| ![]() Java/Dldr.Agent.D Hallo, ich habe folgendes Problem: Ich habe Avira scannen lassen und dabei wurde "Java/Dldr.Agent.D" entdeckt. Habe bereits hier im Forum schon Tipps zu diesem problem gefunden, und habe mit "Malwarebytes" gescannt und wie beschrieben die infizierten Dateien entfernt. Dannach kam ein Neustart und seit dem habe ich zahlreiche Dateien, auf die ich nicht zugreifen kann. Anschließend habe ich noch einen scan mit "OTL" durchgeführt. Meine Frage ist, ob das Problem jetzt behoben ist und was es mit den Dateien zu tun hat, auf die ich keinen Zugriff habe. Bitte um schnellst mögliche Antwort. Mit freundlichen Grüßen BenWi |
Aus den Regeln: 5. Beschreibe Dein Problem in einigen Sätzen und arbeite diese Anleitung ab Punkt 2. durch Auch Funde von deiner Sicherheitssoftware bitte im Thema nennen: (z.B. c:\windows\virus.exe) Fehlen diese Angaben, kann und wird dir hier niemand helfen. Zitat:
| ![]() Java/Dldr.Agent.D Hier der Log von Malwarebytes:
__________________Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Datenbank Version: 4488 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 27.08.2010 13:48:26 mbam-log-2010-08-27 (13-48-26).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 219876 Laufzeit: 24 Minute(n), 58 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 2 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 3 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\csrss (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winlogon (Trojan.Agent) -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: C:\Windows\csrss.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\Windows\tv.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Windows\winlogon.exe (Trojan.Agent) -> Quarantined and deleted successfully. Soll ich die Logs von "OTL" auch posten? |
| ![]() Java/Dldr.Agent.D OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 27.08.2010 14:27:23 - Run 2 OTL by OldTimer - Version Folder = C:\Users\Strikey\Desktop 64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 59,00% Memory free 8,00 Gb Paging File | 6,00 Gb Available in Paging File | 72,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 451,07 Gb Total Space | 423,17 Gb Free Space | 93,81% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: STRIKEY-PC Current User Name: Strikey Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{26A24AE4-039D-4CA4-87B4-2F86416020FF}" = Java(TM) 6 Update 20 (64-bit) "{6A1A7434-D996-350A-F6FD-3A3EF8189B7E}" = ccc-utility64 "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64 "{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 "{C73A3942-84C8-4597-9F9B-EE227DCBA758}" = Dell Dock "{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 "Dell Wireless WLAN Card Utility" = Dell Wireless WLAN Card Utility "SynTPDeinstKey" = Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{045EB31E-AE9B-9726-428B-C56CED299D17}" = CCC Help Korean "{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}" = Microsoft Visual C++ 2005 Redistributable "{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center "{07A80ED7-EE6F-DAF7-2B68-7BFC0AB394C8}" = Catalyst Control Center Localization All "{0B2B4860-D5C9-5903-99A2-844B2F3184CC}" = CCC Help German "{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup "{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online "{1A7CDBFD-9FE9-83AC-6AB4-19EDD22D06E2}" = CCC Help Danish "{1B55C5CD-051C-6F83-9663-FAB967734746}" = Skins "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20071984-5EB1-4881-8EDB-082532ACEC6D}" = Heroes of Might and Magic V "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{233DC280-BF32-3C6A-3DE0-9C0E15A55294}" = CCC Help Swedish "{2353A12B-AA20-5EB7-3361-CEB8055FD3AC}" = CCC Help Chinese Standard "{2457326B-C110-40C3-89B0-889CC913871A}" = AVM FRITZ!DSL "{26427E43-8B33-7063-F26D-59C1120CE2DF}" = Catalyst Control Center Graphics Full New "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20 "{26C96F4B-F019-3F40-1352-AD5298450372}" = CCC Help French "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4ADEAE70-10F8-6EE1-1CB5-B68B4917C565}" = CCC Help Norwegian "{4C11F1A6-CE0F-93C8-B108-228A4A551789}" = Catalyst Control Center InstallProxy "{4E15A0E1-A588-C578-E0C3-4835BA0225ED}" = CCC Help Finnish "{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{57FE772D-FA6C-65C7-58E7-9CEC7E3501B7}" = CCC Help Italian "{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync "{64A7F1FB-ACEC-BAFB-8FAD-BB87580D796C}" = Catalyst Control Center Graphics Full Existing "{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator "{69533745-1E2D-4C98-8B4A-B7643EF9E1A2}" = Catalyst Control Center - Branding "{70AA9B4F-64F7-4B0D-ADD8-05802D61AF72}" = Windows Live Toolbar "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{79FC04F1-E592-C8D7-41CE-319A8B900902}" = CCC Help Portuguese "{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide "{82B21A86-5526-9BA3-2B17-65AF582BF267}" = Catalyst Control Center Core Implementation "{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) "{8C3737D8-5958-218F-8219-9117054430F5}" = Catalyst Control Center Graphics Light "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update "{8F803766-0BAB-CACF-5943-4099F0DFBCE7}" = CCC Help Chinese Traditional "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010 "{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars "{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack "{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn "{A7496F46-78AE-4DB2-BCF5-95F210FA6F96}" = Windows Live Movie Maker "{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software "{AC76BA86-7AD7-1031-7B44-A91000000001}" = Adobe Reader 9.1.2 - Deutsch "{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger "{AFA32E15-B53C-0C82-2C91-93C927258842}" = CCC Help Spanish "{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn "{B4483ACC-2281-6167-02E6-4171E7F9A9A8}" = Catalyst Control Center Graphics Previews Vista "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) "{C31E0F2C-FB0F-552D-C864-138726D5C19A}" = CCC Help English "{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail "{CA886961-382C-8282-AD77-0AB1659FE40D}" = Catalyst Control Center Graphics Previews Common "{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials "{CDD2DDE1-30BB-05D8-BBCE-433F54531F78}" = ccc-core-static "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1 "{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call "{D48B6973-9CC4-DFC3-3696-1BA76796C1F3}" = CCC Help Dutch "{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer "{E0D32964-37E5-8405-1AF0-D31F1120B9AE}" = CCC Help Russian "{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software) "{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F278E7E7-89AE-0F98-DEBF-DB0C5AF4971B}" = CCC Help Japanese "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Advanced Audio FX Engine" = Advanced Audio FX Engine "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "AVMFBox" = AVM FRITZ!Box Dokumentation "Dell Dock" = Dell Dock "Dell Webcam Central" = Dell Webcam Central "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8) "MSC" = McAfee Security Center "WinLiveSuite_Wave3" = Windows Live Essentials ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "World of Warcraft Trial" = Probeversion von World of Warcraft ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 23.08.2010 04:06:55 | Computer Name = Strikey-PC | Source = Swapdrive Backup | ID = 0 Description = Swapdrive Backup: Web Service Error: System.Net.WebException: Der Remotename konnte nicht aufgelöst werden: 'wsvcdell.backup.com' bei System.Net.HttpWebRequest.GetRequestStream(TransportContext& context) bei System.Net.HttpWebRequest.GetRequestStream() bei