KriegerDL | 21.09.2012 21:35 | AKM Virus 50,- Paycard Hallo !
Mein Junior hat es geschafft :-)
Ich selbst bin seit Jahrzenten fit am PC und hatte trotz KEINEM Schutz noch nie ein Problem....
Nun steh ich da und auf seinem Rechner geht nix mehr, zum Start kommt nur der Weisse Bildschirm AKM 50,- zahlen .....
Ich habe laut den Empfehlungen Hier mit OTL Bootdisk gebootet...
Leider ist es eine AHACI Installation und ich hatte erstmal bluescreen...
Es SOLLT nur legale Software drauf sein ....
Nun hab ich den Scan gemacht:
Kann mir bitte jemand mit dem Tool helfen, was ich jetzt tun kann um wieder ins system zu kommen, dort weiss ich weiter :-)
OTL Logfile: Code:
OTL logfile created on: 9/22/2012 6:28:07 AM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
64bit-Windows 7 Home Premium Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 97.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86)
Drive C: | 100.00 Mb Total Space | 75.86 Mb Free Space | 75.87% Space Free | Partition Type: NTFS
Drive D: | 967.22 Mb Total Space | 70.45 Mb Free Space | 7.28% Space Free | Partition Type: FAT
Drive E: | 119.14 Gb Total Space | 79.34 Gb Free Space | 66.60% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2012/06/11 13:19:14 | 000,239,616 | ---- | M] (AMD) [Auto] -- E:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2012/02/02 16:29:52 | 000,628,448 | ---- | M] (Intel(R) Corporation) [Auto] -- E:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R) Capability Licensing Service Interface) Intel(R)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012/09/19 11:16:34 | 000,076,888 | ---- | M] () [Auto] -- E:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012/09/19 10:09:33 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- E:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/15 11:09:53 | 004,537,664 | ---- | M] () [Auto] -- E:/Program Files (x86)/Common Files/Akamai/netsession_win_5891ae0.dll -- (Akamai)
SRV - [2012/09/14 11:36:30 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand] -- E:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/08/13 07:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto] -- E:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/08/08 14:57:43 | 001,695,776 | ---- | M] () [Auto] -- E:\ProgramData\PC Performer Manager\2.2.558.177\{16cdff19-861d-48e3-a751-d99a27784753}\%Protector Process Name%.exe -- (PC Performer Manager)
SRV - [2012/07/21 03:46:14 | 000,830,048 | ---- | M] () [Auto] -- E:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.1.3\ToolbarUpdater.exe -- (vToolbarUpdater12.1.3)
SRV - [2012/07/13 20:13:54 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand] -- E:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/07/13 07:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto] -- E:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/06/27 06:29:24 | 002,369,960 | ---- | M] (LogMeIn Inc.) [Auto] -- E:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2012/06/11 10:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand] -- E:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE -- (BBUpdate)
SRV - [2012/06/11 10:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto] -- E:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE -- (BBSvc)
SRV - [2012/06/05 03:39:42 | 000,289,544 | ---- | M] () [Auto] -- E:\Program Files (x86)\PC Beschleunigen\PCSUService.exe -- (PCSUService)
SRV - [2012/04/10 03:48:12 | 001,473,664 | ---- | M] (ASUSTeK Computer Inc.) [Auto] -- E:\Program Files (x86)\ASUS\AsusFanControlService\1.01.04\AsusFanControlService.exe -- (AsusFanControlService)
SRV - [2012/04/04 01:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/02/17 08:26:00 | 000,149,120 | ---- | M] (ASUSTeK Computer Inc.) [Auto] -- E:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe -- (AsSysCtrlService)
SRV - [2012/02/07 11:53:34 | 000,363,800 | ---- | M] (Intel Corporation) [Auto] -- E:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2012/02/07 11:53:32 | 000,277,784 | ---- | M] (Intel Corporation) [Auto] -- E:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2012/02/07 11:52:04 | 000,161,560 | ---- | M] (Intel Corporation) [Auto] -- E:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe -- (jhi_service) Intel(R)
