Code:
OTL logfile created on: 19.03.2012 20:56:19 - Run 3
OTL by OldTimer - Version 3.2.39.1 Folder = C:\Users\Lea\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
7,86 Gb Total Physical Memory | 6,03 Gb Available Physical Memory | 76,80% Memory free
15,71 Gb Paging File | 13,80 Gb Available in Paging File | 87,86% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 911,40 Gb Total Space | 775,45 Gb Free Space | 85,08% Space Free | Partition Type: NTFS
Drive D: | 6,51 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive E: | 5,12 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive F: | 7,45 Gb Total Space | 7,41 Gb Free Space | 99,38% Space Free | Partition Type: FAT32
Computer Name: LEA-PC | User Name: Lea | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Lea\Desktop\OTL(1).exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.0.13\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\NTI\Packard Bell MyBackup\IScheduleSvc.exe (NTI Corporation)
PRC - C:\Program Files (x86)\NTI\Packard Bell MyBackup\BackupManagerTray.exe (NTI Corporation)
PRC - C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe (CyberLink)
PRC - c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\SPEEDLINK Ferret Gaming Mouse\GMouse.exe ()
PRC - C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\c6b914d595e5b00ae540004a71c6c3a2\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\42ae8760f0a74ab774e82a64368aa1f6\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a1c4a635721f85bef0ea4194b888b871\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6c51e152e7404188914c9fa4d8503ff9\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ab87129c2b603f218e4aa5300c9b1bdd\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\47b9e7f070271ff50f988f75ea68fa3e\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\ebfad289d9759034cd3a887802fadb5b\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files (x86)\NTI\Packard Bell MyBackup\sqlite3.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Program Files (x86)\SPEEDLINK Ferret Gaming Mouse\GMouse.exe ()
========== Win32 Services (SafeList) ==========
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (NIS) -- C:\Program Files (x86)\Norton Internet Security\Engine\18.7.0.13\ccSvcHst.exe (Symantec Corporation)
SRV - (DsiWMIService) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (BBSvc) -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (ePowerSvc) -- C:\Programme\Packard Bell\Packard Bell Power Management\ePowerSvc.exe (Acer Incorporated)
SRV - (NTI IScheduleSvc) -- C:\Program Files (x86)\NTI\Packard Bell MyBackup\IScheduleSvc.exe (NTI Corporation)
SRV - (Live Updater Service) -- C:\Programme\Packard Bell\Packard Bell Updater\UpdaterService.exe (Acer Incorporated)
SRV - (UNS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (TurboBoost) Intel(R) -- C:\Programme\Intel\TurboBoost\TurboBoost.exe (Intel(R) Corporation)
SRV - (AdobeActiveFileMonitor9.0) -- c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (IAStorDataMgrSvc) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (NOBU) -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (NAUpdate) @C:\Program Files (x86) -- C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (GREGService) -- C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymNetS) -- C:\Windows\SysNative\drivers\NISx64\1207000.00D\symnets.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\NISx64\1207000.00D\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\Windows\SysNative\drivers\NISx64\1207000.00D\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (SymEFA) -- C:\Windows\SysNative\drivers\NISx64\1207000.00D\symefa64.sys (Symantec Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (nvpciflt) -- C:\Windows\SysNative\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV:64bit: - (SymDS) -- C:\Windows\SysNative\drivers\NISx64\1207000.00D\symds64.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) -- C:\Windows\SysNative\drivers\NISx64\1207000.00D\ironx64.sys (Symantec Corporation)
DRV:64bit: - (b57xdmp) -- C:\Windows\SysNative\drivers\b57xdmp.sys (Broadcom Corporation)
DRV:64bit: - (b57xdbd) -- C:\Windows\SysNative\drivers\b57xdbd.sys (Broadcom Corporation)
DRV:64bit: - (bScsiMSa) -- C:\Windows\SysNative\drivers\bScsiMSa.sys (Broadcom Corporation)
DRV:64bit: - (k57nd60a) Broadcom NetLink (TM) -- C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (bScsiSDa) -- C:\Windows\SysNative\drivers\bScsiSDa.sys (Broadcom Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (MEIx64) Intel(R) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel(R) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV:64bit: - (TurboB) -- C:\Windows\SysNative\drivers\TurboB.sys (Intel(R) Corporation)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (NTIDrvr) -- C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) -- C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (mcdbus) -- C:\Windows\SysNative\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (BHDrvx64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110909.001\BHDrvx64.sys (Symantec Corporation)
DRV - (IDSVia64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20110917.031\IDSviA64.sys (Symantec Corporation)
DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110916.035\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110916.035\ENG64.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (mcdbus) -- C:\Windows\SysWOW64\drivers\mcdbus.sys (MagicISO, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://packardbell.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://packardbell.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
