Um die BackUp-Problematik weiß ich bescheid ;) Da werde ich mich bessern müssen! :killpc:
Ich habe die Anleitung befolgt und hat auch alles soweit geklappt - allerdings wurde mir keine Extra.txt erstellt. Hier also der Inhalt von OTL.txt: Code:
OTL logfile created on: 1/30/2013 2:58:57 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
64bit-Windows 7 Home Premium (Version = 6.1.7600) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 90.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\Windows | %ProgramFiles% = D:\Program Files (x86)
Drive C: | 100.00 Mb Total Space | 75.86 Mb Free Space | 75.86% Space Free | Partition Type: NTFS
Drive D: | 906.34 Gb Total Space | 508.14 Gb Free Space | 56.07% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011/03/29 05:46:02 | 000,008,192 | ---- | M] () [Auto] -- D:\Program Files\mcShoutCast\mcShoutCastECommerceService.exe -- (mcShoutCastECommerceService)
SRV:64bit: - [2011/03/29 05:45:50 | 000,007,680 | ---- | M] (Sörnt Poppe) [Auto] -- D:\Program Files\mcShoutCast\ShoutCastLauraFMService.exe -- (mcShoutCastLauraFM)
SRV:64bit: - [2011/03/29 05:45:12 | 000,066,560 | ---- | M] (Sörnt Poppe) [Auto] -- D:\Program Files\mcShoutCast\ShoutCastProxyService.exe -- (mcShoutCastProxy)
SRV:64bit: - [2010/04/16 11:45:48 | 000,937,248 | ---- | M] (Broadcom Corporation.) [Auto] -- D:\Program Files\Lenovo\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2010/03/02 23:12:14 | 000,202,752 | ---- | M] (AMD) [Auto] -- D:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto] -- D:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012/10/23 18:11:29 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand] -- D:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/09/24 10:05:00 | 000,384,888 | ---- | M] (BlueStack Systems, Inc.) [Auto] -- D:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe -- (BstHdLogRotatorSvc)
SRV - [2012/09/24 10:04:32 | 000,393,080 | ---- | M] (BlueStack Systems, Inc.) [Auto] -- D:\Program Files (x86)\BlueStacks\HD-Service.exe -- (BstHdAndroidSvc)
SRV - [2012/05/01 18:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- D:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012/05/01 17:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- D:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012/02/16 08:02:22 | 000,087,368 | ---- | M] (Nero AG) [Auto] -- D:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe -- (DeviceMonitorService)
SRV - [2012/02/01 16:55:58 | 000,214,896 | ---- | M] () [Auto] -- D:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe -- (MotoHelper)
SRV - [2012/01/26 09:08:56 | 003,665,752 | ---- | M] () [Auto] -- D:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe -- (Radio.fx)
SRV - [2011/10/21 09:23:42 | 000,196,176 | ---- | M] (Microsoft Corporation.) [Auto] -- D:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/10/13 11:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto] -- D:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (BBUpdate)
SRV - [2011/08/29 07:35:40 | 000,645,048 | ---- | M] (Cisco Systems, Inc.) [Auto] -- D:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent)
SRV - [2011/08/28 13:48:39 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand] -- D:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/06/06 05:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- D:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/05/28 09:29:26 | 002,650,112 | ---- | M] (DATA BECKER GmbH & Co KG) [Auto] -- D:\Program Files (x86)\Common Files\DATA BECKER Shared\DBService.exe -- (DBService)
SRV - [2010/03/18 06:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- D:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 06:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- D:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- D:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/01/16 02:51:44 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto] -- D:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
SRV - [2007/05/31 11:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto] -- D:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 11:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto] -- D:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2007/01/04 12:48:50 | 000,112,152 | ---- | M] (InterVideo) [Auto] -- D:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/05/02 08:24:12 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System] -- D:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2012/04/27 03:20:04 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System] -- D:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012/04/24 17:32:27 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto] -- D:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012/01/25 07:58:02 | 000,027,136 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand] -- D:\Windows\System32\drivers\Motousbnet.sys -- (Motousbnet)
