Zu 3:
Extras:
OTL Logfile: Code:
OTL Extras logfile created on: 31.07.2011 14:12:09 - Run 3
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\Rapho\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,99 Gb Total Physical Memory | 0,74 Gb Available Physical Memory | 37,23% Memory free
4,21 Gb Paging File | 2,68 Gb Available in Paging File | 63,66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 143,95 Gb Total Space | 48,27 Gb Free Space | 33,53% Space Free | Partition Type: NTFS
Computer Name: RAPHO-PC | User Name: Rapho | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1D9E4C1E-E761-4385-80D1-B51DF939FFD5}" = lport=139 | protocol=6 | dir=in | app=system |
"{242194F3-CA12-4FE2-BC80-B8B66CCCF350}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{38C2E15A-997D-4F20-8214-F8E5210018C0}" = lport=445 | protocol=6 | dir=in | app=system |
"{399AE03E-EED5-4351-B3DD-DAECE9C02FEE}" = rport=10243 | protocol=6 | dir=out | app=system |
"{3E5FA714-0EAC-45FA-A1A1-13177A182074}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{51A168E2-A2E9-4078-B70C-D41CABAB659A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{761385AF-BAD8-4C36-974C-5B5802CFDE52}" = rport=137 | protocol=17 | dir=out | app=system |
"{877E0AAD-A9E3-434E-B2D8-8733ACE61EB1}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{913F7A6D-E9DD-4CD0-BC84-4FD3E1DAAC53}" = rport=445 | protocol=6 | dir=out | app=system |
"{B4A3A8B9-A1E8-4EA8-97A1-79E0228CE811}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B5D9E229-33AA-40B8-BBA0-D5DB76ADB41E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D52A2267-5406-495F-91F7-BE62A035B7AF}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D53AFB55-095C-4940-89BC-930E82FA5D80}" = rport=139 | protocol=6 | dir=out | app=system |
"{D5EB17CB-A667-43BF-BF3F-EFC607259404}" = lport=137 | protocol=17 | dir=in | app=system |
"{E810E2A1-7DA1-4934-BB48-BD545655B6D6}" = rport=138 | protocol=17 | dir=out | app=system |
"{EDCBF1BC-9EE8-4936-B52A-A339D1D48CB4}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{F8B58541-25D9-46AE-8BF6-D6CC91CA24AA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F99374A4-EA6A-4C07-AE32-1DA1E0ABD640}" = lport=10243 | protocol=6 | dir=in | app=system |
"{FCDEE1B8-F460-416D-9E80-C36ACB611D0B}" = lport=138 | protocol=17 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0789E2C9-C433-418A-800E-5BA66DC11096}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{0D96D3C3-8A74-4CED-AF8C-FC2E23A10AFA}" = dir=in | app=c:\program files\lenovo multimedia center\powerdirector express\pdx.exe |
"{1A0A5B74-61EE-4743-965C-E21D3F4BE66F}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{3BE7ACBC-53A6-442E-AF6C-D9504237DF11}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{528FD07A-318F-4EDD-9741-DB2B218C23B4}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{535FC8E8-500C-48A6-B53F-91FA15DD2FE5}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{5C42E2BF-F0B4-443A-BDD4-76CD8211454C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{6151902F-83F6-4D5C-BBAF-6B98C2D013D5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{68656724-2BF0-4ED5-9CB5-5E387693CDEC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7022C311-83EB-4595-9D83-8750CCEE4F43}" = protocol=6 | dir=out | app=system |
"{795D2918-1CD7-4102-BDC5-4BDEE8459E76}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7C541091-81E4-4F49-996E-22651DB84FD8}" = protocol=17 | dir=in | app=c:\program files\tobit radio.fx\server\rfx-server.exe |
"{7EA2D9C5-D54F-4D7D-8BAC-7F6DA22EC8A6}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{80A9F8FA-4B13-481F-9D1E-B07038B30531}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{8D7C9D09-E37C-4F75-9761-058FA26CDAF2}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{A7D62927-8BA5-43C0-9A7B-A2E51A04C7F1}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{AEA74DE2-C45A-40E7-B819-B0E753792790}" = protocol=6 | dir=in | app=c:\program files\tobit radio.fx\client\rfx-client.exe |
"{B6BA0155-0D16-4681-ADBD-549D8BB4F37F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{B94CFCF1-6766-48B5-A22D-327E1F72085A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BEEBEF2A-77D2-4B71-841C-3137FD181134}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{BF99B6CA-2496-4A52-A009-77280BE2C165}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C0F411D0-36F8-4C58-B14F-7B86B9EE3F37}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{C8806126-FF94-4090-8E4E-108AA64AB516}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{CABC47A6-CEE3-46A5-BEB0-5D6F73BDD099}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{CF205327-0DF6-4107-A478-FE68CC83BCA8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D7567DAF-7962-471B-89BC-E3B7AD776E9C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D8404B62-C8AF-4E58-9717-F570DAB54FDC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E1B24D1B-3F6B-4CD9-B9BD-978BC87D7B2B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E8FD4B6A-01C8-48DB-AD32-9D6182283F30}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{F4747D9C-8304-4F4D-9913-1E771F5A2EC4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F94A45FB-1F41-4700-9F4D-779BBA0EE4DA}" = protocol=6 | dir=in | app=c:\program files\tobit radio.fx\server\rfx-server.exe |
