Zitat:
Zitat von Larusso
(Beitrag 543165)
was ist hier los ?
PRC - [2010.01.14 004452 000,037,888 ---- M] (Nullsoft, Inc.) -- CProgram FilesWinampwinampa.exe
Normal
PRC - [2010.01.14 004452 000,037,888 ---- M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exe | Ich hab keine Ahnung... Zitat:
Zitat von Larusso
(Beitrag 543165)
Bitte poste in Deiner nächsten Antwort
defogger_disable.txt
OTL.txt
Gmer.txt | defogger_disable.txt Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 22:38 on 17/07/2010 (****)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
Unable to read sptd.sys
SPTD -> Disabled (Service running -> reboot required)
-=E.O.F=- OTL.txt
[CODE]
OTL Logfile: Code:
OTL logfile created on: 17.07.2010 22:43:00 - Run 2
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\****\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 71,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 73,24 Gb Total Space | 24,80 Gb Free Space | 33,86% Space Free | Partition Type: NTFS
Drive D: | 5,12 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 100,01 Gb Total Space | 8,71 Gb Free Space | 8,71% Space Free | Partition Type: NTFS
Drive H: | 132,87 Gb Total Space | 1,63 Gb Free Space | 1,23% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
Drive X: | 224,85 Gb Total Space | 3,97 Gb Free Space | 1,77% Space Free | Partition Type: NTFS
Computer Name: ELCH
Current User Name: ****
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010.07.17 17:47:47 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\****\Desktop\OTL.exe
PRC - [2010.06.30 14:52:22 | 000,836,464 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2010.01.14 00:44:52 | 000,037,888 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exe
PRC - [2009.09.05 17:29:06 | 000,385,024 | ---- | M] (shbox.de) -- C:\Program Files\FreePDF_XP\fpassist.exe
PRC - [2009.07.21 14:34:28 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009.05.13 16:48:18 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009.03.05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009.03.02 13:08:43 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2009.01.21 15:19:54 | 000,092,168 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\Gaming Software\LWEMon.exe
PRC - [2008.04.24 04:32:30 | 000,598,016 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
PRC - [2008.04.24 04:31:54 | 000,176,128 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
PRC - [2007.06.05 14:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
PRC - [2005.12.21 12:52:36 | 000,987,136 | ---- | M] (TerraTec Eletronic GmbH) -- C:\Program Files\Common Files\TerraTec\Remote\TTTVRC.exe
PRC - [2004.08.04 06:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2010.07.17 17:47:47 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\****\Desktop\OTL.exe
MOD - [2010.07.17 00:19:10 | 000,046,592 | -H-- | M] () -- C:\WINDOWS\system32\dllhsn32.dll
MOD - [2004.08.04 06:57:02 | 001,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
MOD - [2004.08.04 05:01:18 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - [2009.10.20 20:19:48 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2009.08.17 08:54:36 | 000,093,336 | ---- | M] (SiSoftware) [Disabled | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP1a\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV - [2009.07.21 14:34:28 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009.05.13 16:48:18 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2008.04.24 04:32:30 | 000,598,016 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2008.04.24 04:31:54 | 000,176,128 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp)
SRV - [2007.06.05 14:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PSIService.exe -- (ProtexisLicensing)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\HYPERG~1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys -- (cpuz130)
DRV - [2010.02.05 22:32:48 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010.02.05 22:18:15 | 000,223,440 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\truecrypt.sys -- (truecrypt)
DRV - [2010.02.03 15:56:56 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2010.01.12 06:03:33 | 010,276,768 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2009.11.25 12:19:02 | 000,056,816 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009.10.20 20:19:44 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2009.08.07 23:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP1a\WNt500x86\sandra.sys -- (SANDRA)
DRV - [2009.05.11 10:12:20 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.03.30 10:33:03 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2009.02.13 12:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009.01.19 20:31:56 | 000,277,544 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2009.01.13 20:13:52 | 000,049,160 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2009.01.13 20:13:44 | 000,014,728 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2009.01.13 20:13:28 | 000,029,192 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2009.01.13 20:13:20 | 000,019,336 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2008.05.08 23:23:22 | 000,238,080 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2008.03.25 13:48:08 | 000,022,016 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2008.03.25 13:48:06 | 000,054,400 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2008.02.14 16:12:00 | 001,389,056 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\monfilt.sys -- (monfilt)
DRV - [2008.01.14 12:06:32 | 000,021,632 | ---- | M] (ManyCam LLC.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ManyCam.sys -- (ManyCam)
DRV - [2007.06.29 15:47:34 | 000,034,304 | ---- | M] (AMD, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AmdLLD.sys -- (AmdLLD)
DRV - [2006.12.04 17:13:14 | 001,121,536 | ---- | M] (Philips Semiconductors GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\3xHybrid.sys -- (3xHybrid)
DRV - [2006.07.02 00:30:28 | 000,043,520 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005.05.09 20:08:40 | 000,033,792 | ---- | M] (Team H2O) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cledx.sys -- (CLEDX)
DRV - [2005.01.07 18:07:18 | 000,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2004.08.12 20:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2004.08.04 00:10:14 | 000,015,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MPE.sys -- (MPE)
DRV - [2004.08.03 23:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2002.09.16 18:14:32 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.0.2
FF - prefs.js..extensions.enabledItems: {AB7308B2-C13C-4eba-AC78-2AD55B96EE09}:3.0.0
FF - prefs.js..extensions.enabledItems: {3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}:0.8.6.1
FF - prefs.js..extensions.enabledItems: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca}:1.2.5
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.07.01 14:04:16 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.07.01 14:04:16 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.5\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010.06.18 15:22:36 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.5\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010.03.11 16:17:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Mozilla\Extensions
[2010.02.05 22:23:18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\****\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.03.11 16:17:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010.07.17 12:42:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Mozilla\Firefox\Profiles\s7dsvfdj.default\extensions
[2010.02.08 19:06:04 | 000,000,000 | ---D | M] (Html Validator) -- C:\Documents and Settings\****\Application Data\Mozilla\Firefox\Profiles\s7dsvfdj.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}
[2010.02.08 19:06:02 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Documents and Settings\****\Application Data\Mozilla\Firefox\Profiles\s7dsvfdj.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2010.02.08 19:06:02 | 000,000,000 | ---D | M] (CSS Validator) -- C:\Documents and Settings\****\Application Data\Mozilla\Firefox\Profiles\s7dsvfdj.default\extensions\{AB7308B2-C13C-4eba-AC78-2AD55B96EE09}
[2010.02.08 00:24:50 | 000,000,000 | ---D | M] (Web Developer) -- C:\Documents and Settings\****\Application Data\Mozilla\Firefox\Profiles\s7dsvfdj.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010.04.23 10:39:28 | 000,000,000 | ---D | M] (Torbutton) -- C:\Documents and Settings\****\Application Data\Mozilla\Firefox\Profiles\s7dsvfdj.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2010.02.05 22:04:35 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.07.01 14:04:13 | 000,001,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.07.01 14:04:13 | 000,002,344 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.07.01 14:04:13 | 000,006,805 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.07.01 14:04:13 | 000,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.07.01 14:04:13 | 000,001,105 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2010.07.17 11:17:01 | 000,412,092 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14242 more lines...
