Schritt 9 OLT.txt Code:
OTL logfile created on: 26.12.2011 16:07:26 - Run 4
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\UserXY\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: xxx| Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,93 Gb Total Physical Memory | 1,67 Gb Available Physical Memory | 42,41% Memory free
7,87 Gb Paging File | 4,97 Gb Available in Paging File | 63,16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 420,33 Gb Total Space | 198,09 Gb Free Space | 47,13% Space Free | Partition Type: NTFS
Drive D: | 30,48 Gb Total Space | 28,23 Gb Free Space | 92,62% Space Free | Partition Type: NTFS
Computer Name: UserXY-PC | User Name: UserXY | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.12.21 22:50:17 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\UserXY\Desktop\OTL.exe
PRC - [2011.12.15 14:59:48 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.12.15 14:59:38 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.12.15 14:59:37 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.12.07 12:16:29 | 001,047,096 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2011.11.10 10:17:04 | 003,514,176 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2011.08.31 17:00:48 | 000,449,608 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011.05.10 12:54:22 | 000,100,256 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
PRC - [2011.05.10 12:54:10 | 003,122,528 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
PRC - [2011.01.17 17:50:34 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2011.01.17 17:50:34 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2010.07.04 18:13:56 | 000,095,576 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
PRC - [2010.06.14 08:28:12 | 001,310,720 | ---- | M] () -- C:\Program Files (x86)\SPEEDLINK Ferret Gaming Mouse\GMouse.exe
PRC - [2010.03.03 21:16:06 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010.03.03 21:16:04 | 000,284,696 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
PRC - [2010.02.03 23:48:12 | 000,167,008 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
PRC - [2010.01.24 11:47:46 | 001,021,888 | ---- | M] (Lenovo) -- C:\Programme\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe
PRC - [2010.01.19 03:44:40 | 000,536,576 | ---- | M] (Vimicro) -- C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
PRC - [2009.11.04 22:45:46 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009.11.04 22:45:44 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2008.07.04 11:52:18 | 000,014,336 | ---- | M] (Vodafone) -- C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
========== Modules (No Company Name) ==========
MOD - [2011.12.07 12:16:28 | 000,411,192 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\16.0.912.63\ppgooglenaclpluginchrome.dll
MOD - [2011.12.07 12:16:27 | 003,767,864 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\16.0.912.63\pdf.dll
MOD - [2011.12.07 12:14:56 | 000,122,952 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\16.0.912.63\avutil-51.dll
MOD - [2011.12.07 12:14:55 | 000,222,280 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\16.0.912.63\avformat-53.dll
MOD - [2011.12.07 12:14:53 | 001,746,504 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\16.0.912.63\avcodec-53.dll
MOD - [2011.12.07 08:22:33 | 008,593,056 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\16.0.912.63\gcswf32.dll
MOD - [2011.10.13 01:00:04 | 000,452,608 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\3c8f9ba115087754b5b1d8394fc818ba\IAStorUtil.ni.dll
MOD - [2011.10.13 00:00:46 | 011,819,520 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\8e7909ef6b5f953d49244c6b9f5f5100\System.Web.ni.dll
MOD - [2011.10.13 00:00:35 | 000,771,584 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b2622080e047040fa044dd21a04ff10d\System.Runtime.Remoting.ni.dll
MOD - [2011.10.12 23:59:52 | 012,433,408 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll
MOD - [2011.10.12 23:59:43 | 001,587,200 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll
MOD - [2011.10.12 23:59:22 | 003,347,968 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d7a64c28cf0c90e6c48af4f7d6f9ed41\WindowsBase.ni.dll
MOD - [2011.10.12 23:59:12 | 005,453,312 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
MOD - [2011.10.12 23:59:06 | 000,971,264 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
MOD - [2011.10.12 23:59:04 | 007,963,648 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
MOD - [2011.10.12 23:58:54 | 011,490,304 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011.05.20 23:47:09 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
MOD - [2011.05.10 19:47:26 | 000,032,768 | ---- | M] () -- C:\windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll
MOD - [2011.05.10 12:54:22 | 000,100,256 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
MOD - [2011.05.10 12:54:10 | 000,492,896 | ---- | M] () -- C:\Program Files (x86)\Lenovo\VeriFace\ChooseLang.dll
MOD - [2010.11.13 01:08:41 | 000,315,392 | ---- | M] () -- C:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010.10.18 15:49:24 | 000,133,024 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\WindowsApiHookDll32.dll
