kreditloser. | 25.03.2013 22:22 | Hallo Leo,
ich hab alles erledigt und den Plugin Check bestanden.
OTL-log: Code:
OTL logfile created on: 25.03.2013 22:09:05 - Run 6
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\Buero\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,11 Gb Available Physical Memory | 70,50% Memory free
4,84 Gb Paging File | 4,15 Gb Available in Paging File | 85,72% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 195,31 Gb Total Space | 84,47 Gb Free Space | 43,25% Space Free | Partition Type: NTFS
Drive E: | 270,44 Gb Total Space | 48,21 Gb Free Space | 17,83% Space Free | Partition Type: NTFS
Drive H: | 465,65 Gb Total Space | 189,09 Gb Free Space | 40,61% Space Free | Partition Type: FAT32
Computer Name: HBK-BUERO | User Name: Buero | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.03.25 22:07:31 | 001,014,328 | ---- | M] (Solid State Networks) -- C:\Dokumente und Einstellungen\Buero\Lokale Einstellungen\temp\install_reader11_de_mssd_aih_1.exe
PRC - [2013.03.25 21:57:28 | 000,170,912 | ---- | M] (Oracle Corporation) -- C:\Programme\Java\jre7\bin\jqs.exe
PRC - [2013.03.25 21:37:51 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe
PRC - [2013.03.24 11:34:49 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Buero\Desktop\OTL.exe
PRC - [2013.03.01 19:51:42 | 000,599,552 | ---- | M] () -- C:\Programme\Serviio\bin\ServiioConsole.exe
PRC - [2013.03.01 19:51:42 | 000,316,416 | ---- | M] () -- C:\Programme\Serviio\bin\ServiioService.exe
PRC - [2013.02.05 16:48:44 | 000,272,248 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee Security Scan\3.0.318\SSScheduler.exe
PRC - [2012.12.14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.12.14 16:49:28 | 000,512,360 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.12.14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.07.03 09:04:54 | 000,252,848 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
PRC - [2012.06.28 00:53:46 | 000,086,016 | ---- | M] (alch) -- C:\Programme\ClamWin\bin\ClamTray.exe
PRC - [2009.12.16 16:44:36 | 003,750,400 | ---- | M] (SafeNet Inc.) -- C:\WINDOWS\system32\hasplms.exe
PRC - [2008.04.14 03:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2003.03.19 16:43:00 | 000,065,536 | ---- | M] (Brother Industries, Ltd.) -- C:\WINDOWS\system32\Brmfrmps.exe
========== Modules (No Company Name) ==========
MOD - [2013.03.25 21:37:51 | 003,069,848 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll
MOD - [2013.03.13 11:50:23 | 014,717,144 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll
MOD - [2013.03.01 19:51:42 | 000,599,552 | ---- | M] () -- C:\Programme\Serviio\bin\ServiioConsole.exe
MOD - [2013.03.01 19:51:42 | 000,316,416 | ---- | M] () -- C:\Programme\Serviio\bin\ServiioService.exe
MOD - [2008.04.14 03:22:16 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2005.02.08 15:23:10 | 000,979,005 | ---- | M] () -- C:\Programme\ClamWin\bin\python23.dll
MOD - [2004.11.20 01:27:54 | 000,106,496 | ---- | M] () -- C:\Programme\ClamWin\lib\shell.pyd
MOD - [2004.11.20 01:27:54 | 000,086,016 | ---- | M] () -- C:\Programme\ClamWin\lib\win32gui.pyd
MOD - [2004.11.20 01:27:54 | 000,077,824 | ---- | M] () -- C:\Programme\ClamWin\lib\win32file.pyd
MOD - [2004.11.20 01:27:54 | 000,069,632 | ---- | M] () -- C:\Programme\ClamWin\lib\win32api.pyd
MOD - [2004.11.20 01:27:54 | 000,065,536 | ---- | M] () -- C:\Programme\ClamWin\lib\win32security.pyd
MOD - [2004.11.20 01:27:54 | 000,036,864 | ---- | M] () -- C:\Programme\ClamWin\lib\win32process.pyd
MOD - [2004.11.20 01:27:54 | 000,024,576 | ---- | M] () -- C:\Programme\ClamWin\lib\win32pipe.pyd
MOD - [2004.11.20 01:27:54 | 000,024,576 | ---- | M] () -- C:\Programme\ClamWin\lib\win32event.pyd
MOD - [2004.10.11 18:22:18 | 000,315,392 | ---- | M] () -- C:\Programme\ClamWin\lib\pythoncom23.dll
MOD - [2004.10.11 18:21:26 | 000,094,208 | ---- | M] () -- C:\Programme\ClamWin\lib\pywintypes23.dll
MOD - [2004.05.25 19:20:30 | 000,036,864 | ---- | M] () -- C:\Programme\ClamWin\lib\_winreg.pyd
MOD - [2004.05.25 19:19:32 | 000,045,117 | ---- | M] () -- C:\Programme\ClamWin\lib\datetime.pyd
MOD - [2004.05.25 19:18:42 | 000,495,616 | ---- | M] () -- C:\Programme\ClamWin\lib\_ssl.pyd
MOD - [2004.05.25 19:18:28 | 000,057,401 | ---- | M] () -- C:\Programme\ClamWin\lib\_sre.pyd
MOD - [2004.05.25 19:18:20 | 000,049,212 | ---- | M] () -- C:\Programme\ClamWin\lib\_socket.pyd
MOD - [2004.05.25 19:17:14 | 000,622,651 | ---- | M] () -- C:\Programme\ClamWin\lib\_bsddb.pyd