O2 - BHO: (no name) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [FreePDF Assistant] C:\Program Files\FreePDF_XP\fpassist.exe (shbox.de)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] File not found
O4 - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [TerraTec Remote Control] C:\Program Files\Common Files\TerraTec\Remote\TTTVRC.exe (TerraTec Eletronic GmbH)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\****\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\****\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2010.02.05 21:10:56 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2008.06.10 15:32:42 | 000,000,044 | R--- | M] () - D:\Autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O36 - AppCertDlls: odbcdial - (C:\WINDOWS\system32\dllhsn32.dll) - C:\WINDOWS\system32\dllhsn32.dll ()
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17746534284132352)
========== Files/Folders - Created Within 90 Days ==========
[2010.07.17 17:47:45 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\****\Desktop\OTL.exe
[2010.07.17 17:36:24 | 000,000,000 | --SD | C] -- C:\Documents and Settings\****\UserData
[2010.07.17 17:33:00 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\****\Recent
[2010.07.17 14:58:42 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010.07.17 14:38:22 | 000,000,000 | ---D | C] -- C:\Program Files\lynx
[2010.07.17 14:31:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Desktop\osam_autorun_manager_5_0_portable
[2010.07.17 13:16:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Application Data\Wireshark
[2010.07.17 13:08:14 | 000,000,000 | ---D | C] -- C:\Program Files\WinPcap
[2010.07.17 13:07:32 | 000,000,000 | ---D | C] -- C:\Program Files\Wireshark
[2010.07.17 06:30:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010.07.17 06:30:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010.07.17 01:37:03 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010.07.17 01:37:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010.07.17 01:30:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Application Data\Malwarebytes
[2010.07.17 01:30:35 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.07.17 01:30:34 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.07.17 01:30:34 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.07.17 01:30:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010.07.17 00:56:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010.07.14 10:49:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2010.07.13 02:09:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Application Data\Dropbox
[2010.07.11 17:02:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\My Documents\Drakensang
[2010.07.11 17:01:40 | 000,000,000 | ---D | C] -- C:\Program Files\ProtectDisc Driver Installer
[2010.07.11 17:01:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Application Data\ProtectDisc
[2010.07.09 23:49:57 | 005,619,712 | ---- | C] (Gas Powered Games) -- C:\Documents and Settings\****\Desktop\supcom_fa_patch_1.5.3596_to_1.5.3599.exe
[2010.07.09 23:36:06 | 039,362,560 | ---- | C] (Gas Powered Games) -- C:\Documents and Settings\****\Desktop\supcom_patch_1.0.3189_to_1.1.3280.exe
[2010.07.09 07:00:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Desktop\dummy file generator12
[2010.07.08 03:00:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Local Settings\Application Data\Gas Powered Games
[2010.07.08 02:59:52 | 000,108,144 | ---- | C] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2010.07.08 02:58:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Media Center Programs
[2010.07.06 00:03:15 | 000,000,000 | ---D | C] -- C:\Program Files\MusicLab
[2010.06.30 01:22:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Application Data\Steinberg
[2010.06.30 01:18:18 | 000,033,792 | ---- | C] (Team H2O) -- C:\WINDOWS\System32\drivers\cledx.sys
[2010.06.30 01:18:11 | 000,016,896 | ---- | C] (Syncrosoft GmbH) -- C:\WINDOWS\System32\drivers\synasUSB.sys
[2010.06.26 02:40:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Local Settings\Application Data\My Games
[2010.06.22 03:24:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\My Documents\Neverwinter Nights 2
[2010.06.17 16:07:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Local Settings\Application Data\FreePDF_XP
[2010.06.17 11:18:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Application Data\Microsoft Games
[2010.06.17 01:04:53 | 000,000,000 | ---D | C] -- C:\Program Files\FreePDF_XP
[2010.06.17 01:04:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\FreePDF
[2010.06.17 01:04:24 | 000,000,000 | ---D | C] -- C:\Program Files\gs
[2010.06.10 13:40:40 | 000,000,000 | ---D | C] -- C:\Program Files\FileZilla
[2010.06.08 09:03:13 | 000,000,000 | ---D | C] -- C:\Program Files\FileZilla FTP Client
[2010.06.07 16:14:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\My Documents\Any Video Converter
[2010.06.07 16:12:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Application Data\AnvSoft
[2010.06.07 16:12:31 | 000,000,000 | ---D | C] -- C:\Program Files\Any Video Converter
[2010.06.07 06:28:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\My Documents\Disney Interactive Studios
[2010.06.05 03:41:20 | 000,000,000 | ---D | C] -- C:\Program Files\trueSpace761
[2010.06.05 02:47:47 | 000,000,000 | ---D | C] -- C:\Program Files\Python26
[2010.06.05 02:41:04 | 000,000,000 | ---D | C] -- C:\Program Files\Blender Foundation
