lilith love | 22.04.2011 16:51 | Schritt #1: Fix mit OTL ========== OTL ========== | Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully. | Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully. | C:\Users\Nina\AppData\Roaming\Azureus\updates folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\torrents folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\tmp folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\subs\temp folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\subs folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\shares folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\rss folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\plugins\azupnpav folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\plugins\azemp folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\plugins\aefeatman_v folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\plugins folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\net folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\logs\save folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\logs folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\dht\net3 folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\dht folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus\active folder moved successfully. | C:\Users\Nina\AppData\Roaming\Azureus folder moved successfully. | Folder move failed. C:\Programme\Ask.com scheduled to be moved on reboot. | Folder move failed. C:\Programme\LimeWire scheduled to be moved on reboot. | C:\Programme\Vuze\splist folder moved successfully. | C:\Programme\Vuze\plugins\azupnpav folder moved successfully. | C:\Programme\Vuze\plugins\azupdater folder moved successfully. | C:\Programme\Vuze\plugins\azemp\mplayer folder moved successfully. | C:\Programme\Vuze\plugins\azemp folder moved successfully. | C:\Programme\Vuze\plugins folder moved successfully. | Folder move failed. C:\Programme\Vuze scheduled to be moved on reboot. | ========== REGISTRY ========== | Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{17ECF3A7-2F93-4205-A4EE-708A58920872} deleted successfully. | Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17ECF3A7-2F93-4205-A4EE-708A58920872}\ not found. | Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{732DC946-4E61-4660-9D85-B710B4B3759B} deleted successfully. | Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{732DC946-4E61-4660-9D85-B710B4B3759B}\ not found. | Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{EE3A834D-6AF3-44E1-88C7-A0D6B78A8BF4}C:\program files\vuze\azureus.exe deleted successfully. | Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{7E3C0F0A-3393-41E2-A514-CFFECDA2C51B}C:\program files\vuze\azureus.exe deleted successfully. | ========== COMMANDS ========== | | OTL by OldTimer - Version 3.2.22.3 log created on 04222011_101504 | Files\Folders moved on Reboot... | Folder move failed. C:\Programme\Ask.com scheduled to be moved on reboot. | Folder move failed. C:\Programme\LimeWire scheduled to be moved on reboot. | Folder move failed. C:\Programme\Vuze scheduled to be moved on reboot. | Registry entries deleted on Reboot... | Schritt #2: Kontrollscan mit Malwarebytes Malwarebytes' Anti-Malware 1.50.1.1100 | www.malwarebytes.org | Datenbank Version: 6417 | Windows 6.0.6002 Service Pack 2 | Internet Explorer 9.0.8112.16421 | 22.04.2011 10:44:35 | mbam-log-2011-04-22 (10-44-35).txt | Art des Suchlaufs: Quick-Scan | Durchsuchte Objekte: 172473 | Laufzeit: 11 Minute(n), 10 Sekunde(n) | Infizierte Speicherprozesse: 0 | Infizierte Speichermodule: 0 | Infizierte Registrierungsschlüssel: 0 | Infizierte Registrierungswerte: 0 | Infizierte Dateiobjekte der Registrierung: 0 | Infizierte Verzeichnisse: 0 | Infizierte Dateien: 0 | Infizierte Speicherprozesse: | (Keine bösartigen Objekte gefunden) | Infizierte Speichermodule: | (Keine bösartigen Objekte gefunden) | Infizierte Registrierungsschlüssel: | (Keine bösartigen Objekte gefunden) | Infizierte Registrierungswerte: | (Keine bösartigen Objekte gefunden) | Infizierte Dateiobjekte der Registrierung: | (Keine bösartigen Objekte gefunden) | Infizierte Verzeichnisse: | (Keine bösartigen Objekte gefunden) | Infizierte Dateien: | (Keine bösartigen Objekte gefunden) | Schritt #4: ESET Online Scanner ESETSmartInstaller@High as downloader log: | all ok | # version=7 | # OnlineScannerApp.exe=1.0.0.1 | # OnlineScanner.ocx=1.0.0.6427 | # api_version=3.0.2 | # EOSSerial=6f049069c42ac1498b739e8b24a5f4da | # end=finished | # remove_checked=false | # archives_checked=true | # unwanted_checked=true | # unsafe_checked=false | # antistealth_checked=true | # utc_time=2011-04-22 02:15:02 | # local_time=2011-04-22 04:15:02 (+0100, Mitteleuropäische Sommerzeit) | # country="Austria" | # lang=1033 | # osver=6.0.6002 NT Service Pack 2 | # compatibility_mode=1797 16775165 100 100 2315400 78364665 1598587 0 | # compatibility_mode=5892 16776574 100 100 8046 141000956 0 0 | # compatibility_mode=8192 67108863 100 0 260 260 0 0 | # scanned=214647 | # found=1 | # cleaned=0 | # scan_time=13600 | C:\_OTL\MovedFiles\04212011_104649\C_Users\Nina\AppData\Roaming\8E94923317F1B90AFE3951B201FEA533\local.ini Win32/Adware.AntimalwareDoctor.AE.Gen application (unable to clean) 00000000000000000000000000000000 I |
bzgl. "unable to clean" -> liegt das daran, dass meine Internetverbindung abgebrochen ist? Schritt #5: Systemscan mit OTL
OTL.txt
OTL Logfile: Code:
OTL logfile created on: 22.04.2011 17:16:59 - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Nina\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000C07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 45,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220,28 Gb Total Space | 23,78 Gb Free Space | 10,79% Space Free | Partition Type: NTFS
Drive D: | 10,00 Gb Total Space | 5,92 Gb Free Space | 59,20% Space Free | Partition Type: NTFS
Drive F: | 10,53 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: DELL_1 | User Name: Nina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Nina\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\AutoInstall\ZD1211B_Auto_Install_CD_Only_Gen_0ACE20FF\AutoEJCD.EXE ()
PRC - C:\Programme\pdf24\pdf24.exe (Geek Software GmbH)
PRC - C:\Programme\pdf24\pdf24-DocTool.exe (Geek Software GmbH)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Programme\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Programme\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Programme\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Programme\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Programme\Huawei technologies\Mobile Connect\Mobile Connect.exe (Huawei Technologies Co., Ltd.)