SRV - [2012/02/02 11:56:34 | 000,951,936 | ---- | M] (ASUSTeK Computer Inc.) [Auto] -- E:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe -- (asHmComSvc)
SRV - [2012/02/01 10:29:58 | 000,013,592 | ---- | M] (Intel Corporation) [Auto] -- E:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R)
SRV - [2011/10/29 03:59:26 | 000,918,448 | ---- | M] () [Auto] -- E:\Program Files (x86)\ASUS\AXSP\1.00.18\atkexComSvc.exe -- (asComSvc)
SRV - [2011/06/17 13:33:04 | 000,237,008 | ---- | M] (McAfee, Inc.) [On_Demand] -- E:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe -- (McComponentHostService)
SRV - [2011/05/27 05:07:36 | 000,160,768 | ---- | M] (Intel Corporation) [On_Demand] -- E:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe -- (ICCS) Intel(R) Integrated Clock Controller Service - Intel(R)
SRV - [2010/03/18 07:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 07:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- E:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- E:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/08/03 12:24:03 | 000,560,184 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot] -- E:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV:64bit: - [2012/07/21 03:46:14 | 000,030,568 | ---- | M] (AVG Technologies) [Kernel | System] -- E:\Windows\System32\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2012/06/11 14:59:38 | 010,248,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012/06/11 12:26:14 | 000,367,616 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012/03/26 19:13:20 | 000,789,272 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\iusb3xhc.sys -- (iusb3xhc) Intel(R)
DRV:64bit: - [2012/03/26 19:13:20 | 000,356,632 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\iusb3hub.sys -- (iusb3hub) Intel(R)
DRV:64bit: - [2012/03/26 19:13:18 | 000,019,224 | ---- | M] (Intel Corporation) [Kernel | Boot] -- E:\Windows\System32\drivers\iusb3hcs.sys -- (iusb3hcs) Intel(R)
DRV:64bit: - [2012/02/23 08:32:04 | 000,095,760 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand] -- E:\Windows\System32\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012/02/03 15:01:20 | 000,677,480 | ---- | M] (Realtek ) [Kernel | On_Demand] -- E:\Windows\System32\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/11/09 19:04:14 | 000,060,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\HECIx64.sys -- (MEIx64) Intel(R)
DRV:64bit: - [2011/11/02 21:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot] -- E:\Windows\System32\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2011/08/12 12:13:36 | 000,032,360 | ---- | M] (NT Kernel Resources) [Kernel | System] -- E:\Windows\System32\drivers\ndisrd.sys -- (ndisrd)
DRV:64bit: - [2010/11/20 23:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 23:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\system32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/08/17 19:28:32 | 000,026,136 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\ICCWDT.sys -- (ICCWDT) Intel(R) Watchdog Timer Driver (Intel(R) WDT)
DRV:64bit: - [2010/01/04 21:23:20 | 001,847,296 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\athurx.sys -- (athur)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- E:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\system32\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\system32\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/03/18 10:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\hamachi.sys -- (hamachi)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\KreanPlay_ON_E\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3227980
IE - HKU\KreanPlay_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = https://isearch.avg.com/?cid={C2F56F8A-40D0-4AC9-B0BF-AA40932A7EE9}&mid=4b550233c51a47d0af9ec1f60e974501-eec03004b6a4821d172d3ffe41973a5534b0fa28&lang=de&ds=od011&pr=sa&d=2012-07-21 09:46:14&v=12.1.0.20&sap=hp
IE - HKU\KreanPlay_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
IE - HKU\KreanPlay_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at
IE - HKU\KreanPlay_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 80 F6 9B 4F F5 65 CD 01 [binary data]
IE - HKU\KreanPlay_ON_E\..\URLSearchHook: {0cc09160-108c-4759-bab1-5c12c216e005} - Reg Error: Key error. File not found