[2010.05.30 08:36:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Application Data\DVDVideoSoftIEHelpers
[2010.05.30 08:36:49 | 000,000,000 | ---D | C] -- C:\Program Files\DVDVideoSoft
[2010.05.30 08:36:44 | 000,000,000 | ---D | C] -- C:\Program Files\Free YouTube to MP3 Converter
[2010.05.30 08:36:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DVDVideoSoft
[2010.05.28 20:04:25 | 000,094,208 | ---- | C] (Blizzard Entertainment) -- C:\WINDOWS\DIIUnin.exe
[2010.05.27 14:37:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\de-DE
[2010.05.27 12:26:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2010.05.19 16:28:33 | 000,000,000 | ---D | C] -- C:\Program Files\ManyCam 2.4
[2010.05.19 16:28:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Application Data\ManyCam
[2010.05.19 16:28:27 | 000,000,000 | ---D | C] -- C:\Program Files\Ask.com
[2010.05.19 16:14:54 | 000,000,000 | ---D | C] -- C:\Program Files\Webcam Simulator
[2010.05.17 23:29:20 | 000,278,528 | ---- | C] (Big Sphicter productions) -- C:\Documents and Settings\****\Desktop\cac106.exe
[2010.05.16 01:52:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2010.05.16 01:27:11 | 000,131,072 | ---- | C] (Sunplus) -- C:\WINDOWS\System\SP5X_32.DLL
[2010.05.09 16:16:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Application Data\X-Chat 2
[2010.05.09 16:16:01 | 000,000,000 | ---D | C] -- C:\Program Files\X-Chat 2
[2010.05.06 02:54:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Local Settings\Application Data\WMTools Downloaded Files
[2010.05.05 19:07:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Application Data\quassel-irc.org
[2010.05.03 18:44:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Desktop\schach
[2010.05.02 17:34:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Application Data\InfraRecorder
[2010.05.02 17:33:39 | 000,000,000 | ---D | C] -- C:\Program Files\InfraRecorder
[2010.04.28 23:34:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2010.04.22 06:28:57 | 000,704,512 | ---- | C] (Syncrosoft Hard- und Software GmbH) -- C:\WINDOWS\System32\SYNSOACC.dll
[2010.04.22 06:24:34 | 000,000,000 | ---D | C] -- C:\Program Files\Steinberg
[2010.04.21 19:20:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\Application Data\LucasArts
[2010.04.21 15:58:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\****\My Documents\DVDVideoSoft
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 90 Days ==========
[2010.07.17 22:40:21 | 000,275,208 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2010.07.17 22:39:47 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.07.17 22:39:46 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.07.17 22:39:10 | 013,631,488 | -H-- | M] () -- C:\Documents and Settings\****\NTUSER.DAT
[2010.07.17 22:38:41 | 000,000,020 | ---- | M] () -- C:\Documents and Settings\****\defogger_reenable
[2010.07.17 22:37:38 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\****\Desktop\Defogger.exe
[2010.07.17 20:49:29 | 000,000,574 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.07.17 20:49:29 | 000,000,270 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.07.17 20:49:29 | 000,000,223 | RHS- | M] () -- C:\boot.ini
[2010.07.17 17:47:47 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\****\Desktop\OTL.exe
[2010.07.17 16:30:35 | 000,002,285 | ---- | M] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk
[2010.07.17 15:15:14 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\****\Desktop\xtj2z9vg.exe
[2010.07.17 15:02:26 | 000,088,606 | ---- | M] () -- C:\Documents and Settings\****\My Documents\cc_20100717_150208.reg
[2010.07.17 14:58:43 | 000,000,688 | ---- | M] () -- C:\Documents and Settings\****\Desktop\CCleaner.lnk
[2010.07.17 14:38:22 | 000,001,492 | ---- | M] () -- C:\Documents and Settings\****\Desktop\Lynx Browser.lnk
[2010.07.17 13:08:18 | 000,000,073 | ---- | M] () -- C:\WINDOWS\System32\-1
[2010.07.17 13:07:51 | 000,001,501 | ---- | M] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\Wireshark.lnk
[2010.07.17 11:20:58 | 000,029,184 | ---- | M] () -- C:\Documents and Settings\****\Desktop\Miet-Anzeigen.doc
[2010.07.17 11:17:01 | 000,412,092 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.07.17 10:06:39 | 100,667,044 | ---- | M] () -- C:\Documents and Settings\****\Desktop\chaosradio_express_159_nachrichtendienste.mp3
[2010.07.17 01:37:08 | 000,000,939 | ---- | M] () -- C:\Documents and Settings\****\Desktop\Spybot - Search & Destroy.lnk
[2010.07.17 01:30:38 | 000,000,702 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.07.17 01:24:48 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.07.17 01:24:39 | 000,393,568 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.07.17 00:19:10 | 000,046,592 | -H-- | M] () -- C:\WINDOWS\System32\dllhsn32.dll
[2010.07.16 20:51:44 | 000,002,880 | -HS- | M] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2010.07.16 14:58:43 | 000,163,328 | ---- | M] () -- C:\Documents and Settings\****\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.07.15 00:03:16 | 000,004,096 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\00001119.LCS
[2010.07.13 09:14:26 | 006,178,944 | ---- | M] () -- C:\Documents and Settings\****\Desktop\Delta Blues- Drunk Hearted Man ('Personally Groovy' take ).mp3
[2010.07.12 09:33:50 | 000,119,000 | ---- | M] () -- C:\Documents and Settings\****\Application Data\GDIPFONTCACHEV1.DAT
