Sie sind auf Seite 1von 404

/2/2011 2:31 PM

Modified: 8/2/2011 2:31 PM


Company: Atheros
---------Key:
AtherosSvc
ImagePath: C:\Program Files\Bluetooth Suite\adminservice.exe
C:\Program Files\Bluetooth Suite\adminservice.exe
82592 bytes
Created: 8/2/2011 1:54 PM
Modified: 8/2/2011 1:54 PM
Company: Atheros Commnucations
---------Key:
athr
ImagePath: system32\DRIVERS\athr.sys
C:\Windows\system32\DRIVERS\athr.sys
2171904 bytes
Created: 9/30/2011 11:47 AM
Modified: 4/21/2011 8:14 PM
Company: Atheros Communications, Inc.
---------Key:
avkmgr
ImagePath: system32\DRIVERS\avkmgr.sys
C:\Windows\system32\DRIVERS\avkmgr.sys
36000 bytes
Created: 4/14/2012 9:32 PM
Modified: 9/16/2011 4:09 PM
Company: Avira GmbH
---------Key:
BTATH_A2DP
ImagePath: system32\drivers\btath_a2dp.sys
C:\Windows\system32\drivers\btath_a2dp.sys
290976 bytes
Created: 8/2/2011 2:01 PM
Modified: 8/2/2011 2:01 PM
Company: Atheros
---------Key:
btath_avdt
ImagePath: system32\drivers\btath_avdt.sys
C:\Windows\system32\drivers\btath_avdt.sys
97440 bytes
Created: 8/2/2011 2:02 PM
Modified: 8/2/2011 2:02 PM
Company: Atheros
---------Key:
BTATH_BUS
ImagePath: system32\DRIVERS\btath_bus.sys
C:\Windows\system32\DRIVERS\btath_bus.sys
25248 bytes
Created: 8/2/2011 2:02 PM
Modified: 8/2/2011 2:02 PM
Company: Atheros
---------Key:
BTATH_HCRP
ImagePath: system32\DRIVERS\btath_hcrp.sys
C:\Windows\system32\DRIVERS\btath_hcrp.sys
147616 bytes
Created: 8/2/2011 2:02 PM
Modified: 8/2/2011 2:02 PM
Company: Atheros
----------

Key:
BTATH_LWFLT
ImagePath: system32\DRIVERS\btath_lwflt.sys
C:\Windows\system32\DRIVERS\btath_lwflt.sys
60064 bytes
Created: 8/2/2011 2:03 PM
Modified: 8/2/2011 2:03 PM
Company: Atheros
---------Key:
BTATH_RCP
ImagePath: system32\DRIVERS\btath_rcp.sys
C:\Windows\system32\DRIVERS\btath_rcp.sys
263968 bytes
Created: 8/2/2011 2:03 PM
Modified: 8/2/2011 2:03 PM
Company: Atheros
---------Key:
BtFilter
ImagePath: system32\DRIVERS\btfilter.sys
C:\ndows\system32\DRIVERS\btfilter.sys
436896 bytes
Created: 8/2/2011 2:04 PM
Modified: 8/2/2011 2:04 PM
Company: Atheros
---------Key:
BthEnum
ImagePath: \SystemRoot\system32\drivers\BthEnum.sys
C:\Windows\system32\drivers\BthEnum.sys
34816 bytes
Created: 7/14/2009 6:51 AM
Modified: 7/14/2009 6:51 AM
Company: Microsoft Corporation
---------Key:
BTHPORT
ImagePath: \SystemRoot\System32\Drivers\BTHport.sys
C:\Windows\System32\Drivers\BTHport.sys
393728 bytes
Created: 10/3/2011 10:34 AM
Modified: 4/28/2011 10:15 AM
Company: Microsoft Corporation
---------Key:
BTHUSB
ImagePath: \SystemRoot\System32\Drivers\BTHUSB.sys
C:\Windows\System32\Drivers\BTHUSB.sys
60416 bytes
Created: 10/3/2011 10:34 AM
Modified: 4/28/2011 10:15 AM
Company: Microsoft Corporation
---------Key:
clr_optimization_v4.0.30319_32
ImagePath: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
130384 bytes
Created: 3/18/2010 1:16 PM
Modified: 3/18/2010 1:16 PM
Company: Microsoft Corporation
---------Key:
clwvd
ImagePath: system32\DRIVERS\clwvd.sys
C:\Windows\system32\DRIVERS\clwvd.sys
27632 bytes

Created: 7/28/2010 9:13 AM


Modified: 7/28/2010 9:13 AM
Company: CyberLink Corporation
---------Key:
CompositeBus
ImagePath: \SystemRoot\system32\drivers\CompositeBus.sys
C:\Windows\system32\drivers\CompositeBus.sys
31232 bytes
Created: 10/3/2011 10:49 AM
Modified: 11/20/2010 4:50 PM
Company: Microsoft Corporation
---------Key:
HdAudAddService
ImagePath: \SystemRoot\system32\drivers\HdAudio.sys
C:\Windows\system32\drivers\HdAudio.sys
304128 bytes
Created: 10/3/2011 10:49 AM
Modified: 11/20/2010 5:00 PM
Company: Microsoft Corporation
---------Key:
HP Support Assistant Service
ImagePath: "C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.e
xe"
C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe
85560 bytes
Created: 6/21/2011 3:57 PM
Modified: 6/21/2011 3:57 PM
Company: Hewlett-Packard Company
---------Key:
HPDrvMntSvc.exe
ImagePath: "C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
227384 bytes
Created: 7/5/2011 5:02 PM
Modified: 7/5/2011 5:02 PM
Company: Hewlett-Packard Compy
---------Key:
hpqwmiex
ImagePath: "C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe"
C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
988216 bytes
Created: 7/5/2011 5:00 PM
Modified: 7/5/2011 5:00 PM
Company: Hewlett-Packard Company
---------Key:
HPWMISVC
ImagePath: C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
26680 bytes
Created: 6/14/2011 2:29 PM
Modified: 6/14/2011 2:29 PM
Company: Hewlett-Packard Development Company, L.P.
---------Key:
iaStorV
ImagePath: \SystemRoot\system32\drivers\iaStorV.sys
C:\Windows\system32\drivers\iaStorV.sys
332160 bytes
Created: 10/3/2011 10:34 AM
Modified: 3/11/2011 12:38 PM
Company: Intel Corporation

---------Key:
IconMan_R
ImagePath: "C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe
1755136 bytes
Created: 9/30/2011 11:04 AM
Modified: 3/7/2011 10:45 PM
Company: Realsil Microelectronics Inc.
---------Key:
igfx
ImagePath: system32\DRIVERS\igdkmd32.sys
C:\Windows\system32\DRIVERS\igdkmd32.sys
10855424 bytes
Created: 8/31/2011 12:48 PM
Modified: 8/31/2011 12:48 PM
Company: Intel Corporation
---------Key:
IntcDAud
ImagePath: system32\DRIVERS\IntcDAud.sys
C:\Windows\system32\DRIVERS\IntcDAud.sys
269824 bytes
Created: 10/15/2010 1:27 AM
Modified: 10/15/2010 1:27 AM
Company: Intel(R) Corporation
---------Key:
kbdclass
ImagePath: \SystemRoot\system32\drivers\kbdclass.sys
C:\Windows\system32\drivers\kbdclass.sys
42576 bytes
Created: 7/14/2009 6:11 AM
Modified: 7/14/2009 8:20 AM
Company: Microsoft Corporation
---------Key:
kbdhid
ImagePath: \SystemRoot\system32\drivers\kbdhid.sys
C:\Windows\system32\drivers\kbdhid.sys
28160 bytes
Created: 10/3/2011 10:49 AM
Modified: 11/20/2010 4:50 PM
Company: Microsoft Corporation
---------Key:
LMS
ImagePath: C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.
exe
C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
325912 bytes
Created: 9/30/2011 11:04 AM
Modified: 8/8/2011 5:39 PM
Company: Intel Corporation
---------Key:
MEI
ImagePath: system32\DRIVERS\HECI.sys
C:\Windows\system32\DRIVERS\HECI.sys
41088 bytes
Created: 9/30/2011 11:04 AM
Modified: 10/19/2010 4:33 PM
Company: Intel Corporation
---------Key:
Microsoft SharePoint Workspace Audit Service
ImagePath: "C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" /auditservice