MOD - [2004.01.15 12:45:22 | 000,061,440 | ---- | M] () -- C:\Programme\ClamWin\lib\_ctypes.pyd
MOD - [2003.10.01 11:40:00 | 002,240,512 | ---- | M] () -- C:\Programme\ClamWin\lib\wxc.pyd
MOD - [2003.10.01 09:43:02 | 003,239,936 | ---- | M] () -- C:\Programme\ClamWin\lib\wxmsw24h.dll
MOD - [2003.08.10 07:14:40 | 000,061,440 | ---- | M] () -- C:\Programme\ClamWin\lib\mxDateTime.pyd
MOD - [2002.08.08 08:22:22 | 000,006,144 | ---- | M] () -- C:\Programme\Scansoft\PaperPort\BliceCtr.dll
MOD - [2001.10.28 17:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - [2013.03.25 21:57:28 | 000,170,912 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Programme\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2013.03.25 21:37:51 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.03.13 11:50:24 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.03.01 19:51:42 | 000,316,416 | ---- | M] () [Auto | Running] -- C:\Programme\Serviio\bin\ServiioService.exe -- (Serviio)
SRV - [2013.02.05 16:48:00 | 000,235,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Programme\McAfee Security Scan\3.0.318\McCHSvc.exe -- (McComponentHostService)
SRV - [2012.12.14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.12.14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2011.04.30 09:23:08 | 001,045,256 | ---- | M] (Acresso Software Inc.) [Disabled | Stopped] -- C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009.12.16 16:44:36 | 003,750,400 | ---- | M] (SafeNet Inc.) [Auto | Running] -- C:\WINDOWS\system32\hasplms.exe -- (hasplms)
SRV - [2005.04.03 23:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2003.07.28 12:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2003.03.19 16:43:00 | 000,065,536 | ---- | M] (Brother Industries, Ltd.) [Auto | Running] -- C:\WINDOWS\system32\Brmfrmps.exe -- (brmfrmps)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\dgderdrv.sys -- (dgderdrv)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOKUME~1\Buero\LOKALE~1\Temp\catchme.sys -- (catchme)
DRV - [2012.12.14 16:49:28 | 000,021,104 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.09.29 15:37:40 | 000,013,824 | ---- | M] (Scott) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBDrv.sys -- (usbUDisc)
DRV - [2012.03.07 21:39:47 | 000,045,136 | ---- | M] (MARX CryptoTech LP) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CBUSB.sys -- (CBUSB)
DRV - [2011.06.02 06:47:22 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2011.06.02 06:47:22 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2011.06.02 06:47:22 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV - [2011.03.03 16:59:20 | 000,119,272 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvhda32.sys -- (NVHDA)
DRV - [2010.12.21 06:55:02 | 000,132,424 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2010.12.21 06:55:02 | 000,104,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus)
DRV - [2010.12.21 06:55:02 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2010.05.15 12:11:40 | 002,136,224 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2010.04.08 19:30:10 | 000,168,040 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvgts.sys -- (nvgts)
DRV - [2010.03.04 11:02:10 | 000,013,824 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2010.03.04 11:02:08 | 000,070,912 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2009.12.09 21:27:18 | 000,588,800 | ---- | M] (SafeNet Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (hardlock)
DRV - [2009.08.20 07:01:50 | 000,356,864 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\aksfridge.sys -- (aksfridge)
DRV - [2009.06.22 09:06:32 | 000,016,384 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\aksusb.sys -- (aksusb)
DRV - [2009.03.13 10:55:26 | 000,238,208 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\akshasp.sys -- (akshasp)
DRV - [2008.04.13 19:36:41 | 000,063,744 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mf.sys -- (mf)
DRV - [2004.08.13 03:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2001.08.17 12:12:22 | 000,010,368 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BrUsbScn.sys -- (BrUsbScn)
DRV - [2001.08.17 12:12:12 | 000,002,944 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BrFilt.sys -- (brfilt)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2052111302-879983540-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://web.fx-n.de/egroupware/index.php?menuaction=felamimail.uifelamimail.viewMainScreen
