introplastic | 14.08.2012 20:54 | danke für die schnelle antwort! das problem ist, auch im abgesicherten modus kommt die gvu seite, sodass ich nicht auf den desktop zugreifen kann...
so, habe nun mit otlpenet eine cd erstellt und damit einen scan laufen lassen. allerdings ohne den oben von dir angegebenen inhalt in die textbox zu kopieren. soll ich noch einen scan damit durchführen?
hier die otl.txt: Code:
OTL logfile created on: 8/15/2012 7:20:52 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Windows Vista (TM) Home Premium Service Pack 2 (Version = 6.0.6002) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 89.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 296.62 Gb Total Space | 138.99 Gb Free Space | 46.86% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand] -- -- (SPTISRV)
SRV - File not found [On_Demand] -- -- (MSCSPTISRV)
SRV - File not found [Auto] -- -- (0268391304585483mcinstcleanup)
SRV - [2012/01/20 07:42:40 | 000,329,168 | ---- | M] () [Auto] -- C:\Program Files\Verbindungsassistent\WTGService.exe -- (WTGService)
SRV - [2011/08/03 16:43:45 | 000,645,048 | ---- | M] (Cisco Systems, Inc.) [Auto] -- C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent)
SRV - [2011/06/06 06:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/04/20 04:50:46 | 000,792,976 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Sony\VAIO Update 5\VUAgent.exe -- (VUAgent)
SRV - [2011/03/09 08:30:08 | 000,092,592 | ---- | M] (TomTom) [Disabled] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2009/09/08 12:09:14 | 000,083,312 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe -- (VcmXmlIfHelper)
SRV - [2009/04/01 18:15:30 | 000,114,688 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2008/03/03 08:45:48 | 000,333,088 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr)
SRV - [2008/01/20 22:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/08/14 15:05:18 | 000,182,392 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service)
SRV - [2007/05/31 04:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 04:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (VMnetAdapter)
DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand] -- -- (IpInIp)
DRV - File not found [Kernel | On_Demand] -- -- (igfx)
DRV - File not found [Kernel | On_Demand] -- -- (catchme)
DRV - File not found [File_System | System] -- -- (AFSRedirector)
DRV - File not found [File_System | On_Demand] -- -- (AFSLibrary)
DRV - [2012/07/10 15:07:43 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2012/01/20 07:39:33 | 000,103,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewusbfake.sys -- (hwusbfake)
DRV - [2012/01/20 07:39:33 | 000,100,224 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewsercd.sys -- (ewsercd)
DRV - [2011/08/03 16:27:28 | 000,019,192 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vpnva.sys -- (vpnva)
DRV - [2011/07/29 07:54:56 | 000,014,216 | ---- | M] () [Kernel | On_Demand] -- C:\Windows\System32\epmntdrv.sys -- (epmntdrv)
DRV - [2011/07/29 07:54:56 | 000,008,456 | ---- | M] () [Kernel | On_Demand] -- C:\Windows\System32\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2009/04/11 01:06:26 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WSDScan.sys -- (WSDScan)
DRV - [2009/04/11 00:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
DRV - [2008/12/13 06:27:50 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008/02/22 20:38:50 | 000,164,400 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2008/02/11 20:49:44 | 007,626,400 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008/02/05 20:06:19 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2008/01/20 22:23:21 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2008/01/20 22:23:21 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\loop.sys -- (msloop)
DRV - [2007/12/16 21:57:23 | 000,009,344 | ---- | M] (Sony Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\SFEP.sys -- (SFEP)
DRV - [2007/12/14 00:03:35 | 000,758,784 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2007/12/13 12:40:06 | 000,010,216 | ---- | M] (Sony Corporation) [Kernel | System] -- C:\Windows\System32\drivers\DMICall.sys -- (DMICall)
DRV - [2007/09/18 23:29:09 | 002,222,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Intel(R)
DRV - [2007/06/05 20:00:39 | 000,812,544 | ---- | M] (Texas Instruments) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ti21sony.sys -- (ti21sony)
DRV - [2007/05/26 04:03:06 | 000,128,104 | ---- | M] (Microsoft Corporation) [File_System | On_Demand] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr)
DRV - [2004/02/04 02:19:32 | 000,024,177 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2004/02/04 02:19:16 | 000,057,372 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.club-vaio.com/vbc
IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\Jonas_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Jonas_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/08/07 18:09:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/05/28 11:06:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/05/28 11:06:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/11/18 08:12:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions
[2010/07/05 16:00:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/07/29 11:55:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\home2@tomtom.com
[2010/11/18 08:12:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\uploadr@flickr.com
[2012/08/13 06:31:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions
[2010/07/07 17:45:38 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/29 15:52:00 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011/02/11 17:16:51 | 000,000,000 | ---D | M] ("Biet-O-Matic Firefox Erweiterung") -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{B0D70E72-2FC1-4b9f-A3D4-5921C854D906}
[2012/07/28 01:39:41 | 000,000,000 | ---D | M] (Flash and Video Download) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
[2012/08/08 18:16:15 | 000,000,000 | ---D | M] (Foxdie (Graphite)) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\FoxdieGraphite@tanjihay.com
