| >neu )TR/Dropper.gen , zuvor bekommen GEN/PwdZIP zu HÜLFE so hab hier von einer freundin pc stehen ^^ dachte ja mach ich mal fix heile....... *denkste* ! windows xp *hust* da ich linux benutze hab ich kaum Probleme *grins* nagut fange ich mal an :O
älteres ereignis ist der GEN/PwdZIP (...................anwendungsdatei/spybot - search & destroy\recovery\WinGEMA.zip]
der wurde in Quarantäne gesteckt ^^ ist ja auch fein. Aber denke weg ist er ja noch nicht oder?
nagut der andre der dazu gekommen ist, da er sich einsamm gefühlt hat, ist der TR/Dropper.Gen wurde von antivir erkannt beim download von antivira ^^(antivira_free_antivirus_898de.exe)wollte sie cd brennen so ne sicherheits cd! Echtzeitscanner meint; Malware gefunden!!!!! nähre infos sagen [trojan]
könnte fehler meldungs sein oder auch nicht......
nun seid ihr gefragt ihr götter in gelb? ^^ (Forumfarbe)
>>>>hab euch noch mm log und olt log beigefügt<<<< Zitat:
Malwarebytes Anti-Malware
Datenbank Version: v2012.02.28.02
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
schnitzel :P
29.02.2012 08:24:58
mbam-log-2012-02-29 (08-24-58).txt
Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 220614
Laufzeit: 13 Minute(n), 12 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 2
HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt.
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
habe dann reinigen gemacht! |
olt Zitat:
OTL logfile created on: 29.02.2012 09:41:20 - Run 4
OTL by OldTimer - Version Folder = C:\Dokumente und Einstellungen\xxxx\Desktop\Neuer Ordner\olt
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,75 Gb Total Physical Memory | 1,21 Gb Available Physical Memory | 69,42% Memory free
3,60 Gb Paging File | 3,14 Gb Available in Paging File | 87,05% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Programme
Drive C: | 48,83 Gb Total Space | 29,65 Gb Free Space | 60,73% Space Free | Partition Type: NTFS
Drive D: | 122,07 Gb Total Space | 122,00 Gb Free Space | 99,94% Space Free | Partition Type: NTFS
Drive F: | 127,19 Gb Total Space | 74,28 Gb Free Space | 58,40% Space Free | Partition Type: NTFS
Drive H: | 962,07 Mb Total Space | 942,53 Mb Free Space | 97,97% Space Free | Partition Type: FAT32
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ==========
PRC - [2012.02.29 14:55:18 | 000,583,680 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\xxxxxxx\Desktop\Neuer Ordner\olt\OTL.exe
PRC - [2011.10.11 14:00:02 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.10.11 13:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2011.10.11 13:59:37 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.10.11 13:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.06.06 16:16:20 | 000,671,552 | ---- | M] (TuneUp Software) -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
PRC - [2011.06.06 16:14:42 | 001,524,544 | ---- | M] (TuneUp Software) -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
PRC - [2010.03.04 22:38:00 | 000,071,096 | ---- | M] () -- C:\Programme\CDBurnerXP\NMSAccessU.exe
PRC - [2008.04.14 10:00:00 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINXP\explorer.exe ========== Modules (No Company Name) ==========
MOD - [2012.01.03 14:10:46 | 000,301,056 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.DEU
MOD - [2011.10.11 13:59:51 | 000,398,288 | ---- | M] () -- C:\Programme\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2010.03.04 22:38:00 | 000,071,096 | ---- | M] () -- C:\Programme\CDBurnerXP\NMSAccessU.exe
MOD - [2008.10.16 20:46:00 | 000,466,944 | ---- | M] () -- C:\WINXP\system32\nvshell.dll ========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (wuauserv)
SRV - File not found [On_Demand | Stopped] -- -- (WPFFontCache_v0400)
SRV - [2011.10.11 13:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.10.11 13:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.06.06 16:14:42 | 001,524,544 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2011.06.06 16:12:18 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINXP\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2010.03.04 22:38:00 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Programme\CDBurnerXP\NMSAccessU.exe -- (NMSAccess)
SRV - [2006.10.26 18:49:34 | 000,441,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2006.10.26 13:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose) ========== Driver Services (SafeList) ==========