IE - HKU\S-1-5-21-2052111302-879983540-839522115-1003\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2052111302-879983540-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-2052111302-879983540-839522115-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-2052111302-879983540-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2052111302-879983540-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "hxxp://web.fx-n.de/egroupware/index.php?menuaction=felamimail.uifelamimail.viewMainScreen|hxxp://www.slatedroid.com/topic/36988-cx-01-cortex-a5/"
FF - prefs.js..extensions.enabledAddons: %7Bf53ae83d-ca13-4cf8-8fd4-c58ae36051b4%7D:0.6.7
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Programme\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Programme\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@autodesk.com/DWF: C:\Programme\Autodesk\Autodesk Design Review Browser Add-on v1.2\npADRdwf.dll (Autodesk)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Programme\Mozilla Firefox\components [2013.03.25 21:37:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2012.01.05 13:02:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins
[2011.04.30 04:26:05 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Buero\Anwendungsdaten\Mozilla\Extensions
[2013.01.29 23:42:53 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Buero\Anwendungsdaten\Mozilla\Firefox\Profiles\1uas01h6.default\extensions
[2012.01.07 20:14:07 | 000,057,531 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\Buero\Anwendungsdaten\Mozilla\Firefox\Profiles\1uas01h6.default\extensions\{f53ae83d-ca13-4cf8-8fd4-c58ae36051b4}.xpi
[2013.03.25 22:02:35 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.03.25 21:37:52 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2013.03.25 21:37:49 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.03.25 21:37:49 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2013.03.25 21:37:49 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2013.03.25 21:37:49 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2013.03.25 21:37:49 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2013.03.25 21:37:49 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2013.03.22 23:57:46 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Programme\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [ClamWin] C:\Programme\ClamWin\bin\ClamTray.exe (alch)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SetDefPrt] C:\Programme\Brother\Brmfl03a\BrStDvPt.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\McAfee Security Scan Plus.lnk = C:\Programme\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Dokumente und Einstellungen\Buero\Startmenü\Programme\Autostart\Serviio.lnk = C:\Programme\Serviio\bin\ServiioConsole.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2052111302-879983540-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2052111302-879983540-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2052111302-879983540-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-2052111302-879983540-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1342872440000 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1342872431375 (MUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{43D3D996-E629-434B-A006-0989BA25ADF9}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Grüne Idylle.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011.04.30 09:21:04 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2011.04.27 12:16:28 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.03.25 22:10:53 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Adobe
[2013.03.25 21:58:46 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Buero\Lokale Einstellungen\Anwendungsdaten\Sun
[2013.03.25 21:57:56 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Java
[2013.03.25 21:57:26 | 000,000,000 | ---D | C] -- C:\Programme\Java
[2013.03.25 21:47:18 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2013.03.25 21:47:07 | 000,000,000 | ---D | C] -- C:\Programme\MSECache
[2013.03.25 21:39:14 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013.03.24 20:53:28 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2013.03.24 20:50:57 | 002,347,384 | ---- | C] (ESET) -- C:\Dokumente und Einstellungen\Buero\Desktop\esetsmartinstaller_enu.exe
[2013.03.24 20:44:25 | 010,156,344 | ---- | C] (Malwarebytes Corporation ) -- C:\Dokumente und Einstellungen\Buero\Desktop\mbam-setup-1.70.0.1100(1).exe