[2012/03/20 11:26:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\CSSEDITOR@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\EYEDROPPER@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\FS@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\FULLSCREEN@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\GFD@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-CS@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-DE@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-EN-US@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ES-ES@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-FI@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-FR@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-HE@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-HU@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-IT@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-JA@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-KO@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-NL@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-PL@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SL@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SR@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SV-SE@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ZH-CN@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ZH-TW@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\MATHML@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\SNIPPETS@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\SVG-EDIT@GOOGLEGROUPS.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TABLELAYOUT@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TEMPLATESMANAGER@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\THUMBNAILER@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TIPOFTHEDAY@BLUEGRIFFON.COM.XPI
[2012/08/07 18:09:46 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 00:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/07/12 12:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2012/07/02 06:29:39 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/07/02 06:29:39 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/07/02 06:29:39 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012/07/02 06:29:39 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/07/02 06:29:39 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/07/02 06:29:39 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2012/08/08 14:46:11 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google BAE\BAE.dll (Your Company Name)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\Jonas_ON_C\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Jonas_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0
O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Free YouTube Download - C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKU\Jonas_ON_C Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKU\Jonas_ON_C Winlogon: Shell - (C:\Users\Jonas\AppData\Roaming\msconfig.dat) - C:\Users\Jonas\AppData\Roaming\msconfig.dat ()
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - File not found
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\Windows\System32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img30.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img30.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/08/14 12:14:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/08/13 08:30:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 9.1.1 Home Edition
[2012/08/13 08:08:43 | 000,038,224 | ---- | C] (CANON INC.) -- C:\Windows\System32\IJRMF.exe
[2012/08/12 15:39:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
[2012/08/12 15:39:03 | 000,000,000 | ---D | C] -- C:\Program Files\CrystalDiskInfo
[2012/08/08 14:52:55 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/08/08 14:49:21 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/08/08 14:49:15 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Local\temp
[2012/08/08 14:31:37 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/08/08 14:31:37 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/08/08 14:31:37 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/08/08 14:31:27 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/08/08 14:31:10 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/08/07 12:56:37 | 000,000,000 | ---D | C] -- C:\ProgramData\ztgcrqxmyuqrqqg
[2012/08/03 17:50:58 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Local\Snappy Fax Version 5
[2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
[2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Roaming\IrfanView
[2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView
[2012/07/28 19:09:10 | 002,369,456 | ---- | C] (Codejock Software) -- C:\Windows\System32\Codejock.CommandBars.v13.4.2.ocx
[2012/07/28 19:09:10 | 000,077,504 | ---- | C] (Michael Thummerer Software Design) -- C:\Windows\System32\mtScrollContainer.ocx
[2012/07/21 07:27:35 | 000,000,000 | ---D | C] -- C:\DIE_TUSCHS
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/08/15 05:29:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/08/15 05:29:24 | 000,000,045 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\msconfig.ini
[2012/08/14 13:25:47 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012/08/14 13:25:19 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/14 13:25:10 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/14 13:25:10 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/14 12:45:08 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/14 12:14:46 | 000,000,859 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/08/14 12:14:45 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/08/14 12:13:32 | 000,629,436 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012/08/14 12:13:32 | 000,596,690 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/08/14 12:13:32 | 000,126,890 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012/08/14 12:13:32 | 000,104,506 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/08/13 11:59:43 | 000,042,496 | ---- | M] () -- C:\Users\Jonas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/08/13 11:23:38 | 000,000,746 | -H-- | M] () -- C:\Windows\EPMBatch.ept
