Claudia K. | 01.09.2013 21:55 | Liste der Anhänge anzeigen (Anzahl: 2) Hi Christoph,
*klatschmitderflachenHandvordieStirn*
Mann, bin ich doof! Dein Hinweis "nicht die erforderlichen Berechtigungen eingeräumt" war entscheidend. Mit NoSkripts hab ich bisher keine Erfahrung und daher dieser Anfängerfehler. Bitte entschuldige meine Dummheit!
Hier sind die beiden FRST-Log Dateien, die du wolltest:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-09-2013 02
Ran by clk (administrator) on CK on 01-09-2013 22:18:29
Running from C:\Dokumente und Einstellungen\clk\Desktop
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(Web Eight LLC.) C:\Programme\BrowserProtect\BpSvc.exe
(AVAST Software) C:\Programme\AVAST Software\Avast\AvastSvc.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(TOSHIBA CORPORATION) C:\Programme\TOSHIBA\ConfigFree\CFSvcs.exe
(AVAST Software) C:\Programme\AVAST Software\Avast\avastUI.exe
(TOSHIBA Corporation) C:\Programme\TOSHIBA\Tvs\TvsTray.exe
(PC Tools) C:\Programme\ThreatFire\TFTray.exe
(TOSHIBA) C:\Programme\Toshiba\Toshiba Applet\thotkey.exe
(Synaptics, Inc.) C:\Programme\Synaptics\SynTP\SynTPLpr.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
(Synaptics, Inc.) C:\Programme\Synaptics\SynTP\SynTPEnh.exe
(Oracle Corporation) C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
(Analog Devices, Inc.) C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe
(TOSHIBA) C:\Programme\TOSHIBA\Touch and Launch\PadExe.exe
() C:\Programme\Gemeinsame Dateien\DeviceHelper\DeviceManager.exe
() C:\Programme\Lexmark Pro700 Series\lxeemon.exe
(Samsung Electronics Co., Ltd.) C:\Programme\Samsung\Kies\KiesTrayAgent.exe
(Microsoft Corporation) C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe
() C:\Programme\Lexmark Pro700 Series\ezprint.exe
(ATI Technologies, Inc.) C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
(Sandboxie Holdings, LLC) C:\Programme\Sandboxie\SbieCtrl.exe
(Oracle Corporation) C:\Programme\Java\jre7\bin\jqs.exe
(Elgato Systems) C:\Programme\Gemeinsame Dateien\TerraTec\Remote\TTTVRC.exe
(Samsung Electronics) C:\Programme\Samsung\Kies\KiesAirMessage.exe
(FileHippo.com) C:\Programme\FileHippo.com\UpdateChecker.exe
( ) C:\WINDOWS\system32\lxeecoms.exe
(Microsoft Corporation) C:\Programme\Microsoft Silverlight\sllauncher.exe
(Nero AG) C:\Programme\Gemeinsame Dateien\Nero\Nero BackItUp 4\NBService.exe
(Secunia) C:\Programme\Secunia\PSI\psi_tray.exe
(pdfforge GbR) C:\Programme\PDF Architect\HelperService.exe
(Prolific Technology Inc.) C:\Programme\Nero\Nero BackItUp 4\IoctlSvc.exe
(Secunia) C:\Programme\Secunia\PSI\PSIA.exe
(Skype Technologies S.A.) C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Microsoft Corporation) C:\WINDOWS\System32\snmp.exe
(Analog Devices, Inc.) C:\Programme\Analog Devices\SoundMAX\SMAgent.exe
(TOSHIBA Corp.) C:\Programme\Toshiba\TOSHIBA Applet\TAPPSRV.exe
(PC Tools) C:\Programme\ThreatFire\TFService.exe
() C:\Programme\Verbindungsassistent\wtgservice.exe
(Microsoft Corporation) C:\Programme\Windows Media Player\WMPNetwk.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
(Secunia) C:\Programme\Secunia\PSI\sua.exe
(Microsoft Corporation) C:\WINDOWS\system32\MsiExec.exe
(Microsoft Corporation) C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [avast] - C:\Programme\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k [x]
HKLM\...\Run: [Tvs] - C:\Programme\TOSHIBA\Tvs\TvsTray.exe [73728 2005-04-05] (TOSHIBA Corporation)
HKLM\...\Run: [ThreatFire] - C:\Programme\ThreatFire\TFTray.exe [378128 2011-02-22] (PC Tools)
HKLM\...\Run: [THotkey] - C:\Programme\Toshiba\Toshiba Applet\thotkey.exe [356352 2005-07-06] (TOSHIBA)
HKLM\...\Run: [SynTPLpr] - C:\Programme\Synaptics\SynTP\SynTPLpr.exe [98394 2004-10-15] (Synaptics, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Programme\Synaptics\SynTP\SynTPEnh.exe [688218 2004-10-15] (Synaptics, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [SoundMAXPnP] - C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe [1388544 2004-07-27] (Analog Devices, Inc.)
HKLM\...\Run: [SoundMAX] - C:\Programme\Analog Devices\SoundMAX\Smax4.exe [860160 2004-08-06] (Analog Devices, Inc.)
HKLM\...\Run: [PadTouch] - C:\Programme\TOSHIBA\Touch and Launch\PadExe.exe [1077327 2004-11-17] (TOSHIBA)
HKLM\...\Run: [lxeemon.exe] - C:\Programme\Lexmark Pro700 Series\lxeemon.exe [770728 2010-01-18] ()
HKLM\...\Run: [LifeCam] - C:\Programme\Microsoft LifeCam\LifeExp.exe [118640 2009-07-24] (Microsoft Corporation)
HKLM\...\Run: [LexwareInfoService] - C:\Programme\Gemeinsame Dateien\Lexware\Update Manager\LxUpdateManager.exe [189808 2011-07-31] (Haufe-Lexware GmbH & Co. KG)
HKLM\...\Run: [KiesTrayAgent] - C:\Programme\Samsung\Kies\KiesTrayAgent.exe [309688 2012-11-12] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [GrooveMonitor] - C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [EzPrint] - C:\Programme\Lexmark Pro700 Series\ezprint.exe [139944 2010-01-18] ()
HKLM\...\Run: [ATIPTA] - C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe [344064 2005-04-14] (ATI Technologies, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Programme\Gemeinsame Dateien\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [MSConfig] - C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE [172544 2008-04-14] (Microsoft Corporation)
Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.)
HKLM\...\Policies\Explorer: [HonorAutoRunSetting] 1
HKLM\...\Policies\Explorer: [NoDriveTypeAutoRun] 323
HKLM\...\Policies\Explorer: [NoDriveAutoRun] 67108863
HKLM\...\Policies\Explorer: [NoDrives] 0
HKLM\...\Policies\Explorer: [RestrictRun] 0
HKCU\...\Run: [SandboxieControl] - C:\Programme\Sandboxie\SbieCtrl.exe [543320 2013-07-08] (Sandboxie Holdings, LLC)
HKCU\...\Run: [Remote Control Editor] - C:\Programme\Gemeinsame Dateien\TerraTec\Remote\TTTVRC.exe [1528320 2009-09-22] (Elgato Systems)
HKCU\...\Run: [KiesPreload] - C:\Programme\Samsung\Kies\Kies.exe [968120 2012-11-12] (Samsung)
HKCU\...\Run: [KiesAirMessage] - C:\Programme\Samsung\Kies\KiesAirMessage.exe [577536 2012-11-01] (Samsung Electronics)
HKCU\...\Run: [FileHippo.com] - C:\Programme\FileHippo.com\UpdateChecker.exe [307712 2012-11-23] (FileHippo.com)
HKCU\...\Run: [BrowserProtect] - C:\Programme\BrowserProtect\BpAuto.lnk [1857 2013-08-08] ()
HKCU\...\Policies\Explorer: [NoDriveTypeAutoRun] 323
HKCU\...\Policies\Explorer: [NoDriveAutoRun] 67108863
HKCU\...\Policies\Explorer: [NoDrives] 0
HKCU\...\Policies\Explorer: [RestrictRun] 0
HKU\Default User\...\Run: [TOSCDSPD] - C:\Programme\TOSHIBA\TOSCDSPD\toscdspd.exe [x]
HKU\Default User\...\Run: [MSMSGS] - C:\Programme\Messenger\msmsgs.exe [ 2008-04-14] (Microsoft Corporation)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Programme\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Windows Search.lnk
ShortcutTarget: Windows Search.lnk -> C:\Programme\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - {E649DC79-BD07-46CD-85E1-6D561DA45348} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7ADFA_de
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Lexmark - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Programme\Lexmark Printable Web\bho.dll ()
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - &TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\PROGRA~1\TerraTec\TERRAT~1\THCDES~1.DLL (TerraTec Electronic GmbH)
Toolbar: HKLM - Lexmark Symbolleiste - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Programme\Lexmark Toolbar\toolband.dll ()
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU -&Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU -Lexmark Symbolleiste - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Programme\Lexmark Toolbar\toolband.dll ()
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: haufereader - No CLSID Value -
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\clk\Anwendungsdaten\Mozilla\Firefox\Profiles\apdoscfg.default
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Programme\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Programme\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @citrixonline.com/appdetectorplugin - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Extension: Skype extension for Firefox - C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] C:\Programme\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Programme\PDF Architect\FFPDFArchitectExt
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] C:\Programme\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Programme\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\29.0.1547.62\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\29.0.1547.62\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Programme\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Programme\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Programme\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Programme\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Programme\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Programme\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Programme\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Programme\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft00AE DRM) - C:\Programme\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Programme\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Microsoft00AE DRM) - C:\Programme\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Picasa) - C:\Programme\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.90.5) - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Windows Presentation Foundation) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Dr.Web Anti-Virus Link Checker) - C:\DOKUME~1\clk\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\aleggpabliehgbeagmfhnodcijcmbonb\3.2.1_0
CHR Extension: (WOT) - C:\DOKUME~1\clk\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.13_0
CHR Extension: (VTchromizer) - C:\DOKUME~1\clk\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\efbjojhplkelaegfbieplglfidafgoka\1.2_0
CHR Extension: (AdBlock) - C:\DOKUME~1\clk\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.6_0
CHR Extension: (DVDVideoSoft Browser Extension) - C:\DOKUME~1\clk\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.2_0
CHR Extension: (Chrome In-App Payments service) - C:\DOKUME~1\clk\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR Extension: (NotScripts) - C:\DOKUME~1\clk\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\odjhifogjcknibkahlpidmdajjpkkcfn\0.9.6_0
CHR StartMenuInternet: Google Chrome - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Programme\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
R2 BpSvc; C:\Programme\BrowserProtect\BpSvc.exe [1867776 2011-11-11] (Web Eight LLC.)