C:\Program Files\Microsoft Office\Office14\GROOVE.EXE


31125880 bytes
Created: 6/12/2011 11:15 AM
Modified: 6/12/2011 11:15 AM
Company: Microsoft Corporation
---------Key:
MpFilter
ImagePath: system32\DRIVERS\MpFilter.sys
C:\Windows\system32\DRIVERS\MpFilter.sys
165648 bytes
Created: 4/18/2011 1:18 PM
Modified: 4/18/2011 1:18 PM
Company: Microsoft Corporation
---------Key:
MpKsl5b540e51
ImagePath: \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates
\{9A4BBB1D-5E5D-4CB9-96D0-4E2ADF9DBDEB}\MpKsl5b540e51.sys
c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9A4BBB1D-5E5D
-4CB9-96D0-4E2ADF9DBDEB}\MpKsl5b540e51.sys - [file not found to scan]
---------Key:
MpNWMon
ImagePath: system32\DRIVERS\MpNWMon.sys
C:\Windows\system32\DRIVERS\MpNWMon.sys
43392 bytes
Created: 4/18/2011 1:18 PM
Modified: 4/18/2011 1:18 PM
Company: Microsoft Corporation
---------Key:
msahci
ImagePath: system32\drivers\msahci.sys
C:\Windows\system32\drivers\msahci.sys
28032 bytes
Creed: 10/3/2011 10:49 AM
Modified: 11/20/2010 7:30 PM
Company: Microsoft Corporation
---------Key:
MsMpSvc
ImagePath: "c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
11736 bytes
Created: 4/27/2011 3:39 PM
Modified: 4/27/2011 3:39 PM
Company: Microsoft Corporation
---------Key:
mssmbios
ImagePath: \SystemRoot\system32\drivers\mssmbios.sys
C:\Windows\system32\drivers\mssmbios.sys
28240 bytes
Created: 7/14/2009 6:19 AM
Modified: 7/14/2009 8:20 AM
Company: Microsoft Corporation
---------Key:
Nero BackItUp Scheduler 4.0
ImagePath: C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
935208 bytes
Created: 9/23/2009 1:38 PM
Modified: 9/23/2009 1:38 PM
Company: Nero AG
----------

Key:
NisDrv
ImagePath: system32\DRIVERS\NisDrvWFP.sys
C:\Windows\system32\DRIVERS\NisDrvWFP.sys
65024 bytes
Created: 4/27/2011 3:25 PM
Modified: 4/27/2011 3:25 PM
Company: Microsoft Corporation
--------Key:
NisSrv
ImagePath: "c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
208944 bytes
Created: 4/27/2011 3:39 PM
Modified: 4/27/2011 3:39 PM
Company: Microsoft Corporation
---------Key:
osppsvc
ImagePath: "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtect
ionPlatform\OSPPSVC.EXE"
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\
OSPPSVC.EXE
4640000 bytes
Created: 1/9/2010 9:37 PM
Modified: 1/9/2010 9:37 PM
Company: Microsoft Corporation
---------Key:
RSPCIESTOR
ImagePath: system32\DRIVERS\RtsPStor.sys
C:\Windows\system32\DRIVERS\RtsPStor.sys
253544 bytes
Created: 9/30/2011 11:04 AM
Modified: 5/4/2011 10:44 PM
Company: Realtek Semiconductor Corp.
---------Key:
RTL8167
ImagePath: system32\DRIVERS\Rt86win7.sys
C:\Windows\system32\DRIVERS\Rt86win7.sys
414824 bytes
Created: 8/23/2011 9:57 PM
Modified: 8/23/2011 9:57 PM
Company: Realtek
---------Key:
Serenum
ImagePath: \SystemRoot\system32\DRIVERS\serenum.sys
C:\Windows\system32\DRIVERS\serenum.sys
17920 bytes
Created: 7/14/2009 6:45 AM
Modified: 7/14/2009 6:45 AM
Company: Microsoft Corporation
---------Key:
Serial
ImagePath: \SystemRoot\system32\DRIVERS\serial.sys
C:\Windows\system32\DRIVERS\serial.sys
83456 bytes
Created: 7/14/2009 6:45 AM
Modified: 7/14/2009 6:45 AM
Company: Microsoft Corporation
---------Key:
SHDSERV
ImagePath: C:\Program Files\Shield\shdserv.exe

C:\Program Files\Shield\shdserv.exe
221184 bytes
Created: 11/3/2011 1:31 PM
Modified: 11/4/2010 10:28 AM
Company:
---------Key:
ShieldClientService
ImagePath: C:\Program Files\Shield\shieldclnt.exe
C:\Program Files\Shield\shieldclnt.exe
45056 bytes
Created: 11/3/2011 1:31 PM
Modified: 11/4/2010 10:24 AM
Company: [no info]
---------Key:
SkypeUpdate
ImagePath: "C:\Program Files\Skype\Updater\Updater.exe"
C:\Program Files\Skype\Updater\Updater.exe
-R- 158856 bytes
Created: 2/29/2012 8:50 AM
Modified: 2/29/2012 8:50 AM
Company: Skype Technologies
---------Key:
swenum
ImagePath: \SystemRoot\system32\drivers\swenum.sys
C:\Windows\system32\drivers\swenum.sys
12240 bytes
Created: 7/14/2009 6:45 AM
Modified: 7/14/2009 8:19 AM
Company: Microsoft Corporation
---------Key:
SynTP
ImagePath: system32\DRIVERS\SynTP.sys
C:\Windows\system32\DRIVERS\SynTP.sys
1350704 bytes
Created: 6/9/2011 6:19 PM
Modified: 6/9/2011 6:19 PM
Company: Synaptics Incorporated
---------Key:
TermDD
ImagePath: \SystemRoot\system32\drivers\termdd.sys
C:\Windows\system32\drivers\termdd.sys
53120 bytes
Created: 10/3/2011 10:49 AM
Modified: 11/20/2010 7:30 PM
Company: Microsoft Corporation
---------Key:
TsUsbFlt
ImagePath: System32\drivers\tsusbflt.sys
C:\Windows\System32\drivers\tsusbflt.sys
52224 bytes
Created: 10/3/2011 10:50 AM
Modified: 11/20/2010 5:24 PM
Company: Microsoft Corporation
---------Key:
UNS
ImagePath: "C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS
.exe"
C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
2656536 bytes
Created: 9/30/2011 11:04 AM

