Hallo cosinus, danke für deine schnelle Antwort. Der infizierte notebook hat kein internetverbindung mehr, deshalb muss ich alle daten auf diesen pc übertragen. Ich hoffe, dass alles funktioniert wie du dir es wünscht: hier der otl.txt (edit) OTL-Anleitung entfernt (/edit)
Ich versuche mit dem kopiere:OTL Logfile: Code:
OTL logfile created on: 5/19/2013 10:25:53 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\gosia\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
764.56 Mb Total Physical Memory | 212.72 Mb Available Physical Memory | 27.82% Memory free
1.75 Gb Paging File | 1.19 Gb Available in Paging File | 68.21% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 215.59 Gb Total Space | 151.86 Gb Free Space | 70.44% Space Free | Partition Type: NTFS
Drive F: | 1.99 Gb Total Space | 1.98 Gb Free Space | 99.61% Space Free | Partition Type: FAT32
Computer Name: GOSIA-HP | User Name: gosia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\gosia\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IDT\WDM\stacsv.exe (IDT, Inc.)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard)
PRC - C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company)
PRC - \\?\C:\windows\System32\wbem\WMIADAP.EXE ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Notepad++\NppShell_04.dll ()
========== Services (SafeList) ==========
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (STacSV) -- C:\Program Files\IDT\WDM\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) -- C:\Program Files\IDT\WDM\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (HP Support Assistant Service) -- C:\Program Files\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (HPDrvMntSvc.exe) -- C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (Sony PC Companion) -- C:\Program Files\Sony\Sony PC Companion\PCCService.exe (Avanquest Software)
SRV - (sftvsa) -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (wampmysqld) -- c:\wamp\bin\mysql\mysql5.5.16\bin\mysqld.exe ()
SRV - (wampapache) -- c:\wamp\bin\apache\Apache2.2.21\bin\httpd.exe (Apache Software Foundation)
SRV - (IJPLMSVC) -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (HP Wireless Assistant Service) -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard)
SRV - (pdfcDispatcher) -- C:\Program Files\PDF Complete\pdfsvc.exe (PDF Complete Inc)
SRV - (hpHotkeyMonitor) -- C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company)
SRV - (RoxMediaDB10) -- c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (pccsmcfd) -- system32\DRIVERS\pccsmcfd.sys File not found
DRV - (hwusbdev) -- system32\DRIVERS\ewusbdev.sys File not found
DRV - (hwdatacard) -- system32\DRIVERS\ewusbmdm.sys File not found
DRV - (CpqDfw) -- system32\drivers\CpqDfw.sys File not found
DRV - (btwrchid) -- system32\DRIVERS\btwrchid.sys File not found
DRV - (btwl2cap) -- system32\DRIVERS\btwl2cap.sys File not found
DRV - (btwavdt) -- system32\DRIVERS\btwavdt.sys File not found
DRV - (btwaudio) -- system32\drivers\btwaudio.sys File not found
DRV - (BCM42RLY) -- system32\drivers\BCM42RLY.sys File not found
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (STHDA) -- C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (sptd) -- C:\Windows\System32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (rtsuvc) -- C:\Windows\System32\drivers\rtsuvc.sys (Realtek Semiconductor Corp.)
