Rapport de ZHPDiag v1.3.5.16 par Nicolas Coolman, Update du 04.02.2013 Run by Isabel at 04.02.2013 15:52:23 State : UAC : Deactivate by program ---\\ Web Browser MSIE: Internet Explorer v9.0.8112.16421 MFIE: Mozilla Firefox 18.0.1 v18.0.1 (Defaut) ---\\ Windows Product Information ~ Langage: Allemand Windows 7 Home Premium Edition, 32-bit Service Pack 1 (Build 7601) Windows Server License Manager Script : OK Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ System Information ~ Processor: x86 Family 6 Model 23 Stepping 10, GenuineIntel ~ Operating System: 32 Bits Boot mode: Normal (Normal boot) Total RAM: 2008 MB (49% free) System Restore: Activé (Enable) System drive C: has 8 GB (7%) free of 109 GB ---\\ Logged in mode ~ Computer Name: ISABEL-PC ~ User Name: Isabel ~ All Users Names: Isabel, HomeGroupUser$, Gast, Administrator, ~ Unselected Option: None Logged in as Administrator ---\\ Environnement Variables ~ System Unit : C:\ ~ %AppData% : C:\Users\Isabel\AppData\Roaming\ ~ %Desktop% : C:\Users\Isabel\Desktop\ ~ %Favorites% : C:\Users\Isabel\Favorites\ ~ %LocalAppData% : C:\Users\Isabel\AppData\Local\ ~ %StartMenu% : C:\Users\Isabel\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ DOS/Devices C:\ Hard drive, Flash drive, Thumb drive (Free 8 Go of 109 Go) D:\ Hard drive, Flash drive, Thumb drive (Free 79 Go of 109 Go) E:\ CD-ROM drive (Not Inserted) ---\\ Security Center & Tools Informations [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ~ Scan Security Center in 00mn 00s ---\\ Search Generic System Files [MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Windows-Explorer.) (.25.02.2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320] [MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Windows-Startanwendung.) (.14.07.2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256] [MD5.7FA3A810F383588D46220967DE8B64FF] - (.Microsoft Corporation - Interneterweiterungen für Win32.) (.14.11.2012 - 02:57:37.) -- C:\Windows\System32\wininet.dll [1129472] [MD5.6D13E1406F50C66E2A95D97F22C47560] - (.Microsoft Corporation - Windows-Anmeldeanwendung.) (.20.11.2010 - 13:17:54.) -- C:\Windows\System32\Winlogon.exe [286720] [MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Softwarelizenzierungsbibliothek.) (.20.11.2010 - 13:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536] [MD5.9EBBBA55060F786F0FCAA3893BFA2806] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.25.04.2011 - 03:18:03.) -- C:\Windows\system32\Drivers\AFD.sys [338944] [MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14.07.2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584] [MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14.07.2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656] [MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20.11.2010 - 09:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544] [MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20.11.2010 - 09:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336] [MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20.11.2010 - 10:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544] [MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - i8042-Anschlusstreiber.) (.14.07.2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896] [MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14.07.2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888] [MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27.04.2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904] [MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20.11.2010 - 09:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904] [MD5.0D87503986BB3DFED58E343FE39DDE13] - (.Microsoft Corporation - NT-Dateisystemtreiber.) (.31.08.2012 - 18:18:09.) -- C:\Windows\system32\Drivers\ntfs.sys [1211760] [MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Treiber für parallelen Anschluss.) (.14.07.2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360] [MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14.07.2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848] [MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14.07.2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168] [MD5.B459575348C20E8121D6039DA063C704] - (.Microsoft Corporation - TDI Translation Driver.) (.20.11.2010 - 09:39:17.) -- C:\Windows\system32\Drivers\tdx.sys [74752] [MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Volumeschattenkopie-Treiber.) (.20.11.2010 - 13:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632] ~ Scan Generic Processes in 00mn 00s ---\\ Hidden files state (Hidden/Total) ~ Mes images (My Pictures) : 1/1897 ~ Mes musiques (My Musics) : 1/12323 ~ Mes Videos (My Videos) : 1/20 ~ Mes Favoris (My Favorites) : 1/21 ~ Mes Documents (My Documents) : 1/149 ~ Mon Bureau (My Desktop) : 1/2459 ~ Menu demarrer (Programs) : 1/54 ~ Scan Hidden Files in 00mn 28s ---\\ Running Processes [MD5.8A0B0E4102C2CCA25DA3134FE12FCC3E] - (.SAMSUNG Electronics - SSCKbdHk.) -- C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe [91136] [PID.2624] [MD5.091A0924AC02AE0A04F3D03BCCDE2712] - (.SEC - Samsung Recovery Solution 4.) -- C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2246144] [PID.2656] [MD5.A46796CCF032D35720347262998D1F90] - (.Samsung Electronics Co., Ltd. - Easy Display Manager.) -- C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [835072] [PID.2680] [MD5.F2F3617C63B87AA2DE139DC9E37420B5] - (.Intel Corporation - igfxext Module.) -- C:\windows\system32\igfxext.exe [179224] [PID.2720] [MD5.B9AA850CDA55097EB13E03698C8F5828] - (.Intel Corporation - igfxsrvc Module.) -- C:\windows\system32\igfxsrvc.exe [266776] [PID.2748] [MD5.E3735DC796E5183D63F35921B058934C] - (.Samsung Electronics Co., Ltd. - EasySpeedUpManager.) -- C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [716800] [PID.2816] [MD5.64F562F206E5474B9E01F8CD944770A6] - (.Realtek Semiconductor - Realtek HD Audio-Manager.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8092192] [PID.3628] [MD5.3EE8375B1063CF4A0C4353123F4129C5] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1578280] [PID.3692] [MD5.54FA8528EDA1B6B34615F4EA3FCB35E6] - (.CyberLink - CyberLink MediaLibray Service.) -- C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [103720] [PID.3716] [MD5.428F4A9D4CB5816030F88F3DD7595675] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.3976] [MD5.28FD28A29C637C9AFEFE0A26E27C6DFE] - (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe [91432] [PID.1280] [MD5.869A67EE7C237DD9F9104854CAE0A9CD] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [141608] [PID.2348] [MD5.1029B84ECBE4B95ACB8491A3FE63D70F] - (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxtray.exe [136216] [PID.1092] [MD5.3CD5BBDA19A1AB4EBA359E0A14FDF0F0] - (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe [171032] [PID.1088] [MD5.3142195521FEE436088EE8A5748DE1B1] - (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe [170520] [PID.1460] [MD5.B77081F8221968C7DAB794B0BA55C43E] - (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [254896] [PID.984] [MD5.083649EF692A066880C9326020915AFE] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe [4297136] [PID.2832] [MD5.8FEDBE7A5D3E5F91FD4B96DAFA4DD197] - (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Isabel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1199576] [PID.3196] [MD5.D7826A7440444F40E0406CF37FD2FA88] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [917400] [PID.4712] [MD5.927DC83A2FB5897DE3DDD54DF604EA00] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [5649408] [PID.5476] ~ Scan Processes Running in 00mn 01s ---\\ Mozilla Firefox, Plugins,Startseite,Seiten of search,Ausdehnung (P2,M0,M1,M2,M3) C:\Users\Isabel\AppData\Roaming\Mozilla\Firefox\Profiles\c3g3k5il.default\prefs.js M3 - MFPP: Plugins - [Isabel] -- C:\Program Files\Mozilla FireFox\searchplugins\amazondotcom-de.xml M3 - MFPP: Plugins - [Isabel] -- C:\Program Files\Mozilla FireFox\searchplugins\bing.xml M3 - MFPP: Plugins - [Isabel] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-de.xml M3 - MFPP: Plugins - [Isabel] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml M3 - MFPP: Plugins - [Isabel] -- C:\Program Files\Mozilla FireFox\searchplugins\leo_ende_de.xml M3 - MFPP: Plugins - [Isabel] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-de.xml M3 - MFPP: Plugins - [Isabel] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-de.xml M0 - MFSP: prefs.js [Isabel - c3g3k5il.default] http://www.google.de M2 - MFEP: prefs.js [Isabel - c3g3k5il.default\de_DE@dicts.j3e.de] [] Wörterbuch Deutsch (de-DE), Hunspell-unterstützt v20130128 (.Björn Jacke.) M2 - MFEP: prefs.js [Isabel - c3g3k5il.default\en-GB@dictionaries.addons.mozilla.org] [] British English Dictionary v1.19.1 (.Björn Jacke.) M2 - MFEP: prefs.js [Isabel - c3g3k5il.default\fr-moderne@dictionaries.addons.mozilla.org] [] Dictionnaire français «Moderne» v4.3 (.Olivier R..) M2 - MFEP: prefs.js [Isabel - c3g3k5il.default\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}] [dwhelper] DownloadHelper v4.9.9 (.Michel Gutierrez.) P2 - FPN:Firefox Plugin Navigator . (.BitComet - BitCometAgent v1.27 for Firefox.) -- C:\Program Files\Mozilla Firefox\Plugins\npBitCometAgent.dll P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFFICE.DLL P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape "9.5.3".) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin2.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin3.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin4.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin5.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin6.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin7.dll P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll P2 - FPN: [HKLM] [@adobe.com/ShockwavePlayer] - (.Adobe Systems, Inc. - Adobe Shockwave for Director Netscape plug-in, version 11.5.9.615.) -- C:\windows\system32\Adobe\Director\np32dsw.dll P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll P2 - FPN: [HKLM] [@java.com/DTPlugin,version=1.6.0_39] - (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\windows\system32\npdeployJava1.dll P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Sun Microsystems, Inc. - Next Generation Java Plug-in 1.6.0_39 for Mozilla browsers.) -- C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.1.10329.0.) -- C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll P2 - FPN: [HKLM] [@microsoft.com/OfficeLive,version=1.5] - (.Microsoft Corp. - Office Live Update v1.5.) -- C:\Program Files\Microsoft\Office Live\npOLW.dll P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=14.0.8081.0709] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape "9.5.3".) -- C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll ~ Scan Firefox Browser in 00mn 00s ---\\ Internet Explorer, Startseite,Seiten of search,Ausdehnung (R0,R1,R3,R4) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Browser.) (9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)) -- C:\Windows\System32\ieframe.dll R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1 ~ Scan IE Browser in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Scan Proxy management in 00mn 00s ---\\ Line Analysis F0, F1, F2, F3 - IniFiles, Auto loading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Scan Keys in 00mn 00s ---\\ Hosts file redirection (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Scan Hosts File in 00mn 07s ~ Nombre de lignes (Lines number): 14806 ---\\ Browser Helper Objects (O2) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} . (.BitComet - BitCometBHO.) -- C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Orphean Key O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - avast! WebRep Plugin.) -- C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll ~ Scan BHO in 00mn 00s ---\\ Internet Explorer toolbars (O3) O3 - Toolbar: avast! WebRep - [HKLM]{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - avast! WebRep Plugin.) -- C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll ~ Scan Toolbar in 00mn 00s ---\\ Auto loading programs from Registry and folders (O4) O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Realtek HD Audio-Manager.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [UpdateLBPShortCut] . (.CyberLink Corp. - MUI StartMenu Application.) -- C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe O4 - HKLM\..\Run: [CLMLServer] . (.CyberLink - CyberLink MediaLibray Service.) -- C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe O4 - HKLM\..\Run: [UpdateP2GoShortCut] . (.CyberLink Corp. - MUI StartMenu Application.) -- C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe O4 - HKLM\..\Run: [UpdatePDRShortCut] . (.CyberLink Corp. - StartMen Application.) -- C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe O4 - HKLM\..\Run: [RemoteControl8] . (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe O4 - HKLM\..\Run: [PDVD8LanguageShortcut] . (.CyberLink Corp. - PowerDVD Language Application.) -- C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe O4 - HKLM\..\Run: [UpdatePPShortCut] . (.CyberLink Corp. - MUI StartMenu Application.) -- C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe O4 - HKLM\..\Run: [UpdatePSTShortCut] . (.CyberLink Corp. - MUI StartMenu Application.) -- C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe O4 - HKLM\..\Run: [APLangApp] . (.DoctorSoft - AnyPC Language Application.) -- C:\Program Files\AnyPC Client\APLangApp.exe O4 - HKLM\..\Run: [UCam_Menu] . (.CyberLink Corp. - MUI StartMenu Application.) -- C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIACE.exe O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\windows\system32\igfxpers.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe O4 - HKLM\..\Run: [avast] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\avastUI.exe O4 - HKCU\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Isabel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Windows-Minianwendungen.) -- C:\Program Files\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Windows-Minianwendungen.) -- C:\Program Files\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-21-1871111397-3539990770-1974983793-1001\..