[2012/08/13 08:30:21 | 000,001,219 | ---- | M] () -- C:\Users\Public\Desktop\EaseUS Partition Master 9.1.1 Home Edition.lnk
[2012/08/13 08:30:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 9.1.1 Home Edition
[2012/08/12 16:02:45 | 000,166,763 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\nvModes.001
[2012/08/12 15:39:04 | 000,001,765 | ---- | M] () -- C:\Users\Jonas\Desktop\CrystalDiskInfo.lnk
[2012/08/12 15:39:04 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
[2012/08/11 03:35:56 | 003,846,408 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/08/08 17:26:23 | 000,000,600 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\winscp.rnd
[2012/08/08 14:46:11 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/07/31 18:06:36 | 000,001,687 | ---- | M] () -- C:\Users\Jonas\Desktop\IrfanView Thumbnails.lnk
[2012/07/31 18:06:36 | 000,000,807 | ---- | M] () -- C:\Users\Jonas\Desktop\IrfanView.lnk
[2012/07/28 01:32:30 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/07/28 01:32:30 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/08/14 13:16:31 | 000,000,045 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\msconfig.ini
[2012/08/14 12:14:46 | 000,000,859 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/08/13 08:30:21 | 002,468,520 | ---- | C] () -- C:\Windows\System32\BootMan.exe
[2012/08/13 08:30:21 | 000,019,840 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll
[2012/08/13 08:30:21 | 000,001,219 | ---- | C] () -- C:\Users\Public\Desktop\EaseUS Partition Master 9.1.1 Home Edition.lnk
[2012/08/13 08:30:20 | 000,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe
[2012/08/13 08:30:20 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys
[2012/08/13 08:30:20 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys
[2012/08/12 15:39:04 | 000,001,765 | ---- | C] () -- C:\Users\Jonas\Desktop\CrystalDiskInfo.lnk
[2012/08/08 14:31:37 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/08/08 14:31:37 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/08/08 14:31:37 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/08/08 14:31:37 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/08/08 14:31:37 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/07/31 18:06:36 | 000,001,687 | ---- | C] () -- C:\Users\Jonas\Desktop\IrfanView Thumbnails.lnk
[2012/07/31 18:06:36 | 000,000,807 | ---- | C] () -- C:\Users\Jonas\Desktop\IrfanView.lnk
[2012/06/29 11:15:27 | 000,000,600 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\winscp.rnd
[2012/06/13 11:33:54 | 000,000,206 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2012/05/15 09:33:02 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012/02/11 20:01:20 | 000,000,533 | ---- | C] () -- C:\Windows\eReg.dat
[2012/02/11 15:23:07 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2012/02/11 15:23:00 | 000,138,184 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2012/02/11 15:22:49 | 000,183,112 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2012/02/09 16:15:58 | 000,006,854 | RHS- | C] () -- C:\Windows\innova3.ini
[2012/01/31 14:37:33 | 000,000,196 | ---- | C] () -- C:\Windows\System32\ftdiun2k.ini
[2012/01/15 08:31:23 | 000,099,328 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\msconfig.dat
[2011/08/23 07:34:38 | 000,000,028 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/08/23 07:34:36 | 000,000,772 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011/08/10 01:18:00 | 000,000,000 | ---- | C] () -- C:\Users\Jonas\AppData\Local\{72A5C72A-484F-44E4-A570-0EB5D6ED0F18}
[2011/08/10 01:07:04 | 000,000,000 | ---- | C] () -- C:\Users\Jonas\AppData\Local\{80EA586A-7A9E-4E80-A54B-C062188EA15D}
[2011/06/30 06:38:21 | 000,178,176 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2011/06/30 06:38:20 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011/06/30 06:38:14 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011/04/13 11:40:47 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2011/04/13 11:40:06 | 000,006,360 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2011/02/11 17:15:33 | 000,015,873 | ---- | C] () -- C:\Windows\System32\Inetde.dll
[2010/12/17 04:01:47 | 000,000,037 | ---- | C] () -- C:\Windows\SWFConverter.INI
[2010/12/02 07:51:55 | 000,122,880 | ---- | C] () -- C:\Windows\UnGins.exe
[2010/11/10 10:45:30 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/11/06 05:17:15 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2010/09/30 04:20:58 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2010/09/30 04:20:58 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010/08/18 16:24:04 | 000,002,738 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp DirectShow Decoder.dat
[2010/08/18 16:14:48 | 000,229,752 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
[2010/08/18 16:14:48 | 000,015,341 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp Music Converter.dat
[2010/07/17 11:12:48 | 000,330,240 | ---- | C] () -- C:\Windows\PICSUninstall.exe
[2010/07/13 08:19:52 | 000,042,496 | ---- | C] () -- C:\Users\Jonas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/08 08:07:33 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010/07/08 08:07:32 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010/07/05 17:19:51 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/07/05 13:08:29 | 000,001,356 | ---- | C] () -- C:\Users\Jonas\AppData\Local\d3d9caps.dat
[2010/07/05 13:08:26 | 000,166,763 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\nvModes.dat
[2010/07/05 13:08:26 | 000,166,763 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\nvModes.001
[2010/07/05 12:49:09 | 000,000,000 | ---- | C] () -- C:\Windows\VAIOUpdt.INI
[2008/08/05 02:07:20 | 000,065,216 | ---- | C] () -- C:\Windows\System32\PDFreDirectMonNT.dll
[2008/02/04 20:09:01 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1295.dll
[2008/01/21 03:15:58 | 000,629,436 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008/01/21 03:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008/01/21 03:15:58 | 000,126,890 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008/01/21 03:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2007/09/11 19:57:44 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2007/09/11 19:54:26 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll
[2006/11/02 08:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 003,846,408 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,596,690 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,104,506 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
========== LOP Check ==========
[2010/11/11 10:24:11 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\.purple
[2012/07/30 18:11:13 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\AllDup
[2011/11/26 18:52:17 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Audacity
[2011/04/15 15:54:03 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Azureus
[2011/07/13 05:46:46 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Blender Foundation
[2011/03/16 19:40:42 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\BOM
[2010/07/15 16:07:36 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Canon
[2011/05/05 05:22:48 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2010/07/17 12:13:28 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Crossword Compiler Deutsch 8
[2012/07/26 04:27:20 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DAEMON Tools Lite
[2010/12/02 19:26:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DataCast
[2010/08/18 16:24:05 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\dBpoweramp
[2012/06/25 16:16:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Disruptive Innovations SARL
[2012/08/09 06:35:58 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Dropbox
[2012/03/19 02:34:06 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DVDVideoSoft
[2011/04/04 17:12:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/11/18 08:12:22 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Flickr
[2010/11/26 05:58:12 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Free Sound Recorder
[2011/01/19 05:14:41 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\GetRightToGo
[2010/07/15 13:45:13 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Gutscheinmieze
[2011/09/29 16:22:59 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\HandBrake
[2011/10/19 18:01:35 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\ImgBurn
[2012/02/09 16:15:54 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\innoplus
[2010/09/25 17:23:24 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\InterVideo
[2012/07/31 18:06:36 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\IrfanView
[2012/04/04 06:33:49 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\kompozer.net
[2010/09/29 14:23:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Leadertech
[2011/04/28 04:53:31 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\MAGIX
[2010/09/29 16:14:34 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\OOo-dev
[2010/07/28 07:22:04 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\OpenOffice.org
[2010/08/17 00:13:23 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PDF reDirect
[2010/07/15 17:17:22 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PhotoFiltre
[2010/12/09 12:37:12 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PhotoScape
[2010/07/17 11:13:31 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\pics
[2012/07/21 08:00:40 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\RipIt4Me
[2010/07/05 16:00:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Thunderbird
[2010/07/29 11:55:44 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\TomTom
[2011/04/30 11:50:04 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\TP
[2011/10/24 15:28:05 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\uTorrent
[2012/01/21 02:58:52 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Verbindungsassistent
[2011/06/30 06:42:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Video DVD Maker FREE
[2011/03/09 12:33:05 | 000,000,000 | ---D | M] -- C:\ProgramData\AllDup
[2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2010/07/15 15:38:58 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ
[2010/07/17 09:35:27 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonIJEGV
[2010/07/15 16:07:36 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonIJScan
[2012/06/29 11:56:14 | 000,000,000 | ---D | M] -- C:\ProgramData\Cisco
[2012/07/10 15:21:26 | 000,000,000 | ---D | M] -- C:\ProgramData\DAEMON Tools Lite
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
[2011/02/12 13:20:31 | 000,000,000 | ---D | M] -- C:\ProgramData\Eltima Software
[2012/04/14 17:40:47 | 000,000,000 | ---D | M] -- C:\ProgramData\F4D55F3E00016D2B000B49DB570F1C8B
[2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2010/09/11 17:45:30 | 000,000,000 | ---D | M] -- C:\ProgramData\ifolor
[2012/02/09 16:15:57 | 000,000,000 | ---D | M] -- C:\ProgramData\innoplus
[2012/01/29 08:32:35 | 000,000,000 | ---D | M] -- C:\ProgramData\MAGIX
[2010/07/15 15:10:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Phase6
[2010/07/17 11:13:34 | 000,000,000 | ---D | M] -- C:\ProgramData\pics
[2011/08/27 10:18:04 | 000,000,000 | ---D | M] -- C:\ProgramData\regid.1986-12.com.adobe
[2010/07/05 12:39:54 | 000,000,000 | ---D | M] -- C:\ProgramData\Sony
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
[2010/12/17 04:10:35 | 000,000,000 | ---D | M] -- C:\ProgramData\TEMP
[2006/11/02 09:02:04 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2010/07/29 12:02:08 | 000,000,000 | ---D | M] -- C:\ProgramData\TomTom
[2010/07/05 12:44:03 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall
[2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
[2011/03/27 16:05:14 | 000,000,000 | ---D | M] -- C:\ProgramData\WindowsSearch
[2012/08/07 12:56:37 | 000,000,000 | ---D | M] -- C:\ProgramData\ztgcrqxmyuqrqqg
[2010/07/05 12:30:27 | 000,000,000 | ---D | M] -- C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[2011/03/18 18:25:39 | 000,000,000 | ---D | M] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/08/14 13:25:47 | 000,032,558 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report > so, habe nun mit otlpenet eine cd erstellt und damit einen scan laufen lassen. allerdings ohne den oben von dir angegebenen inhalt in die textbox zu kopieren. soll ich noch einen scan damit durchführen?