DRV:64bit: - [2012/01/25 07:57:50 | 000,030,720 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand] -- D:\Windows\System32\drivers\motmodem.sys -- (motmodem)
DRV:64bit: - [2012/01/25 07:57:46 | 000,009,728 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand] -- D:\Windows\System32\drivers\motccgpfl.sys -- (motccgpfl)
DRV:64bit: - [2012/01/25 07:57:38 | 000,022,016 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand] -- D:\Windows\System32\drivers\motccgp.sys -- (motccgp)
DRV:64bit: - [2011/12/06 04:26:34 | 000,014,760 | ---- | M] () [Kernel | Auto] -- D:\Windows\System32\drivers\DRHMSR64.sys -- (DRHMSR64)
DRV:64bit: - [2011/11/08 06:59:12 | 000,011,776 | ---- | M] (Motorola Inc) [Kernel | On_Demand] -- D:\Windows\System32\drivers\motusbdevice.sys -- (motusbdevice)
DRV:64bit: - [2011/11/03 11:05:38 | 000,021,984 | ---- | M] (Licensed for Gebhard Software) [Kernel | Auto] -- D:\Windows\System32\drivers\DRHARD64.sys -- (DRHARD64)
DRV:64bit: - [2011/11/02 20:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot] -- D:\Windows\System32\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2011/08/29 07:35:40 | 000,022,264 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\vpnva64.sys -- (vpnva)
DRV:64bit: - [2011/05/10 01:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2010/05/18 03:02:48 | 000,164,464 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\jmcr.sys -- (JMCR)
DRV:64bit: - [2010/05/07 00:24:22 | 000,237,440 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\vmc412.sys -- (VMC412)
DRV:64bit: - [2010/03/26 04:12:46 | 001,557,760 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\atinavrr.sys -- (ATIAVPCI)
DRV:64bit: - [2010/03/02 23:23:12 | 006,402,560 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\atipmdag.sys -- (amdkmdag)
DRV:64bit: - [2010/03/02 22:07:34 | 000,188,928 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/02/24 05:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto] -- D:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
DRV:64bit: - [2010/01/14 22:01:58 | 000,023,152 | ---- | M] (JMicron ) [Kernel | Boot] -- D:\Windows\System32\drivers\johci.sys -- (johci)
DRV:64bit: - [2009/11/06 05:56:06 | 001,550,848 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- D:\Windows\System32\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009/11/05 09:15:40 | 000,291,328 | ---- | M] (Realtek ) [Kernel | On_Demand] -- D:\Windows\System32\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/10/29 04:20:30 | 000,014,328 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand] -- D:\Windows\System32\drivers\hidkmdf.sys -- (hidkmdf)
DRV:64bit: - [2009/10/29 04:20:28 | 000,025,080 | ---- | M] () [Kernel | On_Demand] -- D:\Windows\System32\drivers\NW1950.sys -- (NW1950)
DRV:64bit: - [2009/07/21 07:20:06 | 000,121,840 | ---- | M] (CyberLink) [Kernel | On_Demand] -- D:\Windows\System32\drivers\wsvd.sys -- (wsvd)
DRV:64bit: - [2009/07/13 18:31:10 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2009/06/10 15:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- D:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\system32\DRIVERS\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\system32\DRIVERS\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- D:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/01/29 11:11:38 | 000,006,144 | ---- | M] (Motorola Inc) [Kernel | On_Demand] -- D:\Windows\System32\drivers\motfilt.sys -- (BTCFilterService)
DRV:64bit: - [2008/04/07 23:43:04 | 000,020,832 | ---- | M] (Nicomsoft Ltd.) [Kernel | Boot] -- D:\Windows\System32\drivers\ddcdrv.sys -- (WinI2C-DDC)
DRV:64bit: - [2007/11/02 09:52:02 | 000,008,576 | ---- | M] (Motorola) [Kernel | On_Demand] -- D:\Windows\System32\drivers\motswch.sys -- (MotoSwitchService)
DRV - [2012/09/24 10:04:50 | 000,071,032 | ---- | M] (BlueStack Systems) [Kernel | Auto] -- D:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys -- (BstHdDrv)
DRV - [2011/12/06 04:26:34 | 000,014,760 | ---- | M] () [Kernel | Auto] -- D:\Windows\SysWOW64\drivers\DRHMSR64.sys -- (DRHMSR64)
DRV - [2011/11/03 11:05:38 | 000,021,984 | ---- | M] (Licensed for Gebhard Software) [Kernel | Auto] -- D:\Windows\SysWOW64\drivers\DRHARD64.sys -- (DRHARD64)
DRV - [2010/03/22 11:13:08 | 000,015,712 | ---- | M] (Nicomsoft Ltd.) [Kernel | Boot] -- D:\Windows\SysWOW64\drivers\ddcdrv.sys -- (WinI2C-DDC)
DRV - [2004/04/01 09:30:46 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand] -- D:\Windows\SysWOW64\drivers\pfc.sys -- (pfc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Florian_ON_D\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ [binary data]
IE - HKU\Florian_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo.msn.com