Modified: 8/8/2011 5:39 PM


Cpany: Intel Corporation
---------Key:
usbvideo
ImagePath: \SystemRoot\System32\Drivers\usbvideo.sys
C:\Windows\System32\Drivers\usbvideo.sys
146432 bytes
Created: 10/3/2011 10:49 AM
Modified: 11/20/2010 5:00 PM
Company: Microsoft Corporation
---------Key:
vmbus
ImagePath: system32\drivers\vmbus.sys
C:\Windows\system32\drivers\vmbus.sys
175360 bytes
Created: 10/3/2011 10:50 AM
Modified: 11/20/2010 7:30 PM
Company: Microsoft Corporation
---------Key:
vwifibus
ImagePath: system32\DRIVERS\vwifibus.sys
C:\Windows\system32\DRIVERS\vwifibus.sys
19968 bytes
Created: 7/14/2009 6:52 AM
Modified: 7/14/2009 6:52 AM
Company: Microsoft Corporation
---------Key:
vwififlt
ImagePath: system32\DRIVERS\vwififlt.sys
C:\Windows\system32\DRIVERS\vwififlt.sys
48128 bytes
Created: 7/14/2009 6:52 AM
Modified: 7/14/2009 6:52 AM
Company: Microsoft Corporation
---------Key:
vwifimp
ImagePath: system32\DRIVERS\vwifimp.sys
C:\Windows\system32\DRIVERS\vwifimp.sys
14336 bytes
Created: 7/14/2009 6:52 AM
Modified: 7/14/2009 6:52 AM
Company: Microsoft Corporation
---------Key:
WatAdminSvc
ImagePath: %SystemRoot%\system32\Wat\WatAdminSvc.exe
C:\Windows\system32\Wat\WatAdminSvc.exe
1343400 bytes
Created: 9/30/2011 1:32 PM
Modified: 9/30/2011 12:01 PM
Company: Microsoft Corporation
---------************************************************************
10:46:56 PM: Scanning -----VXD ENTRIES----************************************************************
10:46:56 PM: Scanning ----- WINLOGON\NOTIFY DLLS ----************************************************************
10:46:56 PM: Scanning ----- CONTEXTMENUHANDLERS -----

Key: Atheros
CLSID: {B8952421-0E55-400B-94A6-FA858FC0A39F}
Path: C:\Program Files\Bluetooth Suite\BtvAppExt.dll
C:\Program Files\Bluetooth Suite\BtvAppExt.dll
145568 bytes
Created: 8/2/2011 1:58 PM
Modified: 8/2/2011 1:58 PM
Company: Atheros Commnucations
---------Key: Cover Designer
CLSID: {73FCA462-9BD5-4065-A73F-A8E5F6904EF7}
Path: C:\Program Files\Nero\Nero 9\Nero CoverDesigner\CoverEdExtension.dll
C:\Program Files\Nero\Nero 9\Nero CoverDesigner\CoverEdExtension.dll
2250024 bytes
Created: 9/24/2009 5:07 PM
Modified: 9/24/2009 5:07 PM
Company: Nero AG
---------Key: Eazshell
CLSID: {CB0877AB-7E94-4073-8194-6F992D27EFAA}
Path: C:\Program Files\Shield\shieldshell.dll
C:\Program Files\Shield\shieldshell.dll
36864 bytes
Created: 11/3/2011 1:31 PM
Modified: 11/4/2010 10:27 AM
Company:
---------Key: EPP
CLSID: {09A47860-11B0-4DA5-AFA5-26D86198A780}
Path: c:\PROGRA~1\MI8079~1\shellext.dll
c:\PROGRA~1\MI8079~1\shellext.dll
301128 bytes
Created: 6/15/2011 3:16 PM
Modified: 6/15/2011 3:16 PM
Company: Microsoft Corporation
---------Key: Shell Extension for Malware scanning
CLSID: {45AC2688-0253-4ED8-97DE-B5370FA7D48A}
Path: C:\Program Files\Avira\AntiVir Desktop\shlext.dll
C:\Program Files\Avira\AntiVir Desktop\shlext.dll
150480 bytes
Created: 4/14/2012 9:32 PM
Modified: 1/31/2012 8:57 AM
Company: Avira Operations GmbH & Co. KG
---------Key: XXX Groove GFS Context Menu Handler XXX
CLSID: {6C467336-8281-4E60-8204-430CED96822D}
Path: C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
4221328 bytes
Created: 6/12/2011 11:15 AM
Modified: 6/12/2011 11:15 AM
Company: icrosoft Corporation
---------************************************************************
10:46:57 PM: Scanning ----- FOLDER\COLUMNHANDLERS ----No Folder\ColumnHandler entries found to scan
************************************************************

10:46:58 PM: Scanning ----- BROWSER HELPER OBJECTS ----Key: {72853161-30C5-4D22-B7F9-0BBC1D38A37E}


BHO: C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL - file already scanned
---------Key: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}
BHO: C:\Program Files\Bluetooth Suite\IEPlugIn.dll
C:\Program Files\Bluetooth Suite\IEPlugIn.dll
51872 bytes
Created: 8/2/2011 2:06 PM
Modified: 8/2/2011 2:06 PM
Company: Atheros Commnucations
---------Key: {B4F3A835-0E21-4959-BA22-42B3008E02FF}
BHO: C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL
C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL
561552 bytes
Created: 12/21/2010 1:05 AM
Modified: 12/21/2010 1:05 AM
Company: Microsoft Corporation
---------************************************************************
10:46:58 PM: Scanning ----- SHELLSERVICEOBJECTS ----************************************************************
10:46:58 PM: Scanning ----- SHAREDTASKSCHEDULER ENTRIES ----No SharedTaskScheduler entries found to scan
************************************************************
10:46:58 PM: Scanning ----- IMAGEFILE DEBUGGERS ----No "Debugger" entries found.
************************************************************
10:46:58 PM: Scanning ----- APPINIT_DLLS ----The AppInit_DLLs value is blank or does not exist
************************************************************
10:46:59 PM: Scanning ----- SECURITY PROVIDER DLLS ----************************************************************
10:46:59 PM: Scanning ------ COMMON STARTUP GROUP -----[C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]
The Common Startup Group attempts to load the following file(s) at boot time:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-HS- 174 bytes
Created: 7/14/2009 11:41 AM
Modified: 7/14/2009 11:41 AM
Company: [no info]
-------------------************************************************************
10:46:59 PM: Scanning ----- USER STARTUP GROUPS ----Checking Startup Group for: ADMIN
[C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\des
ktop.ini
-HS- 174 bytes
Created: 9/30/2011 9:18 AM
Modified: 10/3/2011 11:32 AM

Company: [no info]


----------------------------Checking Startup Group for: USER
[C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk
top.ini
-HS- 174 bytes
Created: 10/6/2011 3:46 PM
Modified: 3/20/2012 12:37 PM
Company: [no info]
----------------------------************************************************************
10:47:00 PM: Scanning ----- SCHEDULED TASKS ----Taskname:
{11AB47D9-BB17-4D00-B422-2641E30D181C}
File:
c:\program files\mozilla firefox\firefox.exe
c:\program files\mozilla firefox\firefox.exe
924600 bytes
Created: 9/30/2011 11:19 AM
Modified: 4/8/2012 8:50 PM
Company: Mozilla
arameters:
http://www.skype.com/go/downloadg?source=lightinstaller&ver=5.8.0.15
Corporation
8.259&LastError=12002
Schedule:
At task creation/modification
Next Run Time:
Status:
Ready
Creator:
SkypeSetupLight
Comments:
---------Taskname:
{65A7DF39-B5AB-474D-A8CC-FE71AD4F90DA}
File:
c:\program files\mozilla firefox\firefox.exe
c:\program files\mozilla firefox\firefox.exe
924600 bytes
Created: 9/30/2011 11:19 AM
Modified: 4/8/2012 8:50 PM
Company: Mozilla Corporation
Parameters:
http://www.skype.com/go/downloading?source=lightinstaller&ver=5.8
.0.158.259&LastError=12002
Schedule:
At task creation/modification
Next Run Time:
Status:
Ready
Creator:
SkypeSetupLight
Comments:
---------Taskname:
{C90587A9-733C-48DF-BC48-E12CCA883122}
File:
c:\program files\mozilla firefox\firefox.exe
c:\program files\mozilla firefox\firefox.exe
924600 bytes
Created: 9/30/2011 11:19 AM
Modified: 4/8/2012 8:50 PM
Company: Mozilla Corporation
Parameters:
http://ui.skype.com/ui/0/5.8.0.158.259/en/abandoninstall?page=tsM
ain
Schedule:
At task creation/modification
Next Run Time:
Status:
Ready
Creator:
SkypeSetup
Comments:
----------