PRC - C:\Windows\System32\stacsv.exe (IDT, Inc.)
PRC - C:\Programme\RocketDock\RocketDock.exe ()
PRC - C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Programme\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Programme\Common Files\microsoft shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\Nina\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (SBSDWSCService) -- C:\Programme\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (STacSV) -- C:\Windows\System32\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) -- C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (DSBrokerService) -- C:\Program Files\DellSupport\brkrsvc.exe ()
========== Driver Services (SafeList) ==========
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (seehcri) -- C:\Windows\System32\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV - (ggsemc) -- C:\Windows\System32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) -- C:\Windows\System32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (athrusb) -- C:\Windows\System32\drivers\athrusb.sys (Atheros Communications, Inc.)
DRV - (OEM02Dev) -- C:\Windows\System32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (NETw4v32) Intel(R) -- C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (STHDA) -- C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (OEM02Vfx) -- C:\Windows\System32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (hwdatacard) -- C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (dsunidrv) -- C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (bcm4sbxp) -- C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) Intel(R) -- C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (DSproct) -- C:\Programme\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (W700obex) -- C:\Windows\System32\drivers\W700obex.sys (MCCI)
DRV - (W700mgmt) Sony Ericsson W700 USB WMC Device Management Drivers (WDM) -- C:\Windows\System32\drivers\W700mgmt.sys (MCCI)
DRV - (W700mdm) -- C:\Windows\System32\drivers\W700mdm.sys (MCCI)
DRV - (W700mdfl) -- C:\Windows\System32\drivers\W700mdfl.sys (MCCI)
DRV - (W700bus) Sony Ericsson W700 Driver driver (WDM) -- C:\Windows\System32\drivers\W700bus.sys (MCCI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (de)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/ig"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: {a0faa0a4-f1a7-4098-9a74-21efc3a92372}:4.0.1
FF - prefs.js..extensions.enabledItems: {8e9008b4-ec7c-4c2a-828e-007d5d2dad22}:1.2
FF - prefs.js..extensions.enabledItems: {37fa1426-b82d-11db-8314-0800200c9a66}:2.7.7
FF - prefs.js..extensions.enabledItems: optimizegoogle@optimizegoogle.com:0.78.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.27 18:06:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.04.22 12:15:24 | 000,000,000 | ---D | M]
[2009.08.01 20:03:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Nina\AppData\Roaming\mozilla\Extensions
[2009.08.01 20:03:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Nina\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org
[2011.04.22 17:14:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Nina\AppData\Roaming\mozilla\Firefox\Profiles\6hf3mhn8.default\extensions
[2010.04.27 22:50:44 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Nina\AppData\Roaming\mozilla\Firefox\Profiles\6hf3mhn8.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.04.22 10:09:24 | 000,000,000 | ---D | M] (WebMail Notifier) -- C:\Users\Nina\AppData\Roaming\mozilla\Firefox\Profiles\6hf3mhn8.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
[2009.08.20 16:43:25 | 000,000,000 | ---D | M] ("Spamavert.com") -- C:\Users\Nina\AppData\Roaming\mozilla\Firefox\Profiles\6hf3mhn8.default\extensions\{8e9008b4-ec7c-4c2a-828e-007d5d2dad22}
[2010.11.15 21:51:08 | 000,000,000 | ---D | M] (DictionarySearch) -- C:\Users\Nina\AppData\Roaming\mozilla\Firefox\Profiles\6hf3mhn8.default\extensions\{a0faa0a4-f1a7-4098-9a74-21efc3a92372}
[2011.04.08 13:18:21 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Nina\AppData\Roaming\mozilla\Firefox\Profiles\6hf3mhn8.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.12.27 22:55:00 | 000,000,000 | ---D | M] (OptimizeGoogle) -- C:\Users\Nina\AppData\Roaming\mozilla\Firefox\Profiles\6hf3mhn8.default\extensions\optimizegoogle@optimizegoogle.com
[2011.04.22 12:15:43 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.04.22 12:15:43 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2009.02.20 03:10:50 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2011.04.22 12:15:43 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.04.22 12:15:02 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.05.05 10:34:08 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Programme\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2011.03.10 12:32:30 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2011.03.10 12:32:30 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2011.03.10 12:32:30 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2011.03.10 12:32:30 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2011.03.10 12:32:30 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2011.04.21 11:28:38 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programme\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O4 - HKLM..\Run: [AutoEJCD_0ACE20FF] C:\Program Files\AutoInstall\ZD1211B_Auto_Install_CD_Only_Gen_0ACE20FF\AutoEJCD.EXE ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [PDFPrint] C:\Programme\pdf24\pdf24.exe (Geek Software GmbH)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - Startup: C:\Users\Nina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk.disabled ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - c:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - c:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Nina\AppData\Roaming\Mozilla\Firefox\Desktop Hintergrund.bmp
O24 - Desktop BackupWallPaper: C:\Users\Nina\AppData\Roaming\Mozilla\Firefox\Desktop Hintergrund.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2007.07.20 12:13:16 | 000,106,496 | R--- | M] (Huawei Technologies Co., Ltd.) - F:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2006.07.10 20:15:18 | 000,000,046 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.04.22 12:24:01 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2011.04.22 12:23:26 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Nina\Desktop\esetsmartinstaller_enu.exe
[2011.04.22 12:16:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2011.04.22 12:16:01 | 000,000,000 | ---D | C] -- C:\Programme\Common Files\Java
