========== Files/Folders - Created Within 30 Days ==========
[2013.01.19 12:58:09 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Marco Sauer\Desktop\OTL.exe
[2013.01.19 12:00:04 | 000,000,000 | ---D | C] -- C:\ProgramData\XoftSpySE
[2013.01.19 11:44:22 | 000,000,000 | R--D | C] -- C:\Backup
[2013.01.19 11:40:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky PURE 2.0
[2013.01.19 11:39:22 | 000,088,632 | ---- | C] (Infowatch) -- C:\Windows\System32\drivers\CSCrySec.sys
[2013.01.19 11:39:22 | 000,039,352 | ---- | C] (Infowatch) -- C:\Windows\System32\drivers\CSVirtualDiskDrv.sys
[2013.01.19 11:37:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InfoWatch
[2013.01.19 11:36:51 | 000,000,000 | ---D | C] -- C:\Program Files\Kaspersky Lab
[2013.01.19 11:36:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2013.01.19 11:34:45 | 000,585,560 | ---- | C] (Kaspersky Lab) -- C:\Windows\System32\drivers\klif.sys
[2013.01.18 22:35:18 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonRnR
[2013.01.18 22:34:21 | 006,260,632 | ---- | C] (Symantec Corporation) -- C:\Users\Marco Sauer\Desktop\NRnR.exe
[2012.10.29 20:14:49 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\ProgramData\lsass.exe
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.01.19 15:48:44 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.01.19 15:48:44 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.01.19 15:21:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.01.19 12:58:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Marco Sauer\Desktop\OTL.exe
[2013.01.19 12:11:27 | 000,002,463 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
[2013.01.19 11:53:13 | 000,696,180 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.01.19 11:53:13 | 000,651,512 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.01.19 11:53:13 | 000,154,642 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.01.19 11:53:13 | 000,125,718 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.01.19 11:46:58 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.01.19 11:46:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.01.19 11:45:03 | 000,017,408 | ---- | M] () -- C:\Users\Marco Sauer\AppData\Local\WebpageIcons.db
[2013.01.19 11:40:28 | 000,116,189 | ---- | M] () -- C:\Windows\System32\drivers\klin.dat
[2013.01.19 11:40:28 | 000,098,168 | ---- | M] () -- C:\Windows\System32\drivers\klick.dat
[2013.01.19 11:34:45 | 000,585,560 | ---- | M] (Kaspersky Lab) -- C:\Windows\System32\drivers\klif.sys
[2013.01.19 11:10:00 | 000,000,931 | ---- | M] () -- C:\Users\Marco Sauer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk
[2013.01.18 22:34:23 | 006,260,632 | ---- | M] (Symantec Corporation) -- C:\Users\Marco Sauer\Desktop\NRnR.exe
[2013.01.18 22:18:15 | 000,008,268 | ---- | M] () -- C:\Users\Marco Sauer\AppData\Local\d3d9caps.dat
[2013.01.18 22:17:42 | 000,002,279 | ---- | M] () -- C:\Users\Public\Desktop\Norton Security Scan.lnk
[2013.01.18 20:33:28 | 000,002,004 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.12.28 20:53:23 | 000,003,584 | ---- | M] () -- C:\Users\Marco Sauer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.01.19 11:45:01 | 000,017,408 | ---- | C] () -- C:\Users\Marco Sauer\AppData\Local\WebpageIcons.db
[2013.01.19 11:40:28 | 000,116,189 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat
[2013.01.19 11:40:28 | 000,098,168 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat
[2013.01.19 11:10:00 | 000,000,931 | ---- | C] () -- C:\Users\Marco Sauer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk
[2012.10.29 20:14:51 | 083,023,306 | ---- | C] () -- C:\ProgramData\netdislw.pad
[2011.03.11 12:43:54 | 000,029,763 | ---- | C] () -- C:\Windows\System32\drivers\klopp.dat
[2010.06.28 19:55:30 | 000,004,096 | -H-- | C] () -- C:\Users\Marco Sauer\AppData\Local\keyfile3.drm
[2010.01.27 16:40:45 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009.05.18 05:04:05 | 000,008,268 | ---- | C] () -- C:\Users\Marco Sauer\AppData\Local\d3d9caps.dat
[2009.04.06 23:26:40 | 177,579,487 | ---- | C] () -- C:\Users\Marco Sauer\upix3_tbyb_g.exe
[2009.04.06 22:44:42 | 000,000,817 | ---- | C] () -- C:\Users\Marco Sauer\.recently-used.xbel
[2008.11.15 15:15:55 | 000,000,168 | RHS- | C] () -- C:\ProgramData\F0930BEFD2.sys
[2008.11.15 15:15:54 | 000,002,516 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2008.06.27 19:55:08 | 001,404,280 | ---- | C] () -- C:\Users\Marco Sauer\setup_dm_Fotowelt.exe
[2008.03.14 13:45:27 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2007.09.05 10:17:57 | 000,060,968 | ---- | C] () -- C:\Users\Marco Sauer\GoToAssistDownloadHelper.exe
[2007.03.19 20:20:42 | 000,017,350 | ---- | C] () -- C:\Users\Marco Sauer\AppData\Roaming\wklnhst.dat
[2007.03.16 14:01:15 | 000,003,584 | ---- | C] () -- C:\Users\Marco Sauer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006.11.02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
= %SystemRoot%\system32\shell32.dll -- [2011.01.21 16:46:32 | 011,582,464 | ---- | M] (Microsoft Corporation)
ThreadingModel = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
= %systemroot%\system32\wbem\fastprox.dll -- [2009.03.03 05:36:24 | 000,615,424 | ---- | M] (Microsoft Corporation)
ThreadingModel = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
= %systemroot%\system32\wbem\wbemess.dll -- [2008.01.19 08:36:49 | 000,347,648 | ---- | M] (Microsoft Corporation)
ThreadingModel = Both
========== Alternate Data Streams ==========
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP
FC5A2B2
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\Updater5:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\Symantec:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\samsung:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\restore:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\My PSP Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\My Albums:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\Meine Snapfire Shows:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\Meine empfangenen Dateien:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\Meine Corel-Shows:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\Mein Geschenk_mcf-Dateien:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\McafeeRootkitDetective11[1]:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\IMG_2244.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\Fotobuch__NINI_mcf-Dateien:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\Envisioneer 4.5Express:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\Envisioneer 4.5 Express:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\Eigene Google Gadgets:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\Eigene Datenquellen:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\Downloads:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\CDBurnerXP Projects:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\330.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\329.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\328.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\327.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\326.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\325.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\324.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\323.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\322.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\321.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\320.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\319.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\318.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\317.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\316.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\315.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\314.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\313.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\312.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\311.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\310.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\308.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\307.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\306.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\305.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\304.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\303.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\302.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\301.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\300.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\299.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\298.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\297.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\296.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\295.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\294.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\293.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\292.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\291.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\290.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\289.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\288.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\287.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\286.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\284.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\283.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\282.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\281.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\280.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\279.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\278.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\277.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\276.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\275.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\274.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\273.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\272.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\271.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\270.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\269.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\268.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\267.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\266.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\265.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\264.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\263.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\262.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\261.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\260.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\259.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\258.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\257.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\256.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Documents\255.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Desktop\WORD:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Desktop\Studium:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Desktop\MARCO SAUER DATEIEN:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Desktop\Lieder:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Desktop\Leserbrief_GA.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Marco Sauer\Desktop\Adobe CS4:Roxio EMC Stream
< End of report >