Lofile 1, Teil 3
[2012.12.12 17:29:44 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2012.12.12 17:29:44 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2012.12.12 17:29:44 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2012.12.12 17:29:28 | 002,345,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012.12.12 17:29:25 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2012.12.12 17:29:25 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2012.12.12 17:29:16 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012.12.12 01:32:42 | 000,000,000 | ---D | C] -- C:\Users\meinname\Citrix
[4 C:\Users\meinname\Desktop\*.tmp files -> C:\Users\meinname\Desktop\*.tmp -> ]
[1 C:\Users\meinname\AppData\Roaming\*.tmp files -> C:\Users\meinname\AppData\Roaming\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.12.16 16:01:03 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.12.16 13:14:16 | 000,014,976 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.12.16 13:14:16 | 000,014,976 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.12.16 13:06:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.12.16 13:05:59 | 1508,081,664 | -HS- | M] () -- C:\hiberfil.sys
[2012.12.13 10:26:46 | 000,295,536 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.12.12 10:48:10 | 000,029,839 | ---- | M] () -- C:\Users\meinname\Desktop\Handout Kolloquium kurz.odt
[2012.12.12 10:48:09 | 000,000,100 | -H-- | M] () -- C:\Users\meinname\Desktop\.~lock.Handout Kolloquium kurz.odt#
[2012.12.12 10:33:50 | 000,030,144 | ---- | M] () -- C:\Users\meinname\Desktop\Handout Kolloquium.odt
[2012.12.12 02:01:36 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.12.12 02:01:36 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.12.10 11:55:45 | 000,028,326 | ---- | M] () -- C:\Users\meinname\Desktop\Protokoll 6oder so Figal.odt
[2012.12.10 11:55:43 | 000,000,100 | -H-- | M] () -- C:\Users\meinname\Desktop\.~lock.Protokoll 6oder so Figal.odt#
[2012.12.03 11:49:38 | 000,031,744 | ---- | M] () -- C:\Users\meinname\Desktop\protokoll4odersoFigal.odt
[2012.12.01 23:33:49 | 000,227,840 | ---- | M] () -- C:\Users\meinname\Desktop\Hausarbeit Hauptseminar meinname Kiefer 1.12..pdf
[2012.11.25 21:30:52 | 000,654,610 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.11.25 21:30:52 | 000,616,452 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.11.25 21:30:52 | 000,130,192 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.11.25 21:30:52 | 000,106,574 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.11.22 03:56:02 | 002,345,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[4 C:\Users\meinname\Desktop\*.tmp files -> C:\Users\meinname\Desktop\*.tmp -> ]
[1 C:\Users\meinname\AppData\Roaming\*.tmp files -> C:\Users\meinname\AppData\Roaming\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.12.12 10:34:07 | 000,000,100 | -H-- | C] () -- C:\Users\meinname\Desktop\.~lock.Handout Kolloquium kurz.odt#
[2012.12.12 10:34:05 | 000,029,839 | ---- | C] () -- C:\Users\meinname\Desktop\Handout Kolloquium kurz.odt
[2012.12.12 03:08:24 | 000,030,144 | ---- | C] () -- C:\Users\meinname\Desktop\Handout Kolloquium.odt
[2012.12.10 11:55:43 | 000,000,100 | -H-- | C] () -- C:\Users\meinname\Desktop\.~lock.Protokoll 6oder so Figal.odt#
[2012.12.10 11:55:41 | 000,028,326 | ---- | C] () -- C:\Users\meinname\Desktop\Protokoll 6oder so Figal.odt
[2012.12.03 11:49:35 | 000,031,744 | ---- | C] () -- C:\Users\meinname\Desktop\protokoll4odersoFigal.odt
[2012.12.01 23:33:49 | 000,227,840 | ---- | C] () -- C:\Users\meinname\Desktop\Hausarbeit Hauptseminar meinname Kiefer 1.12..pdf
[2012.08.15 09:05:02 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012.08.15 09:05:02 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2012.07.12 14:22:41 | 000,000,051 | ---- | C] () -- C:\Users\meinname\AppData\Roaming\blckdom.res
[2012.06.14 14:20:25 | 000,256,618 | ---- | C] () -- C:\Windows\hpwins24.dat
[2012.06.14 14:20:25 | 000,001,758 | ---- | C] () -- C:\Windows\hpwmdl24.dat
[2012.05.24 11:35:31 | 000,081,408 | ---- | C] () -- C:\Windows\cadkasdeinst01.exe
[2012.04.15 17:04:15 | 000,000,391 | ---- | C] () -- C:\Windows\cdplayer.ini
[2012.03.05 12:17:45 | 000,451,072 | ---- | C] () -- C:\Windows\System32\ISSRemoveSP.exe
[2012.03.04 12:27:41 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2012.03.03 17:21:17 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2012.03.03 17:21:16 | 000,654,610 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2012.03.03 17:21:16 | 000,130,192 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2012.03.03 17:21:16 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2012.03.02 23:38:31 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.06.10 06:34:52 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
========== ZeroAccess Check ==========
[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012.07.12 14:22:53 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\13001.022
[2012.07.12 19:08:36 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\13001.023
[2012.03.30 20:47:12 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\Amazon
[2012.05.24 11:35:45 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\CAD-KAS
[2012.12.16 13:08:01 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\Dropbox
[2012.11.06 20:23:22 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\Foxit Software
[2012.07.12 14:22:14 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\kock
[2012.03.14 16:10:48 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\Lingo4u
[2012.04.08 14:27:51 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\NesterSoft
[2012.04.10 21:20:41 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\OpenOffice.org
[2012.05.24 12:20:42 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\pdfforge
[2012.12.09 00:57:54 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\SoftGrid Client
[2012.03.03 15:57:16 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\toshiba
[2012.03.03 16:21:15 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\TP
[2012.07.12 17:59:41 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\UAs
[2012.08.03 12:20:00 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\Vyeq
[2012.03.03 15:10:42 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\WinBatch
[2012.07.12 18:00:13 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\xmldm
[2012.08.02 23:34:25 | 000,000,000 | ---D | M] -- C:\Users\meinname\AppData\Roaming\Zyyf
========== Purity Check ==========
< End of report >