IE - HKLM\..\URLSearchHook: {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851647
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.facemoods.com/?a=ddrnw
IE - HKCU\..\URLSearchHook: {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851647
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..CommunityToolbar.SearchFromAddressBarSavedUrl: "data:text/plain,keyword.URL=hxxp://de.search.yahoo.com/search?ei=UTF-8&fr=ffbr&type=moz35awe&p="
FF - prefs.js..browser.search.defaultenginename: "Facemoods Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://start.facemoods.com/?a=ddrnw"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2011.09.28 11:03:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_6_3 [2012.03.19 20:54:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.07.24 14:46:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.02.09 20:11:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.02.07 21:12:12 | 000,000,000 | ---D | M]
[2011.07.18 20:55:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lea\AppData\Roaming\mozilla\Extensions
[2012.01.05 15:48:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lea\AppData\Roaming\mozilla\Firefox\Profiles\fhvw2doa.default\extensions
[2012.02.09 20:11:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.07.18 20:55:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\distribution\extensions
[2011.07.18 20:55:18 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Program Files (x86)\mozilla firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
() (No name found) -- C:\USERS\LEA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FHVW2DOA.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012.02.09 20:11:09 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.07.20 14:21:29 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.02.09 20:11:08 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.02.09 20:11:08 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.02.09 20:11:08 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.07.20 14:27:30 | 000,002,048 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml
[2012.02.09 20:11:08 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.09 20:11:08 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.09 20:11:08 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.0.13\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.0.13\IPS\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (uTorrentBar_DE Toolbar) - {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngin.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.0.13\coIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (uTorrentBar_DE Toolbar) - {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.0.13\coIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Power Management] C:\Programme\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NTI\Packard Bell MyBackup\BackupManagerTray.exe (NTI Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Ferret Gaming Mouse] C:\Program Files (x86)\SPEEDLINK Ferret Gaming Mouse\GMouse.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O4 - Startup: C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{65023810-DEDD-4065-A70E-1FE60B3C479D}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011.11.10 14:42:24 | 000,000,046 | R--- | M] () - E:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2009.12.14 11:00:22 | 000,008,192 | ---- | M] (Microsoft) - F:\AutoOff.exe -- [ FAT32 ]
O32 - AutoRun File - [2010.12.14 10:33:52 | 000,000,078 | ---- | M] () - F:\Autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{278630c5-b3ab-11e0-a849-b870f4861692}\Shell - "" = AutoRun
O33 - MountPoints2\{278630c5-b3ab-11e0-a849-b870f4861692}\Shell\AutoRun\command - "" = E:\install.exe -- [2011.06.10 22:14:22 | 000,378,880 | R--- | M] (Install.exe)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012.03.20 03:37:58 | 000,000,000 | ---D | C] -- C:\FRST
[2012.03.19 20:55:26 | 000,594,432 | ---- | C] (OldTimer Tools) -- C:\Users\Lea\Desktop\OTL(1).exe
[2012.03.19 20:55:00 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{71BEB546-4130-4833-998F-0B7E5954DD1D}
[2012.03.19 20:54:48 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{DCA09650-3C3A-4D0A-9B58-A84315387240}
[2012.03.19 20:38:46 | 002,063,920 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Lea\Desktop\tdsskiller(1).exe
[2012.03.19 20:29:11 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Lea\Desktop\aswMBR.exe
[2012.03.19 20:20:29 | 000,389,024 | ---- | C] (Bleeping Computer, LLC) -- C:\Users\Lea\Desktop\unhide.exe
[2012.03.19 18:42:43 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{06C0432F-F5F3-41C1-882E-F3466DAE00A8}
[2012.03.19 18:42:32 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{AF6B6B93-E97E-45DD-8DFE-9DFDB5789F09}
[2012.03.19 18:32:24 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{477F7260-A106-4DC8-AC0B-7B209AE748B8}
[2012.03.19 18:32:12 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{AABD9BEB-A1B0-4166-8866-DDF7AEB53343}
[2012.03.19 18:23:27 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{4E88DAEB-55ED-4EE0-B0D4-907D64C80F59}
[2012.03.19 18:23:16 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{832F1311-F1BA-48E1-B30F-3CCD060007B1}
[2012.03.19 18:17:41 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{5542C9FF-F611-4C63-8A38-3B6AB1A91BCD}
[2012.03.19 18:17:29 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{2080EC75-976D-48B7-8B96-55A31B7EECA8}
