O1 HOSTS File: ([2012.05.16 20:35:31 | 000,442,859 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 15218 more lines...
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-89AF-189327213627} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\hallo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Web-Suche - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ITCCH.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{32084FF4-CC0A-4146-823B-4E41460DC952}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\hallo\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\hallo\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{5a1221f3-0102-11df-8d5a-efd97ae7ef42}\Shell - "" = AutoRun
O33 - MountPoints2\{5a1221f3-0102-11df-8d5a-efd97ae7ef42}\Shell\AutoRun\command - "" = G:\Start.exe
O33 - MountPoints2\{5bb68dd3-2ce4-11df-b13e-00ade1ac1c1a}\Shell - "" = AutoRun
O33 - MountPoints2\{5bb68dd3-2ce4-11df-b13e-00ade1ac1c1a}\Shell\AutoRun\command - "" = G:\Start.exe
O33 - MountPoints2\{5bb68def-2ce4-11df-b13e-001e101f8924}\Shell - "" = AutoRun
O33 - MountPoints2\{5bb68def-2ce4-11df-b13e-001e101f8924}\Shell\AutoRun\command - "" = G:\Start.exe
O33 - MountPoints2\{9f39b4d3-0104-11df-9120-00ade1ac1c1a}\Shell - "" = AutoRun
O33 - MountPoints2\{9f39b4d3-0104-11df-9120-00ade1ac1c1a}\Shell\AutoRun\command - "" = G:\Start.exe
O33 - MountPoints2\{9f39b4ef-0104-11df-9120-001e101fb681}\Shell - "" = AutoRun
O33 - MountPoints2\{9f39b4ef-0104-11df-9120-001e101fb681}\Shell\AutoRun\command - "" = G:\Start.exe
O33 - MountPoints2\{a7e75b73-2b82-11df-94eb-0025b343bb89}\Shell - "" = AutoRun
O33 - MountPoints2\{a7e75b73-2b82-11df-94eb-0025b343bb89}\Shell\AutoRun\command - "" = G:\Start.exe
O33 - MountPoints2\{ab7e4374-2b84-11df-a2c6-00247e5bed1b}\Shell - "" = AutoRun
O33 - MountPoints2\{ab7e4374-2b84-11df-a2c6-00247e5bed1b}\Shell\AutoRun\command - "" = G:\Start.exe
O33 - MountPoints2\{ab7e4376-2b84-11df-a2c6-fb809831f4d0}\Shell - "" = AutoRun
O33 - MountPoints2\{ab7e4376-2b84-11df-a2c6-fb809831f4d0}\Shell\AutoRun\command - "" = H:\Start.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012.05.17 00:00:00 | 000,018,816 | ---- | C] (Sophos Group) -- C:\windows\System32\SAVRKBootTasks.sys
[2012.05.16 23:12:40 | 000,000,000 | ---D | C] -- C:\Users\hallo\AppData\Roaming\Malwarebytes
[2012.05.16 23:12:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.05.16 23:12:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.05.16 23:11:59 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys
[2012.05.16 23:11:59 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.05.16 22:12:29 | 000,000,000 | ---D | C] -- C:\windows\QLB
[2012.05.16 22:12:21 | 000,000,000 | ---D | C] -- C:\windows\LastGood
[2012.05.16 22:09:21 | 000,000,000 | ---D | C] -- C:\Users\hallo\AppData\Local\Adobe
[2012.05.16 21:41:33 | 000,000,000 | ---D | C] -- C:\Users\hallo\AppData\Roaming\Macromedia
[2012.05.16 21:24:08 | 000,000,000 | ---D | C] -- C:\Program Files\SweetIM
[2012.05.16 21:23:04 | 000,000,000 | ---D | C] -- C:\Program Files\RegSupreme
[2012.05.16 21:14:31 | 000,000,000 | ---D | C] -- C:\Users\hallo\AppData\Roaming\Adobe
[2012.05.16 20:29:24 | 000,000,000 | ---D | C] -- C:\Users\hallo\AppData\Local\Mozilla
[2012.05.16 20:29:23 | 000,000,000 | ---D | C] -- C:\Users\hallo\AppData\Roaming\Mozilla
[2012.05.09 10:16:59 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d3d10warp.dll
[2012.05.09 10:16:59 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\DWrite.dll
[2012.05.09 10:16:59 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d2d1.dll
[2012.05.09 10:16:59 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d3d10_1core.dll
[2012.05.09 10:16:59 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d3d10_1.dll
[2012.05.09 10:16:53 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ntoskrnl.exe
[2012.05.09 10:16:52 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ntkrnlpa.exe
[2012.05.09 10:16:52 | 002,044,928 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\win32k.sys
[2012.05.04 12:47:32 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonIJScan
[2012.04.27 20:37:27 | 000,962,560 | ---- | C] (East Wind Software) -- C:\windows\System32\advdaudio.ocx
[2012.04.27 20:37:27 | 000,634,880 | ---- | C] (Online Media Technologies Ltd.) -- C:\windows\System32\NCTAudioEditor2.dll
[2012.04.27 20:37:27 | 000,522,752 | ---- | C] (Online Media Technologies Ltd.) -- C:\windows\System32\NCTAudioTransform2.dll
[2012.04.27 20:37:26 | 000,966,144 | ---- | C] (Online Media Technologies Ltd.) -- C:\windows\System32\NCTAudioInformation2.dll