"{F9AADB00-D9A0-4F0C-99A3-BFCC895FA0AA}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{FCC91798-CA66-4AEF-9FBF-CCA6132A094D}" = protocol=17 | dir=in | app=c:\program files\tobit radio.fx\client\rfx-client.exe |
"TCP Query User{1699ECD7-9FDC-4E0E-A6E5-8E0644AB2F9F}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{27ACF68D-7FFB-42ED-8432-E6939D8A987F}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe |
"TCP Query User{43A76B9E-5E26-4788-946C-A754F46A335F}C:\users\rapho\appdata\local\xenocode\sandbox\adobe after effects cs3\8.0x247\2010.02.14t17.17\native\stubexe\8.0.1135\@programfiles@\bonjour\mdnsresponder.exe" = protocol=6 | dir=in | app=c:\users\rapho\appdata\local\xenocode\sandbox\adobe after effects cs3\8.0x247\2010.02.14t17.17\native\stubexe\8.0.1135\@programfiles@\bonjour\mdnsresponder.exe |
"TCP Query User{87B022A5-1106-4B05-ADE9-454CD95AA02F}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{944572FB-EF4C-4C4B-BAD3-89778814F412}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe |
"TCP Query User{9ED59534-7785-4A09-A847-536AD86B23EA}C:\program files\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"UDP Query User{0DD36079-7355-49B9-B701-F531511F59B9}C:\users\rapho\appdata\local\xenocode\sandbox\adobe after effects cs3\8.0x247\2010.02.14t17.17\native\stubexe\8.0.1135\@programfiles@\bonjour\mdnsresponder.exe" = protocol=17 | dir=in | app=c:\users\rapho\appdata\local\xenocode\sandbox\adobe after effects cs3\8.0x247\2010.02.14t17.17\native\stubexe\8.0.1135\@programfiles@\bonjour\mdnsresponder.exe |
"UDP Query User{1B2B28CC-77D1-4DC4-BF42-33576C6DB470}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{21004A17-ED18-4D08-B6D9-D08BA359F179}C:\program files\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"UDP Query User{4AFB86D5-3DD8-4D72-B25F-ED5646F6E187}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{4DD39CDD-2C81-46BE-8E42-6EAF301A4F56}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{BB27A5F9-C3AB-46EF-B9BE-80A38303DCD5}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = Lenovo Bluetooth with Enhanced Data Rate Software 6.0.1.4900
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F4EFCE8-E358-4430-A504-F55F32BA1816}" = Client Security Solution
"{1007F41F-7D69-468E-8017-3849A5A973C2}" = ThinkVantage Technologies Welcome Message
"{1772DBCE-B61D-4A4D-B881-F717EBE74998}" = Xponent
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Lenovo Multimedia Center
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java(TM) 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 26
"{2AAC4085-DCBF-417B-AEBD-182197839240}" = Native Instruments Traktor
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{35AC562E-F11A-060C-CD06-70FB80113769}" = simfy
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = Integrated Camera
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.33
"{62715632-A555-4D9E-9CEC-4F84EB55B07B}" = PM Driver
"{6280149E-EFF3-4F1B-BD43-5B7EDD6F620A}" = Ergänzung zu Lenovo Care
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{65706020-7B6F-41F2-8047-FC69579E386A}" = Präsentationsdirektor
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{6DED41BC-C9EF-4330-B4E5-46CB2C5C6E2D}" = No23 Recorder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{735619D4-B42A-437A-958C-199BFCAEDB38}" = Safari
"{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}" = ICQ7.5
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{796E076A-82F7-4D49-98C8-DEC0C3BC733A}" = Diskeeper Home
"{7EB114D8-207F-45AE-BABD-1669715F2630}" = ThinkVantage Access Connections
"{800C6CC9-8EEB-4A6A-ABD4-C05EAE279606}" = Network Magic
"{8675339C-128C-44DD-83BF-0A5D6ABD8297}" = System Update
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel(R) Matrix Storage Manager
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{986F64DC-FF15-449D-998F-EE3BCEC6666A}" = Help Center
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A52A504E-18BE-4821-9A2A-BFB4542DA0BD}" = Lenovo PM Driver
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AC76BA86-7AD7-1031-7B44-A80000000002}" = Adobe Reader 8 - Deutsch
"{B1F625EB-9691-4889-A864-DA085739F3F0}" = Power Ux Customization
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C6FA39A7-26B1-480A-BC74-6D17531AC222}" = Access Help
"{C73CA646-73B3-4AEF-A136-C37505745174}" = iTunes
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF52099A-3BEA-4C41-AEA8-1E190F04D737}" = Lenovo Care
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D3B3B9B2-FE73-44CB-8C0A-F737D92F991B}" = Broadcom Gigabit Integrated Controller
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DB44F479-789A-4D76-A31E-663C5658F576}" = Mindjet MindManager 9