MOD - [2010.10.18 15:46:22 | 000,161,696 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\ActiveDetect32.dll
MOD - [2010.06.14 08:28:12 | 001,310,720 | ---- | M] () -- C:\Program Files (x86)\SPEEDLINK Ferret Gaming Mouse\GMouse.exe
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011.08.12 00:38:04 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
SRV:64bit: - [2010.09.22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010.06.29 15:38:34 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009.12.30 07:27:00 | 000,069,568 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNotifier.exe -- (Slidebar Notifier Service)
SRV:64bit: - [2009.11.17 16:00:54 | 000,575,304 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe -- (Lenovo ReadyComm ConnSvc)
SRV:64bit: - [2009.08.14 15:22:48 | 000,509,192 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files\Lenovo\ReadyComm\AppSvc.exe -- (Lenovo ReadyComm AppSvc)
SRV - [2011.12.15 14:59:48 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.12.15 14:59:38 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.08.31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.03.03 21:16:06 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R)
SRV - [2010.01.12 17:15:24 | 000,873,248 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Programme\Lenovo\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2009.11.04 22:45:46 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2009.11.04 22:45:44 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2009.07.15 06:27:26 | 000,038,152 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe -- (IGRS)
SRV - [2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\windows\SysWow64\IgrsSvcs.exe -- (ReadyComm.DirectRouter)
SRV - [2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\windows\SysWow64\IgrsSvcs.exe -- (PS_MDP)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.07.04 11:52:18 | 000,014,336 | ---- | M] (Vodafone) [Auto | Running] -- C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
SRV - [2008.04.07 08:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011.12.15 15:00:00 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011.12.15 14:59:59 | 000,130,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011.12.15 14:59:59 | 000,097,312 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.11.21 16:31:15 | 000,279,616 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011.08.31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011.05.24 17:15:43 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2011.05.24 17:15:43 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2011.04.18 14:43:26 | 000,085,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV:64bit: - [2011.04.18 14:43:22 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 10:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010.06.29 16:09:58 | 007,195,648 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010.06.29 14:48:34 | 000,265,728 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010.06.14 08:32:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TFsExDisk.sys -- (TFsExDisk)
DRV:64bit: - [2010.06.02 07:35:42 | 000,229,456 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vm332avs.sys -- (vm332avs)
DRV:64bit: - [2010.05.24 13:07:58 | 000,253,728 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2010.05.11 18:06:18 | 000,246,224 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbnet.sys -- (ewusbnet)
DRV:64bit: - [2010.05.11 18:06:18 | 000,117,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV:64bit: - [2010.05.11 18:06:18 | 000,114,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbdev.sys -- (hwusbdev)
DRV:64bit: - [2010.05.03 12:19:40 | 000,317,488 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010.04.27 03:25:16 | 000,161,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV:64bit: - [2010.04.27 03:25:16 | 000,127,488 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM)
DRV:64bit: - [2010.04.27 03:25:16 | 000,018,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter)
DRV:64bit: - [2010.03.26 08:03:20 | 000,160,880 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR)
DRV:64bit: - [2010.03.03 20:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010.02.02 16:52:02 | 003,058,168 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2010.01.15 19:08:34 | 000,039,008 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LhdX64.sys -- (LHDmgr)
DRV:64bit: - [2010.01.15 01:51:20 | 000,021,288 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010.01.15 01:51:14 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2010.01.15 01:51:10 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2009.12.14 09:03:50 | 000,053,800 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btusbflt.sys -- (btusbflt)
DRV:64bit: - [2009.10.19 01:40:50 | 000,028,176 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV:64bit: - [2009.10.16 04:32:24 | 000,321,064 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink (TM)
DRV:64bit: - [2009.09.17 21:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