Taskname:
{E5F53081-305B-4CDF-84A0-F1B730B6C3E6}
File:
c:\program files\mozilla firefox\firefox.exe
c:\program files\mozilla firefox\firefox.exe
924600 bytes
Created: 9/30/2011 11:19 AM
Modified: 4/8/2012 8:50 PM
Company: Mozilla Corporation
Parameters:
http://www.skype.com/go/downloading?source=lightinstaller&ver=5.8
.0.158.259&LastError=12002
Schedule:
At task creation/modification
Next Run Time:
Status:
Ready
Creator:
SkypeSetupLight
Comments:
---------Taskname:
MirageAgent
File:
C:\Program Files\CyberLink\YouCam\YCMMirage.exe
C:\Program Files\CyberLink\YouCam\YCMMirage.exe
136488 bytes
Created: 7/6/2011 8:13 PM
Modified: 7/6/2011 8:13 PM
Company: CyberLink
Schedule:
At logon
Next Run Time:
Status:
Running
Creator:
CyberLink
Comments:
---------************************************************************
10:47:01 PM: Scanning ----- SHELLICONOVERLAYIDENTIFIERS ----Key: Groove Explorer Icon Overlay 1 (GFS Unread Stub)
CLSID: {99FD978C-D287-4F50-827F-B2C658EDA8E7}
File: C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
---------Key: Groove Explorer Icon Overlay 2 (GFS Stub)
CLSID: {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}
File: C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
---------Key: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)
CLSID: {920E6DB1-9907-4370-B3A0-BAFC03D81399}
File: C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
---------Key: Groove Explorer Icon Overlay 3 (GFS Folder)
CLSID: {16F3DD56-1AF5-4347-846D-7C10C4192619}
File: C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
---------Key: Groove Explorer Icon Overlay 4 (GFS Unread Mark)
CLSID: {2916C86E-86A6-43FE-8112-43ABE6BF8DCC}
File: C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
---------Key: SharingPrivate
CLSID: {08244EE6-92F0-47f2-9FC9-929BAA2E7235}
File: %SystemRoot%\system32\ntshrui.dll
C:\Windows\system32\ntshrui.dll
442880 bytes
Created: 3/19/2012 8:34 PM
Modified: 1/4/2012 3:58 PM
Company: Microsoft Corporation
----------

************************************************************
10:47:02 PM: Scanning ----- DEVICE DRIVER ENTRIES ----Value: msacm.l3fhg
File: mp3fhg.acm
C:\Windows\system32\mp3fhg.acm
232448 bytes
Created: 9/30/2011 10:30 AM
Modified: 10/19/2006 1:05 AM
Company: Fraunhofer Institut Integrierte Schaltungen IIS
---------Value: VIDC.YV12
File: yv12vfw.dll
C:\Windows\syem32\yv12vfw.dll
237568 bytes
Created: 9/30/2011 10:30 AM
Modified: 11/4/2010 1:08 AM
Company: www.helixcommunity.org
---------Value: msacm.ac3acm
File: ac3acm.acm
C:\Windows\system32\ac3acm.acm
151552 bytes
Created: 9/30/2011 10:30 AM
Modified: 3/20/2011 2:00 AM
Company: fccHandler
---------Value: VIDC.FFDS
File: ff_vfw.dll
C:\Windows\system32\ff_vfw.dll
80896 bytes
Created: 9/30/2011 10:30 AM
Modified: 3/29/2011 3:00 PM
Company: [no info]
---------************************************************************
10:47:03 PM: ----- ADDITIONAL CHECKS ----Winlogon registry rootkit checks completed
---------Heuristic checks for hidden files/drivers completed
---------Layered Service Provider entries checks completed
---------Windows Explorer Policies checks completed
---------Desktop Wallpaper: C:\Users\USER\AppData\Roaming\Microsoft\Windows\Themes\Transc
odedWallpaper.jpg
C:\Users\USER\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
729698 bytes
Created: 10/6/2011 3:46 PM
Modified: 4/14/2012 10:30 PM
Company: [no info]
---------Web Desktop Wallper entry is blank
---------Checks for rogue DNS NameServers completed
---------A Proxy Serr is enabled for Internet Explorer
Proxy Server: [10.10.1.12:8080]

---------Additional checks completed


************************************************************
10:47:04 PM: Scanning ----- RUNNING PROCESSES ----C:\Windows\System32\smss.exe
69632 bytes
Created: 7/14/2009 6:11 AM
Modified: 7/14/2009 8:14 AM
Company: Microsoft Corporation
-------------------C:\Windows\system32\csrss.exe
6144 bytes
Created: 7/14/2009 6:11 AM
Modified: 7/14/2009 8:14 AM
Company: Microsoft Corporation
-------------------C:\Windows\system32\wininit.exe
96256 bytes
Created: 7/14/2009 6:36 AM
Modified: 7/14/2009 8:14 AM
Company: Microsoft Corporation
-------------------C:\Windows\system32\services.exe
259072 bytes
Created: 7/14/2009 6:11 AM
Modified: 7/14/2009 8:14 AM
Company: Microsoft Corporation
-------------------C:\Windows\system32\lsass.exe
22528 bytes
Created: 3/19/2012 8:35 PM
Modified: 11/17/2011 12:29 PM
Company: Microsoft Corporation
-------------------C:\Windows\system32\lsm.exe
267776 bytes
Created: 10/3/2011 10:50 AM
Modified: 11/20/2010 7:17 PM
Company: Microsoft Corporation
-------------------C:\Windows\system32\svchost.exe
20992 bytes
Created: 7/14/2009 6:19 AM
Modified: 7/14/2009 8:14 AM
Company: Microsoft Corporation
-------------------C:\Windows\system32\WLANExt.exe
77312 bytes
Created: 7/14/29 6:51 AM
Modified: 7/14/2009 8:14 AM
Company: icrosoft Corporation
-------------------C:\Windows\system32\conhost.exe
271360 bytes
Created: 9/30/2011 11:57 AM
Modified: 6/24/2011 11:22 AM
Company: Microsoft Corporation
--------------------