"{DB71210F-8314-4AE3-B7A7-EBAF85BD30E9}" = Wallpapers
"{E7E836B8-4BDD-454F-82E6-5FEA17C83AD4}" = Message Center
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FCB739A2-D7C9-4F69-B992-21196057803E}" = M-Audio Xponent Driver 6.0.1 (x86)
"{FD331A3B-F7A5-4C31-B8D4-DF413C85AF7A}" = Message Center Plus
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"ASIO4ALL" = ASIO4ALL
"Audacity_is1" = Audacity 1.2.6
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"AwayTask" = Maintenance Manager
"CCleaner" = CCleaner
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"FileZilla Client" = FileZilla Client 3.5.0
"Free M4a to MP3 Converter_is1" = Free M4a to MP3 Converter 6.2
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9.35.324
"GoldWave v5.58" = GoldWave v5.58
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"IL Download Manager" = IL Download Manager
"InstallShield_{62715632-A555-4D9E-9CEC-4F84EB55B07B}" = PM Driver
"Lenovo Registration" = Lenovo Registration
"LENOVO.SMIIF" = Lenovo System Interface Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Version 1.51.1.1800
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox 5.0 (x86 de)" = Mozilla Firefox 5.0 (x86 de)
"Native Instruments Traktor" = Native Instruments Traktor
"No23 Recorder" = No23 Recorder
"OnScreenDisplay" = Anzeige am Bildschirm
"PC-Doctor 5 for Windows" = PC-Doctor 5 für Windows
"PDF-XChange 3_is1" = PDF-XChange 3
"PokerStars.net" = PokerStars.net
"Simfy" = simfy
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Tobit Radio.fx Server" = Radio.fx
"Uninstall_is1" = Uninstall 1.0.0.1
"USBPMon" = Registry patch for Windows Vista USB S3 PM Enablement
"VLC media player" = VLC media player 1.1.9
"WinRAR archiver" = WinRAR 4.00 (32-Bit)
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report > --- --- ---
OTL.txt
OTL Logfile: Code:
OTL logfile created on: 31.07.2011 14:12:09 - Run 3
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\Rapho\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,99 Gb Total Physical Memory | 0,74 Gb Available Physical Memory | 37,23% Memory free
4,21 Gb Paging File | 2,68 Gb Available in Paging File | 63,66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 143,95 Gb Total Space | 48,27 Gb Free Space | 33,53% Space Free | Partition Type: NTFS
Computer Name: RAPHO-PC | User Name: Rapho | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.07.31 14:02:39 | 000,017,408 | ---- | M] () -- C:\Windows\System32\rpcnetp.exe
PRC - [2011.07.30 14:06:59 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Rapho\Desktop\OTL(1).exe
PRC - [2011.07.01 18:52:54 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.06.24 16:19:11 | 003,627,352 | ---- | M] () -- C:\Programme\Tobit Radio.fx\Server\rfx-server.exe
PRC - [2011.06.23 13:27:13 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe
PRC - [2011.05.21 18:09:35 | 000,748,336 | ---- | M] (Microsoft Corporation) -- C:\Programme\Internet Explorer\iexplore.exe
PRC - [2011.04.27 20:27:18 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2011.04.18 14:11:40 | 000,028,672 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\System Update\SUService.exe
PRC - [2011.03.04 14:36:11 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.01.14 21:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009.10.02 12:45:36 | 000,643,592 | ---- | M] (Avid Technology, Inc.) -- C:\Windows\System32\M-AudioTaskBarIcon.exe
PRC - [2009.05.27 22:09:36 | 000,049,976 | ---- | M] () -- C:\Programme\Lenovo\Message Center Plus\MCPLaunch.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.03.05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Programme\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008.01.21 04:35:20 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2008.01.21 04:35:20 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe
PRC - [2008.01.21 04:33:00 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Defender\MSASCui.exe
PRC - [2007.11.29 20:04:00 | 000,059,168 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\NPDIRECT\tpfnf7sp.exe
PRC - [2007.09.11 10:54:48 | 000,163,840 | ---- | M] (Avid Technology, Inc.) -- C:\Programme\M-Audio\Xponent\MAUSBXPInst.exe
PRC - [2007.08.09 11:11:06 | 000,927,032 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\Client Security Solution\tvtpwm_tray.exe
PRC - [2007.08.09 10:36:36 | 000,644,408 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Common Files\Lenovo\tvt_reg_monitor_svc.exe
PRC - [2007.07.05 15:49:18 | 000,128,296 | ---- | M] (Lenovo) -- C:\Programme\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
PRC - [2007.07.05 15:49:06 | 000,124,200 | ---- | M] (Lenovo) -- C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe
PRC - [2007.07.05 15:48:58 | 000,419,112 | ---- | M] (Lenovo) -- C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe
PRC - [2007.07.05 15:48:54 | 000,206,120 | ---- | M] (Lenovo) -- C:\Programme\ThinkPad\ConnectUtilities\AcSvc.exe