[2010.07.11 21:34:38 | 118,095,214 | ---- | M] () -- C:\Documents and Settings\****\Desktop\chaosradio_express_158_liquidfeedback.mp3
[2010.07.11 01:36:53 | 000,021,558 | ---- | M] () -- C:\Documents and Settings\****\My Documents\019._2wav.wav
[2010.07.11 01:35:46 | 000,021,558 | ---- | M] () -- C:\Documents and Settings\****\My Documents\019.wav
[2010.07.10 23:15:49 | 000,000,551 | ---- | M] () -- C:\Documents and Settings\****\Desktop\Drakensang.lnk
[2010.07.09 23:50:31 | 005,619,712 | ---- | M] (Gas Powered Games) -- C:\Documents and Settings\****\Desktop\supcom_fa_patch_1.5.3596_to_1.5.3599.exe
[2010.07.09 23:41:22 | 039,362,560 | ---- | M] (Gas Powered Games) -- C:\Documents and Settings\****\Desktop\supcom_patch_1.0.3189_to_1.1.3280.exe
[2010.07.09 02:56:26 | 002,806,805 | ---- | M] () -- C:\Documents and Settings\****\Desktop\09 - BMission.mp3
[2010.07.08 02:59:52 | 000,108,144 | ---- | M] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2010.07.08 02:59:06 | 000,000,686 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Supreme Commander.lnk
[2010.07.07 02:21:00 | 000,000,025 | ---- | M] () -- C:\WINDOWS\popcinfot.dat
[2010.07.06 13:54:06 | 000,119,000 | ---- | M] () -- C:\Documents and Settings\****\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010.07.04 23:06:48 | 000,000,616 | ---- | M] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010.06.30 01:55:24 | 000,071,052 | ---- | M] () -- C:\Documents and Settings\****\Desktop\breeda_110g_e.mp3
[2010.06.30 01:55:15 | 000,084,844 | ---- | M] () -- C:\Documents and Settings\****\Desktop\shunta_92c_fsharp.mp3
[2010.06.30 01:55:08 | 000,070,634 | ---- | M] () -- C:\Documents and Settings\****\Desktop\breeda_110i_asharp.mp3
[2010.06.30 01:55:02 | 000,066,872 | ---- | M] () -- C:\Documents and Settings\****\Desktop\masha_117e_a.mp3
[2010.06.30 01:54:27 | 000,071,052 | ---- | M] () -- C:\Documents and Settings\****\Desktop\breeda_110e_c.mp3
[2010.06.30 01:54:21 | 000,106,578 | ---- | M] () -- C:\Documents and Settings\****\Desktop\clankmonsta_146b_fsharp.mp3
[2010.06.30 01:54:12 | 000,084,844 | ---- | M] () -- C:\Documents and Settings\****\Desktop\shunta_92i_b.mp3
[2010.06.30 01:54:05 | 000,084,426 | ---- | M] () -- C:\Documents and Settings\****\Desktop\shunta_92a_e.mp3
[2010.06.29 17:31:09 | 000,000,246 | ---- | M] () -- C:\WINDOWS\Caligari.ini
[2010.06.29 10:23:16 | 000,006,498 | ---- | M] () -- C:\Documents and Settings\****\Desktop\Ablauf Conquest.pdf
[2010.06.29 09:44:58 | 000,136,524 | ---- | M] () -- C:\Documents and Settings\****\Desktop\Geoffrey_Fahne.aep
[2010.06.29 09:30:37 | 000,080,236 | ---- | M] () -- C:\Documents and Settings\****\Desktop\Geoffrey.jpg
[2010.06.22 00:48:21 | 000,040,645 | ---- | M] () -- C:\Documents and Settings\****\Desktop\****062010.pdf
[2010.06.17 16:11:30 | 000,056,681 | ---- | M] () -- C:\Documents and Settings\****\Desktop\****hage.pdf
[2010.06.17 16:09:34 | 000,042,496 | ---- | M] () -- C:\Documents and Settings\****\Desktop\****.doc
[2010.06.17 11:12:51 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2010.06.15 23:40:02 | 000,040,960 | ---- | M] () -- C:\Documents and Settings\****\Desktop\Copy of Wordvorlage.doc
[2010.06.15 15:29:49 | 000,278,231 | ---- | M] () -- C:\Documents and Settings\****\Desktop\ARF_telserkd.sql
[2010.06.15 02:05:10 | 011,683,654 | ---- | M] () -- C:\Documents and Settings\****\My Documents\ColdSteel.pdf
[2010.06.14 15:18:37 | 175,413,889 | ---- | M] () -- C:\Documents and Settings\****\My Documents\FootballAll.mov
[2010.06.14 00:51:00 | 001,658,438 | ---- | M] () -- C:\Documents and Settings\****\Desktop\RW_ConQuest_V5.pdf
[2010.06.12 07:14:17 | 007,955,708 | -H-- | M] () -- C:\Documents and Settings\****\Local Settings\Application Data\IconCache.db
[2010.06.09 01:09:34 | 000,769,114 | ---- | M] () -- C:\Documents and Settings\****\Desktop\demo_loop_fahrstuhl.mp3
[2010.06.08 03:41:28 | 000,000,721 | ---- | M] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\Any Video Converter.lnk
[2010.06.05 13:59:19 | 000,071,537 | ---- | M] () -- C:\Documents and Settings\****\My Documents\Strecklade_01.RsScn
[2010.06.05 03:43:37 | 000,001,634 | ---- | M] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\trueSpace7.61 Beta 8.lnk
[2010.06.05 02:48:20 | 000,001,751 | ---- | M] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\Blender.lnk
[2010.06.04 23:48:28 | 000,936,078 | ---- | M] () -- C:\Documents and Settings\****\Desktop\IMAG0184.JPG
[2010.06.01 06:59:05 | 003,294,650 | ---- | M] () -- C:\Documents and Settings\****\Desktop\turrican.mp3
[2010.05.31 01:47:44 | 000,013,155 | ---- | M] () -- C:\Documents and Settings\****\Desktop\Bauchbinde_01.png
[2010.05.29 03:12:12 | 000,027,126 | ---- | M] () -- C:\WINDOWS\DIIUnin.dat
[2010.05.28 20:05:23 | 000,021,840 | ---- | M] () -- C:\WINDOWS\System32\SIntfNT.dll
[2010.05.28 20:05:23 | 000,017,212 | ---- | M] () -- C:\WINDOWS\System32\SIntf32.dll
[2010.05.28 20:05:23 | 000,012,067 | ---- | M] () -- C:\WINDOWS\System32\SIntf16.dll
[2010.05.28 20:04:26 | 000,094,208 | ---- | M] (Blizzard Entertainment) -- C:\WINDOWS\DIIUnin.exe
[2010.05.28 20:04:26 | 000,002,829 | ---- | M] () -- C:\WINDOWS\DIIUnin.pif
[2010.05.27 14:35:49 | 000,000,224 | ---- | M] () -- C:\WINDOWS\System32\spupdsvc.inf
[2010.05.27 14:34:57 | 000,488,244 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.05.27 14:34:57 | 000,432,356 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.05.27 14:34:57 | 000,067,312 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.05.24 14:26:03 | 000,308,772 | ---- | M] () -- C:\Documents and Settings\****\Desktop\ZSL_Edirol_Performance.ope