[2011.04.22 12:15:24 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2011.04.22 12:15:24 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011.04.22 12:15:23 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011.04.22 12:15:23 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011.04.22 12:11:56 | 000,885,024 | ---- | C] (Sun Microsystems, Inc.) -- C:\Users\Nina\Desktop\jre-6u24-windows-i586-iftw.exe
[2011.04.22 10:14:08 | 000,000,000 | ---D | C] -- C:\Users\Nina\Desktop\Boris Italienisch
[2011.04.22 10:13:46 | 000,000,000 | ---D | C] -- C:\Users\Nina\Desktop\Log Files 21.4
[2011.04.21 19:11:44 | 000,000,000 | ---D | C] -- C:\Users\Nina\Desktop\0503399 Systemantrag 2010-09-01 Bewilligung - ab 2010-09 94,00 Euro
[2011.04.21 11:43:49 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011.04.21 11:07:30 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011.04.21 11:07:30 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011.04.21 11:07:30 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011.04.21 11:07:20 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011.04.21 11:06:46 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.04.21 11:06:23 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011.04.21 10:46:49 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.04.20 15:12:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2011.04.20 15:12:51 | 000,000,000 | ---D | C] -- C:\Programme\7-Zip
[2011.04.19 00:03:07 | 000,000,000 | ---D | C] -- C:\Users\Nina\Documents\Anti-Malware
[2011.04.18 23:50:19 | 000,000,000 | ---D | C] -- C:\Programme\a-squared Free
[2011.04.18 20:09:41 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Nina\Desktop\OTL.exe
[2011.04.18 19:48:59 | 000,000,000 | ---D | C] -- C:\Users\Nina\AppData\Roaming\Malwarebytes
[2011.04.18 19:48:37 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.04.18 19:48:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.04.18 19:48:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.04.18 19:48:29 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.04.18 19:48:29 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2011.04.18 19:47:27 | 007,734,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Nina\Desktop\herbert.exe
[2011.04.18 19:38:06 | 000,000,000 | ---D | C] -- C:\Users\Nina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WLAN Software
[2011.04.18 19:36:53 | 000,894,976 | ---- | C] (Atheros Communications, Inc.) -- C:\Windows\System32\drivers\athrusb.sys
[2011.04.18 19:36:53 | 000,000,000 | ---D | C] -- C:\Programme\WLAN_Software
[2011.04.18 19:36:26 | 000,000,000 | ---D | C] -- C:\Programme\AutoInstall
[2011.04.14 00:38:06 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2011.04.14 00:38:06 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011.04.14 00:38:05 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2011.04.14 00:38:05 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2011.04.14 00:38:04 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011.04.14 00:38:04 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2011.04.14 00:38:04 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2011.04.14 00:38:04 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2011.04.14 00:38:03 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2011.04.14 00:38:03 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2011.04.14 00:38:02 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2011.04.14 00:38:02 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2011.04.14 00:38:02 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2011.04.14 00:38:02 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2011.04.14 00:38:02 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2011.04.14 00:38:01 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2011.04.14 00:38:01 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2011.04.14 00:38:01 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011.04.14 00:38:01 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2011.04.14 00:38:01 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2011.04.14 00:38:00 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011.04.14 00:38:00 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2011.04.14 00:38:00 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2011.04.14 00:38:00 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2011.04.14 00:38:00 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2011.04.14 00:37:58 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011.04.14 00:37:57 | 001,797,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011.04.14 00:37:57 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2011.04.14 00:37:57 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2011.04.14 00:37:57 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2011.04.14 00:37:57 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2011.04.14 00:37:57 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2011.04.14 00:37:57 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2011.04.14 00:37:57 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2011.04.14 00:37:56 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2011.04.14 00:37:56 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2011.04.14 00:37:56 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2011.04.14 00:37:56 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2011.04.14 00:37:56 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2011.04.14 00:36:25 | 000,979,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFH264Dec.dll
[2011.04.14 00:36:25 | 000,357,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFHEAACdec.dll
[2011.04.14 00:36:24 | 000,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfmp4src.dll
[2011.04.14 00:36:24 | 000,261,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
[2011.04.14 00:36:22 | 002,873,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
[2011.04.14 00:36:22 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfps.dll
[2011.04.14 00:36:20 | 000,209,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll
[2011.04.14 00:36:17 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2011.04.14 00:36:17 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
[2011.04.14 00:36:16 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2011.04.14 00:36:16 | 000,486,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2011.04.14 00:36:15 | 001,029,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
[2011.04.14 00:36:15 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll
[2011.04.14 00:36:15 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2011.04.14 00:36:15 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
[2011.04.14 00:36:15 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2011.04.14 00:36:14 | 000,847,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OpcServices.dll
[2011.04.14 00:36:14 | 000,667,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelinesvc.exe
[2011.04.14 00:36:14 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2011.04.14 00:36:14 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelineprxy.dll
[2011.04.14 00:36:13 | 001,554,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xpsservices.dll
[2011.04.14 00:36:13 | 000,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2011.04.14 00:33:22 | 000,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll
[2011.04.14 00:33:22 | 000,369,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll
[2011.04.14 00:33:22 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxdiag.exe
[2011.04.14 00:33:22 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxdiagn.dll
[2011.04.14 00:33:21 | 000,321,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PhotoMetadataHandler.dll
[2011.04.14 00:33:21 | 000,189,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll
[2011.04.14 00:22:44 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2011.04.14 00:22:42 | 000,288,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2011.04.14 00:22:14 | 001,696,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gameux.dll
[2011.04.14 00:22:13 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
[2011.04.14 00:22:12 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
[2011.04.14 00:21:40 | 000,310,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\unregmp2.exe
[2011.04.14 00:20:57 | 000,714,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl
[2011.04.14 00:20:36 | 001,162,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll
[2011.04.14 00:20:35 | 001,136,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll
[2011.04.14 00:20:30 | 000,292,864 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2011.04.14 00:20:30 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2011.04.14 00:20:16 | 002,041,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011.04.14 00:19:52 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe
[2011.04.14 00:08:31 | 000,191,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSCOVER.exe
[2011.04.04 21:35:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pdf24
[2011.03.29 16:40:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Langenscheidt Vokabeltrainer 2.0
[2011.03.29 16:35:41 | 000,000,000 | ---D | C] -- C:\Programme\Vokabeltrainer
[2011.03.28 19:58:26 | 000,000,000 | ---D | C] -- C:\Users\Nina\AppData\Roaming\Avira
[2011.03.27 18:08:29 | 000,000,000 | ---D | C] -- C:\Users\Nina\AppData\Local\PDF24
[2011.03.27 13:54:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.03.27 13:51:38 | 000,000,000 | ---D | C] -- C:\Programme\iPod
[2011.03.27 13:51:28 | 000,000,000 | ---D | C] -- C:\Programme\iTunes
[2011.03.27 12:55:10 | 000,000,000 | ---D | C] -- C:\Users\Nina\Desktop\Italienisch OSTERN
[2009.02.03 21:08:37 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Nina\AppData\Roaming\pcouffin.sys
========== Files - Modified Within 30 Days ==========
[2011.04.22 16:20:52 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.04.22 16:20:52 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.04.22 12:23:40 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Nina\Desktop\esetsmartinstaller_enu.exe
[2011.04.22 12:15:00 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011.04.22 12:15:00 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011.04.22 12:15:00 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011.04.22 12:14:59 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2011.04.22 12:11:57 | 000,885,024 | ---- | M] (Sun Microsystems, Inc.) -- C:\Users\Nina\Desktop\jre-6u24-windows-i586-iftw.exe
[2011.04.22 10:28:37 | 000,628,910 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.04.22 10:28:37 | 000,595,946 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.04.22 10:28:37 | 000,127,412 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.04.22 10:28:37 | 000,105,276 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.04.22 10:21:05 | 000,177,678 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2011.04.22 10:21:04 | 000,177,678 | ---- | M] () -- C:\ProgramData\nvModes.001
[2011.04.22 10:20:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.04.22 10:20:41 | 2145,431,552 | -HS- | M] () -- C:\hiberfil.sys
[2011.04.22 10:19:00 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2011.04.21 11:28:38 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011.04.21 11:00:26 | 004,325,691 | R--- | M] () -- C:\Users\Nina\Desktop\ComboFix.exe
[2011.04.20 15:14:50 | 000,001,201 | ---- | M] () -- C:\Users\Nina\Documents\mbam-log-2011-04-18 (22-45-20).7z
[2011.04.20 15:12:38 | 001,110,476 | ---- | M] () -- C:\Users\Nina\Desktop\7z920.exe
[2011.04.18 20:09:59 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Nina\Desktop\OTL.exe
[2011.04.18 19:48:38 | 000,000,908 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.04.18 19:47:33 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Nina\Desktop\herbert.exe
[2011.04.18 19:42:51 | 001,006,778 | ---- | M] () -- C:\Users\Nina\Desktop\rkill.com
[2011.04.18 19:24:44 | 000,069,120 | ---- | M] () -- C:\Users\Nina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.04.14 13:04:24 | 002,368,816 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.04.14 00:38:27 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat
[2011.04.14 00:38:27 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat
[2011.04.14 00:38:06 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2011.04.14 00:38:06 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011.04.14 00:38:05 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2011.04.14 00:38:05 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2011.04.14 00:38:04 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011.04.14 00:38:04 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2011.04.14 00:38:04 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2011.04.14 00:38:04 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2011.04.14 00:38:03 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2011.04.14 00:38:03 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2011.04.14 00:38:02 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2011.04.14 00:38:02 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2011.04.14 00:38:02 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2011.04.14 00:38:02 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2011.04.14 00:38:02 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2011.04.14 00:38:01 | 001,427,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2011.04.14 00:38:01 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2011.04.14 00:38:01 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011.04.14 00:38:01 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2011.04.14 00:38:01 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2011.04.14 00:38:01 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2011.04.14 00:38:00 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011.04.14 00:38:00 | 000,420,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2011.04.14 00:38:00 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2011.04.14 00:38:00 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2011.04.14 00:38:00 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2011.04.14 00:37:58 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011.04.14 00:37:57 | 001,797,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011.04.14 00:37:57 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2011.04.14 00:37:57 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2011.04.14 00:37:57 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2011.04.14 00:37:57 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2011.04.14 00:37:57 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2011.04.14 00:37:57 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2011.04.14 00:37:57 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2011.04.14 00:37:56 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2011.04.14 00:37:56 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2011.04.14 00:37:56 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2011.04.14 00:37:56 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2011.04.14 00:37:56 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2011.04.14 00:36:25 | 000,979,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MFH264Dec.dll
[2011.04.14 00:36:25 | 000,357,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MFHEAACdec.dll
[2011.04.14 00:36:24 | 000,302,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfmp4src.dll
[2011.04.14 00:36:24 | 000,261,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
[2011.04.14 00:36:23 | 002,873,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
[2011.04.14 00:36:22 | 000,098,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfps.dll
[2011.04.14 00:36:20 | 000,209,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll
[2011.04.14 00:36:17 | 000,683,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2011.04.14 00:36:17 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
[2011.04.14 00:36:16 | 001,172,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2011.04.14 00:36:16 | 000,486,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2011.04.14 00:36:15 | 001,029,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
[2011.04.14 00:36:15 | 000,478,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll
[2011.04.14 00:36:15 | 000,219,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2011.04.14 00:36:15 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
[2011.04.14 00:36:15 | 000,160,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2011.04.14 00:36:14 | 001,554,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\xpsservices.dll
[2011.04.14 00:36:14 | 000,847,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\OpcServices.dll
[2011.04.14 00:36:14 | 000,667,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelinesvc.exe
[2011.04.14 00:36:14 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2011.04.14 00:36:14 | 000,026,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelineprxy.dll
[2011.04.14 00:36:13 | 000,876,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2011.04.14 00:33:23 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\dxgkrnl.sys.mui
[2011.04.14 00:33:22 | 000,519,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d11.dll
[2011.04.14 00:33:22 | 000,369,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WMPhoto.dll
[2011.04.14 00:33:22 | 000,252,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxdiag.exe
[2011.04.14 00:33:22 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxdiagn.dll
[2011.04.14 00:33:21 | 000,321,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PhotoMetadataHandler.dll
[2011.04.14 00:33:21 | 000,189,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll
[2011.04.06 21:02:30 | 000,346,388 | ---- | M] () -- C:\Users\Nina\Desktop\Cat_Fitness.jpg
[2011.03.29 16:40:43 | 000,001,898 | ---- | M] () -- C:\Users\Public\Desktop\Vokabeltrainer 2.0 Italienisch.lnk
[2011.03.27 13:54:14 | 000,001,666 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.03.26 18:18:21 | 000,137,656 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
========== Files Created - No Company Name ==========
[2011.04.21 11:07:30 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011.04.21 11:07:30 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.04.21 11:07:30 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011.04.21 11:07:30 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.04.21 11:07:30 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.04.21 10:59:44 | 004,325,691 | R--- | C] () -- C:\Users\Nina\Desktop\ComboFix.exe
[2011.04.20 15:14:50 | 000,001,201 | ---- | C] () -- C:\Users\Nina\Documents\mbam-log-2011-04-18 (22-45-20).7z
[2011.04.20 15:12:33 | 001,110,476 | ---- | C] () -- C:\Users\Nina\Desktop\7z920.exe
[2011.04.18 19:48:38 | 000,000,908 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.04.18 19:42:37 | 001,006,778 | ---- | C] () -- C:\Users\Nina\Desktop\rkill.com
[2011.04.14 00:38:01 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2011.04.06 21:02:22 | 000,346,388 | ---- | C] () -- C:\Users\Nina\Desktop\Cat_Fitness.jpg
[2011.03.29 16:40:43 | 000,001,898 | ---- | C] () -- C:\Users\Public\Desktop\Vokabeltrainer 2.0 Italienisch.lnk
[2011.03.27 13:54:14 | 000,001,666 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010.09.28 09:15:04 | 000,000,092 | ---- | C] () -- C:\Users\Nina\AppData\Local\fusioncache.dat
[2010.08.11 15:30:55 | 000,001,025 | ---- | C] () -- C:\Windows\System32\sysprs7.dll
[2010.08.11 15:30:55 | 000,000,205 | ---- | C] () -- C:\Windows\System32\lsprst7.dll