DRV - [2012.02.15 15:48:39 | 000,137,416 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINXP\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.10.11 14:00:01 | 000,074,640 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINXP\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.10.11 14:00:01 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINXP\system32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2011.06.06 16:07:20 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2010.06.17 14:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINXP\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.11.12 13:48:56 | 000,005,504 | ---- | M] () [File_System | Auto | Running] -- C:\WINXP\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009.06.28 17:36:36 | 000,017,920 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINXP\system32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2008.10.31 04:38:08 | 004,942,336 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINXP\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008.08.01 03:36:26 | 000,022,016 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINXP\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2008.08.01 03:36:20 | 000,054,784 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINXP\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2006.07.01 22:30:28 | 000,043,520 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINXP\system32\drivers\AmdK8.sys -- (AmdK8) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINXP\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINXP\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Programme\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Programme\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.02.17 18:14:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2012.01.16 17:07:21 | 000,000,000 | ---D | M]
[2011.06.29 14:26:46 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\xxxxxxxx\Anwendungsdaten\Mozilla\Extensions
[2012.01.05 19:19:48 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\xxxxxxxx\Anwendungsdaten\Mozilla\Firefox\Profiles\xd7m9659.default\extensions
[2011.06.29 14:26:28 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.02.17 18:14:13 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2012.02.14 18:26:15 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.02.14 18:26:15 | 000,002,252 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.02.14 18:26:15 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.14 18:26:15 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.14 18:26:15 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.14 18:26:15 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2012.02.12 08:12:47 | 000,441,342 | ---- | M]) - C:\WINXP\system32\drivers\etc\hosts
O1 - Hosts: localhost
O1 - Hosts: www.007guard.com
O1 - Hosts: 007guard.com
O1 - Hosts: 008i.com
O1 - Hosts: www.008k.com
O1 - Hosts: 008k.com
O1 - Hosts: www.00hq.com
O1 - Hosts: 00hq.com
O1 - Hosts: 010402.com
O1 - Hosts: www.032439.com
O1 - Hosts: 032439.com
O1 - Hosts: www.0scan.com
O1 - Hosts: 0scan.com
O1 - Hosts: 1000gratisproben.com
O1 - Hosts: www.1000gratisproben.com
O1 - Hosts: 1001namen.com
O1 - Hosts: www.1001namen.com
O1 - Hosts: 100888290cs.com
O1 - Hosts: www.100888290cs.com
O1 - Hosts: www.100sexlinks.com
O1 - Hosts: 100sexlinks.com
O1 - Hosts: 10sek.com
O1 - Hosts: www.10sek.com
O1 - Hosts: www.1-2005-search.com
O1 - Hosts: 1-2005-search.com
O1 - Hosts: 15168 more lines...
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4 - HKLM..\Run: [Alcmtr] C:\WINXP\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINXP\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Dokumente und Einstellungen\xxxxxxx\Startmenü\Programme\Autostart\CurseClientStartup.ccip ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{735EC899-950D-4A48-82EA-83DA9E46760D}: DhcpNameServer =
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINXP\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINXP\system32\userinit.exe) - C:\WINXP\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\xxxxxxxxxxxxxx\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\xxxxxxxxxx\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2011.06.29 13:59:37 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{60711741-e073-11e0-a54b-002522907983}\Shell - "" = AutoRun
