Munchkin86 | 12.01.2013 07:58 | Adobe Acrobat XI (englisch) installiert sich von selbst, obwohl Acrobat XI Pro installiert ist Also hier mein Problem, ich habe Adobe Acrobat XI Pro XI (neuste Version) auf dem PC installiert (danke an meine Uni).
Jetzt hat sich vor kurzer Zeit, ich weiß nicht mehr ganz genau wann, vor 2-3 Tagen, anscheind Acrobat Reader XI sich selbst installiert. Auf englisch. Habe gedacht ein nebeneinander bestehen von der Pro-Version und der Freeware wäre gar nicht möglich, da diese in Konflikt geraten würden.
Aufmerksam wurde ich darauf, dass das Icon von Acrobat XI auf dem Desktop erschien und auch der Adobe Update Manager ein Update festgestellt hatte.
Ich glaube sogar, dass zu allererst der Update Manager sich bemerkbar gemacht hat und darauf hinwies, dass eine neue Version von Adobe Acrobat zur Verfügung stehen würde (wenn ich mich recht erinnere, sorry hatte zu der Zeit mir nichts gedacht und die Updatebenachrichtigung weggeklickt, wurde darauf hingewiesen, dass Version 11 zur Verfügung stehen würde und ich derzeit Version 9 installiert hätte).
Das hatte mich verwundert, da ich ja schon seit längerer Zeit die Version 11 benutze, deswegen dachte ich mir auch nichts dabei.
Also nachdem dann das Icon auf dem Desktop erschien habe ich dieses angeklickt und siehe da die Version ist auf englisch.
Alles sehr dubios.
Also hab ich Adobe Acrobat XI (Freeware) per iObit Uninstaller deinstalliert.
Hat auch geklappt, Programm war verschwunden und die Pro-Version hat weiterhin funktioniert.
Nun ist aber wieder die Freeware-Version auf meinem PC und ich wüsste nicht wieso diese sich einfach so installiert. Ich habe diese nirgendswo heruntergeladen bzw. ein Programm installiert, welches die Datei mitinstalliert.
Ich dachte erst, dass es vielleicht an einem Virus-Alarm der letzten Tage liegen könne, doch nach nochmaliger Update-Einspeisung hat Emsisoft Anti-Malware gemeldet, dass dieser Virusalarm ein Fehlalarm war.
War auch sehr komisch, da die Datei, welche als Virus gemeldet wurde zu einem Programm (MyMDb 3.6 [Verwaltung von Filmdatenbanken]) gehört, welches zwar glaube ich Open-Source ist, aber ich bei Chip.de heruntergeladen habe. Nach der Meldung, dass das Programm einen Virus enthalte hatte ich die Datei in Quarantäne verschoben, wurde aber mittlerweile wiederhergestellt.
Hier die Virusmeldung (welche sich als Fehlalarm herausgestellt hat):
Also ich hab diese Meldung bekommen, nachdem ich das installierte Programm (MyMDb) gestartet hatte. Gestern bei einem Virenscan wurde der gleiche Virus im Temp-Verzeichnis gefunden, also wahrscheinlich in der entpackten Installationsdatei. Nach erneutem Scan mit den aktuellsten Virensignaturen wurde die Datei dann als Fehlalarm gemeldet.
Meldung von Emsisoft Anti-Malware im Temp-Ordner (Scan von gestern):
C:\Users\***\AppData\Local\Temp\9A5BA3AC39FBEB4E6779B01BFFE8EC9C1F710A1D.zip -> 73120513D319E0367EC87EC9FBE8DF18A45CCD9E.dat gefunden: Gen:Variant.Kazy.133201 (B)
Protokoll des angeblichen Viren-Funds aus der Protokoll-Datei von Emsisoft:
11.01.2013 02:53:19 0 C:\Program Files (x86)\MyMDb\jittemp\jittmp30.dll Von Regel in Quarantäne Gen:Variant.Kazy.133201 (B)
Also hat dieser Virusfund nichts mit meinem Problem zu tun.
Hier noch einige Details zu meinem System:
Windows 7 64bit
Emsisoft Anti-Malware (Vollversion)
Emsisoft Online-Armor (Freeware)
Malwarebytes Anti-Malware (Freeware)
FileHippo Update Checker
Secunia Personal Software Inspector
Hoffe die Infos waren ausreichend und mir kann geholfen werden.
Hier jetzt die Files:
defogger_disable Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 04:28 on 12/01/2013 (Yannick)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
SPTD -> Already disabled
-=E.O.F=- OTL Code:
OTL logfile created on: 12.01.2013 04:29:27 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\****\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
5,91 Gb Total Physical Memory | 3,76 Gb Available Physical Memory | 63,61% Memory free
11,82 Gb Paging File | 9,32 Gb Available in Paging File | 78,81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 85,77 Gb Total Space | 24,18 Gb Free Space | 28,19% Space Free | Partition Type: NTFS
Drive D: | 20,26 Gb Total Space | 8,64 Gb Free Space | 42,66% Space Free | Partition Type: NTFS
Drive E: | 358,55 Gb Total Space | 79,26 Gb Free Space | 22,11% Space Free | Partition Type: NTFS
Drive G: | 1,17 Gb Total Space | 0,51 Gb Free Space | 43,80% Space Free | Partition Type: NTFS
Computer Name: ARAGORN | User Name: **** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.01.12 03:43:09 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\****\Desktop\OTL.exe
PRC - [2012.12.19 03:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.12.12 18:19:34 | 003,084,688 | ---- | M] (Emsisoft GmbH) -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
PRC - [2012.10.17 18:02:24 | 003,364,264 | ---- | M] (Emsisoft GmbH) -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe
PRC - [2012.10.02 15:02:04 | 000,216,072 | ---- | M] (Emsisoft GmbH) -- C:\Program Files (x86)\Online Armor\OAcat.exe
PRC - [2012.05.16 12:32:00 | 001,662,560 | ---- | M] (Lenovo) -- C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
PRC - [2012.05.16 12:32:00 | 000,128,608 | ---- | M] (Lenovo Group Limited) -- C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
PRC - [2012.01.16 11:47:42 | 000,062,016 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\Communications Utility\TPKNRSVC.exe
PRC - [2012.01.16 11:47:40 | 000,044,096 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\Communications Utility\TpKnrres.exe
PRC - [2012.01.16 11:47:22 | 000,043,584 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\Communications Utility\CamMute.exe
PRC - [2011.11.04 15:37:16 | 000,330,304 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\TPONSCR.exe
PRC - [2011.07.12 16:53:24 | 000,101,736 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\micmute.exe
PRC - [2011.07.12 16:53:18 | 000,142,696 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\HOTKEY\TPHKSVC.exe
PRC - [2011.02.16 00:01:48 | 000,019,968 | ---- | M] (Fork Ltd.) -- C:\Program Files (x86)\Prey\platform\windows\cronsvc.exe
PRC - [2011.01.07 18:28:42 | 000,446,592 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\SysWOW64\SASrv.exe
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV:64bit: - [2012.04.11 16:27:06 | 000,047,440 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Windows\SysNative\ibmpmsvc.exe -- (IBMPMSVC)
SRV:64bit: - [2012.03.09 01:10:22 | 000,235,520 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011.12.29 04:48:24 | 000,049,480 | ---- | M] (Lenovo.) [On_Demand | Stopped] -- C:\Windows\SysNative\TPHDEXLG64.exe -- (TPHDEXLGSVC)
SRV:64bit: - [2010.12.17 13:18:08 | 000,198,784 | ---- | M] (Conexant Systems Inc.) [Disabled | Stopped] -- C:\Windows\SysNative\CxAudMsg64.exe -- (CxAudMsg)
SRV:64bit: - [2009.07.14 09:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2013.01.10 00:54:36 | 000,251,400 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.01.09 13:43:54 | 000,115,760 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.01.08 12:55:20 | 000,161,536 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.12.19 03:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.12.12 18:19:34 | 003,084,688 | ---- | M] (Emsisoft GmbH) [Auto | Running] -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe -- (a2AntiMalware)
SRV - [2012.11.29 21:50:25 | 003,463,080 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2012.11.23 15:20:54 | 000,021,416 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2012.10.02 15:02:10 | 004,463,864 | ---- | M] (Emsisoft GmbH) [On_Demand | Stopped] -- C:\Program Files (x86)\Online Armor\oasrv.exe -- (SvcOnlineArmor)
