Mondstein | 07.11.2011 14:06 | Hallo
Ich hoffe ich hab jetzt nix falsch gemachtOTL Logfile: Code:
OTL logfile created on: 07.11.2011 13:50:24 - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = E:\Programs\OTLPE
64bit-Windows 7 Home Premium (Version = 6.1.7600) - Type = System
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 62,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 75,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450,93 Gb Total Space | 323,28 Gb Free Space | 71,69% Space Free | Partition Type: NTFS
Drive D: | 14,53 Gb Total Space | 1,79 Gb Free Space | 12,33% Space Free | Partition Type: NTFS
Drive E: | 436,59 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive F: | 99,02 Mb Total Space | 88,70 Mb Free Space | 89,57% Space Free | Partition Type: FAT32
Computer Name: H-CRITTERSHAUß | User Name: H.-C.Rittershauß
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2010.09.22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010.08.05 19:51:08 | 000,291,896 | ---- | M] (Hewlett-Packard Company) [Auto] -- C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe -- (HPClientSvc)
SRV:64bit: - [2010.08.05 19:47:48 | 000,681,528 | ---- | M] (Hewlett-Packard) [Auto] -- C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe -- (HPAuto)
SRV:64bit: - [2010.07.21 14:33:00 | 000,103,992 | ---- | M] (Hewlett-Packard Company) [Auto] -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe -- (HP Wireless Assistant Service)
SRV:64bit: - [2010.04.23 12:00:00 | 000,514,232 | ---- | M] (EasyBits Software AS) [Auto] -- C:\Windows\System32\ezSharedSvcHost.exe -- (ezSharedSvc)
SRV - [2011.11.07 13:27:36 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.07.05 16:02:58 | 000,227,384 | ---- | M] (Hewlett-Packard Company) [Auto] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe)
SRV - [2011.06.28 18:36:42 | 000,269,480 | ---- | M] (Avira GmbH) [Auto] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.06.21 14:57:34 | 000,085,560 | ---- | M] (Hewlett-Packard Company) [Auto] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe -- (HP Support Assistant Service)
SRV - [2011.04.28 21:46:05 | 000,136,360 | ---- | M] (Avira GmbH) [Auto] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.02.28 17:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011.02.25 09:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2011.01.12 17:00:42 | 000,013,336 | ---- | M] (Intel Corporation) [Auto] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R)
SRV - [2010.12.13 23:04:46 | 000,275,968 | ---- | M] (IDT, Inc.) [Auto] -- C:\Programme\IDT\WDM\stacsv64.exe -- (STacSV)
SRV - [2010.11.21 10:49:24 | 000,247,608 | ---- | M] () [Auto] -- C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2010.11.09 15:20:34 | 000,026,680 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Auto] -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe -- (HPWMISVC)
SRV - [2010.10.12 18:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010.07.23 20:44:54 | 002,320,920 | ---- | M] (Intel Corporation) [Auto] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010.07.23 20:44:48 | 000,268,824 | ---- | M] (Intel Corporation) [Auto] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3880097196-1087461709-2136809990-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4
IE - HKU\S-1-5-21-3880097196-1087461709-2136809990-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/sm
IE - HKU\S-1-5-21-3880097196-1087461709-2136809990-1000\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-3880097196-1087461709-2136809990-1000\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-3880097196-1087461709-2136809990-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.2.9&q="
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "hxxp://start.icq.com/"
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.3&q="