[2012.03.19 18:08:29 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{78040E98-4C41-4368-8E55-758E50B3C00C}
[2012.03.19 18:08:17 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{7848C0F4-BB40-46D8-B293-10A872AB2C9B}
[2012.03.19 17:50:42 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{C7FD4375-AE6B-46E5-81E2-6039AA01B75F}
[2012.03.19 17:50:28 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{10D27E3F-ECE2-4BC0-9024-507DCB6C0875}
[2012.03.19 17:30:56 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{6B56C7D1-30C9-4469-9C71-2B8C49DAF423}
[2012.03.19 17:30:42 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{A58AFB06-95A6-4E7F-A1FA-96D780B1FAEC}
[2012.03.19 17:23:11 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{1859682A-51EE-46BD-AAB1-1653780D5652}
[2012.03.19 17:22:57 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{7CDD7ED7-526E-4EF7-8C3D-9014089F383B}
[2012.03.19 16:22:34 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{330C3EF7-76FC-45A0-9C13-11439BF3174C}
[2012.03.19 16:22:21 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{816FAAE6-039B-466A-9FA5-1CD7411DB7B6}
[2012.03.19 14:34:11 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{014DD10C-0D9E-4371-936C-76401B9CAA1C}
[2012.03.19 14:33:58 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{17FE1AB5-210B-4D76-8C4C-7A076964B097}
[2012.03.19 14:24:12 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{86460572-8B3A-497B-B4C3-7F567E982276}
[2012.03.19 14:23:35 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{E248EBED-739D-4875-A137-116A90876F75}
[2012.03.19 12:23:49 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{53AD8566-1AA5-4663-8908-8C472E817064}
[2012.03.19 12:23:35 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{4F57E392-959E-4750-9A03-A9FE359A5E41}
[2012.03.19 02:41:20 | 000,000,000 | ---D | C] -- C:\Neuer Ordner (2)
[2012.03.19 02:41:19 | 000,000,000 | ---D | C] -- C:\Neuer Ordner
[2012.03.19 02:10:43 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{4EA300B2-9406-44D4-A7EF-0070F9C7C4CB}
[2012.03.19 02:10:31 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{8FB78F87-749C-4F93-BAA5-B644E5741492}
[2012.03.19 02:02:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.03.19 02:01:59 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.03.19 02:01:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.03.19 01:52:02 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Avira
[2012.03.19 01:49:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.03.19 01:49:38 | 000,132,320 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2012.03.19 01:49:38 | 000,097,312 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2012.03.19 01:49:38 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2012.03.19 01:49:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012.03.19 01:49:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2012.03.19 01:32:46 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Malwarebytes
[2012.03.19 01:32:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.03.19 01:25:31 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{BE4BC338-C026-4BB2-A05F-47DB016B7B93}
[2012.03.19 01:25:19 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{8C6BB0A7-DEFC-44A1-828F-11CF99CFF65E}
[2012.03.19 01:19:38 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check
[2012.03.18 22:33:06 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{E1A2BED8-48BD-4744-88E2-A011CFE42E62}
[2012.03.18 22:32:52 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{21D99CC1-B24C-4CCD-B1F9-803CE776D123}
[2012.03.18 13:48:26 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{F6E115A6-AA23-4E6A-8F4D-557A67532FCC}
[2012.03.18 13:48:13 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{AE4F4D14-C097-4753-9F1B-EE98A64A499B}
[2012.03.17 19:33:01 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{5BD111F5-4E3D-4AFD-8B17-44C7DF452298}
[2012.03.17 19:32:48 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{99EFBF6B-E7E2-497A-AE30-45E480921F69}
[2012.03.17 12:23:55 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{9D414FD8-3E75-4514-901B-6C631BEBBFEF}
[2012.03.17 12:23:42 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{E1EAE61E-8BDD-4FBE-A720-9FD892658E15}
[2012.03.16 21:20:34 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{E987027C-55B3-4CC6-9AAF-EE1C0B9CBEA5}
[2012.03.16 21:20:18 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{643F111E-FDFB-4799-A5DD-9D12861A05E6}
[2012.03.16 21:07:57 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{7C2847D6-016A-4024-8782-6735EAD6CDCC}
[2012.03.16 21:05:28 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{E4B89732-6817-4EE1-A90C-3D99A8E02F93}
[2012.03.16 21:04:40 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{F32DF5FC-2E23-4102-8D6D-2C0EF2375C11}
[2012.03.16 21:04:26 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{E76C9EF2-8006-4082-8594-A2AE4750C999}
[2012.03.16 20:48:04 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{0A39B67B-CD08-4D14-9A12-8A724AACC5A0}
[2012.03.16 20:47:49 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{9FB13EF5-3030-4686-8BA2-2004E4A93D4B}
[2012.03.16 20:30:28 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{23620E95-063D-45C9-8451-D5211B8F9BC1}
[2012.03.16 20:30:14 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{427CC69C-44A9-4A5F-9140-B7C01BF0AAE0}
[2012.03.16 18:43:31 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{CEF26974-0EFE-4493-ADD4-65FF927019A9}
[2012.03.16 18:43:20 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{551BAB31-8968-4E72-93C8-FF3468B725B5}
