25 06:47        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
+ 2009-07-14 04:54 . 2011-12-25 07:29        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-12-21 07:13        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-10-12 18:49 . 2011-12-20 08:19        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat
+ 2011-10-12 18:49 . 2011-12-25 06:47        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-12-21 07:13        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-12-25 07:29        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-10-12 18:49 . 2011-12-20 08:19        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
+ 2011-10-12 18:49 . 2011-12-25 06:47        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-12-25 07:29        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-12-21 07:13        16384              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-12-21 09:23 . 2011-12-21 09:28        16384              c:\windows\SysWOW64\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
+ 2011-05-15 03:26 . 2011-12-25 07:14        81758              c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-12-25 07:14        36528              c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-05-20 06:09 . 2011-12-23 20:22        16534              c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3230886925-126132133-2629391164-1003_UserData.bin
- 2009-07-14 05:30 . 2011-11-24 08:56        86016              c:\windows\system32\DriverStore\infpub.dat
+ 2009-07-14 05:30 . 2011-12-21 09:25        86016              c:\windows\system32\DriverStore\infpub.dat
+ 2011-12-10 09:22 . 2011-12-10 09:22        53760              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\sv-se\EKAiO2MUI.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        57856              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\pt-BR\EKAiO2MUI.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        53248              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\no-no\EKAiO2MUI.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        56832              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\nl-NL\EKAiO2MUI.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        61952              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\it-IT\EKAiO2MUI.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        61952              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\fr-FR\EKAiO2MUI.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        54272              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\fi\EKAiO2MUI.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        59904              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\es-ES\EKAiO2MUI.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        52736              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\en-US\EKAiO2MUI.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        52736              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\en-GB\EKAiO2MUI.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        83968              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiOXPST.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        66048              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiOXPRINTABLEAREA.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        40960              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiOXPLPF.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        96256              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiOXNUP.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        40960              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiOXFRAME.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        73216              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiOXBKT.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        14336              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiO2WS.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        61440              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\de-DE\EKAiO2MUI.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        54784              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\da\EKAiO2MUI.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        10240              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\sv-se\EKaio2WiaCoInstRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        10240              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\pt-BR\EKaio2WiaCoInstRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        10240              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\no-no\EKaio2WiaCoInstRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        10240              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\nl-NL\EKaio2WiaCoInstRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        10240              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\it-IT\EKaio2WiaCoInstRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        10240              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\fr-FR\EKaio2WiaCoInstRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        10240              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\fi\EKaio2WiaCoInstRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        10240              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\es-ES\EKaio2WiaCoInstRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        10240              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\en-US\EKaio2WiaCoInstRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        10240              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\en-GB\EKaio2WiaCoInstRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        10240              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\de-DE\EKaio2WiaCoInstRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        10240              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\da\EKaio2WiaCoInstRes.dll
+ 2011-05-18 14:29 . 2011-12-22 19:50        16384              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-05-18 14:29 . 2011-12-19 14:11        16384              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-12-21 07:34 . 2011-12-22 19:50        32768              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-12-19 14:11        16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-12-22 19:50        16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:46 . 2011-12-23 07:10        94640              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2011-12-21 09:26 . 2011-12-21 09:26        53248              c:\windows\Installer\{EF53BFAB-4C10-40DB-A82D-9B07111715C6}\ARPPRODUCTICON.exe
- 2011-11-24 08:37 . 2011-11-24 08:37        53248              c:\windows\Installer\{EF53BFAB-4C10-40DB-A82D-9B07111715C6}\ARPPRODUCTICON.exe
+ 2011-11-24 08:38 . 2011-12-21 09:26        53248              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\ARPPRODUCTICON.exe
- 2011-11-24 08:38 . 2011-11-24 08:38        53248              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\ARPPRODUCTICON.exe
- 2011-11-24 08:39 . 2011-11-24 08:39        53248              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\ARPPRODUCTICON.exe
+ 2011-12-21 09:27 . 2011-12-21 09:27        53248              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\ARPPRODUCTICON.exe
