waldhueter | 05.06.2013 10:12 | Hallo Leo, gestern hatte ich leider keine Zeit zum antworten, dafür heute. Die Updates Java und Acrobat habe ich durchgeführt, genauso wie den Fix und den Scan.
Hier die Logs:
vom Fix: Code:
All processes killed
========== OTL ==========
Service qxjdwyf stopped successfully!
Service qxjdwyf deleted successfully!
File C:\WINDOWS\system32\drivers\rvxtjwraw.sys not found.
Registry value HKEY_USERS\S-1-5-21-1250491402-4247718661-2145709833-1136\Software\Microsoft\Windows\CurrentVersion\Run\\qcgce2mrvjq91kk1e7pnbb19m52fx deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1250491402-4247718661-2145709833-1136\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:cmd.exe deleted successfully.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
HKU\S-1-5-21-1250491402-4247718661-2145709833-1136\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
========== COMMANDS ==========
[EMPTYTEMP]
User: admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
User: administrator.WAHL
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Nutzer
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: TEMP.WAHL.004
->Temporary Internet Files folder emptied: 0 bytes
User: wahl2
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 8348391 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 15755970 bytes
->Flash cache emptied: 492 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 118992919 bytes
RecycleBin emptied: 1590 bytes
Total Files Cleaned = 137,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 06042013_102955
Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\hlktmp scheduled to be moved on reboot.
PendingFileRenameOperations files...
Registry entries deleted on Reboot... vom Scan: Code:
OTL logfile created on: 05.06.2013 10:36:19 - Run 6
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\wahl2\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 0,77 Gb Available Physical Memory | 38,73% Memory free
3,85 Gb Paging File | 2,79 Gb Available in Paging File | 72,41% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 200,09 Gb Total Space | 175,43 Gb Free Space | 87,67% Space Free | Partition Type: NTFS
Drive D: | 353,74 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF
Drive E: | 265,67 Gb Total Space | 265,59 Gb Free Space | 99,97% Space Free | Partition Type: NTFS
Drive F: | 380,35 Gb Total Space | 104,96 Gb Free Space | 27,59% Space Free | Partition Type: NTFS
Drive G: | 380,35 Gb Total Space | 104,96 Gb Free Space | 27,59% Space Free | Partition Type: NTFS
Drive R: | 380,35 Gb Total Space | 104,96 Gb Free Space | 27,59% Space Free | Partition Type: NTFS
Drive V: | 380,35 Gb Total Space | 104,96 Gb Free Space | 27,59% Space Free | Partition Type: NTFS
Computer Name: HR_WAHL_2009 | User Name: wahl2 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.06.04 10:47:40 | 000,181,664 | ---- | M] (Oracle Corporation) -- C:\Programme\Java\jre7\bin\jqs.exe
PRC - [2013.05.30 15:17:55 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\wahl2\Desktop\OTL.exe
PRC - [2013.05.12 00:26:08 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe
PRC - [2010.08.04 10:51:34 | 003,889,064 | ---- | M] (CANON INC.) -- C:\Programme\Canon\DIAS\CnxDIAS.exe
PRC - [2008.04.14 14:00:00 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006.12.20 02:50:00 | 000,136,768 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee\Common Framework\naPrdMgr.exe
PRC - [2006.12.20 02:50:00 | 000,104,000 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee\Common Framework\FrameworkService.exe
PRC - [2006.11.30 09:50:00 | 000,144,960 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee\VirusScan Enterprise\Mcshield.exe
PRC - [2006.11.30 09:50:00 | 000,054,872 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee\VirusScan Enterprise\VsTskMgr.exe
========== Modules (No Company Name) ==========
MOD - [2013.05.12 00:26:24 | 003,128,728 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll
MOD - [2008.10.07 13:33:00 | 000,466,944 | ---- | M] () -- C:\WINDOWS\system32\nvshell.dll
MOD - [2008.05.02 06:15:37 | 000,010,240 | ---- | M] () -- C:\Programme\Unlocker\UnlockerCOM.dll
MOD - [2008.04.14 14:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2006.12.20 02:50:00 | 000,120,384 | ---- | M] () -- C:\Programme\McAfee\Common Framework\naXML71.dll
MOD - [2006.12.20 02:50:00 | 000,071,232 | ---- | M] () -- C:\Programme\McAfee\Common Framework\naisign.dll
MOD - [2006.11.30 09:50:00 | 000,149,080 | ---- | M] () -- C:\Programme\McAfee\VirusScan Enterprise\VsEvntUI.DLL
========== Services (SafeList) ==========