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011.02.20 01:50:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.07.03 17:51:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011.03.22 17:27:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\H.-C.Rittershauß\AppData\Roaming\mozilla\Extensions
[2011.10.25 21:32:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\H.-C.Rittershauß\AppData\Roaming\mozilla\Firefox\Profiles\pn47jxqx.default\extensions
[2011.10.25 21:32:25 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\H.-C.Rittershauß\AppData\Roaming\mozilla\Firefox\Profiles\pn47jxqx.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011.09.29 19:46:31 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\H.-C.Rittershauß\AppData\Roaming\mozilla\Firefox\Profiles\pn47jxqx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.08.12 19:21:26 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\H.-C.Rittershauß\AppData\Roaming\mozilla\Firefox\Profiles\pn47jxqx.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.10.07 14:21:13 | 000,000,000 | ---D | M] ("Ask Toolbar") -- C:\Users\H.-C.Rittershauß\AppData\Roaming\mozilla\Firefox\Profiles\pn47jxqx.default\extensions\toolbar@ask.com
[2011.11.01 19:33:24 | 000,000,950 | ---- | M] () -- C:\Users\H.-C.Rittershauß\AppData\Roaming\Mozilla\Firefox\Profiles\pn47jxqx.default\searchplugins\icqplugin-1.xml
[2011.05.13 17:31:14 | 000,000,950 | ---- | M] () -- C:\Users\H.-C.Rittershauß\AppData\Roaming\Mozilla\Firefox\Profiles\pn47jxqx.default\searchplugins\icqplugin-2.xml
[2011.06.21 22:59:21 | 000,000,950 | ---- | M] () -- C:\Users\H.-C.Rittershauß\AppData\Roaming\Mozilla\Firefox\Profiles\pn47jxqx.default\searchplugins\icqplugin-3.xml
[2011.07.04 18:44:25 | 000,000,950 | ---- | M] () -- C:\Users\H.-C.Rittershauß\AppData\Roaming\Mozilla\Firefox\Profiles\pn47jxqx.default\searchplugins\icqplugin-4.xml
[2011.08.17 04:48:20 | 000,000,950 | ---- | M] () -- C:\Users\H.-C.Rittershauß\AppData\Roaming\Mozilla\Firefox\Profiles\pn47jxqx.default\searchplugins\icqplugin-5.xml
[2011.08.22 15:20:17 | 000,000,950 | ---- | M] () -- C:\Users\H.-C.Rittershauß\AppData\Roaming\Mozilla\Firefox\Profiles\pn47jxqx.default\searchplugins\icqplugin-6.xml
[2011.10.04 18:59:19 | 000,000,950 | ---- | M] () -- C:\Users\H.-C.Rittershauß\AppData\Roaming\Mozilla\Firefox\Profiles\pn47jxqx.default\searchplugins\icqplugin-7.xml
[2011.03.30 14:14:34 | 000,001,042 | ---- | M] () -- C:\Users\H.-C.Rittershauß\AppData\Roaming\Mozilla\Firefox\Profiles\pn47jxqx.default\searchplugins\icqplugin.xml
[2011.07.18 20:28:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011.03.22 17:52:04 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011.07.18 20:28:17 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) --
File not found (No name found) -- C:\USERS\H.-C.RITTERSHAUß\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN47JXQX.DEFAULT\EXTENSIONS\{635ABD67-4FE9-1B23-4F01-E679FA7484C1}
File not found (No name found) -- C:\USERS\H.-C.RITTERSHAUß\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN47JXQX.DEFAULT\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}
File not found (No name found) -- C:\USERS\H.-C.RITTERSHAUß\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN47JXQX.DEFAULT\EXTENSIONS\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
File not found (No name found) -- C:\USERS\H.-C.RITTERSHAUß\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN47JXQX.DEFAULT\EXTENSIONS\TOOLBAR@ASK.COM
[2011.07.03 17:51:18 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010.01.01 09:00:00 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2010.01.01 09:00:00 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2010.01.01 09:00:00 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.01.01 09:00:00 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.01.01 09:00:00 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-3880097196-1087461709-2136809990-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKU\S-1-5-21-3880097196-1087461709-2136809990-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [HotKeysCmds] File not found