PRC - [2007.07.05 15:48:50 | 000,091,432 | ---- | M] (Lenovo) -- C:\Programme\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
PRC - [2007.06.05 17:11:28 | 000,034,352 | ---- | M] (Lenovo) -- C:\Programme\Lenovo\PM Driver\PMHandler.exe
PRC - [2007.04.26 19:10:00 | 000,120,368 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\LenovoCare\LPMGR.EXE
PRC - [2007.04.09 03:24:32 | 000,054,832 | ---- | M] (Lenovo.) -- C:\Programme\Lenovo\HOTKEY\FnF5svc.exe
PRC - [2007.03.29 13:11:50 | 000,719,664 | ---- | M] (Broadcom Corporation.) -- C:\Programme\Lenovo\Bluetooth Software\BTTray.exe
PRC - [2007.03.29 13:11:48 | 001,604,400 | ---- | M] (Broadcom Corporation.) -- C:\Programme\Lenovo\Bluetooth Software\BTStackServer.exe
PRC - [2007.03.23 13:04:54 | 004,423,680 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007.03.16 05:26:22 | 000,057,344 | ---- | M] (Lenovo) -- C:\Programme\Lenovo\PM Driver\PMSveH.exe
PRC - [2007.03.14 15:42:48 | 000,321,088 | ---- | M] (Pure Networks, Inc.) -- C:\Programme\Pure Networks\Network Magic\nmsrvc.exe
PRC - [2007.03.14 15:42:48 | 000,321,088 | ---- | M] (Pure Networks, Inc.) -- C:\Programme\Pure Networks\Network Magic\nmapp.exe
PRC - [2007.03.02 07:07:28 | 000,055,936 | ---- | M] () -- C:\Programme\Lenovo\HOTKEY\TPHKSVC.exe
PRC - [2007.02.12 13:38:04 | 000,355,096 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007.02.12 13:37:58 | 000,174,872 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2007.01.30 05:01:26 | 000,108,080 | ---- | M] (Lenovo Group Limited) -- C:\Windows\System32\IPSSVC.EXE
PRC - [2006.11.23 15:10:42 | 000,056,928 | ---- | M] (Cyberlink Corp.) -- C:\Programme\Lenovo Multimedia Center\PowerDVD\PDVDServ.exe
PRC - [2006.11.15 16:21:56 | 000,217,176 | ---- | M] (Diskeeper Corporation) -- C:\Programme\Diskeeper Corporation\Diskeeper\DkIcon.exe
PRC - [2006.11.15 16:20:46 | 000,634,988 | ---- | M] (Diskeeper Corporation) -- C:\Programme\Diskeeper Corporation\Diskeeper\DkService.exe
PRC - [2006.11.07 12:51:20 | 000,091,688 | ---- | M] (Lenovo Group Limited) -- C:\Programme\Lenovo\AwayTask\AwaySch.EXE
PRC - [2006.10.05 05:10:12 | 000,009,216 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2006.09.06 09:38:44 | 000,054,824 | ---- | M] () -- C:\Programme\Lenovo\HOTKEY\TpWAudAp.exe
========== Modules (SafeList) ==========
MOD - [2011.07.30 14:06:59 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Rapho\Desktop\OTL(1).exe
MOD - [2010.08.31 17:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
MOD - [2010.07.30 13:01:38 | 000,107,856 | ---- | M] (Microsoft Corporation) -- C:\Programme\Mindjet\MindManager 9\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - [2011.07.31 14:03:26 | 000,017,408 | ---- | M] () [Unknown | Running] -- C:\Windows\System32\rpcnetp.dll -- (rpcnetp)
SRV - [2011.07.06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.07.01 18:52:54 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.06.24 16:19:11 | 003,627,352 | ---- | M] () [Auto | Running] -- C:\Programme\Tobit Radio.fx\Server\rfx-server.exe -- (Radio.fx)
SRV - [2011.04.27 20:27:18 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.04.18 14:11:40 | 000,028,672 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Programme\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008.01.21 04:33:00 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.09.11 10:54:48 | 000,163,840 | ---- | M] (Avid Technology, Inc.) [Auto | Running] -- C:\Programme\M-Audio\Xponent\MAUSBXPInst.exe -- (MAudioXponentService)
SRV - [2007.08.09 10:36:36 | 000,644,408 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor Service)
SRV - [2007.07.05 15:48:54 | 000,206,120 | ---- | M] (Lenovo) [Auto | Running] -- C:\Programme\ThinkPad\ConnectUtilities\AcSvc.exe -- (AcSvc)
SRV - [2007.07.05 15:48:50 | 000,091,432 | ---- | M] (Lenovo) [Auto | Running] -- C:\Programme\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe -- (AcPrfMgrSvc)
SRV - [2007.04.09 03:24:32 | 000,054,832 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Programme\Lenovo\HOTKEY\FnF5svc.exe -- (FNF5SVC)
SRV - [2007.03.16 05:26:22 | 000,057,344 | ---- | M] (Lenovo) [Auto | Running] -- C:\Programme\Lenovo\PM Driver\PMSveH.exe -- (PMSveH)
SRV - [2007.03.14 15:42:48 | 000,321,088 | ---- | M] (Pure Networks, Inc.) [Auto | Running] -- C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe -- (nmservice)
SRV - [2007.03.14 15:42:22 | 000,012,800 | ---- | M] (Pure Networks, Inc.) [On_Demand | Stopped] -- C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe -- (nmraapache)
SRV - [2007.03.02 07:07:28 | 000,055,936 | ---- | M] () [Auto | Running] -- C:\Programme\Lenovo\HOTKEY\TPHKSVC.exe -- (TPHKSVC)
SRV - [2007.02.12 13:38:04 | 000,355,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
SRV - [2007.01.30 05:01:26 | 000,108,080 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Windows\System32\IPSSVC.EXE -- (IPSSVC)
SRV - [2006.11.15 16:20:46 | 000,634,988 | ---- | M] (Diskeeper Corporation) [Auto | Running] -- C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe -- (Diskeeper)