[2012.03.16 17:57:17 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{9236C72E-6E97-4CFA-B717-DD7186F76362}
[2012.03.16 17:57:05 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{F19F7252-9324-4586-93E6-077A48E1B73D}
[2012.03.16 00:46:21 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{7F308FD9-6C8C-45B6-B6EE-F4A430781BA2}
[2012.03.16 00:46:07 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{15CD0FB4-240E-4141-AFD3-2D0C7DC6212B}
[2012.03.15 20:07:39 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{825C0FB3-C91E-4F61-A27B-2B615CD3E620}
[2012.03.15 20:07:28 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{0B24B31C-C9FC-467F-B883-12E96A8EF29A}
[2012.03.15 16:23:14 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{FD916566-FD75-4DCD-AE63-65557A3511D2}
[2012.03.15 16:23:01 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{2633AAE3-6C7E-435E-AD4D-67B2DD66C840}
[2012.03.15 15:44:56 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{AFAC969B-9E4F-466D-8A0C-5C5D6DBD1F48}
[2012.03.15 15:44:43 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{4B83E4F9-73AD-48F5-8700-9C1EB609A53F}
[2012.03.15 15:12:28 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{F61E9C19-5E35-4DB9-8CD8-46A02659FB4D}
[2012.03.15 15:12:14 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{8BEA7919-B677-4DD9-81F4-100DD80106FF}
[2012.03.14 19:59:32 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{1D04FEE3-9660-4C4D-AB43-7FA74A4C8C7E}
[2012.03.14 19:59:19 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{8E886416-CFC9-4B39-9188-86BF247715BC}
[2012.03.14 15:18:54 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{0C3967A5-DA5F-42E2-92B7-A36EE7D0F7E3}
[2012.03.14 15:18:43 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{32758D63-5F82-40A1-8A99-0F1BF9B34B2B}
[2012.03.14 14:48:24 | 005,559,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012.03.14 14:48:23 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012.03.14 14:48:23 | 003,913,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012.03.14 14:07:09 | 001,544,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2012.03.14 14:02:58 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{CF099611-8B9E-4D67-8C22-785E74051C8D}
[2012.03.14 14:02:46 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{4717C2C8-1EB0-46FB-AFD8-B68784F49783}
[2012.03.13 22:31:07 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{265034A7-5661-49CC-9A39-6131186BA0FF}
[2012.03.13 22:30:55 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{170E0A4F-6481-44D0-8C37-A0B310B30BD8}
[2012.03.13 18:07:25 | 001,031,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcore.dll
[2012.03.13 18:07:25 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpcore.dll
[2012.03.13 18:07:17 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
[2012.03.13 18:07:17 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
[2012.03.13 18:07:17 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe
[2012.03.13 18:01:17 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{843FA585-DD5F-4BCD-A8DB-8A379F653665}
[2012.03.13 18:01:05 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{FAFD9960-AE44-4A15-95F9-8B8779080667}
[2012.03.13 13:51:48 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{24AD76DF-7266-4306-8DB1-F0B8CEF19D18}
[2012.03.13 13:51:35 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{40A48BDB-5954-42A3-977D-3AC2FC3D5907}
[2012.03.12 22:10:16 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{30266B32-4CA8-41F1-BF04-AB2CFAC8A3D4}
[2012.03.12 22:10:04 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{504B5AF5-D926-4963-A2CA-849CE8E3361A}
[2012.03.12 22:06:21 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{75A05EAE-2589-48E3-A5CD-7C8349A5E15B}
[2012.03.12 22:06:07 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{CC4153B2-7DC9-48CF-86F6-86D4F3EE2A7D}
[2012.03.12 20:13:16 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{AB73D5B5-2A8B-4C72-BC9E-76D3BBCC7017}
[2012.03.12 20:13:05 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{6EAD1187-33A8-40C6-8784-452F8C69B915}
[2012.03.12 16:05:26 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{0A005CA2-0A5E-46F8-B238-B449E8ED1548}
[2012.03.12 16:05:15 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{ADC702E6-D0C1-4BE2-8B64-FA6F1317CB0B}
[2012.03.12 13:24:36 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{5A5EDCAE-A7B5-44C6-BA26-5D47CF0ECD33}
[2012.03.12 13:24:22 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{BEE9F3B5-30FF-4851-9ABD-116A3748821F}
[2012.03.12 00:03:21 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{843800FF-698E-45C6-A3F9-4040E10CDC98}
[2012.03.12 00:03:07 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{A3F7034D-07EC-4845-804C-F5ABCC9F5680}
[2012.03.11 23:47:47 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{12B98AA6-6671-4DA5-9F2B-08FE13A8AA18}
[2012.03.11 22:57:45 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{3C889727-7724-4570-9EA6-559D1A4DF569}
[2012.03.11 22:57:32 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{B0E62CC2-DB3C-4750-84B1-A6D45A8BD009}
[2012.03.11 20:48:23 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{F8169643-08C6-4952-B028-114E5F8F7FB7}
[2012.03.11 20:48:10 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{6B13DBC0-83B6-4ECA-934A-D482026E55FF}
[2012.03.10 19:22:41 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
[2012.03.10 19:22:40 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