IE - HKU\KreanPlay_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\KreanPlay_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\System32\Macromed\Flash\NPSWF64_11_4_402_278.dll ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: E:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\12.1.3\\npsitesafety.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: E:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: E:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: E:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: E:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE: File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: E:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: E:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: E:\Users\KreanPlay\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: E:\Users\KreanPlay\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: E:\Users\KreanPlay\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: E:\Users\KreanPlay\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: E:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\12.1.0.20\ [2012/07/21 03:46:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/08/08 14:56:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\specialsavings@superfish.com: C:\Users\KreanPlay\AppData\Roaming\Mozilla\Profiles\uqp8ve0c.KreanPlay\extensions\specialsavings@superfish.com [2012/08/08 14:57:25 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\PC Performer Manager\2.2.558.177\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension [2012/08/08 14:57:43 | 000,000,000 | ---D | M]
[2012/07/29 14:38:38 | 000,000,000 | ---D | M] (No name found) -- E:\Users\KreanPlay\AppData\Roaming\Mozilla\Extensions
[2012/08/08 14:57:24 | 000,000,000 | ---D | M] (No name found) -- E:\Users\KreanPlay\AppData\Roaming\Mozilla\Firefox\C\Users\KreanPlay\AppData\Roaming\Mozilla\Profiles\uqp8ve0c.KreanPlay\extensions
[2012/08/08 14:57:24 | 000,000,000 | ---D | M] (PriceGong) -- E:\Users\KreanPlay\AppData\Roaming\Mozilla\Firefox\C\Users\KreanPlay\AppData\Roaming\Mozilla\Profiles\uqp8ve0c.KreanPlay\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
[2012/09/20 12:50:18 | 000,000,000 | ---D | M] (No name found) -- E:\Users\KreanPlay\AppData\Roaming\Mozilla\Profiles\uqp8ve0c.KreanPlay\extensions
[2012/09/19 10:46:35 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- E:\Users\KreanPlay\AppData\Roaming\Mozilla\Profiles\uqp8ve0c.KreanPlay\extensions\battlefieldplay4free@ea.com
[2012/09/09 07:59:52 | 000,000,000 | ---D | M] ("Savings Sidekick") -- E:\Users\KreanPlay\AppData\Roaming\Mozilla\Profiles\uqp8ve0c.KreanPlay\extensions\crossriderapp5060@crossrider.com
[2012/09/20 12:50:18 | 000,000,000 | ---D | M] ("Linkury Smartbar") -- E:\Users\KreanPlay\AppData\Roaming\Mozilla\Profiles\uqp8ve0c.KreanPlay\extensions\helperbar@helperbar.com
[2012/08/08 14:57:25 | 000,000,000 | ---D | M] (SpecialSavings) -- E:\Users\KreanPlay\AppData\Roaming\Mozilla\Profiles\uqp8ve0c.KreanPlay\extensions\specialsavings@superfish.com
[2012/09/20 12:50:18 | 000,000,000 | ---D | M] (No name found) -- E:\Users\KreanPlay\AppData\Roaming\Mozilla\Profiles\uqp8ve0c.KreanPlay\extensions\staged
[2012/07/29 14:38:17 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files (x86)\Mozilla Firefox\extensions
[2012/09/16 03:23:08 | 000,000,000 | ---D | M] (Skype Click to Call) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/07/13 20:15:45 | 000,136,672 | ---- | M] (Mozilla Foundation) -- E:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/07/13 20:45:08 | 000,001,392 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/07/21 03:46:14 | 000,003,752 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/07/13 20:45:08 | 000,002,252 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/07/13 20:45:08 | 000,001,153 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012/07/13 20:45:08 | 000,006,805 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/07/13 20:45:08 | 000,001,178 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/07/13 20:45:07 | 000,001,105 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (appbario8 Toolbar) - {0cc09160-108c-4759-bab1-5c12c216e005} - E:\Program Files (x86)\appbario8\prxtbappb.dll (Conduit Ltd.)