DRV:64bit: - [2009.07.21 15:20:06 | 000,121,840 | ---- | M] (CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd)
DRV:64bit: - [2009.07.16 18:31:24 | 001,383,680 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atinavrr.sys -- (ATIAVPCI)
DRV:64bit: - [2009.07.16 12:55:34 | 000,011,280 | ---- | M] (Lenovo) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDMirror.sys -- (wdmirror)
DRV:64bit: - [2009.07.16 04:38:20 | 000,079,376 | ---- | M] (Lenovo) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WDBridge.sys -- (Bridge0)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009.06.10 21:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel(R)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.04.07 07:33:08 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2008.08.06 13:32:16 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV:64bit: - [2007.09.17 14:53:34 | 000,029,184 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
DRV - [2011.07.22 17:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV - [2011.07.12 22:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV - [2010.06.14 08:32:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://www.einsatz.bundeswehr.de/portal/a/einsatzbw/kcxml/04_Sj9SPykssy0xPLMnMz0vM0Y_QjzKLN_SJdw0xB8lB2EGu-pFw0aCUVH1fj_zcVH1v_QD9gtyIckdHRUUAFEVdhA!!/delta/base64xml/L3dJdyEvd0ZNQUFzQUMvNElVRS82XzFMX0VTMQ!!"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpWinExt,version=5.0: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\msntoolbar@msn.com: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011.05.10 13:04:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011.05.10 13:04:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011.05.10 13:04:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\addon\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.10 18:28:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011.05.20 22:49:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\UserXY\AppData\Roaming\mozilla\Extensions
[2011.11.09 22:27:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\UserXY\AppData\Roaming\mozilla\Firefox\Profiles\0gjsybmo.default\extensions
[2011.11.09 22:27:45 | 000,000,000 | ---D | M] (PriceGong) -- C:\Users\UserXY\AppData\Roaming\mozilla\Firefox\Profiles\0gjsybmo.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
[2011.10.05 21:18:14 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\UserXY\AppData\Roaming\mozilla\Firefox\Profiles\0gjsybmo.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.12.21 19:34:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\UserXY\AppData\Roaming\mozilla\Firefox\Profiles\0gjsybmo.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2011.11.10 18:28:22 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011.05.21 16:44:53 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
File not found (No name found) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
File not found (No name found) -- C:\USERS\BJöRN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\0GJSYBMO.DEFAULT\EXTENSIONS\{A5475360-A7EA-437B-9A79-29208F476940}.XPI
File not found (No name found) -- C:\USERS\BJöRN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\0GJSYBMO.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}
[2011.11.10 18:28:16 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.10.02 10:08:48 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.10.02 10:08:48 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.10.02 10:08:48 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.02 10:08:48 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Bing Bar (Enabled) = C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: PriceGong = C:\Users\UserXY\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.5.0_0\
CHR - Extension: YouTube = C:\Users\UserXY\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google-Suche = C:\Users\UserXY\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Google Mail = C:\Users\UserXY\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\
O1 HOSTS File: ([2011.12.26 13:23:54 | 000,000,909 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4:64bit: - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4:64bit: - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..\Run: [OnekeyStudio] C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe (Lenovo)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SynBtnAsst] C:\Program Files\Synaptics\SynTP\SynBtnAsst.exe (Synaptics Incorporated)
O4 - HKLM..\Run: [332BigDog] C:\Program Files (x86)\USB Camera2\VM332_STI.EXE (Vimicro)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Ferret Gaming Mouse] C:\Program Files (x86)\SPEEDLINK Ferret Gaming Mouse\GMouse.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [Lenovo SlideNav2] C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlideNavVDM.exe (Lenovo)
O4 - HKLM..\Run: [Lenovo SplitScreen] C:\Program Files\Lenovo\Lenovo SplitScreen\SplitScreen\AutoRunSpS.exe (Lenovo)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MuteSync] C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe (Lenovo)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UCam_Menu] c:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