SRV - [2012.10.02 15:02:04 | 000,216,072 | ---- | M] (Emsisoft GmbH) [Auto | Running] -- C:\Program Files (x86)\Online Armor\OAcat.exe -- (OAcat)
SRV - [2012.08.16 18:48:54 | 000,295,440 | ---- | M] (CyberLink) [Disabled | Stopped] -- C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe -- (CyberLink PowerDVD 12 Media Server Service)
SRV - [2012.08.16 18:48:51 | 000,078,352 | ---- | M] (CyberLink) [Disabled | Stopped] -- C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe -- (CyberLink PowerDVD 12 Media Server Monitor Service)
SRV - [2012.08.16 18:48:47 | 000,090,640 | ---- | M] (CyberLink Corp.) [Disabled | Stopped] -- C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe -- (CLHNServiceForPowerDVD12)
SRV - [2012.07.25 16:46:44 | 001,326,176 | ---- | M] (Secunia) [Auto | Stopped] -- C:\Program Files (x86)\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
SRV - [2012.07.25 16:46:42 | 000,681,056 | ---- | M] (Secunia) [Auto | Stopped] -- C:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2012.07.17 21:14:44 | 002,292,480 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2012.05.16 12:32:00 | 001,665,120 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE -- (PwmEWSvc)
SRV - [2012.05.16 12:32:00 | 001,662,560 | ---- | M] (Lenovo) [On_Demand | Running] -- C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE -- (Power Manager DBC Service)
SRV - [2012.03.01 12:12:40 | 000,776,848 | ---- | M] (Mister Group) [Disabled | Stopped] -- C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe -- (SystemExplorerHelpService)
SRV - [2012.01.18 06:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2012.01.16 11:47:42 | 000,062,016 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\Communications Utility\TPKNRSVC.exe -- (LENOVO.TPKNRSVC)
SRV - [2012.01.16 11:47:22 | 000,043,584 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\Communications Utility\CamMute.exe -- (LENOVO.CAMMUTE)
SRV - [2011.10.20 18:33:22 | 000,135,440 | ---- | M] (Intel(R) Corporation) [Disabled | Stopped] -- C:\Programme\Intel\BluetoothHS\BTHSSecurityMgr.exe -- (BTHSSecurityMgr)
SRV - [2011.10.19 14:25:00 | 000,661,504 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Programme\Intel\BluetoothHS\BTHSAmpPalService.exe -- (AMPPALR3)
SRV - [2011.10.17 15:48:24 | 000,970,016 | ---- | M] (Broadcom Corporation.) [Disabled | Stopped] -- C:\Programme\ThinkPad\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2011.07.12 16:53:58 | 000,133,992 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC)
SRV - [2011.07.12 16:53:40 | 000,145,256 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\HOTKEY\tphkload.exe -- (TPHKLOAD)
SRV - [2011.07.12 16:53:24 | 000,101,736 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\HOTKEY\micmute.exe -- (LENOVO.MICMUTE)
SRV - [2011.07.12 16:53:18 | 000,142,696 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Programme\Lenovo\HOTKEY\TPHKSVC.exe -- (TPHKSVC)
SRV - [2011.07.08 17:53:20 | 000,144,232 | ---- | M] (Lenovo Group Limited) [Auto | Stopped] -- C:\Programme\Lenovo\RapidBoot\HyperW7Svc64.exe -- (HyperW7Svc)
SRV - [2011.02.24 06:10:24 | 000,212,944 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe -- (jhi_service)
SRV - [2011.02.22 18:19:12 | 002,656,280 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011.02.22 18:19:08 | 000,326,168 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2011.02.16 00:01:48 | 000,019,968 | ---- | M] (Fork Ltd.) [Auto | Running] -- C:\Program Files (x86)\Prey\platform\windows\cronsvc.exe -- (CronService)
SRV - [2011.01.07 18:28:42 | 000,446,592 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\SASrv.exe -- (SAService)
SRV - [2010.06.26 01:07:20 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WinPcap\rpcapd.exe -- (rpcapd)
SRV - [2010.03.18 19:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010.01.10 03:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010.01.10 03:20:56 | 000,174,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose64)
SRV - [2009.11.18 13:40:26 | 000,012,288 | ---- | M] (Chris Pietschmann (hxxp://pietschsoft.com)) [Auto | Stopped] -- C:\Program Files (x86)\Virtual Router\VirtualRouterService.exe -- (Virtual Router)
SRV - [2009.06.11 05:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012.12.06 12:11:40 | 011,518,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Netwsw00.sys -- (NETwNs64)
DRV:64bit: - [2012.11.07 19:57:19 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2012.10.08 19:52:52 | 000,031,968 | -H-- | M] (Wondershare) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apowersoft_AudioDevice.sys -- (Apowersoft_AudioDevice)
DRV:64bit: - [2012.10.02 15:02:34 | 000,035,376 | ---- | M] (Emsisoft) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\OAnet.sys -- (OAnet)
DRV:64bit: - [2012.09.20 12:35:36 | 000,203,104 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudobex.sys -- (ssudobex)
DRV:64bit: - [2012.09.20 12:35:36 | 000,203,104 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2012.09.20 12:35:36 | 000,102,368 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2012.08.23 22:12:16 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2012.08.23 22:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.08.23 22:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012.08.23 22:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012.08.21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012.07.23 11:11:44 | 000,148,328 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsX64.sys -- (Shockprf)
DRV:64bit: - [2012.07.09 13:42:54 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012.07.05 21:43:24 | 000,443,192 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2012.07.05 21:43:24 | 000,027,960 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Smb_driver_Intel.sys -- (SmbDrvI)
DRV:64bit: - [2012.05.16 12:32:00 | 000,019,784 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\TPPWR64V.SYS -- (TPPWRIF)
DRV:64bit: - [2012.05.02 07:35:23 | 000,138,360 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AnyDVD.sys -- (AnyDVD)
DRV:64bit: - [2012.04.22 13:51:38 | 000,025,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
DRV:64bit: - [2012.04.11 16:27:04 | 000,042,280 | ---- | M] (Lenovo.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ibmpmdrv.sys -- (IBMPMDRV)
DRV:64bit: - [2012.03.09 02:28:10 | 010,857,984 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.03.08 23:58:04 | 000,328,704 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.03.01 14:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.02.01 12:54:56 | 000,031,872 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdkmpfd.sys -- (amdkmpfd)
DRV:64bit: - [2012.01.18 06:44:36 | 004,865,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64)
DRV:64bit: - [2012.01.18 06:44:28 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2011.12.29 04:48:24 | 000,025,416 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsHM64.sys -- (TPDIGIMN)
DRV:64bit: - [2011.12.27 09:10:44 | 000,040,248 | ---- | M] (Lenovo Information Product(ShenZhen China) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\psadd.sys -- (psadd)
DRV:64bit: - [2011.12.16 23:53:01 | 000,035,112 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\teamviewervpn.sys -- (teamviewervpn)
DRV:64bit: - [2011.11.03 03:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2011.10.26 16:42:38 | 000,037,456 | ---- | M] (Paragon Software Group) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hotcore3.sys -- (hotcore3)
DRV:64bit: - [2011.10.25 15:57:38 | 000,213,504 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2011.10.25 15:57:38 | 000,096,768 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2011.10.19 14:19:08 | 000,195,072 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPALP)