\Run: [Spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Isabel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe ~ Scan Application in 00mn 00s ---\\ Other User Links (O4) O4 - Global Startup: C:\Users\Isabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe O4 - Global Startup: C:\Users\Isabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk . (.Spotify Ltd.) -- C:\Users\Isabel\AppData\Roaming\Spotify\spotify.exe O4 - Global Startup: C:\Users\Isabel\Desktop\AD-R.lnk . (...) -- C:\Program Files\Ad-Remover\main.exe O4 - Global Startup: C:\Users\Isabel\Desktop\CyberLink DVD Suite.lnk . (.CyberLink.) -- C:\Program Files\CyberLink\DVD Suite\PowerStarter.exe O4 - Global Startup: C:\Users\Isabel\Desktop\CyberLink YouCam.lnk . (.CyberLink Corp..) -- C:\Program Files\CyberLink\YouCam\YouCam.exe O4 - Global Startup: C:\Users\Isabel\Desktop\FreeCell - Verknüpfung.lnk - Orphean Key O4 - Global Startup: C:\Users\Isabel\Desktop\Hearts - Verknüpfung.lnk - Orphean Key O4 - Global Startup: C:\Users\Isabel\Desktop\iTunes.lnk . (...) -- C:\windows\Installer\{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}\iTunesIco.exe O4 - Global Startup: C:\Users\Isabel\Desktop\Mahjong Titans - Verknüpfung.lnk - Orphean Key O4 - Global Startup: C:\Users\Isabel\Desktop\Melanie's datas shortcut.lnk . (...) -- D:\Melanie's datas O4 - Global Startup: C:\Users\Isabel\Desktop\Photoshop.lnk . (.Adobe Systems Incorporated.) -- C:\Program Files\Adobe\Photoshop Elements 6.0\Photoshop Elements 6.0.exe O4 - Global Startup: C:\Users\Isabel\Desktop\Solitär - Verknüpfung.lnk - Orphean Key O4 - Global Startup: C:\Users\Isabel\Desktop\Spotify.lnk . (.Spotify Ltd.) -- C:\Users\Isabel\AppData\Roaming\Spotify\spotify.exe O4 - Global Startup: C:\Users\Isabel\Desktop\Spybot - Search & Destroy.lnk . (.Safer Networking Limited.) -- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe O4 - Global Startup: C:\Users\Isabel\Desktop\wmplayer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe O4 - Global Startup: C:\Users\Isabel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe O4 - Global Startup: C:\Users\Isabel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk . (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\firefox.exe O4 - Global Startup: C:\Users\Isabel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk . (.Safer Networking Limited.) -- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe O4 - Global Startup: C:\Users\Administrator\Desktop\CyberLink YouCam.lnk . (.CyberLink Corp..) -- C:\Program Files\CyberLink\YouCam\YouCam.exe ~ Scan Global Startup in 00mn 00s ---\\ IE Options icon not visible in Control Panel (O5) O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no ~ Scan IE Control Panel in 00mn 00s ---\\ Extra buttons on main IE button toolbar, or extra items in IE 'Tools' menu (O9) O9 - Extra button: In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: In Windows Live Writer in Blog veröffentliche&n - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\OFFICE11\REFBARH.ICO O9 - Extra button: In Windows Live Writer in Blog veröffentliche&n - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} . (.BitComet - BitCometBHO.) -- C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll ~ Scan IE Extra Buttons in 00mn 00s ---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\windows\system32\NLAapi.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - E-Mail-Namenshimanbieter.) -- C:\windows\system32\napinsp.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - PNRP-Namespaceanbieter.) -- C:\windows\system32\pnrpnsp.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - PNRP-Namespaceanbieter.) -- C:\windows\system32\pnrpnsp.dll O10 - WLSP:\000000000005\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - Microsoft Windows Sockets 2.0-Dienstanbieter.) -- C:\windows\system32\mswsock.dll O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\windows\system32\winrnr.dll ~ Scan Winsock in 00mn 00s ---\\ Lop.com/Domain Hijackers (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{6895A045-C7E3-4F9D-9AD9-242EEDEE6385}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{95DE52F9-5E06-47C9-BE22-4B7FE2603F77}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{6895A045-C7E3-4F9D-9AD9-242EEDEE6385}: DhcpDomain = localdomain O17 - HKLM\System\CCS\Services\Tcpip\..\{95DE52F9-5E06-47C9-BE22-4B7FE2603F77}: DhcpDomain = localdomain O17 - HKLM\System\CS1\Services\Tcpip\..\{6895A045-C7E3-4F9D-9AD9-242EEDEE6385}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{95DE52F9-5E06-47C9-BE22-4B7FE2603F77}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{6895A045-C7E3-4F9D-9AD9-242EEDEE6385}: DhcpDomain = localdomain O17 - HKLM\System\CS1\Services\Tcpip\..\{95DE52F9-5E06-47C9-BE22-4B7FE2603F77}: DhcpDomain = localdomain O17 - HKLM\System\CS2\Services\Tcpip\..\{6895A045-C7E3-4F9D-9AD9-242EEDEE6385}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{95DE52F9-5E06-47C9-BE22-4B7FE2603F77}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{6895A045-C7E3-4F9D-9AD9-242EEDEE6385}: DhcpDomain = localdomain O17 - HKLM\System\CS2\Services\Tcpip\..\{95DE52F9-5E06-47C9-BE22-4B7FE2603F77}: DhcpDomain = localdomain ~ Scan Domain in 00mn 00s ---\\ Extra protocols (O18) O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML-Anzeige.) -- C:\Windows\System32\mshtml.dll O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32-Erweiterung für Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX-Steuerung für Streamingvideo.) -- C:\Windows\System32\msvidctl.dll O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32-Erweiterung für Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32-Erweiterung für Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32-Erweiterung für Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32-Erweiterung für Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML-Anzeige.) -- C:\Windows\System32\mshtml.dll O18 - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32-Erweiterung für Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML-Anzeige.) -- C:\Windows\System32\mshtml.dll O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\system32\inetcomm.dll O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32-Erweiterung für Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll O18 - Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll O18 - Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll O18 - Handler: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} . (.Microsoft Corporation - Microsoft Office XP Web Components.) -- C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.dll O18 - Handler: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} . (.Microsoft Corporation - Microsoft Office Web Components 2003.) -- C:\Program Files\Common Files\microsoft shared\Web Components\11\OWC11.dll O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML-Anzeige.) -- C:\Windows\System32\mshtml.dll O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX-Steuerung für Streamingvideo.) -- C:\Windows\System32\msvidctl.dll O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML-Anzeige.) -- C:\Windows\System32\mshtml.dll O18 - Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files\Windows Live\Mail\mailcomm.dll O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.dll ~ Scan Protocole Additionnel in 00mn 00s ---\\ AppInit_DLLs Registry value Autorun (O20) O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll ~ Scan Winlogon in 00mn 00s ---\\ ShellServiceObjectDelayLoad (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. ~ Scan SSODL in 00mn 00s ---\\ non Microsoft non disabled Windows XP/NT/2000 Services (O23) O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - Apple Mobile Device Service.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: avast! Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe O23 - Service: Dienst "Bonjour" (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Google Update Service (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Oberon Media Game Console service (OberonGameConsoleService) . (.Unknown owner - OberonGameConsoleService.) - C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) . (.Unknown owner - RichVideo Module.) - C:\Program Files\CyberLink\Shared files\RichVideo.exe ~ Scan Services in 00mn 06s ---\\ Windows Active Desktop Components & MHTML Editor (O24) O24 - Default MHTML Editor: Last - .(...) - (.not file.) ~ Scan Desktop Component in 00mn 00s ---\\ BootExecute (O34) O34 - HKLM BootExecute: (autocheck autochk *) - File not found ~ Scan Keys in 00mn 00s ---\\ Einträge in Windows' Aufgabenplaner(039) O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Adobe Flash Player Updater.job O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [MD5.424877CB9D5517F980FF7BACA2EB379D] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [MD5.091A0924AC02AE0A04F3D03BCCDE2712] [APT] [advSRS4] (.SEC.) -- C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [MD5.081DBA7C93F21B61DF1C5CE9E8AD0522] [APT] [APSchedulerC] (.DoctorSoft.) -- C:\Program Files\AnyPC Client\APLanMgrC.exe [MD5.7F19838AC317C34FCED020BE529AF71E] [APT] [avast! Emergency Update] (.AVAST Software.) -- C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe [MD5.21E26DC6538C0C255467312559BEB107] [APT] [BatteryLifeExtender] (.Samsung Electronics. Co. Ltd..) -- C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [MD5.A46796CCF032D35720347262998D1F90] [APT] [EasyDisplayMgr] (.Samsung Electronics Co., Ltd..) -- C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [MD5.62DA2C201BC09A55C97C46F0AD73C28A] [APT] [{04023CEA-09C5-4449-BAD0-9FCBA3EBD7B6}] (...) -- C:\Program Files\Samsung Casual Games\Dairy Dash\Uninstall.exe [MD5.62DA2C201BC09A55C97C46F0AD73C28A] [APT] [{1AA288C4-00AE-4840-A7DC-0A6C7B29AE50}] (...) -- C:\Program Files\Samsung Casual Games\Farm Frenzy 2\Uninstall.exe [MD5.00000000000000000000000000000000] [APT] [{8A10D049-EE9E-4DC5-94D8-40C16934CD56}] (...) -- C:\Users\Isabel\Desktop\Neuer Ordner\epson324796eu.exe (.not file.) ~ Scan Scheduled Task in 00mn 04s ---\\ Installierte Komponenten (ActiveSetup Installed Components) (O40) O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player-Ressourcen.) -- C:\Windows\System32\wmploc.dll O40 - ASIC: Internet Explorer - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - IE-Hilfsprogramm für Pro-Benutzerinitalisierung.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: Browser Customizations - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} . (.Microsoft Corporation - IEAK-Branding.) -- C:\Windows\System32\iedkcs32.dll O40 - ASIC: Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\regutils.dll O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - Windows-Design-API.) -- C:\Windows\System32\themeui.dll O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Microsoft Internet Explorer FTP-Ordnershellerweiterung.) -- C:\Windows\System32\msieftp.dll O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Windows Media Player-Ressourcen.) -- C:\Windows\System32\wmploc.dll O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - Allgemeine Windows-Shell-DLL.) -- C:\Windows\System32\shell32.dll O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - IE-Hilfsprogramm für Pro-Benutzerinitalisierung.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11CF-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 9.0 r124.) -- C:\windows\system32\Macromed\Flash\Flash9f.ocx ~ Scan Active Setup in 00mn 00s ---\\ Automatisch gestartete Treiber und Dienste (O41) O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys O41 - Driver: (aswRdr) . (.AVAST Software - avast! WFP Redirect Driver.) - C:\Windows\system32\Drivers\aswrdr2.sys O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\drivers\cdrom.sys O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - QoS-Paketplaner.) - C:\Windows\System32\DRIVERS\pacer.sys O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Subsystemtreiber für Pufferung des umgeleit.) - C:\Windows\System32\DRIVERS\rdbss.sys O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys O41 - Driver: (SABI) . (.SAMSUNG ELECTRONICS - SAMSUNG Kernel Driver.) - C:\windows\system32\Drivers\SABI.sys O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys ~ Scan Drivers in 00mn 00s ---\\ Installierte Programme (O42) O42 - Logiciel: Adobe Flash Player 11 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin O42 - Logiciel: Adobe Flash Player ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Photoshop Elements 6.0 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Photoshop Elements 6 O42 - Logiciel: Adobe Reader 9.5.3 - Deutsch - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1031-7B44-A95000000001} O42 - Logiciel: Adobe Shockwave Player 11.5 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Shockwave Player O42 - Logiciel: Amazon MP3 Downloader 1.0.9 - (.Unknown owner.) [HKLM] -- Amazon MP3 Downloader O42 - Logiciel: Amazon MP3-Downloader 1.0.9 - (.Unknown owner.) [HKLM] -- Amazon MP3-Downloader O42 - Logiciel: AnyPC Client - (.Doctorsoft.) [HKLM] -- {1AFA1FEF-8CF9-4A51-AC46-64FAA7F3D9E2} O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {B2D328BE-45AD-4D92-96F9-2151490A203E} O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {85991ED2-010C-4930-96FA-52F43C2CE98A} O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {C41300B9-185D-475E-BFEC-39EF732F19B1} O42 - Logiciel: Archiveur WinRAR - (.Unknown owner.) [HKLM] -- WinRAR archiver O42 - Logiciel: Atheros Client Installation Program - (.Atheros.) [HKLM] -- {D1434266-0486-4469-B338-A60082CC04E1} O42 - Logiciel: BatteryLifeExtender - (.Samsung.) [HKLM] -- {853F8A41-A3C9-43FA-87FA-1AE74FC6F3F7} O42 - Logiciel: BitComet 1.29 - (.CometNetwork.) [HKLM] -- BitComet O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {0CB9668D-F979-4F31-B8B8-67FE90F929F8} O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner O42 - Logiciel: Compatibility Pack für 2007 Office System - (.Microsoft Corporation.) [HKLM] -- {90120000-0020-0407-0000-0000000FF1CE} O42 - Logiciel: CyberLink DVD Suite - (.CyberLink Corp..) [HKLM] -- InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79} O42 - Logiciel: CyberLink DVD Suite - (.CyberLink Corp..) [HKLM] -- {1FBF6C24-C1FD-4101-A42B-0C564F9E8E79} O42 - Logiciel: CyberLink LabelPrint - (.CyberLink Corp..) [HKLM] -- InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243} O42 - Logiciel: CyberLink LabelPrint - (.CyberLink Corp..) [HKLM] -- {C59C179C-668D-49A9-B6EA-0121CCFC1243} O42 - Logiciel: CyberLink Power2Go - (.CyberLink Corp..) [HKLM] -- InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658} O42 - Logiciel: CyberLink Power2Go - (.CyberLink Corp..) [HKLM] -- {40BF1E83-20EB-11D8-97C5-0009C5020658} O42 - Logiciel: CyberLink PowerDVD 8 - (.CyberLink Corp..) [HKLM] -- InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47} O42 - Logiciel: CyberLink PowerDVD 8 - (.CyberLink Corp..) [HKLM] -- {2BF2E31F-B8BB-40A7-B650-98D28E0F7D47} O42 - Logiciel: CyberLink PowerDirector - (.CyberLink Corp..) [HKLM] -- InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1} O42 - Logiciel: CyberLink PowerDirector - (.CyberLink Corp..) [HKLM] -- {CB099890-1D5F-11D5-9EA9-0050BAE317E1} O42 - Logiciel: CyberLink PowerProducer - (.CyberLink Corp..) [HKLM] -- InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861} O42 - Logiciel: CyberLink PowerProducer - (.CyberLink Corp..) [HKLM] -- {B7A0CE06-068E-11D6-97FD-0050BACBF861} O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM] -- InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D} O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM] -- {01FB4998-33C4-4431-85ED-079E3EEFE75D} O42 - Logiciel: EPSON Logiciel imprimante - (.Unknown owner.) [HKLM] -- EPSON Printer and Utilities O42 - Logiciel: Easy Display Manager - (.Samsung Electronics Co., Ltd..) [HKLM] -- {17283B95-21A8-4996-97DA-547A48DB266F} O42 - Logiciel: Easy Network Manager - (.Samsung.) [HKLM] -- {A5675A9E-F073-414A-9A04-F9BCD50459D7} O42 - Logiciel: Easy SpeedUp Manager - (.Samsung Electronics Co.,Ltd..) [HKLM] -- {EF367AA4-070B-493C-9575-85BE59D789C9} O42 - Logiciel: EasyBatteryManager - (.Samsung.) [HKLM] -- {178EE5F4-0F86-4BF0-A0D1-9790AFF409D1} O42 - Logiciel: Freemake Video Converter version 1.2.0 - (.Ellora Assets Corporation.) [HKLM] -- Freemake Video Converter_is1 O42 - Logiciel: Game Pack - (.Oberon Media, Inc..) [HKLM] -- {63eafc52-b963-4297-a7eb-d412944e7065}_is1 O42 - Logiciel: Google Earth Plug-in - (.Google.) [HKLM] -- {2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E} O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- HDMI O42 - Logiciel: Intel® Matrix Storage Manager - (.Intel Corporation.) [HKLM] -- {9068B2BE-D93A-4C0A-861C-5E35E2C0E09E} O42 - Logiciel: Java(TM) 6 Update 39 - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216033FF} O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {E2DFE069-083E-4631-9B6C-43C48E991DE5} O42 - Logiciel: MOVAVI VideoSuite 3.4 - (.MOVAVI.) [HKLM] -- MOVAVI VideoSuite 3.4 O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94} O42 - Logiciel: Marvell Miniport Driver - (.Marvell.) [HKLM] -- Marvell Miniport Driver O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570} O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} O42 - Logiciel: Microsoft Works - (.Microsoft Corporation.) [HKLM] -- {39D0E034-1042-4905-BECB-5502909FCB7C} O42 - Logiciel: Mozilla Firefox 18.0.1 (x86 de) - (.Mozilla.) [HKLM] -- Mozilla Firefox 18.0.1 (x86 de) O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {3D9892BB-A751-4E48-ADC8-E4289956CE1D} O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} O42 - Logiciel: Samsung Recovery Solution 4 - (.Samsung.) [HKLM] -- {145DE957-0679-4A2A-BB5C-1D3E9808FAB2} O42 - Logiciel: Samsung Support Center - (.Samsung.) [HKLM] -- {CCC2B140-B47A-45FA-AAE3-BD60DA41AE00} O42 - Logiciel: Samsung Update Plus - (.Samsung Electronics Co., Ltd..) [HKLM] -- {D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5} O42 - Logiciel: Spelling Dictionaries Support For Adobe Reader 9 - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-5464-3428-900000000004} O42 - Logiciel: Spotify - (.Spotify AB.) [HKCU] -- Spotify O42 - Logiciel: Spybot - Search & Destroy - (.Safer Networking Limited.) [HKLM] -- {B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey O42 - Logiciel: User Guide - (.Unknown owner.) [HKLM] -- {BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA} O42 - Logiciel: VLC media player 1.1.4 - (.VideoLAN.) [HKLM] -- VLC media player O42 - Logiciel: avast! Free Antivirus v7.0.1474.0 - (.AVAST Software.) [HKLM] -- avast O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {91F7F3F3-CE80-48C3-8327-7D24A0A5716A} O42 - Logiciel: vShare.tv plugin 1.3 - (.vShare.tv, Inc..) [HKLM] -- vShare.tv plugin ---\\ HKCU & HKLM Software Keys [HKCU\Software\ALWIL Software] [HKCU\Software\ASProtect] [HKCU\Software\AVAST Software] [HKCU\Software\Ad-Remover] [HKCU\Software\Adobe] [HKCU\Software\AppDataLow\Software\Google] [HKCU\Software\AppDataLow\Software\Microsoft] [HKCU\Software\AppDataLow\Software\Simplytech] [HKCU\Software\AppDataLow\Software] [HKCU\Software\AppDataLow] [HKCU\Software\Apple Computer, Inc.] [HKCU\Software\Apple Inc.] [HKCU\Software\BitComet] [HKCU\Software\BrowserTemp] [HKCU\Software\CDDB] [HKCU\Software\Classes] [HKCU\Software\Clients] [HKCU\Software\CyberLink] [HKCU\Software\DivXNetworks] [HKCU\Software\EPSON] [HKCU\Software\Freemake] [HKCU\Software\GNU] [HKCU\Software\Gabest] [HKCU\Software\Google] [HKCU\Software\Intel] [HKCU\Software\JavaSoft] [HKCU\Software\Lake] [HKCU\Software\MOVAVI] [HKCU\Software\Macromedia] [HKCU\Software\MozillaPlugins] [HKCU\Software\Mozilla] [HKCU\Software\Netscape] [HKCU\Software\Northcode Inc] [HKCU\Software\ODBC] [HKCU\Software\Oberon Media] [HKCU\Software\Opendisc] [HKCU\Software\Piriform] [HKCU\Software\Policies] [HKCU\Software\Realtek] [HKCU\Software\Safer Networking Limited] [HKCU\Software\Samsung] [HKCU\Software\Synaptics] [HKCU\Software\Trolltech] [HKCU\Software\VB and VBA Program Settings] [HKCU\Software\WinRAR SFX] [HKCU\Software\WinRAR] [HKCU\Software\YahooPartnerToolbar] [HKCU\Software\ZebHelpProcess Helper] [HKCU\Software\vShare.tv] [HKLM\Software\ALWIL Software] [HKLM\Software\ASK] [HKLM\Software\ATI Technologies] [HKLM\Software\AVAST Software] [HKLM\Software\Adobe] [HKLM\Software\AdwCleaner] [HKLM\Software\Amazon] [HKLM\Software\America Online] [HKLM\Software\AppDataLow] [HKLM\Software\Apple Computer, Inc.] [HKLM\Software\Apple Inc.] [HKLM\Software\Atheros] [HKLM\Software\CHECKINSTALLER] [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\CyberLink] [HKLM\Software\DivXNetworks] [HKLM\Software\DivX] [HKLM\Software\DownloadHelper] [HKLM\Software\Dr.Soft] [HKLM\Software\EPSON] [HKLM\Software\GEAR Software] [HKLM\Software\GNU] [HKLM\Software\Google] [HKLM\Software\InstalledOptions] [HKLM\Software\Intel] [HKLM\Software\JavaSoft] [HKLM\Software\JreMetrics] [HKLM\Software\Lake] [HKLM\Software\Loader] [HKLM\Software\Macromedia] [HKLM\Software\Macrovision] [HKLM\Software\Marvell] [HKLM\Software\McAfeeInstaller] [HKLM\Software\McAfee] [HKLM\Software\MozillaPlugins] [HKLM\Software\Mozilla] [HKLM\Software\ODBC] [HKLM\Software\Oberon Media] [HKLM\Software\Phoenix Technologies] [HKLM\Software\Piriform] [HKLM\Software\Policies] [HKLM\Software\Realtek Semiconductor Corp.] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\SRS Labs] [HKLM\Software\Safer Networking Limited] [HKLM\Software\Samsung Electronics Co., Ltd.] [HKLM\Software\Samsung] [HKLM\Software\SiteAdvisor] [HKLM\Software\Sonic] [HKLM\Software\Synaptics] [HKLM\Software\VideoLAN] [HKLM\Software\Volatile] [HKLM\Software\Waves Audio] [HKLM\Software\WinRAR] [HKLM\Software\Windows] [HKLM\Software\Wow6432Node] [HKLM\Software\Yahoo] [HKLM\Software\dotNetInstaller] [HKLM\Software\illiminable] [HKLM\Software\intellidownload] [HKLM\Software\mozilla.org] ~ Scan Softwares in 00mn 00s ---\\ Inhalte der gemeinsamen Dateien (O43) O43 - CFD: 04.02.2013 - 15:34:16 - [120,143] ----D C:\Program Files\Ad-Remover O43 - CFD: 22.10.2012 - 09:44:30 - [527,343] ----D C:\Program Files\Adobe O43 - CFD: 30.07.2010 - 11:57:02 - [292,852] ----D C:\Program Files\Alwil Software O43 - CFD: 26.05.2011 - 14:46:59 - [2,539] ----D C:\Program Files\Amazon O43 - CFD: 05.12.2009 - 03:52:42 - [35,541] ----D C:\Program Files\AnyPC Client O43 - CFD: 29.07.2010 - 18:46:08 - [2,200] ----D C:\Program Files\Apple Software Update O43 - CFD: 26.08.2010 - 13:25:25 - [0,001] ----D C:\Program Files\Atheros Client Installation Program O43 - CFD: 09.08.2010 - 21:34:11 - [26,917] ----D C:\Program Files\BitComet O43 - CFD: 29.07.2010 - 18:45:52 - [0,589] ----D C:\Program Files\Bonjour O43 - CFD: 08.01.2011 - 19:06:08 - [3,351] ----D C:\Program Files\CCleaner O43 - CFD: 04.02.2013 - 15:21:52 - [547,561] ----D C:\Program Files\Common Files O43 - CFD: 28.07.2010 - 20:26:17 - [1132,841] ----D C:\Program Files\CyberLink O43 - CFD: 16.06.2011 - 11:35:39 - [79,371] ----D C:\Program Files\DVD Maker O43 - CFD: 13.10.2010 - 22:39:42 - [0,020] ----D C:\Program Files\EPSON O43 - CFD: 25.10.2010 - 12:14:23 - [33,161] ----D C:\Program Files\Freemake O43 - CFD: 04.02.2013 - 11:48:15 - [76,523] ----D C:\Program Files\Google O43 - CFD: 26.08.2010 - 13:25:25 - [88,041] --H-D C:\Program Files\InstallShield Installation Information O43 - CFD: 05.12.2009 - 03:37:48 - [4,833] ----D C:\Program Files\Intel O43 - CFD: 12.12.2012 - 20:21:43 - [6,460] ----D C:\Program Files\Internet Explorer O43 - CFD: 29.07.2010 - 18:47:36 - [1,504] ----D C:\Program Files\iPod O43 - CFD: 29.07.2010 - 18:48:06 - [121,964] ----D C:\Program Files\iTunes O43 - CFD: 03.02.2013 - 15:15:47 - [84,737] ----D C:\Program Files\Java O43 - CFD: 05.12.2009 - 03:42:25 - [2,983] ----D C:\Program Files\Marvell O43 - CFD: 22.10.2012 - 09:49:35 - [0,717] ----D C:\Program Files\Microsoft O43 - CFD: 05.12.2009 - 21:11:15 - [140,959] ----D C:\Program Files\Microsoft Games O43 - CFD: 09.01.2012 - 06:23:08 - [424,498] ----D C:\Program Files\Microsoft Office O43 - CFD: 10.05.2012 - 12:47:55 - [36,641] ----D C:\Program Files\Microsoft Silverlight O43 - CFD: 28.07.2010 - 20:23:40 - [1,745] ----D C:\Program Files\Microsoft SQL Server Compact Edition O43 - CFD: 11.10.2012 - 00:31:41 - [135,025] ----D C:\Program Files\Microsoft Works O43 - CFD: 25.10.2010 - 12:16:59 - [0,324] ----D C:\Program Files\Microsoft.NET O43 - CFD: 08.12.2010 - 08:33:27 - [24,786] ----D C:\Program Files\MOVAVI O43 - CFD: 08.12.2010 - 08:33:27 - [22,286] ----D C:\Program Files\MOVAVI VideoSuite 3.4 O43 - CFD: 08.12.2010 - 09:19:58 - [8,904] ----D C:\Program Files\Movie Maker 2.6 O43 - CFD: 03.02.2013 - 21:54:09 - [45,422] ----D C:\Program Files\Mozilla Firefox O43 - CFD: 04.02.2013 - 11:14:23 - [0,212] ----D C:\Program Files\Mozilla Maintenance Service O43 - CFD: 04.11.2012 - 22:11:57 - [0] ----D C:\Program Files\MpcStar O43 - CFD: 14.07.2009 - 05:52:30 - [0,025] ----D C:\Program Files\MSBuild O43 - CFD: 09.08.2010 - 21:07:14 - [12,568] ----D C:\Program Files\ORKTOOLS O43 - CFD: 05.12.2009 - 04:02:23 - [2,275] ----D C:\Program Files\Phoenix Technologies Ltd O43 - CFD: 29.07.2010 - 18:46:53 - [72,850] ----D C:\Program Files\QuickTime O43 - CFD: 05.12.2009 - 03:41:46 - [14,939] ----D C:\Program Files\Realtek O43 - CFD: 14.07.2009 - 05:52:30 - [37,308] ----D C:\Program Files\Reference Assemblies O43 - CFD: 05.12.2009 - 03:55:36 - [378,157] ----D C:\Program Files\Samsung O43 - CFD: 03.02.2013 - 14:56:30 - [56,621] ----D C:\Program Files\Samsung Casual Games O43 - CFD: 24.01.2011 - 10:55:01 - [60,978] ----D C:\Program Files\Spybot - Search & Destroy O43 - CFD: 05.12.2009 - 03:44:22 - [26,222] ----D C:\Program Files\Synaptics O43 - CFD: 05.12.2009 - 03:42:22 - [0] --H-D C:\Program Files\Temp O43 - CFD: 14.07.2009 - 05:53:23 - [0] --H-D C:\Program Files\Uninstall Information O43 - CFD: 24.10.2010 - 18:17:12 - [75,227] ----D C:\Program Files\VideoLAN O43 - CFD: 16.06.2011 - 11:35:37 - [2,905] ----D C:\Program Files\Windows Defender O43 - CFD: 10.05.2012 - 13:42:03 - [6,689] ----D C:\Program Files\Windows Journal O43 - CFD: 28.07.2010 - 20:25:00 - [154,736] ----D C:\Program Files\Windows Live O43 - CFD: 28.07.2010 - 20:22:41 - [0,234] ----D C:\Program Files\Windows Live SkyDrive O43 - CFD: 16.06.2011 - 11:35:39 - [5,887] ----D C:\Program Files\Windows Mail O43 - CFD: 16.06.2011 - 11:35:39 - [6,297] ----D C:\Program Files\Windows Media Player O43 - CFD: 14.07.2009 - 05:52:30 - [11,632] ----D C:\Program Files\Windows NT O43 - CFD: 16.06.2011 - 11:35:39 - [4,212] ----D C:\Program Files\Windows Photo Viewer O43 - CFD: 16.06.2011 - 11:35:39 - [0,181] ----D C:\Program Files\Windows Portable Devices O43 - CFD: 16.06.2011 - 11:35:39 - [10,630] ----D C:\Program Files\Windows Sidebar O43 - CFD: 15.03.2011 - 12:00:17 - [2,859] ----D C:\Program Files\WinRAR O43 - CFD: 04.02.2013 - 15:53:02 - [11,849] ----D C:\Program Files\ZHPDiag O43 - CFD: 24.10.2012 - 15:51:43 - [50,056] ----D C:\Program Files\Common Files\Adobe O43 - CFD: 29.07.2010 - 18:47:36 - [96,551] ----D C:\Program Files\Common Files\Apple O43 - CFD: 05.12.2009 - 03:50:50 - [0,109] ----D C:\Program Files\Common Files\CyberLink O43 - CFD: 09.08.2010 - 20:55:24 - [0,082] ----D C:\Program Files\Common Files\DESIGNER O43 - CFD: 05.12.2009 - 03:41:43 - [5,102] ----D C:\Program Files\Common Files\InstallShield O43 - CFD: 22.10.2012 - 09:47:55 - [1,202] ----D C:\Program Files\Common Files\Java O43 - CFD: 11.08.2010 - 16:40:48 - [0,625] ----D C:\Program Files\Common Files\Macrovision Shared O43 - CFD: 27.09.2011 - 23:24:31 - [319,920] ----D C:\Program Files\Common Files\microsoft shared O43 - CFD: 03.12.2010 - 22:23:58 - [0,438] ----D C:\Program Files\Common Files\PX Storage Engine O43 - CFD: 05.12.2009 - 03:55:16 - [4,403] ----D C:\Program Files\Common Files\Samsung O43 - CFD: 14.07.2009 - 03:37:05 - [0,003] ----D C:\Program Files\Common Files\Services O43 - CFD: 14.07.2009 - 03:37:05 - [39,200] ----D C:\Program Files\Common Files\SpeechEngines O43 - CFD: 28.07.2010 - 21:03:54 - [0] ----D C:\Program Files\Common Files\SWF Studio O43 - CFD: 10.11.2011 - 06:29:27 - [29,870] ----D C:\Program Files\Common Files\System O43 - CFD: 28.07.2010 - 20:21:20 - [0] ----D C:\Program Files\Common Files\Windows Live O43 - CFD: 17.01.2013 - 14:12:04 - [506,899] ----D C:\ProgramData\Adobe O43 - CFD: 30.07.2010 - 11:57:02 - [37,471] ----D C:\ProgramData\Alwil Software O43 - CFD: 28.07.2010 - 20:07:17 - [40,412] ----D C:\ProgramData\Apple O43 - CFD: 29.07.2010 - 18:47:35 - [82,342] ----D C:\ProgramData\Apple Computer O43 - CFD: 14.07.2009 - 05:53:55 - [0] --H-D C:\ProgramData\Application Data O43 - CFD: 03.02.2013 - 14:56:30 - [4,927] ----D C:\ProgramData\Browser Manager O43 - CFD: 28.07.2010 - 21:08:31 - [0,079] ----D C:\ProgramData\CyberLink O43 - CFD: 14.07.2009 - 05:53:55 - [0] --H-D C:\ProgramData\Desktop O43 - CFD: 03.12.2010 - 22:24:01 - [0,586] ----D C:\ProgramData\DivX O43 - CFD: 14.07.2009 - 05:53:55 - [0] --H-D C:\ProgramData\Documents O43 - CFD: 13.10.2010 - 22:38:39 - [0,070] ----D C:\ProgramData\EPSON O43 - CFD: 14.07.2009 - 05:53:55 - [0] --H-D C:\ProgramData\Favorites O43 - CFD: 03.02.2013 - 14:56:30 - [0,001] ----D C:\ProgramData\FLEXnet O43 - CFD: 30.07.2010 - 10:59:30 - [0,006] ----D C:\ProgramData\McAfee O43 - CFD: 25.09.2011 - 11:38:11 - [408,989] -S--D C:\ProgramData\Microsoft O43 - CFD: 09.08.2010 - 20:45:01 - [0,054] ----D C:\ProgramData\Microsoft Help O43 - CFD: 03.05.2012 - 22:38:30 - [0,034] ----D C:\ProgramData\Mozilla O43 - CFD: 29.07.2010 - 05:34:43 - [0] ----D C:\ProgramData\NOS O43 - CFD: 05.12.2009 - 04:18:15 - [0,517] ----D C:\ProgramData\SAMSUNG O43 - CFD: 05.12.2009 - 04:01:28 - [0,000] ----D C:\ProgramData\SiteAdvisor O43 - CFD: 03.03.2012 - 10:51:15 - [47,779] ----D C:\ProgramData\Spybot - Search & Destroy O43 - CFD: 14.07.2009 - 05:53:55 - [0] --H-D C:\ProgramData\Start Menu O43 - CFD: 01.08.2010 - 20:03:28 - [0,000] ----D C:\ProgramData\Sun O43 - CFD: 14.01.2013 - 01:15:21 - [0,344] ---AD C:\ProgramData\Temp O43 - CFD: 14.07.2009 - 05:53:55 - [0] --H-D C:\ProgramData\Templates O43 - CFD: 03.02.2013 - 14:56:31 - [16,668] ----D C:\ProgramData\WinClon O43 - CFD: 29.07.2010 - 18:48:06 - [0,517] ----D C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521} O43 - CFD: 28.07.2010 - 21:04:54 - [0] -SH-D C:\Users\Isabel\AppData\Roaming\.