O4 - HKLM..\Run: [YouCam Mirror Tray icon] c:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe (CyberLink Corp.)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Users\UserXY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\UserXY\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8:64bit: - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\UserXY\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Senden an Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Senden an &Bluetooth-Gerät... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = xxx.xxx.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{31151D60-D04C-4C60-AC9C-5CE4955C99C4}: DhcpNameServer = xxx.xxx.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3BA91CBA-DC8C-43FF-9C36-49994A0F6F56}: NameServer = xxx.xxx.244.225 xxx.xxx.244.206
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{82CADA82-B818-4FE4-B28F-3CDA6D559DA7}: NameServer = xxx.xxx.244.225 xxx.xxx.244.206
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9B5605E6-C357-478E-9252-0BC3D7DF10CD}: NameServer = xxx.xxx.244.225 xxx.xxx.244.206
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E7276388-C15C-4634-B5AE-C23E6D14E15E}: NameServer = xxx.xxx.244.225 xxx.xxx.244.206
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F0EE1716-A8A0-4357-995A-AC2B02165EF4}: DhcpNameServer = xxx.xxx.178.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.12.26 13:41:42 | 001,918,464 | ---- | C] (AVAST Software) -- C:\Users\UserXY\Desktop\aswMBR.exe
[2011.12.26 12:24:35 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{E29D4E3E-A243-4215-866E-6CA66356AE6F}
[2011.12.26 12:24:25 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{EC35307F-EE00-4103-B7A7-B8B3E0B2267E}
[2011.12.26 12:24:15 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{D3BCCF37-9EFE-443D-B91E-83A239B11B21}
[2011.12.26 12:23:54 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{F653607B-7D90-441E-A442-0742E15454B3}
[2011.12.26 08:59:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2011.12.26 00:23:26 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{1B418F35-C0CE-4E40-A23F-73F79040B309}
[2011.12.26 00:23:05 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{CA3D505A-7682-4ADF-9AFC-0839445AFAD0}
[2011.12.25 20:20:55 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Roaming\Avira
[2011.12.25 20:15:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011.12.25 20:15:18 | 000,130,760 | ---- | C] (Avira GmbH) -- C:\windows\SysNative\drivers\avipbb.sys
[2011.12.25 20:15:18 | 000,097,312 | ---- | C] (Avira GmbH) -- C:\windows\SysNative\drivers\avgntflt.sys
[2011.12.25 20:15:18 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\windows\SysNative\drivers\avkmgr.sys
[2011.12.25 20:15:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011.12.25 20:15:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2011.12.25 13:29:58 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Roaming\SUPERAntiSpyware.com
[2011.12.25 13:29:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011.12.25 13:29:17 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011.12.25 13:29:17 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011.12.25 12:32:53 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.12.25 12:22:11 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{0AFDD35E-755A-46AF-967F-3152575906D0}
[2011.12.25 12:21:55 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{505C299C-AE15-4640-9D7C-F3724E1FA8D5}
[2011.12.24 18:12:48 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{8E0AB30B-C568-4F79-82DF-4932D0881A54}
[2011.12.24 03:06:02 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{45BBB487-1CB5-488D-9BB5-271B846C8DC7}
[2011.12.23 19:46:18 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.12.23 13:05:00 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Roaming\Malwarebytes
[2011.12.23 13:04:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.12.23 13:04:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.12.23 13:04:35 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2011.12.23 13:04:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.12.23 11:17:21 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{F0F9E42B-D95B-4E4B-BA4E-4987735B32FE}
[2011.12.22 21:17:52 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{E761172F-4A41-4248-9381-30A816C3EDCF}
[2011.12.22 21:17:40 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{DE4A941F-C868-4DD6-B85A-FD7280DF3FB2}
[2011.12.22 07:10:43 | 000,000,000 | -HSD | C] -- C:\windows\SysNative\%APPDATA%
[2011.12.21 22:54:24 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\UserXY\Desktop\OTL.exe
[2011.12.21 22:47:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clean Virus MSN
[2011.12.21 22:47:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AxBx
[2011.12.21 20:28:24 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{23820886-A6F5-4B53-B0E6-A283BF248B94}
[2011.12.21 20:28:06 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{58F3DF79-C147-4721-BA61-623A52F6F513}