DRV - (Sftvol) -- C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) -- C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) -- C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) -- C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (AFD) -- C:\Windows\System32\drivers\afd.sys ()
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (AtiHdmiService) -- C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (HpqKbFiltr) -- C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Company)
DRV - (AtiPcie) -- C:\Windows\System32\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (TPM) -- C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = Qvo6.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = SearchCompletion Search
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = SearchCompletion Search
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = SearchCompletion Search
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = SearchCompletion Search
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Qvo6.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = SearchCompletion Search
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = SearchCompletion Search
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = SearchCompletion Search
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = SearchCompletion Search
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = SearchCompletion Search
IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DE&userid=1f42840d-df23-418d-b13d-53335b2500fc&searchtype=ds&q={searchTerms}&installDate={installDate}
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = Qvo6.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = Qvo6.com
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = SearchCompletion Search
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DE&userid=1f42840d-df23-418d-b13d-53335b2500fc&searchtype=ds&q={searchTerms}&installDate={installDate}
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DE&userid=1f42840d-df23-418d-b13d-53335b2500fc&searchtype=ds&q={searchTerms}&installDate={installDate}
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = SearchCompletion Search
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Yahoo! Deutschland
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DE&userid=1f42840d-df23-418d-b13d-53335b2500fc&searchtype=ds&q={searchTerms}&installDate={installDate}
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = SearchCompletion Search
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = SearchCompletion Search
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DE&userid=1f42840d-df23-418d-b13d-53335b2500fc&searchtype=ds&q={searchTerms}&installDate={installDate}
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = SearchCompletion Search
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = SearchCompletion Search
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\..\SearchScopes,DefaultScope = {8EEAC88A-079B-4b2c-80C1-7836F79EB40A}
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = hxxp://feed.snap.do/?publisher=InternetTurboYB&dpid=InternetTurboYB&co=DE&userid=1f42840d-df23-418d-b13d-53335b2500fc&searchtype=ds&q={searchTerms}&installDate={installDate}
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = Qvo6.com
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\..\SearchScopes\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-comodo"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-comodo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "hxxp://de.yahoo.com?fr=fp-comodo"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0
FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=ytff-comodo&p="
FF - user.js - File not found
[2013/05/07 17:42:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\gosia\AppData\Roaming\mozilla\Extensions
[2012/10/26 17:48:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\gosia\AppData\Roaming\mozilla\Extensions\{718e30fb-e89b-41dd-9da7-e25a45638b28}
[2012/10/26 17:48:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\gosia\AppData\Roaming\mozilla\Sunbird\Profiles\qhwdp6qc.default\extensions
O1 HOSTS File: ([2011/08/30 15:50:28 | 000,000,949 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost127.0.0.1 localhost127.0.0.1 localhost127.0.0.1 localhost127.0.0.1 localhost
O2 - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\gosia\AppData\Roaming\Complitly\Complitly.dll File not found
O2 - BHO: (Reg Error: Value error.) - {2B3B078B-6D29-48B6-A437-4C9C3615FBF5} - C:\Program Files\billigerde\Internet Explorer\billigerde.dll File not found
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Reg Error: Value error.) - {88985437-C8E7-4E5D-9A11-4004B33B39A6} - C:\Program Files\pcwelt\Internet Explorer\pcwelt.dll (solute gmbh)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - No CLSID value found.
O3 - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\..\Toolbar\WebBrowser: (no name) - {DB9D7A78-A76C-4BF2-97C6-258925EE1542} - No CLSID value found.