+ 2011-12-21 09:23 . 2011-12-21 09:23        53248              c:\windows\Installer\{48B41C3A-9A92-4B81-B653-C97FEB85C910}\ARPPRODUCTICON.exe
+ 2011-12-21 09:25 . 2011-12-21 09:25        53248              c:\windows\Installer\{376348C2-E372-48BC-A138-E896757BD86A}\ARPPRODUCTICON.exe
- 2011-11-24 08:37 . 2011-11-24 08:37        53248              c:\windows\Installer\{376348C2-E372-48BC-A138-E896757BD86A}\ARPPRODUCTICON.exe
- 2011-11-24 08:36 . 2011-11-24 08:36        53248              c:\windows\Installer\{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}\ARPPRODUCTICON.exe
+ 2011-12-21 09:25 . 2011-12-21 09:25        53248              c:\windows\Installer\{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}\ARPPRODUCTICON.exe
+ 2011-12-21 09:27 . 2011-12-21 09:27        76288              c:\windows\assembly\NativeImages_v2.0.50727_32\ShellLib\1e8834961201cbdf2227ca7750c5456c\ShellLib.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        78336              c:\windows\assembly\NativeImages_v2.0.50727_32\Kodak.Statistics\c71823f1b43f6d98846baaaa8db4a524\Kodak.Statistics.ni.exe
+ 2011-12-21 09:27 . 2011-12-21 09:27        94208              c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.WIA\75121519a46bfb301886f5f484cb1b44\Interop.WIA.ni.dll
- 2011-11-24 08:38 . 2011-11-24 08:38        94208              c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.WIA\75121519a46bfb301886f5f484cb1b44\Interop.WIA.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        98304              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.DeviceSettin#\f0e6ce5d8da3ee1f1a038e688005d135\Inkjet.DeviceSettings.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        80896              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Configuration\9f929febe825f074285c39800e8e8e62\Inkjet.Configuration.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        52736              c:\windows\assembly\NativeImages_v2.0.50727_32\HRIntp.Interop\579d24976eefa6309b0f380dec1c1221\HRIntp.Interop.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        61440              c:\windows\assembly\NativeImages_v2.0.50727_32\Helper\bdfdf611f220be5d261f6334b587be26\Helper.ni.dll
+ 2011-05-21 11:49 . 2011-12-23 15:29        5594              c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2011-05-15 04:00 . 2011-12-25 07:14        8384              c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3230886925-126132133-2629391164-500_UserData.bin
+ 2011-12-10 09:21 . 2011-12-10 09:21        9728              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\sv-se\EKAiO2WiaShellExtRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        9728              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\pt-BR\EKAiO2WiaShellExtRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        9728              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\no-no\EKAiO2WiaShellExtRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        9728              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\nl-NL\EKAiO2WiaShellExtRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        9728              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\it-IT\EKAiO2WiaShellExtRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        9728              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\fr-FR\EKAiO2WiaShellExtRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        9728              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\fi\EKAiO2WiaShellExtRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        9728              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\es-ES\EKAiO2WiaShellExtRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        9728              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\en-US\EKAiO2WiaShellExtRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        9728              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\en-GB\EKAiO2WiaShellExtRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        9728              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\de-DE\EKAiO2WiaShellExtRes.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        9728              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\da\EKAiO2WiaShellExtRes.dll
- 2011-05-14 21:14 . 2011-12-20 20:25        1951              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat
+ 2011-05-14 21:14 . 2011-12-25 07:28        1951              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat
- 2011-12-21 07:08 . 2011-12-21 07:08        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-12-25 07:29 . 2011-12-25 07:29        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-12-25 07:29 . 2011-12-25 07:29        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-12-21 07:08 . 2011-12-21 07:08        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-11-02 14:52 . 2011-11-02 14:52        434176              c:\windows\twain_32\kodak\kds_aioesp\lexexe.exe
- 2011-03-11 07:12 . 2011-03-11 07:12        434176              c:\windows\twain_32\kodak\kds_aioesp\lexexe.exe
+ 2011-11-02 14:52 . 2011-11-02 14:52        434176              c:\windows\twain_32\kodak\kds_aio5000\lexexe.exe
- 2011-03-11 07:12 . 2011-03-11 07:12        434176              c:\windows\twain_32\kodak\kds_aio5000\lexexe.exe
+ 2011-12-10 09:20 . 2011-12-10 09:20        434176              c:\windows\twain_32\kodak\kds_aio2esp\lexexe.exe
- 2011-08-19 23:10 . 2011-08-19 23:10        434176              c:\windows\twain_32\kodak\kds_aio2esp\lexexe.exe
+ 2011-10-10 15:52 . 2009-07-13 23:15        842163              c:\windows\SysWOW64\scurl\scurlup.dat
+ 2011-05-19 10:09 . 2011-12-21 18:34        330446              c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-07-14 05:30 . 2011-11-24 08:56        239616              c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2011-12-21 09:25        239616              c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2011-11-24 08:36        143360              c:\windows\system32\DriverStore\infstor.dat
+ 2009-07-14 05:30 . 2011-12-21 09:25        143360              c:\windows\system32\DriverStore\infstor.dat
+ 2011-12-14 11:38 . 2011-12-14 11:38        449536              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\sv-se\EKAiO2PRE.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        153600              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\sv-se\EKAiO2FAXD.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        177664              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\sv-se\EKAiO2COI07.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        450048              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\pt-BR\EKAiO2PRE.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        153600              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\pt-BR\EKAiO2FAXD.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        177664              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\pt-BR\EKAiO2COI07.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        449536              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\no-no\EKAiO2PRE.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        153600              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\no-no\EKAiO2FAXD.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        177664              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\no-no\EKAiO2COI07.