[2011.12.21 19:01:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011.12.21 19:01:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2011.12.21 07:28:41 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{CEB77FAC-EE8E-4437-A963-E3BEF9002E86}
[2011.12.21 07:28:20 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{CBB24A00-D4F9-445E-8071-7C0091E08119}
[2011.12.21 06:34:20 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{5E8DB4A2-19F5-4F3F-BE7F-ECAA46A6BBA3}
[2011.12.20 18:33:51 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{EC66862A-2DF5-490F-9508-5AEEAC431E21}
[2011.12.20 18:33:31 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{697BB127-4524-4453-AB01-275367CA3951}
[2011.12.20 18:33:08 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{41B42598-67BF-4517-919A-73358311B963}
[2011.12.20 06:32:22 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{54C49EB5-0534-4A39-8050-23E75C07E051}
[2011.12.20 06:32:11 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{D7CA888B-E28B-4AE2-BFFF-C6B5A8416F25}
[2011.12.20 06:31:30 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{1D5BE593-FF20-4559-A367-F955538BA7A1}
[2011.12.19 18:31:04 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{C0BB5707-38ED-4C52-84CE-51748F9F25D0}
[2011.12.19 18:30:43 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{4C406F28-C620-407D-9319-A689B740C5E4}
[2011.12.19 18:30:32 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{F7817153-F764-4A96-A721-6FADCBEF8169}
[2011.12.19 06:29:20 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{B2131290-3AE3-4142-AFF5-A43F71CC52D9}
[2011.12.19 06:27:38 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{8F9453BA-8A62-41C1-B88F-81AF254418E7}
[2011.12.18 11:45:44 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{93ABE7DE-35BF-4EF7-9E20-FC1940FB9B24}
[2011.12.18 11:45:32 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{3F5C1D84-500F-44DC-AEF1-7B5C26B74827}
[2011.12.18 11:45:12 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{E2CA1C26-4E1A-4E5C-A7CD-352365EC5145}
[2011.12.18 11:44:51 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{807A31A5-76AB-4F78-A333-3367D7D5021D}
[2011.12.17 23:45:18 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{305DA6BA-C871-4E75-B63C-1E2A22683FBB}
[2011.12.17 23:44:57 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{6A554F19-A490-463C-8C20-9D0048D39F3D}
[2011.12.17 11:17:22 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{05A9C5E3-EE3E-4B4A-94F7-4E2DB2F6FA69}
[2011.12.17 11:16:58 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{19DB6FA2-1699-4B0E-A56F-C16BFB239EE5}
[2011.12.17 11:15:19 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{21F762EB-F5F2-4C88-89A4-C15C6FAEC545}
[2011.12.16 12:02:04 | 000,000,000 | ---D | C] -- C:\34dbc5b24e8377ada30ef2a4a1
[2011.12.16 11:59:10 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mshtmled.dll
[2011.12.16 11:59:10 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mshtmled.dll
[2011.12.16 11:59:07 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\url.dll
[2011.12.16 11:59:07 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\url.dll
[2011.12.16 11:59:05 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieui.dll
[2011.12.16 11:59:05 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieui.dll
[2011.12.16 11:59:02 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\inetcpl.cpl
[2011.12.16 11:59:01 | 002,309,120 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript9.dll
[2011.12.16 11:59:01 | 001,493,504 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\inetcpl.cpl
[2011.12.16 11:59:00 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\jscript.dll
[2011.12.16 11:58:59 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript.dll
[2011.12.16 06:25:03 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{5C13D8F7-4F45-4244-8D1B-6C077F0F89C0}
[2011.12.15 23:10:48 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\csrsrv.dll
[2011.12.15 23:10:44 | 000,723,456 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\EncDec.dll
[2011.12.15 23:10:43 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\EncDec.dll
[2011.12.15 17:42:29 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{970AA118-FC0B-445B-B464-AA5B2EB42BE3}
[2011.12.13 22:39:00 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{EE0B5AD9-33D6-4130-8B1F-AF190BC67732}
[2011.12.13 22:38:49 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{88D8C8BC-FD1B-40F1-A81C-B1FFFF200EC0}
[2011.12.13 22:38:07 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{CACFBB0E-87C6-49F1-82EE-577645099B4A}
[2011.12.13 10:37:50 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{6AF9EC01-09AD-4412-BBD5-2FDE8EE7A028}
[2011.12.13 10:37:30 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{31722CC3-4C73-4AA1-9526-B2FD1BF9EA92}
[2011.12.13 10:37:09 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{97474F36-0DE5-445D-A7D7-436AC47745B0}
[2011.12.12 22:36:22 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{0E593BE1-CABE-4429-B207-BD944441BA1D}
[2011.12.12 22:36:11 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{113B489D-6A9A-4359-A5D5-5646D07099FC}
[2011.12.12 22:35:51 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{13D31F98-0CD1-44C2-8772-E43EA81B99E8}