System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters) bei Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest req) bei Swapdrive.Shared.ActivationWsvcs.GetInfo() Error - 23.08.2010 04:42:07 | Computer Name = Strikey-PC | Source = Swapdrive Backup | ID = 0 Description = Swapdrive Backup: Web Service Error: System.Net.WebException: Der Remotename konnte nicht aufgelöst werden: 'wsvcdell.backup.com' bei System.Net.HttpWebRequest.GetRequestStream(TransportContext& context) bei System.Net.HttpWebRequest.GetRequestStream() bei System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters) bei Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest req) bei Swapdrive.Shared.ActivationWsvcs.GetInfo() Error - 23.08.2010 05:01:59 | Computer Name = Strikey-PC | Source = Microsoft-Windows-RestartManager | ID = 10007 Description = Die Anwendung oder der Dienst "AVM IGD CTRL Service" konnte nicht neu gestartet werden. Error - 23.08.2010 11:08:55 | Computer Name = Strikey-PC | Source = Swapdrive Backup | ID = 0 Description = Swapdrive Backup: Web Service Error: System.Net.WebException: Der Remotename konnte nicht aufgelöst werden: 'wsvcdell.backup.com' bei System.Net.HttpWebRequest.GetRequestStream(TransportContext& context) bei System.Net.HttpWebRequest.GetRequestStream() bei System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters) bei Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest req) bei Swapdrive.Shared.ActivationWsvcs.GetInfo() Error - 23.08.2010 15:04:22 | Computer Name = Strikey-PC | Source = Swapdrive Backup | ID = 0 Description = Swapdrive Backup: Web Service Error: System.Net.WebException: Der Remotename konnte nicht aufgelöst werden: 'wsvcdell.backup.com' bei System.Net.HttpWebRequest.GetRequestStream(TransportContext& context) bei System.Net.HttpWebRequest.GetRequestStream() bei System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters) bei Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest req) bei Swapdrive.Shared.ActivationWsvcs.GetInfo() Error - 24.08.2010 02:23:50 | Computer Name = Strikey-PC | Source = Swapdrive Backup | ID = 0 Description = Swapdrive Backup: Web Service Error: System.Net.WebException: Der Remotename konnte nicht aufgelöst werden: 'wsvcdell.backup.com' bei System.Net.HttpWebRequest.GetRequestStream(TransportContext& context) bei System.Net.HttpWebRequest.GetRequestStream() bei System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters) bei Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest req) bei Swapdrive.Shared.ActivationWsvcs.GetInfo() Error - 24.08.2010 06:31:09 | Computer Name = Strikey-PC | Source = EventSystem | ID = 4621 Description = Error - 24.08.2010 07:01:50 | Computer Name = Strikey-PC | Source = Swapdrive Backup | ID = 0 Description = Swapdrive Backup: Web Service Error: System.Net.WebException: Der Remotename konnte nicht aufgelöst werden: 'wsvcdell.backup.com' bei System.Net.HttpWebRequest.GetRequestStream(TransportContext& context) bei System.Net.HttpWebRequest.GetRequestStream() bei System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String methodName, Object[] parameters) bei Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest req) bei Swapdrive.Shared.ActivationWsvcs.GetInfo() [ System Events ] Error - 23.08.2010 04:45:26 | Computer Name = Strikey-PC | Source = Service Control Manager | ID = 7030 Description = Der Dienst "AVM IGD CTRL Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error - 23.08.2010 10:47:48 | Computer Name = Strikey-PC | Source = cdrom | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error - 23.08.2010 10:47:54 | Computer Name = Strikey-PC | Source = cdrom | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error - 23.08.2010 10:48:01 | Computer Name = Strikey-PC | Source = cdrom | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error - 23.08.2010 10:48:07 | Computer Name = Strikey-PC | Source = cdrom | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error - 23.08.2010 10:48:14 | Computer Name = Strikey-PC | Source = cdrom | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error - 23.08.2010 10:48:20 | Computer Name = Strikey-PC | Source = cdrom | ID = 262155 Description = Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error - 26.08.2010 03:51:05 | Computer Name = Strikey-PC | Source = Service Control Manager | ID = 7030 Description = Der Dienst "AVM IGD CTRL Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error - 26.08.2010 07:53:36 | Computer Name = Strikey-PC | Source = ACPI | ID = 327693 Description = : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft. Error - 26.08.2010 08:35:44 | Computer Name = Strikey-PC | Source = Service Control Manager | ID = 7006 Description = Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen: %%5 < End of report > |
| ![]() Java/Dldr.Agent.D OTL Logfile: Code:
ATTFilter OTL logfile created on: 27.08.2010 14:27:23 - Run 2 OTL by OldTimer - Version Folder = C:\Users\Strikey\Desktop 64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 59,00% Memory free 8,00 Gb Paging File | 6,00 Gb Available in Paging File | 72,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 451,07 Gb Total Space | 423,17 Gb Free Space | 93,81% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: STRIKEY-PC Current User Name: Strikey Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Include 64bit Scans Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Windows\SysWow64\DRIVERS\o2flash.exe File not found PRC - C:\Users\Strikey\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (Mozilla Corporation) PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe () PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (SoftThinks) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe () PRC - C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe () PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) PRC - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd) PRC - C:\Programme\Dell\DellDock\DockLogin.exe (Stardock Corporation) PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.) PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.) PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.) PRC - C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin) ========== Modules (SafeList) ========== MOD - C:\Users\Strikey\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV:64bit: - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) SRV:64bit: - (McODS) -- C:\Program Files\mcafee\VirusScan\mcods.exe (McAfee, Inc.) SRV:64bit: - (McProxy) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV:64bit: - (McOobeSv) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV:64bit: - (McNASvc) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV:64bit: - (McNaiAnn) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV:64bit: - (mcmscsvc) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV:64bit: - (McMPFSvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) SRV:64bit: - (STacSV) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\stacsv64.exe (IDT, Inc.) SRV:64bit: - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe () SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD) SRV:64bit: - (wltrysvc) -- C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE () SRV:64bit: - (AESTFilters) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe (Andrea Electronics Corporation) SRV:64bit: - (O2FLASH) -- C:\Windows\SysNative\drivers\o2flash.exe (O2Micro International) SRV - (mfevtp) -- C:\Programme\Common Files\mcafee\systemcore\mfevtps.exe (McAfee, Inc.) SRV - (SftService) -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (SoftThinks) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (UNS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) SRV - (LMS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) SRV - (DockLoginService) -- C:\Programme\Dell\DellDock\DockLogin.exe (Stardock Corporation) SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) -- C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.) SRV - (SeaPort) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.) SRV - (IGDCTRL) -- C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin) ========== Driver Services (SafeList) ========== DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation) DRV:64bit: - (mfehidk) -- C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.) DRV:64bit: - (mfefirek) -- C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.) DRV:64bit: - (mfewfpk) -- C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.) DRV:64bit: - (mfeavfk) -- C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.) DRV:64bit: - (mfeapfk) -- C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.) DRV:64bit: - (mferkdet) -- C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.) DRV:64bit: - (mfenlfk) -- C:\Windows\SysNative\drivers\mfenlfk.sys (McAfee, Inc.) DRV:64bit: - (cfwids) -- C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.) DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH) DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH) DRV:64bit: - (STHDA) -- C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.) DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated) DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.) DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.) DRV:64bit: - (O2MDGRDR) -- C:\Windows\SysNative\drivers\o2mdgx64.sys (O2Micro ) DRV:64bit: - (Acceler) -- C:\Windows\SysNative\drivers\Acceler.sys (ST Microelectronics) DRV:64bit: - (HECIx64) Intel(R) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation) DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek ) DRV:64bit: - (BCM42RLY) -- C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation) DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions) DRV:64bit: - (CtClsFlt) -- C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.) DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof () DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = Dell und MSN IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google Search IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "ICQ Search" FF - prefs.js..browser.search.selectedEngine: "ICQ Search" FF - prefs.js..browser.startup.homepage: "google.de" FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}: FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=" FF - prefs.js..network.proxy.type: 0 FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.08.26 22:30:28 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.08.25 19:57:40 | 000,000,000 | ---D | M] [2010.08.25 19:58:11 | 000,000,000 | ---D | M] -- C:\Users\Strikey\AppData\Roaming\mozilla\Extensions [2010.08.26 15:46:08 | 000,000,000 | ---D | M] -- C:\Users\Strikey\AppData\Roaming\mozilla\Firefox\Profiles\dh9x40ji.default\extensions [2010.08.26 15:46:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Strikey\AppData\Roaming\mozilla\Firefox\Profiles\dh9x40ji.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2010.06.21 17:35:24 | 000,001,042 | ---- | M] () -- C:\Users\Strikey\AppData\Roaming\Mozilla\FireFox\Profiles\dh9x40ji.default\searchplugins\icqplugin.xml [2010.08.25 19:57:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions [2010.05.31 20:32:58 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll [2010.07.23 02:48:56 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2010.07.23 02:48:56 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2010.07.23 02:48:56 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2010.07.23 02:48:56 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2010.07.23 02:48:56 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\Common Files\mcafee\systemcore\ScriptSn.20100826223028.dll (McAfee, Inc.) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.) O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20100826223028.dll (McAfee, Inc.) O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Programme\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.) O4:64bit: - HKLM..\Run: [QuickSet] C:\Programme\Dell\QuickSet\quickset.exe (Dell Inc.) O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray64.exe (IDT, Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe () O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd) O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.) O4 - HKLM..\Run: [Desktop Disc Tool] c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe () O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.) O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\RunOnce: [DSUpdateLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe (Dell) O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks) O4 - Startup: C:\Users\Strikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files (x86)\Dell\DellDock\DellDock.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O13 - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet) O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010.08.27 12:27:50 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Roaming\Malwarebytes [2010.08.27 12:27:43 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2010.08.27 12:27:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010.08.27 12:27:39 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2010.08.27 12:27:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2010.08.27 12:16:36 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Strikey\Desktop\OTL.exe [2010.08.27 09:53:41 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Roaming\Avira [2010.08.26 15:48:03 | 000,000,000 | ---D | C] -- C:\Users\Strikey\Documents\ICQ [2010.08.26 15:46:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ICQ6Toolbar [2010.08.26 15:46:00 | 000,000,000 | ---D | C] -- C:\ProgramData\ICQ [2010.08.26 15:43:30 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Roaming\ICQ [2010.08.26 15:43:29 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Local\AOL [2010.08.26 14:37:53 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox [2010.08.26 14:35:24 | 000,116,568 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys [2010.08.26 14:35:24 | 000,081,072 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys [2010.08.26 14:35:24 | 000,051,992 | ---- | C] (AVIRA GmbH) -- C:\Windows\SysWow64\drivers\avgntdd.sys [2010.08.26 14:35:24 | 000,017,016 | ---- | C] (AVIRA GmbH) -- C:\Windows\SysWow64\drivers\avgntmgr.sys [2010.08.26 14:35:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2010.08.26 14:35:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira [2010.08.26 09:51:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVM [2010.08.26 09:50:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard [2010.08.26 09:42:11 | 000,115,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\MSINET.OCX [2010.08.26 09:42:11 | 000,108,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\MSWINSCK.OCX [2010.08.26 09:42:11 | 000,069,632 | ---- | C] (Seoturk.Net) -- C:\Windows\Hit.exe [2010.08.26 09:24:06 | 000,069,120 | R--- | C] (AVM Berlin) -- C:\Windows\SysWow64\avmadd32.dll [2010.08.26 09:24:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FRITZ!Box [2010.08.26 01:26:13 | 001,942,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfshim.dll [2010.08.26 01:26:13 | 001,130,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfshim.dll [2010.08.26 01:26:13 | 000,320,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHost.exe [2010.08.26 01:26:13 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHost.exe [2010.08.26 01:26:13 | 000,109,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHostProxy.dll [2010.08.26 01:26:13 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHostProxy.dll [2010.08.26 01:26:13 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netfxperf.dll [2010.08.26 01:26:13 | 000,048,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netfxperf.dll [2010.08.26 01:26:08 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browserchoice.exe [2010.08.25 22:42:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment [2010.08.25 22:39:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard [2010.08.25 22:36:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Blizzard Entertainment [2010.08.25 22:35:52 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Local\Blizzard Entertainment [2010.08.25 22:31:37 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Blizzard Entertainment [2010.08.25 22:19:42 | 001,736,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll [2010.08.25 22:16:36 | 005,507,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe [2010.08.25 22:16:35 | 003,955,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe [2010.08.25 22:16:35 | 003,899,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe [2010.08.25 22:16:05 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll [2010.08.25 22:16:05 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2010.08.25 22:16:05 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll [2010.08.25 22:16:05 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2010.08.25 22:16:05 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe [2010.08.25 22:16:05 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe [2010.08.25 22:15:30 | 000,861,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll [2010.08.25 22:15:01 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rtutils.dll [2010.08.25 22:15:01 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rtutils.dll [2010.08.25 22:13:57 | 000,082,944 | ---- | C] (Radius Inc.) -- C:\Windows\SysWow64\iccvid.dll [2010.08.25 22:12:59 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll [2010.08.25 22:12:30 | 000,961,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll [2010.08.25 22:12:30 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll [2010.08.25 22:12:29 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdri.dll [2010.08.25 22:12:29 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSNP.ax [2010.08.25 22:12:29 | 000,258,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpg2splt.ax [2010.08.25 22:12:29 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax [2010.08.25 22:12:29 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax [2010.08.25 22:10:27 | 000,366,080 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll [2010.08.25 22:10:27 | 000,293,888 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll [2010.08.25 22:10:27 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll [2010.08.25 22:10:27 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll [2010.08.25 21:59:11 | 000,000,000 | ---D | C] -- C:\Users\Strikey\Tracing [2010.08.25 21:40:38 | 001,277,264 | ---- | C] (Microsoft Corporation) -- C:\Users\Strikey\wlsetup-custom.exe [2010.08.25 19:57:44 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Roaming\Mozilla [2010.08.25 19:57:44 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Local\Mozilla [2010.08.25 19:57:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2010.08.25 19:55:37 | 008,408,392 | ---- | C] (Mozilla) -- C:\Users\Strikey\Firefox Setup 3.6.8.exe [2010.08.25 17:24:46 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Roaming\Macromedia [2010.08.23 16:50:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Rockstar Games [2010.08.23 11:14:17 | 000,000,000 | ---D | C] -- C:\Users\Strikey\Documents\My Games [2010.08.23 11:12:22 | 000,352,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_1.dll [2010.08.23 11:12:22 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_1.dll [2010.08.23 11:12:22 | 000,083,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xinput1_1.dll [2010.08.23 11:12:22 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_1.dll [2010.08.23 11:12:16 | 003,927,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_30.dll [2010.08.23 11:12:16 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_30.dll [2010.08.23 11:12:15 | 000,355,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xactengine2_0.dll [2010.08.23 11:12:15 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_0.dll [2010.08.23 11:12:15 | 000,016,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\x3daudio1_0.dll [2010.08.23 11:12:15 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_0.dll [2010.08.23 11:12:14 | 003,830,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_29.dll [2010.08.23 11:12:14 | 003,815,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_28.dll [2010.08.23 11:12:14 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_29.dll [2010.08.23 11:12:14 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_28.dll [2010.08.23 11:12:13 | 003,823,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_25.dll [2010.08.23 11:12:13 | 003,807,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_27.dll [2010.08.23 11:12:13 | 003,767,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_26.dll [2010.08.23 11:12:13 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_25.dll [2010.08.23 11:12:13 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_27.dll [2010.08.23 11:12:13 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_26.dll [2010.08.23 11:12:12 | 003,544,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_24.dll [2010.08.23 11:12:12 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_24.dll [2010.08.23 11:06:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ubisoft [2010.08.23 10:52:33 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Roaming\FRITZ! [2010.08.23 10:52:33 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Local\FRITZ! [2010.08.23 10:50:18 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Local\Diagnostics [2010.08.23 10:45:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FRITZ!DSL [2010.08.23 10:27:17 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Roaming\Adobe [2010.08.23 10:27:17 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Local\Adobe [2010.08.23 10:09:47 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Roaming\Macrovision [2010.08.23 10:08:39 | 000,000,000 | -HSD | C] -- C:\System Recovery [2010.08.23 10:06:59 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Roaming\Dell [2010.08.23 10:06:50 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Local\DataSafeOnline [2010.08.23 10:06:45 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Local\Stardock_Corporation [2010.08.23 10:06:44 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Roaming\Roxio [2010.08.23 10:06:41 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Roaming\ATI [2010.08.23 10:06:41 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Local\ATI [2010.08.23 10:06:38 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Local\SupportSoft [2010.08.23 10:06:24 | 000,000,000 | R--D | C] -- C:\Users\Strikey\Searches [2010.08.23 10:06:14 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Roaming\Identities [2010.08.23 10:06:11 | 000,000,000 | R--D | C] -- C:\Users\Strikey\Contacts [2010.08.23 10:06:09 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Local\VirtualStore [2010.08.23 10:02:56 | 000,000,000 | --SD | C] -- C:\Users\Strikey\AppData\Roaming\Microsoft [2010.08.23 10:02:56 | 000,000,000 | R--D | C] -- C:\Users\Strikey\Videos [2010.08.23 10:02:56 | 000,000,000 | R--D | C] -- C:\Users\Strikey\Saved Games [2010.08.23 