SRV - [2013.06.04 10:47:40 | 000,181,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Programme\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2013.05.15 15:45:15 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.05.12 00:26:17 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2011.07.20 05:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2010.08.04 10:51:34 | 003,889,064 | ---- | M] (CANON INC.) [Auto | Running] -- C:\Programme\Canon\DIAS\CnxDIAS.exe -- (Canon Driver Information Assist Service)
SRV - [2010.07.08 16:13:38 | 001,841,664 | ---- | M] (KS System GmbH) [Disabled | Stopped] -- C:\Programme\Terminal Download II\GhostDownload2ServV100.exe -- (GhostDownload2Service)
SRV - [2008.06.24 17:05:56 | 000,537,896 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2006.12.20 02:50:00 | 000,104,000 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Programme\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2006.11.30 09:50:00 | 000,144,960 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Programme\McAfee\VirusScan Enterprise\Mcshield.exe -- (McShield)
SRV - [2006.11.30 09:50:00 | 000,054,872 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Programme\McAfee\VirusScan Enterprise\VsTskMgr.exe -- (McTaskManager)
SRV - [2006.10.26 15:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2013.02.12 02:32:23 | 000,012,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS_XP)
DRV - [2009.06.05 09:16:32 | 000,142,336 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2008.10.13 18:26:10 | 004,879,360 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2006.11.30 09:50:00 | 000,168,776 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2006.11.30 09:50:00 | 000,072,264 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2006.11.30 09:50:00 | 000,064,360 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2006.11.30 09:50:00 | 000,052,136 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mfetdik.sys -- (mfetdik)
DRV - [2006.11.30 09:50:00 | 000,034,152 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2006.11.30 09:50:00 | 000,031,944 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Programme\McAfee\VirusScan Enterprise\mferkdk.sys -- (mferkdk)
DRV - [2006.11.22 10:01:48 | 000,693,760 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.60.1:80
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.60.1:80
IE - HKU\S-1-5-21-1250491402-4247718661-2145709833-1136\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.de
IE - HKU\S-1-5-21-1250491402-4247718661-2145709833-1136\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de
IE - HKU\S-1-5-21-1250491402-4247718661-2145709833-1136\..\SearchScopes,DefaultScope = {10F64DF7-0E9E-4B9E-A066-6ED38527281D}
IE - HKU\S-1-5-21-1250491402-4247718661-2145709833-1136\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-1250491402-4247718661-2145709833-1136\..\SearchScopes\{10F64DF7-0E9E-4B9E-A066-6ED38527281D}: "URL" = hxxp://www.google.de/search?q={searchTerms}
IE - HKU\S-1-5-21-1250491402-4247718661-2145709833-1136\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1250491402-4247718661-2145709833-1136\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Programme\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins
[2013.06.03 13:54:40 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\wahl2\Anwendungsdaten\Mozilla\Extensions
[2013.06.04 10:36:51 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.05.30 10:09:30 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\browser\extensions
[2013.05.30 10:09:30 | 000,000,000 | ---D | M] (Default) -- C:\Programme\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2013.05.31 14:00:23 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\McAfee\VirusScan Enterprise\ScriptCl.dll (McAfee, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe File not found
O4 - HKU\S-1-5-18..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe File not found
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Backnet Office Pro Synchronisierung.lnk = C:\Bop\bopklient\forms\SyncApp.exe (Backnet E&S)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-21-1250491402-4247718661-2145709833-1136\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-21-1250491402-4247718661-2145709833-1136\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-21-1250491402-4247718661-2145709833-1136\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKU\S-1-5-21-1250491402-4247718661-2145709833-1136\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKU\S-1-5-21-1250491402-4247718661-2145709833-1136\..Trusted Domains: dyndns.org ([wahl-back] HTTPS in Local intranet)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1369898901955 (WUWebControl Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.60.1 192.168.60.254 4.2.2.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wahl.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7FB7C888-1C72-4819-AE57-638213E6DFF5}: DhcpNameServer = 192.168.60.1 192.168.60.254 4.2.2.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F214278F-2202-4950-A9D0-2041A111EDF4}: DhcpNameServer = 192.168.60.1 192.168.60.254 4.2.2.2
