Code:
OTL logfile created on: 18.03.2010 17:00:23 - Run 1
OTL by OldTimer - Version 3.1.37.2 Folder = C:\Users\*meinereiner*\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 71,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 82,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 165,92 Gb Total Space | 111,56 Gb Free Space | 67,24% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 10,47 Gb Total Space | 1,79 Gb Free Space | 17,07% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: **
Current User Name: *meinereiner*
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 90 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\*meinereiner*\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Programme\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
PRC - C:\Programme\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
========== Modules (SafeList) ==========
MOD - C:\Users\*meinereiner*\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\fms.dll (Windows (R) Codename Longhorn DDK provider)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (WwanSvc) -- C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) -- C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) -- C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) -- C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) -- C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) -- C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) -- C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) -- C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) -- C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) -- C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) -- C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) -- C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX-Installer (AxInstSV) -- C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) -- C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) -- C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (AVP) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
SRV - (VMCService) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
========== Driver Services (SafeList) ==========
DRV - (KLIF) -- C:\Windows\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (kl1) -- C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (cmdide) -- C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) -- C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) -- C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) -- C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) -- C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) -- C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) -- C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) -- C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) -- C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) -- C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) -- C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) -- C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) -- C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) -- C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) -- C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) -- C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (KSecPkg) -- C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (LSI_SCSI) -- C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) -- C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) -- C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) -- C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) -- C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) -- C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) -- C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) -- C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) -- C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) -- C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) -- C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) -- C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) -- C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) -- C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) -- C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) -- C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) -- C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) -- C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) -- C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) -- C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) -- C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) -- C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) -- C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) -- C:\Windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) -- C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) -- C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) -- C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) -- C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwififlt) -- C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) -- C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