[2009.10.05 22:41:44 | 000,177,678 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009.10.05 22:41:44 | 000,177,678 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009.07.03 21:43:53 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.07.03 21:43:52 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.07.03 21:43:06 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009.07.03 21:42:51 | 000,062,976 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009.03.07 17:34:52 | 000,028,177 | ---- | C] () -- C:\Windows\SETUP1.EXE
[2009.02.03 21:10:44 | 000,000,671 | ---- | C] () -- C:\Users\Nina\AppData\Roaming\vso_ts_preview.xml
[2009.02.03 21:08:37 | 000,007,887 | ---- | C] () -- C:\Users\Nina\AppData\Roaming\pcouffin.cat
[2009.02.03 21:08:37 | 000,001,144 | ---- | C] () -- C:\Users\Nina\AppData\Roaming\pcouffin.inf
[2008.10.07 09:13:30 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008.10.07 09:13:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2008.07.28 18:39:06 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2008.06.27 10:01:01 | 000,081,158 | ---- | C] () -- C:\Windows\System32\manage-bde.ini.en
[2008.06.04 11:23:14 | 000,026,624 | ---- | C] () -- C:\Windows\System32\ssp7ml3.dll
[2008.03.08 21:25:33 | 000,000,112 | ---- | C] () -- C:\Windows\ActiveSkin.INI
[2007.12.22 01:38:38 | 000,069,120 | ---- | C] () -- C:\Users\Nina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.12.19 18:37:31 | 000,000,680 | ---- | C] () -- C:\Users\Nina\AppData\Local\d3d9caps.dat
[2007.12.05 11:22:44 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2007.12.02 11:02:40 | 000,030,920 | ---- | C] () -- C:\Users\Nina\AppData\Roaming\UserTile.png
[2007.11.30 19:29:05 | 000,000,112 | ---- | C] () -- C:\Users\Nina\AppData\Roaming\wklnhst.dat
[2007.11.30 18:18:22 | 000,080,456 | ---- | C] () -- C:\Users\Nina\AppData\Roaming\nvModes.001
[2007.11.29 10:34:21 | 000,080,400 | ---- | C] () -- C:\Users\Nina\AppData\Roaming\nvModes.dat
[2007.11.21 02:50:03 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2007.11.21 02:49:53 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2007.11.20 18:56:34 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2006.11.15 21:24:14 | 000,000,000 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2006.11.07 21:25:58 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini
[2006.11.03 19:25:56 | 000,389,120 | ---- | C] () -- C:\Windows\System32\btwhidcs.dll
[2006.11.02 17:48:52 | 000,628,910 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2006.11.02 17:48:52 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2006.11.02 17:48:52 | 000,127,412 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2006.11.02 17:48:52 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 14:55:52 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:46:27 | 002,368,816 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 14:34:20 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:33:01 | 000,595,946 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,105,276 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:25:44 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.09.17 01:36:50 | 000,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006.09.17 01:36:50 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll
[2003.02.20 18:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI
[2001.11.14 14:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Pharmazie:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Permakultur:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Ernährungswissenschaften:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\WWOOF:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\Weiterbildung:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\Vokabeltraining:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\VISITENKARTEN:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\UMWELTBERATUNG.at:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\Sprachreise:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\Speisekarten:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\Salon 65b:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\Rezepte:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\pdf24:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\PcSetup:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\Notes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\Megafon:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\LimeWire:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\Klaviernoten:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\Image Converter Plus:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\Dell Webcam Center:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\CyberLink:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\Come.on:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\BIO Info:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\Azureus Downloads:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\ARBEITSSUCHE:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Documents\Anti-Malware:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Desktop\Log Files 21.4:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Desktop\Italienisch OSTERN:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Desktop\iPod:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Desktop\Globalisierung:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Desktop\Garten:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Desktop\Diplomarbeit:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Desktop\Cat_Fitness.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Desktop\Boris Italienisch:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\Desktop\0503399 Systemantrag 2010-09-01 Bewilligung - ab 2010-09 94,00 Euro:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Nina\BIOLOGIE:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\SNES Emulator:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\cdex_151:Roxio EMC Stream
< End of report > --- --- ---
Extras.txt
OTL Logfile: Code:
OTL Extras logfile created on: 22.04.2011 17:16:59 - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Nina\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000C07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 45,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220,28 Gb Total Space | 23,78 Gb Free Space | 10,79% Space Free | Partition Type: NTFS
Drive D: | 10,00 Gb Total Space | 5,92 Gb Free Space | 59,20% Space Free | Partition Type: NTFS
Drive F: | 10,53 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: DELL_1 | User Name: Nina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDSee Pro 2.0.Browse] -- "C:\Program Files\ACD Systems\ACDSee Pro\2.0\ACDSeeQVPro2.exe" "%1" (ACD Systems)