O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] File not found
O4:64bit: - HKLM..\Run: [Persistence] File not found
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe (EasyBits Software AS)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [IMSS] C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3880097196-1087461709-2136809990-1000..\Run: [DriverScanner] C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe (Uniblue Systems Limited)
O4 - HKU\S-1-5-21-3880097196-1087461709-2136809990-1000..\Run: [ICQ] C:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-21-3880097196-1087461709-2136809990-1000..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKU\S-1-5-21-3880097196-1087461709-2136809990-1000..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] File not found
O4 - Startup: C:\Users\H.-C.Rittershauß\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKU\S-1-5-21-3880097196-1087461709-2136809990-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKU\S-1-5-21-3880097196-1087461709-2136809990-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\H.-C.Rittershauß\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\H.-C.Rittershauß\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13:64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\System32\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.03.24 12:06:41 | 000,000,053 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{c02ac8a7-5490-11e0-be39-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{c02ac8a7-5490-11e0-be39-806e6f6e6963}\Shell\AutoRun\command - "" = E:\reatogoMenu.exe -- [2005.07.16 22:36:50 | 000,240,128 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.11.07 13:31:49 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{AAA4EE5E-5FCC-45FC-B348-D5A980AA2D90}
[2011.11.07 13:27:31 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{2808D92A-4C3E-45E2-8718-CD1281DE6F9B}
[2011.11.07 13:27:08 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{3A528712-D4E6-4AE1-B7CD-36C497B15D20}
[2011.11.06 12:20:21 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{3C2EC5CF-FF50-4948-A207-83D3A8EC2E76}
[2011.11.06 12:19:59 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{B6EACB21-85FA-4BE9-ADFA-F166408CE04D}
[2011.11.04 14:35:52 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{6CD8C1B7-AE7F-4912-B6A3-BF69F3A72D6D}
[2011.11.04 14:35:35 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{BA4B479F-72C8-4E19-A5A7-E7E482451452}
[2011.11.04 05:54:16 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{72AAFC1F-5D3E-4226-96B2-F5C39BF0C2D4}
[2011.11.04 05:54:05 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{278EFBFC-45E8-445A-9EB7-EE07657F9272}
[2011.11.03 16:58:06 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{0807F6A3-5658-4208-A66D-A6B89C6DA8CF}
[2011.11.03 16:57:46 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{70757A9B-AC12-4D45-BBD1-E94087F0350A}
[2011.10.31 16:03:46 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{6442CFE0-5768-4EF0-A3EC-1A1A994C0E1F}
[2011.10.31 16:03:34 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{7AFFFB25-246E-41BC-A41D-4B9931F20FAF}
[2011.10.30 15:52:51 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{FA122D67-F685-47D0-B756-726C89A31B4F}
[2011.10.30 15:52:37 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{1516970C-C30F-42E7-9D0A-1826751FE354}
[2011.10.29 08:08:44 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{DE21146E-D089-491B-8447-C9D2F4E6DAEC}
[2011.10.29 08:08:32 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{5C8416F3-B12E-4B15-BDF5-367E60ECA585}
[2011.10.28 16:36:21 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{294268B9-EE2A-48C3-9C5B-C1586BA9C39C}