hier die otl.txt: Code:
OTL logfile created on: 8/15/2012 7:20:52 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Windows Vista (TM) Home Premium Service Pack 2 (Version = 6.0.6002) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 89.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 296.62 Gb Total Space | 138.99 Gb Free Space | 46.86% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand] -- -- (SPTISRV)
SRV - File not found [On_Demand] -- -- (MSCSPTISRV)
SRV - File not found [Auto] -- -- (0268391304585483mcinstcleanup)
SRV - [2012/01/20 07:42:40 | 000,329,168 | ---- | M] () [Auto] -- C:\Program Files\Verbindungsassistent\WTGService.exe -- (WTGService)
SRV - [2011/08/03 16:43:45 | 000,645,048 | ---- | M] (Cisco Systems, Inc.) [Auto] -- C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent)
SRV - [2011/06/06 06:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/04/20 04:50:46 | 000,792,976 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Sony\VAIO Update 5\VUAgent.exe -- (VUAgent)
SRV - [2011/03/09 08:30:08 | 000,092,592 | ---- | M] (TomTom) [Disabled] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2009/09/08 12:09:14 | 000,083,312 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe -- (VcmXmlIfHelper)
SRV - [2009/04/01 18:15:30 | 000,114,688 | ---- | M] (Sony Corporation) [On_Demand] -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2008/03/03 08:45:48 | 000,333,088 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr)
SRV - [2008/01/20 22:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/08/14 15:05:18 | 000,182,392 | ---- | M] (Sony Corporation) [Disabled] -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service)
SRV - [2007/05/31 04:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 04:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (VMnetAdapter)
DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand] -- -- (IpInIp)
DRV - File not found [Kernel | On_Demand] -- -- (igfx)
DRV - File not found [Kernel | On_Demand] -- -- (catchme)
DRV - File not found [File_System | System] -- -- (AFSRedirector)
DRV - File not found [File_System | On_Demand] -- -- (AFSLibrary)
DRV - [2012/07/10 15:07:43 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2012/01/20 07:39:33 | 000,103,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewusbfake.sys -- (hwusbfake)
DRV - [2012/01/20 07:39:33 | 000,100,224 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewsercd.sys -- (ewsercd)
DRV - [2011/08/03 16:27:28 | 000,019,192 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\vpnva.sys -- (vpnva)
DRV - [2011/07/29 07:54:56 | 000,014,216 | ---- | M] () [Kernel | On_Demand] -- C:\Windows\System32\epmntdrv.sys -- (epmntdrv)
DRV - [2011/07/29 07:54:56 | 000,008,456 | ---- | M] () [Kernel | On_Demand] -- C:\Windows\System32\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2009/04/11 01:06:26 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WSDScan.sys -- (WSDScan)
DRV - [2009/04/11 00:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
DRV - [2008/12/13 06:27:50 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008/02/22 20:38:50 | 000,164,400 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2008/02/11 20:49:44 | 007,626,400 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008/02/05 20:06:19 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2008/01/20 22:23:21 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2008/01/20 22:23:21 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\loop.sys -- (msloop)
DRV - [2007/12/16 21:57:23 | 000,009,344 | ---- | M] (Sony Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\SFEP.sys -- (SFEP)
DRV - [2007/12/14 00:03:35 | 000,758,784 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2007/12/13 12:40:06 | 000,010,216 | ---- | M] (Sony Corporation) [Kernel | System] -- C:\Windows\System32\drivers\DMICall.sys -- (DMICall)
DRV - [2007/09/18 23:29:09 | 002,222,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Intel(R)
DRV - [2007/06/05 20:00:39 | 000,812,544 | ---- | M] (Texas Instruments) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ti21sony.sys -- (ti21sony)
DRV - [2007/05/26 04:03:06 | 000,128,104 | ---- | M] (Microsoft Corporation) [File_System | On_Demand] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr)
DRV - [2004/02/04 02:19:32 | 000,024,177 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2004/02/04 02:19:16 | 000,057,372 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.club-vaio.com/vbc
IE - HKU\Jonas_ON_C\Software\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\Jonas_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Jonas_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/08/07 18:09:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/05/28 11:06:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/05/28 11:06:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/11/18 08:12:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions
[2010/07/05 16:00:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/07/29 11:55:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\home2@tomtom.com
[2010/11/18 08:12:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Extensions\uploadr@flickr.com
[2012/08/13 06:31:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions
[2010/07/07 17:45:38 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/29 15:52:00 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011/02/11 17:16:51 | 000,000,000 | ---D | M] ("Biet-O-Matic Firefox Erweiterung") -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{B0D70E72-2FC1-4b9f-A3D4-5921C854D906}
[2012/07/28 01:39:41 | 000,000,000 | ---D | M] (Flash and Video Download) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
[2012/08/08 18:16:15 | 000,000,000 | ---D | M] (Foxdie (Graphite)) -- C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\fzjmzo64.default\extensions\FoxdieGraphite@tanjihay.com