C:\Windows\System32\spoolsv.exe
317440 bytes
Created: 10/3/2011 10:50 AM
Modified: 11/20/2010 7:17 PM
Company: Microsoft Corporation
-------------------C:\Program Files\Bonjour\mDNSResponder.exe
349472 bytes
Created: 4/6/2011 4:20 PM
Modified: 4/6/2011 4:20 PM
Company: Apple Inc.
-------------------C:\Program Files\Common Files\LightScribe\LSSrvc.exe
73728 bytes
Created: 8/20/2009 1:34 PM
Modified: 8/20/2009 1:34 PM
Company: Hewlett-Packard Company
-------------------C:\Windows\system32\SearchIndexer.exe
427520 bytes
Created: 9/30/2011 11:57 AM
Modified: 5/4/2011 11:28 AM
Company: Microsoft Corporation
-------------------C:\Windows\system32\wbem\wmiprvse.exe
257536 bytes
Created: 10/3/2011 10:50 AM
Modified: 11/20/2010 7:17 PM
Company: Microsoft Corporation
-------------------C:\Program Files\Windows Media Player\wmpnetwk.exe
1121792 bytes
Created: 10/3/2011 10:50 AM
Modified: 11/20/2010 7:17 PM
Company: Microsoft Corporation
-------------------C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
80336 bytes
Created: 4/14/2012 9:32 PM
Modified: 1/31/2012 8:57 AM
Company: Avira Operations GmbH & Co. KG
-------------------C:\Windows\system32\winlogon.exe
286720 bytes
Created: 10/3/2011 10:50 AM
Modified: 11/20/2010 7:17 PM
Company: Microsoft Corporation
-------------------C:\Windows\system32\Dwm.exe
92672 bytes
Created: 7/14/2009 6:24 AM
Modified: 7/14/2009 8:14 AM
Company: Microsoft Corporation
-------------------C:\Windows\system32\taskhost.exe
49152 bytes
Created: 10/3/2011 10:49 AM
Modified: 11/20/2010 7:17 PM
Company: Microsoft Corporation
--------------------

C:\Windows\system32\taskeng.exe
192000 bytes
Created: 10/3/2011 10:50 AM
Modified: 11/20/2010 7:17 PM
Company: Microsoft Corporation
-------------------C:\Program Files\Mozilla Firefox\plugin-container.exe
16824 bytes
Created: 9/30/2011 11:19 AM
Modified: 4/8/2012 8:50 PM
Company: Mozilla Corporation
-------------------C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
149352 bytes
Created: 1/9/2010 9:18 PM
Modified: 1/9/2010 9:18 PM
Company: Microsoft Corporation
-------------------C:\Windows\system32\SearchProtocolHost.exe
164352 bytes
Created: 9/30/2011 11:57 AM
Modified: 5/4/2011 11:28 AM
Company: Microsoft Corporation
-------------------C:\Windows\system32\SearchFilterHost.exe
86528 bytes
Created: 9/30/2011 11:57 AM
Modified: 5/4/2011 11:28 AM
Company: Microsoft Corporation
-------------------C:\Program Files\Trojan Remover\Rmvtrjan.exe
FileSize:
4738296
[This is a Trojan Remover component]
--------------------------------------************************************************************
10:47:08 PM: Checking HOSTS file
No malicious entries were found in the HOSTS file
************************************************************
------ INTERNET EXPLORER HOME/START/SEARCH SETTINGS -----HKLM\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\Software\Microsoft\Internet Explorer\Main\"Local ge":
C:\Windows\System32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\Software\Microsoft\Internet Explorer\Main\"Default_Page_URL":
http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\Software\Microsoft\Internet Explorer\Main\"Default_Search_URL":
http://.microsoft.com/fwlink/?LinkId=54896
HKCU\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://go.microsoft.com/fwlink/?LinkId=69157
HKCU\Software\Microsoft\Internet Explorer\Main\"Local Page":
C:\Windows\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://go.microsoft.com/fwlink/?LinkId=54896
************************************************************

=== NO CHANGES HAVE BEEN MADE TO YOUR SYSTEM FILES ===


Scan completed at: 10:47:08 PM 14 Apr 2012
Total Scan time: 00:00:34
************************************************************
MZP@
!L! This program must be run under Win32
$7PELl C0
@@0  / . text0& `.datap@
,@.idata6@@.rsrcF@@'P" U SVW } ]

u uh@Ajj BC tKtWujfV%Gf ftft#0h h PAjeVb$jV<$jV-$33_^[]U SV

u uh@Ajj B tKt  E`QAPjeV $ f ftGftdf dum ` QA bJP{+

C t5`QAjeV,$7h5`QAjeV #jV\#jVM#33_^[]U P PHu ESVW } u

] uhAAjj A t

N (  HA  HA =dYAt5dYAjh Sf# =hYAt5hYAjhrjiSB#jgS" EPV"j URSj"jV0#j5AjgS M


jgV"IhjjjjVW"V! jjj1S" tjPj0V"h@jh5V " Ph= jeS! E Ru " E@A
p]AB =@Au[   %AA #  G ~ =X@Au R Al]A - =T@A 3 H@A
ju=  =D@At3f >3e >X@A t, =HAu#HujjhS jjhS  =HAt}fPjS{ f ftIf
HAjS8% =HAtHAUjgS& =HAu!jjhV h @AjhV V  33P P ug  CP

P RSHAjS`M HA3f <3e <3 < H @A  H @A dQAI  H @A 
HA =HAt
=HAuHAjS33_^[ ]U SVW } u

] uh'AAjj ; t

N  =hYAt5hYAjhrjfSJjeS hjh5V4jPjhCV H@A zP@A tP Ap]A(P@AjS5<

 PHu $  d@A L$ $



 $$3

|$$  C | 34

D$(P u C

b
$_@ @ @k@ @ %@j@@@q @ @#@ @#@ |$ 
 $$ Pht $$  $$  $$   $$ $$  $$ 6<

$$ 

$$  w<

$@ I

$l I $  Iej $0

Rb 

$Q tC $P

$0 R O t 7 tjj $Q7

$, 

$$ 3

; ~ $$  : |$  =L@A  uAAL@A |$t


L@A@ D$

$$

 t3

5 L@AT$

>L@A t
L@A L@AX |$
 [ O |$ D $$Rt$. |$ # $3 $$ .u&3 $% \u $&
HA
t
3t02
HA$$
3\t
HA
HA
3HA
$$
3t&3
 
HA
 |$
3$%
 :u
$$3
$$$|$
U $
 L$
QhQjzjhAA
$h Y u3D$ D$P $R L$QjhAAt$$1t$
3S5@@A $PhAA $Rs  $Q tC $Pjet$

 $$  =\@A  $ $$, u93*% @u

$%

$ $

jC$ $ $ u
R $,
$Qut$
& $$ 

$$

$$0

$

$$Y

 tjE@At$HAu |$ h =X@Au


X@AD@AI |$u' $$t $$Pt$ P@A^@A |$ 

$$ |$ 

$$ 3  Pt tHt

D$D$D$D$ $ $$0 $3 $ "ue $$0 $B  =At $A"  $"  P
t $ $$@ :t $$@ $ $ $ $ $$` :t
$$` $$0 8 $ $Q; tAA
uuC B ;u }t- E t#h RVY EG ^[ ]SVW dUA $ t$t!3 t

%AA dUA  <3<3F  "u S V3J3 "u3  "u @ <u3  t3 L /u u

AA3 FC D$ |$t T$@ FD L$@ N <$t= |$u6


=jS
t5HA
 t
u3

)
hv8
v8.
t
tjAA
jjj
$PR
 t3
jdv8
=D@At <$u

$@ VAA

$@

$@3 C Vz  u f ^

hX\
 _<$
^[
(tTh
Q 

 =E@Auo S4 @ @AO uThBA

 D

$3v $f $ $ $R

 SVW P   E ;u 3  {t73  }tA  ~H ~3 T t@Aj 3


\t /u%@ <u[S =]@Ate =lYAt\ T$lYA L$Q D$PjhjjjhBAh
 u$ @ PSj

3TjjhBAh

 uDD$ L$Q

$P T$Rj L$Qt$b

 u

 4$6

@[A
@ASHA
@A @hAS|3P5A

jj A T% [S  t3 T \t

@A [

jjjj D$Po tjjj T$

R
T T


0 @A
jd
V hD$@A
Pjh
L$QR
:  3 $ d SV 0@A 8u

jSh @A D$

Pjh 4^[
S @Bvu3[;vd[kd3[ SVWUQ t ?u
3  3 % "uP3 W "u u;u G3 ,t tG"FO $ t3 G"L  :$u(3  ,u uG3
 EPh@GAjjhPGA
 V UR
QPW EP R }

tju

MQ PD }t

u UR
Q,  K3 t R MQ  P$ URhpGA MQ   |;h Rjujj j  Q EP
QYZ^[
SV H&   =8@Au; =<@Au2h@Aw th@AVr8@A =8@A <@A =8@At BjP T$RS t$
\u3 J \u
\@ "3
\u3 J nu