DRV:64bit: - [2011.10.19 14:19:08 | 000,195,072 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmpPal.sys -- (AMPPAL)
DRV:64bit: - [2011.10.17 16:24:50 | 000,437,288 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (BTWAMPFL)
DRV:64bit: - [2011.10.17 16:24:44 | 000,164,392 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2011.10.17 16:24:44 | 000,146,984 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2011.10.17 16:24:44 | 000,039,976 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2011.10.17 16:24:44 | 000,021,544 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2011.09.21 10:25:54 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:64bit: - [2011.09.03 04:29:54 | 000,019,936 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdrvio.sys -- (pwdrvio)
DRV:64bit: - [2011.09.03 04:29:52 | 000,013,280 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdspio.sys -- (pwdspio)
DRV:64bit: - [2011.08.09 08:32:02 | 012,289,472 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdpmd64.sys -- (intelkmd)
DRV:64bit: - [2011.07.29 13:54:56 | 000,016,776 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\epmntdrv.sys -- (epmntdrv)
DRV:64bit: - [2011.07.29 13:54:56 | 000,009,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\EuGdiDrv.sys -- (EuGdiDrv)
DRV:64bit: - [2011.07.01 17:46:40 | 000,031,232 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:64bit: - [2011.06.10 12:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.05.25 23:23:00 | 000,101,888 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\risdxc64.sys -- (risdxc)
DRV:64bit: - [2011.05.25 07:40:10 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\taphss.sys -- (taphss)
DRV:64bit: - [2011.05.10 14:06:14 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
DRV:64bit: - [2011.04.08 21:09:38 | 000,042,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDKMD.sys -- (wdkmd)
DRV:64bit: - [2011.03.24 21:36:20 | 001,576,064 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2011.03.11 14:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 14:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.03.05 00:18:42 | 000,166,016 | ---- | M] (Ricoh co.,Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\5U877.sys -- (5U877)
DRV:64bit: - [2011.01.16 05:59:52 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:64bit: - [2011.01.16 05:59:52 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:64bit: - [2011.01.16 05:59:52 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2011.01.16 05:59:50 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.12.17 06:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010.10.19 15:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010.10.15 07:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2010.09.07 20:09:34 | 000,015,472 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\smiifx64.sys -- (lenovo.smi)
DRV:64bit: - [2010.09.01 16:30:58 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI)
DRV:64bit: - [2010.06.26 01:07:26 | 000,035,344 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)
DRV:64bit: - [2010.06.05 04:07:26 | 000,032,768 | ---- | M] (Juniper Networks) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dsNcAdpt.sys -- (dsNcAdpt)
DRV:64bit: - [2009.12.30 10:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
DRV:64bit: - [2009.08.21 07:52:10 | 000,079,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2009.07.14 09:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 09:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 09:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.11 04:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.11 04:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.11 04:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.11 04:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2012.10.02 15:03:04 | 000,062,016 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysWOW64\drivers\oahlp64.sys -- (oahlpXX)
DRV - [2012.10.02 15:02:34 | 000,040,520 | ---- | M] (Emsisoft) [Kernel | System | Running] -- C:\Windows\SysWOW64\drivers\OAmon.sys -- (OAmon)
DRV - [2012.10.02 15:02:32 | 000,061,632 | ---- | M] () [File_System | System | Running] -- C:\Windows\SysWOW64\drivers\OADriver.sys -- (OADevice)
DRV - [2012.08.14 18:57:50 | 000,147,704 | ---- | M] (CyberLink Corp.) [2012/09/26 20:43:43] [Kernel | Auto | Running] -- C:\Program Files (x86)\CyberLink\PowerDVD12\Common\NavFilter\000.fcl -- ({73526619-C24F-470B-9BED-53D455FBB5C6})
DRV - [2012.06.20 17:35:49 | 000,083,704 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys -- (ntk_PowerDVD12)
DRV - [2012.05.02 07:35:23 | 000,138,360 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2012.04.30 18:45:28 | 000,066,320 | ---- | M] (Emsisoft GmbH) [File_System | On_Demand | Running] -- C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys -- (a2acc)
DRV - [2012.04.30 18:45:00 | 000,044,688 | ---- | M] (Emsisoft GmbH) [File_System | System | Running] -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys -- (a2injectiondriver)
DRV - [2011.08.07 23:58:26 | 000,021,712 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\DrvAgent64.SYS -- (DrvAgent64)
DRV - [2011.07.29 13:54:56 | 000,014,216 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\epmntdrv.sys -- (epmntdrv)
DRV - [2011.07.29 13:54:56 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2011.07.08 17:53:24 | 000,032,104 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Programme\Lenovo\RapidBoot\PHCORE64.sys -- (PHCORE)
DRV - [2011.06.02 10:08:34 | 000,017,864 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys -- (cpudrv64)
DRV - [2011.05.19 14:10:34 | 000,023,208 | ---- | M] (Emsi Software GmbH) [Kernel | System | Running] -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys -- (A2DDA)
DRV - [2010.07.02 01:11:24 | 000,012,352 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Programme\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV - [2010.05.05 09:40:54 | 000,014,720 | ---- | M] (Emsi Software GmbH) [Kernel | System | Running] -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys -- (a2util)
DRV - [2009.07.14 09:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = CC 63 4A 6F 44 9C CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGNI_deTW475
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Amazon.de"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.spiegel.de/"
FF - prefs.js..extensions.enabledAddons: adblockpopups%40jessehakanen.net:0.5
FF - prefs.js..extensions.enabledAddons: facebook%40disconnect.me:2.1.3
FF - prefs.js..extensions.enabledAddons: firefox%40ghostery.com:2.8.3
FF - prefs.js..extensions.enabledAddons: ich%40maltegoetz.de:1.4.3
FF - prefs.js..extensions.enabledAddons: mandarinpopup%40gmail.com:0.7
FF - prefs.js..extensions.enabledAddons: toolbar%40qipu.de:1.8.8
FF - prefs.js..extensions.enabledAddons: %7B1280606b-2510-4fe0-97ef-9b5a22eafe30%7D:0.7.9.1
FF - prefs.js..extensions.enabledAddons: %7B1BC9BA34-1EED-42ca-A505-6D2F1A935BBB%7D:4.1.3.1
FF - prefs.js..extensions.enabledAddons: %7B4BBDD651-70CF-4821-84F8-2B918CF89CA3%7D:7.0.3.5
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20120926
FF - prefs.js..extensions.enabledAddons: %7Bd40f5e7b-d2cf-4856-b441-cc613eeffbe3%7D:1.68
FF - prefs.js..extensions.enabledAddons: %7BD4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389%7D:0.9.10
FF - prefs.js..extensions.enabledAddons: %7BDDC359D1-844A-42a7-9AA1-88A850A938A8%7D:2.0.15
FF - prefs.js..extensions.enabledAddons: %7B8AA36F4F-6DC7-4c06-77AF-5035170634FE%7D:2012.09.13
FF - prefs.js..extensions.enabledAddons: %7B23fcfd51-4958-4f00-80a3-ae97e717ed8b%7D:2.1.2.145
FF - prefs.js..extensions.enabledAddons: web2pdfextension%40web2pdf.adobedotcom:2.0
FF - prefs.js..extensions.enabledAddons: fastdial%40telega.phpnet.us:4.3.1