10:02:56 | 000,000,000 | R--D | C] -- C:\Users\Strikey\Pictures [2010.08.23 10:02:56 | 000,000,000 | R--D | C] -- C:\Users\Strikey\Music [2010.08.23 10:02:56 | 000,000,000 | R--D | C] -- C:\Users\Strikey\Links [2010.08.23 10:02:56 | 000,000,000 | R--D | C] -- C:\Users\Strikey\Favorites [2010.08.23 10:02:56 | 000,000,000 | R--D | C] -- C:\Users\Strikey\Downloads [2010.08.23 10:02:56 | 000,000,000 | R--D | C] -- C:\Users\Strikey\Documents [2010.08.23 10:02:56 | 000,000,000 | R--D | C] -- C:\Users\Strikey\Desktop [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\Vorlagen [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\AppData\Local\Verlauf [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\AppData\Local\Temporary Internet Files [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\Startmenü [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\SendTo [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\Recent [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\Netzwerkumgebung [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\Lokale Einstellungen [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\Documents\Eigene Videos [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\Documents\Eigene Musik [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\Eigene Dateien [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\Documents\Eigene Bilder [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\Druckumgebung [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\Cookies [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\AppData\Local\Anwendungsdaten [2010.08.23 10:02:56 | 000,000,000 | -HSD | C] -- C:\Users\Strikey\Anwendungsdaten [2010.08.23 10:02:56 | 000,000,000 | -H-D | C] -- C:\Users\Strikey\AppData [2010.08.23 10:02:56 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Local\Temp [2010.08.23 10:02:56 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Local\SoftThinks [2010.08.23 10:02:56 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Local\Microsoft [2010.08.23 10:02:56 | 000,000,000 | ---D | C] -- C:\Users\Strikey\AppData\Roaming\Media Center Programs [2010.08.23 10:02:43 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen [2010.08.23 10:02:43 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü [2010.08.23 10:02:43 | 000,000,000 | -HSD | C] -- C:\Programme [2010.08.23 10:02:43 | 000,000,000 | -HSD | C] -- C:\Programme\Gemeinsame Dateien [2010.08.23 10:02:43 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten [2010.08.23 10:02:43 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos [2010.08.23 10:02:43 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik [2010.08.23 10:02:43 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder [2010.08.23 10:02:43 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen [2010.08.23 10:02:43 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente [2010.08.23 10:02:43 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten [2010.08.18 05:31:01 | 000,000,000 | ---D | C] -- C:\Programme\Synaptics [2010.08.18 05:29:14 | 000,852,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2010.08.18 05:29:14 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2010.08.18 05:29:14 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ks.sys [2010.08.18 05:29:12 | 002,870,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe [2010.08.18 05:29:12 | 002,614,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe [2010.08.18 05:29:12 | 001,572,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll [2010.08.18 05:29:12 | 001,328,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll [2010.08.18 05:29:12 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe [2010.08.18 05:29:12 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll [2010.08.18 05:29:12 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\avifil32.dll [2010.08.18 05:29:12 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mciavi32.dll [2010.08.18 05:29:12 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msasn1.dll [2010.08.18 05:29:12 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2010.08.18 05:29:12 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2010.08.18 05:29:12 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2010.08.18 05:29:12 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2010.08.18 05:29:12 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [2010.08.18 05:29:10 | 000,148,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll [2010.08.18 05:29:10 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll [2010.08.18 05:29:10 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll [2010.08.18 05:29:10 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll [2010.08.18 05:29:09 | 001,446,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll [2010.08.18 05:29:08 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisdecd.dll [2010.08.18 05:29:08 | 000,612,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2010.08.18 05:29:08 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll [2010.08.18 05:29:08 | 000,427,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vbscript.dll [2010.08.18 05:29:06 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll [2010.08.18 05:29:06 | 000,422,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll [2010.08.18 05:29:06 | 000,369,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll [2010.08.18 05:29:06 | 000,365,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll [2010.08.18 05:29:06 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe [2010.08.18 05:29:06 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe [2010.08.18 05:29:06 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe [2010.08.18 05:29:06 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe [2010.08.18 05:29:06 | 000,306,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe [2010.08.18 05:29:06 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe [2010.08.18 05:29:06 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe [2010.08.18 05:29:06 | 000,277,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe [2010.08.18 05:29:06 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll [2010.08.18 05:29:06 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll [2010.08.18 05:29:06 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll [2010.08.18 05:29:06 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll [2010.08.18 05:29:03 | 014,629,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll [2010.08.18 05:29:03 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL [2010.08.18 05:29:03 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL [2010.08.18 05:29:03 | 011,406,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll [2010.08.18 05:29:03 | 001,975,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CertEnroll.dll [2010.08.18 05:29:03 | 001,320,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CertEnroll.dll [2010.08.18 05:29:02 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll [2010.08.18 05:29:02 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wintrust.dll [2010.08.18 05:29:02 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cabview.dll [2010.08.18 05:29:02 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cabview.dll [2010.08.18 05:28:59 | 004,062,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll [2010.08.18 05:28:59 | 003,177,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll [2010.08.18 05:28:59 | 000,687,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFx.dll [2010.08.18 05:28:59 | 000,630,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\evr.dll [2010.08.18 05:28:59 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll [2010.08.18 05:28:59 