R2 CFSvcs; C:\Programme\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2005-01-18] (TOSHIBA CORPORATION)
R2 DeviceManager; C:\Programme\Gemeinsame Dateien\DeviceHelper\DeviceManager.exe [40960 2009-05-25] ()
S2 gupdate; C:\Programme\Google\Update\GoogleUpdate.exe [116648 2013-06-02] (Google Inc.)
S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [116648 2013-06-02] (Google Inc.)
S3 gusvc; C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe [136120 2011-05-10] (Google)
S3 IDriverT; C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation)
S2 lxeeCATSCustConnectService; C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxeeserv.exe [98984 2010-01-07] (Lexmark International, Inc.)
R2 lxee_device; C:\WINDOWS\system32\lxeecoms.exe [598696 2010-01-07] ( )
S3 Microsoft Office Groove Audit Service; C:\Programme\Microsoft Office\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation)
S4 MSCamSvc; C:\Programme\Microsoft LifeCam\MSCamS32.exe [139120 2009-07-24] (Microsoft Corporation)
R2 Nero BackItUp Scheduler 4.0; C:\Programme\Gemeinsame Dateien\Nero\Nero BackItUp 4\NBService.exe [935208 2008-08-29] (Nero AG)
R2 NwSapAgent; C:\Windows\System32\ipxsap.dll [66560 2004-08-04] (Microsoft Corporation)
S3 odserv; C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE [440696 2011-07-20] (Microsoft Corporation)
S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [145184 2006-10-26] (Microsoft Corporation)
R2 PDF Architect Helper Service; C:\Programme\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR)
S2 PDF Architect Service; C:\Programme\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR)
R2 PLFlash DeviceIoControl Service; C:\Programme\Nero\Nero BackItUp 4\IoctlSvc.exe [81920 2008-08-29] (Prolific Technology Inc.)
S4 SbieSvc; C:\Programme\Sandboxie\SbieSvc.exe [129112 2013-07-08] (Sandboxie Holdings, LLC)
R2 Secunia PSI Agent; C:\Programme\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia)
R2 Secunia Update Agent; C:\Programme\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia)
R2 Skype C2C Service; C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.)
S2 SkypeUpdate; C:\Programme\Skype\Updater\Updater.exe [160944 2012-07-13] (Skype Technologies)
R2 SoundMAX Agent Service (default); C:\Programme\Analog Devices\SoundMAX\SMAgent.exe [45056 2002-09-20] (Analog Devices, Inc.)
R2 TAPPSRV; C:\Programme\Toshiba\TOSHIBA Applet\TAPPSRV.exe [34816 2005-07-05] (TOSHIBA Corp.)
R2 ThreatFire; C:\Programme\ThreatFire\TFService.exe [70928 2011-02-22] (PC Tools)
R2 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-11-03] (Microsoft Corporation)
R2 WTGService; C:\Programme\Verbindungsassistent\wtgservice.exe [308688 2010-01-15] ()
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
R2 JavaQuickStarterService; "C:\Programme\Java\jre7\bin\jqs.exe" -service -config "C:\Programme\Java\jre7\lib\deploy\jqs\jqs.conf" [x]
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [x]
S3 WPFFontCache_v0400; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [x]
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [66336 2013-05-09] (AVAST Software)
R1 AswRdr; C:\Windows\System32\Drivers\AswRdr.sys [49760 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [770344 2013-06-28] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [369584 2013-06-28] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [175176 2013-06-28] ()
S3 MPE; C:\Windows\System32\DRIVERS\MPE.sys [15232 2008-04-13] (Microsoft Corporation)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R2 Netdevio; C:\Windows\System32\DRIVERS\netdevio.sys [12032 2003-01-29] (TOSHIBA Corporation.)
S3 nm; C:\Windows\System32\DRIVERS\NMnt.sys [40320 2008-04-13] (Microsoft Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [50704 2009-10-20] (CACE Technologies, Inc.)
R2 NwlnkIpx; C:\Windows\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-13] (Microsoft Corporation)
R2 NwlnkNb; C:\Windows\System32\DRIVERS\nwlnknb.sys [63232 2004-08-04] (Microsoft Corporation)
R2 NwlnkSpx; C:\Windows\System32\DRIVERS\nwlnkspx.sys [55936 2004-08-04] (Microsoft Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-07-03] (Secunia)
S3 qcusbser; C:\Windows\System32\DRIVERS\qcusbser.sys [103552 2009-05-25] (TCT International Mobile Ltd)
S3 S6U12Scanner; C:\Windows\System32\drivers\usbscan.sys [15104 2008-04-13] (Microsoft Corporation)
S3 SbieDrv; C:\Programme\Sandboxie\SbieDrv.sys [159208 2013-07-08] (Sandboxie Holdings, LLC)
R1 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [5632 2006-07-24] ()
R0 TfFsMon; C:\Windows\System32\drivers\TfFsMon.sys [51984 2011-02-22] (PC Tools)
R3 TfNetMon; C:\WINDOWS\system32\drivers\TfNetMon.sys [33552 2011-02-22] (PC Tools)
R0 TfSysMon; C:\Windows\System32\drivers\TfSysMon.sys [69392 2011-02-22] (PC Tools)
S3 TTHID; C:\Windows\System32\DRIVERS\Cinergy_Hybrid-Stick_HID.sys [23104 2009-11-04] (DTV-DVB)
R3 TVALD; C:\Windows\System32\DRIVERS\NBSMI.sys [4864 2005-03-02] (Toshiba Corporation)
R3 Tvs; C:\Windows\System32\DRIVERS\Tvs.sys [29056 2005-05-10] (TOSHIBA Corporation)
S3 UDXTTM6010; C:\Windows\System32\DRIVERS\UDXTTM6010.sys [763584 2009-11-04] ()
R3 w29n51; C:\Windows\System32\DRIVERS\w29n51.sys [3222784 2004-10-29] (Intel® Corporation)
R3 yukonwxp; C:\Windows\System32\DRIVERS\yk51x86.sys [230400 2005-03-31] (Marvell)
S3 catchme; \??\C:\DOKUME~1\clk\LOKALE~1\Temp\catchme.sys [x]
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
U3 TlntSvr;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-01 22:16 - 2013-09-01 22:16 - 01085755 _____ (Farbar) C:\Dokumente und Einstellungen\clk\Desktop\FRST.exe
2013-08-27 22:36 - 2013-08-27 22:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2013-08-27 22:34 - 2013-08-27 22:39 - 00004299 _____ C:\WINDOWS\KB2834904-v2.log
2013-08-17 01:21 - 2013-08-17 01:22 - 00012386 _____ C:\WINDOWS\KB2862772-IE8.log
2013-08-17 00:42 - 2013-08-17 00:42 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2013-08-17 00:41 - 2013-08-17 00:41 - 00005202 _____ C:\WINDOWS\KB2863058.log
2013-08-17 00:41 - 2013-08-17 00:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$
2013-08-17 00:41 - 2013-08-17 00:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2013-08-17 00:41 - 2013-08-17 00:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$
2013-08-16 21:33 - 2013-08-17 00:42 - 00009092 _____ C:\WINDOWS\KB2850869.log
2013-08-16 21:32 - 2013-08-17 00:42 - 00010849 _____ C:\WINDOWS\KB2859537.log
2013-08-15 21:34 - 2013-08-15 21:34 - 00000000 _____ C:\Dokumente und Einstellungen\All Users\SPL15.tmp
2013-08-15 21:29 - 2013-08-15 21:29 - 00206566 _____ C:\Dokumente und Einstellungen\All Users\SPLF.tmp
2013-08-15 01:09 - 2013-08-15 01:09 - 00689334 _____ C:\Dokumente und Einstellungen\All Users\SPL2.tmp
2013-08-15 00:53 - 2013-08-15 00:53 - 00689334 _____ C:\Dokumente und Einstellungen\All Users\SPL4.tmp
2013-08-14 11:35 - 2013-08-14 11:35 - 00106496 _____ C:\WINDOWS\Minidump\Mini081413-01.dmp
2013-08-12 23:08 - 2013-08-30 21:40 - 00016896 ___SH C:\Dokumente und Einstellungen\clk\Desktop\Thumbs.db
2013-08-09 16:28 - 2013-08-15 23:18 - 00002363 _____ C:\Dokumente und Einstellungen\All Users\Desktop\QuickSteuer 2013.lnk
2013-08-09 04:40 - 2013-08-09 04:40 - 00135595 ____C C:\wubildr
2013-08-09 04:40 - 2013-08-09 04:40 - 00008192 ____C C:\wubildr.mbr
2013-08-09 04:08 - 2013-08-09 04:40 - 00000000 ___DC C:\ubuntu
2013-08-08 23:01 - 2013-08-08 23:01 - 00000000 __RDC C:\Sandbox
2013-08-08 23:00 - 2013-08-08 23:01 - 00001236 _____ C:\WINDOWS\Sandboxie.ini
2013-08-08 22:59 - 2013-08-08 22:59 - 00000000 ____D C:\Programme\Sandboxie
2013-08-08 22:55 - 2013-08-08 22:55 - 00001883 _____ C:\Dokumente und Einstellungen\clk\Startmenü\Programme\Browser Protect.lnk
2013-08-08 22:51 - 2013-08-11 10:11 - 00000000 ____D C:\Programme\Microsoft Silverlight
2013-08-08 22:50 - 2013-08-08 22:55 - 00000000 ____D C:\Programme\BrowserProtect
2013-08-08 12:19 - 2013-09-01 21:49 - 00000000 ____D C:\Programme\ThreatFire
2013-08-08 12:19 - 2011-02-22 13:57 - 00069392 _____ (PC Tools) C:\WINDOWS\system32\Drivers\TfSysMon.sys
2013-08-08 12:19 - 2011-02-22 13:57 - 00051984 _____ (PC Tools) C:\WINDOWS\system32\Drivers\TfFsMon.sys
2013-08-08 12:19 - 2011-02-22 13:57 - 00033552 _____ (PC Tools) C:\WINDOWS\system32\Drivers\TfNetMon.sys