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        450048              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\nl-NL\EKAiO2PRE.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        153600              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\nl-NL\EKAiO2FAXD.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        177664              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\nl-NL\EKAiO2COI07.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        450048              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\it-IT\EKAiO2PRE.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        153600              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\it-IT\EKAiO2FAXD.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        177664              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\it-IT\EKAiO2COI07.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        450048              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\fr-FR\EKAiO2PRE.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        154112              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\fr-FR\EKAiO2FAXD.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        177664              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\fr-FR\EKAiO2COI07.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        449536              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\fi\EKAiO2PRE.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        153600              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\fi\EKAiO2FAXD.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        177664              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\fi\EKAiO2COI07.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        450048              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\es-ES\EKAiO2PRE.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        154112              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\es-ES\EKAiO2FAXD.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        177664              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\es-ES\EKAiO2COI07.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        449536              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\en-US\EKAiO2PRE.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        153600              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\en-US\EKAiO2FAXD.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        177664              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\en-US\EKAiO2COI07.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        449536              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\en-GB\EKAiO2PRE.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        153600              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\en-GB\EKAiO2FAXD.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        177664              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\en-GB\EKAiO2COI07.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        111616              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiOXWMK.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        441344              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiOXRPF.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        868864              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiO2XUIP.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        551424              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiO2SDK.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        820224              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiO2PRE.exe
+ 2011-12-10 09:22 . 2011-12-10 09:22        428032              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiO2FAXD.exe
+ 2011-12-14 11:38 . 2011-12-14 11:38        449536              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\de-DE\EKAiO2PRE.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        153600              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\de-DE\EKAiO2FAXD.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        177664              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\de-DE\EKAiO2COI07.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        449536              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\da\EKAiO2PRE.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        153600              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\da\EKAiO2FAXD.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        177664              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\da\EKAiO2COI07.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        213504              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\EKAiO2WiaShellExt.dll
+ 2011-12-02 11:49 . 2011-12-02 11:49        239616              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\EKaio2WiaPtp.exe
+ 2011-12-10 09:21 . 2011-12-10 09:21        122368              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\EKaio2WiaCoInst.dll
- 2009-07-14 05:12 . 2011-12-18 17:18        262144              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:12 . 2011-12-21 09:23        262144              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 05:01 . 2011-12-20 20:25        319168              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-12-25 07:28        319168              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-12-21 09:24 . 2011-12-21 09:24        327680              c:\windows\Installer\2340cb.msi
- 2011-05-25 11:19 . 2011-11-24 08:38        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_start_psu_1046_DC9ADFDC32FF459385901E5DDA1C8858.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_start_psu_1046_DC9ADFDC32FF459385901E5DDA1C8858.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_start_psu_1043_36D939E382C443B4891630DE2B85EBC2.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_start_psu_1043_36D939E382C443B4891630DE2B85EBC2.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_start_psu_1040_1FF72AA9EDC244729C9AFBD24A90E524.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_start_psu_1040_1FF72AA9EDC244729C9AFBD24A90E524.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_start_psu_1036_A41D2291122D4CD7A339DED2B8CA7090.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_start_psu_1036_A41D2291122D4CD7A339DED2B8CA7090.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_start_psu_1034_30438C29EA4E43738D6C3C1094A9F492.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_start_psu_1034_30438C29EA4E43738D6C3C1094A9F492.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_start_psu_1033_DB9A47DD20BD48B78405D4E726B5CA8B.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_start_psu_1033_DB9A47DD20BD48B78405D4E726B5CA8B.exe
+ 2011-11-24 08:38 . 2011-12-21 09:26        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_short_psu_1033_FD077128E4284358A43BDE46525E6847.exe