O2 - BHO: (Savings Sidekick) - {11111111-1111-1111-1111-110011501160} - E:\Program Files (x86)\Savings Sidekick\Savings Sidekick.dll (215 Apps)
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - E:\Program Files (x86)\PriceGong\2.6.4\PriceGongIE.dll (PriceGong)
O2 - BHO: (SpecialSavings) - {74F475FA-6C75-43BD-AAB9-ECDA6184F600} - E:\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll (SpecialSavings)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - E:\Program Files (x86)\AVG Secure Search\12.1.0.20\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - E:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (appbario8 Toolbar) - {0cc09160-108c-4759-bab1-5c12c216e005} - E:\Program Files (x86)\appbario8\prxtbappb.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - E:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - E:\Program Files (x86)\AVG Secure Search\12.1.0.20\AVG Secure Search_toolbar.dll ()
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] E:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [RTHDVCPL] E:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] E:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] E:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AMD AVT] E:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] E:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [IAStorIcon] E:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] E:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [QuickTime Task] File not found
O4 - HKLM..\Run: [StartCCC] E:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] E:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [USB3MON] E:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKLM..\Run: [vProt] E:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKU\KreanPlay_ON_E..\Run: [AdobeBridge] File not found
O4 - HKU\KreanPlay_ON_E..\Run: [Akamai NetSession Interface] E:\Users\KreanPlay\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKU\KreanPlay_ON_E..\Run: [Browser Infrastructure Helper] E:\Users\KreanPlay\AppData\Local\Smartbar\Application\Linkury.exe (Smartbar)
O4 - HKU\KreanPlay_ON_E..\Run: [ccleaner] E:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\KreanPlay_ON_E..\Run: [EA Core] File not found
O4 - HKU\KreanPlay_ON_E..\Run: [PCSpeedUp] E:\Program Files (x86)\PC Beschleunigen\PCSUNotifier.exe ()
O4 - HKU\KreanPlay_ON_E..\Run: [Steam] File not found
O4 - HKU\LocalService_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\LocalService_ON_E..\RunOnce: [mctadmin] File not found
O4 - HKU\NetworkService_ON_E..\RunOnce: [mctadmin] File not found
O4 - Startup: E:\Users\KreanPlay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ja.lnk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: SpecialSavings - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - E:\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll (SpecialSavings)
O13:64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - Reg Error: Key error. File not found
O20 - AppInit_DLLs: (c:\progra~3\pcperf~1\22558~1.177\{16cdf~1\%prote~1.dll) - E:\ProgramData\PC Performer Manager\2.2.558.177\{16cdff19-861d-48e3-a751-d99a27784753}\%Protector Process Name%.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKU\KreanPlay_ON_E Winlogon: Shell - (C:\Users\KreanPlay\AppData\Roaming\1.exe) - E:\Users\KreanPlay\AppData\Roaming\1.exe ()
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{f8d1ae4e-d1e6-11e1-9b3e-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{f8d1ae4e-d1e6-11e1-9b3e-806e6f6e6963}\Shell\AutoRun\command - "" = E:\PopCDRun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/09/22 00:42:42 | 000,000,000 | ---D | C] -- E:\_OTL
[2012/09/19 11:11:30 | 000,000,000 | ---D | C] -- E:\Users\KreanPlay\AppData\Local\PunkBuster
[2012/09/19 11:09:31 | 000,000,000 | ---D | C] -- E:\Users\KreanPlay\Documents\Battlefield Play4Free