2013-08-08 12:17 - 2013-08-08 12:17 - 00001602 _____ C:\Dokumente und Einstellungen\clk\Startmenü\Programme\Update Checker.lnk
2013-08-08 12:17 - 2013-08-08 12:17 - 00000000 ____D C:\Programme\FileHippo.com
2013-08-08 11:24 - 2013-08-08 11:24 - 00000000 ____D C:\Programme\Gemeinsame Dateien\Java
2013-08-08 11:23 - 2013-08-08 11:23 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-08-08 11:23 - 2013-08-08 11:22 - 00263592 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2013-08-08 11:23 - 2013-08-08 11:22 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2013-08-08 11:23 - 2013-08-08 11:22 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2013-08-07 23:21 - 2013-08-07 23:23 - 00007966 _____ C:\WINDOWS\KB946648.log
2013-08-07 20:30 - 2013-08-07 20:33 - 00005846 _____ C:\WINDOWS\KB942288-v3.log
2013-08-07 20:13 - 2013-08-07 20:30 - 00001541 _____ C:\WINDOWS\KB942288-v4.log
2013-08-07 00:52 - 2013-08-07 01:15 - 00010502 _____ C:\WINDOWS\KB2719985.log
2013-08-07 00:52 - 2013-08-07 01:14 - 00010665 _____ C:\WINDOWS\KB2757638.log
2013-08-07 00:43 - 2013-08-07 00:43 - 00000236 _____ C:\WINDOWS\DtcInstall.log
2013-08-07 00:42 - 2013-08-07 00:43 - 00000814 _____ C:\WINDOWS\wmsetup.log
2013-08-07 00:42 - 2013-08-07 00:42 - 00000187 _____ C:\WINDOWS\spupdsvc.log.1.log
2013-08-07 00:38 - 2013-08-07 00:38 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB923561$
2013-08-07 00:37 - 2013-08-07 00:38 - 00005306 _____ C:\WINDOWS\KB923561.log
2013-08-07 00:33 - 2013-08-07 00:43 - 00030753 _____ C:\WINDOWS\spupdsvc.log
2013-08-07 00:33 - 2013-08-07 00:33 - 00000200 _____ C:\WINDOWS\cmsetacl.log
2013-08-07 00:32 - 2013-08-07 00:32 - 00000311 _____ C:\WINDOWS\sessmgr.setup.log
2013-08-07 00:31 - 2013-08-07 00:31 - 00000565 _____ C:\WINDOWS\medctroc.Log
2013-08-07 00:22 - 2013-08-07 00:39 - 00096346 _____ C:\WINDOWS\svcpack.log
2013-08-05 23:25 - 2013-08-05 23:25 - 00000000 ____D C:\Programme\Citrix
2013-08-02 15:00 - 2013-08-02 22:17 - 00000000 ____D C:\Dokumente und Einstellungen\clk\Anwendungsdaten\Web Cake
==================== One Month Modified Files and Folders =======
2013-09-01 22:20 - 2013-06-02 22:05 - 00001084 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-01 22:17 - 2013-09-01 22:17 - 00000000 ___DC C:\FRST
2013-09-01 22:16 - 2013-09-01 22:16 - 01085755 _____ (Farbar) C:\Dokumente und Einstellungen\clk\Desktop\FRST.exe
2013-09-01 22:16 - 2005-08-17 14:43 - 02077010 _____ C:\WINDOWS\WindowsUpdate.log
2013-09-01 22:14 - 2013-06-02 22:04 - 00000350 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2013-09-01 22:09 - 2013-02-05 22:32 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-09-01 22:02 - 2011-09-07 13:03 - 00001202 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2044978897-1172690549-42215457-1007UA.job
2013-09-01 22:02 - 2005-08-17 14:51 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-09-01 21:49 - 2013-08-08 12:19 - 00000000 ____D C:\Programme\ThreatFire
2013-09-01 21:29 - 2010-03-07 22:47 - 00186002 _____ C:\Dokumente und Einstellungen\All Users\lxeescan.log
2013-09-01 21:29 - 2005-08-17 15:39 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-09-01 21:29 - 2005-08-17 15:39 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-09-01 21:28 - 2013-06-02 22:05 - 00001080 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-01 21:28 - 2005-08-17 15:36 - 03622528 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-09-01 21:27 - 2005-08-17 14:47 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-31 23:11 - 2010-01-14 14:04 - 00000190 ___SH C:\Dokumente und Einstellungen\clk\ntuser.ini
2013-08-31 23:11 - 2010-01-14 14:04 - 00000000 ____D C:\Dokumente und Einstellungen\clk
2013-08-31 21:14 - 2013-04-14 21:51 - 00072968 _____ C:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2013-08-31 21:12 - 2010-01-14 23:20 - 00000000 ____D C:\WINDOWS\system32\de-DE
2013-08-31 21:12 - 2010-01-14 17:42 - 00000000 ____D C:\WINDOWS\system32\XPSViewer
2013-08-31 21:09 - 2005-08-17 15:37 - 01091320 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-08-31 21:08 - 2010-01-14 17:45 - 00000000 ____D C:\Programme\MSBuild
2013-08-31 19:14 - 2005-08-17 14:47 - 00032506 _____ C:\WINDOWS\SchedLgU.Txt
2013-08-31 18:29 - 2005-08-17 14:30 - 00000582 _____ C:\WINDOWS\win.ini
2013-08-31 18:29 - 2005-08-17 14:30 - 00000354 __RSH C:\boot.ini
2013-08-31 18:29 - 2005-08-17 14:30 - 00000227 ____C C:\WINDOWS\system.ini
2013-08-31 18:27 - 2010-01-14 18:52 - 00065536 _____ C:\WINDOWS\system32\config\ODiag.evt
2013-08-31 18:13 - 2010-03-07 22:48 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Lx_cats
2013-08-31 02:00 - 2012-12-15 00:51 - 00000342 _____ C:\WINDOWS\Tasks\AdobeAAMUpdater-1.0-CK-clk.job
2013-08-31 00:01 - 2011-09-07 13:03 - 00001150 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2044978897-1172690549-42215457-1007Core.job
2013-08-30 21:40 - 2013-08-12 23:08 - 00016896 ___SH C:\Dokumente und Einstellungen\clk\Desktop\Thumbs.db
2013-08-29 22:52 - 2013-01-01 20:46 - 00000000 ____D C:\Dokumente und Einstellungen\clk\Desktop\Camera
2013-08-29 20:40 - 2010-03-08 14:48 - 02245392 _____ C:\Dokumente und Einstellungen\All Users\lxee.log
2013-08-29 20:39 - 2013-02-25 17:56 - 00661017 _____ C:\WINDOWS\setupapi.log
2013-08-29 20:20 - 2005-08-17 14:30 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl
2013-08-28 20:08 - 2013-03-09 17:39 - 00005940 _____ C:\WINDOWS\setupact.log
2013-08-27 22:39 - 2013-08-27 22:34 - 00004299 _____ C:\WINDOWS\KB2834904-v2.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00177955 _____ C:\WINDOWS\FaxSetup.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00094099 _____ C:\WINDOWS\ocgen.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00070008 _____ C:\WINDOWS\tsoc.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00059722 _____ C:\WINDOWS\comsetup.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00037317 _____ C:\WINDOWS\ntdtcsetup.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00027425 _____ C:\WINDOWS\iis6.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00010536 _____ C:\WINDOWS\ocmsn.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00009003 _____ C:\WINDOWS\msgsocm.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00001374 _____ C:\WINDOWS\imsins.log
2013-08-27 22:36 - 2013-08-27 22:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2013-08-26 23:15 - 2013-07-13 00:44 - 00000000 ____D C:\Dokumente und Einstellungen\clk\Anwendungsdaten\vlc
2013-08-26 23:00 - 2010-01-14 18:36 - 00000000 ____D C:\Programme\IrfanView
2013-08-24 23:14 - 2005-08-17 15:37 - 00000000 ____D C:\Programme
2013-08-24 20:03 - 2013-05-24 12:58 - 00000474 _____ C:\WINDOWS\nsw.log
2013-08-18 22:34 - 2010-01-14 18:48 - 00000000 ____D C:\Programme\Microsoft.NET
2013-08-17 22:08 - 2005-08-17 14:42 - 00000000 ____D C:\WINDOWS\Registration
2013-08-17 01:22 - 2013-08-17 01:21 - 00012386 _____ C:\WINDOWS\KB2862772-IE8.log
2013-08-17 01:22 - 2013-03-14 00:17 - 00017108 _____ C:\WINDOWS\updspapi.log
2013-08-17 01:22 - 2013-03-09 17:40 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-08-17 01:21 - 2010-01-14 23:24 - 00000000 ____D C:\WINDOWS\ie8updates
2013-08-17 01:18 - 2013-07-15 22:10 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-08-17 01:12 - 2010-01-14 22:45 - 75778376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-08-17 00:42 - 2013-08-17 00:42 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2013-08-17 00:42 - 2013-08-16 21:33 - 00009092 _____ C:\WINDOWS\KB2850869.log
2013-08-17 00:42 - 2013-08-16 21:32 - 00010849 _____ C:\WINDOWS\KB2859537.log
2013-08-17 00:41 - 2013-08-17 00:41 - 00005202 _____ C:\WINDOWS\KB2863058.log
2013-08-17 00:41 - 2013-08-17 00:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$
2013-08-17 00:41 - 2013-08-17 00:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2013-08-17 00:41 - 2013-08-17 00:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$
2013-08-17 00:41 - 2010-01-14 23:31 - 00053992 _____ C:\WINDOWS\system32\TZLog.log
2013-08-16 23:17 - 2013-06-01 22:14 - 00000000 ____D C:\WINDOWS\pss
2013-08-15 23:18 - 2013-08-09 16:28 - 00002363 _____ C:\Dokumente und Einstellungen\All Users\Desktop\QuickSteuer 2013.lnk
2013-08-15 23:06 - 2005-08-17 14:42 - 00000000 ____D C:\WINDOWS\system32\Restore
2013-08-15 21:34 - 2013-08-15 21:34 - 00000000 _____ C:\Dokumente und Einstellungen\All Users\SPL15.tmp