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0814E845-CCE5-4B81-B656-8B1373BF32C4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{0AD2931C-49B8-49C9-9EFA-14BA0AB61EFA}" = lport=138 | protocol=17 | dir=in | app=system |
"{0F415974-137B-4A60-8A12-4E597DF8C412}" = rport=137 | protocol=17 | dir=out | app=system |
"{1BE90781-BE94-4880-AC6A-71000DB3432B}" = rport=445 | protocol=6 | dir=out | app=system |
"{1F318BFD-C84D-43A0-BB98-DF2CBB9CB5F9}" = lport=139 | protocol=6 | dir=in | app=system |
"{32928F78-506B-4DD2-A9C3-8EEC6944BC8E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{3F392422-0E45-43F6-A699-53C4A58316DA}" = lport=445 | protocol=6 | dir=in | app=system |
"{6BE08093-84B5-4B42-9317-EADC7E101948}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{919DA9E2-E0DB-4AD9-9BFF-D1B2F4BFE4B4}" = rport=139 | protocol=6 | dir=out | app=system |
"{B668520E-827F-4F43-B946-0515FECFE6F9}" = rport=138 | protocol=17 | dir=out | app=system |
"{C6669524-81BB-4684-916C-FF6F6A333CE9}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E1E8188F-1F47-434A-AF70-30C70C337A7F}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{F06125CA-8962-4F28-A03E-692C80162CA7}" = lport=137 | protocol=17 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{489D7E2F-75F9-46A8-8655-B8DF84932802}" = dir=in | app=c:\program files\dell\mediadirect\pcmservice.exe |
"{525D6DE0-B447-4FEA-8899-71F8A952424B}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{58A4741B-13D4-4478-8A5E-DA3B564C5DCC}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{5B5993CA-3B2B-422D-BA48-074A821F14C5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{67496360-A605-415F-8EBA-07F38B8FF409}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{67C47D12-0CB3-485E-A3BA-5867C59AB7F3}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{688B56F6-AB3A-4E59-984B-389A8B641D2D}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{6DC6BC96-7B09-4D38-9CE7-6F9DC4D03C31}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dms\clmsservice.exe |
"{A8BD6A80-8655-4034-B11C-850E5787EBC8}" = protocol=6 | dir=in | app=c:\program files\sony ericsson\update service\update service.exe |
"{AAB88E75-9553-4974-86AC-BF14AE7F6367}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{AC462A62-EFD3-4F9D-8955-A48EFD2497D5}" = protocol=17 | dir=in | app=c:\program files\sony ericsson\update service\update service.exe |
"{AE43B7CF-81D0-4738-8F5A-CC20575A6534}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dmp\clbrowserengine.exe |
"{AFDF243A-F905-4EFE-B91C-D074DE89C14A}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{CEF32B22-6636-4BD3-9BCC-06C53633A989}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{E88DA116-3E65-4DDD-855F-9B360E71231E}" = dir=in | app=c:\program files\dell\mediadirect\powercinema.exe |
"TCP Query User{0BCA8BA1-A70B-4B2C-9684-C8C8514DBA18}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{2608EC75-1F2C-4093-8A7C-646FF021EEAB}C:\program files\java\jre6\launch4j-tmp\jdownloader.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\launch4j-tmp\jdownloader.exe |
"TCP Query User{55B04EED-69D2-43C9-992D-092AFB81AA63}C:\program files\java\jre1.6.0\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre1.6.0\bin\javaw.exe |
"TCP Query User{74E19E0B-83C6-421D-847F-E002B4C1A65C}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{75EA3FF5-ABF8-456D-B00C-DEDA24BFBB23}E:\easysetupassistant\easysetupassistant.exe" = protocol=6 | dir=in | app=e:\easysetupassistant\easysetupassistant.exe |
"TCP Query User{8040F875-F52B-4C6E-811B-EBBBFFA016EA}C:\program files\java\jre1.6.0\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre1.6.0\bin\java.exe |
"TCP Query User{92E87D3A-A119-41EC-AE43-CC9872B7044A}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{9B34D489-3207-460B-B6BE-1B2CA800D7C3}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"TCP Query User{CD3AF48C-D3F5-43B8-B3C1-31A1631AAAF8}C:\windows\system32\java.exe" = protocol=6 | dir=in | app=c:\windows\system32\java.exe |
"UDP Query User{02026C29-054E-450B-B290-8668F57E4DB2}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{1E45FAD6-433D-477C-B131-12A35B2F8EFD}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{4257BF90-FA1D-46C9-BA5E-495AAF5487FF}E:\easysetupassistant\easysetupassistant.exe" = protocol=17 | dir=in | app=e:\easysetupassistant\easysetupassistant.exe |
"UDP Query User{559F66AA-346F-451F-9936-6E3FD640716C}C:\program files\java\jre6\launch4j-tmp\jdownloader.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\launch4j-tmp\jdownloader.exe |
"UDP Query User{562A9455-9E3C-4A2A-882E-89191441CFE6}C:\windows\system32\java.exe" = protocol=17 | dir=in | app=c:\windows\system32\java.exe |
"UDP Query User{5ECF291A-4D80-4FCE-B049-5F7502B4026B}C:\program files\java\jre1.6.0\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre1.6.0\bin\java.exe |
"UDP Query User{B2E17C72-59EC-44FF-B011-B2E7B6343513}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{C275AC2D-AF28-45C0-B78C-4E50A95A258C}C:\program files\java\jre1.6.0\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre1.6.0\bin\javaw.exe |
"UDP Query User{CAF91F01-A9C6-4F20-A7FF-E4630249B0F2}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00D0200F-3B4D-4A2F-869E-533ED835A943}" = Hervorhebe-Funktion (Windows Live Toolbar)
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{098A2A49-7CF3-4F08-A38D-FB879117152A}" = Adobe Color NA Extra Settings CS4
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}" = Adobe Color EU Recommended Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{218761F6-CBF6-4973-B910-A33E6563A1EA}" = Windows Live Toolbar-Erweiterung (Windows Live Toolbar)
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = Media Player Classic - Home Cinema v. 1.3.1249.0
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 24
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{2DD6C198-FA9A-40B4-8DE5-CE5206E3EB34}" = Smart Menus (Windows Live Toolbar)
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{3EAAC5FD-E209-4856-8C49-D4EA40F85032}" = Mobile Connect
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AAC95F4-A30E-4EE5-A086-6F79581D0D70}" = ACDSee Pro 2
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}" = Microsoft Works
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = Benutzerhandbuch
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.3.4.107
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F0C4457-8E64-491B-8D7B-991504365D1E}" = QuickSet
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 2.9.2
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D1E61D1-1395-4E97-997F-D002DB3A5074}" = OpenOffice.org 3.2