O33 - MountPoints2\{60711741-e073-11e0-a54b-002522907983}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{60711741-e073-11e0-a54b-002522907983}\Shell\AutoRun\command - "" = H:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ==========
[2012.02.29 09:35:59 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxx\Desktop\Neuer Ordner
[2012.02.29 09:34:04 | 000,583,680 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxx\Desktop\OTL.exe
[2012.02.29 09:21:00 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxx\Desktop\logs
[2012.02.28 11:33:05 | 000,000,000 | ---D | C] -- C:\WINXP\ERDNT
[2012.02.28 11:32:50 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxxx\Startmenü\Programme\Verwaltung
[2012.02.28 07:11:35 | 000,000,000 | ---D | C] -- C:\Download
[2012.02.28 07:10:56 | 000,000,000 | ---D | C] -- C:\Nexon
[2012.02.28 07:10:55 | 000,446,464 | ---- | C] (NEXON Inc.) -- C:\WINXP\NEXON_EU_DownloaderUpdater.exe
[2012.02.23 16:23:56 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\DirectX
[2012.02.23 15:13:34 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\xxxxxxxxxxx\Startmenü\Programme\gamigo Games
[2012.02.21 08:45:51 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\xxxxxxxxxxx\Startmenü\Programme\Curse
[2012.02.21 08:18:57 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\GameForge
[2012.02.21 08:18:56 | 000,000,000 | ---D | C] -- C:\Programme\GameForge
[2012.02.21 08:18:38 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DCompiler_43.dll
[2012.02.21 08:18:38 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\XAudio2_7.dll
[2012.02.21 08:18:38 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine3_7.dll
[2012.02.21 08:18:38 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\XAPOFX1_5.dll
[2012.02.21 08:18:37 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DX9_43.dll
[2012.02.21 08:18:37 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dcsx_43.dll
[2012.02.21 08:18:37 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx10_43.dll
[2012.02.21 08:18:37 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx11_43.dll
[2012.02.21 08:18:36 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\XAudio2_6.dll
[2012.02.21 08:18:36 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\XAudio2_5.dll
[2012.02.21 08:18:36 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine3_6.dll
[2012.02.21 08:18:36 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\XAPOFX1_4.dll
[2012.02.21 08:18:36 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\X3DAudio1_7.dll
[2012.02.21 08:18:35 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dcsx_42.dll
[2012.02.21 08:18:35 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DCompiler_42.dll
[2012.02.21 08:18:35 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine3_5.dll
[2012.02.21 08:18:34 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx10_42.dll
[2012.02.21 08:18:34 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx11_42.dll
[2012.02.21 08:18:33 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DX9_41.dll
[2012.02.21 08:18:33 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DCompiler_41.dll
[2012.02.21 08:18:33 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\XAudio2_4.dll
[2012.02.21 08:18:33 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx10_41.dll
[2012.02.21 08:18:33 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\XAPOFX1_3.dll
[2012.02.21 08:18:32 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DCompiler_40.dll
[2012.02.21 08:18:32 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx10_40.dll
[2012.02.21 08:18:32 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine3_4.dll
[2012.02.21 08:18:32 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\X3DAudio1_6.dll
[2012.02.21 08:18:31 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DX9_40.dll
[2012.02.21 08:18:31 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\XAudio2_3.dll
[2012.02.21 08:18:31 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine3_3.dll
[2012.02.21 08:18:31 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\XAPOFX1_2.dll
[2012.02.21 08:18:31 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\X3DAudio1_5.dll
[2012.02.21 08:18:30 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine3_2.dll
[2012.02.21 08:18:29 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\XAudio2_1.dll