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\wahl2\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.12.16 14:38:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.06.05 10:31:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2013.06.04 17:08:45 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
[2013.06.04 17:08:20 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
[2013.06.04 16:55:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTEMP
[2013.06.04 16:55:49 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013.06.04 16:05:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2013.06.04 15:35:32 | 000,081,408 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2013.06.04 15:35:32 | 000,081,408 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2013.06.04 15:35:31 | 000,029,184 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll
[2013.06.04 15:34:26 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2013.06.04 10:57:48 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\wahl2\Anwendungsdaten\ElevatedDiagnostics
[2013.06.04 10:57:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Windows PowerShell 1.0
[2013.06.04 10:57:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell
[2013.06.04 10:49:42 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Adobe
[2013.06.04 10:49:42 | 000,000,000 | ---D | C] -- C:\Programme\Adobe
[2013.06.04 10:48:05 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Sun
[2013.06.04 10:48:04 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Java
[2013.06.04 10:47:33 | 000,000,000 | ---D | C] -- C:\Programme\Java
[2013.06.04 10:43:41 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\wahl2\Desktop\Alte Firefox-Daten
[2013.06.04 10:36:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2013.06.03 17:20:57 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\wahl2\Anwendungsdaten\Windows Search
[2013.06.03 17:12:08 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\wahl2\Desktop\OTL.exe
[2013.06.03 14:50:32 | 000,000,000 | ---D | C] -- C:\Downloads
[2013.06.03 13:54:17 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\wahl2\Anwendungsdaten\Mozilla
[2013.06.03 12:48:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\wahl2\Anwendungsdaten\Windows Desktop Search
[2013.06.01 09:15:19 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\wahl2\Anwendungsdaten\Windows Small Business Server
[2013.05.31 15:06:11 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2013.05.31 15:05:14 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.05.31 13:50:23 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2013.05.31 13:13:27 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2013.05.31 13:13:27 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2013.05.31 13:13:27 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2013.05.31 13:13:27 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2013.05.31 12:54:44 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.05.31 12:54:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2013.05.30 10:09:32 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Maintenance Service
[2013.05.30 10:09:28 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox
[2013.05.30 09:59:45 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\HitmanPro
[2013.05.30 09:59:44 | 000,000,000 | ---D | C] -- C:\Programme\HitmanPro
[2013.05.30 09:59:18 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\HitmanPro
[2013.05.24 09:42:21 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\tmp
[2013.05.24 09:42:21 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\hps
[2013.05.24 09:42:14 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Pixum Fotobuch
[2013.05.24 09:38:53 | 000,000,000 | ---D | C] -- C:\Programme\Pixum
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.06.05 10:45:42 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013.06.05 10:45:15 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013.06.05 10:35:11 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013.06.05 10:35:11 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.bak
[2013.06.05 10:33:59 | 000,200,819 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2013.06.05 10:20:27 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.06.05 10:20:23 | 2145,570,816 | -HS- | M] () -- C:\hiberfil.sys
[2013.06.05 10:20:23 | 000,277,352 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013.06.04 17:15:43 | 000,489,970 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2013.06.04 17:15:43 | 000,446,246 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013.06.04 17:15:43 | 000,096,876 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2013.06.04 17:15:43 | 000,073,528 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013.06.04 16:41:49 | 000,000,846 | RHS- | M] () -- C:\Dokumente und Einstellungen\wahl2\ntuser.pol