[2011.10.28 16:36:11 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{02F1C2BE-4826-4775-8E4E-4ACB87677035}
[2011.10.28 05:40:51 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{12913327-ED89-451A-A0B6-578802CE6EC0}
[2011.10.27 13:58:36 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\Desktop\family guy
[2011.10.27 13:57:57 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\Desktop\Stromberg - Chef Sein Mensch Bleiben
[2011.10.27 13:28:16 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{128482B9-2751-406F-AECD-4B09ADB49FD9}
[2011.10.27 13:26:38 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{2A47ADC1-47AA-4E8D-BC7E-14A82EB6157A}
[2011.10.26 14:12:20 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{A86B1A9B-3506-4B11-9722-0D4DDE3BEF37}
[2011.10.25 20:57:14 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{7A75E972-A53F-44C0-B3D4-81AEFCCA2597}
[2011.10.24 20:48:47 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{7D665531-E24F-481B-BFDD-430570DD1BD0}
[2011.10.24 20:48:25 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{687ED896-3C7E-47DB-B17E-B7D6A3175529}
[2011.10.23 02:19:26 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{DF319AAB-FDD2-4303-BDA2-EFC46E350BA0}
[2011.10.23 02:19:05 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{43C5FFCF-9A61-4855-B996-03B8FA63338A}
[2011.10.22 14:20:10 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{03BECAC7-5270-403A-ACF0-30F129A7FB9F}
[2011.10.22 14:19:57 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{17F10FD6-57ED-47D6-AC04-8E110133470F}
[2011.10.22 12:20:04 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{213C3E00-0495-4868-B7AE-C3230C25E92B}
[2011.10.22 12:19:49 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{DD2638DC-0FA0-4153-93E7-6836DCBBB0F6}
[2011.10.21 23:59:38 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{706088CB-A61A-4191-AE1A-14A45B920025}
[2011.10.21 23:58:54 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{0936D52C-4987-48BF-9A8A-333B0DDCE800}
[2011.10.21 18:13:34 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{19ABBD3F-ED83-4E88-BB30-14AE929E9A32}
[2011.10.21 18:13:19 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{84B8EC62-68EB-40F7-B2A5-A205F49B1DB2}
[2011.10.21 13:37:17 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{B4E82126-C4E2-4FC5-80DF-9537F806AEF6}
[2011.10.21 13:37:04 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{B23AC2D6-97A0-4778-8562-849E5A688D12}
[2011.10.20 21:51:05 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{3053312E-9A49-4B1C-AB5B-C8BF0DAFBA43}
[2011.10.20 21:50:49 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{079BF11F-DAB6-45D1-A19B-E105D2B22D75}
[2011.10.20 15:15:15 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{1409E35E-7508-454D-895D-AEC82E98C2D3}
[2011.10.20 15:15:03 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{558F4C1B-F3E0-4306-9B65-CA6F41BFF7AB}
[2011.10.19 16:32:25 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{84190ED8-4183-4E6F-A72E-2DB502DB2FD6}
[2011.10.19 16:32:12 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{1C07965C-8E2B-4109-A856-CD0831906181}
[2011.10.19 05:06:33 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{00286B12-437D-4C1E-BD02-EE0FDB3C244D}
[2011.10.19 05:06:20 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{2A31BBAB-A6C7-45D7-8073-27A0D315CFE3}
[2011.10.18 15:48:08 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{DE96E773-11F9-4CB8-B6A9-8564CCB815A4}
[2011.10.18 15:47:56 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{C286C7C7-3815-47E8-9ACF-226CA3810D74}
[2011.10.17 15:04:20 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{A5499C33-0903-4D88-9177-6AC222EFBB37}
[2011.10.17 15:03:10 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{CB68DC37-7CAE-4317-8888-A56C904CA24C}