@ 
B @ :u U  E Pu

R

3 ]

SVW jg5HA =@Au:l]A jVzjjhVAh @AjhV/@AhhhV$< Rj

 PuR   HA ] S tSfPjV

SePj>

N =HA [

U QSVW E 5TQA }=XQA =HAt, =HAtSh 0@5HAh@A5A 

$ /@

] uh@Ajj " t

   UE

30

PjeS^h

h`R

jQ7j hpjfS

PP

R

Qj

@Pjhj2

Rj

@Qjhv

UXQA
XQA
PR
R zPh@A
QPV @R MQ^
PR
j2 

PQjjStV PuF

p ,P

Rh@A

Pj

@Rjhj2

Qj

@Pjhj

RQ nPh@A

PR 

PQjkSh Pt

=TQAtE

pTQA P

pRh

 t)jjhqjfS  tPVS33_^[ ]U SVW u }

jfS
]Vh@A
HAj;
SF
jj
M[jS]
7
U_
j
3
EPt3O_^[]
t#j
EZvPh
 =\QA
jUh5HA
WjeS3
S
=PA
WEjfS*
]u Rh
U@Kf
5HA
UfPS
hft
@A=HA
5Auf@t#05\QA

E tPA 
jPj

8t8EP

u

RV

Qh@A tS [ ]

Pj$ U uuu

uP] 

U 3 U ]

U SVQ E

^[]

 Ph@5HAh@A5A
3

SVWP PHu

$p   3 7 3 9

$q  $q #5

p]A
/u43
j3HA
T st
3Su$
p]A lT]At=HA
3 u =HA
uuX@A H@A
\@A3@X
 u E
}uhhdQA
Ej
 E
hdQA
0h=D@A
AAtjVPA
 AjdSL
3=T@A
dYAj~e5
H@A 5dYAkhYA tP\ = Au =HAt A  HA5 A3^[ ]SHA  HA t}PjS3 

EADDA  $CA CA KCA C(DA S

3C K3 C C3  [SV t@$CACA  SCA(DA KC

C tP R3 KtS_Y^[

U SVW } ]

u u
@  ]GA E# u 7  ] GA E u V h ]GA E u F H ]`GA E u V

( ]0GA E u 73  @ V R3_^[ ]

U E@ @]U EHt @

3]U @ ]U @ ]U @ ]U 3]


S M

U 3] U @ ]U S ]s u

3[]

U @ ]U 3]

U 3]

U 3]

U SVW }U

u ] G3 M U R wE33  C U SM K

Su3 F3 W3 VN

F U

Q  P3_^[ ]U @ ]

U @ ]U 3]

U @ ]U @ ]U 3] U @ ]U @ ]


U @ ]U @ ]

U @ ]

U @ ]U @ ]U 3] U @ ]U 3]

U E ]

U @ ]U @ ]U  ]$S D$PR SRh0GAjj L$Q C tMThGAP  |>S L

$R
Q D$Ph GA SR
 | D$P R L$Q P[
Q

S C trThGAP   |!j L$Q Pj T$R

$P RL$QhGA CP  | L$Q  P T$R


Q D$P RKQ  P3 SYZ[ PU QS S K E

C$ US( C t) URhGAP | CPP UR


Q EP R[Y] S VQ C taThGAP   |R t/ sVsjSjj D$P  R,VsjSjj L$Q  P,jsjSjj T$R
Q, $P RZ^[ S Q C t4 t0ThGAP   |! KQsjSjj D$P  R,

$Q PZ[

S C u3[P  R C[

33  H33 P3 H

P@"
@ ME
SVKPVj
t
j URV@
{t PtSj
Y^[
C tPU
SS
3jVVW
P{ U+UR
ujZ
M+M
CQu
CjV E@Ph@jhBAj  { tj

W w3 Oh j 8 G3G  G$3G(BA W,WM 3 0_^[U SVW } u

] HtHt* t4 |uN PjS:?jS E.jSjS  f WuVS


_^[]
SVWU g {  ~
  kj,^Y t  {tn .BA C C,

PhGAV  |j K

Q  V RS ]_^[S C

tP R3 K

C t SR
Q3
RQ 33C^
C[
V ptSVW 3 $3 T$ H+='wKjjjj D$Pn t$jjj T$R L$Q  D$PTV R
 |+ D$P  R |W L$Q P  D$P  R $_^[ SVWU P $

 3 D$jjjjhLBA W

R
Q, $ = D$4$u  lm Uj@ D$

t$

wD$  D$P |$,u T$(  s3 L$dBA  |$t%kBA x  D$BA _ $ C3  td

 |$u

BA
FF
 |$
uT$_ L$Qjl
t$ |$
t|
l G  t]USjVjj V  D$jjURjSjh uD$ P |$t

tT$
Y G L$Q P]_^[ SVW @ $ <$u3Y X 4$: t$3 
u;4$t
3 V t FGW3 t*3  &u!33

 ;u P@ } <u u# ?t 3 u;4$t


F
3
3 V< t
nBA
F G  t E  D$ |$uBA ! u
F |$t
F
FBA  u%BA G u ! ?uG  t
3 >u3

>uG ? > $YZ_^[ ,3  <u"3

 >u@ |B :u3

SVWU + @ 

u BA   qCA  u,BA > U  3 K


3 C
tC/;s%3  u3 K uCA >  

7FC ;u 7 N  p]_^[


D$ D$ D$ D$ D$r D$X D$r
 [ SVWUP PHu $0 $,\  u1h L$Qj` D$

\x t@  D$



 jj T$ $3I  u

 #$3 L$

e  D$

 2   3|3 D *u,3 T *u!@EA E] u \$$ P3 D Ru93 T au.MEA E& u $

- dC O; y D$ RP


<$  <$u $

$3  D$ |$@}

F $RP

$3

 F  u



  F $

N   F33  G t| \uY  ; n t 0 "t :t4 rt t"( \"  "  

t
3 tGB
u

  B ;~ w  V

  ,0]_^[ S  jjhREAP_ tC.jhVEA L$VEA "REA *  K [

U SV W

rt

JtZEA

\EA^EA 7 } t E U7  7 U Sh`EARR

U y u U m tH s

  t +C E E" E t;}t


E_^[ ]
3 SV  O :u. V C u3 S=u3 C

"u ^[C  t

uC3 

t ;u3^[

U SVW M E EP U E M EPVf URV& M+MA+M M E+E@+E

@PjSu
 _^[[]Ul
SVW
=hEAuU
$ujTh
u D$LEA
T$hEA t]A
_=hEA
*
ut]A3 t
 SVQ

  G  

d  

$3 $ PVSiPEZ^[ U 0t
t& A SE A  Q M]SVW T  t3Z \$3 T$L$$ L$

t$D$A3 D$3 T$ L$QK u3WSd S D$P R  (_^[

U SVW U E } t

 EP u
QtS Y^[

=0u EP _^[ ]


U u}] f  

SV 3 C h pEA@ h }EA4 C$D$h EA

 

SV t


 tP tS

Y ^[

SV Q f u    

^[SVW  ;u3  

t V

 


 u!3nV

 

 u3Q




3


3
H S
EA
_^[
 tEA
U SVW
u  0 t3/S + u3PF

 