# O43 - CFD: 22.08.2010 - 17:06:21 - [11,768] ----D C:\Users\Isabel\AppData\Roaming\Adobe O43 - CFD: 26.05.2011 - 14:47:14 - [0,010] ----D C:\Users\Isabel\AppData\Roaming\Amazon O43 - CFD: 05.02.2012 - 12:21:10 - [0,417] ----D C:\Users\Isabel\AppData\Roaming\Apple Computer O43 - CFD: 21.08.2012 - 02:51:47 - [3,833] ----D C:\Users\Isabel\AppData\Roaming\BitComet O43 - CFD: 20.08.2012 - 14:48:37 - [0,475] ----D C:\Users\Isabel\AppData\Roaming\CometPlayer O43 - CFD: 29.07.2010 - 09:54:15 - [0,533] ----D C:\Users\Isabel\AppData\Roaming\CyberLink O43 - CFD: 18.11.2010 - 19:50:46 - [0,154] ----D C:\Users\Isabel\AppData\Roaming\DivX O43 - CFD: 28.07.2010 - 21:04:31 - [0,015] ----D C:\Users\Isabel\AppData\Roaming\GameConsole O43 - CFD: 14.01.2013 - 01:01:06 - [0,001] ----D C:\Users\Isabel\AppData\Roaming\Go Go Gourmet O43 - CFD: 28.07.2010 - 20:58:04 - [0] ----D C:\Users\Isabel\AppData\Roaming\Google O43 - CFD: 28.07.2010 - 20:27:39 - [0] ----D C:\Users\Isabel\AppData\Roaming\Identities O43 - CFD: 28.07.2010 - 19:04:49 - [0,112] ----D C:\Users\Isabel\AppData\Roaming\Macromedia O43 - CFD: 05.12.2009 - 21:11:14 - [0] ----D C:\Users\Isabel\AppData\Roaming\Media Center Programs O43 - CFD: 20.12.2012 - 14:21:51 - [4,907] -S--D C:\Users\Isabel\AppData\Roaming\Microsoft O43 - CFD: 28.07.2010 - 15:31:43 - [205,811] ----D C:\Users\Isabel\AppData\Roaming\Mozilla O43 - CFD: 26.01.2013 - 11:26:36 - [49,806] ----D C:\Users\Isabel\AppData\Roaming\Spotify O43 - CFD: 20.08.2012 - 14:48:05 - [0,272] ----D C:\Users\Isabel\AppData\Roaming\tigerplayer O43 - CFD: 05.11.2012 - 12:21:22 - [1,372] ----D C:\Users\Isabel\AppData\Roaming\vlc O43 - CFD: 06.08.2010 - 17:18:42 - [0,000] ----D C:\Users\Isabel\AppData\Roaming\WinRAR O43 - CFD: 24.10.2012 - 15:51:21 - [3,179] ----D C:\Users\Isabel\AppData\Local\Adobe O43 - CFD: 28.07.2010 - 20:07:59 - [0] ----D C:\Users\Isabel\AppData\Local\Anwendungsdaten O43 - CFD: 28.07.2010 - 20:07:19 - [0] ----D C:\Users\Isabel\AppData\Local\Apple O43 - CFD: 29.07.2010 - 22:04:30 - [14,089] ----D C:\Users\Isabel\AppData\Local\Apple Computer O43 - CFD: 03.02.2013 - 12:24:09 - [1,088] ----D C:\Users\Isabel\AppData\Local\Diagnostics O43 - CFD: 20.03.2011 - 20:09:00 - [0] ----D C:\Users\Isabel\AppData\Local\ElevatedDiagnostics O43 - CFD: 04.02.2013 - 11:46:26 - [0] ----D C:\Users\Isabel\AppData\Local\Google O43 - CFD: 20.12.2012 - 14:15:21 - [0,000] ----D C:\Users\Isabel\AppData\Local\Kreapixel O43 - CFD: 23.06.2012 - 13:07:18 - [0] ----D C:\Users\Isabel\AppData\Local\Macromedia O43 - CFD: 23.06.2012 - 13:07:18 - [435,475] ----D C:\Users\Isabel\AppData\Local\Microsoft O43 - CFD: 14.01.2013 - 01:16:29 - [1,550] ----D C:\Users\Isabel\AppData\Local\Microsoft Games O43 - CFD: 28.07.2010 - 20:16:05 - [0] ----D C:\Users\Isabel\AppData\Local\Microsoft Help O43 - CFD: 28.07.2010 - 15:31:28 - [122,873] ----D C:\Users\Isabel\AppData\Local\Mozilla O43 - CFD: 28.07.2010 - 20:28:36 - [11,918] ----D C:\Users\Isabel\AppData\Local\Power2Go O43 - CFD: 10.11.2012 - 14:12:39 - [0] ----D C:\Users\Isabel\AppData\Local\Programs O43 - CFD: 02.02.2013 - 10:40:56 - [998,018] ----D C:\Users\Isabel\AppData\Local\Spotify O43 - CFD: 04.02.2013 - 15:52:06 - [74,268] ----D C:\Users\Isabel\AppData\Local\Temp O43 - CFD: 28.07.2010 - 20:07:59 - [0] ----D C:\Users\Isabel\AppData\Local\Temporary Internet Files O43 - CFD: 28.07.2010 - 20:07:59 - [0] ----D C:\Users\Isabel\AppData\Local\Verlauf O43 - CFD: 11.08.2010 - 16:35:11 - [0,000] ----D C:\Users\Isabel\AppData\Local\VirtualStore O43 - CFD: 08.12.2010 - 09:51:54 - [0] ----D C:\Users\Isabel\AppData\Local\WMTools Downloaded Files O43 - CFD: 14.07.2009 - 05:42:04 - [0,014] R---D C:\Users\Isabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 12.07.2012 - 07:44:15 - [0,000] R---D C:\Users\Isabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 04.02.2013 - 15:39:29 - [0,039] ----D C:\Users\Isabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite O43 - CFD: 28.07.2010 - 20:26:50 - [0,005] ----D C:\Users\Isabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam O43 - CFD: 14.07.2009 - 05:37:42 - [0,001] R---D C:\Users\Isabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 08.12.2010 - 08:33:13 - [0] ----D C:\Users\Isabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MOVAVI VideoSuite 3.4 O43 - CFD: 12.07.2012 - 07:44:15 - [0,000] R---D C:\Users\Isabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 15.03.2011 - 11:59:59 - [0] ----D C:\Users\Isabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ~ Scan Program Folder in 00mn 33s ---\\ Zuletzt veränderte und erstellte Dateien in Windows und System32 (O44) O44 - LFC:[MD5.7463143F1033974CB5F6A19EE36053BF] - 04.02.2013 - 15:42:19 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1053916] O44 - LFC:[MD5.5A97D5A5DE7187E32B05562D99E64D13] - 04.02.2013 - 15:38:41 ---A- . (...) -- C:\Windows\setupact.log [100958] O44 - LFC:[MD5.EF0064090ABBB3147A47C77C2714E0A9] - 04.02.2013 - 15:38:40 -S-A- . (...) -- C:\Windows\bootstat.dat [67584] O44 - LFC:[MD5.79A9F9DF0A3AEC6A8B75861373685294] - 04.02.2013 - 15:36:08 ---A- . (...) -- C:\Ad-Report-CLEAN[1].txt [4985] O44 - LFC:[MD5.BE6245F6A1E873B228D514CEAABE72DF] - 04.02.2013 - 15:23:20 ---A- . (...) -- C:\Windows\PFRO.log [11650] O44 - LFC:[MD5.A7B67A090B23448CDF97587001BC2488] - 04.02.2013 - 15:22:06 ---A- . (...) -- C:\AdwCleaner[S1].txt [37459] O44 - LFC:[MD5.A10330E22BB6A2223E22D40B934895A1] - 04.02.2013 - 15:22:06 ---A- . (...) -- C:\Windows\DeleteOnReboot.bat [98] O44 - LFC:[MD5.48C0145A104192FAC08C25FC7584458C] - 03.02.2013 - 15:15:47 ---A- . (...) -- C:\Windows\System32\jupdate-1.6.0_39-b04.log [3650] O44 - LFC:[MD5.01C47C2ECED034EF6F8C1552A97CFF00] - 03.02.2013 - 14:58:09 ---A- . (...) -- C:\Windows\System32\config.nt [2577] O44 - LFC:[MD5.1C997EBF3A987A702DA1E831ADC99417] - 21.01.2013 - 10:44:52 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1612484] O44 - LFC:[MD5.3B7274A9D6B791DDCCC3A3AF6B1B2525] - 21.01.2013 - 10:44:52 ---A- . (...) -- C:\Windows\System32\perfc007.dat [148134] O44 - LFC:[MD5.64E1D88410D1A60D180FE0A86D7E2DC1] - 21.01.2013 - 10:44:52 ---A- . (...) -- C:\Windows\System32\perfc009.dat [121080] O44 - LFC:[MD5.9916EAA6A867E61E9D288D7742003A48] - 21.01.2013 - 10:44:52 ---A- . (...) -- C:\Windows\System32\perfh007.dat [696870] O44 - LFC:[MD5.405AAB7758B3D3E57AE87745B17C8CA0] - 21.01.2013 - 10:44:52 ---A- . (...) -- C:\Windows\System32\perfh009.dat [652148] O44 - LFC:[MD5.680CE43141FB1F432CD375063450E0C0] - 17.01.2013 - 14:21:56 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\Windows\System32\FlashPlayerApp.exe [697864] O44 - LFC:[MD5.72AC0DB22D016619E0AD3F9C411B9738] - 17.01.2013 - 14:21:56 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [74248] O44 - LFC:[MD5.DE8275CAB4D3F80E4E266E14955B16EC] - 15.01.2013 - 16:56:10 ---A- . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java(T.) -- C:\Windows\System32\npdeployJava1.dll [477616] O44 - LFC:[MD5.5C7FE0AADBE87665D3C87F80E7356C77] - 15.01.2013 - 16:56:07 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Windows\System32\deployJava1.dll [473520] O44 - LFC:[MD5.6B45E0F73D7B780022EF24996A09A057] - 15.01.2013 - 16:53:05 ---A- . (.Sun Microsystems, Inc. - Java(TM) Web Start Launcher.) -- C:\Windows\System32\javaws.exe [158128] O44 - LFC:[MD5.F67295E82932F094CEEB90707CCA6F02] - 15.01.2013 - 16:53:01 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Windows\System32\javaw.exe [149936] O44 - LFC:[MD5.3CBC9ED862264FE5B87F3E0623407034] - 15.01.2013 - 16:52:55 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Windows\System32\java.exe [149936] O44 - LFC:[MD5.990B77E8BDA78704F4AA96B06B4D408C] - 09.01.2013 - 18:59:25 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [391584] O44 - LFC:[MD5.EFC2A5402AAC871E3EAC194B2A28E081] - 09.01.2013 - 11:15:48 ---A- . (...) -- C:\Windows\win.ini [531] O44 - LFC:[MD5.41CE7975CAD7BCF92538D2C452239523] - 09.01.2013 - 10:12:55 ---A- . (.Microsoft - COB-AU-Freigabesystem.) -- C:\Windows\System32\cob-au.rs [40960] O44 - LFC:[MD5.6EC618588447B82EA8D88719EE46F725] - 09.01.2013 - 10:12:55 ---A- . (.Microsoft - CSRR-Freigabesystem.) -- C:\Windows\System32\csrr.rs [43520] O44 - LFC:[MD5.ED59143843560B5EDB543C2A48CB9E4B] - 09.01.2013 - 10:12:55 ---A- . (.Microsoft - OFLC-NZ-Freigabesystem.) -- C:\Windows\System32\oflc-nz.rs [45568] O44 - LFC:[MD5.27828AAA24AA46F11036954ADE355C1C] - 09.01.2013 - 10:12:54 ---A- . (.Microsoft - DJCTQ-Freigabesystem.) -- C:\Windows\System32\djctq.rs [15360] O44 - LFC:[MD5.A704E750245D5D4EE4A23E99A00F27D5] - 09.01.2013 - 10:12:54 ---A- . (.Microsoft - FPB-Freigabesystem.) -- C:\Windows\System32\fpb.rs [46592] O44 - LFC:[MD5.9B7D7F4D1F79E8B7D727BE94B1630D59] - 09.01.2013 - 10:12:54 ---A- . (.Microsoft - PEGI/BBFC-Bewertungssystem.) -- C:\Windows\System32\pegibbfc.rs [44544] O44 - LFC:[MD5.A067A19A91C2AA0198F9BD01A5CEF5C6] - 09.01.2013 - 10:12:53 ---A- . (.Microsoft - GRB-Bewertungssystem.) -- C:\Windows\System32\grb.rs [21504] O44 - LFC:[MD5.4F5C56DBF076D5BBB1D22B37BF281396] - 09.01.2013 - 10:12:53 ---A- . (.Microsoft - PEGI-Bewertungssystem (Portugal).) -- C:\Windows\System32\pegi-pt.rs [20480] O44 - LFC:[MD5.5109C45498BC709C8A7E016D5FFCCAC2] - 09.01.2013 - 10:12:53 ---A- . (.Microsoft - PEGI-Bewertungssystem.) -- C:\Windows\System32\pegi.rs [20480] O44 - LFC:[MD5.9EDCFA23CC081E38C86CA309D0F7E3DC] - 09.01.2013 - 10:12:53 ---A- . (.Microsoft - USK-Bewertungssystem.) -- C:\Windows\System32\usk.rs [30720] O44 - LFC:[MD5.DDD1C4AB9A9DAE6D4092C4C95E714650] - 09.01.2013 - 10:12:46 ---A- . (.Microsoft - ESRB-Bewertungssystem.) -- C:\Windows\System32\esrb.rs [51712] O44 - LFC:[MD5.7752619457598CF057C4CC02A0867029] - 09.01.2013 - 10:12:45 ---A- . (.Microsoft - CERO-Bewertungssystem.) -- C:\Windows\System32\cero.rs [55296] O44 - LFC:[MD5.CBC69A055EF410CBD65593E4808B6DB4] - 09.01.2013 - 10:12:45 ---A- . (.Microsoft - OFLC-Bewertungssystem.) -- C:\Windows\System32\oflc.rs [23552] O44 - LFC:[MD5.72035C97983745E742D71E9A8EF70BBB] - 09.01.2013 - 10:12:45 ---A- . (.Microsoft - PEGI-Bewertungssystem (Finnland).) -- C:\Windows\System32\pegi-fi.rs [20480] O44 - LFC:[MD5.1153AC6E133AA849853DFD407B086B80] - 30.11.2012 - 00:17:39 ---A- . (...) -- C:\Windows\System32\locale.nls [420064] ~ Scan Files in 00mn 09s ---\\ Zuletzt erstelle Dateien in Windows Prefetch (O45) O45 - LFCP:[MD5.1EDB7AE631420D2D3601017166641B5E] - 02.02.2013 - 14:35:28 ---A- - C:\Windows\Prefetch\SOLITAIRE.EXE-556099DE.pf O45 - LFCP:[MD5.2B20EB43C3FEE6D67072C59C2E0C4783] - 03.02.2013 - 15:00:46 ---A- - C:\Windows\Prefetch\AgCx_SC4.db O45 - LFCP:[MD5.B7EEBF661D2410019C2AE7A49FACCAB4] - 03.02.2013 - 15:01:13 ---A- - C:\Windows\Prefetch\UPDATETASK.EXE-588494CD.pf O45 - LFCP:[MD5.691A86149538DD48C8D30B297A81C38F] - 03.02.2013 - 16:44:32 ---A- - C:\Windows\Prefetch\OPTIONALFEATURES.EXE-F3E13EA6.pf O45 - LFCP:[MD5.BD8A3E8A3C41511D764FF0B4B7645269] - 03.02.2013 - 16:44:40 ---A- - C:\Windows\Prefetch\TRUSTEDINSTALLER.EXE-766EFF52.pf O45 - LFCP:[MD5.8C6CA847341BFCEBA616972918CACB33] - 03.02.2013 - 16:44:50 ---A- - C:\Windows\Prefetch\HELPPANE.EXE-2CB7BD18.pf O45 - LFCP:[MD5.EFC4E615B6B7AAF7C35082E0BB4AEE90] - 03.02.2013 - 16:46:09 ---A- - C:\Windows\Prefetch\MSIE539.TMP-C9F0C76F.pf O45 - LFCP:[MD5.D56C7C5317FF81D413DACD8F0723CB7C] - 03.02.2013 - 16:46:11 ---A- - C:\Windows\Prefetch\INSTAPP.EXE-F0F31C48.pf O45 - LFCP:[MD5.7753D0289BC3551BC8D60FAB26CB2665] - 03.02.2013 - 16:46:21 ---A- - C:\Windows\Prefetch\UI0DETECT.EXE-97E69F68.pf O45 - LFCP:[MD5.CD527F4D18221DD1387D7070A4ABD36E] - 03.02.2013 - 16:48:34 ---A- - C:\Windows\Prefetch\PCALUA.EXE-28D6C54B.pf O45 - LFCP:[MD5.97EA46F2C04F7313C19C49D2564FF276] - 03.02.2013 - 16:57:24 ---A- - C:\Windows\Prefetch\CCLEANER.EXE-DD6AC7E5.pf O45 - LFCP:[MD5.7498242E5C07DC4EEBF6428F1EB2CF73] - 03.02.2013 - 16:58:17 ---A- - C:\Windows\Prefetch\WORDCONV.EXE-DA14787E.pf O45 - LFCP:[MD5.3CC1D387E728B6EAD49F7A9583350756] - 03.02.2013 - 16:58:29 ---A- - C:\Windows\Prefetch\WINWORD.EXE-D0290961.pf O45 - LFCP:[MD5.496FCA83781C3BCF56941DB2D6BEB3C4] - 03.02.2013 - 16:58:53 ---A- - C:\Windows\Prefetch\UNINSTALL.EXE-E8779C0E.pf O45 - LFCP:[MD5.56C9A35448CC2E295289B3137B026447] - 03.02.2013 - 16:59:24 ---A- - C:\Windows\Prefetch\UNINSTALL.EXE-96F15E7A.pf O45 - LFCP:[MD5.567AC1DC0F1130FE36115EAE02BC7E01] - 03.02.2013 - 16:59:40 ---A- - C:\Windows\Prefetch\UNINSTALL.EXE-8CBBEB63.pf O45 - LFCP:[MD5.31574246A579019A734F9A94BA1AEAC1] - 03.02.2013 - 16:59:51 ---A- - C:\Windows\Prefetch\UNINS000.EXE-8F6158C5.pf O45 - LFCP:[MD5.CC7641E0E733F4570F67A2F04E9B2976] - 03.02.2013 - 16:59:51 ---A- - C:\Windows\Prefetch\_IU14D2N.TMP-D7051A97.pf O45 - LFCP:[MD5.2E22531746667F682FC999B4CC514C5E] - 03.02.2013 - 16:59:56 ---A- - C:\Windows\Prefetch\UNINSTALL.EXE-10155A19.pf O45 - LFCP:[MD5.B363C12A386C7CD15DA07EBE5024F2D2] - 03.02.2013 - 18:00:55 ---A- - C:\Windows\Prefetch\SETUP.EXE-A0D5184B.pf O45 - LFCP:[MD5.FCCACF959A1905009164A88CA9B340B8] - 03.02.2013 - 18:01:34 ---A- - C:\Windows\Prefetch\NS6FBA.TMP-C515A23C.pf O45 - LFCP:[MD5.08D83E8785FE4CA0E5C4F591D736A52D] - 03.02.2013 - 18:01:34 ---A- - C:\Windows\Prefetch\NS76C7.TMP-D5B61960.pf O45 - LFCP:[MD5.9C4BA1F87268D3002EDB34E094ADDE33] - 03.02.2013 - 18:04:56 ---A- - C:\Windows\Prefetch\RSTRUI.EXE-125FC252.pf O45 - LFCP:[MD5.F9EDA811741F8725BA10D19AB19043F8] - 03.02.2013 - 18:04:57 ---A- - C:\Windows\Prefetch\VDSLDR.EXE-50179B50.pf O45 - LFCP:[MD5.5B9A4A4D0DEFF4A5E3C86B427902C422] - 03.02.2013 - 18:04:57 ---A- - C:\Windows\Prefetch\WBENGINE.EXE-57BA6C00.pf O45 - LFCP:[MD5.0F4BFB6F42C81E68625B13CB93B87B2E] - 03.02.2013 - 18:05:01 ---A- - C:\Windows\Prefetch\VDS.EXE-2FCA9D16.pf O45 - LFCP:[MD5.25CFAB5192423508773030C0EABEF1B1] - 03.02.2013 - 18:31:22 ---A- - C:\Windows\Prefetch\FIREFOX SETUP 18.0.1.EXE-76385E66.pf O45 - LFCP:[MD5.97EC095605CB558A598811937564D2C3] - 03.02.2013 - 18:31:32 ---A- - C:\Windows\Prefetch\SETUP.EXE-2941561F.pf O45 - LFCP:[MD5.17B5D409D2FBD772CE81F1131B173DED] - 03.02.2013 - 18:31:35 ---A- - C:\Windows\Prefetch\NSF609.TMP-139909C8.pf O45 - LFCP:[MD5.8E562C405C0E5BDA0F7DA88F62B215BB] - 03.02.2013 - 18:31:35 ---A- - C:\Windows\Prefetch\NSFAC5.TMP-8D77853F.pf O45 - LFCP:[MD5.A1088FB760CFBB8779AC2D5BF8CD0DB1] - 03.02.2013 - 19:06:05 ---A- - C:\Windows\Prefetch\SC.EXE-6C4D4413.pf O45 - LFCP:[MD5.41715D2E4EFBFFB4D2F87164A4DBC13F] - 03.02.2013 - 20:22:13 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-7C9048C0.pf O45 - LFCP:[MD5.3B82F7C79C8F8CAA4E0C29E9E24260D7] - 03.02.2013 - 20:22:13 ---A- - C:\Windows\Prefetch\VSSVC.EXE-6C8F0C66.pf O45 - LFCP:[MD5.4F1B638E2529EFB05B14E41C49ABE455] - 03.02.2013 - 20:22:14 ---A- - C:\Windows\Prefetch\CSC.EXE-F8803EEA.pf O45 - LFCP:[MD5.902DEAF0D8648FC3C9BC6BD730963B2F] - 03.02.2013 - 20:22:14 ---A- - C:\Windows\Prefetch\CVTRES.EXE-CB8485B0.pf O45 - LFCP:[MD5.0FBF6050EF3B0140EF88DCAC8C89C752] - 03.02.2013 - 20:22:14 ---A- - C:\Windows\Prefetch\SDIAGNHOST.EXE-B3171AA1.pf O45 - LFCP:[MD5.B90CB2A4B7522A7B89731CE042CF6F8B] - 03.02.2013 - 20:22:17 ---A- - C:\Windows\Prefetch\W32TM.EXE-C4E0F88E.pf O45 - LFCP:[MD5.16665FA61B50D5DE03D8F5CBA76A941A] - 03.02.2013 - 20:22:28 ---A- - C:\Windows\Prefetch\PING.EXE-4A8A6853.pf O45 - LFCP:[MD5.CADBC89322D782A18588B1881CA103D5] - 03.02.2013 - 20:34:19 ---A- - C:\Windows\Prefetch\24.0.1312.57_CHROME_INSTALLER-DEF94C79.pf O45 - LFCP:[MD5.12EC4CFDF2400809EE523B0576074100] - 03.02.2013 - 20:34:19 ---A- - C:\Windows\Prefetch\SETUP.EXE-EB563323.pf O45 - LFCP:[MD5.4F547AC0B7AA753451E0CFB4064EAEDC] - 03.02.2013 - 21:11:50 ---A- - C:\Windows\Prefetch\APLANGAPP.EXE-77E79FF1.pf O45 - LFCP:[MD5.D5DCE4A2159CA04E20B6A79DAD56C4D9] - 03.02.2013 - 21:11:50 ---A- - C:\Windows\Prefetch\MUISTARTMENU.EXE-18BBF740.pf O45 - LFCP:[MD5.E143FAD7DD1E22C2B6EAD60200E341DE] - 03.02.2013 - 21:13:46 ---A- - C:\Windows\Prefetch\TASKMGR.EXE-4C8500BA.pf O45 - LFCP:[MD5.78CA2A612122EFDA73562D358EFBF135] - 03.02.2013 - 21:14:42 ---A- - C:\Windows\Prefetch\FIREFOX SETUP 18.0.1(1).EXE-F4EE060F.pf O45 - LFCP:[MD5.FDCBE374D3238D4B1CDDBE2D4D7FF7FC] - 03.02.2013 - 21:14:55 ---A- - C:\Windows\Prefetch\SETUP.EXE-8505BF15.pf O45 - LFCP:[MD5.656239F24E5B8EC0EC91F95A68FE1514] - 03.02.2013 - 21:15:37 ---A- - C:\Windows\Prefetch\SETUP.EXE-E31797FD.pf O45 - LFCP:[MD5.AC131316FC9596588E11AFA9B50C8B9E] - 03.02.2013 - 21:37:12 ---A- - C:\Windows\Prefetch\Layout.ini O45 - LFCP:[MD5.900840E57DF46900BE4FB7F41F955CCB] - 03.02.2013 - 21:40:01 ---A- - C:\Windows\Prefetch\FIREFOX SETUP 18.0.1.EXE-ABE0DC65.pf O45 - LFCP:[MD5.4AA7DB39F99DDCF83DAF0B9BE0364DCA] - 03.02.2013 - 21:40:11 ---A- - C:\Windows\Prefetch\SETUP.EXE-BBD8D447.pf O45 - LFCP:[MD5.EFE0041607FDEE56D313726A02BBD61D] - 03.02.2013 - 21:40:40 ---A- - C:\Windows\Prefetch\NSDB9A.TMP-D9704308.pf O45 - LFCP:[MD5.8DE268F90DEE9AE21F6F4FCFBD997B2B] - 03.02.2013 - 21:40:40 ---A- - C:\Windows\Prefetch\NSDF39.TMP-0888E475.pf O45 - LFCP:[MD5.954C2216423B73305F359B55137A5439] - 03.02.2013 - 21:53:22 ---A- - C:\Windows\Prefetch\FIREFOX SETUP 18.0.1.EXE-C07547F2.pf O45 - LFCP:[MD5.A47B0E4EF070BDF70F9B9978199BD30A] - 03.02.2013 - 21:54:12 ---A- - C:\Windows\Prefetch\MAINTENANCESERVICE_INSTALLER.