2013-08-15 21:29 - 2013-08-15 21:29 - 00206566 _____ C:\Dokumente und Einstellungen\All Users\SPLF.tmp
2013-08-15 01:09 - 2013-08-15 01:09 - 00689334 _____ C:\Dokumente und Einstellungen\All Users\SPL2.tmp
2013-08-15 00:53 - 2013-08-15 00:53 - 00689334 _____ C:\Dokumente und Einstellungen\All Users\SPL4.tmp
2013-08-14 11:35 - 2013-08-14 11:35 - 00106496 _____ C:\WINDOWS\Minidump\Mini081413-01.dmp
2013-08-14 11:35 - 2010-01-17 21:44 - 00000000 ____D C:\WINDOWS\Minidump
2013-08-11 10:11 - 2013-08-08 22:51 - 00000000 ____D C:\Programme\Microsoft Silverlight
2013-08-09 16:25 - 2010-01-15 23:51 - 00000000 ____D C:\Programme\Gemeinsame Dateien\Lexware
2013-08-09 04:40 - 2013-08-09 04:40 - 00135595 ____C C:\wubildr
2013-08-09 04:40 - 2013-08-09 04:40 - 00008192 ____C C:\wubildr.mbr
2013-08-09 04:40 - 2013-08-09 04:08 - 00000000 ___DC C:\ubuntu
2013-08-09 04:08 - 2005-08-17 14:44 - 00000000 __RSH C:\CONFIG.SYS
2013-08-08 23:01 - 2013-08-08 23:01 - 00000000 __RDC C:\Sandbox
2013-08-08 23:01 - 2013-08-08 23:00 - 00001236 _____ C:\WINDOWS\Sandboxie.ini
2013-08-08 22:59 - 2013-08-08 22:59 - 00000000 ____D C:\Programme\Sandboxie
2013-08-08 22:55 - 2013-08-08 22:55 - 00001883 _____ C:\Dokumente und Einstellungen\clk\Startmenü\Programme\Browser Protect.lnk
2013-08-08 22:55 - 2013-08-08 22:50 - 00000000 ____D C:\Programme\BrowserProtect
2013-08-08 22:55 - 2010-01-14 14:04 - 00000000 ___RD C:\Dokumente und Einstellungen\clk\Startmenü\Programme
2013-08-08 12:40 - 2012-12-14 22:21 - 00000000 ____D C:\Programme\Gemeinsame Dateien\Adobe AIR
2013-08-08 12:17 - 2013-08-08 12:17 - 00001602 _____ C:\Dokumente und Einstellungen\clk\Startmenü\Programme\Update Checker.lnk
2013-08-08 12:17 - 2013-08-08 12:17 - 00000000 ____D C:\Programme\FileHippo.com
2013-08-08 11:48 - 2013-06-16 20:34 - 00004784 ____C C:\DelFix.txt
2013-08-08 11:24 - 2013-08-08 11:24 - 00000000 ____D C:\Programme\Gemeinsame Dateien\Java
2013-08-08 11:23 - 2013-08-08 11:23 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-08-08 11:22 - 2013-08-08 11:23 - 00263592 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2013-08-08 11:22 - 2013-08-08 11:23 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2013-08-08 11:22 - 2013-08-08 11:23 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2013-08-08 11:22 - 2012-11-01 21:20 - 00867240 _____ (Oracle Corporation) C:\WINDOWS\system32\npDeployJava1.dll
2013-08-08 11:22 - 2012-11-01 21:20 - 00144896 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2013-08-08 11:22 - 2010-10-14 20:03 - 00789416 _____ (Oracle Corporation) C:\WINDOWS\system32\deployJava1.dll
2013-08-07 23:23 - 2013-08-07 23:21 - 00007966 _____ C:\WINDOWS\KB946648.log
2013-08-07 23:23 - 2005-08-17 14:41 - 00000000 ____D C:\Programme\Messenger
2013-08-07 20:33 - 2013-08-07 20:30 - 00005846 _____ C:\WINDOWS\KB942288-v3.log
2013-08-07 20:30 - 2013-08-07 20:13 - 00001541 _____ C:\WINDOWS\KB942288-v4.log
2013-08-07 01:15 - 2013-08-07 00:52 - 00010502 _____ C:\WINDOWS\KB2719985.log
2013-08-07 01:14 - 2013-08-07 00:52 - 00010665 _____ C:\WINDOWS\KB2757638.log
2013-08-07 01:14 - 2013-07-12 09:28 - 00017862 _____ C:\WINDOWS\KB2846071-IE8.log
2013-08-07 00:43 - 2013-08-07 00:43 - 00000236 _____ C:\WINDOWS\DtcInstall.log
2013-08-07 00:43 - 2013-08-07 00:42 - 00000814 _____ C:\WINDOWS\wmsetup.log
2013-08-07 00:43 - 2013-08-07 00:33 - 00030753 _____ C:\WINDOWS\spupdsvc.log
2013-08-07 00:42 - 2013-08-07 00:42 - 00000187 _____ C:\WINDOWS\spupdsvc.log.1.log
2013-08-07 00:42 - 2010-01-14 19:17 - 00000090 _____ C:\WINDOWS\system32\spupdwxp.log
2013-08-07 00:39 - 2013-08-07 00:22 - 00096346 _____ C:\WINDOWS\svcpack.log
2013-08-07 00:39 - 2005-08-17 16:31 - 00000000 ____D C:\WINDOWS\security
2013-08-07 00:38 - 2013-08-07 00:38 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB923561$
2013-08-07 00:38 - 2013-08-07 00:37 - 00005306 _____ C:\WINDOWS\KB923561.log
2013-08-07 00:33 - 2013-08-07 00:33 - 00000200 _____ C:\WINDOWS\cmsetacl.log
2013-08-07 00:32 - 2013-08-07 00:32 - 00000311 _____ C:\WINDOWS\sessmgr.setup.log
2013-08-07 00:32 - 2005-08-17 16:31 - 00000000 ____D C:\WINDOWS\Help
2013-08-07 00:32 - 2005-08-17 15:36 - 00000000 ___RD C:\Dokumente und Einstellungen\All Users\Startmenü
2013-08-07 00:31 - 2013-08-07 00:31 - 00000565 _____ C:\WINDOWS\medctroc.Log
2013-08-05 23:25 - 2013-08-05 23:25 - 00000000 ____D C:\Programme\Citrix
2013-08-03 01:48 - 2006-08-24 23:30 - 01543680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmvdecod.dll
2013-08-02 22:17 - 2013-08-02 15:00 - 00000000 ____D C:\Dokumente und Einstellungen\clk\Anwendungsdaten\Web Cake
2013-08-02 22:17 - 2005-08-17 16:31 - 00000000 ____D C:\WINDOWS\Resources
2013-08-02 21:03 - 2010-01-15 02:04 - 00000000 ____D C:\Dokumente und Einstellungen\clk\Eigene Dateien\Dateien von CK
2013-08-02 20:56 - 2005-08-17 14:43 - 00000000 __SHD C:\Dokumente und Einstellungen\All Users\DRM
Files to move or delete:
====================
C:\DOKUME~1\clk\LOKALE~1\Temp\pyl275.tmp.exe
C:\DOKUME~1\clk\LOKALE~1\Temp\pyl29F.tmp.exe
C:\DOKUME~1\clk\LOKALE~1\Temp\Rar$EX06.694\wubi.exe
C:\DOKUME~1\clk\LOKALE~1\Temp\is-IBBLP.tmp\gtapi.dll
C:\DOKUME~1\clk\LOKALE~1\Temp\C379BD5D-8513-468C-B0E2-085A97E85791\G2MAudioStreamingDSP64.dll
C:\DOKUME~1\clk\LOKALE~1\Temp\C379BD5D-8513-468C-B0E2-085A97E85791\G2MVideoStreamingDSP64.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2005-08-17 14:29] - [2008-04-14 04:22] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\Windows\System32\winlogon.exe
[2005-08-17 14:30] - [2008-04-14 04:23] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\Windows\System32\svchost.exe
[2005-08-17 14:30] - [2008-04-14 04:23] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\Windows\System32\services.exe
[2005-08-17 14:30] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\Windows\System32\User32.dll
[2005-08-17 14:30] - [2008-04-14 04:22] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\Windows\System32\userinit.exe
[2005-08-17 14:30] - [2008-04-14 04:23] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\Windows\System32\Drivers\volsnap.sys
[2005-08-17 14:30] - [2008-04-14 03:52] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================ --- --- ---
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-09-2013 02
Ran by clk (administrator) on CK on 01-09-2013 22:18:29
Running from C:\Dokumente und Einstellungen\clk\Desktop
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(Web Eight LLC.) C:\Programme\BrowserProtect\BpSvc.exe
(AVAST Software) C:\Programme\AVAST Software\Avast\AvastSvc.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(TOSHIBA CORPORATION) C:\Programme\TOSHIBA\ConfigFree\CFSvcs.exe
(AVAST Software) C:\Programme\AVAST Software\Avast\avastUI.exe
(TOSHIBA Corporation) C:\Programme\TOSHIBA\Tvs\TvsTray.exe
(PC Tools) C:\Programme\ThreatFire\TFTray.exe
(TOSHIBA) C:\Programme\Toshiba\Toshiba Applet\thotkey.exe
(Synaptics, Inc.) C:\Programme\Synaptics\SynTP\SynTPLpr.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
(Synaptics, Inc.) C:\Programme\Synaptics\SynTP\SynTPEnh.exe
(Oracle Corporation) C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
(Analog Devices, Inc.) C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe
(TOSHIBA) C:\Programme\TOSHIBA\Touch and Launch\PadExe.exe
() C:\Programme\Gemeinsame Dateien\DeviceHelper\DeviceManager.exe
() C:\Programme\Lexmark Pro700 Series\lxeemon.exe
(Samsung Electronics Co., Ltd.) C:\Programme\Samsung\Kies\KiesTrayAgent.exe
(Microsoft Corporation) C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe
() C:\Programme\Lexmark Pro700 Series\ezprint.exe
(ATI Technologies, Inc.) C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
(Sandboxie Holdings, LLC) C:\Programme\Sandboxie\SbieCtrl.exe
(Oracle Corporation) C:\Programme\Java\jre7\bin\jqs.exe
(Elgato Systems) C:\Programme\Gemeinsame Dateien\TerraTec\Remote\TTTVRC.exe
(Samsung Electronics) C:\Programme\Samsung\Kies\KiesAirMessage.exe
(FileHippo.com) C:\Programme\FileHippo.com\UpdateChecker.exe
( ) C:\WINDOWS\system32\lxeecoms.exe
(Microsoft Corporation) C:\Programme\Microsoft Silverlight\sllauncher.exe
(Nero AG) C:\Programme\Gemeinsame Dateien\Nero\Nero BackItUp 4\NBService.exe
(Secunia) C:\Programme\Secunia\PSI\psi_tray.exe
(pdfforge GbR) C:\Programme\PDF Architect\HelperService.exe
(Prolific Technology Inc.) C:\Programme\Nero\Nero BackItUp 4\IoctlSvc.exe