[2011.10.15 18:35:02 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{CB5EF00A-FADD-47DE-B4DB-7C51CCAB746E}
[2011.10.15 18:34:44 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{BAC76647-879C-4082-8B67-366F233A1D59}
[2011.10.14 23:59:40 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{5AD8CA3D-A1F6-4A8E-9FEB-8D0EAEB93A64}
[2011.10.14 23:59:23 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{D2D0DFB3-9A45-4E04-8AC1-837B63EBD543}
[2011.10.14 13:39:14 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{BF34165B-0EB4-407D-BE36-5D26CE000C3F}
[2011.10.14 13:38:56 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{E504C5DB-4486-4E70-9A47-80A593874526}
[2011.10.13 15:41:00 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{3C8E22E7-61F3-4857-8905-5572EFAECF67}
[2011.10.13 15:40:47 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{CB122559-9B78-4B6B-B2BC-75B01DF0A3F9}
[2011.10.12 15:41:44 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{99E8F5B2-1400-40A1-AB8E-6AF47FBFE0B6}
[2011.10.12 15:41:31 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{2E3C5009-D2BE-4787-B7F4-C229B60F12BD}
[2011.10.12 05:05:49 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{01226BAA-1DA9-470A-B331-66914EDAE438}
[2011.10.12 05:05:36 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{03F9036B-514C-48FE-BB04-77531EFE0A1F}
[2011.10.12 01:25:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
[2011.10.12 01:23:42 | 000,000,000 | ---D | C] -- C:\ProgramData\{D3B41B92-9BC2-43EB-916A-4FA9E8191837}
[2011.10.11 23:21:56 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
[2011.10.11 23:21:56 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011.10.11 23:21:56 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011.10.11 23:21:56 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011.10.11 23:21:55 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2011.10.11 23:21:55 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2011.10.11 23:21:55 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011.10.11 23:21:55 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
[2011.10.11 23:21:54 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011.10.11 23:21:54 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011.10.11 23:21:54 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2011.10.11 23:21:54 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2011.10.11 23:21:53 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2011.10.11 23:21:53 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2011.10.11 23:21:53 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2011.10.11 23:21:53 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2011.10.11 23:21:39 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisrndr.ax
[2011.10.11 23:21:39 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2011.10.11 23:21:38 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll
[2011.10.11 23:21:38 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2011.10.11 23:21:38 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax
[2011.10.11 23:21:38 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2011.10.11 23:21:37 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Mpeg2Data.ax
[2011.10.11 23:21:37 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mpeg2Data.ax
[2011.10.11 23:21:37 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSDvbNP.ax
[2011.10.11 23:21:37 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
[2011.10.11 23:21:32 | 000,571,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleaut32.dll
[2011.10.11 23:21:30 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleacc.dll
[2011.10.11 15:20:52 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{8AE2F6AC-E219-4FB3-88BB-A674B8CCE05C}
[2011.10.11 15:20:37 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{A4C3CCF3-A0B3-4435-BA20-AFEE3F203636}