SRV - [2006.10.05 05:10:12 | 000,009,216 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
========== Driver Services (SafeList) ==========
DRV - [2011.07.06 19:52:42 | 000,041,272 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011.07.01 18:52:58 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.07.01 18:52:58 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.06.11 13:49:12 | 000,030,144 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\psadd.sys -- (psadd)
DRV - [2010.06.17 14:27:02 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.10.02 12:45:28 | 000,042,248 | ---- | M] (M-Audio) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MAudioXponent_DFU.sys -- (MADFUXPONENT)
DRV - [2009.10.02 12:45:24 | 000,158,344 | ---- | M] (Avid Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MAudioXponent.sys -- (MAUSBXPONENT)
DRV - [2008.01.21 04:32:52 | 000,045,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tpm.sys -- (TPM)
DRV - [2008.01.21 04:32:51 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel(R)
DRV - [2007.05.22 15:59:38 | 000,030,336 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tvti2c.sys -- (TVTI2C)
DRV - [2007.03.21 22:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007.02.24 14:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007.01.23 16:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006.12.19 02:12:22 | 001,786,880 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32) Intel(R)
DRV - [2006.11.09 14:34:26 | 000,019,456 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\LPCFilter.sys -- (LPCFilter)
DRV - [2006.11.08 09:29:44 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006.11.06 10:23:24 | 000,012,080 | ---- | M] (Lenovo Group Limited) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\PROCDD.SYS -- (PROCDD)
DRV - [2006.08.30 12:04:04 | 000,013,744 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\System32\drivers\smiif32.sys -- (lenovo.smi)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/3000notebook [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/welcome/3000notebook [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.06.23 13:27:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.06.14 15:29:13 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{FCF36B88-1BBA-487f-B64B-D2E8980A9293}: C:\Program Files\Lenovo\Client Security Solution\PWM Firefox Extension [2011.04.09 15:53:18 | 000,000,000 | ---D | M]
[2011.04.09 18:52:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rapho\AppData\Roaming\mozilla\Extensions
[2011.07.31 14:07:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rapho\AppData\Roaming\mozilla\Firefox\Profiles\6wmvbu2m.default\extensions
[2011.06.22 19:43:50 | 000,000,000 | ---D | M] (WebMail Notifier) -- C:\Users\Rapho\AppData\Roaming\mozilla\Firefox\Profiles\6wmvbu2m.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
[2011.07.06 18:52:42 | 000,000,000 | ---D | M] (Awesome screenshot: Capture and Annotate) -- C:\Users\Rapho\AppData\Roaming\mozilla\Firefox\Profiles\6wmvbu2m.default\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack
[2011.06.14 15:29:29 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.04.09 19:06:47 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011.04.09 18:55:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.06.14 15:29:29 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) --
[2011.04.09 18:55:07 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.06.14 15:29:29 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\RAPHO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\6WMVBU2M.DEFAULT\EXTENSIONS\{1F91CDE0-C040-11DA-A94D-0800200C9A66}.XPI
[2011.04.12 13:30:29 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011.06.23 13:27:13 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.05.04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (CmjBrowserHelperObject Object) - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Programme\Mindjet\MindManager 9\Mm8InternetExplorer.dll (Mindjet)
O2 - BHO: (CPwmIEBrowserHelper Object) - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Programme\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O4 - HKLM..\Run: [ACTray] C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo)
O4 - HKLM..\Run: [ACWLIcon] C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [AwaySch] C:\Programme\Lenovo\AwayTask\AwaySch.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [DiskeeperSystray] C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe (Diskeeper Corporation)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\Lenovo Multimedia Center\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [LenovoOobeOffers] c:\SWTOOLS\LenovoWelcome\LenovoOobeOffers.exe (lenovo)
O4 - HKLM..\Run: [LPManager] C:\Programme\Lenovo\LenovoCare\LPMGR.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [M-Audio Taskbar Icon] C:\Windows\System32\M-AudioTaskBarIcon.exe (Avid Technology, Inc.)