O3 - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\..\Toolbar\WebBrowser: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKLM..\RunOnceEx: [ContentMerger] c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe (Sonic Solutions)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O7 - HKU\S-1-5-21-1522757586-4258725587-572043408-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html File not found
O9 - Extra Button: @C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains: //about.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Exclude.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //FWEvent.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //LanguageSelection.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Message.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryCmd.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryNag.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyNotification.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //NOCLessUpdate.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //quarantine.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //ScanNow.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //strings.vbs/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Template.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Update.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //VirFound.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] https in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BFFB692C-A235-44D3-B147-7F82298F2BD9}: NameServer = 193.189.244.206 193.189.244.225
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C1DA1AF1-7003-42A2-B7C1-41AC2FA88546}: NameServer = 192.168.1.1,194.25.2.129
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{1ccfa052-89e5-11e0-b86b-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{1ccfa052-89e5-11e0-b86b-806e6f6e6963}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{3442fbf7-9a6e-11e0-b9fd-1cc1de9e5b8e}\Shell - "" = AutoRun
O33 - MountPoints2\{3442fbf7-9a6e-11e0-b9fd-1cc1de9e5b8e}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{55ba63ec-df49-11e0-bf33-1cc1de9e5b8e}\Shell - "" = AutoRun
O33 - MountPoints2\{55ba63ec-df49-11e0-bf33-1cc1de9e5b8e}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{a7bc90f4-049f-11e2-afaf-70f3957f6ce9}\Shell - "" = AutoRun
O33 - MountPoints2\{a7bc90f4-049f-11e2-afaf-70f3957f6ce9}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{b020b07b-50f4-11e1-806e-1cc1de9e5b8e}\Shell - "" = AutoRun
O33 - MountPoints2\{b020b07b-50f4-11e1-806e-1cc1de9e5b8e}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{b558c072-dd32-11df-b771-002682a8fb8a}\Shell - "" = AutoRun
O33 - MountPoints2\{b558c072-dd32-11df-b771-002682a8fb8a}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{c92e03fd-dced-11df-85ad-70f3957f6ce9}\Shell - "" = AutoRun
O33 - MountPoints2\{c92e03fd-dced-11df-85ad-70f3957f6ce9}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{c92e040d-dced-11df-85ad-70f3957f6ce9}\Shell - "" = AutoRun
O33 - MountPoints2\{c92e040d-dced-11df-85ad-70f3957f6ce9}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{c92e0426-dced-11df-85ad-70f3957f6ce9}\Shell - "" = AutoRun
O33 - MountPoints2\{c92e0426-dced-11df-85ad-70f3957f6ce9}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{cca50e75-89e5-11e0-ba82-1cc1de9e5b8e}\Shell - "" = AutoRun
O33 - MountPoints2\{cca50e75-89e5-11e0-ba82-1cc1de9e5b8e}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{cca50e84-89e5-11e0-ba82-1cc1de9e5b8e}\Shell - "" = AutoRun
O33 - MountPoints2\{cca50e84-89e5-11e0-ba82-1cc1de9e5b8e}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/05/19 10:23:31 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\gosia\Desktop\OTL.exe
[2013/05/17 21:02:53 | 000,000,000 | ---D | C] -- C:\Users\gosia\AppData\Local\Diagnostics
[2013/05/17 07:36:26 | 000,000,000 | ---D | C] -- C:\Users\gosia\AppData\Local\ATI
[2013/05/17 07:35:45 | 000,000,000 | ---D | C] -- C:\Users\gosia\AppData\Local\PDFC
[2013/05/17 07:35:01 | 000,000,000 | ---D | C] -- C:\Users\gosia\AppData\Local\VirtualStore
[2013/05/16 21:58:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/05/16 21:57:58 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys
[2013/05/16 18:39:48 | 000,000,000 | ---D | C] -- C:\Users\gosia\AppData\Roaming\Malwarebytes
[2013/05/16 18:39:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/05/16 18:39:32 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013/05/16 17:29:56 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\gosia\Desktop\mbam-setup-1.75.0.1300.exe
[2013/05/16 17:11:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2013/05/16 17:11:57 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2013/05/08 19:40:43 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013/05/08 19:25:19 | 000,000,000 | ---D | C] -- C:\ProgramData\COMODO
[2013/05/08 19:24:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