[2011.12.12 10:35:04 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{5AABA16F-A2EB-41E0-91D3-EA69DA35EFEA}
[2011.12.12 10:34:26 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{74A83997-9CE3-40B2-9881-B5DB808D96F2}
[2011.12.11 23:38:48 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{74BD2357-8232-4C8B-BF0E-D9D48C282298}
[2011.12.11 08:25:18 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{BAB85B9E-8E61-4C8E-B696-ECF926D35427}
[2011.12.10 20:24:53 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{C3BFF58D-9D89-4A9B-9EF4-8BC52C042533}
[2011.12.10 20:24:37 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{6E5FD438-4B12-4F5C-A6A5-A4D0806AF4E4}
[2011.12.10 20:13:43 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{F810C697-14B5-47B4-8DA2-FBFE26159E90}
[2011.12.10 11:23:39 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{F9D64CC6-D057-47BF-B634-6E25D361A12C}
[2011.12.10 11:19:50 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{305BBCB9-598F-4A3C-987D-4CA19205AF39}
[2011.12.09 06:19:18 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{0FC2882B-FDFA-4F75-8EAE-FD08C2B0308D}
[2011.12.08 18:18:26 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{491EFE69-1C81-4800-BFEA-7ACC72E6FD37}
[2011.12.08 06:17:17 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{8F1098C5-6BC3-4702-8F42-576FB6F5D929}
[2011.12.07 18:16:52 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{0EA8698C-DD91-46A2-B961-1122783E121E}
[2011.12.07 18:16:12 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{E07A583F-30F9-4590-B9A4-BB647CE512C6}
[2011.12.07 06:39:12 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\PokerStars
[2011.12.07 06:38:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerStars
[2011.12.07 06:38:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PokerStars
[2011.12.07 06:15:45 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{9EE2AD73-4899-4594-83C2-660A46C4B24D}
[2011.12.07 06:13:43 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\PokerStars.NET
[2011.12.07 06:13:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PokerStars.NET
[2011.12.06 18:19:08 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{2AC2E61A-8864-47AA-8987-827074C124EE}
[2011.12.06 18:18:56 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{C7D362AE-8706-49B8-8EB0-10C772C88EFA}
[2011.12.06 18:18:15 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{85ECF006-D851-402E-BF00-1F3C36543F66}
[2011.12.06 06:17:59 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{865A431B-ED15-48E2-A596-3B2FE317CC99}
[2011.12.06 06:17:39 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{2676B89B-4E29-4343-99A6-3C72B7146D28}
[2011.12.06 06:17:04 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{CBA9598D-A0A6-4114-B8F3-2EC895C38E8C}
[2011.12.05 18:16:34 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{DD852F19-28B5-4A75-B1EF-46CCC9528C33}
[2011.12.05 18:15:41 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{B93CD67A-A7A9-4593-BDBE-0FE89665D5FB}
[2011.12.05 18:15:20 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{C44382B1-CE69-4830-8F75-E329B19210FE}
[2011.12.05 06:18:34 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{C18C5B99-81F6-41D3-8524-7098AA903B05}
[2011.12.05 06:15:04 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{60521F1E-8875-4202-BB39-5E396956AAC5}
[2011.12.04 13:18:50 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{F847F304-0115-4DA5-AAEB-3D4FE2A5B8F0}
[2011.12.04 13:18:40 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{93A035A6-6C33-44C6-951D-CA21195C8711}
[2011.12.04 13:18:29 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{2A62B45E-C20C-4BC8-ADAE-14C86F08AF86}
[2011.12.04 13:18:17 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{6DC57428-F417-41E7-97CA-8FCEE0C9FBDC}
[2011.12.03 15:21:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011.12.03 15:19:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011.12.03 11:12:29 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{40814D1B-AF76-4E88-88C4-652B229BAD67}
[2011.12.03 11:11:22 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{287CAAE8-EFA7-4D6F-8843-90934BE26E14}
[2011.12.03 11:07:52 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{F7CCBB42-0054-4ADE-B2E5-BC88BF3EED72}
[2011.12.02 17:39:14 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{D3CEB3C2-486C-4DB2-A6B2-6AD4E951536B}
[2011.12.02 17:38:58 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{51BA23A8-0542-4EEB-AA67-A16114A18E1D}
[2011.12.02 12:14:52 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{4A9787D1-8646-45AF-A34D-676526BB1CEE}
[2011.12.02 06:41:05 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{4793DBCB-66A8-4FB0-B07B-D9580B955078}
[2011.12.01 18:40:39 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{073684C9-669F-441E-91CF-9C6F0EC160E2}
[2011.12.01 18:40:19 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{560D7B62-CB23-498B-A449-5E312FA063A9}
[2011.12.01 18:39:57 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{551C8537-084C-4940-A72C-4D5E793A477A}
[2011.12.01 18:39:36 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{058CCC41-4A4E-43D8-8A40-246C18BE1B46}