[2010.05.19 16:28:41 | 000,001,592 | ---- | M] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\ManyCam 2.4.lnk
[2010.05.15 10:40:21 | 000,308,772 | ---- | M] () -- C:\Documents and Settings\****\Desktop\Danglar_Trailer_Edirol_Performance.ope
[2010.05.11 04:50:16 | 000,000,691 | ---- | M] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\X-Chat 2.lnk
[2010.05.10 13:53:38 | 000,037,888 | ---- | M] () -- C:\Documents and Settings\****\Desktop\Kandeko - FAQ Quicktext.doc
[2010.05.02 17:33:39 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\InfraRecorder.lnk
[2010.04.29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.04.29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.04.19 23:23:37 | 000,001,740 | ---- | M] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\HijackThis.lnk
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.07.17 22:38:38 | 000,000,020 | ---- | C] () -- C:\Documents and Settings\****\defogger_reenable
[2010.07.17 22:37:38 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\****\Desktop\Defogger.exe
[2010.07.17 15:15:14 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\****\Desktop\xtj2z9vg.exe
[2010.07.17 15:02:12 | 000,088,606 | ---- | C] () -- C:\Documents and Settings\****\My Documents\cc_20100717_150208.reg
[2010.07.17 14:58:43 | 000,000,688 | ---- | C] () -- C:\Documents and Settings\****\Desktop\CCleaner.lnk
[2010.07.17 14:38:22 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\****\Desktop\Lynx Browser.lnk
[2010.07.17 13:08:17 | 000,000,073 | ---- | C] () -- C:\WINDOWS\System32\-1
[2010.07.17 13:07:51 | 000,001,501 | ---- | C] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\Wireshark.lnk
[2010.07.17 09:11:31 | 100,667,044 | ---- | C] () -- C:\Documents and Settings\****\Desktop\chaosradio_express_159_nachrichtendienste.mp3
[2010.07.17 01:37:08 | 000,000,939 | ---- | C] () -- C:\Documents and Settings\****\Desktop\Spybot - Search & Destroy.lnk
[2010.07.17 01:30:38 | 000,000,702 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.07.17 00:19:10 | 000,046,592 | -H-- | C] () -- C:\WINDOWS\System32\dllhsn32.dll
[2010.07.13 09:14:16 | 006,178,944 | ---- | C] () -- C:\Documents and Settings\****\Desktop\Delta Blues- DHM.mp3
[2010.07.11 17:01:39 | 000,004,096 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\00001119.LCS
[2010.07.11 17:01:30 | 118,095,214 | ---- | C] () -- C:\Documents and Settings\****\Desktop\chaosradio_express_158_liquidfeedback.mp3
[2010.07.11 01:36:53 | 000,021,558 | ---- | C] () -- C:\Documents and Settings\****\My Documents\019._2wav.wav
[2010.07.11 01:32:45 | 000,021,558 | ---- | C] () -- C:\Documents and Settings\****\My Documents\019.wav
[2010.07.10 23:15:49 | 000,000,551 | ---- | C] () -- C:\Documents and Settings\****\Desktop\Drakensang.lnk
[2010.07.09 02:56:24 | 002,806,805 | ---- | C] () -- C:\Documents and Settings\****\Desktop\09 - BMission.mp3
[2010.07.08 02:59:06 | 000,000,686 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SupCom.lnk
[2010.07.01 16:58:56 | 000,029,184 | ---- | C] () -- C:\Documents and Settings\****\Desktop\MA.doc
[2010.06.30 01:55:23 | 000,071,052 | ---- | C] () -- C:\Documents and Settings\****\Desktop\breeda_110g_e.mp3
[2010.06.30 01:55:15 | 000,084,844 | ---- | C] () -- C:\Documents and Settings\****\Desktop\shunta_92c_fsharp.mp3
[2010.06.30 01:55:08 | 000,070,634 | ---- | C] () -- C:\Documents and Settings\****\Desktop\breeda_110i_asharp.mp3
[2010.06.30 01:55:02 | 000,066,872 | ---- | C] () -- C:\Documents and Settings\****\Desktop\masha_117e_a.mp3
[2010.06.30 01:54:26 | 000,071,052 | ---- | C] () -- C:\Documents and Settings\****\Desktop\breeda_110e_c.mp3
[2010.06.30 01:54:21 | 000,106,578 | ---- | C] () -- C:\Documents and Settings\****\Desktop\clankmonsta_146b_fsharp.mp3
[2010.06.30 01:54:12 | 000,084,844 | ---- | C] () -- C:\Documents and Settings\****\Desktop\shunta_92i_b.mp3
[2010.06.30 01:54:05 | 000,084,426 | ---- | C] () -- C:\Documents and Settings\****\Desktop\shunta_92a_e.mp3
[2010.06.29 10:23:12 | 000,006,498 | ---- | C] () -- C:\Documents and Settings\****\Desktop\Ablauf Conquest.pdf
[2010.06.29 09:17:34 | 000,136,524 | ---- | C] () -- C:\Documents and Settings\****\Desktop\Geoffrey_Fahne.aep
[2010.06.29 08:49:01 | 000,080,236 | ---- | C] () -- C:\Documents and Settings\****\Desktop\Geoffrey.jpg
[2010.06.22 00:48:21 | 000,040,645 | ---- | C] () -- C:\Documents and Settings\****\Desktop\****062010.pdf
[2010.06.17 16:10:06 | 000,056,681 | ---- | C] () -- C:\Documents and Settings\****\Desktop\****hage.pdf
[2010.06.17 01:04:54 | 000,119,152 | ---- | C] () -- C:\WINDOWS\System32\redmon.hlp
[2010.06.17 01:04:54 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\redmonnt.dll
[2010.06.17 01:04:54 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\unredmon.exe
[2010.06.15 23:40:10 | 000,040,960 | ---- | C] () -- C:\Documents and Settings\****\Desktop\Copy of Wordvorlage.doc
[2010.06.15 15:29:49 | 000,278,231 | ---- | C] () -- C:\Documents and Settings\****\Desktop\ARF_telserkd.sql
[2010.06.15 14:39:51 | 000,042,496 | ---- | C] () -- C:\Documents and Settings\****\Desktop\****.doc
[2010.06.15 02:02:13 | 011,683,654 | ---- | C] () -- C:\Documents and Settings\****\My Documents\ColdSteel.pdf
[2010.06.14 14:33:30 | 175,413,889 | ---- | C] () -- C:\Documents and Settings\****\My Documents\FootballAll.mov