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.12
FF - prefs.js..extensions.enabledAddons: foxyproxy%40eric.h.jung:4.1
FF - prefs.js..extensions.enabledAddons: %7B46551EC9-40F0-4e47-8E18-8E5CF550CFB8%7D:1.3.1
FF - prefs.js..extensions.enabledAddons: %7Bd37dc5d0-431d-44e5-8c91-49419370caa1%7D:3.1.26
FF - prefs.js..extensions.enabledAddons: %7B3112ca9c-de6d-4884-a869-9855de68056c%7D:7.1.20110512W
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0037-ABCDEFFEDCBA%7D:6.0.37
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0
FF - prefs.js..network.proxy.socks_remote_dns: true
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.0-git-20120217-1212: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeExManDetect: C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeExManDetect: C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Yannick\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll File not found
FF - HKCU\Software\MozillaPlugins\@torrentstream.net/tsplugin,version=2.0.4.1: C:\Users\Yannick\AppData\Roaming\TorrentStream\player\npts_plugin.dll (Innovative Digital Technologies)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}: C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2011.08.09 03:47:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.12.26 23:35:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{09F060FA-566D-42D7-BF79-97AB30863433}: C:\Program Files (x86)\Steganos Privacy Suite 12\pfplugin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{00F0643E-B367-4779-B45D-7046EBA37A88}: C:\Program Files (x86)\Steganos Privacy Suite 12\spmplugin3
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2012.11.08 00:01:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}: C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ [2012.12.18 14:54:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.01.09 13:43:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\magicplayer@torrentstream.org: C:\Users\Yannick\AppData\Roaming\TorrentStream\extensions\firefox\magicplayer@torrentstream.org [2012.12.08 23:01:45 | 000,000,000 | ---D | M]
[2012.09.06 19:12:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Yannick\AppData\Roaming\mozilla\Extensions
[2012.12.17 13:02:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Yannick\AppData\Roaming\mozilla\Firefox\Profiles\pfi9wnut.default\extensions
[2012.09.06 20:09:52 | 000,000,000 | ---D | M] (IE Tab 2 (FF 3.6+)) -- C:\Users\Yannick\AppData\Roaming\mozilla\Firefox\Profiles\pfi9wnut.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}
[2012.09.06 20:05:01 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\Yannick\AppData\Roaming\mozilla\Firefox\Profiles\pfi9wnut.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2012.09.06 19:40:20 | 000,000,000 | ---D | M] (FEBE) -- C:\Users\Yannick\AppData\Roaming\mozilla\Firefox\Profiles\pfi9wnut.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
[2012.10.04 11:11:05 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Yannick\AppData\Roaming\mozilla\Firefox\Profiles\pfi9wnut.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2012.11.22 21:30:48 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Yannick\AppData\Roaming\mozilla\Firefox\Profiles\pfi9wnut.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.09.20 16:54:28 | 000,000,000 | ---D | M] (FoxClocks) -- C:\Users\Yannick\AppData\Roaming\mozilla\Firefox\Profiles\pfi9wnut.default\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
[2012.11.22 21:30:53 | 000,000,000 | ---D | M] (Fast Dial) -- C:\Users\Yannick\AppData\Roaming\mozilla\Firefox\Profiles\pfi9wnut.default\extensions\fastdial@telega.phpnet.us
[2012.09.20 16:54:08 | 000,000,000 | ---D | M] (Ghostery) -- C:\Users\Yannick\AppData\Roaming\mozilla\Firefox\Profiles\pfi9wnut.default\extensions\firefox@ghostery.com
[2012.11.23 21:28:49 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Users\Yannick\AppData\Roaming\mozilla\Firefox\Profiles\pfi9wnut.default\extensions\foxyproxy@eric.h.jung
[2012.09.16 01:48:31 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Yannick\AppData\Roaming\mozilla\Firefox\Profiles\pfi9wnut.default\extensions\ich@maltegoetz.de
[2012.09.06 20:11:16 | 000,000,000 | ---D | M] (Mandarin Popup) -- C:\Users\Yannick\AppData\Roaming\mozilla\Firefox\Profiles\pfi9wnut.default\extensions\mandarinpopup@gmail.com
[2012.11.17 13:56:21 | 000,124,993 | ---- | M] () (No name found) -- C:\Users\Yannick\AppData\Roaming\mozilla\firefox\profiles\pfi9wnut.default\extensions\adblockpopups@jessehakanen.net.xpi
[2012.09.06 20:04:38 | 000,003,679 | ---- | M] () (No name found) -- C:\Users\Yannick\AppData\Roaming\mozilla\firefox\profiles\pfi9wnut.default\extensions\check-compatibility@dactyl.googlecode.com.xpi
[2012.09.06 19:20:46 | 000,088,614 | ---- | M] () (No name found) -- C:\Users\Yannick\AppData\Roaming\mozilla\firefox\profiles\pfi9wnut.default\extensions\extension@ciuvo.com.xpi
[2012.09.06 19:53:57 | 000,035,735 | ---- | M] () (No name found) -- C:\Users\Yannick\AppData\Roaming\mozilla\firefox\profiles\pfi9wnut.default\extensions\facebook@disconnect.me.xpi
[2012.10.17 01:07:24 | 000,091,945 | ---- | M] () (No name found) -- C:\Users\Yannick\AppData\Roaming\mozilla\firefox\profiles\pfi9wnut.default\extensions\toolbar@qipu.de.xpi
[2012.10.08 15:51:38 | 000,506,361 | ---- | M] () (No name found) -- C:\Users\Yannick\AppData\Roaming\mozilla\firefox\profiles\pfi9wnut.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi
[2012.11.26 23:11:28 | 000,269,905 | ---- | M] () (No name found) -- C:\Users\Yannick\AppData\Roaming\mozilla\firefox\profiles\pfi9wnut.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
[2012.11.23 19:25:43 | 000,035,614 | ---- | M] () (No name found) -- C:\Users\Yannick\AppData\Roaming\mozilla\firefox\profiles\pfi9wnut.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
[2012.11.23 19:25:48 | 000,804,627 | ---- | M] () (No name found) -- C:\Users\Yannick\AppData\Roaming\mozilla\firefox\profiles\pfi9wnut.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012.09.06 19:30:44 | 000,138,614 | ---- | M] () (No name found) -- C:\Users\Yannick\AppData\Roaming\mozilla\firefox\profiles\pfi9wnut.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
[2012.09.06 19:19:10 | 000,434,392 | ---- | M] () (No name found) -- C:\Users\Yannick\AppData\Roaming\mozilla\firefox\profiles\pfi9wnut.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2012.09.14 01:35:24 | 000,698,867 | ---- | M] () (No name found) -- C:\Users\Yannick\AppData\Roaming\mozilla\firefox\profiles\pfi9wnut.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2013.01.09 13:43:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2013.01.09 13:43:46 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012.11.08 00:01:13 | 000,000,000 | ---D | M] (Adobe Acrobat - Create PDF) -- C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 11.0\ACROBAT\BROWSER\WCFIREFOXEXTN
[2011.12.26 23:35:30 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2011.08.09 03:47:48 | 000,000,000 | ---D | M] (Citavi Picker) -- C:\PROGRAMDATA\SWISS ACADEMIC SOFTWARE\CITAVI PICKER\FIREFOX
[2013.01.09 13:43:55 | 000,262,704 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.10.12 14:14:01 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.10.12 14:14:01 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.10.12 14:14:01 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.10.12 14:14:01 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.10.12 14:14:01 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.10.12 14:14:01 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2012.12.10 15:50:10 | 000,448,429 | -H-- | M]) - C:\Windows\SysNative\drivers\etc\hosts
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
O1 - Hosts: 15399 more lines...