IE - HKU\Florian_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Florian_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: D:\Windows\System32\Macromed\Flash\NPSWF64_11_4_402_287.dll ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: D:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: D:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=:
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin: D:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: D:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: D:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: D:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: D:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: D:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: D:\Users\Florian\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: D:\Users\Florian\AppData\Local\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: D:\Users\Florian\AppData\Local\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/12/10 09:20:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2012/10/30 13:27:41 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Florian\AppData\Roaming\Mozilla\Extensions
[2012/10/30 13:27:41 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Florian\AppData\Roaming\Mozilla\Extensions\{a79fe89b-6662-4ff4-8e88-09950ad4dfde}
[2012/11/16 14:35:54 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Florian\AppData\Roaming\Mozilla\Firefox\Profiles\apwxkz9e.default\extensions
[2012/10/31 11:15:50 | 000,000,000 | ---D | M] (Flash and Video Download) -- D:\Users\Florian\AppData\Roaming\Mozilla\Firefox\Profiles\apwxkz9e.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
[2012/03/21 16:58:01 | 000,000,000 | ---D | M] (scoyo Aussprachetool) -- D:\Users\Florian\AppData\Roaming\Mozilla\Firefox\Profiles\apwxkz9e.default\extensions\aussprachetool@scoyo.com
[2012/03/20 20:22:48 | 000,000,000 | ---D | M] (No name found) -- D:\Program Files (x86)\Mozilla Firefox\extensions
[2012/10/23 18:11:30 | 000,261,600 | ---- | M] (Mozilla Foundation) -- D:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/10/23 18:11:27 | 000,001,392 | ---- | M] () -- D:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/10/23 18:11:27 | 000,002,465 | ---- | M] () -- D:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/10/23 18:11:27 | 000,001,153 | ---- | M] () -- D:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012/10/23 18:11:27 | 000,006,805 | ---- | M] () -- D:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/10/23 18:11:27 | 000,001,178 | ---- | M] () -- D:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/10/23 18:11:27 | 000,001,105 | ---- | M] () -- D:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2011/08/26 16:32:10 | 000,002,380 | ---- | M]) - D:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 192.150.18.108
O1 - Hosts: 127.0.0.1 activate.adobe.com:443
O1 - Hosts: 127.0.0.1 3dns.adobe.com
O1 - Hosts: 127.0.0.1 3dns-1.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 192.150.18.108
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-1.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 26 more lines...
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - D:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - D:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\Florian_ON_D\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] D:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [RtHDVCpl] D:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Verigesture] D:\Program Files (x86)\Lenovo\Lenovo VeriTouch\Verigesture Dashboard.exe (Lenovo)
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] D:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] D:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] D:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BlueStacks Agent] D:\Program Files (x86)\BlueStacks\HD-Agent.exe (BlueStack Systems, Inc.)
O4 - HKLM..\Run: [CLMLServer] D:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [jmekey] D:\Program Files (x86)\jmesoft\hotkey.exe (JME)
O4 - HKLM..\Run: [Lenovo Dynamic Brightness System] D:\Program Files\Lenovo\Lenovo Brightness System\Lenovo Dynamic Brightness System.exe (Lenovo)
O4 - HKLM..\Run: [Lenovo Eye Distance System] D:\Program Files\Lenovo\Lenovo Eye Distance System\Lenovo Eye Distance System.exe (Lenovo)
O4 - HKLM..\Run: [Nike+ Connect] D:\Program Files (x86)\Nike\Nike+ Connect\Nike+ Connect daemon.exe (Nike)
O4 - HKLM..\Run: [PWRISOVM.EXE] D:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [StartCCC] D:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] D:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [UpdateP2GoShortCut] D:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePRCShortCut] D:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [YouCam Mirror Tray icon] D:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe (CyberLink Corp.)