[2012/09/19 11:08:50 | 000,000,000 | ---D | C] -- E:\Users\KreanPlay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EA Games
[2012/09/19 10:46:54 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\EA Games
[2012/09/16 02:52:48 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\RocketDock
[2012/09/16 02:52:47 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\RocketDock
[2012/09/15 11:22:05 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\alaplaya
[2012/09/15 11:21:34 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\alaplaya
[2012/09/15 11:10:40 | 000,000,000 | ---D | C] -- E:\Users\KreanPlay\AppData\Local\Akamai
[2012/09/15 11:09:50 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\Common Files\Akamai
[2012/09/14 12:32:14 | 000,056,208 | ---- | C] (Rovi Corporation) -- E:\Windows\System32\drivers\PxHlpa64.sys
[2012/09/14 12:32:14 | 000,010,224 | ---- | C] (Sonic Solutions) -- E:\Windows\System32\drivers\cdralw2k.sys
[2012/09/14 12:32:14 | 000,010,224 | ---- | C] (Sonic Solutions) -- E:\Windows\System32\drivers\cdr4_xp.sys
[2012/09/14 12:32:14 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\Common Files\Sonic Shared
[2012/09/14 12:32:14 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\Common Files\PX Storage Engine
[2012/09/14 12:32:10 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\My Company Name
[2012/09/12 07:55:50 | 000,574,464 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\d3d10level9.dll
[2012/09/12 07:55:50 | 000,490,496 | ---- | C] (Microsoft Corporation) -- E:\Windows\SysWow64\d3d10level9.dll
[2012/09/12 07:55:50 | 000,376,688 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\drivers\netio.sys
[2012/09/12 07:55:50 | 000,288,624 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\drivers\FWPKCLNT.SYS
[2012/09/12 07:55:50 | 000,041,472 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\drivers\RNDISMP.sys
========== Files - Modified Within 30 Days ==========
[2012/09/21 18:49:36 | 000,067,584 | --S- | M] () -- E:\Windows\bootstat.dat
[2012/09/21 18:49:10 | 001,048,576 | ---- | M] () -- E:\Windows\PE_Rom.dll
[2012/09/21 18:48:37 | 3182,702,592 | -HS- | M] () -- E:\hiberfil.sys
[2012/09/21 12:03:50 | 000,696,620 | ---- | M] () -- E:\Windows\System32\perfh007.dat
[2012/09/21 12:03:50 | 000,651,938 | ---- | M] () -- E:\Windows\System32\perfh009.dat
[2012/09/21 12:03:50 | 000,147,916 | ---- | M] () -- E:\Windows\System32\perfc007.dat
[2012/09/21 12:03:50 | 000,120,870 | ---- | M] () -- E:\Windows\System32\perfc009.dat
[2012/09/20 12:51:23 | 012,481,704 | ---- | M] () -- E:\Windows\System32\FNTCACHE.DAT
[2012/09/20 12:50:22 | 000,000,665 | ---- | M] () -- E:\Users\KreanPlay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ja.lnk
[2012/09/20 12:50:17 | 000,391,219 | ---- | M] () -- E:\Users\KreanPlay\AppData\Roaming\1.exe
[2012/09/20 12:44:03 | 000,001,099 | ---- | M] () -- E:\Windows\MB.idx
[2012/09/20 12:41:59 | 000,000,551 | ---- | M] () -- E:\Windows\Path.idx
[2012/09/20 12:29:00 | 000,000,884 | ---- | M] () -- E:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/20 12:27:01 | 000,001,136 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1864943427-391754695-4144144592-1000UA.job
[2012/09/20 12:27:00 | 000,001,084 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1864943427-391754695-4144144592-1000Core.job
[2012/09/20 11:41:20 | 000,021,888 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/20 11:41:20 | 000,021,888 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/20 11:36:40 | 000,001,087 | ---- | M] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6 (64 Bit).lnk
[2012/09/20 11:36:31 | 000,001,219 | ---- | M] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6.lnk
[2012/09/20 11:36:22 | 000,000,784 | ---- | M] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk
[2012/09/20 11:36:15 | 000,001,181 | ---- | M] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk
[2012/09/20 11:34:49 | 000,000,859 | ---- | M] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
[2012/09/20 11:34:48 | 000,001,531 | ---- | M] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
[2012/09/19 11:16:34 | 000,076,888 | ---- | M] () -- E:\Windows\SysWow64\PnkBstrA.exe
[2012/09/19 11:16:09 | 000,282,104 | ---- | M] () -- E:\Windows\SysWow64\PnkBstrB.xtr
[2012/09/19 11:16:09 | 000,282,104 | ---- | M] () -- E:\Windows\SysWow64\PnkBstrB.exe
[2012/09/19 10:09:33 | 000,696,240 | ---- | M] (Adobe Systems Incorporated) -- E:\Windows\SysWow64\FlashPlayerApp.exe
[2012/09/19 10:09:33 | 000,073,136 | ---- | M] (Adobe Systems Incorporated) -- E:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/09/18 09:29:54 | 000,000,368 | ---- | M] () -- E:\Windows\tasks\PC SpeedUp Service Deactivator.job
[2012/09/16 02:52:48 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\RocketDock
[2012/09/15 11:22:18 | 000,001,818 | ---- | M] () -- E:\Users\Public\Desktop\S4League.lnk
[2012/09/15 11:22:05 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\alaplaya
[2012/09/14 12:33:35 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
========== Files Created - No Company Name ==========
[2012/09/20 12:50:22 | 000,000,665 | ---- | C] () -- E:\Users\KreanPlay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ja.lnk
[2012/09/20 12:50:17 | 000,391,219 | ---- | C] () -- E:\Users\KreanPlay\AppData\Roaming\1.exe
[2012/09/20 11:36:40 | 000,001,087 | ---- | C] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6 (64 Bit).lnk
[2012/09/20 11:36:31 | 000,001,219 | ---- | C] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6.lnk
[2012/09/20 11:36:15 | 000,001,181 | ---- | C] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk
[2012/09/19 11:12:03 | 000,282,104 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrB.xtr
[2012/09/19 11:08:53 | 000,282,104 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrB.exe
[2012/09/19 11:08:52 | 000,076,888 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrA.exe
[2012/09/15 11:22:18 | 000,001,818 | ---- | C] () -- E:\Users\Public\Desktop\S4League.lnk
[2012/08/20 10:09:54 | 003,596,288 | ---- | C] () -- E:\Windows\SysWow64\qt-dx331.dll
[2012/08/20 10:09:54 | 000,811,008 | ---- | C] () -- E:\Windows\SysWow64\xvidcore.dll
[2012/08/20 10:09:54 | 000,198,656 | ---- | C] () -- E:\Windows\SysWow64\xvidvfw.dll
[2012/08/14 03:10:19 | 000,000,056 | RHS- | C] () -- E:\Windows\SysWow64\DC7F58F417.sys
[2012/08/14 03:10:15 | 000,000,952 | -HS- | C] () -- E:\Windows\SysWow64\KGyGaAvL.sys
[2012/07/20 07:39:47 | 000,005,120 | ---- | C] () -- E:\Users\KreanPlay\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/07/20 06:29:23 | 001,589,442 | ---- | C] () -- E:\Windows\SysWow64\PerfStringBackup.INI
[2012/07/19 17:58:44 | 004,962,240 | ---- | C] () -- E:\Windows\PE_File.dll
[2012/07/19 17:55:04 | 001,048,576 | ---- | C] () -- E:\Windows\PE_Rom.dll
[2012/07/19 17:52:44 | 000,014,464 | ---- | C] () -- E:\Windows\SysWow64\drivers\AsUpIO.sys
[2012/07/19 17:52:08 | 000,013,440 | ---- | C] () -- E:\Windows\SysWow64\drivers\AsIO.sys
[2012/07/19 17:52:08 | 000,011,832 | ---- | C] () -- E:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2012/07/19 17:52:08 | 000,010,216 | ---- | C] () -- E:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2012/07/19 17:46:50 | 000,000,000 | ---- | C] () -- E:\Windows\ativpsrm.bin
[2012/07/19 17:45:21 | 000,003,917 | ---- | C] () -- E:\Windows\SysWow64\atipblag.dat
[2012/07/19 16:26:36 | 000,001,769 | ---- | C] () -- E:\Windows\Language_trs.ini
[2012/07/19 16:26:29 | 000,039,559 | ---- | C] () -- E:\Windows\Ascd_tmp.ini
[2012/06/11 12:50:16 | 000,204,952 | ---- | C] () -- E:\Windows\SysWow64\ativvsvl.dat