(Secunia) C:\Programme\Secunia\PSI\PSIA.exe
(Skype Technologies S.A.) C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Microsoft Corporation) C:\WINDOWS\System32\snmp.exe
(Analog Devices, Inc.) C:\Programme\Analog Devices\SoundMAX\SMAgent.exe
(TOSHIBA Corp.) C:\Programme\Toshiba\TOSHIBA Applet\TAPPSRV.exe
(PC Tools) C:\Programme\ThreatFire\TFService.exe
() C:\Programme\Verbindungsassistent\wtgservice.exe
(Microsoft Corporation) C:\Programme\Windows Media Player\WMPNetwk.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
(Secunia) C:\Programme\Secunia\PSI\sua.exe
(Microsoft Corporation) C:\WINDOWS\system32\MsiExec.exe
(Microsoft Corporation) C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [avast] - C:\Programme\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k [x]
HKLM\...\Run: [Tvs] - C:\Programme\TOSHIBA\Tvs\TvsTray.exe [73728 2005-04-05] (TOSHIBA Corporation)
HKLM\...\Run: [ThreatFire] - C:\Programme\ThreatFire\TFTray.exe [378128 2011-02-22] (PC Tools)
HKLM\...\Run: [THotkey] - C:\Programme\Toshiba\Toshiba Applet\thotkey.exe [356352 2005-07-06] (TOSHIBA)
HKLM\...\Run: [SynTPLpr] - C:\Programme\Synaptics\SynTP\SynTPLpr.exe [98394 2004-10-15] (Synaptics, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Programme\Synaptics\SynTP\SynTPEnh.exe [688218 2004-10-15] (Synaptics, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [SoundMAXPnP] - C:\Programme\Analog Devices\SoundMAX\SMax4PNP.exe [1388544 2004-07-27] (Analog Devices, Inc.)
HKLM\...\Run: [SoundMAX] - C:\Programme\Analog Devices\SoundMAX\Smax4.exe [860160 2004-08-06] (Analog Devices, Inc.)
HKLM\...\Run: [PadTouch] - C:\Programme\TOSHIBA\Touch and Launch\PadExe.exe [1077327 2004-11-17] (TOSHIBA)
HKLM\...\Run: [lxeemon.exe] - C:\Programme\Lexmark Pro700 Series\lxeemon.exe [770728 2010-01-18] ()
HKLM\...\Run: [LifeCam] - C:\Programme\Microsoft LifeCam\LifeExp.exe [118640 2009-07-24] (Microsoft Corporation)
HKLM\...\Run: [LexwareInfoService] - C:\Programme\Gemeinsame Dateien\Lexware\Update Manager\LxUpdateManager.exe [189808 2011-07-31] (Haufe-Lexware GmbH & Co. KG)
HKLM\...\Run: [KiesTrayAgent] - C:\Programme\Samsung\Kies\KiesTrayAgent.exe [309688 2012-11-12] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [GrooveMonitor] - C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [EzPrint] - C:\Programme\Lexmark Pro700 Series\ezprint.exe [139944 2010-01-18] ()
HKLM\...\Run: [ATIPTA] - C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe [344064 2005-04-14] (ATI Technologies, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Programme\Gemeinsame Dateien\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [MSConfig] - C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE [172544 2008-04-14] (Microsoft Corporation)
Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.)
HKLM\...\Policies\Explorer: [HonorAutoRunSetting] 1
HKLM\...\Policies\Explorer: [NoDriveTypeAutoRun] 323
HKLM\...\Policies\Explorer: [NoDriveAutoRun] 67108863
HKLM\...\Policies\Explorer: [NoDrives] 0
HKLM\...\Policies\Explorer: [RestrictRun] 0
HKCU\...\Run: [SandboxieControl] - C:\Programme\Sandboxie\SbieCtrl.exe [543320 2013-07-08] (Sandboxie Holdings, LLC)
HKCU\...\Run: [Remote Control Editor] - C:\Programme\Gemeinsame Dateien\TerraTec\Remote\TTTVRC.exe [1528320 2009-09-22] (Elgato Systems)
HKCU\...\Run: [KiesPreload] - C:\Programme\Samsung\Kies\Kies.exe [968120 2012-11-12] (Samsung)
HKCU\...\Run: [KiesAirMessage] - C:\Programme\Samsung\Kies\KiesAirMessage.exe [577536 2012-11-01] (Samsung Electronics)
HKCU\...\Run: [FileHippo.com] - C:\Programme\FileHippo.com\UpdateChecker.exe [307712 2012-11-23] (FileHippo.com)
HKCU\...\Run: [BrowserProtect] - C:\Programme\BrowserProtect\BpAuto.lnk [1857 2013-08-08] ()
HKCU\...\Policies\Explorer: [NoDriveTypeAutoRun] 323
HKCU\...\Policies\Explorer: [NoDriveAutoRun] 67108863
HKCU\...\Policies\Explorer: [NoDrives] 0
HKCU\...\Policies\Explorer: [RestrictRun] 0
HKU\Default User\...\Run: [TOSCDSPD] - C:\Programme\TOSHIBA\TOSCDSPD\toscdspd.exe [x]
HKU\Default User\...\Run: [MSMSGS] - C:\Programme\Messenger\msmsgs.exe [ 2008-04-14] (Microsoft Corporation)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Programme\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Windows Search.lnk
ShortcutTarget: Windows Search.lnk -> C:\Programme\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - {E649DC79-BD07-46CD-85E1-6D561DA45348} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7ADFA_de
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Lexmark - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Programme\Lexmark Printable Web\bho.dll ()
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - &TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\PROGRA~1\TerraTec\TERRAT~1\THCDES~1.DLL (TerraTec Electronic GmbH)
Toolbar: HKLM - Lexmark Symbolleiste - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Programme\Lexmark Toolbar\toolband.dll ()
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU -&Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU -Lexmark Symbolleiste - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Programme\Lexmark Toolbar\toolband.dll ()
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: haufereader - No CLSID Value -
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\clk\Anwendungsdaten\Mozilla\Firefox\Profiles\apdoscfg.default
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Programme\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Programme\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @citrixonline.com/appdetectorplugin - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Extension: Skype extension for Firefox - C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] C:\Programme\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Programme\PDF Architect\FFPDFArchitectExt
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] C:\Programme\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Programme\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\29.0.1547.62\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\29.0.1547.62\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Programme\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Programme\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Programme\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Programme\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Programme\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Programme\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Programme\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Programme\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft00AE DRM) - C:\Programme\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Programme\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Microsoft00AE DRM) - C:\Programme\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Picasa) - C:\Programme\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Programme\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.90.5) - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Windows Presentation Foundation) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Dr.Web Anti-Virus Link Checker) - C:\DOKUME~1\clk\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\aleggpabliehgbeagmfhnodcijcmbonb\3.2.1_0
CHR Extension: (WOT) - C:\DOKUME~1\clk\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.13_0
CHR Extension: (VTchromizer) - C:\DOKUME~1\clk\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\efbjojhplkelaegfbieplglfidafgoka\1.2_0
CHR Extension: (AdBlock) - C:\DOKUME~1\clk\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.6_0
CHR Extension: (DVDVideoSoft Browser Extension) - C:\DOKUME~1\clk\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.2_0
CHR Extension: (Chrome In-App Payments service) - C:\DOKUME~1\clk\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR Extension: (NotScripts) - C:\DOKUME~1\clk\LOKALE~1\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\odjhifogjcknibkahlpidmdajjpkkcfn\0.9.6_0
CHR StartMenuInternet: Google Chrome - C:\Dokumente und Einstellungen\clk\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Programme\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
R2 BpSvc; C:\Programme\BrowserProtect\BpSvc.exe [1867776 2011-11-11] (Web Eight LLC.)
