Connemara | 08.07.2013 13:03 | OTL Logfile: Code:
OTL logfile created on: 08.07.2013 13:47:28 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Hanna\Desktop\Viren
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,93 Gb Total Physical Memory | 1,70 Gb Available Physical Memory | 57,86% Memory free
6,08 Gb Paging File | 4,61 Gb Available in Paging File | 75,86% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288,08 Gb Total Space | 234,56 Gb Free Space | 81,42% Space Free | Partition Type: NTFS
Computer Name: HANNA-PC | User Name: Hanna | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files\HitmanPro\hmpsched.exe (SurfRight B.V.)
PRC - C:\Users\Hanna\Desktop\Viren\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
PRC - C:\Users\Hanna\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
PRC - c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG)
PRC - C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (Deutsche Telekom AG)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe ()
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\93c9e616b0bf994a9fe885dd4f460218\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\36dc923935a96557c81daa014e7e2ba8\System.EnterpriseServices.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\d995a0e7d64a874cddea6294caaa2539\System.Transactions.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\421cb77e6a4c21f94e3c5ddf766de23b\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\895899bb8c1772f2043de17305d7eb35\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\eb525a947a47b0e41bfabf91855e7459\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\3da65115bf9debbf564861f6b123a2e4\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\bb8af3cf69f1337efda4e810b6751b89\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b757806657fa5db2b1ed1a89b026b463\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e9ea3e70247b4aa4a8b260426db3aa6b\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\78157a494dc9a7e52be8840decfcd9cc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\4d2c890606d2a3a43a90684115bfccfc\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2673a8a481ae675588349b79b521cec1\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\a3968930e9e2ae833447b0a280082073\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\fe2a238282c6fedc2a21b3dd25885437\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cc149d08e75f8c53cd28ac926b38c370\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\2227d1559f87943255069398608d5c56\mscorlib.ni.dll ()
MOD - C:\Users\Hanna\AppData\Roaming\Dropbox\bin\libcef.dll ()
MOD - C:\Users\Hanna\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.ServiceModel.resources\3.0.0.0_de_b77a5c561934e089\System.ServiceModel.resources.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_de_b77a5c561934e089\System.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Xml.resources\2.0.0.0_de_b77a5c561934e089\System.Xml.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\PresentationCore.resources\3.0.0.0_de_31bf3856ad364e35\PresentationCore.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Serialization.resources\3.0.0.0_de_b77a5c561934e089\System.Runtime.Serialization.resources.dll ()
MOD - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTrayLOC.dll ()
========== Services (SafeList) ==========
SRV - (HitmanProScheduler) -- C:\Program Files\HitmanPro\hmpsched.exe (SurfRight B.V.)
SRV - (BingDesktopUpdate) -- C:\Program Files\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.)