[2013.06.04 15:36:25 | 000,000,288 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2013.06.04 15:33:30 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2013.06.04 15:33:29 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2013.06.04 15:33:29 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2013.06.04 15:33:21 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2013.06.04 15:31:32 | 000,023,588 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2013.06.04 15:30:25 | 000,000,282 | -HS- | M] () -- C:\boot.ini
[2013.06.04 15:17:20 | 000,294,243 | ---- | M] () -- C:\WINDOWS\setupapi.old
[2013.06.04 14:46:18 | 000,013,908 | RHS- | M] () -- C:\Dokumente und Einstellungen\All Users\ntuser.pol
[2013.06.04 11:09:14 | 000,002,881 | ---- | M] () -- C:\Dokumente und Einstellungen\wahl2\Desktop\sharedaccess.reg
[2013.06.04 10:50:14 | 000,001,714 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader XI.lnk
[2013.06.03 16:45:22 | 000,890,839 | ---- | M] () -- C:\Dokumente und Einstellungen\wahl2\Desktop\SecurityCheck.exe
[2013.06.01 09:15:20 | 000,000,212 | ---- | M] () -- C:\Dokumente und Einstellungen\wahl2\Desktop\Interne Website.lnk
[2013.05.31 14:00:23 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2013.05.30 15:17:55 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\wahl2\Desktop\OTL.exe
[2013.05.30 10:09:33 | 000,000,696 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2013.05.30 10:07:19 | 000,001,503 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Browserwahl.lnk
[2013.05.30 09:12:55 | 000,000,211 | -HS- | M] () -- C:\Boot.bak
[2013.05.27 13:11:28 | 000,000,432 | ---- | M] () -- C:\WINDOWS\BRWMARK.INI
[2013.05.24 09:42:14 | 000,000,785 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Fotoschau.lnk
[2013.05.24 09:42:13 | 000,000,810 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Pixum Fotobuch.lnk
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[11 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.06.04 16:25:59 | 2145,570,816 | -HS- | C] () -- C:\hiberfil.sys
[2013.06.04 15:35:25 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2013.06.04 15:35:05 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2013.06.04 15:34:56 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2013.06.04 15:34:56 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2013.06.04 15:34:54 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2013.06.04 15:34:48 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2013.06.04 15:34:44 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2013.06.04 15:34:40 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2013.06.04 15:34:28 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2013.06.04 15:17:43 | 000,144,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2013.06.04 15:17:43 | 000,014,433 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn9.cat
[2013.06.04 15:17:42 | 002,039,179 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2013.06.04 15:17:42 | 001,246,537 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP3.CAT
[2013.06.04 15:17:42 | 000,817,199 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2013.06.04 15:17:42 | 000,631,338 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2013.06.04 15:17:42 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2013.06.04 15:17:42 | 000,105,926 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2013.06.04 15:17:42 | 000,041,270 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2013.06.04 15:17:42 | 000,034,747 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2013.06.04 15:17:42 | 000,033,765 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2013.06.04 15:17:42 | 000,021,771 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn7.cat
[2013.06.04 15:17:42 | 000,016,825 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2013.06.04 15:17:42 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2013.06.04 15:17:42 | 000,012,363 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2013.06.04 15:17:42 | 000,010,027 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2013.06.04 15:17:42 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2013.06.04 15:17:42 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2013.06.04 11:09:14 | 000,002,881 | ---- | C] () -- C:\Dokumente und Einstellungen\wahl2\Desktop\sharedaccess.reg
[2013.06.04 10:50:14 | 000,001,714 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader XI.lnk
[2013.06.03 16:43:06 | 000,890,839 | ---- | C] () -- C:\Dokumente und Einstellungen\wahl2\Desktop\SecurityCheck.exe
[2013.05.31 13:50:26 | 000,000,211 | -HS- | C] () -- C:\Boot.bak
[2013.05.31 13:50:23 | 000,262,448 | RHS- | C] () -- C:\cmldr
[2013.05.31 13:13:27 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2013.05.31 13:13:27 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2013.05.31 13:13:27 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2013.05.31 13:13:27 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2013.05.31 13:13:27 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2013.05.30 10:09:33 | 000,000,702 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Mozilla Firefox.lnk
[2013.05.30 10:09:33 | 000,000,696 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2013.05.30 10:07:19 | 000,001,503 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Browserwahl.lnk
[2013.05.30 09:43:17 | 000,001,355 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2013.05.30 09:28:48 | 000,294,243 | ---- | C] () -- C:\WINDOWS\setupapi.old
[2013.05.24 09:42:14 | 000,000,785 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Fotoschau.lnk
[2013.05.24 09:42:13 | 000,000,810 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Pixum Fotobuch.lnk
[2012.02.14 23:17:18 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.01.13 22:49:13 | 000,073,728 | R--- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2011.11.08 11:07:34 | 000,000,432 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2011.08.01 11:47:05 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\hlduinst.exe
[2011.08.01 11:47:04 | 000,006,836 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.INI
[2011.08.01 10:57:44 | 000,000,787 | ---- | C] () -- C:\WINDOWS\UninstBOP.ini
[2011.07.26 11:07:59 | 000,000,846 | RHS- | C] () -- C:\Dokumente und Einstellungen\wahl2\ntuser.pol
[2010.07.26 13:16:16 | 000,005,632 | ---- | C] () -- C:\Dokumente und Einstellungen\wahl2\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.05.29 12:41:06 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\wahl2\KeyTools.lck
[2009.05.29 12:41:06 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\wahl2\KeyToolHidCom_6006347.lck
[2009.05.29 12:37:34 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\wahl2\AutoStarter.lck
[2009.05.29 12:34:11 | 000,035,941 | ---- | C] () -- C:\Programme\buildlog.xml
[2009.01.19 14:34:20 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\wahl2\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2009.01.19 12:18:22 | 000,013,908 | RHS- | C] () -- C:\Dokumente und Einstellungen\All Users\ntuser.pol
========== ZeroAccess Check ==========
[2008.12.16 14:47:34 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2011.06.21 20:18:34 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.02.09 12:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 14:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013.05.30 11:26:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\admin\Anwendungsdaten\QuickScan
[2008.12.16 14:59:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\admin\Anwendungsdaten\Windows Desktop Search
[2013.05.30 09:09:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\admin\Anwendungsdaten\Windows Small Business Server
[2008.12.16 14:59:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Windows Desktop Search
[2011.12.28 10:44:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Windows Search
[2009.07.22 12:58:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\administrator.WAHL\Anwendungsdaten\Continental Trading GmbH
[2008.12.16 14:59:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\administrator.WAHL\Anwendungsdaten\Windows Desktop Search
[2011.09.05 13:33:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\administrator.WAHL\Anwendungsdaten\Windows Small Business Server
[2011.05.05 11:13:25 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Canon
[2013.05.30 10:04:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\HitmanPro
[2010.12.15 12:11:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Terminal Download II
[2013.06.04 12:05:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\tmp
[2008.12.16 14:59:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Default User\Anwendungsdaten\Windows Desktop Search
[2008.12.16 14:59:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Nutzer\Anwendungsdaten\Windows Desktop Search
[2013.06.04 10:57:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\wahl2\Anwendungsdaten\ElevatedDiagnostics
[2013.06.03 12:48:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\wahl2\Anwendungsdaten\Windows Desktop Search
[2013.06.03 17:20:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\wahl2\Anwendungsdaten\Windows Search
[2013.06.01 09:15:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\wahl2\Anwendungsdaten\Windows Small Business Server
========== Purity Check ==========
< End of report > |