[2011.10.10 18:16:51 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{0B9BAC30-0633-46AC-BAFF-FB09B72D3630}
[2011.10.10 18:16:30 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{B51720A1-8621-4488-A9D4-D206FA04EF83}
[2011.10.09 02:38:34 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{8ABB390F-8984-4566-9374-54A3077D4AAC}
[2011.10.09 02:38:19 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{4823DB64-50AB-41E7-822E-79317ED05C22}
[2011.10.08 15:08:02 | 000,000,000 | ---D | C] -- C:\Users\H.-C.Rittershauß\AppData\Local\{9BE03A92-77A4-42D8-97F4-A5740A1A7F28}
========== Files - Modified Within 30 Days ==========
[2011.11.07 13:30:43 | 000,000,362 | ---- | M] () -- C:\Windows\tasks\DriverScanner.job
[2011.11.07 13:30:27 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.11.07 13:30:19 | 3062,255,616 | -HS- | M] () -- C:\hiberfil.sys
[2011.11.03 19:14:30 | 000,001,867 | ---- | M] () -- C:\Users\H.-C.Rittershauß\Documents\rechnung.rtf
[2011.11.03 16:53:46 | 000,000,376 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForH.-C.Rittershauß.job
[2011.11.03 16:53:46 | 000,000,354 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForH-CRITTERSHAUß$.job
[2011.10.25 16:04:06 | 000,001,902 | ---- | M] () -- C:\Users\H.-C.Rittershauß\Documents\wochenberichte.rtf
[2011.10.12 02:08:36 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011.10.12 01:26:05 | 000,000,000 | R--D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
[2011.10.12 01:25:42 | 000,002,139 | ---- | M] () -- C:\Users\Public\Desktop\HP Support Assistant.lnk
[2011.10.12 01:25:42 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
[2011.10.11 19:45:35 | 000,000,192 | ---- | M] () -- C:\Users\H.-C.Rittershauß\Documents\loveless.rtf
[2011.10.09 10:29:41 | 000,001,776 | ---- | M] () -- C:\Users\H.-C.Rittershauß\Documents\beschreibung.rtf
========== Files Created - No Company Name ==========
[2011.11.03 19:14:30 | 000,001,867 | ---- | C] () -- C:\Users\H.-C.Rittershauß\Documents\rechnung.rtf
[2011.10.26 18:09:59 | 000,000,354 | ---- | C] () -- C:\Windows\tasks\HPCeeScheduleForH-CRITTERSHAUß$.job
[2011.10.25 22:11:08 | 110,447,557 | ---- | C] () -- C:\Users\H.-C.Rittershauß\Desktop\01 - Schranz Total 18.0 CD2ey hansi intro is hard techno anthem-viper xxl.mp3
[2011.10.12 01:25:42 | 000,002,139 | ---- | C] () -- C:\Users\Public\Desktop\HP Support Assistant.lnk
[2011.10.11 19:45:35 | 000,000,192 | ---- | C] () -- C:\Users\H.-C.Rittershauß\Documents\loveless.rtf
[2011.10.09 10:18:12 | 000,001,776 | ---- | C] () -- C:\Users\H.-C.Rittershauß\Documents\beschreibung.rtf
[2011.04.27 14:17:41 | 000,001,854 | ---- | C] () -- C:\Users\H.-C.Rittershauß\AppData\Roaming\GhostObjGAFix.xml
[2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.03.23 19:09:23 | 000,087,040 | ---- | C] () -- C:\Windows\UnGins.exe
[2011.03.23 19:09:17 | 000,237,568 | ---- | C] () -- C:\Windows\SysWow64\Unlha32.dll
[2011.03.23 19:09:16 | 000,473,600 | ---- | C] () -- C:\Windows\SysWow64\Harmony.dll
[2011.03.22 17:26:16 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.02.20 01:42:15 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.02.20 01:40:43 | 000,014,051 | ---- | C] () -- C:\Windows\SysWow64\RaCoInst.dat
[2011.02.20 01:36:05 | 000,002,901 | ---- | C] () -- C:\Windows\SysWow64\atipblup.dat
[2011.02.20 01:31:26 | 000,000,048 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011.01.09 18:11:06 | 000,000,202 | ---- | C] () -- C:\Windows\SysWow64\HPWA.ini
[2011.01.09 18:04:09 | 000,009,644 | ---- | C] () -- C:\Windows\SysWow64\ezdigsgn.dat
[2010.12.17 03:26:22 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2010.12.01 23:12:44 | 000,002,901 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010.11.29 06:21:30 | 000,128,204 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2010.11.29 06:21:28 | 000,867,020 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2010.11.29 06:21:28 | 000,105,408 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2010.09.24 15:41:34 | 000,007,736 | ---- | C] () -- C:\Windows\hpDSTRES.DLL