[2010.06.14 00:51:00 | 001,658,438 | ---- | C] () -- C:\Documents and Settings\****\Desktop\RW_ConQuest_V5.pdf
[2010.06.09 01:09:20 | 000,769,114 | ---- | C] () -- C:\Documents and Settings\****\Desktop\demo_loop_fahrstuhl.mp3
[2010.06.08 03:41:28 | 000,000,721 | ---- | C] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\Any Video Converter.lnk
[2010.06.05 13:32:01 | 000,071,537 | ---- | C] () -- C:\Documents and Settings\****\My Documents\Strecklade_01.RsScn
[2010.06.05 03:43:37 | 000,001,634 | ---- | C] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\trueSpace7.61 Beta 8.lnk
[2010.06.05 03:43:14 | 000,000,819 | ---- | C] () -- C:\WINDOWS\System32\regpackages.bat
[2010.06.05 02:48:20 | 000,001,751 | ---- | C] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\Blender.lnk
[2010.06.05 02:15:55 | 000,000,246 | ---- | C] () -- C:\WINDOWS\Caligari.ini
[2010.06.04 23:48:28 | 000,936,078 | ---- | C] () -- C:\Documents and Settings\****\Desktop\IMAG0184.JPG
[2010.06.01 06:53:26 | 003,294,650 | ---- | C] () -- C:\Documents and Settings\****\Desktop\turrican.mp3
[2010.05.31 01:38:40 | 000,013,155 | ---- | C] () -- C:\Documents and Settings\****\Desktop\Bauchbinde_01.png
[2010.05.28 20:05:23 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2010.05.28 20:05:23 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2010.05.28 20:05:23 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2010.05.28 20:04:27 | 000,027,126 | ---- | C] () -- C:\WINDOWS\DIIUnin.dat
[2010.05.28 20:04:26 | 000,002,829 | ---- | C] () -- C:\WINDOWS\DIIUnin.pif
[2010.05.27 14:35:49 | 000,000,224 | ---- | C] () -- C:\WINDOWS\System32\spupdsvc.inf
[2010.05.22 01:43:11 | 000,308,772 | ---- | C] () -- C:\Documents and Settings\****\Desktop\ZSL_Edirol_Performance.ope
[2010.05.19 16:28:41 | 000,001,592 | ---- | C] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\ManyCam 2.4.lnk
[2010.05.11 04:50:16 | 000,000,691 | ---- | C] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\X-Chat 2.lnk
[2010.05.07 14:06:55 | 000,037,888 | ---- | C] () -- C:\Documents and Settings\****\Desktop\Kandeko - FAQ Quicktext.doc
[2010.05.02 17:33:39 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\InfraRecorder.lnk
[2010.04.19 23:23:37 | 000,001,740 | ---- | C] () -- C:\Documents and Settings\****\Application Data\Microsoft\Internet Explorer\Quick Launch\HijackThis.lnk
[2010.02.06 00:38:12 | 000,002,880 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2010.02.06 00:38:12 | 000,000,088 | RHS- | C] () -- C:\WINDOWS\System32\5AFCDF6B76.sys
[2010.02.05 23:37:22 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll
[2010.02.05 22:38:08 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010.02.05 21:35:43 | 000,031,890 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2010.02.05 21:35:11 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2010.02.05 21:34:51 | 000,031,577 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2010.02.05 21:34:51 | 000,010,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009.10.20 20:19:30 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2008.05.03 00:46:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008.02.01 01:55:20 | 000,000,109 | ---- | C] () -- C:\WINDOWS\System32\OSENXPSUITE2005.INI
[2007.04.17 16:34:40 | 000,135,716 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2006.12.04 17:13:12 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\34CoInstaller.dll
[2004.08.04 06:56:44 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
========== LOP Check ==========
[2010.02.09 00:09:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo
[2010.02.05 22:32:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010.06.17 01:04:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreePDF
[2010.02.18 21:31:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap Games
[2010.02.06 00:28:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony
[2010.02.05 22:18:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TrueCrypt
[2010.06.07 16:12:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\AnvSoft
[2010.02.09 00:09:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Ashampoo
[2010.02.22 03:49:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Braid
[2010.03.10 04:10:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Builder
[2010.02.07 02:10:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\DAEMON Tools Lite
[2010.07.17 01:24:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Dropbox
[2010.05.30 08:41:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\DVDVideoSoftIEHelpers
[2010.07.17 21:15:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\EditPlus 3
[2010.07.16 21:09:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\FileZilla
[2010.05.02 17:34:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\InfraRecorder
[2010.04.21 19:20:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\LucasArts
[2010.05.19 16:33:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\ManyCam
[2010.04.11 06:50:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Natural Selection 2
[2010.05.23 18:51:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Opera
[2010.07.11 17:01:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\ProtectDisc
[2010.02.06 00:30:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Publish Providers
[2010.05.05 20:05:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\quassel-irc.org
[2010.03.25 06:05:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Red Alert 3