O4 - HKU\Florian_ON_D..\Run: [AdobeBridge] File not found
O4 - HKU\Florian_ON_D..\Run: [Facebook Update] D:\Users\Florian\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\Florian_ON_D..\Run: [MotoCast] D:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk ()
O4 - HKU\Florian_ON_D..\Run: [MusicManager] D:\Users\Florian\AppData\Local\Programs\Google\MusicManager\MusicManager.exe (Google Inc.)
O4 - HKU\Florian_ON_D..\Run: [rfxsrvtray] D:\Program Files (x86)\Tobit Radio.fx\Client\rfx-tray.exe (Tobit.Software)
O4 - HKU\Florian_ON_D..\Run: [Spotify Web Helper] D:\Users\Florian\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKU\Florian_ON_D..\Run: [Userinit] File not found
O4 - HKU\LocalService_ON_D..\Run: [Sidebar] D:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_D..\Run: [Sidebar] D:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\LocalService_ON_D..\RunOnce: [mctadmin] File not found
O4 - HKU\NetworkService_ON_D..\RunOnce: [mctadmin] File not found
O4 - Startup: D:\Users\Florian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Bild an &Bluetooth-Gerät senden... - D:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Seite an &Bluetooth-Gerät senden... - D:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - D:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - D:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Senden an Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Senden an &Bluetooth-Gerät... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - D:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - D:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13:64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: CC679CB8-DC4B-458B-B817-D447B3B6AC31 vpnweb.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - D:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - D:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - D:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKU\Florian_ON_D Winlogon: Shell - (explorer.exe) - D:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKU\Florian_ON_D Winlogon: Shell - (C:\Users\Florian\AppData\Roaming\skype.dat) - D:\Users\Florian\AppData\Roaming\skype.dat ()
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\start.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\start.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2013/01/23 12:58:53 | 000,000,000 | ---D | C] -- D:\Users\Florian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
[2013/01/09 12:20:34 | 000,751,104 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\win32spl.dll
[2013/01/09 12:20:34 | 000,492,032 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\win32spl.dll
[2013/01/09 12:20:28 | 000,307,200 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\ncrypt.dll
[2013/01/09 12:20:28 | 000,219,136 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\ncrypt.dll
[2013/01/09 12:12:28 | 000,801,280 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\usp10.dll
[2013/01/09 12:12:26 | 000,046,592 | ---- | C] (Microsoft) -- D:\Windows\SysWow64\fpb.rs
[2013/01/09 12:12:26 | 000,046,592 | ---- | C] (Microsoft) -- D:\Windows\System32\fpb.rs
[2013/01/09 12:12:26 | 000,045,568 | ---- | C] (Microsoft) -- D:\Windows\SysWow64\oflc-nz.rs
[2013/01/09 12:12:26 | 000,045,568 | ---- | C] (Microsoft) -- D:\Windows\System32\oflc-nz.rs
[2013/01/09 12:12:26 | 000,044,544 | ---- | C] (Microsoft) -- D:\Windows\SysWow64\pegibbfc.rs
[2013/01/09 12:12:26 | 000,044,544 | ---- | C] (Microsoft) -- D:\Windows\System32\pegibbfc.rs
[2013/01/09 12:12:26 | 000,043,520 | ---- | C] (Microsoft) -- D:\Windows\SysWow64\csrr.rs
[2013/01/09 12:12:26 | 000,043,520 | ---- | C] (Microsoft) -- D:\Windows\System32\csrr.rs