[2011.12.01 06:38:57 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{E1D6E61E-19D7-4160-98D7-B363AC86FE24}
[2011.12.01 06:38:46 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{9A608524-F609-4FC9-B009-D3D08B635FCD}
[2011.12.01 06:38:05 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{4CAE9F50-BF07-4177-BFFD-0B14A7AF6C4E}
[2011.11.30 18:37:40 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{4EB76B30-BA11-4D00-91DD-111950A7362F}
[2011.11.30 18:37:26 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{32C1EABC-BD75-4CFF-81B7-B35E34032172}
[2011.11.30 18:37:05 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{098F093B-D328-4C6F-A24A-B070339875C5}
[2011.11.30 06:36:27 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{06EB71A9-9AD0-43F0-BFCE-8556CD5BD646}
[2011.11.30 06:35:01 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{510135DB-2FA0-4D2D-A9A9-E2D59D5CF3FA}
[2011.11.29 17:26:29 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{4A364C7A-B7D8-4BDD-902D-8EC4095948D6}
[2011.11.29 05:41:45 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{AA088DCA-72AC-4DD5-879A-BB2B11845959}
[2011.11.29 05:28:19 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{3CEBDD1D-3563-494F-870F-0A375A3474FC}
[2011.11.28 12:07:05 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{73FE2BCA-E1B0-4CF7-B065-0382560973DE}
[2011.11.28 12:06:44 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{E3BE7BB0-FA64-4891-8668-B5EE519D4575}
[2011.11.28 12:06:23 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{3FC2D951-AD94-49C1-87F3-6F183F38C1D1}
[2011.11.28 12:06:02 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{9F121627-F028-4593-A91B-D2B582616B4E}
[2011.11.28 00:05:05 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{A82A9321-AB02-4633-85FB-6AFEC96C0A1F}
[2011.11.28 00:04:07 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{05D885C5-39C2-4071-BC4C-34D9C985F235}
[2011.11.27 23:06:37 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{3B2832DD-C063-462B-B08A-91059C8115EE}
[2011.11.27 10:02:58 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{2F3C11DA-A800-421F-B788-200D352AA354}
[2011.11.27 10:02:33 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{6206C6DE-F5D9-4330-9371-98052D88A512}
[2011.11.27 10:02:22 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{650C1E02-7A27-4702-8D68-1E73BE44673A}
[2011.11.27 10:02:11 | 000,000,000 | ---D | C] -- C:\Users\UserXY\AppData\Local\{401740B1-B4D1-4089-83F8-82DA06FF7FFE}
========== Files - Modified Within 30 Days ==========
[2011.12.26 16:11:01 | 000,001,108 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.12.26 16:01:49 | 000,000,512 | ---- | M] () -- C:\Users\UserXY\Desktop\MBR.dat
[2011.12.26 15:20:14 | 000,013,424 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.12.26 15:20:14 | 000,013,424 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.12.26 15:11:46 | 000,001,104 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.12.26 15:11:21 | 000,067,584 | ---- | M] () -- C:\windows\bootstat.dat
[2011.12.26 15:11:19 | 639,425,588 | ---- | M] () -- C:\windows\MEMORY.DMP
[2011.12.26 15:11:12 | 3168,190,464 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.26 13:44:19 | 001,498,742 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2011.12.26 13:44:19 | 000,654,400 | ---- | M] () -- C:\windows\SysNative\perfh007.dat
[2011.12.26 13:44:19 | 000,616,242 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2011.12.26 13:44:19 | 000,130,240 | ---- | M] () -- C:\windows\SysNative\perfc007.dat
[2011.12.26 13:44:19 | 000,106,622 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2011.12.26 13:41:54 | 001,918,464 | ---- | M] (AVAST Software) -- C:\Users\UserXY\Desktop\aswMBR.exe
[2011.12.26 13:23:54 | 000,000,909 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts
[2011.12.26 09:00:44 | 000,001,974 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011.12.25 20:15:31 | 000,001,954 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2011.12.25 13:29:22 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.12.24 11:18:43 | 000,112,028 | ---- | M] () -- C:\Users\UserXY\cc_20111224_111832.reg
[2011.12.21 22:50:17 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\UserXY\Desktop\OTL.exe
[2011.12.21 22:47:53 | 000,001,056 | ---- | M] () -- C:\Users\UserXY\Desktop\Clean Virus MSN.lnk
[2011.12.17 11:13:35 | 000,453,560 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2011.12.15 15:00:00 | 000,027,760 | ---- | M] (Avira GmbH) -- C:\windows\SysNative\drivers\avkmgr.sys
[2011.12.15 14:59:59 | 000,130,760 | ---- | M] (Avira GmbH) -- C:\windows\SysNative\drivers\avipbb.sys
[2011.12.15 14:59:59 | 000,097,312 | ---- | M] (Avira GmbH) -- C:\windows\SysNative\drivers\avgntflt.sys
[2011.12.07 06:38:57 | 000,001,025 | ---- | M] () -- C:\Users\Public\Desktop\PokerStars.lnk
[2011.12.01 06:46:02 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\config.nt
[2011.11.28 19:01:14 | 000,256,960 | ---- | M] (AVAST Software) -- C:\windows\SysNative\aswBoot.exe
[2011.11.28 16:04:22 | 000,012,956 | ---- | M] () -- C:\Users\UserXY\Bilder\Documents\X.odt