[2010.02.25 15:53:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Sony
[2010.02.06 00:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Sony Setup
[2010.06.30 01:22:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Steinberg
[2010.02.05 22:23:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Thunderbird
[2010.02.06 00:42:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\TrueCrypt
[2010.07.17 00:12:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\uTorrent
[2010.07.17 13:16:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Wireshark
[2010.05.09 16:18:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\X-Chat 2
[2010.03.03 00:19:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\****\Application Data\Zen of Sudoku
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010.02.05 21:10:56 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010.07.17 20:49:29 | 000,000,223 | RHS- | M] () -- C:\boot.ini
[2010.02.05 21:10:56 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010.07.17 20:58:16 | 000,000,900 | ---- | M] () -- C:\fpRedmon.log
[2010.02.05 21:10:56 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010.02.05 21:10:56 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004.08.04 04:38:34 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2004.08.04 04:59:34 | 000,250,032 | RHS- | M] () -- C:\ntldr
[2010.07.17 22:39:43 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2010.02.05 20:41:47 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010.02.05 20:41:47 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010.02.05 20:41:47 | 000,901,120 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\drivers\*.sys /90 >
[2010.04.29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys
[2010.04.29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
[2010.06.26 02:39:35 | 000,163,644 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys
< %systemroot%\system32\user32.dll /md5 >
[2004.08.04 06:56:48 | 000,577,024 | ---- | M] (Microsoft Corporation) MD5=C72661F8552ACE7C5C85E16A3CF505C4 -- C:\WINDOWS\system32\user32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\ws2_32.dll /md5 >
[2004.08.04 06:56:48 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 -- C:\WINDOWS\system32\ws2_32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\ws2help.dll /md5 >
[2004.08.04 06:56:48 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=9BEACB911CA61E5881102188AB7FB431 -- C:\WINDOWS\system32\ws2help.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdat e\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpd ate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report > --- --- ---
Extras.txt
[CODE]
OTL Logfile: Code:
OTL Extras logfile created on: 17.07.2010 18:19:19 - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\****\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 64,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 77,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 73,24 Gb Total Space | 24,82 Gb Free Space | 33,89% Space Free | Partition Type: NTFS
Drive D: | 5,12 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 100,01 Gb Total Space | 8,71 Gb Free Space | 8,71% Space Free | Partition Type: NTFS
Drive H: | 132,87 Gb Total Space | 1,63 Gb Free Space | 1,23% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
Drive X: | 224,85 Gb Total Space | 3,97 Gb Free Space | 1,77% Space Free | Partition Type: NTFS
Computer Name: ELCH
Current User Name: ****
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software)
https [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"G:\Mass Effect 2\Binaries\MassEffect2.exe" = G:\Mass Effect 2\Binaries\MassEffect2.exe:*:Enabled:Mass Effect 2 Game -- (BioWare)
"G:\Mass Effect 2\MassEffect2Launcher.exe" = G:\Mass Effect 2\MassEffect2Launcher.exe:*:Enabled:Mass Effect 2 Launcher -- (BioWare)
"G:\Steam\Steam.exe" = G:\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation)
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP1a\RpcAgentSrv.exe" = C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP1a\RpcAgentSrv.exe:*:Enabled:SiSoftware Deployment Agent Service -- (SiSoftware)
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP1a\WNt500x86\RpcSandraSrv.exe" = C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP1a\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service -- (SiSoftware)
"G:\Blood Bowl\BB.exe" = G:\Blood Bowl\BB.exe:*:Enabled:Blood Bowl -- (Cyanide)
"G:\Blood Bowl\Autorun\Exe\Autorun.exe" = G:\Blood Bowl\Autorun\Exe\Autorun.exe:*:Enabled:Blood Bowl - AutoRun -- ()
"G:\Steam\steamapps\common\natural selection 2\NS2.exe" = G:\Steam\steamapps\common\natural selection 2\NS2.exe:*:Enabled:Natural Selection 2 -- ()
"G:\Split Second\SplitSecond.exe" = G:\Split Second\SplitSecond.exe:*:Enabled:Split/Second -- (Disney Interactive Studios)
"G:\Neverwinter Nights 2\nwn2main.exe" = G:\Neverwinter Nights 2\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main -- (Obsidian Entertainment, Inc.)
"G:\Neverwinter Nights 2\nwn2main_amdxp.exe" = G:\Neverwinter Nights 2\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD -- (Obsidian Entertainment, Inc.)
"G:\Neverwinter Nights 2\nwupdate.exe" = G:\Neverwinter Nights 2\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater -- (Obsidian Entertainment, Inc.)
"G:\Neverwinter Nights 2\nwn2server.exe" = G:\Neverwinter Nights 2\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server -- (Obsidian Entertainment, Inc.)