[2013/01/09 12:12:26 | 000,040,960 | ---- | C] (Microsoft) -- D:\Windows\SysWow64\cob-au.rs
[2013/01/09 12:12:26 | 000,040,960 | ---- | C] (Microsoft) -- D:\Windows\System32\cob-au.rs
[2013/01/09 12:12:26 | 000,030,720 | ---- | C] (Microsoft) -- D:\Windows\SysWow64\usk.rs
[2013/01/09 12:12:26 | 000,030,720 | ---- | C] (Microsoft) -- D:\Windows\System32\usk.rs
[2013/01/09 12:12:26 | 000,021,504 | ---- | C] (Microsoft) -- D:\Windows\SysWow64\grb.rs
[2013/01/09 12:12:26 | 000,015,360 | ---- | C] (Microsoft) -- D:\Windows\SysWow64\djctq.rs
[2013/01/09 12:12:26 | 000,015,360 | ---- | C] (Microsoft) -- D:\Windows\System32\djctq.rs
[2013/01/09 12:12:25 | 002,745,856 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\gameux.dll
[2013/01/09 12:12:25 | 002,576,384 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\gameux.dll
[2013/01/09 12:12:25 | 000,441,856 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\Wpc.dll
[2013/01/09 12:12:25 | 000,308,736 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\Wpc.dll
[2013/01/09 12:12:25 | 000,021,504 | ---- | C] (Microsoft) -- D:\Windows\System32\grb.rs
[2013/01/09 12:12:25 | 000,020,480 | ---- | C] (Microsoft) -- D:\Windows\SysWow64\pegi-pt.rs
[2013/01/09 12:12:25 | 000,020,480 | ---- | C] (Microsoft) -- D:\Windows\System32\pegi-pt.rs
[2013/01/09 12:12:25 | 000,020,480 | ---- | C] (Microsoft) -- D:\Windows\SysWow64\pegi.rs
[2013/01/09 12:12:25 | 000,020,480 | ---- | C] (Microsoft) -- D:\Windows\System32\pegi.rs
[2013/01/09 12:12:24 | 000,055,296 | ---- | C] (Microsoft) -- D:\Windows\SysWow64\cero.rs
[2013/01/09 12:12:24 | 000,055,296 | ---- | C] (Microsoft) -- D:\Windows\System32\cero.rs
[2013/01/09 12:12:24 | 000,051,712 | ---- | C] (Microsoft) -- D:\Windows\SysWow64\esrb.rs
[2013/01/09 12:12:24 | 000,051,712 | ---- | C] (Microsoft) -- D:\Windows\System32\esrb.rs
[2013/01/09 12:12:24 | 000,023,552 | ---- | C] (Microsoft) -- D:\Windows\SysWow64\oflc.rs
[2013/01/09 12:12:24 | 000,023,552 | ---- | C] (Microsoft) -- D:\Windows\System32\oflc.rs
[2013/01/09 12:12:24 | 000,020,480 | ---- | C] (Microsoft) -- D:\Windows\SysWow64\pegi-fi.rs
[2013/01/09 12:12:24 | 000,020,480 | ---- | C] (Microsoft) -- D:\Windows\System32\pegi-fi.rs
[2013/01/09 12:12:14 | 000,424,960 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\KernelBase.dll
[2013/01/09 12:12:13 | 001,161,216 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\kernel32.dll
[2013/01/09 12:12:12 | 000,362,496 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\wow64win.dll
[2013/01/09 12:12:12 | 000,338,432 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\conhost.exe
[2013/01/09 12:12:12 | 000,243,200 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\wow64.dll
[2013/01/09 12:12:12 | 000,215,040 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\winsrv.dll
[2013/01/09 12:12:12 | 000,016,384 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\ntvdm64.dll
[2013/01/09 12:12:12 | 000,013,312 | ---- | C] (Microsoft Corporation) -- D:\Windows\System32\wow64cpu.dll
[2013/01/09 12:12:11 | 000,014,336 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\ntvdm64.dll
[2013/01/09 12:12:11 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013/01/09 12:12:11 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013/01/09 12:12:11 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2013/01/09 12:12:11 | 000,005,120 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\wow32.dll