[2012/03/20 11:26:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\CSSEDITOR@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\EYEDROPPER@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\FS@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\FULLSCREEN@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\GFD@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-CS@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-DE@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-EN-US@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ES-ES@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-FI@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-FR@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-HE@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-HU@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-IT@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-JA@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-KO@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-NL@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-PL@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SL@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SR@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-SV-SE@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ZH-CN@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\LANGPACK-ZH-TW@BLUEGRIFFON.ORG.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\MATHML@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\SNIPPETS@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\SVG-EDIT@GOOGLEGROUPS.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TABLELAYOUT@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TEMPLATESMANAGER@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\THUMBNAILER@BLUEGRIFFON.COM.XPI
() (No name found) -- C:\USERS\JONAS\APPDATA\ROAMING\DISRUPTIVE INNOVATIONS SARL\BLUEGRIFFON\PROFILES\4UTVJ3QI.DEFAULT\EXTENSIONS\TIPOFTHEDAY@BLUEGRIFFON.COM.XPI
[2012/08/07 18:09:46 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 00:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/07/12 12:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2012/07/02 06:29:39 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/07/02 06:29:39 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/07/02 06:29:39 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012/07/02 06:29:39 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/07/02 06:29:39 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/07/02 06:29:39 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2012/08/08 14:46:11 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google BAE\BAE.dll (Your Company Name)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\Jonas_ON_C\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Jonas_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0
O7 - HKU\Jonas_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Free YouTube Download - C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKU\Jonas_ON_C Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKU\Jonas_ON_C Winlogon: Shell - (C:\Users\Jonas\AppData\Roaming\msconfig.dat) - C:\Users\Jonas\AppData\Roaming\msconfig.dat ()
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - File not found
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\Windows\System32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img30.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img30.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/08/14 12:14:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/08/13 08:30:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 9.1.1 Home Edition
[2012/08/13 08:08:43 | 000,038,224 | ---- | C] (CANON INC.) -- C:\Windows\System32\IJRMF.exe
[2012/08/12 15:39:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
[2012/08/12 15:39:03 | 000,000,000 | ---D | C] -- C:\Program Files\CrystalDiskInfo
[2012/08/08 14:52:55 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/08/08 14:49:21 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/08/08 14:49:15 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Local\temp
[2012/08/08 14:31:37 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/08/08 14:31:37 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/08/08 14:31:37 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/08/08 14:31:27 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/08/08 14:31:10 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/08/07 12:56:37 | 000,000,000 | ---D | C] -- C:\ProgramData\ztgcrqxmyuqrqqg
[2012/08/03 17:50:58 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Local\Snappy Fax Version 5
[2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
[2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Users\Jonas\AppData\Roaming\IrfanView
[2012/07/31 18:06:36 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView
[2012/07/28 19:09:10 | 002,369,456 | ---- | C] (Codejock Software) -- C:\Windows\System32\Codejock.CommandBars.v13.4.2.ocx
[2012/07/28 19:09:10 | 000,077,504 | ---- | C] (Michael Thummerer Software Design) -- C:\Windows\System32\mtScrollContainer.ocx
[2012/07/21 07:27:35 | 000,000,000 | ---D | C] -- C:\DIE_TUSCHS
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/08/15 05:29:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/08/15 05:29:24 | 000,000,045 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\msconfig.ini
[2012/08/14 13:25:47 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012/08/14 13:25:19 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/14 13:25:10 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/14 13:25:10 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/14 12:45:08 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/14 12:14:46 | 000,000,859 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/08/14 12:14:45 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/08/14 12:13:32 | 000,629,436 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012/08/14 12:13:32 | 000,596,690 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/08/14 12:13:32 | 000,126,890 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012/08/14 12:13:32 | 000,104,506 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/08/13 11:59:43 | 000,042,496 | ---- | M] () -- C:\Users\Jonas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/08/13 11:23:38 | 000,000,746 | -H-- | M] () -- C:\Windows\EPMBatch.ept