SRV - (NisSrv) -- c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (BBSvc) -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (Netzmanager Service) -- C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (Deutsche Telekom AG)
SRV - (ETService) -- C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe ()
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (IviRegMgr) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
========== Driver Services (SafeList) ==========
DRV - (zpnnlqgu) -- C:\Windows\system32\drivers\zpnnlqgu.sys File not found
DRV - (zhhohjdn) -- C:\Windows\system32\drivers\zhhohjdn.sys File not found
DRV - (ycqhnloq) -- C:\Windows\system32\drivers\ycqhnloq.sys File not found
DRV - (xvysrriv) -- C:\Windows\system32\drivers\xvysrriv.sys File not found
DRV - (wpmqlqgd) -- C:\Windows\system32\drivers\wpmqlqgd.sys File not found
DRV - (wpddpvvm) -- C:\Windows\system32\drivers\wpddpvvm.sys File not found
DRV - (wikoztsj) -- C:\Windows\system32\drivers\wikoztsj.sys File not found
DRV - (whqdilhl) -- C:\Windows\system32\drivers\whqdilhl.sys File not found
DRV - (wgriqhda) -- C:\Windows\system32\drivers\wgriqhda.sys File not found
DRV - (wduvamgn) -- C:\Windows\system32\drivers\wduvamgn.sys File not found
DRV - (vlqoefga) -- C:\Windows\system32\drivers\vlqoefga.sys File not found
DRV - (vildfska) -- C:\Windows\system32\drivers\vildfska.sys File not found
DRV - (vhmlfgnv) -- C:\Windows\system32\drivers\vhmlfgnv.sys File not found
DRV - (vewtcbpb) -- C:\Windows\system32\drivers\vewtcbpb.sys File not found
DRV - (ujaqhsqy) -- C:\Windows\system32\drivers\ujaqhsqy.sys File not found
DRV - (uepbqtfa) -- C:\Windows\system32\drivers\uepbqtfa.sys File not found
DRV - (szfeofbd) -- C:\Windows\system32\drivers\szfeofbd.sys File not found
DRV - (sukifpdx) -- C:\Windows\system32\drivers\sukifpdx.sys File not found
DRV - (smdnbrfu) -- C:\Windows\system32\drivers\smdnbrfu.sys File not found
DRV - (sejafszk) -- C:\Windows\system32\drivers\sejafszk.sys File not found
DRV - (sdyslqfg) -- C:\Windows\system32\drivers\sdyslqfg.sys File not found
DRV - (saeacjqj) -- C:\Windows\system32\drivers\saeacjqj.sys File not found
DRV - (rulvxbun) -- C:\Windows\system32\drivers\rulvxbun.sys File not found
DRV - (rpxapolq) -- C:\Windows\system32\drivers\rpxapolq.sys File not found
DRV - (rhkplgwu) -- C:\Windows\system32\drivers\rhkplgwu.sys File not found
DRV - (rgxkmttj) -- C:\Windows\system32\drivers\rgxkmttj.sys File not found
DRV - (qstzxuhm) -- C:\Windows\system32\drivers\qstzxuhm.sys File not found
DRV - (qpqgvjav) -- C:\Windows\system32\drivers\qpqgvjav.sys File not found
DRV - (qkvropkb) -- C:\Windows\system32\drivers\qkvropkb.sys File not found
DRV - (qikqudhb) -- C:\Windows\system32\drivers\qikqudhb.sys File not found
DRV - (qhqacqdw) -- C:\Windows\system32\drivers\qhqacqdw.sys File not found
DRV - (qaguxzum) -- C:\Windows\system32\drivers\qaguxzum.sys File not found
DRV - (pyofpkri) -- C:\Windows\system32\drivers\pyofpkri.sys File not found
DRV - (pqjnmqma) -- C:\Windows\system32\drivers\pqjnmqma.sys File not found
DRV - (pcbiiwiv) -- C:\Windows\system32\drivers\pcbiiwiv.sys File not found
DRV - (oqvnraux) -- C:\Windows\system32\drivers\oqvnraux.sys File not found
DRV - (ookslhnv) -- C:\Windows\system32\drivers\ookslhnv.sys File not found
DRV - (ojutlavf) -- C:\Windows\system32\drivers\ojutlavf.sys File not found
DRV - (nzmbgvme) -- C:\Windows\system32\drivers\nzmbgvme.sys File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (nmakobim) -- C:\Windows\system32\drivers\nmakobim.sys File not found
DRV - (mpelvrzl) -- C:\Windows\system32\drivers\mpelvrzl.sys File not found
DRV - (mfjmcbdz) -- C:\Windows\system32\drivers\mfjmcbdz.sys File not found
DRV - (lqybegeo) -- C:\Windows\system32\drivers\lqybegeo.sys File not found