O4 - HKLM..\Run: [Message Center Plus] C:\Program Files\LENOVO\Message Center Plus\MCPLaunch.exe ()
O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Pure Networks, Inc.)
O4 - HKLM..\Run: [PMHandler] C:\Programme\Lenovo\PM Driver\PMHandler.exe (Lenovo)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\Lenovo Multimedia Center\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SwitchBoard] C:\Programme\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPWAUDAP] C:\Programme\Lenovo\HOTKEY\TpWAudAp.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [rfxsrvtray] C:\Program Files\Tobit Radio.fx\Client\rfx-tray.exe (Tobit.Software)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Rapho\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : ThinkVantage Password Manager... - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Programme\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O9 - Extra Button: An Mindjet MindManager senden - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Programme\Mindjet\MindManager 9\Mm8InternetExplorer.dll (Mindjet)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Programme\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Programme\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Programme\Common Files\Pure Networks Shared\puresp3.dll (Pure Networks, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Rapho\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Rapho\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.07.31 13:58:48 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.07.30 15:36:56 | 000,000,000 | ---D | C] -- C:\Users\Rapho\Desktop\SciLor's Grooveshark.com Downloader
[2011.07.30 14:36:58 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011.07.30 14:06:51 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Users\Rapho\Desktop\OTL(1).exe
[2011.07.26 19:35:51 | 000,000,000 | ---D | C] -- C:\Users\Rapho\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011.07.26 19:35:50 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011.07.21 14:13:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.07.21 14:11:20 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.07.21 14:02:59 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011.07.21 13:53:56 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2011.07.18 19:18:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Caphyon
[2011.07.18 19:18:41 | 000,000,000 | ---D | C] -- C:\Program Files\No23 Recorder
[2011.07.18 19:18:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\No23 Recorder
[2011.07.18 18:51:12 | 000,000,000 | ---D | C] -- C:\Users\Rapho\AppData\Roaming\Simfy
[2011.07.18 18:51:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\simfy
[2011.07.18 18:51:05 | 000,000,000 | ---D | C] -- C:\Program Files\simfy
[2011.07.16 13:44:07 | 000,000,000 | ---D | C] -- C:\Users\Rapho\AppData\Roaming\Ovvy
[2011.07.16 13:44:07 | 000,000,000 | ---D | C] -- C:\Users\Rapho\AppData\Roaming\Aguhi
[2011.07.13 22:23:33 | 002,043,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011.07.13 22:23:30 | 000,375,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2011.07.13 22:23:30 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2011.07.12 11:20:54 | 000,178,536 | ---- | C] (Apple Inc.) -- C:\Windows\System32\dnssdX.dll
[2011.07.12 11:20:54 | 000,083,816 | ---- | C] (Apple Inc.) -- C:\Windows\System32\dns-sd.exe
[2011.07.12 11:20:54 | 000,073,064 | ---- | C] (Apple Inc.) -- C:\Windows\System32\dnssd.dll
[2011.07.12 11:20:54 | 000,050,536 | ---- | C] (Apple Inc.) -- C:\Windows\System32\jdns_sd.dll
[2011.07.09 17:17:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tobit.Software
[2011.07.09 17:17:33 | 001,844,488 | ---- | C] (Tobit.Software) -- C:\Windows\RXSUnins.exe
[2011.07.09 17:17:33 | 001,844,488 | ---- | C] (Tobit.Software) -- C:\Windows\RXCUnins.exe
[2011.07.07 19:11:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavalys
[2011.07.07 19:11:27 | 000,000,000 | ---D | C] -- C:\Program Files\Lavalys
[2011.07.01 19:37:30 | 000,000,000 | ---D | C] -- C:\Users\Rapho\AppData\Roaming\Ugab
[2011.07.01 19:37:30 | 000,000,000 | ---D | C] -- C:\Users\Rapho\AppData\Roaming\Ucef
[2011.04.09 15:23:53 | 000,167,936 | ---- | C] ( ) -- C:\Windows\System32\rsnp2uvc.dll
[2011.04.09 15:23:53 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\csnp2uvc.dll
========== Files - Modified Within 30 Days ==========
[2011.07.31 14:04:12 | 000,025,181 | ---- | M] () -- C:\Windows\System32\PROCDB.INI
[2011.07.31 14:03:26 | 000,017,408 | ---- | M] () -- C:\Windows\System32\rpcnetp.dll
[2011.07.31 14:02:59 | 000,000,380 | ---- | M] () -- C:\Windows\System32\IPSCtrl.INI