- 2011-11-24 08:38 . 2011-11-24 08:38        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_short_psu_1033_FD077128E4284358A43BDE46525E6847.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_setuputility_sv_69FFC3852D35471285A2CD1137B709EF.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_setuputility_sv_69FFC3852D35471285A2CD1137B709EF.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_setuputility_fi_658C81035500483EAE984694F2DE2F78.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_setuputility_fi_658C81035500483EAE984694F2DE2F78.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_setuputility_da_65223DD5D2A345BB8B47872BEEF97383.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_setuputility_da_65223DD5D2A345BB8B47872BEEF97383.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_printertool_sv_0A467CA819044BC7BA6D21816C4309FF.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_printertool_sv_0A467CA819044BC7BA6D21816C4309FF.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_printertool_fi_07FDBE5CC1054277AD6FE9C7A54FAC8B.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_printertool_fi_07FDBE5CC1054277AD6FE9C7A54FAC8B.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_printertool_da_BB63BB88F76047BBA98F4107EB360A4B.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\sc_printertool_da_BB63BB88F76047BBA98F4107EB360A4B.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut9_DF6F7E57247F405F8D44C945B89AFA1F.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut9_DF6F7E57247F405F8D44C945B89AFA1F.exe
- 2011-11-24 08:38 . 2011-11-24 08:38        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut6_04D5FD60DD5F47279ABF3C110518B687.exe
+ 2011-11-24 08:38 . 2011-12-21 09:26        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut6_04D5FD60DD5F47279ABF3C110518B687.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut34_F09544D3367843A48B5C31EDAA81E9A0.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut34_F09544D3367843A48B5C31EDAA81E9A0.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut33_73079DBCC88F41C7997E276DA153E481.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        126976              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut33_73079DBCC88F41C7997E276DA153E481.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut21_DD4D035ACA374327B7D30079F8FF9FB0.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut21_DD4D035ACA374327B7D30079F8FF9FB0.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut18_D23DA57BCA0C4A49A36A2015848FD42C.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut18_D23DA57BCA0C4A49A36A2015848FD42C.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut15_BEE2106E8860474594FD3BA39B0660F1.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut15_BEE2106E8860474594FD3BA39B0660F1.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut12_BBBC8FEC15EA45B58B2C60FEAC100AF7.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut12_BBBC8FEC15EA45B58B2C60FEAC100AF7.exe
+ 2011-05-25 11:19 . 2011-12-21 09:26        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut1_481DD05EA1B846948FF5700EFC7B9BBB.exe
- 2011-05-25 11:19 . 2011-11-24 08:38        143360              c:\windows\Installer\{BE94C681-68E2-4561-8ABC-8D2E799168B4}\NewShortcut1_481DD05EA1B846948FF5700EFC7B9BBB.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_6_79F4F9B00B33480CA4DD22609500B856.exe
+ 2011-05-25 11:20 . 2011-12-21 09:28        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_6_79F4F9B00B33480CA4DD22609500B856.exe
+ 2011-05-25 11:20 . 2011-12-21 09:28        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_29_0043EC1FF6794304B01705D24B1F1AF5.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_29_0043EC1FF6794304B01705D24B1F1AF5.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_11_9CC041322C0846838F374B3FE71F2E66.exe
+ 2011-05-25 11:20 . 2011-12-21 09:28        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_11_9CC041322C0846838F374B3FE71F2E66.exe
+ 2011-05-25 11:20 . 2011-12-21 09:28        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_1046_CE127699C7D04AC3ABFEEBDACA880F1C.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_1046_CE127699C7D04AC3ABFEEBDACA880F1C.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_1043_50E79B3800BF47C2856089BA7CDB9C55.exe
+ 2011-05-25 11:20 . 2011-12-21 09:28        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_1043_50E79B3800BF47C2856089BA7CDB9C55.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_1040_FDECD279997D49C1AB752E8B4D63C3DA.exe
+ 2011-05-25 11:20 . 2011-12-21 09:28        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_1040_FDECD279997D49C1AB752E8B4D63C3DA.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_1036_96F5C37CA28344EC92728F24942D8DA6.exe
+ 2011-05-25 11:20 . 2011-12-21 09:28        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_1036_96F5C37CA28344EC92728F24942D8DA6.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_1034_8B0483CD192840ECAB7BB0ADBDC95740.exe
+ 2011-05-25 11:20 . 2011-12-21 09:28        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_1034_8B0483CD192840ECAB7BB0ADBDC95740.exe
+ 2011-05-25 11:20 . 2011-12-21 09:28        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_1033_1BE79BF0F7964E19A6276040740D2ADF.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_start_hc_1033_1BE79BF0F7964E19A6276040740D2ADF.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_short_hc_1033_3289F1C2118D4AEDA29BA1A286FB16FB.exe
+ 2011-05-25 11:20 . 2011-12-21 09:28        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_short_hc_1033_3289F1C2118D4AEDA29BA1A286FB16FB.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_6_93F60001B9734662953DF13B2078359F.exe
+ 2011-05-25 11:20 . 2011-12-21 09:27        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_6_93F60001B9734662953DF13B2078359F.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_29_2BB123578BED4BFA8A4296F6B839F571.exe
+ 2011-05-25 11:20 . 2011-12-21 09:27        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_29_2BB123578BED4BFA8A4296F6B839F571.exe
+ 2011-05-25 11:20 . 2011-12-21 09:27        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_11_65D472CF1A584F9C98B3549AB33F2BF9.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_11_65D472CF1A584F9C98B3549AB33F2BF9.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_1046_A704C36B0B3D446CADC1752FAB36D1A7.exe
+ 2011-05-25 11:20 . 2011-12-21 09:27        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_1046_A704C36B0B3D446CADC1752FAB36D1A7.exe
+ 2011-05-25 11:20 . 2011-12-21 09:27        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_1043_43F2ECE9B10E406E9E6D011AC1B793EB.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_1043_43F2ECE9B10E406E9E6D011AC1B793EB.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_1040_2C957938BFAD43BCAB25B5C8F4C9A599.exe
+ 2011-05-25 11:20 . 2011-12-21 09:27        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_1040_2C957938BFAD43BCAB25B5C8F4C9A599.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_1036_4FEF69180DD749EAAF34573883C0B1B3.exe
+ 2011-05-25 11:20 . 2011-12-21 09:27        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_1036_4FEF69180DD749EAAF34573883C0B1B3.exe
+ 2011-05-25 11:20 . 2011-12-21 09:27        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_1034_A63805436CD547E38C59DCA2B67B0696.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_1034_A63805436CD547E38C59DCA2B67B0696.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_1033_E318532C033F488B809A057A09313CBF.exe
+ 2011-05-25 11:20 . 2011-12-21 09:27        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_1033_E318532C033F488B809A057A09313CBF.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_1031_F0C07CC6934F4DCDAD1D095765033C65.exe
+ 2011-05-25 11:20 . 2011-12-21 09:27        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\sc_desk_hc_1031_F0C07CC6934F4DCDAD1D095765033C65.exe