DRV - (lpptswil) -- C:\Windows\system32\drivers\lpptswil.sys File not found
DRV - (loctzsie) -- C:\Windows\system32\drivers\loctzsie.sys File not found
DRV - (lksnseyp) -- C:\Windows\system32\drivers\lksnseyp.sys File not found
DRV - (lguaqttw) -- C:\Windows\system32\drivers\lguaqttw.sys File not found
DRV - (lfssgnvy) -- C:\Windows\system32\drivers\lfssgnvy.sys File not found
DRV - (kquxfouq) -- C:\Windows\system32\drivers\kquxfouq.sys File not found
DRV - (klrntvnk) -- C:\Windows\system32\drivers\klrntvnk.sys File not found
DRV - (jyftkbgr) -- C:\Windows\system32\drivers\jyftkbgr.sys File not found
DRV - (jnbosovs) -- C:\Windows\system32\drivers\jnbosovs.sys File not found
DRV - (jmzsylmz) -- C:\Windows\system32\drivers\jmzsylmz.sys File not found
DRV - (iugnudez) -- C:\Windows\system32\drivers\iugnudez.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (hwdatacard) -- system32\DRIVERS\ewusbmdm.sys File not found
DRV - (huotufyo) -- C:\Windows\system32\drivers\huotufyo.sys File not found
DRV - (hmzcnucm) -- C:\Windows\system32\drivers\hmzcnucm.sys File not found
DRV - (hmhwazky) -- C:\Windows\system32\drivers\hmhwazky.sys File not found
DRV - (gvcruzyt) -- C:\Windows\system32\drivers\gvcruzyt.sys File not found
DRV - (gqtapwpm) -- C:\Windows\system32\drivers\gqtapwpm.sys File not found
DRV - (gnuwogzg) -- C:\Windows\system32\drivers\gnuwogzg.sys File not found
DRV - (gnkropup) -- C:\Windows\system32\drivers\gnkropup.sys File not found
DRV - (gksmkjpj) -- C:\Windows\system32\drivers\gksmkjpj.sys File not found
DRV - (ggxxvjrb) -- C:\Windows\system32\drivers\ggxxvjrb.sys File not found
DRV - (fpugudpo) -- C:\Windows\system32\drivers\fpugudpo.sys File not found
DRV - (ekmlgvdv) -- C:\Windows\system32\drivers\ekmlgvdv.sys File not found
DRV - (egxmgzqs) -- C:\Windows\system32\drivers\egxmgzqs.sys File not found
DRV - (ebfgapfz) -- C:\Windows\system32\drivers\ebfgapfz.sys File not found
DRV - (dvinguwj) -- C:\Windows\system32\drivers\dvinguwj.sys File not found
DRV - (DritekPortIO) -- C:\PROGRA~1\LAUNCH~1\DPortIO.sys File not found
DRV - (dpjqrnkw) -- C:\Windows\system32\drivers\dpjqrnkw.sys File not found
DRV - (dhomzlpo) -- C:\Windows\system32\drivers\dhomzlpo.sys File not found
DRV - (dgkupvxr) -- C:\Windows\system32\drivers\dgkupvxr.sys File not found
DRV - (cxtarluf) -- C:\Windows\system32\drivers\cxtarluf.sys File not found
DRV - (cuybmpcq) -- C:\Windows\system32\drivers\cuybmpcq.sys File not found
DRV - (cdvczbkm) -- C:\Windows\system32\drivers\cdvczbkm.sys File not found
DRV - (cbjmreek) -- C:\Windows\system32\drivers\cbjmreek.sys File not found
DRV - (catchme) -- C:\Users\Hanna\AppData\Local\Temp\catchme.sys File not found
DRV - (brqnibiq) -- C:\Windows\system32\drivers\brqnibiq.sys File not found
DRV - (bkgrynvj) -- C:\Windows\system32\drivers\bkgrynvj.sys File not found
DRV - (bhckyxba) -- C:\Windows\system32\drivers\bhckyxba.sys File not found
DRV - (azimzwac) -- C:\Windows\system32\drivers\azimzwac.sys File not found
DRV - (assfgepf) -- C:\Windows\system32\drivers\assfgepf.sys File not found
DRV - (asrwumcr) -- C:\Windows\system32\drivers\asrwumcr.sys File not found
DRV - (ashqevxg) -- C:\Windows\system32\drivers\ashqevxg.sys File not found
DRV - (aqkhnymt) -- C:\Windows\system32\drivers\aqkhnymt.sys File not found
DRV - (amdcsfmn) -- C:\Windows\system32\drivers\amdcsfmn.sys File not found
DRV - (afwmrqtc) -- C:\Windows\system32\drivers\afwmrqtc.sys File not found
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (NisDrv) -- C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (int15) -- C:\Windows\System32\drivers\int15.sys (Acer, Inc.)
DRV - (ApfiltrService) -- C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (regi) -- C:\Windows\System32\drivers\regi.sys (InterVideo)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0407&s=2&o=vp32&d=0209&m=e720
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACEW
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{36377DD7-B3EB-42f5-986F-680BAF59BA9D}: "URL" = hxxp://start.iplay.com/searchresults.aspx?o=chrome&q={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{BB17F21B-B06E-41FE-A424-F1E51D59C2C0}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ACEW_de
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/webhp?rls=ig"
FF - prefs.js..extensions.enabledAddons: firefox%40ghostery.com:2.8.3
FF - prefs.js..extensions.enabledAddons: ich%40maltegoetz.de:1.4.3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.11.3.100008
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:3.6.0.10
FF - prefs.js..extensions.enabledItems: de-DE@dictionaries.addons.mozilla.org:2.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:3.6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.0.19
FF - prefs.js..extensions.enabledItems: {f4e6547e-325b-403c-a3bb-ad29ed37a92f}:3.6.0.10
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}:3.6.0.10
FF - prefs.js..extensions.enabledItems: gamesbar@oberon-media.com:1.2.1.94
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Components: C:\program files\Mozilla Firefox\components [2013.07.05 21:00:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Plugins: C:\program files\Mozilla Firefox\plugins [2013.07.08 10:30:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.06.27 09:56:04 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\extensions\\{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}: C:\Users\Hanna\AppData\Roaming\14001.019
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.06.27 09:56:04 | 000,000,000 | ---D | M]
[2009.11.22 00:10:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hanna\AppData\Roaming\mozilla\Extensions
[2012.11.24 23:28:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hanna\AppData\Roaming\mozilla\Firefox\Profiles\i9p06hy1.default\extensions
[2011.12.12 20:41:02 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Hanna\AppData\Roaming\mozilla\Firefox\Profiles\i9p06hy1.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}(7)
[2012.10.25 20:17:53 | 000,000,000 | ---D | M] (Ghostery) -- C:\Users\Hanna\AppData\Roaming\mozilla\Firefox\Profiles\i9p06hy1.default\extensions\firefox@ghostery.com
[2012.11.24 23:28:07 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Hanna\AppData\Roaming\mozilla\Firefox\Profiles\i9p06hy1.default\extensions\ich@maltegoetz.de
[2009.12.27 22:04:35 | 000,002,321 | ---- | M] () -- C:\Users\Hanna\AppData\Roaming\mozilla\firefox\profiles\i9p06hy1.default\searchplugins\forestle-de.xml
[2013.02.22 12:08:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013.02.16 02:34:54 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013.02.16 06:15:47 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.02.16 06:15:47 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013.02.16 06:15:47 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2013.02.16 06:15:47 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.01.08 22:32:42 | 000,001,456 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\WebSearchober19111479.xml
[2013.02.16 06:15:47 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2013.02.16 06:15:47 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - homepage: hxxp://www.google.com
O1 HOSTS File: ([2013.07.04 16:28:05 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BingDesktop] C:\Program Files\Microsoft\BingDesktop\BingDesktop.exe (Microsoft Corp.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [WarReg_PopUp] C:\Program Files\EMACHINES\WR_PopUp\WarReg_PopUp.exe (eMachines)
O4 - HKCU..\Run: [FilterHost] C:\Users\Hanna\AppData\Roaming\mmserver\FilterHost.exe (Synatix GmbH)
O4 - HKCU..\Run: [SearchEngineProtection] C:\Program Files\Gamesbar\SearchEngineProtection.exe File not found
O4 - Startup: C:\Users\Hanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Hanna\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Hanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk = C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube Download - C:\Users\Hanna\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm File not found
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Hanna\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C5DE2AF7-7FDA-4FA8-87BF-290CD98962D2}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C5DE2AF7-7FDA-4FA8-87BF-290CD98962D2}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DAE15BB4-E5D7-4D17-BBE1-F64F678EB3B0}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Hanna\Pictures\Bild 023.jpg
O24 - Desktop BackupWallPaper: C:\Users\Hanna\Pictures\Bild 023.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.07.08 13:27:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
[2013.07.08 13:27:14 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
[2013.07.08 13:26:53 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2013.07.08 11:25:13 | 000,000,000 | ---D | C] -- C:\Windows\de
[2013.07.08 11:24:00 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2013.07.08 11:22:56 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2013.07.08 11:22:43 | 000,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2013.07.08 11:22:40 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2013.07.08 11:22:39 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2013.07.08 11:22:39 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2013.07.08 11:22:37 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2013.07.08 11:22:37 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2013.07.08 11:20:43 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2013.07.08 11:14:13 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2013.07.08 11:09:38 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2013.07.08 11:09:38 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2013.07.08 11:09:37 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2013.07.08 11:08:18 | 000,000,000 | ---D | C] -- C:\Users\Hanna\AppData\Local\Windows Live