[2012/08/13 08:30:21 | 000,001,219 | ---- | M] () -- C:\Users\Public\Desktop\EaseUS Partition Master 9.1.1 Home Edition.lnk
[2012/08/13 08:30:21 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 9.1.1 Home Edition
[2012/08/12 16:02:45 | 000,166,763 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\nvModes.001
[2012/08/12 15:39:04 | 000,001,765 | ---- | M] () -- C:\Users\Jonas\Desktop\CrystalDiskInfo.lnk
[2012/08/12 15:39:04 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
[2012/08/11 03:35:56 | 003,846,408 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/08/08 17:26:23 | 000,000,600 | ---- | M] () -- C:\Users\Jonas\AppData\Roaming\winscp.rnd
[2012/08/08 14:46:11 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/07/31 18:06:36 | 000,001,687 | ---- | M] () -- C:\Users\Jonas\Desktop\IrfanView Thumbnails.lnk
[2012/07/31 18:06:36 | 000,000,807 | ---- | M] () -- C:\Users\Jonas\Desktop\IrfanView.lnk
[2012/07/28 01:32:30 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/07/28 01:32:30 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/08/14 13:16:31 | 000,000,045 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\msconfig.ini
[2012/08/14 12:14:46 | 000,000,859 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/08/13 08:30:21 | 002,468,520 | ---- | C] () -- C:\Windows\System32\BootMan.exe
[2012/08/13 08:30:21 | 000,019,840 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll
[2012/08/13 08:30:21 | 000,001,219 | ---- | C] () -- C:\Users\Public\Desktop\EaseUS Partition Master 9.1.1 Home Edition.lnk
[2012/08/13 08:30:20 | 000,086,408 | ---- | C] () -- C:\Windows\System32\setupempdrv03.exe
[2012/08/13 08:30:20 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys
[2012/08/13 08:30:20 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys
[2012/08/12 15:39:04 | 000,001,765 | ---- | C] () -- C:\Users\Jonas\Desktop\CrystalDiskInfo.lnk
[2012/08/08 14:31:37 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/08/08 14:31:37 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/08/08 14:31:37 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/08/08 14:31:37 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/08/08 14:31:37 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/07/31 18:06:36 | 000,001,687 | ---- | C] () -- C:\Users\Jonas\Desktop\IrfanView Thumbnails.lnk
[2012/07/31 18:06:36 | 000,000,807 | ---- | C] () -- C:\Users\Jonas\Desktop\IrfanView.lnk
[2012/06/29 11:15:27 | 000,000,600 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\winscp.rnd
[2012/06/13 11:33:54 | 000,000,206 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2012/05/15 09:33:02 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012/02/11 20:01:20 | 000,000,533 | ---- | C] () -- C:\Windows\eReg.dat
[2012/02/11 15:23:07 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2012/02/11 15:23:00 | 000,138,184 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2012/02/11 15:22:49 | 000,183,112 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2012/02/09 16:15:58 | 000,006,854 | RHS- | C] () -- C:\Windows\innova3.ini
[2012/01/31 14:37:33 | 000,000,196 | ---- | C] () -- C:\Windows\System32\ftdiun2k.ini
[2012/01/15 08:31:23 | 000,099,328 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\msconfig.dat
[2011/08/23 07:34:38 | 000,000,028 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/08/23 07:34:36 | 000,000,772 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011/08/10 01:18:00 | 000,000,000 | ---- | C] () -- C:\Users\Jonas\AppData\Local\{72A5C72A-484F-44E4-A570-0EB5D6ED0F18}
[2011/08/10 01:07:04 | 000,000,000 | ---- | C] () -- C:\Users\Jonas\AppData\Local\{80EA586A-7A9E-4E80-A54B-C062188EA15D}
[2011/06/30 06:38:21 | 000,178,176 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2011/06/30 06:38:20 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011/06/30 06:38:14 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011/04/13 11:40:47 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2011/04/13 11:40:06 | 000,006,360 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2011/02/11 17:15:33 | 000,015,873 | ---- | C] () -- C:\Windows\System32\Inetde.dll
[2010/12/17 04:01:47 | 000,000,037 | ---- | C] () -- C:\Windows\SWFConverter.INI
[2010/12/02 07:51:55 | 000,122,880 | ---- | C] () -- C:\Windows\UnGins.exe
[2010/11/10 10:45:30 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/11/06 05:17:15 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2010/09/30 04:20:58 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2010/09/30 04:20:58 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010/08/18 16:24:04 | 000,002,738 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp DirectShow Decoder.dat
[2010/08/18 16:14:48 | 000,229,752 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
[2010/08/18 16:14:48 | 000,015,341 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpoweramp Music Converter.dat
[2010/07/17 11:12:48 | 000,330,240 | ---- | C] () -- C:\Windows\PICSUninstall.exe
[2010/07/13 08:19:52 | 000,042,496 | ---- | C] () -- C:\Users\Jonas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/08 08:07:33 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010/07/08 08:07:32 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010/07/05 17:19:51 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/07/05 13:08:29 | 000,001,356 | ---- | C] () -- C:\Users\Jonas\AppData\Local\d3d9caps.dat
[2010/07/05 13:08:26 | 000,166,763 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\nvModes.dat
[2010/07/05 13:08:26 | 000,166,763 | ---- | C] () -- C:\Users\Jonas\AppData\Roaming\nvModes.001
[2010/07/05 12:49:09 | 000,000,000 | ---- | C] () -- C:\Windows\VAIOUpdt.INI
[2008/08/05 02:07:20 | 000,065,216 | ---- | C] () -- C:\Windows\System32\PDFreDirectMonNT.dll
[2008/02/04 20:09:01 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1295.dll
[2008/01/21 03:15:58 | 000,629,436 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008/01/21 03:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008/01/21 03:15:58 | 000,126,890 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008/01/21 03:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2007/09/11 19:57:44 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2007/09/11 19:54:26 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll
[2006/11/02 08:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 003,846,408 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,596,690 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,104,506 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
========== LOP Check ==========
[2010/11/11 10:24:11 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\.purple
[2012/07/30 18:11:13 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\AllDup
[2011/11/26 18:52:17 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Audacity
[2011/04/15 15:54:03 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Azureus
[2011/07/13 05:46:46 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Blender Foundation
[2011/03/16 19:40:42 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\BOM
[2010/07/15 16:07:36 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Canon
[2011/05/05 05:22:48 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2010/07/17 12:13:28 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Crossword Compiler Deutsch 8
[2012/07/26 04:27:20 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DAEMON Tools Lite
[2010/12/02 19:26:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DataCast
[2010/08/18 16:24:05 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\dBpoweramp
[2012/06/25 16:16:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Disruptive Innovations SARL
[2012/08/09 06:35:58 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Dropbox
[2012/03/19 02:34:06 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DVDVideoSoft
[2011/04/04 17:12:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/11/18 08:12:22 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Flickr
[2010/11/26 05:58:12 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Free Sound Recorder
[2011/01/19 05:14:41 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\GetRightToGo
[2010/07/15 13:45:13 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Gutscheinmieze
[2011/09/29 16:22:59 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\HandBrake
[2011/10/19 18:01:35 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\ImgBurn
[2012/02/09 16:15:54 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\innoplus
[2010/09/25 17:23:24 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\InterVideo
[2012/07/31 18:06:36 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\IrfanView
[2012/04/04 06:33:49 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\kompozer.net
[2010/09/29 14:23:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Leadertech
[2011/04/28 04:53:31 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\MAGIX
[2010/09/29 16:14:34 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\OOo-dev
[2010/07/28 07:22:04 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\OpenOffice.org
[2010/08/17 00:13:23 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PDF reDirect
[2010/07/15 17:17:22 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PhotoFiltre
[2010/12/09 12:37:12 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\PhotoScape
[2010/07/17 11:13:31 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\pics
[2012/07/21 08:00:40 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\RipIt4Me
[2010/07/05 16:00:47 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Thunderbird
[2010/07/29 11:55:44 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\TomTom
[2011/04/30 11:50:04 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\TP
[2011/10/24 15:28:05 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\uTorrent
[2012/01/21 02:58:52 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Verbindungsassistent
[2011/06/30 06:42:15 | 000,000,000 | ---D | M] -- C:\Users\Jonas\AppData\Roaming\Video DVD Maker FREE
[2011/03/09 12:33:05 | 000,000,000 | ---D | M] -- C:\ProgramData\AllDup
[2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2010/07/15 15:38:58 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ
[2010/07/17 09:35:27 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonIJEGV
[2010/07/15 16:07:36 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonIJScan
[2012/06/29 11:56:14 | 000,000,000 | ---D | M] -- C:\ProgramData\Cisco
[2012/07/10 15:21:26 | 000,000,000 | ---D | M] -- C:\ProgramData\DAEMON Tools Lite
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
[2011/02/12 13:20:31 | 000,000,000 | ---D | M] -- C:\ProgramData\Eltima Software
[2012/04/14 17:40:47 | 000,000,000 | ---D | M] -- C:\ProgramData\F4D55F3E00016D2B000B49DB570F1C8B
[2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2010/09/11 17:45:30 | 000,000,000 | ---D | M] -- C:\ProgramData\ifolor
[2012/02/09 16:15:57 | 000,000,000 | ---D | M] -- C:\ProgramData\innoplus
[2012/01/29 08:32:35 | 000,000,000 | ---D | M] -- C:\ProgramData\MAGIX
[2010/07/15 15:10:58 | 000,000,000 | ---D | M] -- C:\ProgramData\Phase6
[2010/07/17 11:13:34 | 000,000,000 | ---D | M] -- C:\ProgramData\pics
[2011/08/27 10:18:04 | 000,000,000 | ---D | M] -- C:\ProgramData\regid.1986-12.com.adobe
[2010/07/05 12:39:54 | 000,000,000 | ---D | M] -- C:\ProgramData\Sony
[2006/11/02 09:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
[2010/12/17 04:10:35 | 000,000,000 | ---D | M] -- C:\ProgramData\TEMP
[2006/11/02 09:02:04 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2010/07/29 12:02:08 | 000,000,000 | ---D | M] -- C:\ProgramData\TomTom
[2010/07/05 12:44:03 | 000,000,000 | ---D | M] -- C:\ProgramData\Uninstall
[2008/03/13 05:11:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
[2011/03/27 16:05:14 | 000,000,000 | ---D | M] -- C:\ProgramData\WindowsSearch
[2012/08/07 12:56:37 | 000,000,000 | ---D | M] -- C:\ProgramData\ztgcrqxmyuqrqqg
[2010/07/05 12:30:27 | 000,000,000 | ---D | M] -- C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[2011/03/18 18:25:39 | 000,000,000 | ---D | M] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/08/14 13:25:47 | 000,032,558 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report > |