[2013/01/09 12:12:11 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013/01/09 12:12:11 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2013/01/09 12:12:11 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013/01/09 12:12:11 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2013/01/09 12:12:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/01/09 12:12:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/01/09 12:12:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013/01/09 12:12:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2013/01/09 12:12:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013/01/09 12:12:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013/01/09 12:12:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013/01/09 12:12:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2013/01/09 12:12:10 | 000,025,600 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\setup16.exe
[2013/01/09 12:12:10 | 000,007,680 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\instnm.exe
[2013/01/09 12:12:10 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2013/01/09 12:12:10 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013/01/09 12:12:10 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2013/01/09 12:12:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013/01/09 12:12:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- D:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2013/01/09 12:12:09 | 000,002,048 | ---- | C] (Microsoft Corporation) -- D:\Windows\SysWow64\user.exe
[2013/01/07 09:19:20 | 000,000,000 | ---D | C] -- D:\Users\Florian\Desktop\Atlas der Globalisierung
[2010/06/13 07:09:50 | 001,914,000 | ---- | C] (Adobe Systems Incorporated) -- D:\ProgramData\flashax10.exe
[3 D:\Users\Florian\AppData\Roaming\*.tmp files -> D:\Users\Florian\AppData\Roaming\*.tmp -> ]
[1 D:\Windows\SysWow64\*.tmp files -> D:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/01/30 08:47:20 | 000,067,584 | --S- | M] () -- D:\Windows\bootstat.dat
[2013/01/30 08:47:19 | 2415,321,088 | -HS- | M] () -- D:\hiberfil.sys
[2013/01/26 12:12:00 | 000,001,146 | ---- | M] () -- D:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2706925119-857912825-4293364795-1004UA.job
[2013/01/26 12:12:00 | 000,001,124 | ---- | M] () -- D:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2706925119-857912825-4293364795-1004Core.job
[2013/01/26 12:08:42 | 000,000,916 | ---- | M] () -- D:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2706925119-857912825-4293364795-1004UA.job
[2013/01/26 11:07:30 | 000,015,760 | -H-- | M] () -- D:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/26 11:07:30 | 000,015,760 | -H-- | M] () -- D:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/26 10:44:39 | 000,000,004 | ---- | M] () -- D:\Users\Florian\AppData\Roaming\skype.ini
[2013/01/26 10:41:55 | 000,001,053 | ---- | M] () -- D:\Users\Florian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/01/26 10:41:34 | 000,001,025 | ---- | M] () -- D:\Users\Florian\Desktop\Dropbox.lnk
[2013/01/25 14:53:01 | 000,000,864 | ---- | M] () -- D:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2706925119-857912825-4293364795-1004Core.job
[2013/01/23 19:15:14 | 007,940,761 | ---- | M] () -- D:\Users\Florian\Desktop\b2 001kopie.jpg
[2013/01/22 12:24:44 | 000,711,120 | ---- | M] () -- D:\Windows\System32\perfh007.dat
[2013/01/22 12:24:44 | 000,662,740 | ---- | M] () -- D:\Windows\System32\perfh009.dat
[2013/01/22 12:24:44 | 000,153,548 | ---- | M] () -- D:\Windows\System32\perfc007.dat
[2013/01/22 12:24:44 | 000,123,934 | ---- | M] () -- D:\Windows\System32\perfc009.dat
[2013/01/21 09:50:30 | 000,040,371 | ---- | M] () -- D:\Users\Florian\Desktop\ggg 001.jpg
[2013/01/21 09:16:24 | 000,157,091 | ---- | M] () -- D:\Users\Florian\Desktop\Bewerbungsformular_2013-14_Neu.pdf