[2012.03.10 18:19:50 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{7608E7E7-8E26-4903-B57D-FCF122703206}
[2012.03.10 18:19:37 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{CB97B69C-6016-41D2-8BC3-9116A0B6F787}
[2012.03.10 15:11:42 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{93DBFF92-FF7C-4609-B705-3D7D40CEF327}
[2012.03.10 15:11:31 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{CFC16E4C-DA89-43AE-8BB8-4A1E9D4A4155}
[2012.03.09 22:50:59 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{39FC71BD-DF40-4E44-A57D-C52ADC245970}
[2012.03.09 22:50:40 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{FAA07C67-0905-4465-A505-597C1219792A}
[2012.03.09 22:11:41 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{996AB37C-6EC7-44CB-B3E5-32FAF309820A}
[2012.03.09 22:11:24 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{8BF9EB1E-00A9-4E43-A689-6F59EBE1E53F}
[2012.03.08 19:03:36 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{51C28BAF-36E2-4CBE-B38C-10C104187175}
[2012.03.08 19:03:23 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{E8A3364D-8F8B-4EDF-8FF0-9C7D7AF1724A}
[2012.03.08 14:11:05 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{C9A46BD9-4DAE-4491-86A8-47849D07365C}
[2012.03.08 14:10:52 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{F99C6E12-A8E2-40F1-B9AB-91C487D75C5D}
[2012.03.08 01:52:28 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{658FE045-B28A-4468-82C0-6A11DBC6A46B}
[2012.03.08 01:52:14 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{80293F6C-C9F9-444C-9B6A-A3DBFA0FFDC3}
[2012.03.07 20:58:56 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{C04747E4-3F9E-47A1-867F-5530BC4BFC3B}
[2012.03.07 20:58:44 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{9E7435C1-CC80-498E-97EA-138E6F6BECC5}
[2012.03.07 15:13:37 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{8C0B67A6-8387-429C-9A75-8670546523EE}
[2012.03.07 15:13:23 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{F633A35D-0FEF-44D2-B836-514FD04788D4}
[2012.03.07 12:42:56 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{1BE3C620-0E43-48D7-BC9C-FD1237395CDD}
[2012.03.07 12:42:45 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{65531FE1-5D6A-4A68-96EC-B1892087B8AE}
[2012.03.06 23:17:30 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{F8002216-DAB8-485B-ADAA-12084154A807}
[2012.03.06 23:17:16 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{7DCFF7CC-08EA-4B2B-998F-02EA368F6AEA}
[2012.03.06 21:27:29 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{F99A0A53-68F7-44AF-A723-C3C7BA2F3839}
[2012.03.06 21:27:16 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{1F4D2DDC-C045-4E23-B593-2EFCD678F383}
[2012.03.06 17:58:28 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{FB40629C-67A1-4672-9114-1C01B3BF6FD7}
[2012.03.06 17:58:14 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{B15AD594-7C5D-473F-AAEC-4B8A5A0AFB41}
[2012.03.06 16:10:37 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{53E868E2-04A1-4FFE-8496-F90C74C6D4E3}
[2012.03.06 16:10:24 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{5C3C5AA1-17B2-400C-A2BB-8520385D5E0E}
[2012.03.06 14:26:00 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{54F06A61-4024-4B76-8A1C-EAD5AFB6A5E5}
[2012.03.06 14:25:48 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{139871A6-0FD7-4B5C-8F8D-570042554C50}
[2012.03.05 23:55:22 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{6712AC3B-78E7-4AF1-8B1A-C4E7CAF2D7C5}
[2012.03.05 23:55:08 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{4D85FD5F-020A-4739-9FDC-88F097FF62A2}
[2012.03.05 18:29:58 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{6EE6EC6F-98F3-421E-99A3-D67751F6078B}
[2012.03.05 18:29:45 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{56A6EB2E-5C74-4348-BD7F-2F16B385B115}
[2012.03.04 23:39:45 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{2216CE00-34DC-4AD7-A555-53F2FB80B383}
[2012.03.04 23:39:31 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{09F38D8E-3C08-492D-86AA-D84BDFD704C4}
[2012.03.04 17:19:33 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{F5157283-D0DB-456D-A64B-E77C1761AE5A}
[2012.03.04 17:19:20 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{21212B48-5891-4BA9-A4EE-67A74B045BE3}
[2012.03.03 19:08:54 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{74FA76E8-D859-4133-90C3-A99BACFB88A3}
[2012.03.03 19:08:41 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{C4EB48EE-292B-4ADB-B9BA-CA78E94FFAFD}
[2012.03.03 16:17:53 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{77F33E26-4381-4876-8C8A-4C099C5ECA0A}
[2012.03.03 16:17:40 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{AFD21380-5D38-49CC-96F9-B39E696F2A57}
[2012.03.03 14:09:10 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{4F48DBA0-DBB0-423F-BE59-7A3C754CA99F}
[2012.03.03 14:08:57 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{17D40953-4808-4266-895A-630028F820A5}
[2012.03.02 17:17:38 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{EE4AB413-7DED-4F6D-8BAF-89BD47C533BC}
[2012.03.02 17:17:26 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{6E867DD8-B570-4A0C-8D7D-741C0E60A940}
[2012.03.02 16:50:10 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{EE05E3A6-11CC-4529-9892-5B3873AFAFC1}
[2012.03.02 16:49:56 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{3F6BDFBC-48BD-42D7-9AC5-F0178268BD2D}
[2012.03.02 15:02:20 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{9EBF598E-7AB2-496B-83D7-F2BB39252273}
[2012.03.02 15:02:07 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{DFD8BA30-314A-4577-8DA7-3917907C883F}