) -- C:\Windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) -- C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (mshidkmdf) -- C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) -- C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) -- C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) -- C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) -- C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) -- C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) -- C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) -- C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) -- C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) -- C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) -- C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) -- C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (RTL8167) -- C:\Windows\System32\drivers\Rt86win7.sys (Realtek Corporation )
DRV - (b57nd60x) -- C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) -- C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) -- C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (klmouflt) -- C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (KLIM6) -- C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab)
DRV - (ZTEusbnet) -- C:\Windows\System32\drivers\ZTEusbnet.sys (ZTE Corporation)
DRV - (ZTEusbvoice) -- C:\Windows\System32\drivers\zteusbvoice.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) -- C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbser6k) -- C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) -- C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (klbg) -- C:\Windows\system32\drivers\klbg.sys (Kaspersky Lab)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2398151456-759757974-3751660826-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
IE - HKU\S-1-5-21-2398151456-759757974-3751660826-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-2398151456-759757974-3751660826-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-2398151456-759757974-3751660826-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = EB BD FE FF 31 AB CA 01 [binary data]
IE - HKU\S-1-5-21-2398151456-759757974-3751660826-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.de/"
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:9.0.0.459
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.02.24 08:50:40 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.02.25 08:57:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2010.02.12 00:28:08 | 000,000,000 | ---D | M]
[2010.02.24 08:51:15 | 000,000,000 | ---D | M] -- C:\Users\*meinereiner*\AppData\Roaming\mozilla\Extensions
[2010.02.25 09:24:55 | 000,000,000 | ---D | M] -- C:\Users\*meinereiner*\AppData\Roaming\mozilla\Firefox\Profiles\wx344pyr.default\extensions
[2010.03.15 10:47:41 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2010.02.25 08:56:55 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
[2010.01.16 02:15:29 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.01.16 02:15:29 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.01.16 02:15:29 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.01.16 02:15:29 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.01.16 02:15:29 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\*meinereiner*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 139.7.30.126 139.7.30.125
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\kloehk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\klogon: DllName - C:\Windows\system32\klogon.dll - C:\Windows\System32\klogon.dll (Kaspersky Lab)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0af595e9-2398-11df-b51d-00269e0d7e07}\Shell - "" = AutoRun
O33 - MountPoints2\{0af595e9-2398-11df-b51d-00269e0d7e07}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe -- File not found
O33 - MountPoints2\{f3beb303-2440-11df-b512-00a0c6000000}\Shell - "" = AutoRun
O33 - MountPoints2\{f3beb303-2440-11df-b512-00a0c6000000}\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe -- File not found
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\setup_vmc_lite.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 90 Days ==========
[2010.03.18 16:40:51 | 000,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Users\*meinereiner*\Desktop\HJTInstall.exe
[2010.03.17 17:56:07 | 000,556,032 | ---- | C] (OldTimer Tools) -- C:\Users\*meinereiner*\Desktop\OTL.exe
[2010.03.17 17:25:06 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\Malwarebytes
[2010.03.17 17:24:59 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.03.17 17:24:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.03.17 17:24:51 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010.03.17 17:24:50 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2010.03.16 18:38:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Vodafone
[2010.03.16 18:38:15 | 000,000,000 | ---D | C] -- C:\Programme\Vodafone
[2010.03.15 11:37:38 | 000,000,000 | ---D | C] -- C:\Programme\QIP 2005 psYNovA-Edition
[2010.03.15 11:00:52 | 000,000,000 | ---D | C] -- C:\Programme\MSXML 4.0