[2013/01/21 09:16:24 | 000,091,424 | ---- | M] () -- D:\Users\Florian\Desktop\Preliminary_Learning_Agreement_2013_-14_Neu.pdf
[2013/01/10 16:47:51 | 005,061,672 | ---- | M] () -- D:\Windows\System32\FNTCACHE.DAT
[2013/01/09 10:18:58 | 001,266,789 | ---- | M] () -- D:\Users\Florian\Desktop\c1 001.jpg
[2013/01/09 10:16:52 | 001,261,130 | ---- | M] () -- D:\Users\Florian\Desktop\b2 001.jpg
[2013/01/09 10:15:10 | 000,426,688 | ---- | M] () -- D:\Users\Florian\Desktop\scan 002.jpg
[2013/01/08 13:47:19 | 000,025,815 | ---- | M] () -- D:\Users\Florian\Desktop\1.JPG
[2013/01/07 09:11:51 | 006,467,937 | ---- | M] () -- D:\Users\Florian\Desktop\Atlas-Der-Globalisierung.pdf
[2013/01/06 17:44:53 | 083,405,206 | ---- | M] () -- D:\Users\Florian\Desktop\indiependent 10.01.2012.mp3
[3 D:\Users\Florian\AppData\Roaming\*.tmp files -> D:\Users\Florian\AppData\Roaming\*.tmp -> ]
[1 D:\Windows\SysWow64\*.tmp files -> D:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/01/26 10:16:56 | 000,000,004 | ---- | C] () -- D:\Users\Florian\AppData\Roaming\skype.ini
[2013/01/22 17:01:53 | 007,940,761 | ---- | C] () -- D:\Users\Florian\Desktop\b2 001kopie.jpg
[2013/01/21 09:16:18 | 000,091,424 | ---- | C] () -- D:\Users\Florian\Desktop\Preliminary_Learning_Agreement_2013_-14_Neu.pdf
[2013/01/21 09:15:31 | 000,157,091 | ---- | C] () -- D:\Users\Florian\Desktop\Bewerbungsformular_2013-14_Neu.pdf
[2013/01/13 13:13:36 | 000,040,371 | ---- | C] () -- D:\Users\Florian\Desktop\ggg 001.jpg
[2013/01/09 10:18:58 | 001,266,789 | ---- | C] () -- D:\Users\Florian\Desktop\c1 001.jpg
[2013/01/09 10:16:52 | 001,261,130 | ---- | C] () -- D:\Users\Florian\Desktop\b2 001.jpg
[2013/01/09 10:15:10 | 000,426,688 | ---- | C] () -- D:\Users\Florian\Desktop\scan 002.jpg
[2013/01/08 13:47:17 | 000,025,815 | ---- | C] () -- D:\Users\Florian\Desktop\1.JPG
[2013/01/07 09:11:47 | 006,467,937 | ---- | C] () -- D:\Users\Florian\Desktop\Atlas-Der-Globalisierung.pdf
[2013/01/06 17:43:48 | 083,405,206 | ---- | C] () -- D:\Users\Florian\Desktop\indiependent 10.01.2012.mp3
[2013/01/06 16:30:46 | 000,062,464 | ---- | C] () -- D:\Users\Florian\Desktop\Word_Sendeanmeldung-Formular für Mail_TideRadio_01-2013.dot
[2012/11/16 16:18:46 | 000,197,728 | ---- | C] () -- D:\Users\Florian\AppData\Roaming\AcroIEHelpe.dll
[2012/11/16 16:18:46 | 000,007,104 | ---- | C] () -- D:\Users\Florian\AppData\Roaming\BAcroIEHelpe.dll
[2012/11/16 16:18:40 | 000,000,016 | ---- | C] () -- D:\Users\Florian\AppData\Roaming\blckdom.res
[2012/11/16 16:18:32 | 000,065,536 | ---- | C] () -- D:\Users\Florian\AppData\Roaming\apwxkz9e.default.dat
[2012/10/25 10:41:36 | 000,000,132 | ---- | C] () -- D:\Users\Florian\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2012/10/25 10:37:10 | 000,000,132 | ---- | C] () -- D:\Users\Florian\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/06/29 17:26:44 | 000,014,760 | ---- | C] () -- D:\Windows\SysWow64\drivers\DRHMSR64.sys
[2012/06/25 12:50:55 | 000,001,024 | ---- | C] () -- D:\Windows\SysWow64\clauth2.dll
[2012/06/25 12:50:55 | 000,001,024 | ---- | C] () -- D:\Windows\SysWow64\clauth1.dll
[2012/06/25 12:50:55 | 000,000,000 | ---- | C] () -- D:\Windows\SysWow64\ssprs.dll
[2012/06/25 12:50:55 | 000,000,000 | ---- | C] () -- D:\Windows\SysWow64\serauth2.dll
[2012/06/25 12:50:55 | 000,000,000 | ---- | C] () -- D:\Windows\SysWow64\serauth1.dll
[2012/06/25 12:50:55 | 000,000,000 | ---- | C] () -- D:\Windows\SysWow64\nsprs.dll
[2012/06/25 12:47:52 | 000,001,025 | ---- | C] () -- D:\Windows\SysWow64\sysprs7.dll
[2012/06/25 12:47:52 | 000,000,205 | ---- | C] () -- D:\Windows\SysWow64\lsprst7.dll
[2012/01/11 14:22:05 | 000,098,304 | -HS- | C] () -- D:\Users\Florian\AppData\Roaming\skype.dat