[2011.07.31 14:02:55 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.07.31 14:02:55 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.07.31 14:02:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.07.31 14:02:42 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys
[2011.07.31 14:02:39 | 000,017,408 | ---- | M] () -- C:\Windows\System32\rpcnetp.exe
[2011.07.31 14:01:21 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2011.07.31 13:50:46 | 000,089,088 | ---- | M] () -- C:\Windows\System32\mbr.exe
[2011.07.30 15:50:53 | 008,390,239 | ---- | M] () -- C:\Users\Rapho\Desktop\01 - Pitbull feat. Rapho - Took my love.mp3
[2011.07.30 15:04:39 | 006,151,650 | ---- | M] () -- C:\Users\Rapho\Desktop\01 - Tim Bendzko - Nur noch kurz die Welt retten.mp3
[2011.07.30 14:58:28 | 000,044,544 | ---- | M] (Absolute Software Corp.) -- C:\Windows\System32\agremove.exe
[2011.07.30 14:31:32 | 000,302,592 | ---- | M] () -- C:\Users\Rapho\Desktop\n48vj8s9.exe
[2011.07.30 14:06:59 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Rapho\Desktop\OTL(1).exe
[2011.07.29 01:12:12 | 195,127,952 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011.07.26 20:10:17 | 000,322,022 | ---- | M] () -- C:\Users\Rapho\AppData\Local\census.cache
[2011.07.26 20:09:34 | 000,221,743 | ---- | M] () -- C:\Users\Rapho\AppData\Local\ars.cache
[2011.07.26 19:53:14 | 000,000,036 | ---- | M] () -- C:\Users\Rapho\AppData\Local\housecall.guid.cache
[2011.07.26 19:35:51 | 000,001,948 | ---- | M] () -- C:\Users\Rapho\Desktop\HiJackThis.lnk
[2011.07.23 18:12:30 | 013,165,864 | ---- | M] () -- C:\Users\Rapho\Desktop\Set-Fire-to-the-Rain-A-Stupid-Hole-Bootleg.mp3
[2011.07.22 17:26:30 | 003,523,810 | ---- | M] () -- C:\Users\Rapho\Desktop\Seeed-Molotov.mp3
[2011.07.22 13:27:55 | 021,073,936 | ---- | M] () -- C:\Users\Rapho\Documents\vlc-1.1.11-win32.exe
[2011.07.21 19:06:28 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.07.21 19:06:28 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.07.21 19:06:28 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.07.21 19:06:27 | 000,126,454 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.07.21 14:18:27 | 000,001,854 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
[2011.07.21 14:13:09 | 000,001,674 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.07.21 13:52:24 | 000,001,356 | ---- | M] () -- C:\Users\Rapho\AppData\Local\d3d9caps.dat
[2011.07.18 19:18:44 | 000,000,940 | ---- | M] () -- C:\Users\Public\Desktop\No23 Recorder.lnk
[2011.07.18 18:51:06 | 000,000,724 | ---- | M] () -- C:\Users\Public\Desktop\simfy.lnk
[2011.07.14 14:19:03 | 003,611,600 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.07.13 19:35:52 | 000,002,061 | ---- | M] () -- C:\Users\Rapho\Documents\Firefox Sync Key.html
[2011.07.13 19:34:30 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011.07.12 11:20:54 | 000,178,536 | ---- | M] (Apple Inc.) -- C:\Windows\System32\dnssdX.dll
[2011.07.12 11:20:54 | 000,083,816 | ---- | M] (Apple Inc.) -- C:\Windows\System32\dns-sd.exe
[2011.07.12 11:20:54 | 000,073,064 | ---- | M] (Apple Inc.) -- C:\Windows\System32\dnssd.dll
[2011.07.12 11:20:54 | 000,050,536 | ---- | M] (Apple Inc.) -- C:\Windows\System32\jdns_sd.dll
[2011.07.07 19:11:34 | 000,000,917 | ---- | M] () -- C:\Users\Rapho\Desktop\EVEREST Home Edition.lnk
[2011.07.07 19:02:11 | 000,000,814 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.07.06 19:52:42 | 000,041,272 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.07.01 18:52:58 | 000,138,192 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011.07.01 18:52:58 | 000,066,616 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
========== Files Created - No Company Name ==========
[2011.07.31 14:03:26 | 000,017,408 | ---- | C] () -- C:\Windows\System32\rpcnetp.dll
[2011.07.31 14:02:39 | 000,017,408 | ---- | C] () -- C:\Windows\System32\rpcnetp.exe
[2011.07.31 13:50:29 | 000,089,088 | ---- | C] () -- C:\Windows\System32\mbr.exe
[2011.07.30 15:46:23 | 008,390,239 | ---- | C] () -- C:\Users\Rapho\Desktop\01 - Pitbull feat. Rapho - Took my love.mp3
[2011.07.30 15:01:25 | 006,151,650 | ---- | C] () -- C:\Users\Rapho\Desktop\01 - Tim Bendzko - Nur noch kurz die Welt retten.mp3
[2011.07.30 14:31:25 | 000,302,592 | ---- | C] () -- C:\Users\Rapho\Desktop\n48vj8s9.exe
[2011.07.29 01:12:12 | 195,127,952 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011.07.27 17:11:45 | 000,030,259 | ---- | C] () -- C:\Users\Rapho\Desktop\hjtscanlist.bat
[2011.07.26 20:10:17 | 000,322,022 | ---- | C] () -- C:\Users\Rapho\AppData\Local\census.cache
[2011.07.26 20:09:34 | 000,221,743 | ---- | C] () -- C:\Users\Rapho\AppData\Local\ars.cache
[2011.07.26 19:53:14 | 000,000,036 | ---- | C] () -- C:\Users\Rapho\AppData\Local\housecall.guid.cache
[2011.07.26 19:35:51 | 000,001,948 | ---- | C] () -- C:\Users\Rapho\Desktop\HiJackThis.lnk
[2011.07.23 18:12:13 | 013,165,864 | ---- | C] () -- C:\Users\Rapho\Desktop\Set-Fire-to-the-Rain-A-Stupid-Hole-Bootleg.mp3