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90850407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}" = WIDCOMM Bluetooth Software 6.0.1.3100
"{AC76BA86-7AD7-1031-7B44-A82000000003}" = Adobe Reader 8.2.6 - Deutsch
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{C0888D7E-F534-4F03-BA79-226EBFD94D32}" = Langenscheidt Vokabeltrainer 2.0 Italienisch
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem-Diagnose-Tool
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FD023F61-65E9-465C-B558-7C64EB2B97E6}" = Dell Handbuch zum Einstieg
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Advanced Video FX Engine" = Advanced Video FX Engine
"AFPL Ghostscript 8.10" = AFPL Ghostscript 8.10
"AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BlueShot 1.3.2_is1" = BlueShot 1.3.2
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"Creative OEM002" = Laptop Integrated Webcam Driver (1.04.01.1011)
"Dell Webcam Center" = Dell Webcam Center
"Dell Webcam Manager" = Dell Webcam Manager
"EPSON Printer and Utilities" = EPSON-Drucker-Software
"EPSON Scanner" = EPSON Scan
"ESET Online Scanner" = ESET Online Scanner v3
"Foxit Reader" = Foxit Reader
"ImageConverter Plus_is1" = ImageConverter Plus 8.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"MPE" = MyPhoneExplorer
"NVIDIA Drivers" = NVIDIA Drivers
"Picasa 3" = Picasa 3
"RealPlayer 6.0" = RealPlayer
"Recover My Files_is1" = Recover My Files
"RocketDock_is1" = RocketDock 1.3.5
"Sony Ericsson W800" = Sony Ericsson W800 Software
"SynTPDeinstKey" = Dell Touchpad
"SystemRequirementsLab" = System Requirements Lab
"Teachmaster 4.3" = Teachmaster 4.3 (nur Entfernen)
"Update Service" = Update Service
"VLC media player" = VLC media player 1.0.2
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"309a46b1dc89b774" = Dell Driver Download Manager
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 14.04.2011 11:29:41 | Computer Name = dell_1 | Source = Bonjour Service | ID = 100
Description =
Error - 14.04.2011 11:29:41 | Computer Name = dell_1 | Source = Bonjour Service | ID = 100
Description =
Error - 14.04.2011 11:29:41 | Computer Name = dell_1 | Source = Bonjour Service | ID = 100
Description =
Error - 14.04.2011 11:29:43 | Computer Name = dell_1 | Source = Bonjour Service | ID = 100
Description =
Error - 14.04.2011 11:29:43 | Computer Name = dell_1 | Source = Bonjour Service | ID = 100
Description =
Error - 14.04.2011 11:29:43 | Computer Name = dell_1 | Source = Bonjour Service | ID = 100
Description =
Error - 18.04.2011 13:13:21 | Computer Name = dell_1 | Source = Application Hang | ID = 1002
Description = Programm firefox.exe, Version 1.9.2.4095 arbeitet nicht mehr mit Windows
zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen
für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem
zu suchen. Prozess-ID: 138c Anfangszeit: 01cbfde9ec3869a7 Zeitpunkt der Beendigung:
93
Error - 18.04.2011 13:32:19 | Computer Name = dell_1 | Source = Application Hang | ID = 1002
Description = Programm arg70techsdk.exe, Version 2.4.5600.0 arbeitet nicht mehr
mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet
"Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen
über das Problem zu suchen. Prozess-ID: fd4 Anfangszeit: 01cbfdee2c7ed53f Zeitpunkt
der Beendigung: 16
Error - 20.04.2011 08:51:40 | Computer Name = dell_1 | Source = Application Hang | ID = 1002
Description = Programm OTL.exe, Version 3.2.22.3 arbeitet nicht mehr mit Windows
zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen
für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem
zu suchen. Prozess-ID: 14e0 Anfangszeit: 01cbff595deffbb8 Zeitpunkt der Beendigung:
16
Error - 21.04.2011 13:33:01 | Computer Name = dell_1 | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung firefox.exe, Version 1.9.2.4095, Zeitstempel
0x4d852c95, fehlerhaftes Modul FOXITR~1.OCX, Version 1.0.1.224, Zeitstempel 0x4b849404,
Ausnahmecode 0xc0000005, Fehleroffset 0x00002dce, Prozess-ID 0x480, Anwendungsstartzeit
01cc0046f64efcba.
[ Media Center Events ]
Error - 17.04.2008 13:17:33 | Computer Name = dell_1 | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: Download von Paket MCESpotlight
gescheitert.
[ System Events ]
Error - 13.04.2011 17:42:46 | Computer Name = dell_1 | Source = Service Control Manager | ID = 7026
Description =
Error - 14.04.2011 07:10:44 | Computer Name = dell_1 | Source = Service Control Manager | ID = 7022
Description =
Error - 14.04.2011 11:29:38 | Computer Name = dell_1 | Source = Service Control Manager | ID = 7011
Description =
Error - 14.04.2011 11:30:11 | Computer Name = dell_1 | Source = PlugPlayManager | ID = 12
Description = Das Gerät "PIONEER DVD+-RW DR-K17Y ATA Device" (IDE\CdRomPIONEER_DVD+-RW_DR-K17Y_________________0.96____\5&14f32b41&0&0.0.0)
wurde ohne vorbereitende Maßnahmen vom System entfernt.
Error - 14.04.2011 16:18:32 | Computer Name = dell_1 | Source = Service Control Manager | ID = 7011
Description =
Error - 21.04.2011 04:46:51 | Computer Name = dell_1 | Source = Service Control Manager | ID = 7034
Description =
Error - 21.04.2011 05:11:04 | Computer Name = dell_1 | Source = Service Control Manager | ID = 7034
Description =
Error - 21.04.2011 05:11:43 | Computer Name = dell_1 | Source = Service Control Manager | ID = 7030
Description =
Error - 21.04.2011 05:19:37 | Computer Name = dell_1 | Source = Service Control Manager | ID = 7030
Description =
Error - 21.04.2011 05:28:54 | Computer Name = dell_1 | Source = Service Control Manager | ID = 7030
Description =
< End of report > --- --- --- Schritt #6: Security Check Results of screen317's Security Check version 0.99.10 | Windows Vista Service Pack 2 (UAC is enabled) | Internet Explorer 8 | `````````````````````````````` | Antivirus/Firewall Check: | Avira AntiVir Personal - Free Antivirus | ESET Online Scanner v3 | WMI entry may not exist for antivirus; attempting automatic update. | Avira successfully updated! | ``````````````````````````````` | Anti-malware/Other Utilities Check: | Malwarebytes' Anti-Malware | Java(TM) 6 Update 24 | Adobe Flash Player 10.1.53.64 | Adobe Reader 8.2.6 - Deutsch | Out of date Adobe Reader installed! | ```````````````````````````````` | Process Check: | objlist.exe by Laurent | Spybot Teatimer.exe is disabled! | Avira Antivir avgnt.exe | Avira Antivir avguard.exe | ``````````End of Log```````````` | Schritt #7: Fragen beantworten
Neben temporären Dateien waren es auch Dateien, von denen ich genau weiß, dass ich sie irgendwann mal gelöscht habe, sprich Word Dokumente. All diese Dateien sind grau hinterlegt am Desktop erschienen. |