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (no name) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No CLSID value found.
O2 - BHO: (Ghostery Add-On) - {237EB6DA-3FEA-4DD2-8A61-A901B5C489D7} - C:\Program Files (x86)\GhosteryIEplugin\GhosteryBrowserHelperObject.dll ()
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe Acrobat Create PDF Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe Acrobat Create PDF from Selection) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe Acrobat Create PDF Toolbar) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe Acrobat Create PDF Toolbar) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [ForteConfig] C:\Programme\CONEXANT\ForteConfig\fmapp.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LENOVO.TPKNRRES] C:\Programme\Lenovo\Communications Utility\TpKnrres.exe (Lenovo Group Limited)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [TpShocks] C:\Windows\SysNative\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [emsisoft anti-malware] c:\program files (x86)\emsisoft anti-malware\a2guard.exe (Emsisoft GmbH)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor File not found
O4 - HKLM..\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe (Ricoh co.,Ltd.)
O4 - HKCU..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKCU..\Run: [Clock Widget (HTC Home)] C:\Program Files (x86)\HTC Home\Clock.exe ()
O4 - HKCU..\Run: [FileHippo.com] C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe (FileHippo.com)
O4 - HKCU..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O4 - HKCU..\Run: [Rainlendar2] C:\Programme\Rainlendar2\Rainlendar2.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O8:64bit: - Extra context menu item: An vorhandene PDF-Datei anfügen - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html File not found
O8:64bit: - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Yannick\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Yannick\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: In Adobe PDF konvertieren - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html File not found
O8:64bit: - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found
O8:64bit: - Extra context menu item: Linkziel in Adobe PDF konvertieren - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html File not found
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\Yannick\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Yannick\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html File not found
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Ghostery - {237EB6DA-3FEA-4DD2-8A61-A901B5C489D7} - C:\Program Files (x86)\GhosteryIEplugin\GhosteryBrowserHelperObject.dll ()
O9 - Extra Button: Senden an Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Senden an &Bluetooth-Gerät... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {10000000-1000-1000-1000-100000000000} hxxp://cdn.betteradvertising.com/ghostery/addons/ie/2.4.2.0/ghostery.cab (Reg Error: Value error.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {816BE035-1450-40D0-8A3B-BA7825A83A77} hxxp://support.lenovo.com/Resources/Lenovo/AutoDetect/Lenovo_AutoDetect2.cab (IASRunner Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab (Java Plug-in 10.9.2)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab (Java Plug-in 1.7.0_04)
O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab (Java Plug-in 1.7.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 10.9.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F81308E-3037-4152-B565-0F43FFFE7ECC}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E7206F6F-4164-4DD4-BEC6-8F3F8F737997}: DhcpNameServer = 140.119.1.110 140.119.252.12 168.95.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Handler\wot - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
O18:64bit: - Protocol\Filter\text/html - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/html {4459DC76-1FDE-4B16-BAD0-E4F8E7647555} - C:\Program Files (x86)\GhosteryIEplugin\GhosteryMimeFilter.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll (Microsoft Corporation)
O27:64bit: - HKLM IFEO\taskmgr.exe: Debugger - C:\Program Files (x86)\System Explorer\SystemExplorer.exe (Mister Group)
O27 - HKLM IFEO\taskmgr.exe: Debugger - C:\Program Files (x86)\System Explorer\SystemExplorer.exe (Mister Group)
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (sdnclean64.exe)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.01.12 03:43:08 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Yannick\Desktop\OTL.exe
[2013.01.12 02:33:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013.01.12 02:33:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2013.01.12 02:33:43 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2013.01.11 02:47:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MyMDb
[2013.01.11 01:59:15 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Adobe
[2013.01.09 21:05:02 | 000,000,000 | ---D | C] -- C:\Users\Yannick\Desktop\Music
[2013.01.09 13:43:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013.01.09 02:19:56 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\CrashDump
[2013.01.07 03:46:58 | 000,203,104 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudobex.sys
[2013.01.07 03:46:58 | 000,203,104 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudmdm.sys
[2013.01.07 03:46:58 | 000,102,368 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudbus.sys
[2013.01.07 03:46:24 | 000,000,000 | ---D | C] -- C:\Program Files\SAMSUNG
[2012.12.23 17:01:24 | 000,000,000 | ---D | C] -- C:\Users\Yannick\AppData\Roaming\vlc
[2012.12.23 17:00:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012.12.18 14:57:09 | 000,000,000 | ---D | C] -- C:\Users\Yannick\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.12.18 14:54:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DVDVideoSoft
[2012.12.18 14:54:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DVDVideoSoft
[2012.12.14 18:41:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Python
[2011.02.24 06:10:36 | 000,020,432 | ---- | C] (Intel Corporation) -- C:\Users\Yannick\AppData\Roaming\JomCap.dll
[2007.08.13 17:46:00 | 000,102,912 | ---- | C] (Albert L Faber) -- C:\Users\Yannick\AppData\Local\CDRip.dll
[2007.01.18 21:09:54 | 000,623,616 | ---- | C] (Ivan Bischof ©2003 - 2005) -- C:\Users\Yannick\AppData\Local\No23 Recorder.exe
[2006.12.11 19:13:14 | 000,013,872 | ---- | C] (Un4seen Developments) -- C:\Users\Yannick\AppData\Local\basscd.dll
[2006.12.11 19:13:12 | 000,097,336 | ---- | C] (Un4seen Developments) -- C:\Users\Yannick\AppData\Local\bass.dll
[1 C:\Users\Yannick\Desktop\*.tmp files -> C:\Users\Yannick\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.01.12 04:27:29 | 000,000,029 | ---- | M] () -- C:\Windows\SysWow64\TempWmicBatchFile.bat