[2013.07.08 11:08:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2013.07.08 11:07:28 | 000,754,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webservices.dll
[2013.07.08 11:06:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013.07.08 11:05:17 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2013.07.08 11:03:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bing-Desktop
[2013.07.08 10:36:45 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2013.07.08 10:36:45 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.07.08 10:36:44 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2013.07.08 10:36:44 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2013.07.08 10:36:44 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2013.07.08 10:36:43 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.07.08 10:36:43 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2013.07.08 10:36:43 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2013.07.08 10:36:42 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2013.07.08 10:36:42 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2013.07.08 10:36:42 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2013.07.08 10:36:41 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2013.07.08 10:36:41 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2013.07.08 10:36:41 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2013.07.08 10:36:41 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2013.07.08 10:36:41 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2013.07.08 10:36:40 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013.07.08 10:36:40 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2013.07.08 10:36:40 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.07.08 10:36:40 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2013.07.08 10:36:40 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2013.07.08 10:36:39 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.07.08 10:36:39 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2013.07.08 10:36:39 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2013.07.08 10:36:38 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.07.08 10:36:38 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013.07.08 10:36:38 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2013.07.08 10:36:37 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013.07.08 10:36:37 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2013.07.08 10:36:37 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2013.07.08 10:36:37 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2013.07.08 10:36:36 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2013.07.08 10:36:36 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2013.07.08 10:36:35 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2013.07.08 10:36:35 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2013.07.08 10:36:34 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2013.07.08 10:36:34 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2013.07.07 23:43:51 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Portable Devices
[2013.07.07 23:20:22 | 000,092,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAnimation.dll
[2013.07.07 23:20:18 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbonRes.dll
[2013.07.07 23:20:17 | 003,023,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbon.dll
[2013.07.07 23:18:04 | 000,369,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll
[2013.07.07 23:17:57 | 000,321,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PhotoMetadataHandler.dll
[2013.07.07 23:17:57 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxdiagn.dll
[2013.07.07 23:17:57 | 000,189,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll
[2013.07.07 23:17:56 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxdiag.exe
[2013.07.07 23:17:54 | 000,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll
[2013.07.07 23:16:26 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\BthMtpContextHandler.dll
[2013.07.07 23:16:26 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WPDShextAutoplay.exe
[2013.07.07 23:16:19 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceConnectApi.dll
[2013.07.07 23:16:14 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WpdMtpUS.dll
[2013.07.07 23:16:14 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WpdConns.dll
[2013.07.07 23:16:13 | 000,546,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wpd_ci.dll
[2013.07.07 23:16:13 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WpdMtp.dll
[2013.07.07 23:16:13 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceTypes.dll
[2013.07.07 23:16:12 | 000,334,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceApi.dll
[2013.07.07 23:16:12 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceWMDRM.dll
[2013.07.07 23:16:12 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceClassExtension.dll
[2013.07.07 23:16:11 | 000,350,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WPDSp.dll
[2013.07.07 21:53:13 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wdfres.dll
[2013.07.07 21:53:01 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winusb.dll