[2012.02.21 08:18:29 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\XAPOFX1_0.dll
[2012.02.21 08:18:28 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DX9_38.dll
[2012.02.21 08:18:28 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DCompiler_38.dll
[2012.02.21 08:18:28 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx10_38.dll
[2012.02.21 08:18:28 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine3_1.dll
[2012.02.21 08:18:28 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\X3DAudio1_4.dll
[2012.02.21 08:18:27 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\XAudio2_0.dll
[2012.02.21 08:18:27 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine3_0.dll
[2012.02.21 08:18:27 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\X3DAudio1_3.dll
[2012.02.21 08:18:26 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DX9_37.dll
[2012.02.21 08:18:26 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DCompiler_37.dll
[2012.02.21 08:18:26 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx10_37.dll
[2012.02.21 08:18:26 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine2_10.dll
[2012.02.21 08:18:25 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx9_36.dll
[2012.02.21 08:18:25 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DCompiler_36.dll
[2012.02.21 08:18:25 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx10_36.dll
[2012.02.21 08:18:25 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine2_9.dll
[2012.02.21 08:18:24 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx9_35.dll
[2012.02.21 08:18:24 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DCompiler_35.dll
[2012.02.21 08:18:24 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx10_35.dll
[2012.02.21 08:18:23 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx9_34.dll
[2012.02.21 08:18:23 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DCompiler_34.dll
[2012.02.21 08:18:23 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx10_34.dll
[2012.02.21 08:18:23 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine2_8.dll
[2012.02.21 08:18:23 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\X3DAudio1_2.dll
[2012.02.21 08:18:22 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx10_33.dll
[2012.02.21 08:18:22 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine2_7.dll
[2012.02.21 08:18:22 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xinput1_3.dll
[2012.02.21 08:18:21 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx9_33.dll
[2012.02.21 08:18:21 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\D3DCompiler_33.dll
[2012.02.21 08:18:20 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx9_32.dll
[2012.02.21 08:18:20 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine2_6.dll
[2012.02.21 08:18:20 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine2_5.dll
[2012.02.21 08:18:20 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine2_4.dll
[2012.02.21 08:18:20 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\x3daudio1_1.dll
[2012.02.21 08:18:19 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine2_3.dll
[2012.02.21 08:18:19 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine2_2.dll
[2012.02.21 08:18:19 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xinput1_2.dll
[2012.02.21 08:18:18 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine2_1.dll
[2012.02.21 08:18:18 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xinput1_1.dll
[2012.02.21 08:18:14 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx9_30.dll
[2012.02.21 08:18:14 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx9_29.dll
[2012.02.21 08:18:14 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xactengine2_0.dll
[2012.02.21 08:18:14 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\x3daudio1_0.dll
[2012.02.21 08:18:13 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx9_28.dll
[2012.02.21 08:18:13 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx9_27.dll
[2012.02.21 08:18:13 | 000,061,136 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\xinput9_1_0.dll
[2012.02.21 08:18:12 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx9_25.dll
[2012.02.21 08:18:12 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx9_26.dll
[2012.02.21 08:18:11 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\d3dx9_24.dll