[2013/05/08 19:24:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo Downloader
[2013/05/08 00:14:25 | 000,000,000 | ---D | C] -- C:\Users\gosia\AppData\Local\ElevatedDiagnostics
[2013/05/07 21:02:54 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2013/05/07 17:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\337
[2013/05/07 17:50:14 | 000,000,000 | ---D | C] -- C:\ProgramData\eSafe
[2013/05/07 17:42:21 | 000,000,000 | ---D | C] -- C:\Users\gosia\Desktop\Download
[2013/05/07 17:42:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder
[2013/05/06 18:40:14 | 000,000,000 | ---D | C] -- C:\Users\gosia\Documents\DreamVideoSoft
[2013/04/30 09:28:20 | 002,877,440 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\jscript9.dll
[2013/04/30 09:28:20 | 002,706,432 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mshtml.tlb
[2013/04/30 09:28:20 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\inetcpl.cpl
[2013/04/30 09:28:20 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ieapfltr.dat
[2013/04/30 09:28:20 | 000,745,472 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\MsSpellCheckingFacility.exe
[2013/04/30 09:28:20 | 000,719,360 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mshtmlmedia.dll
[2013/04/30 09:28:20 | 000,629,248 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ieapfltr.dll
[2013/04/30 09:28:20 | 000,493,056 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeeds.dll
[2013/04/30 09:28:20 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ieui.dll
[2013/04/30 09:28:20 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\html.iec
[2013/04/30 09:28:20 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\dxtmsft.dll
[2013/04/30 09:28:20 | 000,242,200 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iedkcs32.dll
[2013/04/30 09:28:20 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\url.dll
[2013/04/30 09:28:20 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\dxtrans.dll
[2013/04/30 09:28:20 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\elshyph.dll
[2013/04/30 09:28:20 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msrating.dll
[2013/04/30 09:28:20 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msls31.dll
[2013/04/30 09:28:20 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iexpress.exe
[2013/04/30 09:28:20 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\wextract.exe
[2013/04/30 09:28:20 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ieUnatt.exe
[2013/04/30 09:28:20 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iepeers.dll
[2013/04/30 09:28:20 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\IEAdvpack.dll
[2013/04/30 09:28:20 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iesysprep.dll
[2013/04/30 09:28:20 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\inseng.dll
[2013/04/30 09:28:20 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\SetIEInstalledDate.exe
[2013/04/30 09:28:20 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\RegisterIEPKEYs.exe
[2013/04/30 09:28:20 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iesetup.dll
[2013/04/30 09:28:20 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\pngfilt.dll
[2013/04/30 09:28:20 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mshtmler.dll
[2013/04/30 09:28:20 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ie4uinit.exe
[2013/04/30 09:28:20 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeedsbs.dll
[2013/04/30 09:28:20 | 000,039,424 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\jsproxy.dll
[2013/04/30 09:28:20 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\imgutil.dll
[2013/04/30 09:28:20 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iernonce.dll
[2013/04/30 09:28:20 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\licmgr10.dll
[2013/04/30 09:28:20 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeedssync.exe
[2013/04/25 00:14:09 | 000,000,000 | ---D | C] -- C:\Users\gosia\AppData\Roaming\MS-Buchhalter
[2013/04/25 00:14:09 | 000,000,000 | ---D | C] -- C:\ProgramData\MS-Buchhalter
[2013/04/25 00:14:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MS-Buchhalter Start
[2013/04/25 00:14:00 | 000,000,000 | ---D | C] -- C:\Program Files\MS-Buchhalter
[2013/04/23 09:29:28 | 000,000,000 | ---D | C] -- C:\Users\gosia\Desktop\Entpacken
[2013/04/23 09:20:07 | 000,000,000 | ---D | C] -- C:\Users\gosia\Desktop\EmailAnhang
[2013/04/22 21:23:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013/04/22 21:23:35 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013/04/20 14:19:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer
[2013/04/20 14:18:41 | 000,000,000 | ---D | C] -- C:\Users\gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movie2KDownloader.com
[2012/04/07 08:52:22 | 016,032,571 | ---- | C] (Romain Bourdon (Roms) ) -- C:\Users\gosia\WampServer2.0i.exe
[2012/04/07 08:48:23 | 000,301,640 | ---- | C] (Softonic) -- C:\Users\gosia\SoftonicDownloader_fuer_wampserver.exe
[2006/09/20 19:46:22 | 004,985,856 | ---- | C] (thaler) -- C:\Program Files\tswebeditor.exe