[2013.03.24 19:38:36 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Buero\Desktop\mbar
[2013.03.24 19:22:18 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2013.03.24 19:22:04 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.03.24 11:34:49 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Buero\Desktop\OTL.exe
[2013.03.23 00:02:32 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Buero\Eigene Dateien\Virus
[2013.03.22 23:47:01 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2013.03.22 23:44:54 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2013.03.22 23:44:54 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2013.03.22 23:44:54 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2013.03.22 23:44:54 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2013.03.22 23:44:49 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.03.22 23:44:46 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Buero\Startmenü\Programme\Verwaltung
[2013.03.22 23:44:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2013.03.22 23:32:57 | 005,044,071 | R--- | C] (Swearware) -- C:\Dokumente und Einstellungen\Buero\Desktop\ComboFix.exe
[2013.03.22 22:59:07 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Panda Security
[2013.03.22 22:59:01 | 000,000,000 | ---D | C] -- C:\Programme\Panda USB Vaccine
[2013.03.22 22:59:01 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Panda Security
[2013.03.22 22:58:15 | 000,848,856 | ---- | C] (Panda Security ) -- C:\Dokumente und Einstellungen\Buero\Desktop\USBVaccine1014Setup.exe
[2013.03.06 22:07:56 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Serviio
[2013.03.04 11:35:34 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\McAfee Security Scan Plus
[2013.02.25 06:21:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\McAfee Security Scan
[2013.02.25 06:21:21 | 000,000,000 | ---D | C] -- C:\Programme\McAfee Security Scan
[2013.02.25 06:21:21 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\McAfee
========== Files - Modified Within 30 Days ==========
[2013.03.25 22:11:24 | 000,001,714 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader XI.lnk
[2013.03.25 22:04:46 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013.03.25 22:03:03 | 000,000,268 | ---- | M] () -- C:\Dokumente und Einstellungen\Buero\.dir
[2013.03.25 22:02:40 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.03.25 22:02:38 | 000,237,552 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013.03.25 21:50:47 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013.03.25 21:49:15 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013.03.25 00:01:12 | 002,195,813 | ---- | M] () -- C:\Qoobox.zip
[2013.03.24 22:56:22 | 000,000,268 | ---- | M] () -- C:\.dir
[2013.03.24 22:30:00 | 000,890,798 | ---- | M] () -- C:\Dokumente und Einstellungen\Buero\Desktop\SecurityCheck.exe
[2013.03.24 20:51:01 | 002,347,384 | ---- | M] (ESET) -- C:\Dokumente und Einstellungen\Buero\Desktop\esetsmartinstaller_enu.exe
[2013.03.24 20:45:16 | 000,000,756 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013.03.24 20:44:27 | 010,156,344 | ---- | M] (Malwarebytes Corporation ) -- C:\Dokumente und Einstellungen\Buero\Desktop\mbam-setup-1.70.0.1100(1).exe
[2013.03.24 19:38:01 | 013,786,977 | ---- | M] () -- C:\Dokumente und Einstellungen\Buero\Desktop\mbar-1.01.0.1021.zip
[2013.03.24 17:27:39 | 005,044,071 | R--- | M] (Swearware) -- C:\Dokumente und Einstellungen\Buero\Desktop\ComboFix.exe
[2013.03.24 15:24:36 | 000,609,993 | ---- | M] () -- C:\Dokumente und Einstellungen\Buero\Desktop\adwcleaner.exe
[2013.03.24 12:37:42 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\Buero\Desktop\Neu Bitmap.bmp
[2013.03.24 11:34:49 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Buero\Desktop\OTL.exe
[2013.03.24 00:53:12 | 000,377,856 | ---- | M] () -- C:\Dokumente und Einstellungen\Buero\Desktop\05n32v33.exe
[2013.03.24 00:51:08 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\Buero\defogger_reenable
[2013.03.24 00:48:52 | 000,050,477 | ---- | M] () -- C:\Dokumente und Einstellungen\Buero\Desktop\Defogger.exe
[2013.03.23 23:39:36 | 000,002,162 | ---- | M] () -- C:\WINDOWS\BrmfBidi.ini
[2013.03.22 23:57:46 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2013.03.22 23:47:03 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2013.03.22 22:58:15 | 000,848,856 | ---- | M] (Panda Security ) -- C:\Dokumente und Einstellungen\Buero\Desktop\USBVaccine1014Setup.exe