[2012.02.14 17:25:23 | 000,000,000 | ---D | C] -- C:\Programme\stinger
[2012.02.12 15:44:20 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\xxxxxxxxxxx\Startmenü\Programme\WinRAR
[2012.02.12 15:44:20 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\WinRAR
[2012.02.12 15:44:11 | 000,000,000 | ---D | C] -- C:\Programme\WinRAR
[2012.02.11 11:52:25 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Warcraft III
[2012.02.11 07:11:30 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Elaborate Bytes
[1 C:\WINXP\System32\*.tmp files -> C:\WINXP\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ==========
[2012.02.29 14:55:18 | 000,583,680 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxx\Desktop\OTL.exe
[2012.02.29 08:26:30 | 000,448,470 | ---- | M] () -- C:\WINXP\System32\perfh007.dat
[2012.02.29 08:26:30 | 000,432,356 | ---- | M] () -- C:\WINXP\System32\perfh009.dat
[2012.02.29 08:26:30 | 000,080,104 | ---- | M] () -- C:\WINXP\System32\perfc007.dat
[2012.02.29 08:26:30 | 000,067,312 | ---- | M] () -- C:\WINXP\System32\perfc009.dat
[2012.02.29 08:22:32 | 000,200,819 | ---- | M] () -- C:\WINXP\System32\nvapps.xml
[2012.02.29 08:22:27 | 000,002,048 | --S- | M] () -- C:\WINXP\bootstat.dat
[2012.02.28 13:10:14 | 000,146,808 | ---- | M] () -- C:\WINXP\System32\FNTCACHE.DAT
[2012.02.28 11:45:03 | 000,000,231 | ---- | M] () -- C:\WINXP\System32\nxEuUninstall.bat
[2012.02.28 11:45:02 | 000,446,464 | ---- | M] (NEXON Inc.) -- C:\WINXP\NEXON_EU_DownloaderUpdater.exe
[2012.02.26 09:36:00 | 000,002,206 | ---- | M] () -- C:\WINXP\System32\wpa.dbl
[2012.02.23 15:13:34 | 000,000,637 | ---- | M] () -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxx\Desktop\Fiesta Online(EU_German).lnk
[2012.02.22 16:49:07 | 000,086,528 | ---- | M] () -- C:\WINXP\bnetunin.exe
[2012.02.21 08:54:01 | 000,000,531 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\World of Warcraft.lnk
[2012.02.21 08:46:00 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxxxxx\Startmenü\Programme\Autostart\CurseClientStartup.ccip
[2012.02.21 08:45:51 | 000,000,312 | ---- | M] () -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxx\Desktop\Curse Client.appref-ms
[2012.02.21 08:18:57 | 000,001,838 | ---- | M] () -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxxxxx\Desktop\AION Free-To-Play.lnk
[2012.02.17 06:56:05 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\WINXP\System32\FlashPlayerCPLApp.cpl
[2012.02.15 15:48:39 | 000,137,416 | ---- | M] (Avira GmbH) -- C:\WINXP\System32\drivers\avipbb.sys
[2012.02.12 08:12:47 | 000,441,342 | R--- | M] () -- C:\WINXP\System32\drivers\etc\hosts.20120217-070937.backup
[2012.02.12 08:12:47 | 000,441,342 | ---- | M] () -- C:\WINXP\System32\drivers\etc\hosts.20120228-115906.backup
[2012.02.12 08:12:47 | 000,441,342 | ---- | M] () -- C:\WINXP\System32\drivers\etc\hosts
[2012.02.11 11:52:53 | 000,000,669 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Warcraft III - The Frozen Throne.lnk
[2012.02.11 07:11:36 | 000,000,590 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Virtual CloneDrive.lnk
[2012.01.30 14:12:15 | 000,441,096 | R--- | M] () -- C:\WINXP\System32\drivers\etc\hosts.20120204-121413.backup
[2012.01.30 14:12:15 | 000,441,096 | ---- | M] () -- C:\WINXP\System32\drivers\etc\hosts.20120212-081247.backup
[1 C:\WINXP\System32\*.tmp files -> C:\WINXP\System32\*.tmp -> ] ========== Files Created - No Company Name ==========
[2012.02.28 07:10:56 | 000,000,231 | ---- | C] () -- C:\WINXP\System32\nxEuUninstall.bat
[2012.02.23 15:13:34 | 000,000,637 | ---- | C] () -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxxxxxxx\Desktop\Fiesta Online(EU_German).lnk
[2012.02.22 16:49:07 | 000,086,528 | ---- | C] () -- C:\WINXP\bnetunin.exe
[2012.02.21 17:14:03 | 000,948,504 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2012.02.21 08:46:00 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxxx\Startmenü\Programme\Autostart\CurseClientStartup.ccip
[2012.02.21 08:18:57 | 000,001,838 | ---- | C] () -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxx\Desktop\AION Free-To-Play.lnk
[2012.02.11 11:52:25 | 000,000,669 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Warcraft III - The Frozen Throne.lnk
[2012.02.11 07:11:36 | 000,000,590 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Virtual CloneDrive.lnk