[2012.04.27 20:37:26 | 000,877,568 | ---- | C] (NCT Company Ltd.) -- C:\windows\System32\NCTAudioFile2.dll
[2012.04.27 20:37:26 | 000,467,968 | ---- | C] (Online Media Technologies Ltd.) -- C:\windows\System32\NCTAudioRecord2.dll
[2012.04.27 20:37:26 | 000,467,456 | ---- | C] (Online Media Technologies Ltd.) -- C:\windows\System32\NCTAudioPlayer2.dll
[2012.04.27 20:37:25 | 000,413,696 | ---- | C] (Gabest) -- C:\windows\System32\flvsplitter.ax
[3 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
[1 C:\windows\System32\drivers\*.tmp files -> C:\windows\System32\drivers\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.05.16 23:58:46 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys
[2012.05.16 23:34:54 | 000,003,216 | ---- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.05.16 23:34:54 | 000,003,216 | ---- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.05.16 22:21:02 | 000,083,613 | ---- | M] () -- C:\Users\hallo\Desktop\31660_430230787064_291586927064_5114870_3605342_n.jpg
[2012.05.16 21:36:55 | 000,000,012 | ---- | M] () -- C:\windows\bthservsdp.dat
[2012.05.16 21:34:37 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012.05.16 20:35:31 | 000,442,859 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts
[2012.05.16 20:30:20 | 000,442,859 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts.20120516-203531.backup
[2012.05.16 20:27:51 | 000,442,859 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts.20120516-203020.backup
[2012.05.16 18:41:12 | 000,442,859 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts.20120516-202751.backup
[2012.05.16 18:37:40 | 000,442,859 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts.20120516-184112.backup
[2012.05.16 18:12:45 | 000,442,859 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts.20120516-183739.backup
[2012.05.09 12:04:50 | 000,377,056 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2012.05.09 11:54:36 | 000,637,554 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2012.05.09 11:54:36 | 000,121,058 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2012.05.09 11:54:35 | 000,678,342 | ---- | M] () -- C:\windows\System32\perfh007.dat
[2012.05.09 11:54:35 | 000,147,494 | ---- | M] () -- C:\windows\System32\perfc007.dat
[2012.04.25 14:43:48 | 000,442,689 | R--- | M] () -- C:\windows\System32\drivers\etc\hosts.20120516-181245.backup
[2012.04.25 09:54:28 | 001,598,464 | ---- | M] () -- C:\Users\hallo\Documents\Was_es_bedeutet_ARM_zu_sein1.pps
[3 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
[1 C:\windows\System32\drivers\*.tmp files -> C:\windows\System32\drivers\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.05.16 22:20:59 | 000,083,613 | ---- | C] () -- C:\Users\hallo\Desktop\31660_430230787064_291586927064_5114870_3605342_n.jpg
[2012.04.27 20:37:27 | 000,110,080 | ---- | C] () -- C:\windows\System32\advd.dll
[2012.04.27 20:37:27 | 000,023,040 | ---- | C] () -- C:\windows\System32\auth.dll
[2012.04.27 20:37:25 | 000,511,488 | ---- | C] () -- C:\windows\System32\lame_enc.dll
[2012.01.01 21:27:22 | 000,000,146 | ---- | C] () -- C:\windows\WININIT.INI
[2011.01.27 10:34:05 | 000,000,229 | ---- | C] () -- C:\windows\Brpfx04a.ini
[2011.01.27 10:34:05 | 000,000,093 | ---- | C] () -- C:\windows\brpcfx.ini
[2011.01.27 10:34:05 | 000,000,050 | ---- | C] () -- C:\windows\System32\bd9840cn.dat
[2011.01.27 10:31:12 | 000,000,066 | ---- | C] () -- C:\windows\Brfaxrx.ini
[2011.01.27 10:31:11 | 000,000,000 | ---- | C] () -- C:\windows\brdfxspd.dat
[2011.01.27 10:31:10 | 000,106,496 | ---- | C] () -- C:\windows\System32\BrMuSNMP.dll
[2011.01.27 10:29:33 | 000,031,664 | ---- | C] () -- C:\windows\maxlink.ini
[2010.09.18 11:30:02 | 000,000,432 | ---- | C] () -- C:\windows\BRWMARK.INI
[2010.09.18 11:30:02 | 000,000,026 | ---- | C] () -- C:\windows\BRPP2KA.INI
[2010.09.18 11:30:00 | 000,000,034 | ---- | C] () -- C:\windows\System32\bd9840cd.dat
[2010.09.18 11:29:32 | 000,000,000 | ---- | C] () -- C:\Program Files\error.dat
[2010.09.18 11:29:32 | 000,000,000 | ---- | C] () -- C:\windows\brmx2001.ini
[2010.09.18 11:29:21 | 000,045,056 | ---- | C] () -- C:\windows\System32\BRTCPCON.DLL
[2010.09.18 11:29:19 | 000,000,114 | ---- | C] () -- C:\windows\System32\BRLMW03A.INI
[2010.09.18 11:29:19 | 000,000,050 | ---- | C] () -- C:\windows\System32\BAOCH06A.DAT
========== LOP Check ==========
[2012.05.16 19:48:28 | 000,032,536 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\windows\$NtUninstallKB62280$] -> Error: Cannot create file handle -> Unknown point type
< End of report >