[2012.03.02 13:06:39 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{13C89C40-9DB6-4648-A45B-0E85D0BA6835}
[2012.03.02 13:06:28 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{66F907BA-F7CD-4EED-B207-FB184800342C}
[2012.03.02 00:02:25 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{0E34A7C5-2272-4853-81F6-8D6A1ED76421}
[2012.03.02 00:02:11 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{81EB8D46-92EB-4C5D-BD8E-5699ACC3B469}
[2012.03.01 20:14:57 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{268BF1C8-A857-445E-9D70-77D84EB20A2A}
[2012.03.01 20:14:44 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{E09CAC75-283B-414D-8C33-81C056E2A82F}
[2012.03.01 19:58:53 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{364A9C61-D6D1-4040-BD2C-2F1229235780}
[2012.03.01 19:58:39 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{94023D83-0C89-4E52-9093-9FC220DDF0FF}
[2012.03.01 15:35:41 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{3C1CF477-CB9A-48B8-BF7F-0C68CF6C16A2}
[2012.03.01 15:35:28 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{5B162CBA-1837-4DCF-B1EE-F33B2027D0DA}
[2012.03.01 13:29:40 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{2E90B5A3-F3A2-4063-B80F-3E1B740B3D58}
[2012.03.01 13:29:28 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{071CD7FF-9C6D-4030-BF87-E550F5F453C3}
[2012.02.29 17:18:12 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{5B6A15D2-6A38-4B41-8052-5094E6830905}
[2012.02.29 17:18:00 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{40BF68D9-5BCA-40F2-A7E3-6C3D3651EF96}
[2012.02.29 17:17:26 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{EE523F07-541A-40D5-9BD3-193A46BE9071}
[2012.02.29 17:17:14 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{5CB3953B-B1F2-49DB-852D-A832831363D1}
[2012.02.29 15:22:57 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{BE4E4F2C-DAB2-4642-A700-6F44F75470A5}
[2012.02.29 15:22:44 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{8BF2E8B1-621C-4099-B2F6-3CBED4A4AB18}
[2012.02.29 13:08:12 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{8FD23658-82A4-48BA-9E60-8E2566AB5666}
[2012.02.29 13:08:00 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{850E8323-0A9E-4221-B23C-40AA5EA312AE}
[2012.02.28 21:26:09 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{3CEF0A26-56BF-4B13-9137-A2335FEDB32E}
[2012.02.28 21:25:56 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{AB59F6B6-62A6-49B8-83BC-50B541BFC4EC}
[2012.02.28 15:30:21 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{D8350C1E-9EA8-437D-9E87-F2544C905CCD}
[2012.02.28 15:30:09 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{5BFB4C24-D7BB-4E80-9F7C-32B7828D1432}
[2012.02.28 14:36:04 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{E9348CD0-EF09-4C12-956F-54B07F8C8F9F}
[2012.02.28 14:35:53 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{B1A4B181-6927-42C9-B40B-05EF772F1A43}
[2012.02.27 22:57:16 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{7873B8EA-47DF-4786-AFC1-20821C78D341}
[2012.02.27 22:57:05 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{D66A5760-36EE-43D3-96AC-CDE0CA0561BB}
[2012.02.27 20:14:16 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{4174466A-F8D9-4D8D-AFE6-996D3F8DA493}
[2012.02.27 20:14:05 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{DAA48DD8-370E-4D93-B391-03E638C7B17D}
[2012.02.27 15:43:57 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{2F4495BF-5D5C-4BB2-B6AA-FBCAC6503F60}
[2012.02.27 15:43:45 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{94F827B3-CA16-4D57-BEFD-4EC252571A14}
[2012.02.27 13:29:27 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{A663D04B-8F40-450E-9652-9E814C14F67D}
[2012.02.27 13:29:16 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{77C91A1B-BF19-44A8-8E1E-D4D76BA8731D}
[2012.02.26 16:59:00 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{801A500A-6BDB-460D-8FD5-8C3D3A2FF0AF}
[2012.02.26 16:58:48 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{41F95E9B-CEC8-49E8-B34D-F251E4F11732}
[2012.02.25 23:13:54 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{4815F7DD-D308-45EB-84BF-C58E5FCBF26D}
[2012.02.25 23:13:41 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{D6F5BBD1-922B-4C84-8AAE-2FDC86124774}
[2012.02.25 17:10:17 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{B5E0545B-E679-496E-9B8C-2EDD557FB8B7}
[2012.02.25 17:10:04 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{4A6F5646-9BE7-46B6-A5CD-A6265CCBF8D7}
[2012.02.25 14:09:36 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{169FAE4D-DE8C-4785-9F9D-0085FD526652}
[2012.02.25 14:09:23 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{98FFBBCB-1602-4002-AFC3-ADD144407699}
[2012.02.24 16:03:11 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{3ACCA056-6F82-4034-9F47-2BF915C87743}
[2012.02.24 16:02:58 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{7205E594-6563-47B3-8928-23C4A254382F}
[2012.02.24 14:56:33 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{E93766CB-1D59-488F-A9FC-22E10B8588AF}
[2012.02.24 14:45:35 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{490BCE40-833A-4668-8D3A-33F5232A21F3}
[2012.02.24 14:45:23 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{75AEF534-9024-4196-8E47-EB96C2B81D48}
[2012.02.24 00:16:44 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{8081B0D9-C6BE-42BE-A1D3-D9A9AE8A507D}
[2012.02.24 00:16:30 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{78C2E430-A41E-421F-961B-49DDE8AA2324}