[2011.12.31 16:11:55 | 000,005,504 | ---- | C] () -- C:\WINXP\System32\drivers\StarOpen.sys
[2011.11.04 09:55:15 | 000,027,748 | -H-- | C] () -- C:\WINXP\System32\mlfcache.dat
[2011.10.19 11:00:25 | 000,032,608 | ---- | C] () -- C:\WINXP\king-uninstall.exe
[2011.09.16 16:07:09 | 000,021,840 | ---- | C] () -- C:\WINXP\System32\SIntfNT.dll
[2011.09.16 16:07:09 | 000,017,212 | ---- | C] () -- C:\WINXP\System32\SIntf32.dll
[2011.09.16 16:07:09 | 000,012,067 | ---- | C] () -- C:\WINXP\System32\SIntf16.dll
[2011.09.16 16:01:30 | 000,032,611 | ---- | C] () -- C:\WINXP\DIIUnin.dat
[2011.09.12 11:57:45 | 000,012,800 | ---- | C] () -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxxxxxxx\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.06.29 16:48:08 | 000,004,984 | R--- | C] () -- C:\WINXP\System32\drivers\nvphy.bin
[2011.06.29 14:52:08 | 000,004,073 | ---- | C] () -- C:\WINXP\ODBCINST.INI
[2011.06.29 14:50:59 | 000,146,808 | ---- | C] () -- C:\WINXP\System32\FNTCACHE.DAT
[2011.06.29 14:26:42 | 000,000,000 | ---- | C] () -- C:\WINXP\nsreg.dat
[2011.06.29 14:08:25 | 001,630,208 | ---- | C] () -- C:\WINXP\System32\nwiz.exe
[2011.06.29 14:08:24 | 001,703,936 | ---- | C] () -- C:\WINXP\System32\nvwdmcpl.dll
[2011.06.29 14:08:24 | 001,019,904 | ---- | C] () -- C:\WINXP\System32\nvwimg.dll
[2011.06.29 14:08:23 | 000,466,944 | ---- | C] () -- C:\WINXP\System32\nvshell.dll
[2011.06.29 14:08:23 | 000,286,720 | ---- | C] () -- C:\WINXP\System32\nvnt4cpl.dll
[2011.06.29 14:08:22 | 001,486,848 | ---- | C] () -- C:\WINXP\System32\nview.dll
[2011.06.29 14:08:22 | 001,339,392 | ---- | C] () -- C:\WINXP\System32\nvdspsch.exe
[2011.06.29 14:08:21 | 000,442,368 | ---- | C] () -- C:\WINXP\System32\nvappbar.exe
[2011.06.29 14:08:18 | 000,425,984 | ---- | C] () -- C:\WINXP\System32\keystone.exe
[2011.06.29 14:02:10 | 000,002,048 | --S- | C] () -- C:\WINXP\bootstat.dat
[2011.06.29 13:56:37 | 000,021,740 | ---- | C] () -- C:\WINXP\System32\emptyregdb.dat ========== LOP Check ==========
[2011.10.11 14:23:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Battle.net
[2011.12.31 16:12:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Canneverbe Limited
[2011.12.14 16:46:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PMB Files
[2011.06.29 14:28:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software
[2011.06.29 14:27:06 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2011.12.31 16:12:07 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxxxxxxxxxx\Anwendungsdaten\Canneverbe Limited
[2011.11.04 09:53:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxxxxxxxxxxx\Anwendungsdaten\LolClient
[2012.01.04 18:42:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxxxxxxxxxxx\Anwendungsdaten\Safer Networking
[2011.10.29 16:18:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxxxxxxxxxxx\Anwendungsdaten\Stellarium
[2011.07.01 00:01:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxxxxxxx\Anwendungsdaten\TS3Client
[2011.07.02 11:01:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\xxxxxxxxxxxxxxxxx\Anwendungsdaten\TuneUp Software ========== Purity Check ==========
< End of report >
extra Zitat:
OTL Extras logfile created on: 29.02.2012 09:41:20 - Run 4
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
1,75 Gb Total Physical Memory | 1,21 Gb Available Physical Memory | 69,42% Memory free
3,60 Gb Paging File | 3,14 Gb Available in Paging File | 87,05% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Programme
Drive C: | 48,83 Gb Total Space | 29,65 Gb Free Space | 60,73% Space Free | Partition Type: NTFS
Drive D: | 122,07 Gb Total Space | 122,00 Gb Free Space | 99,94% Space Free | Partition Type: NTFS
Drive F: | 127,19 Gb Total Space | 74,28 Gb Free Space | 58,40% Space Free | Partition Type: NTFS
Drive H: | 962,07 Mb Total Space | 942,53 Mb Free Space | 97,97% Space Free | Partition Type: FAT32
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ==========
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ==========
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "C:\Programme\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Programme\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Programme\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] ========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
"Start" = 0
"Start" = 2 ========== Firewall Settings ==========