R2 CFSvcs; C:\Programme\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2005-01-18] (TOSHIBA CORPORATION)
R2 DeviceManager; C:\Programme\Gemeinsame Dateien\DeviceHelper\DeviceManager.exe [40960 2009-05-25] ()
S2 gupdate; C:\Programme\Google\Update\GoogleUpdate.exe [116648 2013-06-02] (Google Inc.)
S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [116648 2013-06-02] (Google Inc.)
S3 gusvc; C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe [136120 2011-05-10] (Google)
S3 IDriverT; C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation)
S2 lxeeCATSCustConnectService; C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxeeserv.exe [98984 2010-01-07] (Lexmark International, Inc.)
R2 lxee_device; C:\WINDOWS\system32\lxeecoms.exe [598696 2010-01-07] ( )
S3 Microsoft Office Groove Audit Service; C:\Programme\Microsoft Office\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation)
S4 MSCamSvc; C:\Programme\Microsoft LifeCam\MSCamS32.exe [139120 2009-07-24] (Microsoft Corporation)
R2 Nero BackItUp Scheduler 4.0; C:\Programme\Gemeinsame Dateien\Nero\Nero BackItUp 4\NBService.exe [935208 2008-08-29] (Nero AG)
R2 NwSapAgent; C:\Windows\System32\ipxsap.dll [66560 2004-08-04] (Microsoft Corporation)
S3 odserv; C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE [440696 2011-07-20] (Microsoft Corporation)
S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [145184 2006-10-26] (Microsoft Corporation)
R2 PDF Architect Helper Service; C:\Programme\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR)
S2 PDF Architect Service; C:\Programme\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR)
R2 PLFlash DeviceIoControl Service; C:\Programme\Nero\Nero BackItUp 4\IoctlSvc.exe [81920 2008-08-29] (Prolific Technology Inc.)
S4 SbieSvc; C:\Programme\Sandboxie\SbieSvc.exe [129112 2013-07-08] (Sandboxie Holdings, LLC)
R2 Secunia PSI Agent; C:\Programme\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia)
R2 Secunia Update Agent; C:\Programme\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia)
R2 Skype C2C Service; C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.)
S2 SkypeUpdate; C:\Programme\Skype\Updater\Updater.exe [160944 2012-07-13] (Skype Technologies)
R2 SoundMAX Agent Service (default); C:\Programme\Analog Devices\SoundMAX\SMAgent.exe [45056 2002-09-20] (Analog Devices, Inc.)
R2 TAPPSRV; C:\Programme\Toshiba\TOSHIBA Applet\TAPPSRV.exe [34816 2005-07-05] (TOSHIBA Corp.)
R2 ThreatFire; C:\Programme\ThreatFire\TFService.exe [70928 2011-02-22] (PC Tools)
R2 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-11-03] (Microsoft Corporation)
R2 WTGService; C:\Programme\Verbindungsassistent\wtgservice.exe [308688 2010-01-15] ()
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
R2 JavaQuickStarterService; "C:\Programme\Java\jre7\bin\jqs.exe" -service -config "C:\Programme\Java\jre7\lib\deploy\jqs\jqs.conf" [x]
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [x]
S3 WPFFontCache_v0400; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [x]
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [66336 2013-05-09] (AVAST Software)
R1 AswRdr; C:\Windows\System32\Drivers\AswRdr.sys [49760 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [770344 2013-06-28] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [369584 2013-06-28] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [175176 2013-06-28] ()
S3 MPE; C:\Windows\System32\DRIVERS\MPE.sys [15232 2008-04-13] (Microsoft Corporation)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R2 Netdevio; C:\Windows\System32\DRIVERS\netdevio.sys [12032 2003-01-29] (TOSHIBA Corporation.)
S3 nm; C:\Windows\System32\DRIVERS\NMnt.sys [40320 2008-04-13] (Microsoft Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [50704 2009-10-20] (CACE Technologies, Inc.)
R2 NwlnkIpx; C:\Windows\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-13] (Microsoft Corporation)
R2 NwlnkNb; C:\Windows\System32\DRIVERS\nwlnknb.sys [63232 2004-08-04] (Microsoft Corporation)
R2 NwlnkSpx; C:\Windows\System32\DRIVERS\nwlnkspx.sys [55936 2004-08-04] (Microsoft Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-07-03] (Secunia)
S3 qcusbser; C:\Windows\System32\DRIVERS\qcusbser.sys [103552 2009-05-25] (TCT International Mobile Ltd)
S3 S6U12Scanner; C:\Windows\System32\drivers\usbscan.sys [15104 2008-04-13] (Microsoft Corporation)
S3 SbieDrv; C:\Programme\Sandboxie\SbieDrv.sys [159208 2013-07-08] (Sandboxie Holdings, LLC)
R1 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [5632 2006-07-24] ()
R0 TfFsMon; C:\Windows\System32\drivers\TfFsMon.sys [51984 2011-02-22] (PC Tools)
R3 TfNetMon; C:\WINDOWS\system32\drivers\TfNetMon.sys [33552 2011-02-22] (PC Tools)
R0 TfSysMon; C:\Windows\System32\drivers\TfSysMon.sys [69392 2011-02-22] (PC Tools)
S3 TTHID; C:\Windows\System32\DRIVERS\Cinergy_Hybrid-Stick_HID.sys [23104 2009-11-04] (DTV-DVB)
R3 TVALD; C:\Windows\System32\DRIVERS\NBSMI.sys [4864 2005-03-02] (Toshiba Corporation)
R3 Tvs; C:\Windows\System32\DRIVERS\Tvs.sys [29056 2005-05-10] (TOSHIBA Corporation)
S3 UDXTTM6010; C:\Windows\System32\DRIVERS\UDXTTM6010.sys [763584 2009-11-04] ()
R3 w29n51; C:\Windows\System32\DRIVERS\w29n51.sys [3222784 2004-10-29] (Intel® Corporation)
R3 yukonwxp; C:\Windows\System32\DRIVERS\yk51x86.sys [230400 2005-03-31] (Marvell)
S3 catchme; \??\C:\DOKUME~1\clk\LOKALE~1\Temp\catchme.sys [x]
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
U3 TlntSvr;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-01 22:16 - 2013-09-01 22:16 - 01085755 _____ (Farbar) C:\Dokumente und Einstellungen\clk\Desktop\FRST.exe
2013-08-27 22:36 - 2013-08-27 22:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2013-08-27 22:34 - 2013-08-27 22:39 - 00004299 _____ C:\WINDOWS\KB2834904-v2.log
2013-08-17 01:21 - 2013-08-17 01:22 - 00012386 _____ C:\WINDOWS\KB2862772-IE8.log
2013-08-17 00:42 - 2013-08-17 00:42 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2013-08-17 00:41 - 2013-08-17 00:41 - 00005202 _____ C:\WINDOWS\KB2863058.log
2013-08-17 00:41 - 2013-08-17 00:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$
2013-08-17 00:41 - 2013-08-17 00:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2013-08-17 00:41 - 2013-08-17 00:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$
2013-08-16 21:33 - 2013-08-17 00:42 - 00009092 _____ C:\WINDOWS\KB2850869.log
2013-08-16 21:32 - 2013-08-17 00:42 - 00010849 _____ C:\WINDOWS\KB2859537.log
2013-08-15 21:34 - 2013-08-15 21:34 - 00000000 _____ C:\Dokumente und Einstellungen\All Users\SPL15.tmp
2013-08-15 21:29 - 2013-08-15 21:29 - 00206566 _____ C:\Dokumente und Einstellungen\All Users\SPLF.tmp
2013-08-15 01:09 - 2013-08-15 01:09 - 00689334 _____ C:\Dokumente und Einstellungen\All Users\SPL2.tmp
2013-08-15 00:53 - 2013-08-15 00:53 - 00689334 _____ C:\Dokumente und Einstellungen\All Users\SPL4.tmp
2013-08-14 11:35 - 2013-08-14 11:35 - 00106496 _____ C:\WINDOWS\Minidump\Mini081413-01.dmp
2013-08-12 23:08 - 2013-08-30 21:40 - 00016896 ___SH C:\Dokumente und Einstellungen\clk\Desktop\Thumbs.db
2013-08-09 16:28 - 2013-08-15 23:18 - 00002363 _____ C:\Dokumente und Einstellungen\All Users\Desktop\QuickSteuer 2013.lnk
2013-08-09 04:40 - 2013-08-09 04:40 - 00135595 ____C C:\wubildr
2013-08-09 04:40 - 2013-08-09 04:40 - 00008192 ____C C:\wubildr.mbr
2013-08-09 04:08 - 2013-08-09 04:40 - 00000000 ___DC C:\ubuntu
2013-08-08 23:01 - 2013-08-08 23:01 - 00000000 __RDC C:\Sandbox
2013-08-08 23:00 - 2013-08-08 23:01 - 00001236 _____ C:\WINDOWS\Sandboxie.ini
2013-08-08 22:59 - 2013-08-08 22:59 - 00000000 ____D C:\Programme\Sandboxie