[2012/06/11 12:50:16 | 000,157,144 | ---- | C] () -- E:\Windows\SysWow64\ativvsva.dat
[2012/05/10 10:35:16 | 000,029,184 | ---- | C] () -- E:\Windows\SysWow64\kdbsdk32.dll
[2012/02/02 16:08:26 | 000,001,536 | ---- | C] () -- E:\Windows\SysWow64\IusEventLog.dll
[2011/09/28 11:44:14 | 000,179,271 | ---- | C] () -- E:\Windows\SysWow64\xlive.dll.cat
[2010/11/20 23:24:49 | 000,252,928 | ---- | C] () -- E:\Windows\SysWow64\DShowRdpFilter.dll
[2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- E:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- E:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- E:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 18:25:04 | 000,197,632 | ---- | C] () -- E:\Windows\SysWow64\ir32_32.dll
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- E:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- E:\Windows\SysWow64\mlang.dat
[2009/04/02 08:30:14 | 000,010,296 | ---- | C] () -- E:\Windows\SysWow64\drivers\ASUSHWIO.SYS
[2005/08/29 18:00:00 | 000,781,312 | ---- | C] () -- E:\Windows\SysWow64\RGSS102J.dll
[2005/08/29 18:00:00 | 000,778,752 | ---- | C] () -- E:\Windows\SysWow64\RGSS102E.dll
[2005/08/29 18:00:00 | 000,771,584 | ---- | C] () -- E:\Windows\SysWow64\RGSS100J.dll
========== LOP Check ==========
[2012/07/19 17:51:02 | 000,000,000 | ---D | M] -- E:\ProgramData\AMD
[2012/07/19 16:21:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Anwendungsdaten
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data
[2012/07/19 17:52:10 | 000,000,000 | ---D | M] -- E:\ProgramData\ASUS
[2012/07/19 17:54:47 | 000,000,000 | ---D | M] -- E:\ProgramData\ASUS OC Profiles
[2012/07/19 17:54:44 | 000,000,000 | ---D | M] -- E:\ProgramData\ASUS PowerControl Profiles
[2012/07/21 03:46:17 | 000,000,000 | ---D | M] -- E:\ProgramData\AVG Secure Search
[2012/07/21 03:46:00 | 000,000,000 | -H-D | M] -- E:\ProgramData\Common Files
[2012/08/03 12:29:13 | 000,000,000 | ---D | M] -- E:\ProgramData\DAEMON Tools Lite
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents
[2012/07/19 16:21:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Dokumente
[2012/08/03 13:27:16 | 000,000,000 | ---D | M] -- E:\ProgramData\Electronic Arts
[2012/07/19 16:21:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favoriten
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites
[2012/08/16 07:31:59 | 000,000,000 | ---D | M] -- E:\ProgramData\Hi-Rez Studios
[2012/08/08 14:57:56 | 000,000,000 | ---D | M] -- E:\ProgramData\IBUpdaterService
[2012/08/08 06:22:21 | 000,000,000 | ---D | M] -- E:\ProgramData\PACE Anti-Piracy
[2012/08/08 14:57:43 | 000,000,000 | ---D | M] -- E:\ProgramData\PC Performer Manager
[2012/07/29 10:41:08 | 000,000,000 | ---D | M] -- E:\ProgramData\PMB Files
[2012/08/08 05:35:05 | 000,000,000 | ---D | M] -- E:\ProgramData\PopCap Games
[2012/08/13 06:36:39 | 000,000,000 | ---D | M] -- E:\ProgramData\regid.1986-12.com.adobe
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu
[2012/07/19 16:21:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Startmenü
[2012/07/21 05:30:51 | 000,000,000 | ---D | M] -- E:\ProgramData\TechSmith
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates
[2012/07/19 17:35:22 | 000,000,000 | ---D | M] -- E:\ProgramData\TP-LINK
[2012/07/19 16:21:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Vorlagen
[2012/09/18 09:29:54 | 000,000,368 | ---- | M] () -- E:\Windows\Tasks\PC SpeedUp Service Deactivator.job
[2009/07/14 01:08:49 | 000,030,870 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 1244 bytes -> E:\Wintemp:iwg54f3osEWs8NJVq12
@Alternate Data Stream - 1185 bytes -> E:\Users\KreanPlay\AppData\Local:xYPO4pfARrwr38j6b1lcTOO
@Alternate Data Stream - 1169 bytes -> E:\Users\KreanPlay\AppData\Local\E81GlaSED3Y:WMiH9CWZVAFVDcUQIrbLwdlI
< End of report > --- --- ---
kann mir hier irgendjemand helfen ? |