_^[] U lSVW M ]-  }t Ef 8t U   u? P R


t u3 ( RV  u        ]   D  3 3

 








@





I

8

'




  f  t ?t

   E"  u:

lP

R uHH t u3 (

 l

p 

 x

 |









x

g T

  t f  _^[ ]
SVWU 3 /%n t k =AtA H  F  u t = ?t63 G@ t(
C^[K }f >tF t F ^[ SVW $ 33   t%3 S .u3 K .u3 Co t {C ;u 

. ^[SV t C S

 t3^[

SV tf ;tEA |  ^[ u3EA  ^[

\t

/t3 :

. x  t;v K;s


3  .u ]_^[ SVQ $ - uEA w   5 {t"EA C
 tEA C
EA
3
uYC cu
<$uL ;t
20K;w
 PH;uC1_ 3 :tP3 C  t3 C  uEA C % 3 S .uA0K 3 :tZ^[ S

3  }_ +H~

3  :u_ =AtA *   F ;u Z]_^[SVWU t;t c ; w V  9% /u u\

V3  \uM3 C \uC C\  t0 F\o  t+F

M   7_^[SVWUQ

$ 3 =AtA; 

; (  t C  <$t t+;  t u


C  <$tf Z]_^[3 
S TR% D$P T$RL$ D$ CT$ SL$ K

D$ CT$ SL$ K CH C   EAS @;Cr {v   tC fD$ T$R L$Q $+D$C [S V f  f D$f Sf T
f Kf L$f C

f D$f Sf T$f Kf L$fD$T D$

Pb C$;$vD$V T$R ^[ 8u33YZ z D$3 3RP D$3$T$ YZ


u0 H;Ju( H;Ju H

;J

u H;Ju H;Ju@;Bt3

SV wRP n;T$u;$   ^[SV u p u3

 H H  -  H  ? H   H

  H H  3 P S u d u  t3[ SVW t tf ;t


jS>jV. t 3  t u_^[SVWU 3 L$ $ D$<$t $f :t
 u3D$

 3 t +=} ?uD$

 t   $ f <r  u |$

  t

$f <q\t

3  \uy3 T$t D$ $` fDt D$ D$ |$

t $ D$i   +

$9  +

  $L$T$ |$

u$ |$ =AtA T$   D$@ F |$u L$$ 9 

];t
_^[
T$ `U Q
SVW
 ^M[SV
U q
}t E t
8 t
fu;t3
S M}tVE
 8 ^[
u3u
 MFA}t E8|]A
 u3|]A
 RPM
Ml


 r v3B <u 3f

Pf P
rfu
3v
3Bf
P D$<P
uX+ VS ~
V e u3 
>t e3R P 3kw
U > e3R
R P P ~ P D$W X ^[S VW K 3 $  u3z ^ <$to S D$b T$   L
AU s s^[ SV t  t tS Y ^[ ;P~ +P P S VWS S C;}< y  ;} s
AEU s_^[
SVW "o FA 

  hO~

{

@> > 0

z

o

d K

H

=

2

f'
eue e
  e
3  e
33 Se
3
 e` e e
ef i
e e
e e
e t>
e_^[
e @>SQ
 $e
  e
$ 
 e u&x
 l>3
QP
e 
eS
 D$  r L$ T$ p 3;  D$3 0 R   t} et? ~; }6 ~1+D$3  RuR3

>3
e e
D$R 3P
v gq
 e L$
eue
 $>
L$ e
o
 D$

F; Y eu3P D$?X D$+ p Ef

ef;

>t)|

e D$ e 

p> zuGFA K~  t e Ku etD

>u; e2 tuC >u et1 >r(

e L$ e  0]_^[SV '|  ;u t


AN s s^[ SV t  t|tS ~Y^[ ee3nSVWU tT K 0

R > 0

<
8u3 whtS%~Y]_^[
SVWU 3!E u ;p>u $ W t t {t p>{u3
; ev~3  `  k t3P D$0X  u4h   U u i ANjj
 

 ` D$D D$,Pt |$<

 n $ T$

e

e;T$u;$w 

e e;T$u;$v*~&gSP U AN

AvM3P D$05XV |>uu D$,s5 |>su >t D$,r > D$,r >  e e

e

e

rD$,}r
V! D$,
 VrD$,qr
V" D$,
 VrD$,1r
V$ D$,
 VrD$,Yr
F t V(
 V D$,
D$,Mr
r V,
 V D$,q
D$, 3 V, V( ~u

3 FF,

F(3 3RP F

3$T$

 F,3 3RP F3$T$

f ~"s

~" T$H D$, qD<H T$H F0 w / ~z ~
F"+ F
t  0

 D$,

Jq(FA F0Uw 


3 3 H  3 H@ 4>k ~tueF

tO

$HcF D$HFv@N"+Q

0Qh T$T 

$TFFf 0uf f

 D$,vp

 VT33

3

F
 ' T$
D$,o J

K $\

$`

8K dK $d $h3 D$

T$

\ L$+L$

|$
  |$

t T$ D$, o T$ D$ L$VW $t

_^t $ 3  $  |$3;|$}- T$ D$,n O3+L$ D$

|$

 e eF  L$ D$, T$

o+FA
 ff
F0f
u ee
 A
f;>ts
G~F0
zu PhP UR

> t T$

D$,=n D$ 3 e e D$,3xnff% f

e

|>

p>  D$0+D$<  e ef

x>f; e 3

ma e A F3P D$0VXz e


; ewJ Fh$FAh|P URF e

e; eu

A1F3P D$0X D$<P D$0X ]_^[

>%= 

>w >u3 

> r^t t

>
<5w

>3 
 >
 K
/3
K
uvp K
/t
CP
u\u
 h
S\%k

=A
 tD$
A
  D$
y
3S
 F u
;uKB$
f f /tf \uf\ f 8u_^[ SVWP  

$ 

Knf KtQ

 t+t X 3Q 3j

Kn3P D$ X-

K3 D$ T$L$ h

 L$

T$ L$

$tW L$ $xW $ W K0u

K3RP V3

K D$3Z 

t; KtO

KPq P S_

AQB <$t$ 33P D$ XP D$ X p _^[

S  t :m3 3 3 K C[

S f3

B

$ $ Pj

B t+

B x0u3 $ Rj \ t3Z^[

U S VW s0 Mnk=s

 B |  |aAA |[

SVW|aAU  u  32N  3@ vu 33

 

3 B;w ]_^[RJ U SVW M U E E 8  } 33i eA Ui  }ui fAt2 }tli


F@
 S
uEV

0
 EEo
^ fE
  0D

y?
Io 
 E ,
o  /}
Ct
  a

Ug
 3
3 
3

@ |B |i4FA eA Ug } i4FA 

fA<ui4FA fA U fi4FA |eA U bfi4FA eA U

t3 M E _^[ ] U S VW

 E

p> U }zuK > }tt }zuuG3 E t: }t4

e
[X
D
u3
ECU
P3
JE
NT S UTu
4f
Eyp }
>utI SR
P
e
f  Ejj 3 Q t

e<

}t

U  p>tu* [

e

e+

K

KRP3 V tn }{u

.G
 



 E

 E U V U V$ <X      _^[ ]