2013-08-08 22:55 - 2013-08-08 22:55 - 00001883 _____ C:\Dokumente und Einstellungen\clk\Startmenü\Programme\Browser Protect.lnk
2013-08-08 22:51 - 2013-08-11 10:11 - 00000000 ____D C:\Programme\Microsoft Silverlight
2013-08-08 22:50 - 2013-08-08 22:55 - 00000000 ____D C:\Programme\BrowserProtect
2013-08-08 12:19 - 2013-09-01 21:49 - 00000000 ____D C:\Programme\ThreatFire
2013-08-08 12:19 - 2011-02-22 13:57 - 00069392 _____ (PC Tools) C:\WINDOWS\system32\Drivers\TfSysMon.sys
2013-08-08 12:19 - 2011-02-22 13:57 - 00051984 _____ (PC Tools) C:\WINDOWS\system32\Drivers\TfFsMon.sys
2013-08-08 12:19 - 2011-02-22 13:57 - 00033552 _____ (PC Tools) C:\WINDOWS\system32\Drivers\TfNetMon.sys
2013-08-08 12:17 - 2013-08-08 12:17 - 00001602 _____ C:\Dokumente und Einstellungen\clk\Startmenü\Programme\Update Checker.lnk
2013-08-08 12:17 - 2013-08-08 12:17 - 00000000 ____D C:\Programme\FileHippo.com
2013-08-08 11:24 - 2013-08-08 11:24 - 00000000 ____D C:\Programme\Gemeinsame Dateien\Java
2013-08-08 11:23 - 2013-08-08 11:23 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-08-08 11:23 - 2013-08-08 11:22 - 00263592 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2013-08-08 11:23 - 2013-08-08 11:22 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2013-08-08 11:23 - 2013-08-08 11:22 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2013-08-07 23:21 - 2013-08-07 23:23 - 00007966 _____ C:\WINDOWS\KB946648.log
2013-08-07 20:30 - 2013-08-07 20:33 - 00005846 _____ C:\WINDOWS\KB942288-v3.log
2013-08-07 20:13 - 2013-08-07 20:30 - 00001541 _____ C:\WINDOWS\KB942288-v4.log
2013-08-07 00:52 - 2013-08-07 01:15 - 00010502 _____ C:\WINDOWS\KB2719985.log
2013-08-07 00:52 - 2013-08-07 01:14 - 00010665 _____ C:\WINDOWS\KB2757638.log
2013-08-07 00:43 - 2013-08-07 00:43 - 00000236 _____ C:\WINDOWS\DtcInstall.log
2013-08-07 00:42 - 2013-08-07 00:43 - 00000814 _____ C:\WINDOWS\wmsetup.log
2013-08-07 00:42 - 2013-08-07 00:42 - 00000187 _____ C:\WINDOWS\spupdsvc.log.1.log
2013-08-07 00:38 - 2013-08-07 00:38 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB923561$
2013-08-07 00:37 - 2013-08-07 00:38 - 00005306 _____ C:\WINDOWS\KB923561.log
2013-08-07 00:33 - 2013-08-07 00:43 - 00030753 _____ C:\WINDOWS\spupdsvc.log
2013-08-07 00:33 - 2013-08-07 00:33 - 00000200 _____ C:\WINDOWS\cmsetacl.log
2013-08-07 00:32 - 2013-08-07 00:32 - 00000311 _____ C:\WINDOWS\sessmgr.setup.log
2013-08-07 00:31 - 2013-08-07 00:31 - 00000565 _____ C:\WINDOWS\medctroc.Log
2013-08-07 00:22 - 2013-08-07 00:39 - 00096346 _____ C:\WINDOWS\svcpack.log
2013-08-05 23:25 - 2013-08-05 23:25 - 00000000 ____D C:\Programme\Citrix
2013-08-02 15:00 - 2013-08-02 22:17 - 00000000 ____D C:\Dokumente und Einstellungen\clk\Anwendungsdaten\Web Cake
==================== One Month Modified Files and Folders =======
2013-09-01 22:20 - 2013-06-02 22:05 - 00001084 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-01 22:17 - 2013-09-01 22:17 - 00000000 ___DC C:\FRST
2013-09-01 22:16 - 2013-09-01 22:16 - 01085755 _____ (Farbar) C:\Dokumente und Einstellungen\clk\Desktop\FRST.exe
2013-09-01 22:16 - 2005-08-17 14:43 - 02077010 _____ C:\WINDOWS\WindowsUpdate.log
2013-09-01 22:14 - 2013-06-02 22:04 - 00000350 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2013-09-01 22:09 - 2013-02-05 22:32 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-09-01 22:02 - 2011-09-07 13:03 - 00001202 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2044978897-1172690549-42215457-1007UA.job
2013-09-01 22:02 - 2005-08-17 14:51 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-09-01 21:49 - 2013-08-08 12:19 - 00000000 ____D C:\Programme\ThreatFire
2013-09-01 21:29 - 2010-03-07 22:47 - 00186002 _____ C:\Dokumente und Einstellungen\All Users\lxeescan.log
2013-09-01 21:29 - 2005-08-17 15:39 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-09-01 21:29 - 2005-08-17 15:39 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-09-01 21:28 - 2013-06-02 22:05 - 00001080 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-01 21:28 - 2005-08-17 15:36 - 03622528 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-09-01 21:27 - 2005-08-17 14:47 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-31 23:11 - 2010-01-14 14:04 - 00000190 ___SH C:\Dokumente und Einstellungen\clk\ntuser.ini
2013-08-31 23:11 - 2010-01-14 14:04 - 00000000 ____D C:\Dokumente und Einstellungen\clk
2013-08-31 21:14 - 2013-04-14 21:51 - 00072968 _____ C:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2013-08-31 21:12 - 2010-01-14 23:20 - 00000000 ____D C:\WINDOWS\system32\de-DE
2013-08-31 21:12 - 2010-01-14 17:42 - 00000000 ____D C:\WINDOWS\system32\XPSViewer
2013-08-31 21:09 - 2005-08-17 15:37 - 01091320 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-08-31 21:08 - 2010-01-14 17:45 - 00000000 ____D C:\Programme\MSBuild
2013-08-31 19:14 - 2005-08-17 14:47 - 00032506 _____ C:\WINDOWS\SchedLgU.Txt
2013-08-31 18:29 - 2005-08-17 14:30 - 00000582 _____ C:\WINDOWS\win.ini
2013-08-31 18:29 - 2005-08-17 14:30 - 00000354 __RSH C:\boot.ini
2013-08-31 18:29 - 2005-08-17 14:30 - 00000227 ____C C:\WINDOWS\system.ini
2013-08-31 18:27 - 2010-01-14 18:52 - 00065536 _____ C:\WINDOWS\system32\config\ODiag.evt
2013-08-31 18:13 - 2010-03-07 22:48 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Lx_cats
2013-08-31 02:00 - 2012-12-15 00:51 - 00000342 _____ C:\WINDOWS\Tasks\AdobeAAMUpdater-1.0-CK-clk.job
2013-08-31 00:01 - 2011-09-07 13:03 - 00001150 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2044978897-1172690549-42215457-1007Core.job
2013-08-30 21:40 - 2013-08-12 23:08 - 00016896 ___SH C:\Dokumente und Einstellungen\clk\Desktop\Thumbs.db
2013-08-29 22:52 - 2013-01-01 20:46 - 00000000 ____D C:\Dokumente und Einstellungen\clk\Desktop\Camera
2013-08-29 20:40 - 2010-03-08 14:48 - 02245392 _____ C:\Dokumente und Einstellungen\All Users\lxee.log
2013-08-29 20:39 - 2013-02-25 17:56 - 00661017 _____ C:\WINDOWS\setupapi.log
2013-08-29 20:20 - 2005-08-17 14:30 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl
2013-08-28 20:08 - 2013-03-09 17:39 - 00005940 _____ C:\WINDOWS\setupact.log
2013-08-27 22:39 - 2013-08-27 22:34 - 00004299 _____ C:\WINDOWS\KB2834904-v2.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00177955 _____ C:\WINDOWS\FaxSetup.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00094099 _____ C:\WINDOWS\ocgen.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00070008 _____ C:\WINDOWS\tsoc.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00059722 _____ C:\WINDOWS\comsetup.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00037317 _____ C:\WINDOWS\ntdtcsetup.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00027425 _____ C:\WINDOWS\iis6.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00010536 _____ C:\WINDOWS\ocmsn.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00009003 _____ C:\WINDOWS\msgsocm.log
2013-08-27 22:39 - 2013-03-09 17:40 - 00001374 _____ C:\WINDOWS\imsins.log
2013-08-27 22:36 - 2013-08-27 22:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2013-08-26 23:15 - 2013-07-13 00:44 - 00000000 ____D C:\Dokumente und Einstellungen\clk\Anwendungsdaten\vlc
2013-08-26 23:00 - 2010-01-14 18:36 - 00000000 ____D C:\Programme\IrfanView
2013-08-24 23:14 - 2005-08-17 15:37 - 00000000 ____D C:\Programme
2013-08-24 20:03 - 2013-05-24 12:58 - 00000474 _____ C:\WINDOWS\nsw.log
2013-08-18 22:34 - 2010-01-14 18:48 - 00000000 ____D C:\Programme\Microsoft.NET
2013-08-17 22:08 - 2005-08-17 14:42 - 00000000 ____D C:\WINDOWS\Registration
2013-08-17 01:22 - 2013-08-17 01:21 - 00012386 _____ C:\WINDOWS\KB2862772-IE8.log
2013-08-17 01:22 - 2013-03-14 00:17 - 00017108 _____ C:\WINDOWS\updspapi.log