[2013.01.12 04:26:09 | 000,365,568 | ---- | M] () -- C:\Users\Yannick\Desktop\gmer-2.0.18444.exe
[2013.01.12 03:54:53 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.01.12 03:43:09 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Yannick\Desktop\OTL.exe
[2013.01.12 03:42:58 | 000,050,477 | ---- | M] () -- C:\Users\Yannick\Desktop\Defogger.exe
[2013.01.11 23:12:43 | 000,002,019 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2013.01.11 22:36:07 | 000,020,704 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.01.11 22:36:07 | 000,020,704 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.01.11 22:27:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.01.11 22:27:04 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\lvuvc.hs
[2013.01.11 22:27:02 | 467,062,783 | -HS- | M] () -- C:\hiberfil.sys
[2013.01.11 02:47:13 | 000,000,963 | ---- | M] () -- C:\Users\Public\Desktop\MyMDb.lnk
[2013.01.10 20:08:32 | 002,151,050 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.01.10 20:08:32 | 000,715,384 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.01.10 20:08:32 | 000,655,264 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.01.10 20:08:32 | 000,395,124 | ---- | M] () -- C:\Windows\SysNative\prfh0404.dat
[2013.01.10 20:08:32 | 000,154,092 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.01.10 20:08:32 | 000,122,136 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.01.10 20:08:32 | 000,115,082 | ---- | M] () -- C:\Windows\SysNative\prfc0404.dat
[2013.01.09 13:40:30 | 004,966,848 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.01.09 11:12:01 | 002,125,140 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.01.04 03:44:48 | 000,000,132 | ---- | M] () -- C:\Users\Yannick\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
[2013.01.04 01:56:24 | 000,156,681 | ---- | M] () -- E:\Eigene Dokumente\26 key indicator.jpg
[2012.12.28 14:41:26 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.12.23 17:08:24 | 000,000,866 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.12.18 14:57:02 | 000,001,239 | ---- | M] () -- C:\Users\Yannick\Desktop\DVDVideoSoft Free Studio.lnk
[2012.12.14 22:45:22 | 000,120,844 | -H-- | M] () -- C:\Windows\SysWow64\mlfcache.dat
[2012.12.14 20:13:00 | 001,019,974 | ---- | M] () -- E:\Eigene Dokumente\Privilegiert.pdf
[2012.12.14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.12.13 21:45:00 | 004,359,140 | ---- | M] () -- E:\Eigene Dokumente\SCAN_USI_20121213_1255.pdf
[2012.12.13 17:52:43 | 008,525,792 | ---- | M] () -- E:\Eigene Dokumente\800+8000zhuyin.rar
[1 C:\Users\Yannick\Desktop\*.tmp files -> C:\Users\Yannick\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.01.12 04:26:09 | 000,365,568 | ---- | C] () -- C:\Users\Yannick\Desktop\gmer-2.0.18444.exe
[2013.01.12 03:42:55 | 000,050,477 | ---- | C] () -- C:\Users\Yannick\Desktop\Defogger.exe
[2013.01.11 23:12:43 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013.01.11 23:12:43 | 000,002,019 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2013.01.11 02:47:13 | 000,000,963 | ---- | C] () -- C:\Users\Public\Desktop\MyMDb.lnk
[2013.01.11 01:44:32 | 000,001,245 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Audition CS6.lnk
[2013.01.11 01:43:23 | 000,001,530 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk
[2013.01.11 01:42:36 | 000,000,997 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2013.01.04 01:56:24 | 000,156,681 | ---- | C] () -- E:\Eigene Dokumente\26 key indicator.jpg
[2012.12.18 14:57:02 | 000,001,239 | ---- | C] () -- C:\Users\Yannick\Desktop\DVDVideoSoft Free Studio.lnk
[2012.12.14 20:13:00 | 001,019,974 | ---- | C] () -- E:\Eigene Dokumente\Privilegiert.pdf
[2012.12.13 21:45:00 | 004,359,140 | ---- | C] () -- E:\Eigene Dokumente\SCAN_USI_20121213_1255.pdf
[2012.12.13 17:52:26 | 008,525,792 | ---- | C] () -- E:\Eigene Dokumente\800+8000zhuyin.rar
[2012.12.05 13:38:53 | 000,065,536 | -H-- | C] () -- C:\Windows\SysWow64\WebCamLib.dll
[2012.11.14 13:57:47 | 000,001,456 | ---- | C] () -- C:\Users\Yannick\AppData\Local\RecConfig.xml
[2012.10.22 23:55:16 | 000,062,016 | ---- | C] () -- C:\Windows\SysWow64\drivers\oahlp64.sys
[2012.10.22 23:55:16 | 000,061,632 | ---- | C] () -- C:\Windows\SysWow64\drivers\OADriver.sys
[2012.10.16 01:07:45 | 000,870,683 | ---- | C] () -- C:\Windows\PlagiarismFinder 2.1 Uninstaller.exe
[2012.10.14 02:46:37 | 000,000,032 | ---- | C] () -- C:\Windows\CD_Start.INI
[2012.10.10 13:53:57 | 000,000,132 | ---- | C] () -- C:\Users\Yannick\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
[2012.09.13 15:10:59 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.09.13 15:10:59 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.09.13 15:10:56 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2012.08.12 22:03:02 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2012.05.24 00:49:34 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012.05.24 00:49:32 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2012.05.24 00:49:32 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2012.05.24 00:49:32 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2012.05.24 00:49:32 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2012.05.22 17:17:17 | 002,469,760 | ---- | C] () -- C:\Windows\SysWow64\BootMan.exe
[2012.05.22 17:17:17 | 000,086,408 | ---- | C] () -- C:\Windows\SysWow64\setupempdrv03.exe
[2012.05.22 17:17:17 | 000,019,840 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll
[2012.05.22 17:17:17 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys
[2012.05.22 17:17:17 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys
[2012.05.14 21:11:37 | 000,000,020 | ---- | C] () -- C:\Users\Yannick\defogger_reenable
[2012.04.21 21:00:25 | 000,000,911 | ---- | C] () -- C:\Users\Yannick\AppData\Roaming\coreavc.ini
[2012.04.06 09:37:35 | 000,000,021 | ---- | C] () -- C:\Windows\SysWow64\STGRAMDiskHandler64.ini
[2012.04.05 13:16:52 | 000,005,941 | ---- | C] () -- C:\Windows\wininit.ini
[2012.03.09 01:26:20 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2012.03.03 19:44:25 | 000,008,192 | ---- | C] () -- C:\Windows\d3dx.dat
[2012.01.31 07:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012.01.20 15:10:52 | 000,311,296 | ---- | C] () -- C:\Windows\SysWow64\EMRegSys.dll
[2012.01.18 06:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2012.01.18 06:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2012.01.18 06:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2012.01.05 18:59:20 | 000,216,000 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2012.01.05 18:59:19 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012.01.05 18:59:16 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011.12.17 13:10:14 | 000,110,080 | ---- | C] () -- C:\Windows\SysWow64\advd.dll