[2011/09/18 08:33:38 | 002,681,344 | ---- | C] () -- D:\Windows\SysWow64\dvmsg.dll
[2010/06/13 07:22:59 | 001,499,556 | ---- | C] () -- D:\Windows\SysWow64\PerfStringBackup.INI
[2010/06/13 07:02:49 | 000,000,000 | ---- | C] () -- D:\Windows\ativpsrm.bin
[2010/02/23 11:15:02 | 000,001,105 | ---- | C] () -- D:\Windows\SysWow64\atipblag.dat
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- D:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- D:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- D:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- D:\Windows\mib.bin
[2009/07/13 19:02:54 | 000,245,248 | ---- | C] () -- D:\Windows\SysWow64\DShowRdpFilter.dll
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- D:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:25:04 | 000,197,632 | ---- | C] () -- D:\Windows\SysWow64\ir32_32.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- D:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- D:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/08/16 14:35:42 | 000,000,000 | -HSD | M] -- D:\ProgramData\Anwendungsdaten
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Application Data
[2012/11/28 13:30:49 | 000,000,000 | ---D | M] -- D:\ProgramData\BlueStacks
[2012/11/28 13:34:56 | 000,000,000 | ---D | M] -- D:\ProgramData\BlueStacksSetup
[2011/09/08 12:31:44 | 000,000,000 | -H-D | M] -- D:\ProgramData\CanonBJ
[2012/06/29 17:08:05 | 000,000,000 | ---D | M] -- D:\ProgramData\Cisco
[2011/08/26 17:15:45 | 000,000,000 | ---D | M] -- D:\ProgramData\DATA BECKER Downloads
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Desktop
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Documents
[2011/08/16 14:35:42 | 000,000,000 | -HSD | M] -- D:\ProgramData\Dokumente
[2011/08/16 14:35:42 | 000,000,000 | -HSD | M] -- D:\ProgramData\Favoriten
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Favorites
[2011/08/17 17:46:49 | 000,000,000 | ---D | M] -- D:\ProgramData\Langenscheidt
[2011/08/16 15:10:53 | 000,000,000 | ---D | M] -- D:\ProgramData\Lenovo
[2011/08/17 18:17:53 | 000,000,000 | ---D | M] -- D:\ProgramData\mcShoutCast
[2012/02/28 10:51:48 | 000,000,000 | ---D | M] -- D:\ProgramData\Motorola
[2012/11/09 11:14:03 | 000,000,000 | ---D | M] -- D:\ProgramData\Nike
[2012/10/15 09:36:22 | 000,000,000 | ---D | M] -- D:\ProgramData\PACE Anti-Piracy
[2012/10/15 07:30:17 | 000,000,000 | ---D | M] -- D:\ProgramData\regid.1986-12.com.adobe
[2013/01/22 10:57:44 | 000,000,000 | ---D | M] -- D:\ProgramData\Rosetta Stone
[2012/06/25 13:24:09 | 000,000,000 | ---D | M] -- D:\ProgramData\SafeNet Sentinel
[2011/08/28 15:08:47 | 000,000,000 | ---D | M] -- D:\ProgramData\Sony
[2012/06/29 17:19:46 | 000,000,000 | ---D | M] -- D:\ProgramData\SPSS
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Start Menu
[2011/08/16 14:35:42 | 000,000,000 | -HSD | M] -- D:\ProgramData\Startmenü
[2010/06/13 07:13:18 | 000,000,000 | ---D | M] -- D:\ProgramData\Temp
[2009/07/14 00:08:56 | 000,000,000 | -HSD | M] -- D:\ProgramData\Templates
[2011/08/16 14:35:42 | 000,000,000 | -HSD | M] -- D:\ProgramData\Vorlagen
[2011/09/27 07:04:09 | 000,000,000 | ---D | M] -- D:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2013/01/26 12:12:00 | 000,001,124 | ---- | M] () -- D:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2706925119-857912825-4293364795-1004Core.job
[2013/01/26 12:12:00 | 000,001,146 | ---- | M] () -- D:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2706925119-857912825-4293364795-1004UA.job
[2012/12/13 08:32:49 | 000,032,640 | ---- | M] () -- D:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report > danke im voraus und beste grüße! :sword2: |