+ 2011-05-25 11:20 . 2011-12-21 09:27        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\NewShortcut29_98C5194EC8604E1E96A7F324A1D64755.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\NewShortcut29_98C5194EC8604E1E96A7F324A1D64755.exe
- 2011-05-25 11:20 . 2011-11-24 08:39        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\NewShortcut28_CE3CC1DE1D7040629B4F8D8BAC9ACE26.exe
+ 2011-05-25 11:20 . 2011-12-21 09:27        557056              c:\windows\Installer\{56BA241F-580C-43D2-8403-947241AAE633}\NewShortcut28_CE3CC1DE1D7040629B4F8D8BAC9ACE26.exe
- 2011-06-17 08:44 . 2011-06-17 08:44        323624              c:\windows\Installer\$PatchCache$\Managed\186C49EB2E861654A8CBD8E29719864B\6.0.14\wiaaut.dll
+ 2011-12-19 15:32 . 2011-12-19 15:32        323624              c:\windows\Installer\$PatchCache$\Managed\186C49EB2E861654A8CBD8E29719864B\6.0.14\wiaaut.dll
- 2011-11-24 08:39 . 2011-11-24 08:39        308224              c:\windows\assembly\NativeImages_v2.0.50727_32\Windows7.DesktopInt#\03dc0636114436742866ba51ea90686b\Windows7.DesktopIntegration.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        308224              c:\windows\assembly\NativeImages_v2.0.50727_32\Windows7.DesktopInt#\03dc0636114436742866ba51ea90686b\Windows7.DesktopIntegration.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        643584              c:\windows\assembly\NativeImages_v2.0.50727_32\VistaBridgeLibrary\8e53cd2e249b870506ad504282b05d02\VistaBridgeLibrary.ni.dll
- 2011-11-24 08:39 . 2011-11-24 08:39        643584              c:\windows\assembly\NativeImages_v2.0.50727_32\VistaBridgeLibrary\8e53cd2e249b870506ad504282b05d02\VistaBridgeLibrary.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        170496              c:\windows\assembly\NativeImages_v2.0.50727_32\PhotobucketNet\7fe608911e3d04f5d88c81916d5c75d7\PhotobucketNet.ni.dll
- 2011-11-24 08:40 . 2011-11-24 08:40        170496              c:\windows\assembly\NativeImages_v2.0.50727_32\PhotobucketNet\7fe608911e3d04f5d88c81916d5c75d7\PhotobucketNet.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        155648              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Windows\400750560e604bf36dfa946d4e88a081\Inkjet.Windows.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        283136              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Utilities\8618abe8c3754ea09cb862f82d7a2947\Inkjet.Utilities.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        282624              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Utilities\36c396c7df50809f1542ac66b45e7a23\Inkjet.Utilities.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        138240              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Tray\ea23fbd89574940e19f79b7e55c0dd50\Inkjet.Tray.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        977920              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Tools\dc07a6af7626793c82afcc433d75bf75\Inkjet.Tools.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        180736              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Statistics\426109970fd34b16d14ee0d53b9e3427\Inkjet.Statistics.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        378368              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Scanning\1a59845076c2edac566f38bb463564ee\Inkjet.Scanning.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        567296              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Scan\54dbb851c066e03ca1ebc7ffb4044d3e\Inkjet.Scan.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        343040              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Printing\7037ded51528aa41bca37e17e186e1d1\Inkjet.Printing.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        298496              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Picasa\434655e4026a7f015e60e97642a60ec4\Inkjet.Picasa.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        210944              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.PhotoBucket\1ea953d47055a603a5e9349856cb45aa\Inkjet.PhotoBucket.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        237056              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Localization\a00d9badb4f2e344b42a5c76a8b89014\Inkjet.Localization.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        522240              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.KodakGallery\02088502de74f0377acd8f4af5d06e54\Inkjet.KodakGallery.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        750080              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.IO\3a7650c5ca2dbe3cb1f00a003aae4515\Inkjet.IO.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        824832              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Hardware\5d49e7ab1d92aed39b2abc96bbee0aeb\Inkjet.Hardware.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        163328              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Flickr\9816827e2806c14d8a1906629eaa78fe\Inkjet.Flickr.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        162816              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Facebook\445bacea289d66b91f47c313c0ee9ade\Inkjet.Facebook.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        168448              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.EasyShare\a6e304d7a1a79c2b40cdf225a317dd56\Inkjet.EasyShare.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        105984              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Diagnostics\a2f4c2178fba1eb4e26423b25f7ee362\Inkjet.Diagnostics.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        280064              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Browse\fbb84a21981d09d113a19d5ee87b1623\Inkjet.Browse.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        169984              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Automation\ffbf2237475a302344c16554abe0e489\Inkjet.Automation.ni.dll
- 2011-11-24 08:40 . 2011-11-24 08:40        102912              c:\windows\assembly\NativeImages_v2.0.50727_32\Google.GData.Photos\c5c86e423e7c4801aa5a77f3da350b1e\Google.GData.Photos.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        102912              c:\windows\assembly\NativeImages_v2.0.50727_32\Google.GData.Photos\c5c86e423e7c4801aa5a77f3da350b1e\Google.GData.Photos.ni.dll
- 2011-11-24 08:40 . 2011-11-24 08:40        216576              c:\windows\assembly\NativeImages_v2.0.50727_32\Google.GData.Extens#\a62cc0c7d812759ac282b0678c13ecb6\Google.GData.Extensions.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        216576              c:\windows\assembly\NativeImages_v2.0.50727_32\Google.GData.Extens#\a62cc0c7d812759ac282b0678c13ecb6\Google.GData.Extensions.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        551424              c:\windows\assembly\NativeImages_v2.0.50727_32\Google.GData.Client\1ff834921875b7a3d77239115ce5d5d7\Google.GData.Client.ni.dll
- 2011-11-24 08:40 . 2011-11-24 08:40        551424              c:\windows\assembly\NativeImages_v2.0.50727_32\Google.GData.Client\1ff834921875b7a3d77239115ce5d5d7\Google.GData.Client.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        372736              c:\windows\assembly\NativeImages_v2.0.50727_32\FlickrNet\0e98497384490272c94b83f7d752681b\FlickrNet.ni.dll
- 2011-11-24 08:39 . 2011-11-24 08:39        372736              c:\windows\assembly\NativeImages_v2.0.50727_32\FlickrNet\0e98497384490272c94b83f7d752681b\FlickrNet.ni.dll