-47A82BA7.pf O45 - LFCP:[MD5.DD1F8B6E716B204E06664E917979F279] - 03.02.2013 - 21:54:12 ---A- - C:\Windows\Prefetch\MAINTENANCESERVICE_TMP.EXE-F66DDF9B.pf O45 - LFCP:[MD5.70B17F232B5106F44F76F4F8063E5BA7] - 03.02.2013 - 21:54:12 ---A- - C:\Windows\Prefetch\NS40ED.TMP-F1FCF185.pf O45 - LFCP:[MD5.7C82D8FF9FFEBFEAE995E3F9366C7FD0] - 03.02.2013 - 21:54:12 ---A- - C:\Windows\Prefetch\NS455B.TMP-26331F14.pf O45 - LFCP:[MD5.DACDF5CE0B63DC9AE777379BFE3D8902] - 03.02.2013 - 21:54:13 ---A- - C:\Windows\Prefetch\SETUP.EXE-0CD24F21.pf O45 - LFCP:[MD5.86A0A953A1B050B7DFC6612B9060A688] - 03.02.2013 - 21:55:05 ---A- - C:\Windows\Prefetch\SILVERLIGHT.CONFIGURATION.EXE-DBDAD523.pf O45 - LFCP:[MD5.B7C8C80C34C2554849236C268914C2E0] - 03.02.2013 - 21:55:15 ---A- - C:\Windows\Prefetch\AGCP.EXE-53D0E2A3.pf O45 - LFCP:[MD5.483A31FE8222857EF2E1DA45D7834C2C] - 04.02.2013 - 02:59:25 ---A- - C:\Windows\Prefetch\BROWSEMNGR.EXE-163F901D.pf O45 - LFCP:[MD5.6D9D22A39E5ED5BB70668F190895D32D] - 04.02.2013 - 11:16:09 ---A- - C:\Windows\Prefetch\E_FATIACE.EXE-B169FB47.pf O45 - LFCP:[MD5.391B409E0E7EC796F7F1C3ED1A39662C] - 04.02.2013 - 11:16:17 ---A- - C:\Windows\Prefetch\HKCMD.EXE-61FD4888.pf O45 - LFCP:[MD5.E942BDF026247458A62063091E746BA0] - 04.02.2013 - 11:16:17 ---A- - C:\Windows\Prefetch\IGFXPERS.EXE-540AA77D.pf O45 - LFCP:[MD5.78EE3EBEDB2FCA13603EECA82AD59FA6] - 04.02.2013 - 11:16:17 ---A- - C:\Windows\Prefetch\IGFXTRAY.EXE-F30110F3.pf O45 - LFCP:[MD5.3DEE8E7E8D67017CD2BA794CD26C4714] - 04.02.2013 - 11:16:18 ---A- - C:\Windows\Prefetch\JUSCHED.EXE-9A2C4A78.pf O45 - LFCP:[MD5.38FA6982DA1B7192EDCEF80A359E7F1D] - 04.02.2013 - 11:16:51 ---A- - C:\Windows\Prefetch\IMINENT.EXE-381F6E23.pf O45 - LFCP:[MD5.4A2B7464A9BD45EE956B90FDCCDD5322] - 04.02.2013 - 11:29:34 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-D058412F.pf O45 - LFCP:[MD5.48A6A1ED2959B8C611C2223B997CE019] - 04.02.2013 - 11:35:36 ---A- - C:\Windows\Prefetch\SUPNOT~1.EXE-CFE55A3B.pf O45 - LFCP:[MD5.2D067C1A112063CEEBF49FB4C47E71A6] - 04.02.2013 - 11:42:38 ---A- - C:\Windows\Prefetch\SETUP.EXE-AB57E7A0.pf O45 - LFCP:[MD5.438961ACD0D4E187F67378AF13268564] - 04.02.2013 - 11:42:40 ---A- - C:\Windows\Prefetch\CHROME.EXE-AED7BA3C.pf O45 - LFCP:[MD5.2CEF950BF596227DA68C19289E04AAC1] - 04.02.2013 - 11:43:00 ---A- - C:\Windows\Prefetch\IEXPLORE.EXE-058FE8F5.pf O45 - LFCP:[MD5.3D3E843CF2C5EBB570CD3AE22C8EFFD3] - 04.02.2013 - 11:45:43 ---A- - C:\Windows\Prefetch\WERFAULT.EXE-155C56CF.pf O45 - LFCP:[MD5.EEA1E74AF6254CFBF11F1D990C79D772] - 04.02.2013 - 11:46:08 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-02D72769.pf O45 - LFCP:[MD5.85388945817F85D502917B8EE261A776] - 04.02.2013 - 11:46:09 ---A- - C:\Windows\Prefetch\GOOGLETOOLBARMANAGER_E582EA55-B24FF9C2.pf O45 - LFCP:[MD5.3E67703370CA8C48A6384B23394ABA60] - 04.02.2013 - 11:46:18 ---A- - C:\Windows\Prefetch\GOOGLETOOLBARNOTIFIER.EXE-2297EB70.pf O45 - LFCP:[MD5.FD6A141B85FE1350579F8AEEC63A336B] - 04.02.2013 - 11:46:25 ---A- - C:\Windows\Prefetch\GOOGLEUPDATERSERVICE.EXE-B29A0C52.pf O45 - LFCP:[MD5.9A372B85A82F017FEBCEF5930EA9B086] - 04.02.2013 - 11:46:25 ---A- - C:\Windows\Prefetch\GUS7177.TMP-273161CA.pf O45 - LFCP:[MD5.913F89469A28BA069038D74F1CAA6B95] - 04.02.2013 - 11:46:30 ---A- - C:\Windows\Prefetch\MSIEXEC.EXE-8FFB1633.pf O45 - LFCP:[MD5.0C083BCE36D0C22F72DB88F133128763] - 04.02.2013 - 11:48:20 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-ED743652.pf O45 - LFCP:[MD5.652BFC49055B28E1F5D7EAE00B204EDA] - 04.02.2013 - 12:51:05 ---A- - C:\Windows\Prefetch\HEARTS.EXE-0AA35744.pf O45 - LFCP:[MD5.F5FE30C7686DAF239BCD255D35243FBD] - 04.02.2013 - 13:13:49 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-38FE020E.pf O45 - LFCP:[MD5.85EB1A9280A4057597229A41E7EF81A3] - 04.02.2013 - 13:36:12 ---A- - C:\Windows\Prefetch\CALC.EXE-43F37294.pf O45 - LFCP:[MD5.90FCB99257900AFD227576A0B26ABFD8] - 04.02.2013 - 14:57:11 ---A- - C:\Windows\Prefetch\WMPNSCFG.EXE-18FC9E64.pf O45 - LFCP:[MD5.8A4623F844F978E1BF9FBECE8549F36C] - 04.02.2013 - 14:57:13 ---A- - C:\Windows\Prefetch\AgCx_SC1.db.trx O45 - LFCP:[MD5.7C777EDE81362741DDD08C3CC95D3CF8] - 04.02.2013 - 14:57:16 ---A- - C:\Windows\Prefetch\IGFXSRVC.EXE-C5618119.pf O45 - LFCP:[MD5.B9F6C54BAD7C87FD51E6431F413BC945] - 04.02.2013 - 14:58:14 ---A- - C:\Windows\Prefetch\AgCx_SC1.db O45 - LFCP:[MD5.3E7EBD15094D018ABD2ACBB938B9A409] - 04.02.2013 - 15:00:13 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-A0F5E092.pf O45 - LFCP:[MD5.74B18CCE2CF2F889CA30E628A6A4A566] - 04.02.2013 - 15:00:49 ---A- - C:\Windows\Prefetch\HELPER.EXE-DFB54970.pf O45 - LFCP:[MD5.524E31989A597C47BA84D23F33C78EC4] - 04.02.2013 - 15:01:07 ---A- - C:\Windows\Prefetch\CSC.EXE-A14D0E83.pf O45 - LFCP:[MD5.0DB6F9F17BDE7283D8C338B2E7F5C80A] - 04.02.2013 - 15:01:07 ---A- - C:\Windows\Prefetch\CVTRES.EXE-929E64D1.pf O45 - LFCP:[MD5.C3C54537A84959CA12BA64A46DDB2936] - 04.02.2013 - 15:01:16 ---A- - C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-1871111397-3539990770-1974983793-1001.db O45 - LFCP:[MD5.10BA27C03D05F2E3E6E20CF8ABEC6A83] - 04.02.2013 - 15:01:16 ---A- - C:\Windows\Prefetch\AgGlUAD_S-1-5-21-1871111397-3539990770-1974983793-1001.db O45 - LFCP:[MD5.F38E214DBC5BA8E88B1E59082800AAAA] - 04.02.2013 - 15:03:01 ---A- - C:\Windows\Prefetch\E_FAMTACE.EXE-069E07B3.pf O45 - LFCP:[MD5.64F6C74C59B18AD95DF88C323DBDFB63] - 04.02.2013 - 15:16:03 ---A- - C:\Windows\Prefetch\AVAST.SETUP-0294E3FE.pf O45 - LFCP:[MD5.C5C0939E86A74D6275A91C451AD53864] - 04.02.2013 - 15:18:07 ---A- - C:\Windows\Prefetch\PRINTISOLATIONHOST.EXE-3DD89C8E.pf O45 - LFCP:[MD5.E50B33DB973C6F7198B7399CF3B9EC9A] - 04.02.2013 - 15:22:50 ---A- - C:\Windows\Prefetch\LOGONUI.EXE-F639BD7E.pf O45 - LFCP:[MD5.E3D7B78EB45425B1A48B34C753CC7AEC] - 04.02.2013 - 15:25:59 ---A- - C:\Windows\Prefetch\MUISTARTMENU.EXE-28E55131.pf O45 - LFCP:[MD5.6B32AF7FD9790956003CD583360C61B8] - 04.02.2013 - 15:25:59 ---A- - C:\Windows\Prefetch\MUISTARTMENU.EXE-2CC9B9B5.pf O45 - LFCP:[MD5.CEC757B28B06286D960A18FB70678A46] - 04.02.2013 - 15:26:01 ---A- - C:\Windows\Prefetch\MUISTARTMENU.EXE-415FCA95.pf O45 - LFCP:[MD5.832D6C29EA3B8808DCD23538DCD4AA54] - 04.02.2013 - 15:26:02 ---A- - C:\Windows\Prefetch\LANGUAGE.EXE-BD36F169.pf O45 - LFCP:[MD5.2396654D095C028EDC95B42CBF3346FF] - 04.02.2013 - 15:26:04 ---A- - C:\Windows\Prefetch\MUISTARTMENU.EXE-EA3510BE.pf O45 - LFCP:[MD5.368BF66E39B613E34B85FA71689E2B47] - 04.02.2013 - 15:26:04 ---A- - C:\Windows\Prefetch\QTTASK.EXE-794D22BF.pf O45 - LFCP:[MD5.C51C3CA94E81193A06D049471414D207] - 04.02.2013 - 15:26:12 ---A- - C:\Windows\Prefetch\SYNTPHELPER.EXE-C8D211B9.pf O45 - LFCP:[MD5.1567FB79E93DAF8184DA20A1B8469EC7] - 04.02.2013 - 15:26:16 ---A- - C:\Windows\Prefetch\ITUNESHELPER.EXE-C9C22763.pf O45 - LFCP:[MD5.7F415ED55642A7601B6BCE071B30E2E9] - 04.02.2013 - 15:26:17 ---A- - C:\Windows\Prefetch\READER_SL.EXE-12F321E0.pf O45 - LFCP:[MD5.CB589AFF61A13C77F85B7B38D08B111A] - 04.02.2013 - 15:26:22 ---A- - C:\Windows\Prefetch\GFXUI.EXE-7A92D15C.pf O45 - LFCP:[MD5.2E8C6710C5766F9C650C43D83430F527] - 04.02.2013 - 15:36:00 ---A- - C:\Windows\Prefetch\FLASHPLAYERUPDATESERVICE.EXE-CC69B9EE.pf O45 - LFCP:[MD5.5624359DFD75732F3D22A6B69737FA85] - 04.02.2013 - 15:36:10 ---A- - C:\Windows\Prefetch\TASKENG.EXE-35FA9C06.pf O45 - LFCP:[MD5.C609C70ECF1BC9106000FFDCD3198D6F] - 04.02.2013 - 15:38:07 ---A- - C:\Windows\Prefetch\AgRobust.db O45 - LFCP:[MD5.FF0986A001111FB4B16CAD02F3885442] - 04.02.2013 - 15:38:07 ---A- - C:\Windows\Prefetch\PfSvPerfStats.bin O45 - LFCP:[MD5.DA9CC02C40EB05C1CA91AFC3A97459E0] - 04.02.2013 - 15:38:08 ---A- - C:\Windows\Prefetch\AgGlFaultHistory.db O45 - LFCP:[MD5.ADF96567BBE719B350DAD531C4289FAF] - 04.02.2013 - 15:38:08 ---A- - C:\Windows\Prefetch\AgGlFgAppHistory.db O45 - LFCP:[MD5.1601479E63E17F406D343550F6F61590] - 04.02.2013 - 15:38:08 ---A- - C:\Windows\Prefetch\AgGlGlobalHistory.db O45 - LFCP:[MD5.D598B44FEEC0273A2E72EE94FBA8569C] - 04.02.2013 - 15:39:42 ---A- - C:\Windows\Prefetch\AUTOUPDATEAPILIB.EXE-3FC6EF25.pf O45 - LFCP:[MD5.C7767B9994AB3D9D64A5E338F6A8C347] - 04.02.2013 - 15:39:54 ---A- - C:\Windows\Prefetch\IPODSERVICE.EXE-716E0AD1.pf O45 - LFCP:[MD5.CD2551F6448977A91AB6B1E11DF1618C] - 04.02.2013 - 15:40:05 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-1B0E9471.pf O45 - LFCP:[MD5.BEFAEE61E8F4F22EC72C3D76C2AB2B56] - 04.02.2013 - 15:40:24 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-C40A3D6A.pf O45 - LFCP:[MD5.ED917DBC594975F15281B5FC108B2A6D] - 04.02.2013 - 15:40:52 ---A- - C:\Windows\Prefetch\NOTEPAD.EXE-C5670914.pf O45 - LFCP:[MD5.DF874C8C753B305BE0650B696115383D] - 04.02.2013 - 15:41:18 ---A- - C:\Windows\Prefetch\GOOGLEUPDATE.EXE-737A6CD7.pf O45 - LFCP:[MD5.1EE76092AEDF513D7378DC00757151E7] - 04.02.2013 - 15:41:18 ---A- - C:\Windows\Prefetch\MSCORSVW.EXE-8CE1A322.pf O45 - LFCP:[MD5.37E8BCA6031FE85BF2E8252EAA997DC1] - 04.02.2013 - 15:41:30 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-8CDC24C8.pf O45 - LFCP:[MD5.833C790AC7F103DAC4F6FC17A94896EF] - 04.02.2013 - 15:42:57 ---A- - C:\Windows\Prefetch\WMIADAP.EXE-BB21CD77.pf O45 - LFCP:[MD5.6EB3DB95E2EBF4F63320CB8B6F0384E4] - 04.02.2013 - 15:43:08 ---A- - C:\Windows\Prefetch\FIREFOX.EXE-66015FD1.pf O45 - LFCP:[MD5.BE9D2B6A6F2CD69D4CC81FB465ECAC7E] - 04.02.2013 - 15:43:39 ---A- - C:\Windows\Prefetch\FLASHPLAYERPLUGIN_11_5_502_14-86027D86.pf O45 - LFCP:[MD5.A57E4FBAFE32D0526E556B7F3D30F938] - 04.02.2013 - 15:43:39 ---A- - C:\Windows\Prefetch\PLUGIN-CONTAINER.EXE-C6EE3785.pf O45 - LFCP:[MD5.B3496C41F33E9CEC4D0B648DF56CCB49] - 04.02.2013 - 15:45:27 ---A- - C:\Windows\Prefetch\AUDIODG.EXE-AB22E9A6.pf O45 - LFCP:[MD5.D0A71643996EDD0AA0B394BF3995E568] - 04.02.2013 - 15:48:59 ---A- - C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-44162447.pf O45 - LFCP:[MD5.48A405CB895280C742C6F24E3F217D4B] - 04.02.2013 - 15:48:59 ---A- - C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-69C456C3.pf O45 - LFCP:[MD5.0144C94210ABBC875991B1D2748C1FC7] - 04.02.2013 - 15:49:12 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-E173F32A.pf O45 - LFCP:[MD5.107BBE995FE7CADCFE0A921204CA0285] - 04.02.2013 - 15:49:29 ---A- - C:\Windows\Prefetch\CONSENT.EXE-40419367.pf O45 - LFCP:[MD5.DD803B7767103E67B3A958E2BF594CFC] - 04.02.2013 - 15:49:34 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-F99091EF.pf O45 - LFCP:[MD5.D496B922DC242F379BE20B2A67C42A3A] - 04.02.2013 - 15:51:28 ---A- - C:\Windows\Prefetch\CONHOST.EXE-0C6456FB.pf O45 - LFCP:[MD5.ACDF3AAAF5FFB361AC677997CD139A2E] - 04.02.2013 - 15:51:38 ---A- - C:\Windows\Prefetch\MPCMDRUN.EXE-2C9109F9.pf O45 - LFCP:[MD5.3298BA3F0D4ED60E1CCCC6878C83AF6B] - 04.02.2013 - 15:52:01 ---A- - C:\Windows\Prefetch\WERMGR.EXE-F439C551.pf O45 - LFCP:[MD5.6C7E5941F113B23CF3F09959FC86761E] - 04.02.2013 - 15:52:06 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-8CB5CF15.pf O45 - LFCP:[MD5.EA6CEDF37637BDB07B0DAEFCAA117D50] - 04.02.2013 - 15:52:34 ---A- - C:\Windows\Prefetch\SPPSVC.EXE-96070FE0.pf O45 - LFCP:[MD5.1FF87B6C744696C9AF2966B3101B4A08] - 04.02.2013 - 15:52:34 ---A- - C:\Windows\Prefetch\WMIPRVSE.EXE-E8B8DD29.pf O45 - LFCP:[MD5.91C57E141F837D1B78DC86816F784E51] - 04.02.2013 - 15:52:48 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-6D6FB3A1.pf O45 - LFCP:[MD5.63E5991B3B1E6F49E030BD357D074569] - 04.02.2013 - 15:53:25 ---A- - C:\Windows\Prefetch\SCHTASKS.EXE-8B6144A9.pf ~ Scan Prefetcher in 00mn 01s ---\\ Lokale Sicherheits-Autorität LSA (O48) O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentifizierungspaket v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Clientmodul für Windows-Sicherheitskonfigurations-Editor.) -- C:\Windows\System32\scecli.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Kerberos-Sicherheitspaket.) -- C:\Windows\System32\kerberos.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentifizierungspaket v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll ~ Scan Keys in 00mn 00s ---\\ Registryeinträge für den abgesicherten Modus (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Serieller Mausfiltertreiber.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Treiber für Erweiterung des Volume-Managers.) -- C:\Windows\System32\Drivers\volmgrx.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Serieller Mausfiltertreiber.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Treiber für Erweiterung des Volume-Managers.) -- C:\Windows\System32\Drivers\volmgrx.sys ~ Scan CSB in 00mn 00s ---\\ MountPoints2 Shell Key (MPKS) (O51) O51 - MPSK:{20a32420-8a75-11e0-aa77-002454289581}\AutoRun\command. (...) -- F:\WD SmartWare.exe (.not file.) ~ Scan Keys in 00mn 00s ---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52) O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Cinepak(C) Codec.) -- C:\Windows\System32\iccvid.dll O52 - TDSD: \Drivers32\"vidc.XVID"="xvidvfw.dll" . (...) -- C:\Windows\System32\xvidvfw.dll O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \drivers.desc\"xvidvfw.dll"="XviD MPEG-4 Video Codec" . (...) -- C:\Windows\System32\xvidvfw.dll ~ Scan Keys in 00mn 00s ---\\ ShareTools MSconfig StartupReg (SMSR) (O53) (None) ---\\ Microsoft Control Security Providers (MCSP) (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll ~ Scan Keys in 00mn 00s ---\\ Microsoft Windows Policies System (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0 O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ Scan Keys in 00mn 00s ---\\ System Drivers List (SDL) (O58) O58 - SDL:[MD5.21E785EBD7DC90A06391141AAC7892FB] - 14.07.2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976] O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 13.07.2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029] ~ Scan Drivers in 00mn 00s ---\\ Zuletzt veränderte und erstellte Dateien durch Benutzer(LFC) (O61) O61 - LFC:Last File Created 02.02.2013 - 10:35:55 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\running [0] O61 - LFC:Last File Created 02.02.2013 - 10:36:04 ---A- C:\Users\Isabel\AppData\Local\Spotify\Users\1122199773-user\offline2 [174] O61 - LFC:Last File Created 02.02.2013 - 10:36:17 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\watchdog.bnk [0] O61 - LFC:Last File Created 02.02.2013 - 10:36:18 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\2a\2a7294a6d080511a8e9535374fb11d99382235d9.file [6988] O61 - LFC:Last File Created 02.02.2013 - 10:36:26 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\LocalStorage\Local Storage\sp_feed_0.localstorage [195584] O61 - LFC:Last File Created 02.02.2013 - 10:36:35 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\fd\fde7454bcf38bcbae2ec10f5c094a02a08cf8166.file [18075] O61 - LFC:Last File Created 02.02.2013 - 10:36:45 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\05\0599763ab89bc99aa5e1c11c4b3a0125e8e3d088.file [62968] O61 - LFC:Last File Created 02.02.2013 - 10:36:52 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\LocalStorage\Local Storage\sp_home_0.localstorage [717824] O61 - LFC:Last File Created 02.02.2013 - 10:36:54 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\6b\6b4f6341395988d5917bbb8a38a3e1164bae2725.file [5485] O61 - LFC:Last File Created 02.02.2013 - 10:36:54 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\8c\8c29cd466052fd5a78241bae0f7492dd7ced4f8b.file [14624] O61 - LFC:Last File Created 02.02.2013 - 10:36:55 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\0c\0c7278623a172539594db4288f3268925d0a0c76.file [3919] O61 - LFC:Last File Created 02.02.2013 - 10:36:55 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\Apps\feed\Cookies [7168] O61 - LFC:Last File Created 02.02.2013 - 10:36:56 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\ab\abcce1d75c5612a85774ca8a3196900c434d5a03.file [11553] O61 - LFC:Last File Created 02.02.2013 - 10:36:59 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\ac\acb61ee836d249849cb70b6e2bc267740e1b01d9.file [6299] O61 - LFC:Last File Created 02.02.2013 - 10:36:59 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\cf\cf0a98d9bcd495ba41aec4b6f8156d3089cf5f78.file [2954] O61 - LFC:Last File Created 02.02.2013 - 10:36:59 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\f0\f0c0569185d34a6c0c0332908c25a36ff72a85a1.file [56316] O61 - LFC:Last File Created 02.02.2013 - 10:37:00 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\6e\6e4b293ee55cbef599135cd1bb4f178a0cb58c47.file [18707] O61 - LFC:Last File Created 02.02.2013 - 10:37:06 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\fb\fb52558cb461b1a4dcfa95d4d17d949b8ebf9b14.file [11312] O61 - LFC:Last File Created 02.02.2013 - 10:37:22 ---A- C:\Users\Isabel\AppData\Local\Spotify\Browser\f_0000b9 [117217] O61 - LFC:Last File Created 02.02.2013 - 10:37:29 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\ca\cac751b2c31f818e4979c5a2cfc9c61d775e1262.file [3320] O61 - LFC:Last File Created 02.02.2013 - 10:37:30 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\1c\1c77a73b64a2134b0d9c170d093defc1942963b5.file [3619] O61 - LFC:Last File Created 02.02.2013 - 10:37:30 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\26\26bb00e1b235dc825d5970f2bda9fee313295e4b.file [2936] O61 - LFC:Last File Created 02.02.2013 - 10:37:30 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\34\34c9bfe862092ba65cea7e9da70ea7a69c899501.file [1707] O61 - LFC:Last File Created 02.02.2013 - 10:37:30 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\51\519078cf59eeec90e23174dcd5b82b991fee216b.file [3619] O61 - LFC:Last File Created 02.02.2013 - 10:37:30 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\8e\8ec8992de89c12a72f3ea4bc9832b5620a2078d9.file [1329] O61 - LFC:Last File Created 02.02.2013 - 10:37:30 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\a8\a8def3e206d7fabbef57f88e0f2dea5c75bc8bd5.file [960] O61 - LFC:Last File Created 02.02.2013 - 10:37:30 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\aa\aa41d0476e4feb8ff9b49292dc9a20dee82e4489.file [3019] O61 - LFC:Last File Created 02.02.2013 - 10:37:30 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\b1\b1363bf8c9dc07148470b255733e2c433fd869de.file [1142] O61 - LFC:Last File Created 02.02.2013 - 10:37:30 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\f5\f56ecd714a4c5b40c97ed49b43f3e552b9d79db1.file [3655] O61 - LFC:Last File Created 02.02.2013 - 10:39:51 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\06\067333497612210a6eb0a338425cec4b2ef85fd1.file [32429] O61 - LFC:Last File Created 02.02.2013 - 10:40:56 ---A- C:\Users\Isabel\AppData\Local\Spotify\offline.bnk [430] O61 - LFC:Last File Created 02.02.2013 - 10:40:56 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\local-files.bnk [5639300] O61 - LFC:Last File Created 02.02.2013 - 10:40:56 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\playlist-2b7d55e854eb08078cc0c6640994875c02.bnk [3809] O61 - LFC:Last File Created 02.02.2013 - 10:40:56 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\playlist-4c422394151ed6bbd7e3b7c78bb2158f02.bnk [264268] O61 - LFC:Last File Created 02.02.2013 - 10:40:56 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\playlist-6c9fb429aa05d73777da84e5213cf66502.bnk [712] O61 - LFC:Last File Created 02.02.2013 - 10:40:56 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\playlist-82008728e3eb54c4cc8289f2d976947902.bnk [27189] O61 - LFC:Last File Created 02.02.2013 - 10:40:56 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\playlist-859b9855fb7e51a95664eb90aeb0c00302.bnk [416712] O61 - LFC:Last File Created 02.02.2013 - 10:40:56 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\playlist-a3dac1f9a65673af5eaef11214fb95c402.bnk [7850] O61 - LFC:Last File Created 02.02.2013 - 10:40:56 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\playlist-baa805b5e562ce91f56824b3ba1a745802.bnk [5376] O61 - LFC:Last File Created 02.02.2013 - 10:40:56 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\playlist-f714514829935aa81fe03c1cf3693b3f02.bnk [2914] O61 - LFC:Last File Created 02.02.2013 - 10:40:56 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\purchased.bnk [178] O61 - LFC:Last File Created 02.02.2013 - 10:40:56 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\social_manager.bnk [85938] O61 - LFC:Last File Created 02.02.2013 - 10:40:56 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\watch-sources.bnk [406103] O61 - LFC:Last File Created 02.02.2013 - 10:44:51 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\db\dbe1867ba3bb2927555f64a8b6585f88dcee34d6.file [69215] O61 - LFC:Last File Created 02.02.2013 - 10:44:52 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\6a\6a3e5626a427e4191a6dd710cb84c3e8c2dd6912.file [76146] O61 - LFC:Last File Created 02.02.2013 - 10:45:56 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\settings [1610] O61 - LFC:Last File Created 02.02.2013 - 10:50:56 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\playlist-ffde569bcd20970c4a646803410daa8602.bnk [3626] O61 - LFC:Last File Created 02.02.2013 - 10:52:48 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\05\05bb66352d5563dfc165078d75807302b4d0a688.file [28275] O61 - LFC:Last File Created 02.02.2013 - 10:52:48 ---A- C:\Users\Isabel\AppData\Local\Spotify\Storage\index.dat [169088] O61 - LFC:Last File Created 02.02.2013 - 10:52:48 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\ad.bnk [32555] O61 - LFC:Last File Created 02.02.2013 - 10:52:48 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\guistate [8577] O61 - LFC:Last File Created 02.02.2013 - 10:52:48 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\playlist-bb4ea41a8c72c42691ea4010ebe5126302.bnk [9411] O61 - LFC:Last File Created 02.02.2013 - 10:52:48 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\playlist.bnk [3933] O61 - LFC:Last File Created 02.02.2013 - 10:52:48 ---A- C:\Users\Isabel\AppData\Roaming\Spotify\Users\1122199773-user\track-player.bnk [89671] O61 - LFC:Last File Created 02.02.2013 - 10:52:51 ---A- C:\Users\Isabel\AppData\Local\Spotify\Browser\data_0 [81920] O61 - LFC:Last File Created 02.02.2013 - 10:52:51 ---A- C:\Users\Isabel\AppData\Local\Spotify\Browser\data_1 [1581056] O61 - LFC:Last File Created 02.02.2013 - 10:52:51 ---A- C:\Users\Isabel\AppData\Local\Spotify\Browser\data_2 [1056768] O61 - LFC:Last File Created 02.02.2013 - 13:58:52 ----- C:\Users\Isabel\AppData\Local\Temp\Twain001.Mtx [3] O61 - LFC:Last File Created 02.02.2013 - 13:58:52 ----- C:\Users\Isabel\AppData\Local\Temp\Twunk001.MTX [156] O61 - LFC:Last File Created 02.02.2013 - 13:58:53 ----- C:\Users\Isabel\AppData\Local\Temp\TWAIN.LOG [713] O61 - LFC:Last File Created 02.02.2013 - 13:58:58 ---A- C:\Users\Isabel\AppData\Roaming\Adobe\Photoshop Elements\6.0\Editor\LaunchEndFlag.psp [11] O61 - LFC:Last File Created 02.02.2013 - 14:00:24 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1573.jpg [100979] O61 - LFC:Last File Created 02.02.2013 - 14:00:28 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1574.jpg [133639] O61 - LFC:Last File Created 02.02.2013 - 14:00:35 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1576.jpg [174382] O61 - LFC:Last File Created 02.02.2013 - 14:00:39 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1577.jpg [165771] O61 - LFC:Last File Created 02.02.2013 - 14:00:42 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1578.jpg [191448] O61 - LFC:Last File Created 02.02.2013 - 14:00:45 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1579.jpg [191476] O61 - LFC:Last File Created 02.02.2013 - 14:01:08 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1589.jpg [116429] O61 - LFC:Last File Created 02.02.2013 - 14:01:11 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1590.jpg [101158] O61 - LFC:Last File Created 02.02.2013 - 14:01:17 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1592.jpg [139179] O61 - LFC:Last File Created 02.02.2013 - 14:01:24 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1595.jpg [106815] O61 - LFC:Last File Created 02.02.2013 - 14:01:27 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1596.jpg [98703] O61 - LFC:Last File Created 02.02.2013 - 14:01:32 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1598.jpg [99907] O61 - LFC:Last File Created 02.02.2013 - 14:01:40 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1601.jpg [120643] O61 - LFC:Last File Created 02.02.2013 - 14:01:54 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1606.jpg [95854] O61 - LFC:Last File Created 02.02.2013 - 14:01:57 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1607.jpg [96763] O61 - LFC:Last File Created 02.02.2013 - 14:02:03 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1610.jpg [98056] O61 - LFC:Last File Created 02.02.2013 - 14:02:14 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1614.jpg [117941] O61 - LFC:Last File Created 02.02.2013 - 14:02:16 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1615.jpg [111140] O61 - LFC:Last File Created 02.02.2013 - 14:02:22 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1618.jpg [101705] O61 - LFC:Last File Created 02.02.2013 - 14:02:25 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1619.jpg [105219] O61 - LFC:Last File Created 02.02.2013 - 14:02:27 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1620.jpg [105199] O61 - LFC:Last File Created 02.02.2013 - 14:02:33 ---A- C:\Users\Isabel\Pictures\2012\12 - 04 Glühwein Party\DSCF1622.jpg [118501] O61 - LFC:Last File Created 02.02.2013 - 14:02:38 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1626.jpg [138891] O61 - LFC:Last File Created 02.02.2013 - 14:02:41 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1627.jpg [183746] O61 - LFC:Last File Created 02.02.2013 - 14:02:43 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1628.jpg [123717] O61 - LFC:Last File Created 02.02.2013 - 14:02:46 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1629.jpg [119017] O61 - LFC:Last File Created 02.02.2013 - 14:02:49 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1630.jpg [140826] O61 - LFC:Last File Created 02.02.2013 - 14:02:51 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1631.jpg [116929] O61 - LFC:Last File Created 02.02.2013 - 14:02:54 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1632.jpg [124333] O61 - LFC:Last File Created 02.02.2013 - 14:02:57 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1633.jpg [98436] O61 - LFC:Last File Created 02.02.2013 - 14:02:59 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1634.jpg [98929] O61 - LFC:Last File Created 02.02.2013 - 14:03:02 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1635.jpg [95006] O61 - LFC:Last File Created 02.02.2013 - 14:03:04 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1636.jpg [120247] O61 - LFC:Last File Created 02.02.2013 - 14:03:07 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1637.jpg [95129] O61 - LFC:Last File Created 02.02.2013 - 14:03:10 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1638.jpg [237597] O61 - LFC:Last File Created 02.02.2013 - 14:03:13 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1639.jpg [152362] O61 - LFC:Last File Created 02.02.2013 - 14:03:15 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1640.jpg [139290] O61 - LFC:Last File Created 02.02.2013 - 14:03:18 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1641.jpg [133556] O61 - LFC:Last File Created 02.02.2013 - 14:03:21 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1642.jpg [144760] O61 - LFC:Last File Created 02.02.2013 - 14:03:23 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1643.jpg [98226] O61 - LFC:Last File Created 02.02.2013 - 14:03:26 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1644.jpg [175072] O61 - LFC:Last File Created 02.02.2013 - 14:03:28 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1645.jpg [168918] O61 - LFC:Last File Created 02.02.2013 - 14:03:31 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1646.jpg [104678] O61 - LFC:Last File Created 02.02.2013 - 14:03:34 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1647.jpg [137635] O61 - LFC:Last File Created 02.02.2013 - 14:03:37 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1648.jpg [120586] O61 - LFC:Last File Created 02.02.2013 - 14:03:39 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1649.jpg [144828] O61 - LFC:Last File Created 02.02.2013 - 14:03:42 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1650.jpg [156293] O61 - LFC:Last File Created 02.02.2013 - 14:03:45 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1651.jpg [135385] O61 - LFC:Last File Created 02.02.2013 - 14:03:47 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1652.jpg [117699] O61 - LFC:Last File Created 02.02.2013 - 14:03:50 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1653.jpg [126920] O61 - LFC:Last File Created 02.02.2013 - 14:03:53 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1654.jpg [136218] O61 - LFC:Last File Created 02.02.2013 - 14:03:55 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1655.jpg [118555] O61 - LFC:Last File Created 02.02.2013 - 14:03:58 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1656.jpg [143325] O61 - LFC:Last File Created 02.02.2013 - 14:04:01 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1657.jpg [139718] O61 - LFC:Last File Created 02.02.2013 - 14:04:03 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1658.jpg [155675] O61 - LFC:Last File Created 02.02.2013 - 14:04:06 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1659.jpg [106687] O61 - LFC:Last File Created 02.02.2013 - 14:04:08 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1660.jpg [108018] O61 - LFC:Last File Created 02.02.2013 - 14:04:11 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1661.jpg [137765] O61 - LFC:Last File Created 02.02.2013 - 14:04:14 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1662.jpg [130690] O61 - LFC:Last File Created 02.02.2013 - 14:04:17 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1663.jpg [104478] O61 - LFC:Last File Created 02.02.2013 - 14:04:19 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1664.jpg [231279] O61 - LFC:Last File Created 02.02.2013 - 14:04:22 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1665.jpg [211862] O61 - LFC:Last File Created 02.02.2013 - 14:04:25 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1666.jpg [244897] O61 - LFC:Last File Created 02.02.2013 - 14:04:28 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1667.jpg [236581] O61 - LFC:Last File Created 02.02.2013 - 14:04:31 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1668.jpg [279330] O61 - LFC:Last File Created 02.02.2013 - 14:04:33 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1669.jpg [220398] O61 - LFC:Last File Created 02.02.2013 - 14:04:36 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1670.jpg [205813] O61 - LFC:Last File Created 02.02.2013 - 14:04:39 