"G:\Supreme Commander\bin\SupremeCommander.exe" = G:\Supreme Commander\bin\SupremeCommander.exe:*:Enabled:Supreme Commander -- (Gas Powered Games)
"G:\GPGNet\GPG.Multiplayer.Client.exe" = G:\GPGNet\GPG.Multiplayer.Client.exe:*:Enabled:GPGNet - Supreme Commander -- (Gas Powered Games)
"C:\Documents and Settings\****\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\****\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- File not found
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{1864B4F0-7777-4A57-9930-C2B307597966}" = MusicLab RealGuitar 2.0
"{1D2C96C3-A3F3-49E7-B839-95279DED837F}" = Opera 10.60
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{25A1E6A4-2DBD-4AC0-8650-8EA9A45B183D}" = Supreme Commander
"{28526951-55EF-4901-A0CA-B9AC966D1DD1}" = Split/Second
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4723f199-fa64-4233-8e6e-9fccc95a18ee}" = Python 2.6.5
"{64E72FB1-2343-4977-B4A8-262CD53D0BD3}" = Corel Paint Shop Pro Photo X2
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}" = Mass Effect 2
"{768F22DC-2D20-4F52-A9A1-5E231FB7F752}" = Logitech Gaming Software 5.04
"{7C9AD221-994C-45B2-B46D-26F5735158CF}" = Sony Vegas Pro 8.0
"{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{839916F4-D8B5-4407-BE6D-6D4EB9D96AF4}" = LIVE gaming on Windows Runtime Version 1.0.6027
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90280407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional mit FrontPage
"{91B79CFA-5662-11D4-8398-0800096F616B}" = TerraTec Cinergy TV
"{96606195-A36C-4614-9482-D4E61464159D}" = DDS Converter 2
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.3 - Deutsch
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{C194D333-B84A-4BB7-B35E-060732D98DC4}" = GPGNet
"{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2296}_is1" = SiSoftware Sandra Lite 2010.SP1a
"{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DD362256-A7A2-4524-9457-213DDC2AFC2A}" = Adobe After Effects 7.0
"{E10DB5DA-E576-40EA-A7FC-1CB2A7B283A6}" = NVIDIA PhysX
"{F20C1251-1D0A-4944-B2AE-678581B33B19}" = Neverwinter Nights 2
"{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Earth
"{FF3D660E-E5CC-47FD-8050-1B4DE3BA81A9}" = Dual-Core Optimizer
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Any Video Converter_is1" = Any Video Converter 3.0.3
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE
"ASIO4ALL" = ASIO4ALL
"Audacity_is1" = Audacity 1.2.6
"AVI2Flash Converter v.1.4_is1" = AVI2Flash Converter v.1.4
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Blender" = Blender (remove only)
"BloodBowl_is1" = Blood Bowl 1.0.1.7
"Caligari trueSpace7.61 Beta 8_is1" = Uninstall trueSpace7.61 Beta 8
"CCleaner" = CCleaner
"Collab" = Collab
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09
"Cool Edit Pro 2.1" = Cool Edit Pro 2.1
"Diablo II" = Diablo II
"Drakensang_is1" = Drakensang
"East West EWQLSO Silver Edition" = East West EWQLSO Silver Edition
"East West Ra" = East West Ra
"East West Stormdrum Kompakt" = East West Stormdrum Kompakt
"Edirol HQ Orchestral v1.01" = Edirol HQ Orchestral v1.01
"EditPlus 3" = EditPlus 3
"FileZilla Client" = FileZilla Client 3.3.3
"FL Studio 8" = FL Studio 8
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.3
"Free M4a to MP3 Converter_is1" = Free M4a to MP3 Converter 6.1
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.5
"FreePDF_XP" = FreePDF (Remove only)
"GPL Ghostscript 8.71" = GPL Ghostscript 8.71
"HijackThis" = HijackThis 2.0.2
"IL Download Manager" = IL Download Manager
"Image-Line PoiZone v2.1" = Image-Line PoiZone v2.1
"InfraRecorder" = InfraRecorder
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Plattform-Geräte-Manager
"InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0
"InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Lynx Web Browser_is1" = Lynx 2.8.5rel.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"ManyCam" = ManyCam 2.4 (remove only)
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"mIRC" = mIRC
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"Mozilla Thunderbird (3.0.5)" = Mozilla Thunderbird (3.0.5)
"Native Instruments Absynth 4" = Native Instruments Absynth 4
"Native Instruments FM8 v1.0.1.002 VSTi DXi RTAS" = Native Instruments FM8 v1.0.1.002 VSTi DXi RTAS
"Natural Selection_is1" = Natural Selection 3.2
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OpenAL" = OpenAL
"PoiZone" = PoiZone
"Polipo" = Polipo 1.0.4
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"RADVideo" = RAD Video Tools
"Redirection Port Monitor" = RedMon - Redirection Port Monitor
"reFX quadraSID 1.6.0_is1" = reFX quadraSID 1.6.0
"seopowersuite" = SEO SpyGlass
"Starcraft" = Starcraft
"Steam App 10" = Counter-Strike
"Steam App 400" = Portal
"Steam App 4900" = Zen of Sudoku
"Steam App 4920" = Natural Selection 2
"Steam App 70" = Half-Life
"SWiSHmax" = SWiSHmax
"The Grand" = Steinberg The Grand
"Tor" = Tor 0.2.1.22
"Toxic Biohazard" = Toxic Biohazard
"TrueCrypt" = TrueCrypt
"Uninstall_is1" = Uninstall 1.0.0.1
"uTorrent" = µTorrent
"Vidalia" = Vidalia 0.2.6
"Virtual Guitarist" = Steinberg Virtual Guitarist
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinPcapInst" = WinPcap 4.1.1
"WinRAR archiver" = WinRAR
"Wireshark" = Wireshark 1.2.9
"X-Chat 2_is1" = X-Chat 2.8.6-2
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"YDKJG" = YOU DON'T KNOW JACK®
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-2052111302-343818398-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ExeIco" = ExeIco (remove only)
"Winamp Detect" = Winamp Erkennungs-Plug-in
========== Last 10 Event Log Errors ==========
[ System Events ]
Error - 28.05.2010 14:26:33 | Computer Name = ELCH | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 28.05.2010 14:26:37 | Computer Name = ELCH | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 28.05.2010 14:26:40 | Computer Name = ELCH | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 28.05.2010 14:26:48 | Computer Name = ELCH | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 28.05.2010 14:26:52 | Computer Name = ELCH | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 28.05.2010 14:26:56 | Computer Name = ELCH | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 28.05.2010 14:27:02 | Computer Name = ELCH | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 28.05.2010 14:27:06 | Computer Name = ELCH | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 28.05.2010 14:27:10 | Computer Name = ELCH | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 28.05.2010 14:27:13 | Computer Name = ELCH | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
< End of report > --- --- ---
Gmar liefere ich gleich nach, vorher noch kurz der Hinweis:
Avira war während der Scans deaktiviert, LAN-Verbindung habe ich versucht zu deaktivieren, habe allerdings eine Fehlermeldung bekommen: Code:
"Error Disabling Connection- It is not possible to disable the connection at this time. This connection may have one or more protocals that do not support Plug-and-Play" |