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"56459:TCP" = 56459:TCP:*:Enabled:Pando Media Booster
"56459:UDP" = 56459:UDP:*:Enabled:Pando Media Booster
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet isabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet isabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet isabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet isabled:@xpsp2res.dll,-22002 ========== Authorized Applications List ==========
"C:\Programme\Pando Networks\Media Booster\PMB.exe" = C:\Programme\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()
"C:\Dokumente und Einstellungen\xxxxxxxxxx\Lokale Einstellungen\Apps\2.0\NTM0KZLA.EHO\N40BD6AO.NO8\curs..tion_eee711038731a406_0004.0000_0d453ed5fea2fe48\CurseClient.exe" = C:\Dokumente und Einstellungen\xxxxxxxxxx\Lokale Einstellungen\Apps\2.0\NTM0KZLA.EHO\N40BD6AO.NO8\curs..tion_eee711038731a406_0004.0000_0d453ed5fea2fe48\CurseClient.exe:* isabled:Curse Client 4.0 -- (Curse)
"C:\Programme\Diablo III Beta\Diablo III.exe" = C:\Programme\Diablo III Beta\Diablo III.exe:* isabled iablo III Retail -- (Blizzard Entertainment)
"C:\Programme\Pando Networks\Media Booster\PMB.exe" = C:\Programme\Pando Networks\Media Booster\PMB.exe:* isabled:Pando Media Booster -- ()
"F:\WOOOOAR\BackgroundDownloader.exe" = F:\WOOOOAR\BackgroundDownloader.exe:* isabled:BackgroundDownloader.exe -- (Blizzard Entertainment)
"C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Battle.net\Agent\Agent.516\Agent.exe" = C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Battle.net\Agent\Agent.516\Agent.exe:* isabled:Blizzard Agent -- (Blizzard Entertainment)
"C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Battle.net\Agent\Agent.515\Agent.exe" = C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Battle.net\Agent\Agent.515\Agent.exe:* isabled:Blizzard Agent -- (Blizzard Entertainment)
"F:\WOOOOAR\Launcher.exe" = F:\WOOOOAR\Launcher.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment)
"F:\WOOOOAR\WoW-x.x.x.x-" = F:\WOOOOAR\WoW-x.x.x.x-*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe" = C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe:*:Enabled:NEXON_EU_Downloader_Engine -- () ========== HKEY_LOCAL_MACHINE Uninstall List ==========
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011
"{296B2D8E-CE82-92AF-B2E8-A646E7CB78A2}_is1" = RegAlyzer
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{5D4C60AA-84E6-4E1A-8A68-69970D387BE1}" = TuneUp Utilities Language Pack (de-DE)
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{90120000-0010-0407-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (German) 12
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC54E544-3E42-443C-A91D-A00A6974C592}" = NVIDIA PhysX v8.10.13
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.2) - Deutsch
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU
"{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AION Free-To-Play" = AION Free-To-Play
"Avira AntiVir Desktop" = Avira Free Antivirus
"Battle.net" = Battle.net
"Celestia_is1" = Celestia 1.6.1
"Diablo II" = Diablo II
"Diablo III Beta" = Diablo III Beta
"Fiesta Online(EU_German)" = Fiesta Online(EU_German) 1.04.000
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 10.0.2 (x86 de)" = Mozilla Firefox 10.0.2 (x86 de)
"NCLauncher_GameForge" = NC Launcher (GameForge)
"NVIDIA Drivers" = NVIDIA Drivers
"Stellarium_is1" = Stellarium
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"TuneUp Utilities 2011" = TuneUp Utilities 2011
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 1.1.11
"Warcraft III" = Warcraft III
"Winamp" = Winamp
"WinRAR archiver" = WinRAR 4.10 (32-Bit)
"World of Warcraft" = World of Warcraft
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0 ========== HKEY_CURRENT_USER Uninstall List ==========
"090215de958f1060" = Curse Client
"Warcraft III" = Warcraft III ========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 04.01.2012 13:55:30 | Computer Name = xxxxxxxxxx | Source = VSS | ID = 12289
Description = Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\Volume{1b638f55-a25e-11e0-8664-806d6172696f},0xc0000000,0x00000003,...)".
hr = 0x80070005.
Error - 04.01.2012 13:55:58 | Computer Name = xxxxxxxxxx | Source = VSS | ID = 12289
Description = Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\Volume{1b638f55-a25e-11e0-8664-806d6172696f},0xc0000000,0x00000003,...)".
hr = 0x80070005.