========== Files Created - No Company Name ==========
[2011.12.26 16:01:49 | 000,000,512 | ---- | C] () -- C:\Users\UserXY\Desktop\MBR.dat
[2011.12.26 14:29:28 | 639,425,588 | ---- | C] () -- C:\windows\MEMORY.DMP
[2011.12.26 08:59:44 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2011.12.26 08:59:44 | 000,001,974 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011.12.25 20:15:31 | 000,001,954 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2011.12.25 13:29:22 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.12.24 11:18:38 | 000,112,028 | ---- | C] () -- C:\Users\UserXY\cc_20111224_111832.reg
[2011.12.21 22:47:53 | 000,001,056 | ---- | C] () -- C:\Users\UserXY\Desktop\Clean Virus MSN.lnk
[2011.12.07 06:38:57 | 000,001,025 | ---- | C] () -- C:\Users\Public\Desktop\PokerStars.lnk
[2011.12.02 20:15:27 | 000,012,800 | ---- | C] () -- C:\Users\UserXY\Bilder\Documents\X.odt
[2011.11.28 16:03:33 | 000,012,956 | ---- | C] () -- C:\Users\UserXY\Bilder\Documents\X.odt
[2011.10.06 19:30:32 | 000,004,608 | ---- | C] () -- C:\Users\UserXY\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.07.02 19:42:26 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011.07.01 08:06:48 | 001,526,948 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2011.05.21 16:46:00 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.05.21 09:33:59 | 000,000,088 | ---- | C] () -- C:\ProgramData\profile.xml
[2011.05.10 13:09:25 | 000,016,648 | R--- | C] () -- C:\windows\SysWow64\LogAPI.dll
[2011.05.10 12:54:12 | 002,110,816 | ---- | C] () -- C:\windows\SysWow64\Apblend.dll
[2011.05.10 12:54:12 | 001,171,456 | ---- | C] () -- C:\windows\SysWow64\PicNotify.dll
[2011.05.10 12:54:05 | 001,044,480 | ---- | C] () -- C:\windows\SysWow64\3DImageRenderer.dll
[2011.05.10 12:36:01 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2010.08.09 09:28:09 | 000,002,857 | ---- | C] () -- C:\windows\SysWow64\atipblag.dat
[2010.07.06 02:54:55 | 000,001,341 | ---- | C] () -- C:\windows\vm332Rmv.ini
[2009.07.14 06:38:36 | 000,067,584 | ---- | C] () -- C:\windows\bootstat.dat
[2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\windows\SysWow64\NOISE.DAT
[2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\windows\SysWow64\dssec.dat
[2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:59:36 | 000,982,196 | ---- | C] () -- C:\windows\SysWow64\igkrng500.bin
[2009.07.13 22:59:36 | 000,139,824 | ---- | C] () -- C:\windows\SysWow64\igfcg500.bin
[2009.07.13 22:59:36 | 000,097,448 | ---- | C] () -- C:\windows\SysWow64\igfcg500m.bin
[2009.07.13 22:59:35 | 000,417,344 | ---- | C] () -- C:\windows\SysWow64\igcompkrng500.bin
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\windows\SysWow64\msjetoledb40.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\windows\SysWow64\mlang.dat
[2008.10.07 08:13:30 | 000,197,912 | ---- | C] () -- C:\windows\SysWow64\physxcudart_20.dll
[2008.10.07 08:13:22 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelSwedish.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelSpanish.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelPortugese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelKorean.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelJapanese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelGerman.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelFrench.dll
[2008.06.23 12:02:02 | 000,097,410 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2008.05.23 16:48:50 | 000,020,270 | ---- | C] () -- C:\ProgramData\DeviceInstaller.xml
[2007.10.25 16:26:10 | 000,005,632 | ---- | C] () -- C:\windows\SysWow64\drivers\StarOpen.sys
========== LOP Check ==========
[2011.05.21 09:37:40 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\ArcSyncConfig
[2011.12.23 20:54:06 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\Azureus
[2011.12.23 20:54:07 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\DAEMON Tools Lite
[2011.10.05 21:18:21 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\DVDVideoSoft
[2011.10.05 21:18:13 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.12.18 19:07:40 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\ICQ
[2011.05.20 22:18:26 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\Lenovo
[2011.05.22 08:22:59 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\OpenOffice.org
[2011.09.09 21:00:44 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\PC Suite
[2011.09.09 20:58:06 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\Samsung
[2011.08.12 09:40:39 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\SoftGrid Client
[2011.07.01 08:07:51 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\TP
[2011.10.24 16:38:38 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\Ubisoft
[2011.05.21 15:51:39 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\Verbindungsassistent
[2011.10.04 15:08:49 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\Vodafone
[2011.05.24 11:33:01 | 000,000,000 | ---D | M] -- C:\Users\UserXY\AppData\Roaming\Windows Live Writer
[2011.11.14 05:59:01 | 000,032,640 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report > komischerweise wurde keine Extra.txt ausgeworfen |