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1671.jpg [323883] O61 - LFC:Last File Created 02.02.2013 - 14:04:42 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1673.jpg [148799] O61 - LFC:Last File Created 02.02.2013 - 14:04:45 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1674.jpg [169848] O61 - LFC:Last File Created 02.02.2013 - 14:04:47 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1675.jpg [119749] O61 - LFC:Last File Created 02.02.2013 - 14:04:50 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1683.jpg [118602] O61 - LFC:Last File Created 02.02.2013 - 14:04:53 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1684.jpg [117982] O61 - LFC:Last File Created 02.02.2013 - 14:04:55 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1685.jpg [120210] O61 - LFC:Last File Created 02.02.2013 - 14:04:58 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1686.jpg [253527] O61 - LFC:Last File Created 02.02.2013 - 14:05:01 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1687.jpg [244611] O61 - LFC:Last File Created 02.02.2013 - 14:05:04 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1688.jpg [221258] O61 - LFC:Last File Created 02.02.2013 - 14:05:06 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1689.jpg [195949] O61 - LFC:Last File Created 02.02.2013 - 14:05:09 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1690.jpg [251040] O61 - LFC:Last File Created 02.02.2013 - 14:05:12 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1691.jpg [195561] O61 - LFC:Last File Created 02.02.2013 - 14:05:15 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1692.jpg [165518] O61 - LFC:Last File Created 02.02.2013 - 14:05:18 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1693.jpg [298976] O61 - LFC:Last File Created 02.02.2013 - 14:05:21 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1694.jpg [261600] O61 - LFC:Last File Created 02.02.2013 - 14:05:23 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1695.jpg [316070] O61 - LFC:Last File Created 02.02.2013 - 14:05:26 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1696.jpg [218805] O61 - LFC:Last File Created 02.02.2013 - 14:05:29 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1697.jpg [244903] O61 - LFC:Last File Created 02.02.2013 - 14:05:31 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1698.jpg [192738] O61 - LFC:Last File Created 02.02.2013 - 14:05:34 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1699.jpg [168411] O61 - LFC:Last File Created 02.02.2013 - 14:05:37 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1700.jpg [257893] O61 - LFC:Last File Created 02.02.2013 - 14:05:40 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1701.jpg [305746] O61 - LFC:Last File Created 02.02.2013 - 14:05:43 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1702.jpg [304258] O61 - LFC:Last File Created 02.02.2013 - 14:05:46 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1703.jpg [262804] O61 - LFC:Last File Created 02.02.2013 - 14:05:49 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1704.jpg [259827] O61 - LFC:Last File Created 02.02.2013 - 14:05:52 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1705.jpg [272195] O61 - LFC:Last File Created 02.02.2013 - 14:05:55 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1706.jpg [217725] O61 - LFC:Last File Created 02.02.2013 - 14:05:58 ---A- C:\Users\Isabel\Pictures\2013\01 - 29 Johanna zu Hause\DSCF1707.jpg [162732] O61 - LFC:Last File Created 02.02.2013 - 14:08:24 ---A- C:\Users\Isabel\AppData\Roaming\Adobe\Photoshop Elements\6.0\Editor\Adobe Photoshop Elements 6 Prefs.psp [163962] O61 - LFC:Last File Created 02.02.2013 - 14:08:24 ---A- C:\Users\Isabel\AppData\Roaming\Adobe\Photoshop Elements\6.0\Editor\Couleurs [562560] O61 - LFC:Last File Created 02.02.2013 - 14:08:24 ---A- C:\Users\Isabel\AppData\Roaming\Adobe\Photoshop Elements\6.0\Editor\PresetsCache.psp [22740] O61 - LFC:Last File Created 03.02.2013 - 12:23:46 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.000\53AE5752-F722-41FA-B854-27F73528E4BE.Diagnose.0.etl [196608] O61 - LFC:Last File Created 03.02.2013 - 12:23:49 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.000\NetworkConfiguration.cab [1855] O61 - LFC:Last File Created 03.02.2013 - 12:23:55 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.000\53AE5752-F722-41FA-B854-27F73528E4BE.Repair.1.etl [131072] O61 - LFC:Last File Created 03.02.2013 - 12:24:09 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.000\53AE5752-F722-41FA-B854-27F73528E4BE.Verify.2.etl [196608] O61 - LFC:Last File Created 03.02.2013 - 12:24:09 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.000\NetworkDiagnostics.0.debugreport.xml [73752] O61 - LFC:Last File Created 03.02.2013 - 12:24:09 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.000\results.xsl [49032] O61 - LFC:Last File Created 03.02.2013 - 12:25:38 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.000\NetworkDiagnostics.1.debugreport.xml [65442] O61 - LFC:Last File Created 03.02.2013 - 12:25:38 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.000\ResultReport.xml [47600] O61 - LFC:Last File Created 03.02.2013 - 12:25:38 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.000\results.xml [250] O61 - LFC:Last File Created 03.02.2013 - 12:27:09 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.001\results.xsl [49032] O61 - LFC:Last File Created 03.02.2013 - 12:27:15 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.001\6A9625C1-66B5-4C25-A023-1910F3F2F3DB.Diagnose.0.etl [196608] O61 - LFC:Last File Created 03.02.2013 - 12:27:16 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.001\NetworkConfiguration.cab [1869] O61 - LFC:Last File Created 03.02.2013 - 12:27:27 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.001\NetworkDiagnostics.0.debugreport.xml [68076] O61 - LFC:Last File Created 03.02.2013 - 12:27:27 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.001\ResultReport.xml [39013] O61 - LFC:Last File Created 03.02.2013 - 12:27:27 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\2013020311.001\results.xml [250] O61 - LFC:Last File Created 03.02.2013 - 12:27:27 ---A- C:\Users\Isabel\AppData\Local\Diagnostics\460911090\latest.cab [24064] O61 - LFC:Last File Created 03.02.2013 - 12:56:56 ----- C:\Users\Isabel\AppData\Local\Temp\acro_rd_dir\Cookies\index.dat [16384] O61 - LFC:Last File Created 03.02.2013 - 12:56:56 ----- C:\Users\Isabel\AppData\Local\Temp\acro_rd_dir\History\History.IE5\index.dat [16384] O61 - LFC:Last File Created 03.02.2013 - 13:33:25 ----- C:\Users\Isabel\AppData\Local\Temp\MSI89a1c.LOG [198186] O61 - LFC:Last File Created 03.02.2013 - 13:33:54 ----- C:\Users\Isabel\AppData\Local\Temp\MSI89a1d.LOG [431810] O61 - LFC:Last File Created 03.02.2013 - 14:08:52 ---A- C:\Users\Isabel\AppData\Roaming\Microsoft\MMC\taskschd [145158] O61 - LFC:Last File Created 03.02.2013 - 15:00:00 ----- C:\Users\Isabel\AppData\Local\Temp\nsvABE8.tmp\InetLoad.dll [62464] O61 - LFC:Last File Created 03.02.2013 - 15:00:00 ----- C:\Users\Isabel\AppData\Local\Temp\nsvABE8.tmp\babylon.dll [84992] O61 - LFC:Last File Created 03.02.2013 - 15:00:00 ----- C:\Users\Isabel\AppData\Local\Temp\nsvABE8.tmp\installutils.dll [125440] O61 - LFC:Last File Created 03.02.2013 - 15:01:13 ----- C:\Users\Isabel\AppData\Local\Temp\nsvABE8.tmp\nsis7z.dll [173056] O61 - LFC:Last File Created 03.02.2013 - 15:01:13 ----- C:\Users\Isabel\AppData\Local\Temp\nsvABE8.tmp\pack.7z [1173142] O61 - LFC:Last File Created 03.02.2013 - 15:01:54 ----- C:\Users\Isabel\AppData\Local\Temp\nsvABE8.tmp\18.7z [49152] O61 - LFC:Last File Created 03.02.2013 - 15:11:33 ----- C:\Users\Isabel\AppData\Local\Temp\jinstall.cfg [1354] O61 - LFC:Last File Created 03.02.2013 - 16:46:23 ----- C:\Users\Isabel\AppData\Local\Temp\MSIecca3.LOG [428256] O61 - LFC:Last File Created 03.02.2013 - 16:58:06 ---A- C:\Users\Isabel\AppData\Roaming\Microsoft\Office\Récent\Bewerbungsschreiben -Theater Freiburg.LNK [1045] O61 - LFC:Last File Created 03.02.2013 - 16:58:06 ---A- C:\Users\Isabel\AppData\Roaming\Microsoft\Office\Word11.pip [1728] O61 - LFC:Last File Created 03.02.2013 - 16:58:16 ---A- C:\Users\Isabel\AppData\Roaming\Microsoft\Office\Word12.pip [1684] O61 - LFC:Last File Created 03.02.2013 - 16:58:18 ---A- C:\Users\Isabel\AppData\Roaming\Microsoft\Office\Récent\Franck Ring1.LNK [925] O61 - LFC:Last File Created 03.02.2013 - 16:58:26 ---A- C:\Users\Isabel\AppData\Roaming\Microsoft\Office\Récent\Lebenslauf_20.01.2013[1].LNK [980] O61 - LFC:Last File Created 03.02.2013 - 16:58:27 ---A- C:\Users\Isabel\AppData\Roaming\Microsoft\Office\Récent\Bewerbung Ausbildung Theater.LNK [763] O61 - LFC:Last File Created 04.02.2013 - 11:29:39 ----- C:\Users\Isabel\AppData\Local\Temp\OutofProcReport929197.txt [1628] O61 - LFC:Last File Created 30.12.1899 - 15:37:59 --HA- C:\Users\Isabel\AppData\Local\IconCache.db [6291456] O61 - LFC:Last File Created 30.12.1899 - 16:58:27 --H-- C:\Users\Isabel\AppData\Roaming\Microsoft\Office\Récent\index.dat [1307] ~ Scan Files in 03mn 53s ---\\ List all tools cleaner (LATC) (O63) O63 - Logiciel: Ad-Remover par C_XX - (.C_XX.) [HKLM] -- Ad-Remover O63 - Logiciel: ZHPDiag 1.3.5 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 ~ Scan ADS in 00mn 00s ---\\ List all legacy services(LALS) (O64) O64 - Services: CurCS - 30.12.1899 - C:\Windows\System32\Drivers\aswFsBlk.sys (aswFsBlk) .(.AVAST Software - avast! File System Access Blocking Driver.) - LEGACY_ASWFSBLK O64 - Services: CurCS - 30.10.2012 - C:\windows\system32\drivers\aswMonFlt.sys (aswMonFlt) .(.AVAST Software - avast! File System Minifilter for Windows 2.) - LEGACY_ASWMONFLT O64 - Services: CurCS - 15.10.2012 - C:\Windows\system32\Drivers\aswrdr2.sys (aswRdr) .(.AVAST Software - avast! WFP Redirect Driver.) - LEGACY_ASWRDR O64 - Services: CurCS - 30.12.1899 - C:\Windows\System32\Drivers\aswSnx.sys (aswSnx) .(.AVAST Software - avast! Virtualization Driver.) - LEGACY_ASWSNX O64 - Services: CurCS - 30.12.1899 - C:\Windows\System32\Drivers\aswSP.sys (aswSP) .(.AVAST Software - avast! self protection module.) - LEGACY_ASWSP O64 - Services: CurCS - 30.12.1899 - C:\Windows\System32\Drivers\aswTdi.sys (aswTdi) .(.AVAST Software - avast! TDI Filter Driver.) - LEGACY_ASWTDI O64 - Services: CurCS - 28.05.2009 - C:\windows\system32\Drivers\SABI.sys (SABI) .(.SAMSUNG ELECTRONICS - SAMSUNG Kernel Driver.) - LEGACY_SABI O64 - Services: CurCS - 30.12.1899 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV ~ Scan Services in 00mn 01s ---\\ File Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Startprogramm für Ereignisanzeige-Snap-In.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registrierungs-Editor.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O67 - Shell Spawning: <.bat> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe O67 - Shell Spawning: <.cmd> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKCR\..\open\Command] (.Microsoft Corporation - Startprogramm für Ereignisanzeige-Snap-In.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O67 - Shell Spawning: <.js> [HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKCR\..\open\Command] (.Microsoft Corporation - Registrierungs-Editor.) -- C:\Windows\regedit.exe ~ Scan Keys in 00mn 00s ---\\ Start Menu Internet (SMI) (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe (.not file.) O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.) O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe (.not file.) O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.) O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe (.not file.) O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.) ~ Scan Keys in 00mn 00s ---\\ Search Browser Infection (SBI) (O69) O69 - SBI: SearchScopes [HKCU] ${searchCLSID} [DefaultScope] - (@ieframe.dll,-12512) - http://search.live.com O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {27EC6ECF-6DE9-4D1C-8B8D-FE64441577CE} - (Google) - http://www.google.com O69 - SBI: SearchScopes [HKCU] {67A2568C-7A0A-4EED-AECC-B5405DE63B64} - (Web Search) - http://startsear.ch O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (@ieframe.dll,-12512) - http://www.bing.com ~ Scan Keys in 00mn 00s ---\\ Search Svchost Services (SSS) (O83) O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Anwendungserfahrungdienst.) -- C:\Windows\System32\aelupsvc.dll [62464] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard-Zertifikatpropagierungsdienst.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard-Zertifikatpropagierungsdienst.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Serverdienst-DLL.) -- C:\Windows\System32\srvsvc.dll [168960] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Gruppenrichtlinienclient.) -- C:\Windows\System32\gpsvc.dll [593408] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE-Erweiterung.) -- C:\Windows\System32\ikeext.dll [674304] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows-Audiodienst.) -- C:\Windows\System32\Audiosrv.dll [473600] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - RAS-Verwaltung für automatisches Wählen.) -- C:\Windows\System32\rasauto.dll [90624] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - RAS-Verbindungsverwaltung.) -- C:\Windows\System32\rasmans.dll [286208] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamischer Schnittstellen-Manager.) -- C:\Windows\System32\mprdim.dll [75264] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Benachrichtigungsdienst für Systemereignisse.) -- C:\Windows\System32\sens.dll [49664] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT-Hilfskomponenten.) -- C:\Windows\System32\ipnathlp.dll [300544] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft(R) Windows(R) Telefonieserver.) -- C:\Windows\System32\tapisrv.dll [242176] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remoteverbindungs-Manager für Remotedesktop-Hostserver.) -- C:\Windows\System32\termsrv.dll [521216] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update-Agent.) -- C:\Windows\System32\wuaueng.dll [1933848] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Intelligenter Hintergrundübertragungsdienst.) -- C:\Windows\System32\qmgr.dll [585728] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows-Shelldienste-DLL.) -- C:\Windows\System32\shsvcs.dll [328192] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Dienst, der IPv6-Konnektivität über ein IPv4-Netzwerk bietet..) -- C:\Windows\System32\iphlpsvc.dll [499712] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL für sekundären Anmeldedienst.) -- C:\Windows\system32\seclogon.dll [21504] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Anwendungsinformationsdienst.) -- C:\Windows\System32\appinfo.dll [47104] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI-Ermittlungsdienst.) -- C:\Windows\System32\iscsiexe.dll [114688] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimediaklassen-Planungsdienst.) -- C:\Windows\System32\mmcss.dll [49664] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problemberichte und -lösungen.) -- C:\Windows\System32\wercplsupport.dll [61440] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost-Dienst.) -- C:\Windows\System32\eapsvc.dll [98304] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164352] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Aufgabenplanungsdienst.) -- C:\Windows\System32\schedsvc.dll [750592] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Schlüsselverwaltungsdienst.) -- C:\Windows\System32\kmsvc.dll [71168] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remotedesktop-Konfigurationsdienst.) -- C:\Windows\System32\sessenv.dll [113664] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computersuchdienst-DLL.) -- C:\Windows\System32\browser.dll [102912] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows-Shelldesigndienste-DLL.) -- C:\Windows\System32\themeservice.dll [37376] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE-Dienst.) -- C:\Windows\System32\bdesvc.dll [76800] ~ Scan Services in 00mn 00s ---\\ Search Particular Root Folder (SPRF) (O84) [MD5.1FE339E72FE03A27DD9D5A9A357CFE7D] [SPRF][17.08.2009] (...) -- C:\ProgramData\FullRemove.exe [131368] [MD5.9B0E9FD025A85C68708C69B7DABB4D85] [SPRF][17.01.2013] (...) -- C:\Users\Isabel\AppData\Local\Temp\ICReinstall_install_flashplayer11x32_mssd_aih.exe [667016] [MD5.E0A7D2C78B9B349FE6299285BCB02FE9] [SPRF][20.12.2012] (...) -- C:\Users\Isabel\AppData\Local\Temp\ICReinstall_Webplayer_FR.exe [1208696] [MD5.6B7CBE90162CB68B6382B6A9D726821D] [SPRF][21.03.2012] (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Users\Isabel\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe [908576] [MD5.107167F15D30AA71D7CAFC0326AFB315] [SPRF][08.06.2012] (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Users\Isabel\AppData\Local\Temp\jre-6u33-windows-i586-iftw.exe [909104] [MD5.8E51D3D38A26EEAC819974C9295AF35F] [SPRF][29.08.2012] (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Users\Isabel\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe [908272] [MD5.47C6B9B408CBB4DEE11A1EE517CD89BE] [SPRF][01.10.2012] (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Users\Isabel\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe [912880] [MD5.C6AA274F69EBDD86F75B7E3E4FA58AF4] [SPRF][31.01.2013] (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Users\Isabel\AppData\Local\Temp\jre-6u39-windows-i586-iftw.exe [915376] [MD5.AE7E0C99C5BC7D28325C0CD7885C851F] [SPRF][24.10.2012] (.Yontoo LLC - Installer.) -- C:\Users\Isabel\AppData\Local\Temp\YontooSetup-S.exe [1062504] [MD5.2D7A941C90C382788AC5E072B7A72A64] [SPRF][04.02.2013] (...) -- C:\Users\Isabel\Desktop\AdwCleaner.exe [582107] [MD5.A1F5F0A62DDE363C0A2CA399B863BD5C] [SPRF][04.02.2013] (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Isabel\Desktop\ZHPDiag2.exe [3724491] ~ Scan Files in 00mn 00s ---\\ Firewall Active Exception List (FirewallRules) (O87) O87 - FAEL: "NetPres-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.) O87 - FAEL: "NetPres-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.) O87 - FAEL: "NetPres-WSD-In-UDP" |In - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.) O87 - FAEL: "NetPres-WSD-Out-UDP" |Out - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.) O87 - FAEL: "NetPres-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.) O87 - FAEL: "NetPres-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.) O87 - FAEL: "{895FD37D-B4E0-46AB-88FB-684517B522C2}" | In - None - P6 - TRUE | .(.CyberLink Corp. - PowerDirector.) -- C:\Program Files\CyberLink\PowerDirector\PDR.exe O87 - FAEL: "{305F9C3B-6616-42C0-A09C-602E3015B637}" | In - None - P6 - TRUE | .(.CyberLink Corp. - PowerDVD 8.0.) -- C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe O87 - FAEL: "{485F75EA-4C9D-4335-8A42-195AAB8111D5}" |In - Domain - P6 - TRUE | .(...) -- C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe (.not file.) O87 - FAEL: "{375268CA-8295-48F7-92F5-5F97517569F8}" | In - Private - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe O87 - FAEL: "{B48D47EF-6898-4B65-B320-426DD7416459}" | In - Private - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe O87 - FAEL: "{AE908982-A474-4E3D-876F-F8CDAD885572}" | In - Private - P6 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files\iTunes\iTunes.exe O87 - FAEL: "{6B1E23B3-D8D4-46D7-83C1-CA9A75159F3F}" | In - Private - P17 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files\iTunes\iTunes.exe O87 - FAEL: "{FC0D8CBF-5B95-47FC-A029-29A61B83723E}" | In - Private - P6 - TRUE | .(.www.BitComet.com - BitComet - a BitTorrent Client.) -- C:\Program Files\BitComet\BitComet.exe O87 - FAEL: "{BB67FEC8-E228-4264-9691-C905385430A6}" | In - Private - P17 - TRUE | .(.www.BitComet.com - BitComet - a BitTorrent Client.) -- C:\Program Files\BitComet\BitComet.exe O87 - FAEL: "TCP Query User{085796F8-3AA9-484E-BBCC-D131C650DB20}C:\program files\google\google earth\plugin\geplugin.exe" | In - Private - P6 - TRUE | .(.Google - Google Earth.) -- C:\program files\google\google earth\plugin\geplugin.exe O87 - FAEL: "UDP Query User{79415409-F16C-497C-B4E0-6C48B039653E}C:\program files\google\google earth\plugin\geplugin.exe" | In - Private - P17 - TRUE | .(.Google - Google Earth.) -- C:\program files\google\google earth\plugin\geplugin.exe O87 - FAEL: "TCP Query User{2E085A22-46E9-4A9A-B34E-23B037F359C2}C:\users\isabel\appdata\roaming\spotify\spotify.exe" | In - Private - P6 - TRUE | .(.Spotify Ltd - Spotify.) -- C:\users\isabel\appdata\roaming\spotify\spotify.exe O87 - FAEL: "UDP Query User{5DFDCEBC-2731-4FB6-A6E1-4EB170D9F2BE}C:\users\isabel\appdata\roaming\spotify\spotify.exe" | In - Private - P17 - TRUE | .(.Spotify Ltd - Spotify.) -- C:\users\isabel\appdata\roaming\spotify\spotify.exe O87 - FAEL: "{78CA13A4-EA12-4051-9E4D-327AE5A3185D}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Iminent\Iminent.exe (.not file.) O87 - FAEL: "{3D887C8F-D3D9-4A05-AE46-7D7069E542FD}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Iminent\Iminent.Messengers.exe (.not file.) ~ Scan Firewall in 00mn 01s ---\\ Additionnal Scan (O88) Database Version : v2.10515 - (04.02.2013) Clés trouvées (Keys found) : 21 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 1 Fichiers trouvés (Files found) : 3 [HKLM\Software\Google\Chrome\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj] =>PUP.VShareRedir [HKLM\Software\Classes\CLSID\{35b8892d-c3fb-4d88-990d-31db2ebd72bd}] =>Adware.RecordNRip [HKLM\Software\Classes\Interface\{3f607e46-0d3c-4442-b1de-de7fa4768f5c}] =>Adware.RecordNRip [HKLM\Software\Classes\TypeLib\{93e3d79c-0786-48ff-9329-93bc9f6dc2b3}] =>Adware.RecordNRip [HKLM\Software\Classes\Interface\{fe0273d1-99df-4ac0-87d5-1371c6271785}] =>Adware.RecordNRip [HKLM\Software\Classes\CLSID\{03F14321-8FED-4CBC-B01A-4B57FC199062}] =>PUP.BearShare [HKLM\Software\Classes\CLSID\{2C6F7E96-73BC-47A5-9F51-B67F0BAFE24D}] =>PUP.BearShare [HKLM\Software\Classes\CLSID\{4C58EB04-7B72-4D3D-A36E-66167A99BC31}] =>PUP.BearShare [HKLM\Software\Classes\CLSID\{4EE0B011-604C-47F3-8F2B-39F79640B85E}] =>PUP.BearShare [HKLM\Software\Classes\CLSID\{6BC38BF4-E84D-46E1-920B-42D31AEA617E}] =>Toolbar.Agent [HKLM\Software\Classes\TypeLib\{6C9945B7-1D19-46CB-88C0-45A24DF6CD6E}] =>PUP.iMesh [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}] =>PUP.VShareRedir [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}] =>PUP.VShareRedir [HKLM\Software\Classes\TypeLib\{84B9B044-17C0-48FB-A300-C9747D5DF29C}] =>PUP.iMesh [HKLM\Software\Classes\AppID\{F54A0D21-6A53-460C-8301-C694EC9E1033}] =>PUP.iMesh [HKLM\Software\Classes\AppID\{F7BCCFD4-2FA6-477D-A1B0-EF7500B3C49E}] =>PUP.iMesh [HKLM\Software\Classes\AppID\NCTAudioCompress3.DLL] =>PUP.BearShare [HKLM\Software\Classes\AppID\NCTAudioFormatSettings3.DLL] =>PUP.BearShare [HKCU\Software\vShare.tv] =>PUP.VShareRedir [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]:Shell =>Hijack.Shell.Gen [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\vShare.tv plugin] =>PUP.VShareRedir C:\ProgramData\Browser Manager =>Toolbar.Babylon C:\Users\Isabel\AppData\Local\Temp\YontooSetup-S.exe =>Toolbar.Alot C:\Users\Isabel\AppData\Local\Temp\YontooSetup-S.exe => Infection PUP (Adware.Yontoo) ~ Scan Additionnel in 00mn 12s ---\\ Router Hijack DNS (O89) (None) ---\\ Product Upgrade Codes (O90) O90 - PUC: "00002109020070400000000000F01FEC" . (.Compatibility Pack für 2007 Office System.) -- C:\windows\Installer\{90120000-0020-0407-0000-0000000FF1CE}\O12ConvIcon.exe O90 - PUC: "041B2CCCA74BAF54AA3EDB06AD14EA00" . (.Samsung Support Center.) -- C:\windows\Installer\{CCC2B140-B47A-45FA-AAE3-BD60DA41AE00}\_6FEFF9B68218417F98F549.exe O90 - PUC: "098990BCF5D15D11E99A0005AB3E711E" . (.PowerDirector.) -- C:\windows\Installer\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\ARPPRODUCTICON.exe O90 - PUC: "0BCD4392EE8F0E114A5A8BCAF6798BE8" . (.Google Earth Plug-in.) -- C:\windows\Installer\{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}\ARPPRODUCTICON.exe O90 - PUC: "14A8F3589C3AAF3478AFA17EF46C3F7F" . (.BatteryLifeExtender.) -- C:\windows\Installer\{853F8A41-A3C9-43FA-87FA-1AE74FC6F3F7}\_6FEFF9B68218417F98F549.exe O90 - PUC: "1D034B0FAA6BD374B960AAD30DF10D8B" . (.Microsoft SQL Server 2005 Compact Edition [ENU].) -- C:\windows\Installer\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}\ProductIcon O90 - PUC: "1D227AB21D84E6041932A85E34D136FE" . (.Windows Live Fotogalerie.) -- C:\windows\Installer\{2BA722D1-48D1-406E-9123-8AE5431D63EF}\WLXPhotoGalleryIcon.exe O90 - PUC: "20481667D97199646AB63D155C4963CB" . (.Windows Live Sync.) -- C:\windows\Installer\{76618402-179D-4699-A66B-D351C59436BC}\FolderShare48x48.ico O90 - PUC: "2DE19958C010039469AF254FC3C29EA8" . (.Apple Mobile Device Support.) -- C:\windows\Installer\{85991ED2-010C-4930-96FA-52F43C2CE98A}\Installer.ico O90 - PUC: "38E1FB04BE028D11795C00905C206085" . (.Power2Go.) -- C:\windows\Installer\{40BF1E83-20EB-11D8-97C5-0009C5020658}\ARPPRODUCTICON.exe O90 - PUC: "3F322499B99ADDD4E9D110091AC78606" . (.Windows Live Family Safety.) -- C:\windows\Installer\{994223F3-A99B-4DDD-9E1D-0190A17C6860}\fssicon.ico O90 - PUC: "3F3F7F1908EC3C843872D7420A5A17A6" . (.iTunes.) -- C:\windows\Installer\{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}\Installer.ico O90 - PUC: "42C6FBF1DF1C10144AB2C065F4E9E897" . (.PowerStarter.) -- C:\windows\Installer\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\ARPPRODUCTICON.exe O90 - PUC: "430E0D9324015094EBBC552009F9BCC7" . (.Microsoft Works.) -- C:\windows\Installer\{39D0E034-1042-4905-BECB-5502909FCB7C}\MSWorks.exe O90 - PUC: "60EC0A7BE8606D1179DF0005ABBC8F16" . (.PowerProducer.) -- C:\windows\Installer\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\ARPPRODUCTICON.exe O90 - PUC: "68AB67CA7DA71301B7449A0500000010" . (.Adobe Reader 9.5.3 - Deutsch.) -- C:\windows\Installer\{AC76BA86-7AD7-1031-7B44-A95000000001}\SC_Reader.ico O90 - PUC: "68AB67CA7DA746454382090000000040" . (.Spelling Dictionaries Support For Adobe Reader 9.) -- C:\windows\Installer\{AC76BA86-7AD7-5464-3428-900000000004}\ARPPRODUCTICON.exe O90 - PUC: "7040E10900063D11C8EF10054038389C" . (.Microsoft Office 2003 German User Interface Pack.) -- C:\windows\Installer\{901E0407-6000-11D3-8CFE-0150048383C9}\misc.exe,6 O90 - PUC: "7CEBB04F4A2C00A4B942A750A5C22526" . (.Microsoft Office Live Add-in 1.5.) -- C:\windows\Installer\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}\ProductIcon O90 - PUC: "7F837D4CA69918C48BAF4C2ED667E714" . (.Windows Live Mail.) -- C:\windows\Installer\{C4D738F7-996A-4C81-B8FA-C4E26D767E41}\wlmail.exe O90 - PUC: "81279B25BC89B8B429382D318CE5A14A" . (.Windows Live Anmelde-Assistent.) -- C:\windows\Installer\{52B97218-98CB-4B8B-9283-D213C85E1AA4}\prodicon.ico O90 - PUC: "8994BF104C33134458DE70E9E3FE7ED5" . (.YouCam.) -- C:\windows\Installer\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\ARPPRODUCTICON.exe O90 - PUC: "9040420900063D11C8EF10054038389C" . (.Microsoft Office 2003 Resource Kit.) -- C:\windows\Installer\{90240409-6000-11D3-8CFE-0150048383C9}\misc.exe,6 O90 - PUC: "9A456E140D62CAE458B4F08A42FFAFBB" . (.Windows Live Messenger.) -- C:\windows\Installer\{41E654A9-26D0-4EAC-854B-0FA824FFFABB}\MsblIco.Exe O90 - PUC: "9B00314CD581E574FBCE93FE37F2911B" . (.Apple Software Update.) -- C:\windows\Installer\{C41300B9-185D-475E-BFEC-39EF732F19B1}\Installer.ico O90 - PUC: "BB2989D3157A84E4DA8C4E829965ECD1" . (.QuickTime.) -- C:\windows\Installer\{3D9892BB-A751-4E48-ADC8-E4289956CE1D}\Installer.ico O90 - PUC: "C040110900063D11C8EF10054038389C" . (.Microsoft Office Professional Edition 2003.) -- C:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe,6 O90 - PUC: "C971C95CD8669A946BAE1012CCCF2134" . (.LabelPrint.) -- C:\windows\Installer\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\ARPPRODUCTICON.exe O90 - PUC: "D5084A0EA0827DD4E947A3F5583E201A" . (.Windows Live Writer.) -- C:\windows\Installer\{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}\ApplicationIcon.ico O90 - PUC: "D7314F9862C648A4DB8BE2A5B47BE100" . (.Microsoft Silverlight.) -- C:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ARPIcon O90 - PUC: "D8669BC0979F13F48B8B76EF099F928F" . (.Bonjour.) -- C:\windows\Installer\{0CB9668D-F979-4F31-B8B8-67FE90F929F8}\Bonjour.ico O90 - PUC: "DDB6C50237B7ED245850A990F3532A83" . (.Windows Live-Uploadtool.) -- C:\windows\Installer\{205C6BDD-7B73-42DE-8505-9A093F35A238}\RichUpload.ico O90 - PUC: "E9A5765A370FA414A9409FCB5D40957D" . (.Easy Network Manager.) -- C:\windows\Installer\{A5675A9E-F073-414A-9A04-F9BCD50459D7}\_6FEFF9B68218417F98F549.exe O90 - PUC: "EB823D2BDA5429D4699F121594A002E3" . (.Apple Application Support.) -- C:\windows\Installer\{B2D328BE-45AD-4D92-96F9-2151490A203E}\WinInstall.ico O90 - PUC: "F13E2FB2BB8B7A046B05892DE8F0D774" . (.PowerDVD.) -- C:\windows\Installer\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\ARPPRODUCTICON.exe ~ Scan Files in 00mn 00s ---\\ MyComputer Name Space (O92) O92 - MNS: Dossiers Web - {BDEADF00-C265-11D0-BCED-00A0C90AB50F} ~ Scan MNS in 00mn 00s ---\\ General States of Services not Microsoft (EGS) (R=Running, S=Stopped) SS - | Demand 17.01.2013 251400 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe SR - | Auto 10.06.2010 144176 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe SR - | Auto 30.10.2012 44808 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe SS - | Demand 28.12.2010 1296728 | (BITCOMET_HELPER_SERVICE) . (.www.BitComet.com.) - C:\Program Files\BitComet\tools\BitCometService.exe SR - | Auto 18.05.2010 345376 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe SS - | Demand 11.08.2010 654848 | (FLEXnet Licensing Service) . (.Macrovision Europe Ltd..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe SS - | Auto 25.10.2010 136176 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Demand 25.10.2010 136176 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SR - | Demand 21.07.2010 540968 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe SS - | Demand 19.01.2013 115608 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe SR - | Auto 44312 | (OberonGameConsoleService) . (...) - C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe SR - | Auto 247152 | (RichVideo) . (...) - C:\Program Files\CyberLink\Shared files\RichVideo.exe SR - | Auto 14.07.2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 14.07.2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Scan Services in 00mn 03s ---\\ Search Master Boot Record Infection (MBR)(O80) Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net ~ Scan MBR in 00mn 02s ---\\ Search Master Boot Record Infection (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by Isabel at 04.02.2013 16:00:28 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ Scan MBR in 00mn 04s End of the scan (1539 lines in 08mn 05s)(0)