[2012.02.23 13:05:34 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{94EDE067-96D7-4D3D-944B-A4354C5A42DD}
[2012.02.23 13:05:22 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{0DBE7988-3777-4F2C-A320-869D981B542C}
[2012.02.23 00:45:54 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{1C0D3B05-8AFC-4D5E-9DF6-A52A1D423FAC}
[2012.02.23 00:45:40 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{9AB7030A-6FEB-4DA6-9F59-208F24C577F0}
[2012.02.22 20:13:16 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{85B1CDCE-6E01-403D-97A7-FDE4FFC33725}
[2012.02.22 20:13:02 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{741DA8EA-BA7B-45E6-8F02-0396FCEFE2CF}
[2012.02.22 17:43:30 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{77B01DDE-EF07-4FD5-9BAE-96441216F195}
[2012.02.22 17:43:16 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{226D7D9C-C7C3-41EE-9867-922B8ABCFCBE}
[2012.02.22 16:46:01 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{F1E9FDBC-940D-47B1-98E9-7A5BF7E96D63}
[2012.02.22 16:45:47 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{6EA230C0-0AEA-41B0-9403-71A2321F1268}
[2012.02.21 21:42:52 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{C15366B7-54A8-4401-9CCB-160633B3A6E8}
[2012.02.21 21:42:38 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{09A5852D-64A5-43E9-A250-C20EE88C41A0}
[2012.02.21 20:14:58 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{E40D1795-9548-4342-81E0-0E09F752C45B}
[2012.02.21 20:14:45 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{8F603694-3185-40E2-A7B2-B19BACDBA2F5}
[2012.02.21 20:10:04 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{45A8B452-1029-4FE9-B628-E0988D9CC126}
[2012.02.21 20:09:49 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{4B71E742-F4B9-4FB9-8C4A-699737231F3E}
[2012.02.21 15:21:01 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{655F2CB1-1B89-481D-9716-D6FB63D627C2}
[2012.02.21 15:20:49 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{7B963675-1F34-4067-A7F7-3C08366CA57B}
[2012.02.21 13:47:38 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{9F2837C0-24F8-4ADA-9AA5-43B8C4E747CD}
[2012.02.21 13:47:25 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{745B1C02-775A-418E-854D-03B5B86F3C66}
[2012.02.20 16:42:16 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{5136A57A-DBDA-4248-B682-11275CFD58BC}
[2012.02.20 16:42:03 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{106BDB83-E526-42EF-ABD0-E8C6AF7B0ED9}
[2012.02.20 13:58:50 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{0A2A9689-B835-46CB-B27A-ECED0E6549C8}
[2012.02.20 13:58:36 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{E781CE25-A03D-4A9D-A09A-61F7972D4102}
[2012.02.20 02:47:52 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{735ABC2F-0E4F-4E7D-86ED-32F61C44CD70}
[2012.02.20 02:47:39 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{57549B07-F7AD-4A7B-89AC-559BA9BBFC18}
[2012.02.19 23:04:20 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{A036C1D2-728F-486F-91F3-A2A0383AA085}
[2012.02.19 23:04:09 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{301F0442-C208-49EC-8E54-3F35A6CCE3FB}
[2012.02.19 15:32:11 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{DE74C7BF-4A09-4CFD-9F3D-4786CCA2D2C6}
[2012.02.19 15:31:58 | 000,000,000 | ---D | C] -- C:\Users\Lea\AppData\Local\{DF46B3DD-8235-4A59-B893-1A4A42431FEB}
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.03.19 21:00:00 | 000,000,414 | ---- | M] () -- C:\Windows\tasks\Packard Bell Registration - Reminder Recall task.job
[2012.03.19 20:55:32 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Users\Lea\Desktop\OTL(1).exe
[2012.03.19 20:53:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.03.19 20:53:40 | 692,997,991 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.03.19 20:53:39 | 2030,981,119 | -HS- | M] () -- C:\hiberfil.sys
[2012.03.19 20:39:08 | 002,063,920 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Lea\Desktop\tdsskiller(1).exe
[2012.03.19 20:36:38 | 000,000,512 | ---- | M] () -- C:\Users\Lea\Desktop\MBR.dat
[2012.03.19 20:30:41 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Lea\Desktop\aswMBR.exe
[2012.03.19 20:20:38 | 000,389,024 | ---- | M] (Bleeping Computer, LLC) -- C:\Users\Lea\Desktop\unhide.exe
[2012.03.19 18:50:09 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.03.19 18:50:09 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.19 18:00:49 | 000,000,017 | ---- | M] () -- C:\Windows\SysWow64\shortcut_ex.dat
[2012.03.19 17:37:22 | 001,556,122 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.03.19 17:37:22 | 000,679,194 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.03.19 17:37:22 | 000,629,314 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.03.19 17:37:22 | 000,140,116 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.03.19 17:37:22 | 000,114,848 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.03.19 14:26:26 | 001,385,843 | ---- | M] () -- C:\Users\Lea\Desktop\FRST64.exe
[2012.03.19 12:24:03 | 000,013,854 | ---- | M] () -- C:\Users\Lea\Desktop\firefox.exe - Verknüpfung.lnk
[2012.03.19 02:02:01 | 000,001,125 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.03.19 01:49:45 | 000,002,082 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.03.19 01:21:21 | 000,000,456 | ---- | M] () -- C:\ProgramData\mv6gbLFrjRSkXy
[2012.03.19 01:19:39 | 000,000,665 | ---- | M] () -- C:\Users\Lea\Desktop\System Check.lnk
[2012.03.19 01:19:39 | 000,000,264 | ---- | M] () -- C:\ProgramData\~mv6gbLFrjRSkXy
[2012.03.19 01:19:39 | 000,000,176 | ---- | M] () -- C:\ProgramData\~mv6gbLFrjRSkXyr