[2010.03.14 15:04:47 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\LEd
[2010.03.14 14:58:22 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\MiKTeX
[2010.03.14 14:58:18 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\MiKTeX
[2010.03.14 14:29:38 | 000,000,000 | ---D | C] -- C:\Programme\MiKTeX 2.8b
[2010.03.14 12:38:30 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\WinShell
[2010.03.14 12:38:19 | 000,000,000 | ---D | C] -- C:\Programme\WinShell
[2010.03.14 12:33:58 | 000,000,000 | ---D | C] -- C:\ProgramData\MiKTeX
[2010.03.14 12:15:32 | 000,000,000 | ---D | C] -- C:\Programme\MiKTeX 2.8
[2010.03.14 11:50:48 | 000,000,000 | ---D | C] -- C:\Programme\LEd
[2010.03.14 11:48:27 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml4r.dll
[2010.03.14 11:48:27 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml4a.dll
[2010.03.14 11:48:24 | 000,000,000 | ---D | C] -- C:\Programme\TeXnicCenter
[2010.03.09 19:11:04 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\TS3Client
[2010.03.09 19:07:23 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Blizzard Entertainment
[2010.03.06 19:10:48 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\Documents\ICQ
[2010.03.05 14:42:13 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\Desktop\projekt
[2010.03.04 13:42:48 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\Documents\Downloads
[2010.03.01 08:48:47 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2010.03.01 08:48:44 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\Sun
[2010.02.27 13:17:27 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\FLEXnet
[2010.02.27 13:11:16 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\Vodafone
[2010.02.27 13:10:55 | 000,105,344 | ---- | C] (ZTE Incorporated) -- C:\Windows\System32\drivers\zteusbvoice.sys
[2010.02.27 13:10:54 | 000,105,344 | ---- | C] (ZTE Incorporated) -- C:\Windows\System32\drivers\ZTEusbnmea.sys
[2010.02.27 13:10:53 | 000,110,592 | ---- | C] (ZTE Corporation) -- C:\Windows\System32\drivers\ZTEusbnet.sys
[2010.02.27 13:10:51 | 000,104,960 | ---- | C] (ZTE Incorporated) -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys
[2010.02.27 13:10:50 | 000,104,960 | ---- | C] (ZTE Incorporated) -- C:\Windows\System32\drivers\ZTEusbser6k.sys
[2010.02.27 13:10:04 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2010.02.27 13:09:08 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\{AADEF95F-E36B-426E-B7B1-70E7D4F6AA5B}
[2010.02.25 09:51:36 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\Pelles C
[2010.02.25 09:37:51 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\Documents\Pelles C Projects
[2010.02.25 09:37:35 | 000,000,000 | ---D | C] -- C:\Programme\PellesC
[2010.02.24 14:54:03 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2010.02.24 12:13:35 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\.thumbnails
[2010.02.24 12:01:44 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\Documents\gegl-0.0
[2010.02.24 12:01:44 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\.gimp-2.6
[2010.02.24 11:35:18 | 000,000,000 | ---D | C] -- C:\Programme\GIMP-2.0
[2010.02.24 10:20:44 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\Notepad++
[2010.02.24 10:20:44 | 000,000,000 | ---D | C] -- C:\Programme\Notepad++
[2010.02.24 08:50:59 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\Mozilla
[2010.02.24 08:50:59 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\Mozilla
[2010.02.24 08:50:38 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox
[2010.02.24 08:11:15 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2010.02.24 08:11:14 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2010.02.24 08:11:13 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2010.02.24 08:11:13 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdri.dll
[2010.02.24 08:11:13 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2010.02.24 08:11:12 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2010.02.24 08:06:34 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\Citrix
[2010.02.23 19:53:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010.02.23 19:53:54 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Java
[2010.02.23 19:26:22 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deploytk.dll
[2010.02.23 19:26:22 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.02.23 19:26:22 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.02.23 19:26:22 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.02.23 19:26:08 | 000,000,000 | ---D | C] -- C:\Programme\Java
[2010.02.22 17:33:34 | 003,955,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2010.02.22 17:33:34 | 003,899,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2010.02.16 22:40:06 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\Diagnostics
[2010.02.15 20:21:22 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\Adobe
[2010.02.15 20:09:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2010.02.15 20:09:09 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Adobe
[2010.02.15 20:09:09 | 000,000,000 | ---D | C] -- C:\Programme\Adobe