2013-08-17 01:22 - 2013-03-09 17:40 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-08-17 01:21 - 2010-01-14 23:24 - 00000000 ____D C:\WINDOWS\ie8updates
2013-08-17 01:18 - 2013-07-15 22:10 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-08-17 01:12 - 2010-01-14 22:45 - 75778376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-08-17 00:42 - 2013-08-17 00:42 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2013-08-17 00:42 - 2013-08-16 21:33 - 00009092 _____ C:\WINDOWS\KB2850869.log
2013-08-17 00:42 - 2013-08-16 21:32 - 00010849 _____ C:\WINDOWS\KB2859537.log
2013-08-17 00:41 - 2013-08-17 00:41 - 00005202 _____ C:\WINDOWS\KB2863058.log
2013-08-17 00:41 - 2013-08-17 00:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$
2013-08-17 00:41 - 2013-08-17 00:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2013-08-17 00:41 - 2013-08-17 00:41 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$
2013-08-17 00:41 - 2010-01-14 23:31 - 00053992 _____ C:\WINDOWS\system32\TZLog.log
2013-08-16 23:17 - 2013-06-01 22:14 - 00000000 ____D C:\WINDOWS\pss
2013-08-15 23:18 - 2013-08-09 16:28 - 00002363 _____ C:\Dokumente und Einstellungen\All Users\Desktop\QuickSteuer 2013.lnk
2013-08-15 23:06 - 2005-08-17 14:42 - 00000000 ____D C:\WINDOWS\system32\Restore
2013-08-15 21:34 - 2013-08-15 21:34 - 00000000 _____ C:\Dokumente und Einstellungen\All Users\SPL15.tmp
2013-08-15 21:29 - 2013-08-15 21:29 - 00206566 _____ C:\Dokumente und Einstellungen\All Users\SPLF.tmp
2013-08-15 01:09 - 2013-08-15 01:09 - 00689334 _____ C:\Dokumente und Einstellungen\All Users\SPL2.tmp
2013-08-15 00:53 - 2013-08-15 00:53 - 00689334 _____ C:\Dokumente und Einstellungen\All Users\SPL4.tmp
2013-08-14 11:35 - 2013-08-14 11:35 - 00106496 _____ C:\WINDOWS\Minidump\Mini081413-01.dmp
2013-08-14 11:35 - 2010-01-17 21:44 - 00000000 ____D C:\WINDOWS\Minidump
2013-08-11 10:11 - 2013-08-08 22:51 - 00000000 ____D C:\Programme\Microsoft Silverlight
2013-08-09 16:25 - 2010-01-15 23:51 - 00000000 ____D C:\Programme\Gemeinsame Dateien\Lexware
2013-08-09 04:40 - 2013-08-09 04:40 - 00135595 ____C C:\wubildr
2013-08-09 04:40 - 2013-08-09 04:40 - 00008192 ____C C:\wubildr.mbr
2013-08-09 04:40 - 2013-08-09 04:08 - 00000000 ___DC C:\ubuntu
2013-08-09 04:08 - 2005-08-17 14:44 - 00000000 __RSH C:\CONFIG.SYS
2013-08-08 23:01 - 2013-08-08 23:01 - 00000000 __RDC C:\Sandbox
2013-08-08 23:01 - 2013-08-08 23:00 - 00001236 _____ C:\WINDOWS\Sandboxie.ini
2013-08-08 22:59 - 2013-08-08 22:59 - 00000000 ____D C:\Programme\Sandboxie
2013-08-08 22:55 - 2013-08-08 22:55 - 00001883 _____ C:\Dokumente und Einstellungen\clk\Startmenü\Programme\Browser Protect.lnk
2013-08-08 22:55 - 2013-08-08 22:50 - 00000000 ____D C:\Programme\BrowserProtect
2013-08-08 22:55 - 2010-01-14 14:04 - 00000000 ___RD C:\Dokumente und Einstellungen\clk\Startmenü\Programme
2013-08-08 12:40 - 2012-12-14 22:21 - 00000000 ____D C:\Programme\Gemeinsame Dateien\Adobe AIR
2013-08-08 12:17 - 2013-08-08 12:17 - 00001602 _____ C:\Dokumente und Einstellungen\clk\Startmenü\Programme\Update Checker.lnk
2013-08-08 12:17 - 2013-08-08 12:17 - 00000000 ____D C:\Programme\FileHippo.com
2013-08-08 11:48 - 2013-06-16 20:34 - 00004784 ____C C:\DelFix.txt
2013-08-08 11:24 - 2013-08-08 11:24 - 00000000 ____D C:\Programme\Gemeinsame Dateien\Java
2013-08-08 11:23 - 2013-08-08 11:23 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-08-08 11:22 - 2013-08-08 11:23 - 00263592 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2013-08-08 11:22 - 2013-08-08 11:23 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2013-08-08 11:22 - 2013-08-08 11:23 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2013-08-08 11:22 - 2012-11-01 21:20 - 00867240 _____ (Oracle Corporation) C:\WINDOWS\system32\npDeployJava1.dll
2013-08-08 11:22 - 2012-11-01 21:20 - 00144896 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2013-08-08 11:22 - 2010-10-14 20:03 - 00789416 _____ (Oracle Corporation) C:\WINDOWS\system32\deployJava1.dll
2013-08-07 23:23 - 2013-08-07 23:21 - 00007966 _____ C:\WINDOWS\KB946648.log
2013-08-07 23:23 - 2005-08-17 14:41 - 00000000 ____D C:\Programme\Messenger
2013-08-07 20:33 - 2013-08-07 20:30 - 00005846 _____ C:\WINDOWS\KB942288-v3.log
2013-08-07 20:30 - 2013-08-07 20:13 - 00001541 _____ C:\WINDOWS\KB942288-v4.log
2013-08-07 01:15 - 2013-08-07 00:52 - 00010502 _____ C:\WINDOWS\KB2719985.log
2013-08-07 01:14 - 2013-08-07 00:52 - 00010665 _____ C:\WINDOWS\KB2757638.log
2013-08-07 01:14 - 2013-07-12 09:28 - 00017862 _____ C:\WINDOWS\KB2846071-IE8.log
2013-08-07 00:43 - 2013-08-07 00:43 - 00000236 _____ C:\WINDOWS\DtcInstall.log
2013-08-07 00:43 - 2013-08-07 00:42 - 00000814 _____ C:\WINDOWS\wmsetup.log
2013-08-07 00:43 - 2013-08-07 00:33 - 00030753 _____ C:\WINDOWS\spupdsvc.log
2013-08-07 00:42 - 2013-08-07 00:42 - 00000187 _____ C:\WINDOWS\spupdsvc.log.1.log
2013-08-07 00:42 - 2010-01-14 19:17 - 00000090 _____ C:\WINDOWS\system32\spupdwxp.log
2013-08-07 00:39 - 2013-08-07 00:22 - 00096346 _____ C:\WINDOWS\svcpack.log
2013-08-07 00:39 - 2005-08-17 16:31 - 00000000 ____D C:\WINDOWS\security
2013-08-07 00:38 - 2013-08-07 00:38 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB923561$
2013-08-07 00:38 - 2013-08-07 00:37 - 00005306 _____ C:\WINDOWS\KB923561.log
2013-08-07 00:33 - 2013-08-07 00:33 - 00000200 _____ C:\WINDOWS\cmsetacl.log
2013-08-07 00:32 - 2013-08-07 00:32 - 00000311 _____ C:\WINDOWS\sessmgr.setup.log
2013-08-07 00:32 - 2005-08-17 16:31 - 00000000 ____D C:\WINDOWS\Help
2013-08-07 00:32 - 2005-08-17 15:36 - 00000000 ___RD C:\Dokumente und Einstellungen\All Users\Startmenü
2013-08-07 00:31 - 2013-08-07 00:31 - 00000565 _____ C:\WINDOWS\medctroc.Log
2013-08-05 23:25 - 2013-08-05 23:25 - 00000000 ____D C:\Programme\Citrix
2013-08-03 01:48 - 2006-08-24 23:30 - 01543680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmvdecod.dll
2013-08-02 22:17 - 2013-08-02 15:00 - 00000000 ____D C:\Dokumente und Einstellungen\clk\Anwendungsdaten\Web Cake
2013-08-02 22:17 - 2005-08-17 16:31 - 00000000 ____D C:\WINDOWS\Resources
2013-08-02 21:03 - 2010-01-15 02:04 - 00000000 ____D C:\Dokumente und Einstellungen\clk\Eigene Dateien\Dateien von CK
2013-08-02 20:56 - 2005-08-17 14:43 - 00000000 __SHD C:\Dokumente und Einstellungen\All Users\DRM
Files to move or delete:
====================
C:\DOKUME~1\clk\LOKALE~1\Temp\pyl275.tmp.exe
C:\DOKUME~1\clk\LOKALE~1\Temp\pyl29F.tmp.exe
C:\DOKUME~1\clk\LOKALE~1\Temp\Rar$EX06.694\wubi.exe
C:\DOKUME~1\clk\LOKALE~1\Temp\is-IBBLP.tmp\gtapi.dll
C:\DOKUME~1\clk\LOKALE~1\Temp\C379BD5D-8513-468C-B0E2-085A97E85791\G2MAudioStreamingDSP64.dll
C:\DOKUME~1\clk\LOKALE~1\Temp\C379BD5D-8513-468C-B0E2-085A97E85791\G2MVideoStreamingDSP64.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2005-08-17 14:29] - [2008-04-14 04:22] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\Windows\System32\winlogon.exe
[2005-08-17 14:30] - [2008-04-14 04:23] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\Windows\System32\svchost.exe
[2005-08-17 14:30] - [2008-04-14 04:23] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\Windows\System32\services.exe
[2005-08-17 14:30] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\Windows\System32\User32.dll
[2005-08-17 14:30] - [2008-04-14 04:22] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\Windows\System32\userinit.exe
[2005-08-17 14:30] - [2008-04-14 04:23] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\Windows\System32\Drivers\volsnap.sys
[2005-08-17 14:30] - [2008-04-14 03:52] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================ --- --- ---
Jetzt bekomme ich nur noch diese Meldungen:
(siehe Anhänge)
Liebe Grüße
Claudia |