[2012.03.19 01:05:54 | 000,021,239 | ---- | M] () -- C:\Users\Lea\Desktop\hkjh.jpg
[2012.03.18 18:54:19 | 000,023,013 | ---- | M] () -- C:\Users\Lea\Documents\Hausarbeit.odt
[2012.03.17 20:45:10 | 000,013,223 | ---- | M] () -- C:\Users\Lea\Documents\kuchen.odt
[2012.03.14 15:17:55 | 000,315,456 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.03.02 17:52:04 | 000,000,031 | ---- | M] () -- C:\Windows\progress
[2012.02.22 17:10:22 | 001,023,346 | ---- | M] () -- C:\Users\Lea\Documents\bafög3.pdf
[2012.02.22 17:03:46 | 001,117,471 | ---- | M] () -- C:\Users\Lea\Documents\bafög2.pdf
[2012.02.22 17:02:07 | 001,321,898 | ---- | M] () -- C:\Users\Lea\Documents\bafög.pdf
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.03.19 20:36:38 | 000,000,512 | ---- | C] () -- C:\Users\Lea\Desktop\MBR.dat
[2012.03.19 20:25:18 | 000,001,300 | ---- | C] () -- C:\Users\Public\Desktop\Paint.NET.lnk
[2012.03.19 20:25:18 | 000,001,124 | ---- | C] () -- C:\Users\Public\Desktop\OpenOffice.org 3.3.lnk
[2012.03.19 20:25:18 | 000,001,082 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012.03.19 20:25:18 | 000,000,959 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012.03.19 20:25:17 | 000,002,501 | ---- | C] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk
[2012.03.19 20:25:17 | 000,002,498 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2012.03.19 20:25:17 | 000,002,194 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Welcome Center.lnk
[2012.03.19 20:25:17 | 000,002,031 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012.03.19 20:25:17 | 000,001,547 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2012.03.19 20:25:17 | 000,001,460 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2012.03.19 20:25:17 | 000,001,376 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2012.03.19 20:25:17 | 000,001,352 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
[2012.03.19 20:25:17 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012.03.19 20:25:17 | 000,001,307 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2012.03.19 20:25:17 | 000,001,246 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[2012.03.19 20:25:17 | 000,001,210 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[2012.03.19 20:25:17 | 000,001,150 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.03.19 20:25:17 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Deus EX Human Revolution.lnk
[2012.03.19 20:25:15 | 000,001,330 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2012.03.19 20:25:14 | 000,001,312 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk
[2012.03.19 20:25:13 | 000,001,162 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.03.19 20:25:12 | 000,002,435 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk
[2012.03.19 20:25:12 | 000,001,982 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012.03.19 20:25:12 | 000,001,961 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk
[2012.03.19 20:25:12 | 000,001,940 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012.03.19 20:25:12 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012.03.19 20:25:09 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012.03.19 20:25:09 | 000,002,279 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Elements 9.lnk
[2012.03.19 20:25:09 | 000,001,949 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Contact a friend for assistance.lnk
[2012.03.19 20:25:09 | 000,001,892 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Elements 9.lnk
[2012.03.19 20:25:09 | 000,001,531 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.lnk
[2012.03.19 20:25:09 | 000,001,009 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2012.03.19 18:00:49 | 000,000,017 | ---- | C] () -- C:\Windows\SysWow64\shortcut_ex.dat
[2012.03.19 14:26:08 | 001,385,843 | ---- | C] () -- C:\Users\Lea\Desktop\FRST64.exe
[2012.03.19 12:24:03 | 000,013,854 | ---- | C] () -- C:\Users\Lea\Desktop\firefox.exe - Verknüpfung.lnk
[2012.03.19 02:02:01 | 000,001,125 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.03.19 01:49:45 | 000,002,082 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.03.19 01:19:39 | 000,000,665 | ---- | C] () -- C:\Users\Lea\Desktop\System Check.lnk
[2012.03.19 01:19:39 | 000,000,264 | ---- | C] () -- C:\ProgramData\~mv6gbLFrjRSkXy
[2012.03.19 01:19:39 | 000,000,176 | ---- | C] () -- C:\ProgramData\~mv6gbLFrjRSkXyr
[2012.03.19 01:19:35 | 000,000,456 | ---- | C] () -- C:\ProgramData\mv6gbLFrjRSkXy
[2012.03.19 01:05:53 | 000,021,239 | ---- | C] () -- C:\Users\Lea\Desktop\hkjh.jpg
[2012.03.17 20:45:08 | 000,013,223 | ---- | C] () -- C:\Users\Lea\Documents\kuchen.odt
[2012.03.14 18:05:06 | 000,023,013 | ---- | C] () -- C:\Users\Lea\Documents\Hausarbeit.odt
[2012.03.02 17:51:53 | 000,000,031 | ---- | C] () -- C:\Windows\progress
[2012.02.22 17:10:22 | 001,023,346 | ---- | C] () -- C:\Users\Lea\Documents\bafög3.pdf
[2012.02.22 17:03:46 | 001,117,471 | ---- | C] () -- C:\Users\Lea\Documents\bafög2.pdf
[2012.02.22 17:02:07 | 001,321,898 | ---- | C] () -- C:\Users\Lea\Documents\bafög.pdf
[2011.08.10 18:27:15 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll
[2011.08.05 12:33:23 | 001,583,740 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.07.18 20:55:26 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.04.15 10:15:00 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.04.15 10:14:58 | 000,216,876 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.04.15 10:14:57 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
< End of report > |