Error - 04.01.2012 13:56:44 | Computer Name = xxxxxxxxxx | Source = VSS | ID = 12289
Description = Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\Volume{1b638f55-a25e-11e0-8664-806d6172696f},0xc0000000,0x00000003,...)".
hr = 0x80070005.
Error - 04.01.2012 13:58:29 | Computer Name = xxxxxxxxxx | Source = VSS | ID = 12289
Description = Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\Volume{1b638f55-a25e-11e0-8664-806d6172696f},0xc0000000,0x00000003,...)".
hr = 0x80070005.
Error - 04.01.2012 14:00:31 | Computer Name = xxxxxxxxxx | Source = VSS | ID = 12289
Description = Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\Volume{1b638f55-a25e-11e0-8664-806d6172696f},0xc0000000,0x00000003,...)".
hr = 0x80070005.
Error - 17.01.2012 05:35:20 | Computer Name = xxxxxxxxxx | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung spybotsd.exe, Version, fehlgeschlagenes
Modul spybotsd.exe, Version, Fehleradresse 0x000049ee.
Error - 26.01.2012 04:25:16 | Computer Name = xxxxxxxxxx | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung turatingsynch.exe, Version 10.0.4200.95,
fehlgeschlagenes Modul xmlrtl120.bpl, Version 12.0.3420.21218, Fehleradresse 0x0009903d.
Error - 28.01.2012 12:38:29 | Computer Name = xxxxxxxxxx | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung winamp.exe, Version, fehlgeschlagenes
Modul ntdll.dll, Version 5.1.2600.5755, Fehleradresse 0x0001ac4a.
Error - 01.02.2012 10:50:54 | Computer Name = xxxxxxxxxx | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung winamp.exe, Version, fehlgeschlagenes
Modul ntdll.dll, Version 5.1.2600.5755, Fehleradresse 0x0001ac4a.
Error - 29.02.2012 04:31:25 | Computer Name = xxxxxxxxxx | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung teatimer.exe, Version, fehlgeschlagenes
Modul teatimer.exe, Version, Fehleradresse 0x0006e66e.
[ System Events ]
Error - 10.02.2012 10:07:25 | Computer Name = xxxxxxxxxx | Source = Cdrom | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\CdRom0.
Error - 10.02.2012 10:07:31 | Computer Name = xxxxxxxxxx | Source = Cdrom | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\CdRom0.
Error - 10.02.2012 10:50:13 | Computer Name = xxxxxxxxxx | Source = Cdrom | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\CdRom0.
Error - 25.02.2012 13:03:11 | Computer Name = xxxxxxxxxx | Source = Service Control Manager | ID = 7034
Description = Dienst "NMSAccess" wurde unerwartet beendet. Dies ist bereits 1 Mal
Error - 28.02.2012 04:18:44 | Computer Name = xxxxxxxxxx | Source = Dhcp | ID = 1002
Description = Die IP-Adresslease für die Netzwerkkarte mit der Netzwerkadresse
002522907983 wurde durch den DHCP-Server abgelehnt (der DHCP-Server
hat eine DHCPNACK-Meldung gesendet).
Error - 28.02.2012 08:10:31 | Computer Name = xxxxxxxxxx | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatic Updates" wurde mit folgendem Fehler beendet:
Error - 28.02.2012 08:10:33 | Computer Name = xxxxxxxxxx | Source = sr | ID = 1
Description = Beim Verarbeiten der Datei "" auf Volume "HarddiskVolume1" ist im
Wiederherstellungsfilter der unerwartete Fehler "0xC0000001" aufgetreten. Die Volumeüberwachung
wurde angehalten.
Error - 28.02.2012 10:37:18 | Computer Name = xxxxxxxxxx | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatic Updates" wurde mit folgendem Fehler beendet:
Error - 29.02.2012 01:39:07 | Computer Name = xxxxxxxxxx | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatic Updates" wurde mit folgendem Fehler beendet:
Error - 29.02.2012 03:22:31 | Computer Name = xxxxxxxxxx | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatic Updates" wurde mit folgendem Fehler beendet:
< End of report >
| |