[2010.02.15 13:28:26 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\Apps
[2010.02.15 13:28:25 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\Deployment
[2010.02.14 10:42:21 | 000,000,000 | -H-D | C] -- C:\Programme\InstallShield Installation Information
[2010.02.14 10:37:55 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\ICQ
[2010.02.14 10:37:55 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\AOL
[2010.02.13 13:57:58 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\Rawr
[2010.02.13 12:14:34 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\Desktop\Rawr v2.3.9
[2010.02.12 19:47:10 | 000,030,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mdimon.dll
[2010.02.12 19:44:21 | 000,032,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msonpmon.dll
[2010.02.12 19:42:31 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Works
[2010.02.12 19:42:18 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\DESIGNER
[2010.02.12 19:41:56 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010.02.12 19:41:56 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft.NET
[2010.02.12 19:39:09 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\Microsoft Help
[2010.02.12 19:38:59 | 000,000,000 | ---D | C] -- C:\Programme\Microsoft Office
[2010.02.12 19:38:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2010.02.12 19:38:19 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2010.02.12 17:03:03 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\Blizzard Entertainment
[2010.02.12 16:23:15 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\teamspeak2
[2010.02.12 16:18:23 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\Desktop\World of Warcraft - Kopie
[2010.02.12 14:05:04 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\Macromedia
[2010.02.12 14:05:04 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\Adobe
[2010.02.12 14:05:02 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2010.02.12 12:26:47 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\Desktop\filme
[2010.02.12 12:25:38 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Blizzard Entertainment
[2010.02.12 12:17:21 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\Desktop\3.x to 3.2.2a alle patches
[2010.02.12 12:09:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard
[2010.02.12 11:52:47 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\WinRAR
[2010.02.12 10:53:37 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\Desktop\sonstiges
[2010.02.12 10:53:35 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\Desktop\kto2
[2010.02.12 10:53:17 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\Desktop\dhbw
[2010.02.12 10:50:24 | 000,000,000 | ---D | C] -- C:\Programme\TeamSpeak 3 Client
[2010.02.12 10:49:54 | 000,034,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lhacm.acm
[2010.02.12 10:49:49 | 000,000,000 | ---D | C] -- C:\Programme\Teamspeak2_RC2
[2010.02.12 10:32:46 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\Microsoft Games
[2010.02.12 10:28:28 | 000,000,000 | ---D | C] -- C:\Programme\WinRAR
[2010.02.12 10:19:43 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\skypePM
[2010.02.12 10:12:43 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\Skype
[2010.02.12 01:33:21 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2010.02.12 00:37:56 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Skype
[2010.02.12 00:37:55 | 000,000,000 | R--D | C] -- C:\Programme\Skype
[2010.02.12 00:37:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2010.02.12 00:27:56 | 000,000,000 | ---D | C] -- C:\Programme\Kaspersky Lab
[2010.02.12 00:27:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2010.02.12 00:27:49 | 000,280,592 | ---- | C] (Kaspersky Lab) -- C:\Windows\System32\drivers\klif.sys
[2010.02.12 00:19:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab Setup Files
[2010.02.11 22:01:02 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2010.02.11 18:36:42 | 002,614,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2010.02.11 18:36:33 | 001,320,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertEnroll.dll
[2010.02.11 18:36:33 | 000,507,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winload.exe
[2010.02.11 18:36:33 | 000,442,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winresume.exe
[2010.02.11 18:36:32 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL
[2010.02.11 18:34:37 | 000,293,888 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2010.02.11 18:34:37 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll
[2010.02.11 18:34:37 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2010.02.11 18:34:35 | 001,328,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2010.02.11 18:34:35 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\avifil32.dll
[2010.02.11 18:34:35 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciavi32.dll
[2010.02.11 18:34:32 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2010.02.11 18:34:32 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2010.02.11 18:34:12 | 000,369,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc.dll