[22 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/05/19 10:26:56 | 000,019,536 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/19 10:26:56 | 000,019,536 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/19 10:25:41 | 000,654,844 | ---- | M] () -- C:\windows\System32\perfh007.dat
[2013/05/19 10:25:41 | 000,616,686 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2013/05/19 10:25:41 | 000,130,426 | ---- | M] () -- C:\windows\System32\perfc007.dat
[2013/05/19 10:25:41 | 000,106,808 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2013/05/19 10:18:25 | 000,016,384 | ---- | M] () -- C:\windows\System32\Ikeext.etl
[2013/05/19 10:18:11 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2013/05/19 10:18:07 | 801,697,792 | -HS- | M] () -- C:\hiberfil.sys
[2013/05/18 12:24:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\gosia\Desktop\OTL.exe
[2013/05/16 21:58:01 | 000,001,027 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/05/16 17:26:46 | 010,285,040 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\gosia\Desktop\mbam-setup-1.75.0.1300.exe
[2013/05/08 19:43:12 | 000,002,000 | ---- | M] () -- C:\windows\System32\drivers\sfi.dat
[2013/05/08 19:26:16 | 000,000,593 | ---- | M] () -- C:\Users\Public\Desktop\Gemeinsamer Bereich.lnk
[2013/05/07 21:03:01 | 000,001,065 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/05/07 17:49:53 | 000,773,712 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\msvcr100.dll
[2013/05/07 17:49:52 | 000,420,944 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\msvcp100.dll
[2013/05/07 17:49:47 | 000,001,573 | ---- | M] () -- C:\Users\gosia\Desktop\Internet Explorer.lnk
[2013/05/07 17:35:51 | 000,691,592 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\System32\FlashPlayerApp.exe
[2013/05/07 17:35:50 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\System32\FlashPlayerCPLApp.cpl
[2013/05/07 12:57:30 | 000,000,017 | ---- | M] () -- C:\windows\System32\shortcut_ex.dat
[2013/05/03 09:24:43 | 000,010,354 | ---- | M] () -- C:\Users\gosia\Desktop\praktikum_september.odt
[2013/05/02 18:14:39 | 000,013,155 | ---- | M] () -- C:\Users\gosia\Desktop\ratenzahlung_muster.odt
[2013/04/30 09:28:20 | 002,877,440 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\jscript9.dll
[2013/04/30 09:28:20 | 002,706,432 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\mshtml.tlb
[2013/04/30 09:28:20 | 001,441,280 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\inetcpl.cpl
[2013/04/30 09:28:20 | 001,400,416 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\ieapfltr.dat
[2013/04/30 09:28:20 | 000,745,472 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\MsSpellCheckingFacility.exe
[2013/04/30 09:28:20 | 000,719,360 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\mshtmlmedia.dll
[2013/04/30 09:28:20 | 000,629,248 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\ieapfltr.dll
[2013/04/30 09:28:20 | 000,493,056 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\msfeeds.dll
[2013/04/30 09:28:20 | 000,391,168 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\ieui.dll
[2013/04/30 09:28:20 | 000,361,984 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\html.iec
[2013/04/30 09:28:20 | 000,357,888 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\dxtmsft.dll
[2013/04/30 09:28:20 | 000,242,200 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\iedkcs32.dll
[2013/04/30 09:28:20 | 000,232,960 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\url.dll
[2013/04/30 09:28:20 | 000,226,816 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\dxtrans.dll
[2013/04/30 09:28:20 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\elshyph.dll
[2013/04/30 09:28:20 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\msrating.dll
[2013/04/30 09:28:20 | 000,158,720 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\msls31.dll
[2013/04/30 09:28:20 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\iexpress.exe
[2013/04/30 09:28:20 | 000,138,752 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\wextract.exe
[2013/04/30 09:28:20 | 000,137,216 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\ieUnatt.exe
[2013/04/30 09:28:20 | 000,117,248 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\iepeers.dll
[2013/04/30 09:28:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\IEAdvpack.dll
[2013/04/30 09:28:20 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\iesysprep.dll
[2013/04/30 09:28:20 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\inseng.dll
[2013/04/30 09:28:20 | 000,073,728 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\SetIEInstalledDate.exe
[2013/04/30 09:28:20 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\RegisterIEPKEYs.exe
[2013/04/30 09:28:20 | 000,061,440 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\iesetup.dll
[2013/04/30 09:28:20 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\pngfilt.dll