[2013.07.07 21:52:59 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFPlatform.dll
[2013.07.07 21:52:57 | 000,047,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\WdfLdr.sys
[2013.07.07 21:52:54 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFCoinstaller.dll
[2013.07.07 21:52:53 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFx.dll
[2013.07.07 21:36:22 | 000,979,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFH264Dec.dll
[2013.07.07 21:36:19 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll
[2013.07.07 21:36:18 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
[2013.07.07 21:36:16 | 000,357,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFHEAACdec.dll
[2013.07.07 21:36:16 | 000,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfmp4src.dll
[2013.07.07 21:36:16 | 000,261,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
[2013.07.07 21:36:11 | 002,873,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
[2013.07.07 21:36:09 | 000,667,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelinesvc.exe
[2013.07.07 21:36:08 | 000,209,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll
[2013.07.07 21:35:53 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfps.dll
[2013.07.07 21:35:53 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelineprxy.dll
[2013.07.07 21:35:35 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2013.07.07 21:35:34 | 000,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2013.07.07 21:35:34 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mpeg2Data.ax
[2013.07.07 21:35:27 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
[2013.07.07 21:35:16 | 001,029,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
[2013.07.07 21:35:14 | 000,486,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2013.07.07 21:35:14 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
[2013.07.07 21:35:13 | 001,554,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xpsservices.dll
[2013.07.07 21:35:13 | 000,847,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OpcServices.dll
[2013.07.07 21:35:13 | 000,288,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2013.07.07 21:31:40 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciseq.dll
[2013.07.07 21:31:33 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll
[2013.07.07 21:31:09 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2013.07.07 21:31:05 | 000,376,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpnet.dll
[2013.07.07 21:31:04 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpnsvr.exe
[2013.07.07 21:28:57 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2013.07.07 21:28:10 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll
[2013.07.07 21:26:35 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2013.07.07 21:25:50 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printcom.dll
[2013.07.07 21:25:43 | 001,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2013.07.07 21:25:38 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2013.07.07 21:25:28 | 002,049,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013.07.07 21:25:05 | 003,603,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2013.07.07 21:25:03 | 003,551,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2013.07.07 21:25:00 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2013.07.07 21:24:36 | 000,812,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certutil.exe
[2013.07.07 21:24:33 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certenc.dll
[2013.07.07 21:24:28 | 000,293,376 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2013.07.07 21:24:28 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2013.07.07 21:23:27 | 000,497,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2013.07.07 21:23:08 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleaccrc.dll
[2013.07.07 21:23:07 | 000,555,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAutomationCore.dll
[2013.07.06 14:30:23 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cryptdlg.dll
[2013.07.06 14:29:46 | 000,376,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2013.07.06 14:05:46 | 000,231,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshsq.dll
[2013.07.06 14:05:43 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usb8023.sys
[2013.07.06 14:03:54 | 000,613,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpencom.dll
[2013.07.06 13:46:27 | 002,422,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2013.07.06 13:46:27 | 000,045,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2013.07.06 13:45:54 | 000,577,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2013.07.06 13:45:54 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2013.07.06 13:45:54 | 000,035,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2013.07.06 13:45:44 | 000,171,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2013.07.06 13:45:44 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2013.07.06 13:16:27 | 000,000,000 | ---D | C] -- C:\Windows\System32\eu-ES
[2013.07.06 13:16:27 | 000,000,000 | ---D | C] -- C:\Windows\System32\ca-ES
[2013.07.06 13:16:26 | 000,000,000 | ---D | C] -- C:\Windows\System32\vi-VN
[2013.07.06 12:26:30 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders
[2013.07.06 12:24:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
[2013.07.06 12:24:36 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2013.07.05 20:47:25 | 000,867,240 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2013.07.05 20:47:25 | 000,263,592 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2013.07.05 20:47:02 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013.07.05 20:47:02 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2013.07.05 20:47:02 | 000,094,632 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013.07.05 20:46:14 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2013.07.05 20:26:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
[2013.07.05 20:14:50 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Security Scan
[2013.07.05 18:44:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013.07.05 18:43:57 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013.07.05 16:16:29 | 000,000,000 | ---D | C] -- C:\Users\Hanna\AppData\Roaming\Malwarebytes
[2013.07.05 16:16:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.07.05 16:16:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.07.05 16:16:04 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.07.05 16:16:04 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.07.05 10:25:48 | 000,000,000 | ---D | C] -- C:\Users\Hanna\AppData\Roaming\WinRAR
[2013.07.05 10:25:47 | 000,000,000 | ---D | C] -- C:\Users\Hanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013.07.05 10:25:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013.07.05 10:25:31 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2013.07.04 16:31:18 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.07.04 16:31:15 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.07.04 16:16:01 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.07.04 16:16:00 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.07.04 16:16:00 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.07.04 16:15:55 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013.07.04 16:13:58 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.07.04 16:13:33 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.07.04 14:47:55 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.07.04 13:58:03 | 000,000,000 | ---D | C] -- C:\Users\Hanna\Desktop\Viren
[2013.06.27 09:56:03 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
[2013.06.25 16:31:19 | 000,000,000 | ---D | C] -- C:\Users\Hanna\Desktop\Irland England
[2013.06.18 16:00:11 | 000,000,000 | ---D | C] -- C:\Users\Hanna\Desktop\Kindergeld
========== Files - Modified Within 30 Days ==========
[2013.07.08 13:35:27 | 000,001,706 | ---- | M] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2013.07.08 13:07:37 | 000,163,528 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.07.08 13:07:37 | 000,065,938 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.07.08 13:07:37 | 000,017,656 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.07.08 13:07:37 | 000,009,268 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.07.08 13:00:54 | 000,000,000 | ---- | M] () -- C:\Windows\System32\LogConfigTemp.xml
[2013.07.08 13:00:29 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2013.07.08 13:00:17 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.07.08 13:00:16 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.07.08 12:59:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.07.08 12:27:17 | 003,744,320 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.07.08 10:36:59 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat
[2013.07.08 10:36:58 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat
[2013.07.08 10:36:45 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2013.07.08 10:36:45 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.07.08 10:36:44 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2013.07.08 10:36:44 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2013.07.08 10:36:44 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2013.07.08 10:36:43 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.07.08 10:36:43 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2013.07.08 10:36:43 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2013.07.08 10:36:42 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2013.07.08 10:36:42 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2013.07.08 10:36:42 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2013.07.08 10:36:42 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2013.07.08 10:36:41 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2013.07.08 10:36:41 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.07.08 10:36:41 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2013.07.08 10:36:41 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2013.07.08 10:36:41 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2013.07.08 10:36:41 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2013.07.08 10:36:40 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013.07.08 10:36:40 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2013.07.08 10:36:40 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2013.07.08 10:36:40 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2013.07.08 10:36:39 | 000,607,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.07.08 10:36:39 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2013.07.08 10:36:39 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2013.07.08 10:36:38 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.07.08 10:36:38 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013.07.08 10:36:38 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2013.07.08 10:36:37 | 001,800,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013.07.08 10:36:37 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2013.07.08 10:36:37 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2013.07.08 10:36:37 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2013.07.08 10:36:36 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2013.07.08 10:36:36 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2013.07.08 10:36:35 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2013.07.08 10:36:35 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2013.07.08 10:36:35 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2013.07.08 10:36:34 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2013.07.07 23:42:24 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2013.07.07 23:38:20 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2013.07.05 20:46:37 | 000,094,632 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2013.07.05 20:46:30 | 000,263,592 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2013.07.05 20:46:29 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2013.07.05 20:46:29 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2013.07.05 20:46:26 | 000,867,240 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2013.07.05 20:46:25 | 000,789,416 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2013.07.05 20:26:31 | 000,001,873 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2013.07.05 19:48:45 | 000,002,560 | ---- | M] () -- C:\Windows\_MSRSTRT.EXE
[2013.07.04 16:28:05 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013.07.04 13:35:13 | 000,000,000 | ---- | M] () -- C:\Users\Hanna\defogger_reenable
[2013.07.03 02:57:54 | 000,002,693 | ---- | M] () -- C:\Users\Hanna\.recently-used.xbel
[2013.06.25 11:50:01 | 000,175,949 | ---- | M] () -- C:\Users\Hanna\Desktop\Flyer C.A. Krankenpflege_2012.pdf
[2013.06.12 10:22:27 | 000,001,224 | ---- | M] () -- C:\Windows\WININIT.INI
[2013.06.12 10:22:27 | 000,000,993 | ---- | M] () -- C:\Users\Hanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
========== Files Created - No Company Name ==========
[2013.07.08 13:27:18 | 000,001,706 | ---- | C] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2013.07.08 11:22:32 | 000,001,120 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2013.07.08 11:21:11 | 000,001,189 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2013.07.08 11:19:52 | 000,000,999 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2013.07.08 11:19:04 | 000,001,987 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2013.07.08 10:36:41 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2013.07.07 23:42:24 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2013.07.07 23:38:20 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2013.07.07 21:53:45 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013.07.07 21:53:45 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013.07.06 13:39:54 | 000,000,911 | ---- | C] () -- C:\Users\Hanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013.07.05 20:35:58 | 000,002,425 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2013.07.05 20:26:28 | 000,001,873 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2013.07.05 19:48:43 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2013.07.04 16:16:01 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.07.04 16:16:01 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.07.04 16:16:00 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.07.04 16:16:00 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.07.04 16:16:00 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.07.04 13:35:13 | 000,000,000 | ---- | C] () -- C:\Users\Hanna\defogger_reenable
[2013.07.03 02:57:54 | 000,002,693 | ---- | C] () -- C:\Users\Hanna\.recently-used.xbel
[2013.06.25 11:50:00 | 000,175,949 | ---- | C] () -- C:\Users\Hanna\Desktop\Flyer C.A. Krankenpflege_2012.pdf
[2012.09.11 22:57:35 | 000,065,536 | ---- | C] () -- C:\Users\Hanna\AppData\Roaming\i9p06hy1.default.dat
[2012.08.04 11:58:40 | 000,000,069 | ---- | C] () -- C:\Users\Hanna\AppData\Roaming\urhtps.dat
[2012.07.27 16:33:24 | 000,000,034 | ---- | C] () -- C:\Users\Hanna\AppData\Roaming\blckdom.res
[2011.07.21 14:06:50 | 000,015,364 | -H-- | C] () -- C:\Users\Hanna\.DS_Store
[2010.09.21 11:19:45 | 000,000,680 | ---- | C] () -- C:\Users\Hanna\AppData\Local\d3d9caps.dat
[2009.11.21 23:52:17 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009.07.12 13:14:01 | 000,024,206 | ---- | C] () -- C:\Users\Hanna\AppData\Roaming\UserTile.png
[2009.03.27 16:39:30 | 000,005,115 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2009.03.20 16:58:24 | 000,071,680 | ---- | C] () -- C:\Users\Hanna\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.03.18 20:46:11 | 000,000,326 | ---- | C] () -- C:\Users\Hanna\AppData\Roaming\wklnhst.dat
[2001.01.04 01:01:22 | 000,101,820 | ---- | C] () -- C:\Users\Hanna\CHILLER.TTF
========== ZeroAccess Check ==========
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Alternate Data Streams ==========
@Alternate Data Stream - 60 bytes -> C:\Users\Hanna\Desktop\.TEMP_com.apple.iWork.Pages_147_336291406_2:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Users\Hanna\Desktop\.DS_Store:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Users\Hanna\.DS_Store:AFP_AfpInfo
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:A696643D
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:9F683177
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:CF5C4195
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:861A898F
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:4F636E25
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:4D066AD2
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:4CF61E54
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:8AB6C1D7
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:E36F5B57
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:B623B5B8
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:9B52F176
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:798A3728
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:C46995DA
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:4BB26BE9
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:9E22BBE8
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:3E7393FC
< End of report > --- --- --- |