[2010.02.11 18:34:12 | 000,365,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_isv.dll
[2010.02.11 18:34:12 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_isv.exe
[2010.02.11 18:34:12 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate.exe
[2010.02.11 18:34:12 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp.exe
[2010.02.11 18:34:12 | 000,277,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp_isv.exe
[2010.02.11 18:34:12 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp_isv.dll
[2010.02.11 18:34:12 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp.dll
[2010.02.11 18:24:58 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2010.02.11 18:24:49 | 000,485,920 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvuninst.exe
[2010.02.11 17:17:20 | 000,181,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010.02.11 16:45:58 | 000,000,000 | R--D | C] -- C:\Users\*meinereiner*\Searches
[2010.02.11 16:45:47 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\Identities
[2010.02.11 16:45:46 | 000,000,000 | R--D | C] -- C:\Users\*meinereiner*\Contacts
[2010.02.11 16:45:37 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\VirtualStore
[2010.02.11 16:45:36 | 000,000,000 | --SD | C] -- C:\Users\*meinereiner*\AppData\Roaming\Microsoft
[2010.02.11 16:45:36 | 000,000,000 | R--D | C] -- C:\Users\*meinereiner*\Videos
[2010.02.11 16:45:36 | 000,000,000 | R--D | C] -- C:\Users\*meinereiner*\Saved Games
[2010.02.11 16:45:36 | 000,000,000 | R--D | C] -- C:\Users\*meinereiner*\Pictures
[2010.02.11 16:45:36 | 000,000,000 | R--D | C] -- C:\Users\*meinereiner*\Music
[2010.02.11 16:45:36 | 000,000,000 | R--D | C] -- C:\Users\*meinereiner*\Links
[2010.02.11 16:45:36 | 000,000,000 | R--D | C] -- C:\Users\*meinereiner*\Favorites
[2010.02.11 16:45:36 | 000,000,000 | R--D | C] -- C:\Users\*meinereiner*\Downloads
[2010.02.11 16:45:36 | 000,000,000 | R--D | C] -- C:\Users\*meinereiner*\Documents
[2010.02.11 16:45:36 | 000,000,000 | R--D | C] -- C:\Users\*meinereiner*\Desktop
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\Vorlagen
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\AppData\Local\Verlauf
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\AppData\Local\Temporary Internet Files
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\Startmenü
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\SendTo
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\Recent
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\Netzwerkumgebung
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\Lokale Einstellungen
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\Documents\Eigene Videos
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\Documents\Eigene Musik
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\Eigene Dateien
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\Documents\Eigene Bilder
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\Druckumgebung
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\Cookies
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\AppData\Local\Anwendungsdaten
[2010.02.11 16:45:36 | 000,000,000 | -HSD | C] -- C:\Users\*meinereiner*\Anwendungsdaten
[2010.02.11 16:45:36 | 000,000,000 | -H-D | C] -- C:\Users\*meinereiner*\AppData
[2010.02.11 16:45:36 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\Temp
[2010.02.11 16:45:36 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Local\Microsoft
[2010.02.11 16:45:36 | 000,000,000 | ---D | C] -- C:\Users\*meinereiner*\AppData\Roaming\Media Center Programs
[2010.02.11 16:45:22 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2010.02.11 16:45:22 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2010.02.11 16:45:22 | 000,000,000 | -HSD | C] -- C:\Recovery
[2010.02.11 16:45:22 | 000,000,000 | -HSD | C] -- C:\Programme
[2010.02.11 16:45:22 | 000,000,000 | -HSD | C] -- C:\Programme\Gemeinsame Dateien
[2010.02.11 16:45:22 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2010.02.11 16:45:22 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2010.02.11 16:45:22 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2010.02.11 16:45:22 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2010.02.11 16:45:22 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2010.02.11 16:45:22 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2010.02.11 16:45:22 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2010.02.11 16:37:01 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2010.02.11 16:34:48 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2010.02.11 16:33:58 | 000,000,000 | -HSD | C] -- C:\System Volume Information
========== Files - Modified Within 90 Days ==========
[2010.03.18 17:01:46 | 001,572,864 | -HS- | M] () -- C:\Users\*meinereiner*\NTUSER.DAT
[2010.03.18 16:55:53 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2010.03.18 16:40:58 | 000,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Users\*meinereiner*\Desktop\HJTInstall.exe