- 2011-11-24 08:39 . 2011-11-24 08:39        238080              c:\windows\assembly\NativeImages_v2.0.50727_32\Facebook\77f22ff9ac1758d9bbdec45e280b2fa0\Facebook.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        238080              c:\windows\assembly\NativeImages_v2.0.50727_32\Facebook\77f22ff9ac1758d9bbdec45e280b2fa0\Facebook.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        435200              c:\windows\assembly\NativeImages_v2.0.50727_32\EastmanKodakCompany#\0599448619bdd5951b3f404c7a7579e5\EastmanKodakCompany.EasyShare.ni.dll
- 2011-11-24 08:39 . 2011-11-24 08:39        435200              c:\windows\assembly\NativeImages_v2.0.50727_32\EastmanKodakCompany#\0599448619bdd5951b3f404c7a7579e5\EastmanKodakCompany.EasyShare.ni.dll
+ 2011-11-02 14:52 . 2011-11-02 14:52        2754560              c:\windows\twain_32\kodak\kds_aioesp\twaingui.exe
+ 2011-11-02 14:52 . 2011-11-02 14:52        2754560              c:\windows\twain_32\kodak\kds_aio5000\twaingui.exe
+ 2011-12-10 09:20 . 2011-12-10 09:20        2761216              c:\windows\twain_32\kodak\kds_aio2esp\twaingui.exe
+ 2011-12-25 07:12 . 2009-07-13 23:15        4170108              c:\windows\SysWOW64\wdrv\wdrvbdb.bin
+ 2011-12-14 11:38 . 2011-12-14 11:38        1883648              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\sv-se\EKAiO2RES.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        1886208              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\pt-BR\EKAiO2RES.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        1884160              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\no-no\EKAiO2RES.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        1884672              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\nl-NL\EKAiO2RES.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        1885696              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\it-IT\EKAiO2RES.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        1887232              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\fr-FR\EKAiO2RES.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        1884160              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\fi\EKAiO2RES.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        1886208              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\es-ES\EKAiO2RES.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        1882624              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\en-US\EKAiO2RES.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        1882624              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\en-GB\EKAiO2RES.dll
+ 2011-12-10 09:22 . 2011-12-10 09:22        3240448              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiO2MUI.exe
+ 2011-12-10 09:22 . 2011-12-10 09:22        1058304              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\EKAiO2MON.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        1885184              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\de-DE\EKAiO2RES.dll
+ 2011-12-14 11:38 . 2011-12-14 11:38        1884672              c:\windows\system32\DriverStore\FileRepository\ekaio2xps.inf_amd64_neutral_3f3caa4af0d278a8\Drivers\XpsPrinter\amd64\da\EKAiO2RES.dll
+ 2011-12-10 09:21 . 2011-12-10 09:21        1626112              c:\windows\system32\DriverStore\FileRepository\ekaio2wia.inf_amd64_neutral_ca7406939318428c\Drivers\Scanner\wia64\ekaiO2wia2Drv.dll
+ 2011-05-19 13:53 . 2011-12-25 07:28        8453937              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3230886925-126132133-2629391164-500-12288.dat
+ 2011-12-21 09:26 . 2011-12-21 09:26        3778560              c:\windows\Installer\2341a1.msi
+ 2011-12-21 09:25 . 2011-12-21 09:25        3611136              c:\windows\assembly\NativeImages_v2.0.50727_32\twaingui\de67648e38ddf8cac41b692f93da6c6e\twaingui.ni.exe
- 2011-11-24 08:39 . 2011-11-24 08:39        1762304              c:\windows\assembly\NativeImages_v2.0.50727_32\Newtonsoft.Json.Net#\cfff56c84c790176f77942a32d70b935\Newtonsoft.Json.Net20.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        1762304              c:\windows\assembly\NativeImages_v2.0.50727_32\Newtonsoft.Json.Net#\cfff56c84c790176f77942a32d70b935\Newtonsoft.Json.Net20.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        2438144              c:\windows\assembly\NativeImages_v2.0.50727_32\NetworkPrinterDisco#\f3d4d13b4f1a2845a521e6f8f263711c\NetworkPrinterDiscovery.ni.exe
+ 2011-12-21 09:27 . 2011-12-21 09:27        1247744              c:\windows\assembly\NativeImages_v2.0.50727_32\KodakAiOUpdater\f357abd61c37423c05064a544c6d8004\KodakAiOUpdater.ni.exe
+ 2011-12-21 09:26 . 2011-12-21 09:26        1190912              c:\windows\assembly\NativeImages_v2.0.50727_32\InkjetCore\e3631aec5ba73a1091270c5869ec8580\InkjetCore.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        1178624              c:\windows\assembly\NativeImages_v2.0.50727_32\InkjetCore\93ce0e05bad79cc3f9326cc560e46e2c\InkjetCore.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        1532928              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Editing\b3015cfe45ded52272a6030cc84848cf\Inkjet.Editing.ni.dll
+ 2011-12-21 09:28 . 2011-12-21 09:28        1217536              c:\windows\assembly\NativeImages_v2.0.50727_32\Inkjet.Destination\91d29b724f5e27dea5802cb39852a158\Inkjet.Destination.ni.dll
- 2011-11-24 08:38 . 2011-11-24 08:38        1177600              c:\windows\assembly\NativeImages_v2.0.50727_32\idrskrn_net14\81fdd5d81e1fb7757764133c129e8664\idrskrn_net14.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        1177600              c:\windows\assembly\NativeImages_v2.0.50727_32\idrskrn_net14\81fdd5d81e1fb7757764133c129e8664\idrskrn_net14.ni.dll
+ 2011-12-21 09:27 . 2011-12-21 09:27        3761664              c:\windows\assembly\NativeImages_v2.0.50727_32\CommonControls\6ba4d5b19fd438585fd79682330e015a\CommonControls.ni.dll
+ 2011-12-21 09:26 . 2011-12-21 09:26        3763712              c:\windows\assembly\NativeImages_v2.0.50727_32\CommonControls\42dce472bed35c03b6491141433b9106\CommonControls.ni.dll
+ 2011-12-21 09:26 . 2011-12-21 09:26        3207680              c:\windows\assembly\NativeImages_v2.0.50727_32\AiOPrinterTools\6d3cffb08b995cb8d61a0955a39d7cef\AiOPrinterTools.ni.exe
+ 2011-12-21 09:27 . 2011-12-21 09:27        1059328              c:\windows\assembly\NativeImages_v2.0.50727_32\AiOHostDirector\5fea9ab4ea17c71abde1df3529adc650\AiOHostDirector.ni.exe
+ 2011-12-21 09:28 . 2011-12-21 09:28        1874944              c:\windows\assembly\NativeImages_v2.0.50727_32\AiOHomeCenter\cb47f0efcd648466bb9b72de5711c6af\AiOHomeCenter.ni.exe
+ 2011-05-20 07:35 . 2011-12-25 07:09        22418236              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3230886925-126132133-2629391164-1003-8192.dat
+ 2011-05-23 16:36 . 2011-12-22 20:02        26271128              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3230886925-126132133-2629391164-1003-12288.dat
+ 2011-12-21 09:27 . 2011-12-21 09:27        13282816              c:\windows\Installer\2341bd.msi
+ 2011-12-21 09:26 . 2011-12-21 09:26        14059520              c:\windows\Installer\2340de.msi
+ 2011-12-21 09:25 . 2011-12-21 09:25        26562560              c:\windows\Installer\2340d8.msi
+ 2011-12-21 09:25 . 2011-12-21 09:25        32674304              c:\windows\Installer\2340d2.msi
+ 2011-12-21 09:23 . 2011-12-21 09:23        13505024              c:\windows\Installer\233ef8.msi
.
-- Snapshot auf jetziges Datum zurückgesetzt --


Rheingold 25.12.2011 08:52

Zweiter Teil combo fix log:

Code:

.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2010-08-19 487562]
"Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544]
"SMSTray"="c:\program files (x86)\Samsung\EmoDio\SMSTray.exe" [2009-04-16 479232]
"NBAgent"="c:\program files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 1493288]
"ChicoSys"="c:\windows\SysWOW64\cc32\webtmr.exe" [2009-07-13 5635736]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2011-12-15 296056]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-12-08 421736]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe" [2011-06-16 2922496]
"Conime"="c:\windows\system32\conime.exe" [BU]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-10-11 258512]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe" [2010-08-11 163040]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CCWinTray"="c:\windows\tray\wintmr.exe" [2009-07-13 5975704]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"KodakHomeCenter"="c:\program files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe" [2011-12-12 2234288]
.
c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\users\Jasmina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-4-19 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 1 (0x1)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableClock"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ksupmgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-19 136176]
R2 ksupmgr;File-/Update Service;c:\windows\SysWOW64\ksupmgr.exe [2010-08-25 765592]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-19 136176]
R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys [x]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [x]
R3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [x]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys [x]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x]
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 AntiVirMailService;Avira Email Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avmailc.exe [2011-12-22 342480]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-11 86224]
S2 AntiVirWebService;Avira Browser Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [2011-10-11 463824]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-01-24 901184]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-01-24 991296]
S2 DBService;DATA BECKER Update Service;c:\program files (x86)\Common Files\DATA BECKER Shared\DBService.exe [2010-05-28 2650112]
S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files (x86)\Kodak\AiO\Center\EKAiOHostService.exe [2011-12-19 394672]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-09-23 641832]
S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2010-11-30 1997416]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-04-19 993848]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-04-19 399416]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-08-20 689472]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-11-29 378472]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-20 2656280]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [x]
S3 AVer7231_x64;AVerMedia 7231 capture service;c:\windows\system32\DRIVERS\AVer7231_x64.sys [x]
S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-01-24 1298496]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [x]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [x]
S3 HPMo4DE3;Mouse Suite Driver_4DE3 (WDF Version);c:\windows\system32\DRIVERS\HPMo4DE3.sys [x]
S3 HPub4DE3;USB Mouse Low Filter Driver_4DE3 (WDF Version);c:\windows\system32\Drivers\HPub4DE3.sys [x]
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai        REG_MULTI_SZ          Akamai
.
Inhalt des "geplante Tasks" Ordners
.
2011-12-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025UA.job
- c:\users\Nico.dell-PC.000\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-10 19:23]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2010-12-14 6561384]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-12-11 2186856]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2010-11-29 312936]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-12 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-12 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-12 418328]
"FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-01-24 10355200]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-12-17 1933584]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-05-30 2055816]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-07-28 497648]
"EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe" [2011-06-16 2922496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Free YouTube to iPod Converter - c:\users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm
IE: Free YouTube to MP3 Converter - c:\users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: Interfaces\{F50EF1BC-60D3-4A72-B6ED-99F234833F2C}: NameServer = 62.109.123.7 213.191.92.86
FF - ProfilePath - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\3cers2zs.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - www.google.de
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_b427739.dll"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ce,9e,47,77,90,b8,f8,4f,8e,46,72,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ce,9e,47,77,90,b8,f8,4f,8e,46,72,\
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.123\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.csv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dbf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dot\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ThunderbirdEML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hwp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.log\UserChoice]
@Denied: (2) (Administrator)
"Progid"="txtfile"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarMathDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpdp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="NCH.MixPad.mpdp"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odb\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.DatabaseDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.MathDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.DrawDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.WriterDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.ImpressDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ods\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.CalcDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.WriterDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.otg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.DrawDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.oth\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.WriterDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.otp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.ImpressDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ott\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.WriterDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.oxt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="office.Extension.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pot\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pps\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rtf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.slk\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.stc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.std\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarDrawTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sti\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.stw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarDrawDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarMathDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.URL"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdseml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ThunderbirdEML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wk1\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wks\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="NCH.WavePad.wpp"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xls\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsb\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\SysWOW64\cchservice.exe
c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
c:\program files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-12-25  08:34:55 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2011-12-25 07:34
ComboFix2.txt  2011-12-21 07:36
.
Vor Suchlauf: 17 Verzeichnis(se), 115.714.088.960 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 115.401.179.136 Bytes frei
.
- - End Of File - - 4A5C54B28517F4A01C4D7079D2BCDCFE


Rheingold 25.12.2011 09:08

c:\users\Jasmina\AppData\Local\4d0d2e25 ist ein Ordner, darunter gibt es einen weiteren Ordner U und eine datei @
Der Unterordner U ist leer.

Bei Eigenschaften/Details:
Typ: Systemdatei
Größe: 2,00 KB
Änderungsdatum: 14.12.2011 08:38


Sonst keine Angaben.

Unter c:\users\Nico.dell-PC.000\AppData\Local\4d0d2e25 sind die Angbaen genauso, bis auf datum und uhrzeit.

Viele grüße
jasmina

kira 26.12.2011 14:15

lade Dir HijackThis 2.0.4 von *von hier* herunter
HijackThis starten→ "Do a system scan and save a logfile" klicken→ das erhaltene Logfile "markieren" → "kopieren"→ hier in deinem Thread (rechte Maustaste) "einfügen"

- Problem besteht immer noch?

Rheingold 26.12.2011 18:27

Hi Kira,
unten der hijackthis log.
Probleme sind:

Windows Defender funktioniert nicht
windows firewall kann nicht gestartet werden

Malwarebytes meldet weiterhin folgenden Fund:

Code:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 911122501

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

25.12.2011 13:45:20
mbam-log-2011-12-25 (13-45-05).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 492289
Laufzeit: 42 Minute(n), 4 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 1
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableConfig (Windows.Tool.Disabled) -> Bad: (1) Good: (0) -> No action taken.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)


Code:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:13:15, on 26.12.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Samsung\EmoDio\SMSTray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [SMSTray] C:\Program Files (x86)\Samsung\EmoDio\SMSTray.exe
O4 - HKLM\..\Run: [NBAgent] "C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKLM\..\Run: [ChicoSys] C:\Windows\SysWOW64\cc32\webtmr.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe"  -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Conime] %windir%\system32\conime.exe
O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe
O4 - HKLM\..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-21-3230886925-126132133-2629391164-1000\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [KodakHomeCenter] "C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [KodakHomeCenter] "C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe" (User 'Default user')
O4 - Global Startup: Secunia PSI Tray.lnk = Secunia\PSI\psi_tray.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Active File Monitor V9 (AdobeActiveFileMonitor9.0) - Adobe Systems Incorporated - C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Email Schutz (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira Planer (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Echtzeit Scanner (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Browser Schutz (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Device Monitor - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth Media Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
O23 - Service: Bluetooth OBEX Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DATA BECKER Update Service (DBService) - DATA BECKER GmbH & Co KG - C:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Kodak AiO Network Discovery Service - Eastman Kodak Company - C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe
O23 - Service: File-/Update Service (ksupmgr) - Salfeld Computer - C:\Windows\SysWOW64\ksupmgr.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Dell DataSafe Online (NOBU) - Dell, Inc. - C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: RoxMediaDB12OEM - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\sua.exe
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Druckwarteschlange (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel(R) Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13456 bytes


Rheingold 26.12.2011 18:31

Viele Grüße
Jasmina

kira 27.12.2011 05:43

Zitat:

Zitat von Rheingold (Beitrag 740918)
1. unter System und Sicherheit - Verwaltung - Dienste, gibt es Basisfiltermodul nicht.

gehe bitte auf (Rechtsklick) Eigenschaften-> "Abhängigkeiten"

Rheingold 27.12.2011 09:14

Zitat:

Zitat von kira (Beitrag 741896)
gehe bitte auf (Rechtsklick) Eigenschaften-> "Abhängigkeiten"

rechtsklick auf dienste, .... da gibt es bei mir keine "Abhängigkeiten" .... ? Was soll ich tun?
J.

Rheingold 27.12.2011 11:13

p.s. bin am 29ten wieder on. vielen dank bis hierher und grüße
jasmina

Rheingold 30.12.2011 11:32

Hallo Kira,
bei Eigenschaften von Dienste gibt es bei mir nur die Reiter: Allgemein, Verknüpfung, Sicherheit, Details, Vorgängerversion

Die Virusmeldung von Malware ist auch noch da.

Was kann ich tun?

Viele Grüße
Jasmina

kira 31.12.2011 08:31

Was die Malware bereits mit dem System angestellt bzw welche Spuren hinterlassen, kann man nicht wirklich einschätzen. Neuinstallation ist immer schnellste und einfachste meiner Meinung nach, da nie wieder nachvollziehbar ist, was der Schädling alles manipulliert hat:-> *klick* - Technische Kompromittierung
Ich denke, die einzige 100%ige Lösung ist: Festplatte formatieren und Windows neu installieren, nur so kannst Du sicher sein, dass dein Arbeitsspeicher virenfrei ist!

Rheingold 31.12.2011 14:42

Hallo Kira,
vielen Dank für die Antwort. Dann werde ich wohl oder übel als neu installieren müssen. :-( Danke dir sehr herzlich für deine Hilfe!
Alles Gute und viel Glück für´s neue Jahr!

Jasmina

kira 01.01.2012 10:47

1.
Datensicherung:
► NUR Daten sichern, die nicht ausführbaren Dateien enthalten - Dateiendungen - Dies ist eine Liste von Dateiendungen, die Dateien mit ausführbarem Code bezeichnen können.
- Vorsicht mit den schon vorhandenen Dateien auf die extern gespeicherten Daten und auch jetzt mit dem Virus infizierte Dateien eine Datensicherung anzufertigen
- Am besten alles was dir sehr wichtig, separat (extern) sichern - nicht mischen eventuell früher geschicherten Daten, also vor dem Befall!
- Eventuell gecrackte Software nicht sichern und dann auf neu aufgesetztem System wieder drauf installieren!

- Vor zurückspielen - bevor du mit deinem PC direkt ins Netz gehst...:
- die Autoplay-Funktion für alle Laufwerke deaktivieren/ausschalten -> Autorun/Autoplay gezielt für Laufwerkstypen oder -buchstaben abschalten

Die auf eine externe Festplatte gesicherten Daten, gründlich zu scannen von einem suaberen System aus, am besten mit mehreren Scannern-> Kostenlose Online Scanner - Anleitung

2.
-> Anleitung: Neuaufsetzen des Systems + Absicherung
-> Anleitung zum Neuaufsetzen - Windows XP, Vista und Win7

3.
Ich würde Dir vorsichtshalber raten, dein Passwort zu ändern
z.B. Login-, Mail- oder Website-Passwörter
Tipps:
Die sichere Passwort-Wahl - (sollte man eigentlich regelmäßigen Abständen ca. alle 3-5 Monate ändern)
auch noch hier unter: Sicheres Kennwort (Password)

alles Gute:)
kira

Rheingold 01.01.2012 15:07

Danke! Werde ich alles so machen!

:daumenhoc

Jasmina


Alle Zeitangaben in WEZ +1. Es ist jetzt 13:44 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131