[2013/04/30 09:28:20 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\mshtmler.dll
[2013/04/30 09:28:20 | 000,042,496 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\ie4uinit.exe
[2013/04/30 09:28:20 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\msfeedsbs.dll
[2013/04/30 09:28:20 | 000,039,424 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\jsproxy.dll
[2013/04/30 09:28:20 | 000,038,400 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\imgutil.dll
[2013/04/30 09:28:20 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\iernonce.dll
[2013/04/30 09:28:20 | 000,025,185 | ---- | M] () -- C:\windows\System32\ieuinit.inf
[2013/04/30 09:28:20 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\licmgr10.dll
[2013/04/30 09:28:20 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\msfeedssync.exe
[2013/04/27 14:59:34 | 000,171,877 | ---- | M] () -- C:\Users\gosia\EÜR_Musikschule.tzb
[2013/04/25 00:14:05 | 000,000,984 | ---- | M] () -- C:\Users\Public\Desktop\MS-Buchhalter 3.0 Start.lnk
[2013/04/22 21:40:03 | 000,341,208 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2013/04/22 21:23:42 | 000,000,961 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[22 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/05/16 21:58:01 | 000,001,027 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/05/08 19:26:16 | 000,000,593 | ---- | C] () -- C:\Users\Public\Desktop\Gemeinsamer Bereich.lnk
[2013/05/08 19:26:07 | 000,002,000 | ---- | C] () -- C:\windows\System32\drivers\sfi.dat
[2013/05/07 21:03:00 | 000,001,077 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013/05/07 21:03:00 | 000,001,065 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/05/07 12:57:28 | 000,000,017 | ---- | C] () -- C:\windows\System32\shortcut_ex.dat
[2013/05/03 09:24:42 | 000,010,354 | ---- | C] () -- C:\Users\gosia\Desktop\praktikum_september.odt
[2013/05/02 18:14:38 | 000,013,155 | ---- | C] () -- C:\Users\gosia\Desktop\ratenzahlung_muster.odt
[2013/04/30 09:28:20 | 000,025,185 | ---- | C] () -- C:\windows\System32\ieuinit.inf
[2013/04/27 14:59:34 | 000,171,877 | ---- | C] () -- C:\Users\gosia\EÜR_Musikschule.tzb
[2013/04/25 00:14:05 | 000,000,984 | ---- | C] () -- C:\Users\Public\Desktop\MS-Buchhalter 3.0 Start.lnk
[2013/04/22 21:39:50 | 000,341,208 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT
[2013/04/22 21:23:42 | 000,000,961 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013/02/24 12:50:13 | 000,028,672 | ---- | C] () -- C:\windows\System32\hccps.dll
[2013/02/24 12:50:07 | 000,024,576 | ---- | C] () -- C:\windows\System32\hndlib.dll
[2013/02/24 12:50:00 | 000,311,296 | ---- | C] () -- C:\windows\System32\XICrCore.DLL
[2013/02/23 13:08:42 | 000,000,016 | ---- | C] () -- C:\Users\gosia\AppData\Roaming\msregsvv.dll
[2013/02/23 13:08:42 | 000,000,016 | ---- | C] () -- C:\ProgramData\autobk.inc
[2013/01/21 21:44:37 | 000,034,815 | ---- | C] () -- C:\Program Files\Common Files\plugin.crx
[2012/12/26 17:59:45 | 000,002,150 | ---- | C] () -- C:\Users\gosia\.recently-used.xbel
[2012/11/28 11:07:46 | 000,000,082 | ---- | C] () -- C:\windows\odbc_merge.INI
[2012/11/14 00:04:04 | 000,338,432 | ---- | C] () -- C:\windows\System32\sqlite36_engine.dll
[2012/11/08 06:54:54 | 000,000,101 | ---- | C] () -- C:\windows\SAWReg.ini
[2012/06/26 09:44:30 | 000,006,656 | ---- | C] () -- C:\windows\System32\bcmwlrc.dll
[2011/12/16 21:10:07 | 000,000,127 | ---- | C] () -- C:\windows\System32\MRT.INI
[2011/09/28 18:44:14 | 000,179,271 | ---- | C] () -- C:\windows\System32\xlive.dll.cat
[2011/09/08 19:18:37 | 000,032,256 | ---- | C] () -- C:\windows\System32\AVSredirect.dll
[2011/06/16 09:36:43 | 000,338,944 | ---- | C] () -- C:\windows\System32\drivers\afd.sys
[2011/06/10 06:34:52 | 000,080,416 | ---- | C] () -- C:\windows\System32\RtNicProp32.dll
[2011/05/31 13:38:31 | 000,088,576 | ---- | C] () -- C:\windows\AmCap.exe
[2011/01/18 16:41:56 | 088,694,089 | ---- | C] () -- C:\Users\gosia\Al Anderson & Junior Marvin.mp4
[2011/01/16 15:53:25 | 012,633,116 | ---- | C] () -- C:\Users\gosia\Impress eine Präsentation erstellen- erste Schritte.mp4
[2010/12/18 22:13:08 | 007,159,363 | ---- | C] () -- C:\Users\gosia\Dua from Quraan Saad Al-Ghamdee+mp3 Link.mp4
[2010/11/06 00:14:41 | 000,000,088 | RHS- | C] () -- C:\ProgramData\188E6822A8.sys
[2010/11/06 00:14:34 | 000,002,672 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2010/10/28 21:58:11 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2006/09/20 19:46:28 | 000,464,200 | ---- | C] () -- C:\Program Files\tswebeditor.jdbg
[2006/09/17 14:09:06 | 000,034,233 | ---- | C] () -- C:\Program Files\tswebeditor.jpg
[2006/05/28 19:26:06 | 000,014,832 | ---- | C] () -- C:\Program Files\german.lng
[2006/05/28 19:25:32 | 000,029,522 | ---- | C] () -- C:\Program Files\english.lng
========== ZeroAccess Check ==========
[2009/07/14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\windows\$NtUninstallKB1218$] -> Error: Cannot create file handle -> Unknown point type
< End of report > --- --- ---
kamit |