[2010.03.18 15:36:15 | 000,014,608 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010.03.18 15:36:15 | 000,014,608 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010.03.18 15:35:46 | 001,472,002 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010.03.18 15:35:46 | 000,643,866 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2010.03.18 15:35:46 | 000,607,190 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010.03.18 15:35:46 | 000,126,394 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2010.03.18 15:35:46 | 000,103,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010.03.18 15:28:52 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.03.18 15:28:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.03.18 15:28:42 | 2389,905,408 | -HS- | M] () -- C:\hiberfil.sys
[2010.03.17 23:52:53 | 001,771,227 | -H-- | M] () -- C:\Users\*meinereiner*\AppData\Local\IconCache.db
[2010.03.17 18:03:40 | 001,339,288 | ---- | M] () -- C:\Users\*meinereiner*\Desktop\sar_15_sfx.exe
[2010.03.17 17:56:30 | 000,556,032 | ---- | M] (OldTimer Tools) -- C:\Users\*meinereiner*\Desktop\OTL.exe
[2010.03.17 17:25:03 | 000,000,979 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.03.16 18:39:00 | 000,002,755 | ---- | M] () -- C:\Users\Public\Desktop\Vodafone Mobile Connect.lnk
[2010.03.15 11:37:41 | 000,000,962 | ---- | M] () -- C:\Users\Public\Desktop\QIP 2005 psYNovA-Edition.lnk
[2010.03.14 14:53:12 | 000,000,653 | ---- | M] () -- C:\Users\*meinereiner*\Documents\TeX-Dokument 1.tex
[2010.03.09 17:54:22 | 000,067,856 | ---- | M] () -- C:\Users\*meinereiner*\AppData\Local\GDIPFONTCACHEV1.DAT
[2010.03.09 17:52:29 | 000,308,704 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010.03.06 17:54:34 | 000,011,009 | ---- | M] () -- C:\Users\*meinereiner*\Documents\kündigung.docx
[2010.03.01 17:59:27 | 000,001,984 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010.02.28 14:24:33 | 000,007,959 | ---- | M] () -- C:\Users\*meinereiner*\Documents\sumi.xml
[2010.02.26 12:58:00 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010.02.24 12:13:35 | 000,000,869 | ---- | M] () -- C:\Users\*meinereiner*\.recently-used.xbel
[2010.02.24 11:35:38 | 000,001,063 | ---- | M] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2010.02.24 10:21:02 | 000,001,003 | ---- | M] () -- C:\Users\Public\Desktop\Notepad++.lnk
[2010.02.24 10:16:06 | 000,181,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010.02.24 08:50:41 | 000,001,885 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010.02.23 19:26:10 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deploytk.dll
[2010.02.23 19:26:10 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010.02.23 19:26:10 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010.02.23 19:26:10 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010.02.15 13:53:23 | 000,000,000 | ---- | M] () -- C:\Users\*meinereiner*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
[2010.02.15 13:33:02 | 000,000,312 | ---- | M] () -- C:\Users\*meinereiner*\Desktop\Curse Client.appref-ms
[2010.02.13 17:53:15 | 000,001,225 | ---- | M] () -- C:\Users\*meinereiner*\Desktop\Launcher.lnk
[2010.02.13 16:49:00 | 009,503,594 | ---- | M] () -- C:\Users\*meinereiner*\Documents\a.wav
[2010.02.13 14:14:04 | 000,008,157 | ---- | M] () -- C:\Users\*meinereiner*\Documents\sumi3.xml
[2010.02.13 12:48:18 | 000,007,926 | ---- | M] () -- C:\Users\*meinereiner*\Documents\sumi2.xml
[2010.02.12 11:07:58 | 000,280,592 | ---- | M] (Kaspersky Lab) -- C:\Windows\System32\drivers\klif.sys
[2010.02.12 11:07:58 | 000,128,016 | ---- | M] (Kaspersky Lab) -- C:\Windows\System32\drivers\kl1.sys
[2010.02.12 11:07:56 | 000,108,059 | ---- | M] () -- C:\Windows\System32\drivers\klin.dat
[2010.02.12 11:07:56 | 000,095,259 | ---- | M] () -- C:\Windows\System32\drivers\klick.dat
[2010.02.12 10:50:25 | 000,001,120 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2010.02.12 10:49:54 | 000,034,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\lhacm.acm
[2010.02.12 10:49:51 | 000,000,948 | ---- | M] () -- C:\Users\*meinereiner*\Desktop\Teamspeak 2 RC2.lnk
[2010.02.12 10:19:44 | 000,000,056 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat
[2010.02.12 10:15:10 | 000,604,140 | -HS- | M] () -- C:\Windows\System32\drivers\ISwift3.dat
[2010.02.12 00:37:56 | 000,002,505 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2010.02.11 21:57:31 | 000,524,288 | -HS- | M] () -- C:\Users\*meinereiner*\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010.02.11 21:57:31 | 000,524,288 | -HS- | M] () -- C:\Users\*meinereiner*\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010.02.11 21:57:31 | 000,065,536 | -HS- | M] () -- C:\Users\*meinereiner*\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010.02.11 16:45:36 | 000,000,020 | -HS- | M] () -- C:\Users\*meinereiner*\ntuser.ini
[2010.02.11 16:39:04 | 000,056,735 | ---- | M] () -- C:\Windows\System32\license.rtf
[2010.02.02 08:45:54 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2010.01.19 00:29:31 | 000,365,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\secproc_isv.dll
[2010.01.19 00:29:31 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp_isv.dll
[2010.01.19 00:29:31 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\secproc_ssp.dll