[2011.12.17 13:10:14 | 000,023,040 | ---- | C] () -- C:\Windows\SysWow64\auth.dll
[2011.12.17 13:10:12 | 000,237,568 | ---- | C] () -- C:\Windows\SysWow64\lame_enc.dll
[2011.12.07 21:20:12 | 000,000,079 | ---- | C] () -- C:\Users\Yannick\AppData\Local\CrystalDiskMark30.ini
[2011.11.02 23:58:58 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2011.10.31 01:27:10 | 000,000,021 | ---- | C] () -- C:\Windows\SurCode.INI
[2011.10.27 16:16:59 | 000,000,030 | ---- | C] () -- C:\Program Files (x86)\Exiferupdate.ini
[2011.10.05 00:24:28 | 000,017,408 | ---- | C] () -- C:\Users\Yannick\AppData\Local\WebpageIcons.db
[2011.09.27 19:30:08 | 000,000,024 | -H-- | C] () -- C:\Users\Yannick\AppData\Roaming\xpy.ini
[2011.09.22 21:43:49 | 002,125,140 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.09.18 01:36:07 | 000,003,584 | ---- | C] () -- C:\Users\Yannick\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.08.21 22:21:03 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.08.14 23:42:55 | 000,032,204 | ---- | C] () -- C:\Users\Yannick\energy-report.html
[2011.08.12 02:13:55 | 000,120,844 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011.08.09 18:43:05 | 000,000,020 | ---- | C] () -- C:\Windows\mafosav.INI
[2011.08.09 18:36:25 | 000,000,132 | ---- | C] () -- C:\Users\Yannick\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011.08.06 22:44:07 | 000,834,056 | ---- | C] () -- C:\Windows\SysWow64\sig.bin
[2011.08.06 06:52:12 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.08.06 05:43:55 | 000,002,975 | ---- | C] () -- C:\Windows\SysWow64\atipblup.dat
[2011.08.06 05:42:28 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.08.06 05:42:26 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2007.08.13 17:46:00 | 000,155,136 | ---- | C] () -- C:\Users\Yannick\AppData\Local\lame_enc.dll
[2006.10.26 01:06:48 | 000,064,000 | ---- | C] () -- C:\Users\Yannick\AppData\Local\vorbisenc.dll
[2006.10.26 01:06:48 | 000,019,456 | ---- | C] () -- C:\Users\Yannick\AppData\Local\vorbisfile.dll
[2006.10.26 01:06:46 | 000,143,872 | ---- | C] () -- C:\Users\Yannick\AppData\Local\vorbis.dll
[2006.10.26 01:06:36 | 000,015,872 | ---- | C] () -- C:\Users\Yannick\AppData\Local\ogg.dll
[2005.08.23 22:34:06 | 000,029,184 | ---- | C] () -- C:\Users\Yannick\AppData\Local\no23xwrapper.dll
========== ZeroAccess Check ==========
[2009.07.14 12:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 13:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 12:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012.08.21 21:11:31 | 000,857,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012.08.21 21:37:44 | 000,636,928 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012.08.21 21:08:38 | 000,453,120 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012.12.08 23:23:24 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\.Torrent Stream
[2011.12.06 15:50:34 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\ActiveState
[2012.09.13 04:07:07 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Amazon
[2012.12.05 13:38:53 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Apowersoft
[2012.07.14 16:24:19 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Applied Recognition Inc
[2011.12.11 17:56:24 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\ASCOMP Software
[2012.03.16 08:48:07 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Avant Downloader
[2012.01.20 13:03:24 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012.07.14 16:24:02 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\com.appliedrec.Fotobounce
[2011.12.17 13:10:28 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\concept design
[2012.04.02 07:35:04 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\CrystalIdea Software
[2012.10.15 14:28:54 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\DAEMON Tools Lite
[2013.01.07 15:35:15 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Dropbox
[2012.12.18 14:57:09 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\DVDVideoSoft
[2012.12.18 14:57:10 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.04.07 19:50:32 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Engelmann Media
[2012.10.22 12:43:40 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\EurekaLog
[2011.12.09 23:25:29 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\FreeHideIP
[2012.09.26 02:05:40 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\G Data
[2012.11.07 22:48:02 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\GetRightToGo
[2011.08.07 21:42:07 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\GlarySoft
[2012.06.12 16:29:33 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\IObit
[2011.09.01 18:42:24 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\IrfanView
[2011.08.09 17:55:43 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Jens Lorek
[2012.10.30 20:50:33 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Juniper Networks
[2012.04.07 19:05:25 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\KC Softwares
[2011.08.30 19:40:12 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\KeePass
[2012.03.01 00:11:38 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\KKman
[2011.12.09 23:27:49 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\LCARS Terminal
[2011.08.08 07:58:19 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Leadertech
[2011.11.03 14:11:19 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\LEAPS
[2012.02.27 14:43:03 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Lingo4u
[2012.05.24 19:15:52 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\LSC
[2011.08.06 22:00:26 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Miranda Fusion
[2013.01.12 02:51:39 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Mp3tag
[2011.11.27 23:41:46 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\MPTagThat
[2011.09.10 13:52:55 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\NetSpeedMonitor
[2011.12.02 10:29:23 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Nik Software
[2012.09.23 02:21:00 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Nokia
[2011.09.24 12:15:35 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Nokia Ovi Suite
[2012.10.22 23:57:12 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\OnlineArmor
[2011.10.31 01:27:10 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\PACE Anti-Piracy
[2011.09.24 12:05:15 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\PC Suite
[2011.11.03 14:05:58 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Pegasys Inc
[2011.10.27 15:03:39 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\PhotoScape