[2009.07.14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:59:36 | 001,498,564 | ---- | C] () -- C:\Windows\SysWow64\igkrng400.bin
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2005.08.29 23:00:00 | 000,781,312 | ---- | C] () -- C:\Windows\SysWow64\RGSS102J.dll
[2005.08.29 23:00:00 | 000,778,752 | ---- | C] () -- C:\Windows\SysWow64\RGSS102E.dll
[2005.08.29 23:00:00 | 000,771,584 | ---- | C] () -- C:\Windows\SysWow64\RGSS100J.dll
========== LOP Check ==========
[2011.10.17 21:47:17 | 000,000,000 | ---D | M] -- C:\Users\H.-C.Rittershauß\AppData\Roaming\.minecraft
[2011.08.06 13:20:35 | 000,000,000 | ---D | M] -- C:\Users\H.-C.Rittershauß\AppData\Roaming\Canneverbe Limited
[2011.08.12 19:36:21 | 000,000,000 | ---D | M] -- C:\Users\H.-C.Rittershauß\AppData\Roaming\DVDVideoSoft
[2011.08.12 19:21:25 | 000,000,000 | ---D | M] -- C:\Users\H.-C.Rittershauß\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.11.07 13:32:24 | 000,000,000 | ---D | M] -- C:\Users\H.-C.Rittershauß\AppData\Roaming\ICQ
[2011.08.06 13:20:18 | 000,000,000 | ---D | M] -- C:\Users\H.-C.Rittershauß\AppData\Roaming\OpenCandy
[2011.03.25 19:07:13 | 000,000,000 | ---D | M] -- C:\Users\H.-C.Rittershauß\AppData\Roaming\OpenOffice.org
[2011.07.01 04:11:21 | 000,000,000 | ---D | M] -- C:\Users\H.-C.Rittershauß\AppData\Roaming\PhotoFiltre
[2011.03.22 16:59:44 | 000,000,000 | ---D | M] -- C:\Users\H.-C.Rittershauß\AppData\Roaming\PictureMover
[2011.03.22 16:58:41 | 000,000,000 | ---D | M] -- C:\Users\H.-C.Rittershauß\AppData\Roaming\Synaptics
[2011.10.04 16:33:04 | 000,000,000 | ---D | M] -- C:\Users\H.-C.Rittershauß\AppData\Roaming\Ubisoft
[2011.08.06 13:20:47 | 000,000,000 | ---D | M] -- C:\Users\H.-C.Rittershauß\AppData\Roaming\Uniblue
[2011.04.23 09:10:46 | 000,000,000 | ---D | M] -- C:\Users\H.-C.Rittershauß\AppData\Roaming\Windows Live Writer
[2011.03.22 17:43:09 | 000,000,000 | ---D | M] -- C:\Users\H.-C.Rittershauß\AppData\Roaming\_MDLogs
[2011.03.22 16:46:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2011.08.06 13:20:35 | 000,000,000 | ---D | M] -- C:\ProgramData\Canneverbe Limited
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2011.03.22 16:46:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
[2011.03.22 16:46:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2011.07.18 08:55:43 | 000,000,000 | ---D | M] -- C:\ProgramData\ICQ
[2011.02.20 01:48:01 | 000,000,000 | ---D | M] -- C:\ProgramData\PictureMover
[2011.06.27 19:19:26 | 000,000,000 | ---D | M] -- C:\ProgramData\PMB Files
[2011.02.20 01:40:42 | 000,000,000 | ---D | M] -- C:\ProgramData\Ralink Driver
[2011.01.09 17:51:08 | 000,000,000 | ---D | M] -- C:\ProgramData\Stardock
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2011.03.22 16:46:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
[2011.02.20 01:48:11 | 000,000,000 | ---D | M] -- C:\ProgramData\Temp
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2011.10.04 16:21:00 | 000,000,000 | ---D | M] -- C:\ProgramData\Ubisoft
[2011.08.07 07:40:50 | 000,000,000 | ---D | M] -- C:\ProgramData\Uniblue
[2011.03.22 16:46:28 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
[2011.03.27 20:47:48 | 000,000,000 | ---D | M] -- C:\ProgramData\WildTangent
[2011.01.09 18:06:56 | 000,000,000 | ---D | M] -- C:\ProgramData\{7A89BFAF-D4AA-434A-B652-6F880DD86278}
[2011.10.12 01:23:43 | 000,000,000 | ---D | M] -- C:\ProgramData\{D3B41B92-9BC2-43EB-916A-4FA9E8191837}
[2011.06.23 16:45:44 | 000,000,000 | ---D | M] -- C:\ProgramData\{E91883C8-8CDC-46A4-A45F-CB40EB82ED60}
[2011.11.07 13:30:43 | 000,000,362 | ---- | M] () -- C:\Windows\Tasks\DriverScanner.job
[2011.07.18 15:46:37 | 000,032,624 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report > --- --- ---
Mondstein |