7 u3 S = hAu 
 [ U SVW U UE 3   | S _ @ r3

 L@ | U  >u _^[ ]U SV E t 3 U  E b y  u U U }~m M E

1E
J H JHR

E U  M H U PM H

 EM }

U E a E^[ ]SVWU  $ 3 D$ D$

D$a3339$3 ,$ \

|=  < \@ |BA;T$} | uF3;T$}


~
 D$3 T
hA T$

0 D$3 T
hA T$

0B D$3 T 

hA T$

0B D$3 T

hA T$

0B D$

jA D$

0D$ |$t1;T$3 \ |

0@ |B;T$|  3 \ |

0@ |B D$y ;| D$y 3 T

hA0T

3 T
hA0T
hA0T 3 T 
hA0T

B;T$}3 \ |

0@ |B;T$|3:%3  <$  

| \

 @ |BA;T$} | uF3;T$}
~
i ,]_^[ SVW $ 33 $3 z  <> A  > A 2zR <> A  > A22 T  A |@ | T
| _^[
SVW P T$ $ $ T$

D$ D$ $ D$ D$ \$ 3 \$

 D$ \$ @3C \$

C D$ \$ @3C \$

C D$ \$ @

3C

\$

3 L$   >zA D$ B

@ >~A D$

B@ > A D$$ B@ > A D$( D$ \$

3  \$$3 \$(3 \$  A D$, B >zA D$03 B

@ > A D$8 B@ > A D$< D$0 \$4 3  \$83 \$<3 \$,  A D$@ B >zA D$D B@ >~A D$H3 B

@ > A D$P D$D \$H 3  \$L3 \$P3 \$@  A

D$T B

 >zA D$X B@ >~A D$\ B@ > A D$`3 B > A D$d D$X \$\ 3 \$`3 \$d3 \$T D$

 D$

3p

 v3  > A |$h z   >zA > A >~A |$l  z

3 t$h3 t$l3  Z  r A > A |$p z  >zA > A >~A |$t 3 t$p3 t$t3 r  Zzv A> A |$x

  >zA > A >~A |$|  z3 t$x3 t$|3 r Z

 v A

> A $ z >zA > A >~A $  3 $ 3  $ 3 L$|$ O

$  $  $ $

$ 

$ 

$  3 $  

3C

$  C

3 

iA  B

@

iA A B@

iA A B@

iA A B

iA A3 B

iA A B

@
B

iA A B@

iA A B

iA AB@

iA A 3 B

iA A

@

iA A B

iA A

BB@
@

iA A
AR

iA A $  $  $ 

$  $  $  

$ 3 

$ 

$  P

$ 3Q P

$ 

$  J $ 3 HJ $  $ 

$ 3B

_^[

SVW  3 

 4@ t 333 u3

jA  t33 B |3 t3 3

 L3

AvA

@rA

?nA

>jA t   L3

@vA

?rA

>nA 

AjA 3 3 2 tB  3 3 2   + 3


iA t3  \h
tttttttttttttttttttttttttttttt t ttttttttttttttt ttttttttttt   t tttttttttttttttt At ttAttt
tttttttttt t A AtAttttttt? Atttttttt t tttttttt ttAttttA ttttttttttt t  >t ttAtttttttttt
tt @t? ttAtttttttttttttttttttA tt  @ AtttttttttAttttttttt> AAttt > Attttttt   ttt ttAttt
hNAt t jjjtttt/ Pttttt$$44  ttt

tRP$
t$ttAttttttt 
VL t t$Pt
$tttP
 $ 3tttu
 D$
tD$


tttAtt$x
) @A
ttt(
tAAAA
D$i
^[
$ <$ t<$
 SVW<$t
Hu tthth tt

ttt

ttt

t  D$ At |Hu tA+ttt| btt $

[[[[

tttt t ttL t tt At t

 [

fff

tt$ W L W tyt $

t5[
WWty$
tttttjt$ytt$tt'SSSSS
tttt@tttAtHu
t$ ^[
ttttZtHu
t| [tthttttt$ftttttttttf ;

tttttt t t  t ttttt  ttttYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY


YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY>Y$

Y $$$

$$AYYYYYYYYYY3 <YYYYYY>Y$

YYYYYYYYYYYY >Y$YYYYYYYYYYYYYYYYYY Y? t$ $P YY R $ YYYYYYYYYYYY$0000YYYYYY


'YYYYYYYYYYFA KYYYYYYYY YY tYYYYY YYYYYYYYYYYYYYYYYYY YY A KAYYYYYYYYYYYYY KY

YYQ Y TYYY? tYY P|Y3YYYY YYY

Y|3 4YYYYYYYYYY YYYY  <YYYYYYYYYYYYYYYYYYYYYlY

 |Y YYYY

YYYYYYYYYYAYYYY YYYYY|YY , Y YYYYYYYYYYY

YYYYYYYYYYYYYYYYYYYy YYYYtYYYYY YYYYYY t

YY

YxYYYYY
YYY YYY
 4YYYY>Y3
$YYYYYTYYYYYY T
Y YYYY YYYYYYYYYY T Y YYYYYYYY Y YYYYYY YYY <YYYYYY

ltYYYYYYY

YY lY <YYYYYYYYY$00, YYYYYY

YYYYYYYYYYYYlYYY Y

YYY |

yt 4<YY t tYYY T

YYYYYYYY TYYY@ * |YYYYYYYYYYt'YYYY h   >Y$Y YYYYY YYYYYY

0YYt'YY Y YYYYYYYU

Y|

YY4<Y YYY

YYY

YYY Yt 4 t t |Y T

  TYYY@ (5YY 4 <

YYt |YYYYTYTYYYYY

YYYYYYYYY tYYY#t

YYYYYYYYYY YYY Y

Y YYYY x3<Y 

YY YYYY  YYYYY <   <

Y 

T

YY

4 T  tYY

$

YYY4

t

@< YYYYYYYYYYYYYY  Yt YY Y YYYYY

YYYYYYYY YYYYYYYY Y$Y <YY<< Y YYY4YYYYYYYYY |YY|

YY

 Y$

YYY



t 4YYY t t T



Y TY@ P5 $YY

Y@ ^[ @@YY|YY@

YYYlY   PYSVWU  VYy Y?;vT

 YYY

YYYYY:YYYYY  BLLLL ,  Y   YYYY T YY;Y<< Y YYY_^[YYSVW  t$Y$ ====Y+ Y

  YY

 YY

Y$

Y  ====YYY Y YYY Y$Y

34K $KYC 3K  YYK C3J $JYY Y4YYYYYf3YYYT[YV YY! 

LLLL YYYYtSLY^[

SYD h L $YYY Y Y YY<YUt 4, FY Y { } {YYYrYYtS SKJYYYYY

Y {YY Y _JYFJYFJ3Y3N0 {

t {

  YYY uY

Y    % < r3  KH SL C V

0 s N

0  t

o@ C  V

 CnI]_^[ SVWU $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$


$$$$$$N$$$$$$$$$$$$$$$  ($$$$$$$$$EEEEEEEEEEEEEE$$$$$$$$$$$$$$$$$$$$$$$$$$$$

$$  
 0$$$$$$$$$t
$$$$$$
$$$$$X$
$$  rF$$t
 ($$$$
$$$$ $$$$hhhhhhhhhhhh
$$$$$ H {t ($
$$$$
$$$$$$rhhhb $$$$$$$V$$$X
$$$$ #
$$$$P$
$ $$$$

 $$$$$$t$

$$$$$  V0
$${$$$$$$$$ $$999999999   $$$$$$ $$~$$$t  .$$$$$$$$ V0
F
$t33 u $ $$$$T$$t@@$$$  ($$ $ $ H$$$T$$P$$ $$$$$$$$  |$|$|{t $$
$Z
p
/
p$}-.

{{{{{{{{t

}
$2
$ 2$$2$
$4 {3-$ {t$$$$  $  3 8 {{{{{{{{ $$8$$$$$$$$$t$$$$$$t F,%

Das könnte Ihnen auch gefallen