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\evr.dll [2010.08.18 05:28:59 | 000,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfds.dll [2010.08.18 05:28:59 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll [2010.08.18 05:28:59 | 000,292,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfds.dll [2010.08.18 05:28:59 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFHost.exe [2010.08.18 05:28:59 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll [2010.08.18 05:28:59 | 000,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFPlatform.dll [2010.08.18 05:28:59 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\sdbus.sys [2010.08.18 05:28:59 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\isoburn.exe [2010.08.18 05:28:59 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\isoburn.exe [2010.08.18 05:28:59 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFCoinstaller.dll [2010.08.18 05:20:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\oem [2010.08.18 05:20:36 | 000,000,000 | ---D | C] -- C:\Windows\Panther [2010.08.18 05:20:36 | 000,000,000 | ---D | C] -- C:\Drivers [2010.08.18 05:12:20 | 000,000,000 | ---D | C] -- C:\dell [2010.08.18 03:13:05 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI [2010.08.18 03:07:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dell [2010.08.18 03:06:13 | 000,000,000 | -H-D | C] -- C:\ProgramData\{D19C2D22-6043-47E7-B400-83A351841204} [2010.08.18 03:05:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office [2010.08.18 03:03:53 | 000,009,984 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfeclnk.sys [2010.08.18 03:03:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\mcafee.com [2010.08.18 03:03:08 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\mcafee [2010.08.18 03:03:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\mcafee [2010.08.18 03:03:07 | 000,000,000 | ---D | C] -- C:\Programme\mcafee.com [2010.08.18 03:03:07 | 000,000,000 | ---D | C] -- C:\Programme\mcafee [2010.08.18 03:03:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\McAfee [2010.08.18 03:03:05 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee [2010.08.18 03:03:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Uninstall [2010.08.18 03:02:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Sonic [2010.08.18 03:02:50 | 000,055,280 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\PxHlpa64.sys [2010.08.18 03:02:50 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\cdralw2k.sys [2010.08.18 03:02:50 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\cdr4_xp.sys [2010.08.18 03:02:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared [2010.08.18 03:02:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Roxio Shared [2010.08.18 03:02:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine [2010.08.18 03:02:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Macrovision [2010.08.18 03:02:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Roxio [2010.08.18 03:01:05 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Reallusion [2010.08.18 03:00:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Reallusion [2010.08.18 03:00:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Creative [2010.08.18 03:00:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dell Webcam [2010.08.18 03:00:06 | 000,224,768 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\drivers\CtAudDrv.sys [2010.08.18 03:00:06 | 000,172,704 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\drivers\CtClsFlt.sys [2010.08.18 03:00:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Creative Live! Cam [2010.08.18 02:59:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype [2010.08.18 02:59:42 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype [2010.08.18 02:59:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype [2010.08.18 02:59:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight [2010.08.18 02:59:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Sync Framework [2010.08.18 02:58:20 | 004,398,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_32.dll [2010.08.18 02:58:20 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_32.dll [2010.08.18 02:58:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition [2010.08.18 02:57:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft [2010.08.18 02:57:14 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft [2010.08.18 02:57:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live SkyDrive [2010.08.18 02:56:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live [2010.08.18 02:56:35 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH [2010.08.18 02:55:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live [2010.08.18 02:55:20 | 000,000,000 | ---D | C] -- C:\ProgramData\SupportSoft [2010.08.18 02:55:16 | 000,000,000 | ---D | C] -- C:\ProgramData\PCDr [2010.08.18 02:54:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\supportsoft [2010.08.18 02:54:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dell Support Center [2010.08.18 02:53:59 | 000,000,000 | ---D | C] -- C:\Temp [2010.08.18 02:53:57 | 000,151,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WimFltr.sys [2010.08.18 02:53:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dell DataSafe Local Backup [2010.08.18 02:53:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft CAPICOM [2010.08.18 02:53:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dell DataSafe Online [2010.08.18 02:52:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe [2010.08.18 02:52:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe [2010.08.18 02:52:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe [2010.08.18 02:52:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\postureAgent [2010.08.18 02:52:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel [2010.08.18 02:52:26 | 000,000,000 | ---D | C] -- C:\Intel [2010.08.18 02:51:25 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information [2010.08.18 02:51:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies [2010.08.18 02:51:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield [2010.08.18 02:51:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Dell [2010.08.18 02:50:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cisco [2010.08.18 02:49:33 | 001,114,624 | ---- | C] (Dell Inc.) -- C:\Windows\SysNative\BCMLogon.dll [2010.08.18 02:49:26 | 004,961,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vcredist_x64.exe [2010.08.18 02:49:26 | 004,767,744 | ---- | C] (Dell Inc.) -- C:\Windows\SysNative\bcmttls.dll [2010.08.18 02:49:26 | 000,073,216 | ---- | C] (Broadcom Corporation) -- C:\Windows\SysNative\wltrynt.dll [2010.08.18 02:49:26 | 000,022,520 | ---- | C] (Broadcom Corporation) -- C:\Windows\SysNative\drivers\bcm42rly.sys [2010.08.18 02:49:25 | 007,911,424 | ---- | C] (Dell Inc.) -- C:\Windows\SysNative\BCMWLCPL.CPL [2010.08.18 02:49:25 | 003,161,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vcredist_x64.exe [2010.08.18 02:49:23 | 000,000,000 | ---D | C] -- C:\Programme\Dell [2010.08.18 02:48:49 | 000,455,680 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\deployJava1.dll [2010.08.18 02:48:49 | 000,182,784 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaws.exe [2010.08.18 02:48:49 | 000,165,888 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaw.exe [2010.08.18 02:48:49 | 000,165,888 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\java.exe [2010.08.18 02:48:45 | 000,000,000 | ---D | C] -- C:\Programme\Java [2010.08.18 02:48:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2010.08.18 02:48:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2010.08.18 02:48:37 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll [2010.08.18 