[2011.07.22 13:27:25 | 021,073,936 | ---- | C] () -- C:\Users\Rapho\Documents\vlc-1.1.11-win32.exe
[2011.07.21 14:18:27 | 000,001,854 | ---- | C] () -- C:\Users\Public\Desktop\Safari.lnk
[2011.07.21 14:13:09 | 000,001,674 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.07.18 19:18:44 | 000,000,940 | ---- | C] () -- C:\Users\Public\Desktop\No23 Recorder.lnk
[2011.07.18 18:51:06 | 000,000,724 | ---- | C] () -- C:\Users\Public\Desktop\simfy.lnk
[2011.07.13 19:35:51 | 000,002,061 | ---- | C] () -- C:\Users\Rapho\Documents\Firefox Sync Key.html
[2011.07.08 20:07:38 | 003,523,810 | ---- | C] () -- C:\Users\Rapho\Desktop\Seeed-Molotov.mp3
[2011.07.07 19:11:34 | 000,000,917 | ---- | C] () -- C:\Users\Rapho\Desktop\EVEREST Home Edition.lnk
[2011.05.30 19:50:10 | 000,003,584 | ---- | C] () -- C:\Users\Rapho\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.05.10 19:15:34 | 002,681,344 | ---- | C] () -- C:\Windows\System32\dvmsg.dll
[2011.04.11 13:54:20 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011.04.11 13:54:20 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.04.11 13:53:35 | 000,643,072 | ---- | C] () -- C:\Windows\System32\autochk.exe
[2011.04.11 12:04:09 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011.04.10 01:06:41 | 000,628,742 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2011.04.10 01:06:41 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2011.04.10 01:06:41 | 000,126,454 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2011.04.10 01:06:41 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2011.04.09 18:46:52 | 000,001,356 | ---- | C] () -- C:\Users\Rapho\AppData\Local\d3d9caps.dat
[2011.04.09 15:39:25 | 002,115,816 | ---- | C] () -- C:\Windows\System32\NPSWF32.dll
[2011.04.09 15:32:11 | 000,910,464 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2011.04.09 15:32:11 | 000,249,856 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2011.04.09 15:32:11 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1268.dll
[2011.04.09 15:30:05 | 000,000,176 | ---- | C] () -- C:\Windows\System32\drivers\RTHDAEQ0.dat
[2011.04.09 15:28:23 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2011.04.09 15:23:53 | 009,598,080 | ---- | C] () -- C:\Windows\System32\drivers\snp2uvc.sys
[2011.04.09 15:23:53 | 000,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini
[2011.04.09 15:20:06 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2007.08.16 12:28:38 | 000,025,181 | ---- | C] () -- C:\Windows\System32\PROCDB.INI
[2007.08.16 12:28:27 | 000,000,380 | ---- | C] () -- C:\Windows\System32\IPSCtrl.INI
[2007.03.29 12:42:38 | 000,389,120 | ---- | C] () -- C:\Windows\System32\btwhidcs.dll
[2006.12.05 07:26:43 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2006.11.02 14:53:49 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:44:53 | 003,611,600 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 12:33:01 | 000,595,996 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,104,070 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2001.11.14 13:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll
========== LOP Check ==========
[2011.07.26 18:57:45 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\Acurpo
[2011.07.19 14:49:16 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\Aguhi
[2011.06.11 13:49:10 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\Downloaded Installations
[2011.04.24 22:17:51 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.07.21 13:22:41 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\FileZilla
[2011.07.31 13:43:41 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\ICQ
[2011.06.15 16:39:33 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\Image-Line
[2011.04.09 18:48:32 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\Lenovo
[2011.04.09 19:10:23 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\OpenOffice.org
[2011.07.19 14:30:56 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\Ovvy
[2011.06.11 13:54:38 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\PCDr
[2011.07.18 18:51:12 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\Simfy
[2011.06.17 15:59:03 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\SynthMaker
[2011.07.09 17:18:11 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\Tobit
[2011.04.11 13:27:44 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\TuneUp Software
[2011.07.01 19:37:30 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\Ucef
[2011.07.01 19:37:30 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\Ugab
[2011.07.26 19:57:34 | 000,000,000 | ---D | M] -- C:\Users\Rapho\AppData\Roaming\Veavna
[2011.07.31 14:01:26 | 000,032,614 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report > --- --- ---
[/code] |