[2013.03.18 19:53:04 | 000,218,624 | ---- | M] () -- C:\Dokumente und Einstellungen\Buero\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.03.06 23:48:15 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013.03.06 22:07:59 | 000,001,631 | ---- | M] () -- C:\Dokumente und Einstellungen\Buero\Startmenü\Programme\Autostart\Serviio.lnk
[2013.03.06 22:02:51 | 022,612,824 | ---- | M] () -- C:\Dokumente und Einstellungen\Buero\Desktop\serviio-1.2-win-setup.exe
[2013.03.04 11:35:34 | 000,001,733 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\McAfee Security Scan Plus.lnk
[2013.02.25 06:05:43 | 000,459,746 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2013.02.25 06:05:43 | 000,441,960 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013.02.25 06:05:43 | 000,085,508 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2013.02.25 06:05:43 | 000,071,982 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
========== Files Created - No Company Name ==========
[2013.03.25 00:01:12 | 002,195,813 | ---- | C] () -- C:\Qoobox.zip
[2013.03.24 22:29:59 | 000,890,798 | ---- | C] () -- C:\Dokumente und Einstellungen\Buero\Desktop\SecurityCheck.exe
[2013.03.24 19:37:28 | 013,786,977 | ---- | C] () -- C:\Dokumente und Einstellungen\Buero\Desktop\mbar-1.01.0.1021.zip
[2013.03.24 15:24:35 | 000,609,993 | ---- | C] () -- C:\Dokumente und Einstellungen\Buero\Desktop\adwcleaner.exe
[2013.03.24 12:37:42 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\Buero\Desktop\Neu Bitmap.bmp
[2013.03.24 00:53:11 | 000,377,856 | ---- | C] () -- C:\Dokumente und Einstellungen\Buero\Desktop\05n32v33.exe
[2013.03.24 00:51:08 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\Buero\defogger_reenable
[2013.03.24 00:48:51 | 000,050,477 | ---- | C] () -- C:\Dokumente und Einstellungen\Buero\Desktop\Defogger.exe
[2013.03.22 23:47:03 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2013.03.22 23:47:01 | 000,262,448 | RHS- | C] () -- C:\cmldr
[2013.03.22 23:44:54 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2013.03.22 23:44:54 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2013.03.22 23:44:54 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2013.03.22 23:44:54 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2013.03.22 23:44:54 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2013.03.08 06:10:20 | 000,000,756 | ---- | C] () -- C:\Dokumente und Einstellungen\Buero\Desktop\Malwarebytes Anti-Malware.lnk
[2013.03.06 21:51:11 | 022,612,824 | ---- | C] () -- C:\Dokumente und Einstellungen\Buero\Desktop\serviio-1.2-win-setup.exe
[2013.02.25 06:21:21 | 000,001,733 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\McAfee Security Scan Plus.lnk
[2012.09.06 19:16:21 | 000,000,268 | ---- | C] () -- C:\Dokumente und Einstellungen\Buero\.dir
[2012.09.05 22:31:13 | 001,522,795 | ---- | C] () -- C:\Programme\WOL2.zip
[2012.07.24 12:41:05 | 000,000,020 | ---- | C] () -- C:\WINDOWS\System32\urhtps.dat
[2012.07.21 13:23:51 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.05.21 13:34:03 | 000,000,040 | ---- | C] () -- C:\WINDOWS\opt_2460.ini
[2012.05.21 12:54:35 | 000,000,180 | ---- | C] () -- C:\WINDOWS\WEKP.INI
[2012.05.21 07:44:55 | 000,000,051 | ---- | C] () -- C:\WINDOWS\brmx2001.ini
[2012.05.17 17:42:42 | 000,002,162 | ---- | C] () -- C:\WINDOWS\BrmfBidi.ini
[2012.05.17 17:42:32 | 000,001,345 | ---- | C] () -- C:\WINDOWS\Brpcfx.ini
[2012.05.17 17:42:32 | 000,000,052 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2012.05.17 17:42:32 | 000,000,050 | ---- | C] () -- C:\WINDOWS\System32\m8440def.dat
[2012.05.17 17:42:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\brwmark.ini
[2012.05.17 17:42:15 | 000,000,256 | ---- | C] () -- C:\WINDOWS\System32\BRMSL07F.BIN
[2012.05.17 17:33:07 | 000,000,767 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2012.04.29 12:22:33 | 000,001,835 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2012.04.07 17:24:24 | 000,000,837 | ---- | C] () -- C:\WINDOWS\Solitaire.ini
[2012.04.03 12:19:14 | 000,000,138 | ---- | C] () -- C:\Dokumente und Einstellungen\Buero\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2012.03.07 21:38:55 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2012.03.07 21:25:08 | 000,000,040 | ---- | C] () -- C:\WINDOWS\vi_dsgn7.ini