[2012.10.16 01:08:11 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\PlagiarismFinder
[2011.11.28 18:47:12 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Publish Providers
[2011.08.06 06:32:30 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\PwrMgr
[2012.10.06 16:06:28 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Samsung
[2011.10.17 16:05:47 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Sinvise Systems
[2012.11.28 00:20:44 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\SolidDocuments
[2012.03.24 22:20:12 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Sony
[2011.08.09 18:28:39 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012.04.06 14:21:28 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Steganos
[2012.06.16 01:15:26 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\StreamTorrent
[2012.06.22 16:19:12 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Swiss Academic Software
[2012.12.08 21:41:26 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\TeamViewer
[2012.12.09 04:41:24 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\TechSmith
[2012.02.25 13:41:47 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\TeraCopy
[2012.02.06 03:12:43 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\VitySoft
[2012.04.02 07:11:35 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\WinPatrol
[2011.09.22 23:00:11 | 000,000,000 | ---D | M] -- C:\Users\Yannick\AppData\Roaming\Youtube Downloader HD
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2012.12.14 23:34:27 | 000,000,000 | ---D | M](E:\Eigene Dokumente\????) -- E:\Eigene Dokumente\政治大學
[2012.11.04 14:51:22 | 001,607,995 | ---- | M] ()(C:\Users\****\Desktop\??????.jpg) -- C:\Users\Yannick\Desktop\台北捷運地圖.jpg
[2012.11.04 14:51:21 | 001,607,995 | ---- | C] ()(C:\Users\****\Desktop\??????.jpg) -- C:\Users\Yannick\Desktop\台北捷運地圖.jpg
[2012.10.23 01:20:13 | 000,018,090 | ---- | M] ()(E:\Eigene Dokumente\??? - ??????2(?).docx) -- E:\Eigene Dokumente\*** - 台灣政治作業2(修).docx
[2012.10.23 00:23:00 | 000,018,090 | ---- | C] ()(E:\Eigene Dokumente\??? - ??????2(?).docx) -- E:\Eigene Dokumente\*** - 台灣政治作業2(修).docx
[2012.10.22 20:12:13 | 000,647,038 | ---- | M] ()(E:\Eigene Dokumente\????????????.pdf) -- E:\Eigene Dokumente\從憲法觀點論生命權之保障.pdf
[2012.10.22 20:12:13 | 000,647,038 | ---- | C] ()(E:\Eigene Dokumente\????????????.pdf) -- E:\Eigene Dokumente\從憲法觀點論生命權之保障.pdf
[2012.10.08 22:55:00 | 000,017,601 | ---- | M] ()(E:\Eigene Dokumente\??? - ??????1(?).docx) -- E:\Eigene Dokumente\*** - 台灣政治作業1(修).docx
[2012.10.08 22:55:00 | 000,017,601 | ---- | C] ()(E:\Eigene Dokumente\??? - ??????1(?).docx) -- E:\Eigene Dokumente\*** - 台灣政治作業1(修).docx
[2012.10.07 16:17:34 | 000,133,344 | ---- | M] ()(E:\Eigene Dokumente\7net????.pdf) -- E:\Eigene Dokumente\7net雲端超商.pdf
[2012.10.07 16:17:34 | 000,133,344 | ---- | C] ()(E:\Eigene Dokumente\7net????.pdf) -- E:\Eigene Dokumente\7net雲端超商.pdf
[2012.09.25 13:22:07 | 003,897,528 | ---- | M] ()(E:\Eigene Dokumente\??? 100-101.pdf) -- E:\Eigene Dokumente\成績單 100-101.pdf
[2012.09.25 13:22:07 | 003,897,528 | ---- | C] ()(E:\Eigene Dokumente\??? 100-101.pdf) -- E:\Eigene Dokumente\成績單 100-101.pdf
[2012.09.06 00:00:00 | 000,047,115 | ---- | M] ()(E:\Eigene Dokumente\101-1 ??.pdf) -- E:\Eigene Dokumente\101-1 課表.pdf
[2012.09.06 00:00:00 | 000,047,115 | ---- | C] ()(E:\Eigene Dokumente\101-1 ??.pdf) -- E:\Eigene Dokumente\101-1 課表.pdf
[2012.07.20 23:59:00 | 000,099,328 | ---- | M] ()(E:\Eigene Dokumente\???? - ???.doc) -- E:\Eigene Dokumente\期末報告 - 中文版.doc
[2012.07.20 23:58:25 | 000,099,328 | ---- | C] ()(E:\Eigene Dokumente\???? - ???.doc) -- E:\Eigene Dokumente\期末報告 - 中文版.doc
[2012.07.07 21:33:54 | 000,227,068 | ---- | M] ()(E:\Eigene Dokumente\?????.pdf) -- E:\Eigene Dokumente\列印登機證.pdf
[2012.07.07 21:33:54 | 000,227,068 | ---- | C] ()(E:\Eigene Dokumente\?????.pdf) -- E:\Eigene Dokumente\列印登機證.pdf
[2012.06.28 16:37:24 | 000,113,052 | ---- | M] ()(E:\Eigene Dokumente\???????--ISIC?????.pdf) -- E:\Eigene Dokumente\康文文教基金會--ISIC國際學生證.pdf
[2012.06.28 16:37:24 | 000,113,052 | ---- | C] ()(E:\Eigene Dokumente\???????--ISIC?????.pdf) -- E:\Eigene Dokumente\康文文教基金會--ISIC國際學生證.pdf
[2012.06.26 22:04:09 | 000,014,850 | ---- | M] ()(E:\Eigene Dokumente\??.docx) -- E:\Eigene Dokumente\**.docx
[2012.06.26 19:48:47 | 000,014,850 | ---- | C] ()(E:\Eigene Dokumente\??.docx) -- E:\Eigene Dokumente\**.docx
[2012.04.12 14:57:09 | 000,298,006 | ---- | M] ()(E:\Eigene Dokumente\momo ????? -????1.pdf) -- E:\Eigene Dokumente\momo 富邦購物網 -訂購完成1.pdf
[2012.04.12 14:57:09 | 000,298,006 | ---- | C] ()(E:\Eigene Dokumente\momo ????? -????1.pdf) -- E:\Eigene Dokumente\momo 富邦購物網 -訂購完成1.pdf
[2012.02.24 12:52:32 | 000,303,518 | ---- | M] ()(E:\Eigene Dokumente\momo ????? -????.pdf) -- E:\Eigene Dokumente\momo 富邦購物網 -訂購完成.pdf
[2012.02.24 12:52:32 | 000,303,518 | ---- | C] ()(E:\Eigene Dokumente\momo ????? -????.pdf) -- E:\Eigene Dokumente\momo 富邦購物網 -訂購完成.pdf
[2012.02.20 00:16:12 | 000,146,948 | ---- | C] ()(E:\Eigene Dokumente\??? - ??.pdf) -- E:\Eigene Dokumente\*** - 履歷.pdf
[2012.02.20 00:15:04 | 000,146,948 | ---- | M] ()(E:\Eigene Dokumente\??? - ??.pdf) -- E:\Eigene Dokumente\*** - 履歷.pdf
[2012.02.07 13:10:47 | 000,272,752 | ---- | M] ()(E:\Eigene Dokumente\??????-????.pdf) -- E:\Eigene Dokumente\國際個人機票-交易完成.pdf
[2012.02.07 13:10:47 | 000,272,752 | ---- | C] ()(E:\Eigene Dokumente\??????-????.pdf) -- E:\Eigene Dokumente\國際個人機票-交易完成.pdf
[2011.11.08 23:49:05 | 000,038,912 | ---- | M] ()(E:\Eigene Dokumente\???-????.doc) -- E:\Eigene Dokumente\五月天-軋車歌詞.doc
[2011.11.08 23:49:00 | 000,038,912 | ---- | C] ()(E:\Eigene Dokumente\???-????.doc) -- E:\Eigene Dokumente\五月天-軋車歌詞.doc
[2011.09.13 17:53:13 | 000,001,100 | ---- | M] ()(C:\Users\Yannick\Desktop\????.lnk) -- C:\Users\Yannick\Desktop\**大學.lnk
[2011.08.19 20:51:08 | 000,001,100 | ---- | C] ()(C:\Users\Yannick\Desktop\????.lnk) -- C:\Users\Yannick\Desktop\**大學.lnk
[2011.08.11 17:33:32 | 000,000,000 | ---D | C](E:\Eigene Dokumente\????) -- E:\Eigene Dokumente\**大學
========== Alternate Data Streams ==========
@Alternate Data Stream - 1290 bytes -> C:\ProgramData\Microsoft:3JOoQbmUJD78MOdkCfoQAB
@Alternate Data Stream - 1225 bytes -> C:\Program Files\Common Files\Microsoft Shared:nsA3vPOfhGwJqkHerQmpUa
@Alternate Data Stream - 1089 bytes -> C:\ProgramData\Microsoft:MZUiocPID2CccJMBZ2ggdBah7
@Alternate Data Stream - 105 bytes -> C:\ProgramData\Temp:5C321E34
< End of report > Extras-Datei gab es irgendwie aus was für einem Grund auch immer nicht.
Schön, dass GMER jetzt auch unter 64bit läuft
GMER hat die maximale Länge des Posts erhöht, deshalb kann ich die Datei hier nicht als CODE posten, hänge deshalb an, falls ihr möchtet, dass ich sie in einem Reply nochmal poste, einfach Bescheid geben. |