02:48:37 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2010.08.18 02:48:37 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2010.08.18 02:48:37 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe [2010.08.18 02:48:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java [2010.08.18 02:48:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed [2010.08.18 02:48:21 | 000,000,000 | ---D | C] -- C:\Programme\Dell Inc [2010.08.18 02:48:17 | 000,000,000 | -HSD | C] -- C:\Windows\Installer [2010.08.17 19:42:32 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2010.08.17 19:42:01 | 000,601,088 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\ctapo64.dll [2010.08.17 19:42:01 | 000,524,288 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\ctapo32.dll [2010.08.17 19:42:01 | 000,442,368 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AESTEC64.dll [2010.08.17 19:42:01 | 000,162,304 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AESTAC64.dll [2010.08.17 19:42:01 | 000,068,608 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AESTAR64.dll [2010.08.17 19:42:01 | 000,000,000 | ---D | C] -- C:\Programme\IDT [2010.08.17 19:42:00 | 012,572,672 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\idtcpl64.cpl [2010.08.17 19:42:00 | 003,309,568 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stlang64.dll [2010.08.17 19:42:00 | 000,564,224 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\idt64mp1.exe [2010.08.17 19:42:00 | 000,090,624 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AESTCo64.dll [2010.08.17 19:42:00 | 000,057,856 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\ctppld64.dll [2010.08.17 19:41:59 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SRSLabs [2010.08.17 19:40:27 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch [2010.08.17 19:39:42 | 000,000,000 | -HSD | C] -- C:\System Volume Information ========== Files - Modified Within 30 Days ========== [2010.08.27 14:28:50 | 001,048,576 | -HS- | M] () -- C:\Users\Strikey\NTUSER.DAT [2010.08.27 13:58:57 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2010.08.27 13:58:57 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2010.08.27 13:51:32 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010.08.27 13:51:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010.08.27 13:51:22 | 3111,550,976 | -HS- | M] () -- C:\hiberfil.sys [2010.08.27 13:50:19 | 002,247,710 | -H-- | M] () -- C:\Users\Strikey\AppData\Local\IconCache.db [2010.08.27 12:27:46 | 000,001,015 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.08.27 12:16:41 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Strikey\Desktop\OTL.exe [2010.08.26 14:35:32 | 000,002,072 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk [2010.08.26 09:07:56 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010.08.26 09:07:56 | 000,643,866 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2010.08.26 09:07:56 | 000,607,190 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010.08.26 09:07:56 | 000,126,394 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2010.08.26 09:07:56 | 000,103,568 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010.08.26 01:31:30 | 000,274,464 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2010.08.25 22:34:28 | 000,001,193 | ---- | M] () -- C:\Users\Strikey\Desktop\Probeversion von World of Warcraft.lnk [2010.08.25 21:40:46 | 001,277,264 | ---- | M] (Microsoft Corporation) -- C:\Users\Strikey\wlsetup-custom.exe [2010.08.25 19:57:42 | 000,001,945 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2010.08.25 19:55:37 | 008,408,392 | ---- | M] (Mozilla) -- C:\Users\Strikey\Firefox Setup 3.6.8.exe [2010.08.23 11:11:01 | 000,001,351 | ---- | M] () -- C:\Users\Public\Desktop\Heroes of Might and Magic V.lnk [2010.08.23 10:39:14 | 000,524,288 | -HS- | M] () -- C:\Users\Strikey\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms [2010.08.23 10:39:14 | 000,524,288 | -HS- | M] () -- C:\Users\Strikey\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms [2010.08.23 10:39:14 | 000,065,536 | -HS- | M] () -- C:\Users\Strikey\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf [2010.08.23 10:06:46 | 000,001,984 | ---- | M] () -- C:\Users\Strikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk [2010.08.23 10:03:11 | 000,057,560 | ---- | M] () -- C:\Users\Strikey\AppData\Local\GDIPFONTCACHEV1.DAT [2010.08.23 10:02:56 | 000,000,020 | -HS- | M] () -- C:\Users\Strikey\ntuser.ini [2010.08.23 10:01:55 | 000,052,870 | ---- | M] () -- C:\Windows\SysWow64\license.rtf [2010.08.23 10:01:55 | 000,052,870 | ---- | M] () -- C:\Windows\SysNative\license.rtf [2010.08.19 17:57:06 | 000,069,632 | ---- | M] (Seoturk.Net) -- C:\Windows\Hit.exe [2010.08.18 05:32:05 | 000,003,556 | RH-- | M] () -- C:\dell.sdr [2010.08.18 05:31:13 | 000,898,624 | ---- | M] () -- C:\Windows\SysNative\oem4.inf [2010.08.18 05:29:14 | 000,852,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2010.08.18 05:29:14 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2010.08.18 05:29:14 | 000,243,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ks.sys [2010.08.18 05:29:12 | 002,870,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe [2010.08.18 05:29:12 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe [2010.08.18 05:29:12 | 001,572,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll [2010.08.18 05:29:12 | 001,328,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll [2010.08.18 05:29:12 | 000,389,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe [2010.08.18 05:29:12 | 000,243,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll [2010.08.18 05:29:12 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\avifil32.dll [2010.08.18 05:29:12 | 000,084,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mciavi32.dll [2010.08.18 05:29:12 | 000,046,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msasn1.dll [2010.08.18 05:29:12 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2010.08.18 05:29:12 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2010.08.18 05:29:12 | 000,007,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2010.08.18 05:29:12 | 000,005,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2010.08.18 05:29:12 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [2010.08.18 05:29:10 | 000,148,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll [2010.08.18 05:29:10 | 000,108,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll [2010.08.18 05:29:10 | 000,100,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll [2010.08.18 05:29:10 | 000,070,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll [2010.08.18 05:29:09 | 001,446,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll [2010.08.18 05:29:08 | 000,613,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\psisdecd.dll [2010.08.18 05:29:08 | 000,612,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2010.08.18 05:29:08 | 000,465,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll [2010.08.18 05:29:08 | 000,427,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\vbscript.dll [2010.08.18 05:29:06 | 000,424,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll [2010.08.18 05:29:06 | 000,422,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll [2010.08.18 05:29:06 | 000,369,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll [2010.08.18 05:29:06 | 000,365,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll [2010.08.18 05:29:06 | 000,357,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe [2010.08.18 05:29:06 | 000,356,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe [2010.08.18 05:29:06 | 000,324,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe [2010.08.18 05:29:06 | 000,320,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe [2010.08.18 05:29:06 | 000,306,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe [2010.08.18 05:29:06 | 000,305,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe [2010.08.18 05:29:06 | 000,280,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe [2010.08.18 05:29:06 | 000,277,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe [2010.08.18 05:29:06 | 000,121,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll [2010.08.18 05:29:06 | 000,121,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll [2010.08.18 05:29:06 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll [2010.08.18 05:29:06 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll [2010.08.18 05:29:03 | 014,629,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll [2010.08.18 05:29:03 | 012,625,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL [2010.08.18 05:29:03 | 012,625,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL [2010.08.18 05:29:03 | 011,406,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll [2010.08.18 05:29:03 | 001,975,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\CertEnroll.dll [2010.08.18 05:29:03 | 001,320,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\CertEnroll.dll [2010.08.18 05:29:02 | 000,220,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll [2010.08.18 05:29:02 | 000,172,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wintrust.dll [2010.08.18 05:29:02 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cabview.dll [2010.08.18 05:29:02 | 000,132,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\cabview.dll [2010.08.18 05:28:59 | 004,062,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll [2010.08.18 05:28:59 | 003,177,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll [2010.08.18 05:28:59 | 000,687,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFx.dll [2010.08.18 05:28:59 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\evr.dll [2010.08.18 05:28:59 | 000,514,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll [2010.08.18 05:28:59 | 000,488,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\evr.dll [2010.08.18 05:28:59 | 000,376,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfds.dll [2010.08.18 05:28:59 | 000,366,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll [2010.08.18 05:28:59 | 000,292,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mfds.dll [2010.08.18 05:28:59 | 000,228,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFHost.exe [2010.08.18 05:28:59 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll [2010.08.18 05:28:59 | 000,183,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFPlatform.dll [2010.08.18 05:28:59 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\sdbus.sys [2010.08.18 05:28:59 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\isoburn.exe [2010.08.18 05:28:59 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\isoburn.exe [2010.08.18 05:28:59 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFCoinstaller.dll [2010.08.18 05:22:16 | 000,003,556 | ---- | M] () -- C:\Windows\SysWow64\drivers\1028_Dell_STU_1749.mrk [2010.08.18 05:22:16 | 000,003,556 | ---- | M] () -- C:\Windows\SysNative\drivers\1028_Dell_STU_1749.mrk [2010.08.18 03:10:58 | 000,781,162 | ---- | M] () -- C:\Windows\SysNative\chklogo6.wtl [2010.08.18 03:01:17 | 000,000,074 | RHS- | M] () -- C:\Windows\CT4CET.bin [2010.08.18 02:48:46 | 000,455,680 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\deployJava1.dll [2010.08.18 02:48:46 | 000,182,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaws.exe [2010.08.18 02:48:46 | 000,165,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaw.exe [2010.08.18 02:48:46 | 000,165,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\java.exe [2010.08.18 02:48:31 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll [2010.08.18 02:48:31 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2010.08.18 02:48:31 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2010.08.18 02:48:31 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe [2010.08.17 19:43:17 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin [2010.08.17 19:42:42 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf [2010.07.29 08:30:34 | 000,082,944 | ---- | M] (Radius Inc.) -- C:\Windows\SysWow64\iccvid.dll ========== Files Created - No Company Name ========== [2010.08.27 12:27:46 | 000,001,015 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010.08.26 14:35:32 | 000,002,072 | ---- | C] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk [2010.08.25 22:34:28 | 000,001,193 | ---- | C] () -- C:\Users\Strikey\Desktop\Probeversion von World of Warcraft.lnk [2010.08.25 19:57:42 | 000,001,945 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2010.08.23 11:11:01 | 000,001,351 | ---- | C] () -- C:\Users\Public\Desktop\Heroes of Might and Magic V.lnk [2010.08.23 10:06:46 | 000,001,984 | ---- | C] () -- C:\Users\Strikey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk [2010.08.23 10:02:56 | 001,048,576 | -HS- | C] () -- C:\Users\Strikey\NTUSER.DAT [2010.08.23 10:02:56 | 000,524,288 | -HS- | C] () -- C:\Users\Strikey\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms [2010.08.23 10:02:56 | 000,524,288 | -HS- | C] () -- C:\Users\Strikey\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms [2010.08.23 10:02:56 | 000,262,144 | -HS- | C] () -- C:\Users\Strikey\ntuser.dat.LOG1 [2010.08.23 10:02:56 | 000,065,536 | -HS- | C] () -- C:\Users\Strikey\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf [2010.08.23 10:02:56 | 000,000,020 | -HS- | C] () -- C:\Users\Strikey\ntuser.ini [2010.08.23 10:02:56 | 000,000,000 | -HS- | C] () -- C:\Users\Strikey\ntuser.dat.LOG2 [2010.08.18 05:32:05 | 000,003,556 | RH-- | C] () -- C:\dell.sdr [2010.08.18 05:22:16 | 000,003,556 | ---- | C] () -- C:\Windows\SysWow64\drivers\1028_Dell_STU_1749.mrk [2010.08.18 05:22:16 | 000,003,556 | ---- | C] () -- C:\Windows\SysNative\drivers\1028_Dell_STU_1749.mrk [2010.08.18 03:10:58 | 000,781,162 | ---- | C] () -- C:\Windows\SysNative\chklogo6.wtl [2010.08.18 03:01:17 | 000,000,074 | RHS- | C] () -- C:\Windows\CT4CET.bin [2010.08.18 03:00:36 | 000,057,656 | ---- | C] () -- C:\Windows\SysNative\drivers\FilterPC.bmp [2010.08.18 03:00:36 | 000,024,995 | ---- | C] () -- C:\Windows\SysNative\drivers\FilterPC.jpg [2010.08.18 02:49:26 | 000,058,368 | ---- | C] () -- C:\Windows\SysNative\bcmwlrmt.dll [2010.08.18 02:49:26 | 000,006,656 | ---- | C] () -- C:\Windows\SysNative\bcmwlrc.dll [2010.08.18 02:49:26 | 000,000,459 | ---- | C] () -- C:\Windows\SysWow64\vcredist_x64.bat [2010.08.18 02:49:25 | 000,000,457 | ---- | C] () -- C:\Windows\SysNative\vcredist_x64.bat [2010.08.17 19:43:17 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2010.08.17 19:43:01 | 000,898,624 | ---- | C] () -- C:\Windows\SysNative\oem4.inf [2010.08.17 19:42:42 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf [2010.08.17 19:39:42 | 3111,550,976 | -HS- | C] () -- C:\hiberfil.sys [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll ========== LOP Check ========== [2010.08.23 10:52:43 | 000,000,000 | ---D | M] -- C:\Users\Strikey\AppData\Roaming\FRITZ! [2010.08.26 18:11:53 | 000,000,000 | ---D | M] -- C:\Users\Strikey\AppData\Roaming\ICQ [2009.07.14 07:08:49 | 000,006,174 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > |
| ![]() Java/Dldr.Agent.D Das Problem ist bereits gelöst, trotzdem danke mfg BenWi |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Java/Dldr.Agent.DZitat:
| ![]() Java/Dldr.Agent.D Ein Bekannter von mir, der sich damit besser auskennt als ich hat hier letztendlich formatiert. Gruß BenWi |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Java/Dldr.Agent.D Ist letztenendes die sicherste Lösung.