[2012.03.07 21:15:30 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2012.01.31 17:15:42 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2012.01.31 17:15:42 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2012.01.31 17:15:42 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2012.01.31 17:15:42 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2012.01.07 19:10:45 | 000,218,624 | ---- | C] () -- C:\Dokumente und Einstellungen\Buero\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.01.03 23:05:33 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.05.03 22:06:14 | 000,014,857 | ---- | C] () -- C:\Dokumente und Einstellungen\Buero\Anwendungsdaten\ekiga.conf
[2011.05.03 16:41:57 | 000,259,604 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011.05.03 16:41:57 | 000,259,604 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011.05.03 16:41:57 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011.05.03 16:40:41 | 002,116,894 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2011.05.03 16:06:50 | 000,254,000 | R--- | C] ( ) -- C:\WINDOWS\System32\Audio3D.dll
[2011.05.03 16:06:50 | 000,254,000 | R--- | C] ( ) -- C:\WINDOWS\System32\A3D.dll
[2011.04.30 07:45:29 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2011.04.30 04:26:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011.04.28 13:23:10 | 000,010,084 | R--- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
[2011.04.28 12:10:56 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2011.04.28 12:10:49 | 000,001,769 | ---- | C] () -- C:\WINDOWS\Language_trs.ini
[2011.04.28 12:10:43 | 000,026,638 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2011.04.28 12:10:43 | 000,010,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2011.04.27 19:07:14 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011.04.27 19:06:12 | 000,237,552 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.04.27 12:17:59 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011.04.27 12:14:04 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
========== ZeroAccess Check ==========
[2011.04.30 08:30:09 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2012.12.27 11:24:13 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.02.09 11:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008.04.14 03:22:32 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011.04.30 09:11:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Autodesk
[2012.12.27 16:25:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DAEMON Tools Lite
[2012.02.04 23:10:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\mquadr.at
[2013.03.22 22:59:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Panda Security
[2013.01.29 23:41:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Samsung
[2012.06.05 18:04:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ScanSoft
[2012.06.05 18:04:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SUIIMAGE
[2012.07.02 13:34:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Buero\Anwendungsdaten\.minecraft
[2011.04.30 09:11:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Buero\Anwendungsdaten\Autodesk
[2012.12.27 16:25:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Buero\Anwendungsdaten\DAEMON Tools Lite
[2012.07.19 20:12:51 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Buero\Anwendungsdaten\ElevatedDiagnostics
[2012.01.07 19:07:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Buero\Anwendungsdaten\Keseling
[2012.01.21 15:43:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Buero\Anwendungsdaten\LibreOffice
[2012.02.19 07:47:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Buero\Anwendungsdaten\Petroglyph
[2012.04.29 16:40:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Buero\Anwendungsdaten\Samsung
[2012.01.05 13:02:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Buero\Anwendungsdaten\Thunderbird
[2012.04.03 12:20:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Buero\Anwendungsdaten\Turbine
========== Purity Check ==========
< End of report > Checkup-Log: Code:
Results of screen317's Security Check version 0.99.61
Windows XP Service Pack 3 x86
Internet Explorer 8 ``````````````Antivirus/Firewall Check:``````````````
WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.70.0.1100
Java 7 Update 17
Adobe Flash Player 11.6.602.180
Adobe Reader XI
Mozilla Firefox (19.0.2)
Mozilla Thunderbird (9.0.1) ````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C:: ````````````````````End of Log`````````````````````` das schaut gut aus oder?
Als Wächter hab ich eigendlich den Clamwin, aber den hab ich vor dem Checkup für einen Scan geschlossen und bekam ihn ohne neustart nicht wieder zum laufen.
Gruß, der bernd |