[2010.01.19 00:29:30 | 000,369,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\secproc.dll
[2010.01.19 00:28:33 | 000,324,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_isv.exe
[2010.01.19 00:28:33 | 000,277,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp_isv.exe
[2010.01.19 00:28:30 | 000,320,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RMActivate.exe
[2010.01.19 00:28:30 | 000,280,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RMActivate_ssp.exe
[2010.01.11 08:12:38 | 000,381,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2010.01.07 16:07:14 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010.01.07 16:07:04 | 000,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009.12.19 10:02:48 | 001,328,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2009.12.19 10:02:42 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2009.12.19 10:02:40 | 000,084,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mciavi32.dll
[2009.12.19 10:02:01 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\avifil32.dll
========== Files Created - No Company Name ==========
[2010.03.18 16:55:53 | 000,065,536 | ---- | C] () -- C:\Windows\System32\Ikeext.etl
[2010.03.17 18:03:20 | 001,339,288 | ---- | C] () -- C:\Users\*meinereiner*\Desktop\sar_15_sfx.exe
[2010.03.17 17:25:03 | 000,000,979 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.03.16 18:39:00 | 000,002,755 | ---- | C] () -- C:\Users\Public\Desktop\Vodafone Mobile Connect.lnk
[2010.03.15 11:37:41 | 000,000,962 | ---- | C] () -- C:\Users\Public\Desktop\QIP 2005 psYNovA-Edition.lnk
[2010.03.14 14:40:31 | 000,000,653 | ---- | C] () -- C:\Users\*meinereiner*\Documents\TeX-Dokument 1.tex
[2010.03.06 16:19:22 | 000,011,009 | ---- | C] () -- C:\Users\*meinereiner*\Documents\kündigung.docx
[2010.02.26 12:58:00 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010.02.24 12:13:35 | 000,000,869 | ---- | C] () -- C:\Users\*meinereiner*\.recently-used.xbel
[2010.02.24 11:35:38 | 000,001,063 | ---- | C] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2010.02.24 10:21:02 | 000,001,003 | ---- | C] () -- C:\Users\Public\Desktop\Notepad++.lnk
[2010.02.24 08:50:41 | 000,001,885 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010.02.15 20:09:18 | 000,001,984 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010.02.15 13:53:23 | 000,000,000 | ---- | C] () -- C:\Users\*meinereiner*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
[2010.02.15 13:33:02 | 000,000,312 | ---- | C] () -- C:\Users\*meinereiner*\Desktop\Curse Client.appref-ms
[2010.02.13 16:45:24 | 009,503,594 | ---- | C] () -- C:\Users\*meinereiner*\Documents\a.wav
[2010.02.13 13:58:29 | 000,008,157 | ---- | C] () -- C:\Users\*meinereiner*\Documents\sumi3.xml
[2010.02.13 12:43:40 | 000,007,926 | ---- | C] () -- C:\Users\*meinereiner*\Documents\sumi2.xml
[2010.02.13 12:21:43 | 000,007,959 | ---- | C] () -- C:\Users\*meinereiner*\Documents\sumi.xml
[2010.02.12 19:46:46 | 000,001,225 | ---- | C] () -- C:\Users\*meinereiner*\Desktop\Launcher.lnk
[2010.02.12 10:50:25 | 000,001,120 | ---- | C] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2010.02.12 10:49:51 | 000,000,948 | ---- | C] () -- C:\Users\*meinereiner*\Desktop\Teamspeak 2 RC2.lnk
[2010.02.12 10:19:44 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.02.12 10:15:10 | 000,604,140 | -HS- | C] () -- C:\Windows\System32\drivers\ISwift3.dat
[2010.02.12 00:37:56 | 000,002,505 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2010.02.12 00:28:24 | 000,108,059 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat
[2010.02.12 00:28:24 | 000,095,259 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat
[2010.02.11 16:45:36 | 001,572,864 | -HS- | C] () -- C:\Users\*meinereiner*\NTUSER.DAT
[2010.02.11 16:45:36 | 000,524,288 | -HS- | C] () -- C:\Users\*meinereiner*\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010.02.11 16:45:36 | 000,524,288 | -HS- | C] () -- C:\Users\*meinereiner*\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010.02.11 16:45:36 | 000,065,536 | -HS- | C] () -- C:\Users\*meinereiner*\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010.02.11 16:45:36 | 000,000,020 | -HS- | C] () -- C:\Users\*meinereiner*\ntuser.ini
[2010.02.11 16:33:58 | 2389,905,408 | -HS- | C] () -- C:\hiberfil.sys
[2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.04.09 13:44:42 | 000,108,066 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
========== LOP Check ==========
[2010.03.15 08:57:36 | 000,000,000 | ---D | M] -- C:\Users\*meinereiner*\AppData\Roaming\ICQ
[2010.02.24 13:12:36 | 000,000,000 | ---D | M] -- C:\Users\*meinereiner*\AppData\Roaming\Notepad++
[2010.02.25 09:52:09 | 000,000,000 | ---D | M] -- C:\Users\*meinereiner*\AppData\Roaming\Pelles C
[2010.03.09 19:13:05 | 000,000,000 | ---D | M] -- C:\Users\*meinereiner*\AppData\Roaming\TS3Client
[2010.02.27 13:11:16 | 000,000,000 | ---D | M] -- C:\Users\*meinereiner*\AppData\Roaming\Vodafone
[2010.03.14 14:33:17 | 000,000,000 | ---D | M] -- C:\Users\*meinereiner*\AppData\Roaming\WinShell
[2009.07.14 05:53:46 | 000,013,732 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >
Extras.txt: