Nicky711 | 21.02.2012 20:57 | ESET Code:
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=c131294505b561409bf5e7fd2a259008
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-02-21 07:25:14
# local_time=2012-02-21 08:25:14 (+0100, Westeuropäische Normalzeit)
# country="Germany"
# lang=1031
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=1280 16777191 100 0 122449 122449 0 0
# compatibility_mode=1797 16775141 100 93 0 66381347 30979 0
# compatibility_mode=6143 16777215 0 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 712776 712776 0 0
# scanned=130168
# found=0
# cleaned=0
# scan_time=2833 OTL Log
OTL Logfile: Code:
OTL logfile created on: 21.02.2012 20:37:26 - Run 2
OTL by OldTimer - Version 3.2.33.1 Folder = H:\Dokumente und Einstellungen\Isa\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,25 Gb Total Physical Memory | 2,07 Gb Available Physical Memory | 63,83% Memory free
5,08 Gb Paging File | 3,68 Gb Available in Paging File | 72,29% Paging File free
Paging file location(s): H:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = H: | %SystemRoot% = H:\WINDOWS | %ProgramFiles% = H:\Programme
Drive H: | 65,17 Gb Total Space | 35,02 Gb Free Space | 53,73% Space Free | Partition Type: NTFS
Drive I: | 221,62 Gb Total Space | 128,15 Gb Free Space | 57,83% Space Free | Partition Type: NTFS
Computer Name: EFA-E79777A29C9 | User Name: Isa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.02.21 20:35:57 | 000,583,168 | ---- | M] (OldTimer Tools) -- H:\Dokumente und Einstellungen\Isa\Desktop\OTL.exe
PRC - [2012.01.22 08:40:04 | 003,025,112 | ---- | M] (Emsi Software GmbH) -- H:\Programme\Emsisoft Anti-Malware\a2service.exe
PRC - [2011.10.27 20:15:32 | 000,396,288 | ---- | M] (Hauppauge Computer Works) -- H:\Programme\WinTV\TVServer\CaptureGenUSB.exe
PRC - [2011.10.27 20:15:16 | 000,570,368 | ---- | M] (Hauppauge Computer Works) -- H:\Programme\WinTV\TVServer\HauppaugeTVServer.exe
PRC - [2011.10.08 20:55:10 | 000,161,664 | ---- | M] (Oracle Corporation) -- H:\Programme\Java\jre7\bin\jqs.exe
PRC - [2011.09.29 08:09:51 | 000,924,632 | ---- | M] (Mozilla Corporation) -- H:\Programme\Mozilla Firefox\firefox.exe
PRC - [2011.07.21 11:08:02 | 000,269,480 | ---- | M] (Avira GmbH) -- H:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.04.24 23:15:02 | 000,202,296 | ---- | M] (Kaspersky Lab ZAO) -- H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
PRC - [2011.04.24 23:12:42 | 000,131,472 | ---- | M] (Kaspersky Lab ZAO) -- H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\klwtblfs.exe
PRC - [2011.04.21 06:53:10 | 000,076,968 | ---- | M] (Avira GmbH) -- H:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.04.21 06:52:51 | 000,136,360 | ---- | M] (Avira GmbH) -- H:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2011.04.21 06:52:36 | 000,281,768 | ---- | M] (Avira GmbH) -- H:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2009.09.18 17:48:28 | 000,009,216 | ---- | M] (Vodafone) -- H:\Programme\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
PRC - [2008.04.14 06:52:46 | 001,036,800 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\explorer.exe
PRC - [2007.01.17 11:20:10 | 000,061,440 | ---- | M] (Hewlett-Packard Company) -- H:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
PRC - [2006.11.03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) -- H:\Programme\Windows Defender\MsMpEng.exe
PRC - [2005.11.21 10:34:24 | 000,081,920 | ---- | M] (AVM Berlin) -- H:\Programme\FRITZ!DSL\IGDCTRL.EXE
PRC - [2005.11.15 02:07:28 | 000,679,936 | ---- | M] (AVM Berlin) -- H:\Programme\FRITZ!DSL\StCenter.exe
========== Modules (No Company Name) ==========
MOD - [2012.02.21 15:21:23 | 011,817,472 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\29bdc8352d3c26e3c572ea60639dec3b\System.Web.ni.dll
MOD - [2012.02.21 15:08:47 | 000,212,992 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\11dcb806c92f55111f5fa9f1a90e3bdd\System.ServiceProcess.ni.dll
MOD - [2012.02.21 15:08:28 | 000,998,400 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\a2a14380e8c9149d5b212d0100ef588a\System.Management.ni.dll
MOD - [2012.02.21 15:06:10 | 000,679,936 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\5fb9981f4147b537b53be9d58bf4e9b4\System.Security.ni.dll
MOD - [2012.02.21 15:06:05 | 000,971,264 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\94a40f415bfa947e251888bbe88bb973\System.Configuration.ni.dll
MOD - [2012.02.21 15:02:51 | 005,450,752 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\77e1279cbf4eecfb0284b63316fe43fe\System.Xml.ni.dll
MOD - [2012.02.21 15:02:42 | 012,430,848 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ad99ac6b5666edb8ee742dd64f9578af\System.Windows.Forms.ni.dll
MOD - [2012.02.21 15:02:24 | 001,587,200 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\9351cf29bb1ba951e45a9b3b0edab937\System.Drawing.ni.dll
MOD - [2012.02.21 15:00:55 | 007,953,408 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\9e3803cd2a11f056291862e306a8e2b2\System.ni.dll
MOD - [2012.02.21 14:58:50 | 000,303,104 | ---- | M] () -- H:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2012.01.03 14:10:46 | 000,301,056 | ---- | M] () -- H:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.DEU
MOD - [2011.10.15 10:53:12 | 000,025,600 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll
MOD - [2011.10.15 10:15:24 | 011,490,816 | ---- | M] () -- H:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
MOD - [2011.09.30 19:10:40 | 006,277,280 | ---- | M] () -- H:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011.09.29 08:09:51 | 001,833,944 | ---- | M] () -- H:\Programme\Mozilla Firefox\mozjs.dll
MOD - [2011.09.08 12:20:28 | 000,270,336 | ---- | M] () -- H:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2011.07.21 14:12:30 | 000,355,688 | ---- | M] () -- H:\Programme\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2011.05.28 21:04:56 | 000,140,288 | ---- | M] () -- H:\Programme\WinRAR\RarExt.dll
MOD - [2011.04.24 23:13:30 | 007,008,656 | ---- | M] () -- H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\qtgui4.dll
MOD - [2011.04.24 23:13:28 | 000,192,912 | ---- | M] () -- H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\qtsql4.dll
MOD - [2011.04.24 23:13:26 | 001,270,160 | ---- | M] () -- H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\qtscript4.dll
MOD - [2011.04.24 23:13:26 | 000,758,160 | ---- | M] () -- H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\qtnetwork4.dll
MOD - [2011.04.24 23:13:24 | 002,118,032 | ---- | M] () -- H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\qtcore4.dll
MOD - [2011.04.24 23:13:24 | 002,089,360 | ---- | M] () -- H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\qtdeclarative4.dll
MOD - [2011.04.20 19:56:28 | 000,025,088 | ---- | M] () -- H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\imageformats\qgif4.dll
MOD - [2010.03.16 11:22:12 | 000,014,848 | ---- | M] () -- H:\Programme\ATI Technologies\ATI.ACE\Core-Static\AxInterop.WBOCXLib.dll
MOD - [2008.04.14 06:52:18 | 000,014,336 | ---- | M] () -- H:\WINDOWS\system32\msdmo.dll
MOD - [2001.10.28 17:42:30 | 000,116,224 | ---- | M] () -- H:\WINDOWS\system32\pdfcmnnt.dll
========== Win32 Services (SafeList) ==========
SRV - [2012.01.22 08:40:04 | 003,025,112 | ---- | M] (Emsi Software GmbH) [Auto | Running] -- H:\Programme\Emsisoft Anti-Malware\a2service.exe -- (a2AntiMalware)
SRV - [2011.10.27 20:15:16 | 000,570,368 | ---- | M] (Hauppauge Computer Works) [Auto | Running] -- H:\Programme\WinTV\TVServer\HauppaugeTVServer.exe -- (HauppaugeTVServer)
SRV - [2011.10.08 20:55:10 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- H:\Programme\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2011.07.21 11:08:02 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- H:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.24 23:15:02 | 000,202,296 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe -- (AVP)
SRV - [2011.04.21 06:52:51 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- H:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2009.09.18 17:48:28 | 000,009,216 | ---- | M] (Vodafone) [Auto | Running] -- H:\Programme\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
SRV - [2007.03.26 11:51:06 | 000,267,824 | ---- | M] (Nero AG) [On_Demand | Stopped] -- H:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2007.01.17 11:20:10 | 000,061,440 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- H:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe -- (LightScribeService)
SRV - [2006.11.03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- H:\Programme\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2005.11.21 10:34:24 | 000,081,920 | ---- | M] (AVM Berlin) [Auto | Running] -- H:\Programme\FRITZ!DSL\IGDCTRL.EXE -- (AVM IGD CTRL Service)
SRV - [2005.11.21 09:48:06 | 000,315,392 | ---- | M] (AVM Berlin) [On_Demand | Stopped] -- H:\Programme\Gemeinsame Dateien\AVM\De_serv.exe -- (de_serv)
========== Driver Services (SafeList) ==========
DRV - [2012.02.21 19:36:33 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2012.02.20 10:37:02 | 000,565,552 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- H:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
DRV - [2011.11.02 10:13:28 | 000,034,768 | ---- | M] (Emsi Software GmbH) [File_System | System | Running] -- H:\Programme\Emsisoft Anti-Malware\a2dix86.sys -- (a2injectiondriver)
DRV - [2011.11.02 10:13:12 | 000,051,632 | ---- | M] (Emsi Software GmbH) [File_System | On_Demand | Running] -- H:\Programme\Emsisoft Anti-Malware\a2accx86.sys -- (a2acc)
DRV - [2011.09.08 19:24:14 | 007,180,800 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2011.08.30 16:28:46 | 006,435,432 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2011.07.21 11:11:12 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- H:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.07.21 11:11:11 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- H:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.05.19 13:10:34 | 000,017,904 | ---- | M] (Emsi Software GmbH) [Kernel | System | Running] -- H:\Programme\Emsisoft Anti-Malware\a2ddax86.sys -- (A2DDA)
DRV - [2011.04.04 17:53:00 | 000,016,000 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\hcw95rc.sys -- (hcw95rc)
DRV - [2011.04.04 17:52:26 | 000,573,952 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\hcw95bda.sys -- (hcw95bda)
DRV - [2011.03.10 18:34:46 | 000,034,608 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\klim5.sys -- (klim5)
DRV - [2011.03.04 13:23:20 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- H:\WINDOWS\system32\drivers\kl2.sys -- (kl2)
DRV - [2011.03.04 13:23:14 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- H:\WINDOWS\system32\DRIVERS\kl1.sys -- (KL1)
DRV - [2010.12.30 15:19:40 | 000,016,640 | ---- | M] (Wondershare) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\Apowersoft_AudioDevice.sys -- (Apowersoft_AudioDevice)
DRV - [2010.12.29 02:37:40 | 000,276,968 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2010.05.05 08:40:32 | 000,011,776 | ---- | M] (Emsi Software GmbH) [Kernel | System | Running] -- H:\Programme\Emsisoft Anti-Malware\a2util32.sys -- (a2util)
DRV - [2009.12.07 19:53:12 | 000,102,912 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2009.11.18 06:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009.11.18 06:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2009.11.02 20:27:24 | 000,019,472 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2009.10.08 16:55:33 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- H:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.09.29 15:05:15 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- H:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009.08.18 12:06:56 | 000,114,688 | R--- | M] (ZTE Corporation) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\ZTEusbnet.sys -- (ZTEusbnet)
DRV - [2009.08.18 12:06:56 | 000,105,088 | R--- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\zteusbvoice.sys -- (ZTEusbvoice)
DRV - [2009.08.18 12:06:56 | 000,105,088 | R--- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2009.08.18 12:06:56 | 000,105,088 | R--- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2009.08.18 12:06:56 | 000,105,088 | R--- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2009.06.30 17:46:24 | 000,009,728 | R--- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\massfilter.sys -- (massfilter)
DRV - [2008.04.14 00:16:24 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- H:\WINDOWS\system32\drivers\MPE.sys -- (MPE)
DRV - [2007.04.16 15:46:34 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- H:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2000.01.01 01:00:00 | 000,101,904 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- H:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://www.tauschbillet.de/"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: H:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: H:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: H:\Programme\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: H:\Programme\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: H:\Programme\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: H:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\linkfilter@kaspersky.ru: H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\linkfilter@kaspersky.ru [2012.02.21 14:56:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru [2012.02.21 14:56:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\KavAntiBanner@Kaspersky.ru: H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\KavAntiBanner@Kaspersky.ru [2012.02.21 14:56:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: H:\Programme\Mozilla Firefox\components [2011.09.30 15:56:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: H:\Programme\Mozilla Firefox\plugins
[2011.09.30 14:19:05 | 000,000,000 | ---D | M] (No name found) -- H:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Mozilla\Extensions
[2012.02.18 09:40:14 | 000,000,000 | ---D | M] (No name found) -- H:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Mozilla\Firefox\Profiles\m233qzw0.default\extensions
[2011.12.25 19:52:05 | 000,000,000 | ---D | M] (DownloadHelper) -- H:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Mozilla\Firefox\Profiles\m233qzw0.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.02.18 09:40:14 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- H:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Mozilla\Firefox\Profiles\m233qzw0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012.02.13 09:50:53 | 000,000,000 | ---D | M] (Greasemonkey) -- H:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Mozilla\Firefox\Profiles\m233qzw0.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011.12.08 12:32:55 | 000,000,000 | ---D | M] (Roomy Bookmarks Toolbar) -- H:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Mozilla\Firefox\Profiles\m233qzw0.default\extensions\ALone-live@ya.ru
[2011.10.08 20:55:22 | 000,000,000 | ---D | M] (No name found) -- H:\Programme\Mozilla Firefox\extensions
[2011.10.03 08:05:33 | 000,000,000 | ---D | M] (Java Console) -- H:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011.10.07 21:34:21 | 000,000,000 | ---D | M] (Java Console) -- H:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011.10.08 20:53:42 | 000,000,000 | ---D | M] (Java Console) -- H:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011.10.08 20:55:20 | 000,000,000 | ---D | M] (Java Console) -- H:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
() (No name found) -- H:\DOKUMENTE UND EINSTELLUNGEN\ISA\ANWENDUNGSDATEN\MOZILLA\FIREFOX\PROFILES\M233QZW0.DEFAULT\EXTENSIONS\{888D99E7-E8B5-46A3-851E-1EC45DA1E644}.XPI
[2012.02.21 14:56:28 | 000,000,000 | ---D | M] (Anti-Banner) -- H:\PROGRAMME\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\FFEXT\KAVANTIBANNER@KASPERSKY.RU
[2012.02.21 14:56:28 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- H:\PROGRAMME\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\FFEXT\LINKFILTER@KASPERSKY.RU
[2012.02.21 14:56:29 | 000,000,000 | ---D | M] (Kaspersky Virtual Keyboard) -- H:\PROGRAMME\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\FFEXT\VIRTUALKEYBOARD@KASPERSKY.RU
[2011.10.08 21:59:17 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- H:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011.09.29 08:09:51 | 000,134,104 | ---- | M] (Mozilla Foundation) -- H:\Programme\mozilla firefox\components\browsercomps.dll
[2011.09.29 02:24:37 | 000,001,392 | ---- | M] () -- H:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.09.29 02:16:42 | 000,002,252 | ---- | M] () -- H:\Programme\mozilla firefox\searchplugins\bing.xml
[2011.09.29 02:24:37 | 000,001,153 | ---- | M] () -- H:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2011.09.29 02:24:37 | 000,006,805 | ---- | M] () -- H:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.29 02:24:37 | 000,001,178 | ---- | M] () -- H:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.09.29 02:24:37 | 000,001,105 | ---- | M] () -- H:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2012.02.20 16:47:51 | 000,000,027 | ---- | M]) - H:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [Adobe ARM] H:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] H:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [AVP] H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [emsisoft anti-malware] h:\programme\emsisoft anti-malware\a2guard.exe (Emsi Software GmbH)
O4 - HKLM..\Run: [StartCCC] H:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] H:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: H:\Dokumente und Einstellungen\Isa\Startmenü\Programme\Autostart\FRITZ!DSL Internet.lnk = H:\Programme\FRITZ!DSL\FritzDsl.exe (AVM Berlin)
O4 - Startup: H:\Dokumente und Einstellungen\Isa\Startmenü\Programme\Autostart\FRITZ!DSL Startcenter.lnk = H:\Programme\FRITZ!DSL\StCenter.exe (AVM Berlin)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Hinzufügen zu Anti-Banner - H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm ()
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - H:\Programme\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O15 - HKCU\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKCU\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1329686990562 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D897CDC7-1E95-4326-BA1B-0BAB38EE7D33}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - H:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - H:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - H:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - H:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (H:\WINDOWS\system32\userinit.exe) - H:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - H:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\klogon: DllName - (H:\WINDOWS\system32\klogon.dll) - H:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: H:\Dokumente und Einstellungen\Isa\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: H:\Dokumente und Einstellungen\Isa\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - H:\Programme\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.03.19 12:29:16 | 000,052,556 | ---- | M] () - I:\autobild.de.pdf -- [ NTFS ]
O32 - AutoRun File - [2011.02.14 09:03:10 | 000,016,679 | ---- | M] () - I:\A.gif -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012.02.21 20:36:05 | 000,583,168 | ---- | C] (OldTimer Tools) -- H:\Dokumente und Einstellungen\Isa\Desktop\OTL.exe
[2012.02.21 17:40:43 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012.02.21 17:40:40 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- H:\WINDOWS\System32\drivers\mbam.sys
[2012.02.21 14:36:17 | 000,237,072 | ---- | C] (Microsoft Corporation) -- H:\WINDOWS\System32\MpSigStub.exe
[2012.02.20 21:17:30 | 000,000,000 | -HSD | C] -- H:\RECYCLER
[2012.02.20 18:21:43 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Isa\Lokale Einstellungen\Anwendungsdaten\Solid State Networks
[2012.02.20 15:58:12 | 000,000,000 | -HSD | C] -- H:\WINDOWS\CSC
[2012.02.20 10:39:13 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Application Data
[2012.02.20 10:38:24 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Kaspersky Internet Security 2012
[2012.02.20 10:37:15 | 000,000,000 | ---D | C] -- H:\Programme\Kaspersky Lab
[2012.02.20 10:37:15 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab
[2012.02.20 10:37:02 | 000,565,552 | ---- | C] (Kaspersky Lab) -- H:\WINDOWS\System32\drivers\klif.sys
[2012.02.19 22:05:14 | 000,000,000 | ---D | C] -- H:\Programme\Windows Defender
[2012.02.19 21:58:51 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Isa\Desktop\ResultReport ms fix it-Dateien
[2012.02.19 21:57:29 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Isa\Anwendungsdaten\ElevatedDiagnostics
[2012.02.19 21:56:39 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Windows PowerShell 1.0
[2012.02.19 21:56:28 | 000,000,000 | ---D | C] -- H:\WINDOWS\System32\windowspowershell
[2012.02.18 22:49:30 | 000,000,000 | ---D | C] -- H:\WINDOWS\System32\CatRoot_bak
[2012.02.18 17:36:16 | 069,507,776 | ---- | C] (Microsoft Corporation) -- H:\Dokumente und Einstellungen\Isa\Desktop\msert.exe
[2012.02.18 09:57:49 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Emsisoft Anti-Malware
[2012.02.18 09:57:36 | 000,000,000 | ---D | C] -- H:\Programme\Emsisoft Anti-Malware
[2012.02.18 09:57:36 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Isa\Eigene Dateien\Anti-Malware
[2012.02.17 18:02:20 | 000,000,000 | ---D | C] -- H:\WINDOWS\pss
[2012.02.17 17:57:54 | 000,000,000 | R--D | C] -- H:\Dokumente und Einstellungen\Isa\Recent
[2012.02.16 15:05:45 | 000,000,000 | RHSD | C] -- H:\cmdcons
[2012.02.16 15:03:58 | 000,518,144 | ---- | C] (SteelWerX) -- H:\WINDOWS\SWREG.exe
[2012.02.16 15:03:58 | 000,406,528 | ---- | C] (SteelWerX) -- H:\WINDOWS\SWSC.exe
[2012.02.16 15:03:58 | 000,212,480 | ---- | C] (SteelWerX) -- H:\WINDOWS\SWXCACLS.exe
[2012.02.16 15:03:58 | 000,060,416 | ---- | C] (NirSoft) -- H:\WINDOWS\NIRCMD.exe
[2012.02.16 15:03:53 | 000,000,000 | ---D | C] -- H:\WINDOWS\ERDNT
[2012.02.16 15:03:50 | 000,000,000 | ---D | C] -- H:\Qoobox
[2012.02.16 15:03:48 | 000,000,000 | R--D | C] -- H:\Dokumente und Einstellungen\Isa\Startmenü\Programme\Verwaltung
[2012.02.16 15:03:48 | 000,000,000 | R--D | C] -- H:\Dokumente und Einstellungen\Isa\Eigene Dateien\Eigene Videos
[2012.02.16 14:56:39 | 004,405,806 | R--- | C] (Swearware) -- H:\Dokumente und Einstellungen\Isa\Desktop\ComboFix.exe
[2012.02.15 16:32:22 | 002,061,360 | ---- | C] (Kaspersky Lab ZAO) -- H:\Dokumente und Einstellungen\Isa\Desktop\tdsskiller.exe
[2012.02.13 16:35:54 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Isa\Desktop\Virus
[2012.02.13 16:21:26 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- H:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012.02.13 16:21:26 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Malwarebytes
[2012.02.13 16:21:21 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2012.02.13 16:21:20 | 000,000,000 | ---D | C] -- H:\Programme\Malwarebytes' Anti-Malware
[2012.02.13 14:38:28 | 000,000,000 | ---D | C] -- H:\Programme\ESET
[2012.02.13 12:01:58 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Isa\Anwendungsdaten\f-secure
[2012.02.13 12:01:47 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\F-Secure
[2012.02.13 11:46:47 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Isa\Anwendungsdaten\QuickScan
[2012.02.08 09:40:20 | 000,000,000 | ---D | C] -- H:\Programme\AntiTwin
[2012.02.05 19:31:01 | 000,000,000 | ---D | C] -- H:\CloneDVDTemp
[2012.02.05 19:21:11 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Isa\Eigene Dateien\AnyDVDHD
[2012.02.05 19:20:04 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SlySoft
[2012.02.05 19:11:31 | 000,000,000 | ---D | C] -- H:\Programme\SlySoft
[2012.02.05 10:39:17 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Isa\Anwendungsdaten\Lonely Troops
[2012.01.23 21:23:30 | 000,000,000 | ---D | C] -- H:\Dokumente und Einstellungen\Isa\Desktop\tauschgnom
[2009.10.15 18:17:10 | 000,130,520 | R--- | C] () -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DeviceManager.xml.rc4
[5 H:\WINDOWS\*.tmp files -> H:\WINDOWS\*.tmp -> ]
[1 H:\*.tmp files -> H:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.02.21 20:35:57 | 000,583,168 | ---- | M] (OldTimer Tools) -- H:\Dokumente und Einstellungen\Isa\Desktop\OTL.exe
[2012.02.21 20:19:03 | 000,001,084 | ---- | M] () -- H:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012.02.21 19:36:33 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- H:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012.02.21 17:40:44 | 000,000,756 | ---- | M] () -- H:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.02.21 17:40:00 | 000,000,069 | ---- | M] () -- H:\WINDOWS\NeroDigital.ini
[2012.02.21 17:02:16 | 000,000,260 | ---- | M] () -- H:\WINDOWS\tasks\WGASetup.job
[2012.02.21 17:00:54 | 000,000,322 | -H-- | M] () -- H:\WINDOWS\tasks\MP Scheduled Scan.job
[2012.02.21 16:59:31 | 000,001,080 | ---- | M] () -- H:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012.02.21 16:57:48 | 000,002,048 | --S- | M] () -- H:\WINDOWS\bootstat.dat
[2012.02.21 16:57:42 | 000,122,928 | ---- | M] () -- H:\WINDOWS\System32\FNTCACHE.DAT
[2012.02.21 14:59:17 | 000,516,590 | ---- | M] () -- H:\WINDOWS\System32\perfh007.dat
[2012.02.21 14:59:17 | 000,493,190 | ---- | M] () -- H:\WINDOWS\System32\perfh009.dat
[2012.02.21 14:59:17 | 000,100,494 | ---- | M] () -- H:\WINDOWS\System32\perfc007.dat
[2012.02.21 14:59:17 | 000,083,734 | ---- | M] () -- H:\WINDOWS\System32\perfc009.dat
[2012.02.21 14:53:21 | 000,001,374 | ---- | M] () -- H:\WINDOWS\imsins.BAK
[2012.02.20 20:23:14 | 000,010,029 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\h.odt
[2012.02.20 18:33:24 | 000,000,046 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\GMX - E-Mail, FreeMail, Themen- & Shopping-Portal.URL
[2012.02.20 17:12:40 | 000,684,297 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\unhide.exe
[2012.02.20 16:47:51 | 000,000,027 | ---- | M] () -- H:\WINDOWS\System32\drivers\etc\hosts
[2012.02.20 10:39:47 | 000,017,408 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Lokale Einstellungen\Anwendungsdaten\WebpageIcons.db
[2012.02.20 10:38:28 | 000,115,369 | ---- | M] () -- H:\WINDOWS\System32\drivers\klin.dat
[2012.02.20 10:38:28 | 000,097,961 | ---- | M] () -- H:\WINDOWS\System32\drivers\klick.dat
[2012.02.20 10:37:02 | 000,565,552 | ---- | M] (Kaspersky Lab) -- H:\WINDOWS\System32\drivers\klif.sys
[2012.02.20 10:35:20 | 000,002,206 | ---- | M] () -- H:\WINDOWS\System32\wpa.dbl
[2012.02.19 21:58:51 | 000,040,014 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\ResultReport ms fix it.htm
[2012.02.19 09:43:56 | 000,000,678 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Verknüpfung mit PDFCreator.lnk
[2012.02.19 09:37:11 | 000,000,787 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Verknüpfung mit avcenter.lnk
[2012.02.19 04:28:18 | 000,000,000 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Rechner - Ergebnis.pdf
[2012.02.18 21:33:34 | 000,003,913 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\fsonlinescanner_report.html
[2012.02.18 21:09:30 | 069,507,776 | ---- | M] (Microsoft Corporation) -- H:\Dokumente und Einstellungen\Isa\Desktop\msert.exe
[2012.02.18 19:05:44 | 000,005,120 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.02.18 14:08:11 | 000,000,696 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Verknüpfung mit firefox.lnk
[2012.02.18 09:57:49 | 000,000,738 | ---- | M] () -- H:\Dokumente und Einstellungen\All Users\Desktop\Emsisoft Anti-Malware.lnk
[2012.02.16 15:05:49 | 000,000,327 | RHS- | M] () -- H:\boot.ini
[2012.02.16 14:56:40 | 004,405,806 | R--- | M] (Swearware) -- H:\Dokumente und Einstellungen\Isa\Desktop\ComboFix.exe
[2012.02.15 16:32:25 | 002,061,360 | ---- | M] (Kaspersky Lab ZAO) -- H:\Dokumente und Einstellungen\Isa\Desktop\tdsskiller.exe
[2012.02.15 15:57:53 | 000,302,592 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\54kyunvb.exe
[2012.02.13 19:36:42 | 000,000,000 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\defogger_reenable
[2012.02.12 17:22:17 | 000,000,861 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Verknüpfung mit IncaBall.lnk
[2012.02.09 10:10:04 | 000,082,652 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\2012_02_08.pdf
[2012.02.09 09:43:56 | 000,000,125 | -HS- | M] () -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\.zreglib
[2012.02.07 18:24:45 | 000,034,230 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\efa.pdf
[2012.02.07 14:48:13 | 000,032,779 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\efa03.pdf
[2012.02.07 08:55:52 | 000,027,359 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\die-band-3.pdf
[2012.02.05 10:39:11 | 000,000,646 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Verknüpfung mit Romopolis.lnk
[2012.01.31 17:53:43 | 000,021,417 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\ECON.odt
[2012.01.30 20:25:43 | 000,017,538 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\S.ods
[2012.01.29 05:10:42 | 000,237,072 | ---- | M] (Microsoft Corporation) -- H:\WINDOWS\System32\MpSigStub.exe
[2012.01.28 18:52:32 | 000,000,134 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\.~lock.F_2012_01_28.odt#
[2012.01.25 20:19:58 | 000,085,592 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Zwischenablage01 .jpg
[2012.01.25 10:13:12 | 000,010,854 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Adressen.odt
[2012.01.24 20:03:33 | 000,021,486 | ---- | M] () -- H:\Dokumente und Einstellungen\Isa\Desktop\BdP-2012.odt
[5 H:\WINDOWS\*.tmp files -> H:\WINDOWS\*.tmp -> ]
[1 H:\*.tmp files -> H:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.02.21 17:40:44 | 000,000,756 | ---- | C] () -- H:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.02.21 14:34:12 | 000,003,072 | ---- | C] () -- H:\WINDOWS\System32\iacenc.dll
[2012.02.21 14:34:12 | 000,003,072 | ---- | C] () -- H:\WINDOWS\System32\dllcache\iacenc.dll
[2012.02.20 18:33:24 | 000,000,046 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\GMX - E-Mail, FreeMail, Themen- & Shopping-Portal.URL
[2012.02.20 18:26:39 | 000,002,347 | ---- | C] () -- H:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Adobe Reader X.lnk
[2012.02.20 17:12:44 | 000,684,297 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\unhide.exe
[2012.02.20 10:39:45 | 000,017,408 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Lokale Einstellungen\Anwendungsdaten\WebpageIcons.db
[2012.02.20 10:38:28 | 000,115,369 | ---- | C] () -- H:\WINDOWS\System32\drivers\klin.dat
[2012.02.20 10:38:28 | 000,097,961 | ---- | C] () -- H:\WINDOWS\System32\drivers\klick.dat
[2012.02.19 22:08:18 | 000,000,322 | -H-- | C] () -- H:\WINDOWS\tasks\MP Scheduled Scan.job
[2012.02.19 22:05:16 | 000,000,927 | ---- | C] () -- H:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Windows Defender.lnk
[2012.02.19 21:58:50 | 000,040,014 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\ResultReport ms fix it.htm
[2012.02.19 09:43:56 | 000,000,678 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Verknüpfung mit PDFCreator.lnk
[2012.02.19 09:37:11 | 000,000,787 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Verknüpfung mit avcenter.lnk
[2012.02.19 04:28:05 | 000,000,000 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Rechner - Ergebnis.pdf
[2012.02.18 21:33:34 | 000,003,913 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\fsonlinescanner_report.html
[2012.02.18 14:08:11 | 000,000,696 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Verknüpfung mit firefox.lnk
[2012.02.18 09:57:49 | 000,000,738 | ---- | C] () -- H:\Dokumente und Einstellungen\All Users\Desktop\Emsisoft Anti-Malware.lnk
[2012.02.16 15:05:49 | 000,000,210 | ---- | C] () -- H:\Boot.bak
[2012.02.16 15:05:47 | 000,262,448 | RHS- | C] () -- H:\cmldr
[2012.02.16 15:03:58 | 000,256,000 | ---- | C] () -- H:\WINDOWS\PEV.exe
[2012.02.16 15:03:58 | 000,208,896 | ---- | C] () -- H:\WINDOWS\MBR.exe
[2012.02.16 15:03:58 | 000,098,816 | ---- | C] () -- H:\WINDOWS\sed.exe
[2012.02.16 15:03:58 | 000,080,412 | ---- | C] () -- H:\WINDOWS\grep.exe
[2012.02.16 15:03:58 | 000,068,096 | ---- | C] () -- H:\WINDOWS\zip.exe
[2012.02.15 15:57:53 | 000,302,592 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\54kyunvb.exe
[2012.02.13 19:36:42 | 000,000,000 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\defogger_reenable
[2012.02.12 17:22:17 | 000,000,861 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Verknüpfung mit IncaBall.lnk
[2012.02.08 11:30:14 | 000,082,652 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\2012_02_08.pdf
[2012.02.07 18:24:45 | 000,034,230 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\efa.pdf
[2012.02.07 14:48:13 | 000,032,779 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\efa03.pdf
[2012.02.07 08:55:52 | 000,027,359 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\die-band-3.pdf
[2012.02.05 19:19:54 | 000,000,125 | -HS- | C] () -- H:\Dokumente und Einstellungen\All Users\Anwendungsdaten\.zreglib
[2012.02.05 10:39:11 | 000,000,646 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Verknüpfung mit Romopolis.lnk
[2012.01.30 22:51:42 | 000,021,417 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\ECON.odt
[2012.01.28 18:52:32 | 000,000,134 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\.~lock.2012_01_28.odt#
[2012.01.25 20:19:58 | 000,085,592 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Zwischenablage01 .jpg
[2012.01.24 20:03:32 | 000,021,486 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Desktop\Aug 2012.odt
[2012.01.21 10:29:22 | 000,004,096 | ---- | C] () -- H:\WINDOWS\d3dx.dat
[2012.01.16 19:50:54 | 000,000,135 | ---- | C] () -- H:\WINDOWS\ODBC.INI
[2012.01.16 19:50:39 | 000,037,621 | ---- | C] () -- H:\WINDOWS\Irremote.ini
[2012.01.16 19:50:27 | 000,142,337 | ---- | C] () -- H:\WINDOWS\System32\Wait.exe
[2012.01.16 19:48:39 | 000,007,188 | ---- | C] () -- H:\WINDOWS\HCWPNP.INI
[2012.01.16 19:48:02 | 000,363,520 | ---- | C] () -- H:\WINDOWS\System32\PsisDecd.dll
[2011.12.26 19:23:43 | 000,000,069 | ---- | C] () -- H:\WINDOWS\NeroDigital.ini
[2011.11.21 21:17:11 | 000,116,224 | ---- | C] () -- H:\WINDOWS\System32\pdfcmnnt.dll
[2011.11.17 18:52:53 | 000,005,120 | ---- | C] () -- H:\Dokumente und Einstellungen\Isa\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.11.04 11:23:56 | 000,065,536 | ---- | C] () -- H:\WINDOWS\System32\WebCamLib.dll
[2011.10.19 10:40:23 | 000,000,425 | ---- | C] () -- H:\WINDOWS\BRWMARK.INI
[2011.10.19 10:40:23 | 000,000,027 | ---- | C] () -- H:\WINDOWS\BRPP2KA.INI
[2011.10.19 10:39:35 | 000,000,050 | ---- | C] () -- H:\WINDOWS\System32\bridf07a.dat
[2011.10.19 10:37:30 | 000,031,664 | ---- | C] () -- H:\WINDOWS\maxlink.ini
[2011.10.09 08:16:43 | 000,000,000 | ---- | C] () -- H:\WINDOWS\ativpsrm.bin
[2011.10.09 08:16:34 | 000,887,724 | ---- | C] () -- H:\WINDOWS\System32\ativva6x.dat
[2011.10.09 08:16:33 | 000,239,869 | ---- | C] () -- H:\WINDOWS\System32\atiicdxx.dat
[2011.10.09 08:16:33 | 000,000,003 | ---- | C] () -- H:\WINDOWS\System32\ativva5x.dat
[2011.10.08 19:25:00 | 000,085,504 | ---- | C] () -- H:\WINDOWS\System32\ff_vfw.dll
[2011.10.02 10:23:47 | 000,000,552 | ---- | C] () -- H:\WINDOWS\System32\d3d8caps.dat
[2011.09.30 19:36:14 | 000,049,152 | R--- | C] () -- H:\WINDOWS\System32\ChCfg.exe
[2011.09.30 19:18:19 | 000,000,664 | ---- | C] () -- H:\WINDOWS\System32\d3d9caps.dat
[2011.09.30 14:19:01 | 000,000,000 | ---- | C] () -- H:\WINDOWS\nsreg.dat
[2011.09.30 14:06:05 | 000,081,936 | R--- | C] () -- H:\WINDOWS\System32\RtNicProp32.dll
[2011.09.30 13:08:20 | 000,002,048 | --S- | C] () -- H:\WINDOWS\bootstat.dat
[2011.09.30 13:04:00 | 000,021,740 | ---- | C] () -- H:\WINDOWS\System32\emptyregdb.dat
[2011.09.30 12:17:31 | 000,004,161 | ---- | C] () -- H:\WINDOWS\ODBCINST.INI
[2011.09.30 12:16:24 | 000,122,928 | ---- | C] () -- H:\WINDOWS\System32\FNTCACHE.DAT
[2011.09.14 10:47:40 | 000,053,760 | ---- | C] () -- H:\WINDOWS\System32\OVDecode.dll
[2011.03.11 12:43:54 | 000,029,763 | ---- | C] () -- H:\WINDOWS\System32\drivers\klopp.dat
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> H:\Dokumente und Einstellungen\Isa\Desktop\msert.exe:SummaryInformation
< End of report > --- --- ---
OTL Extras Log
OTL Logfile: Code:
OTL Extras logfile created on: 21.02.2012 20:37:27 - Run 2
OTL by OldTimer - Version 3.2.33.1 Folder = H:\Dokumente und Einstellungen\Isa\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,25 Gb Total Physical Memory | 2,07 Gb Available Physical Memory | 63,83% Memory free
5,08 Gb Paging File | 3,68 Gb Available in Paging File | 72,29% Paging File free
Paging file location(s): H:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = H: | %SystemRoot% = H:\WINDOWS | %ProgramFiles% = H:\Programme
Drive H: | 65,17 Gb Total Space | 35,02 Gb Free Space | 53,73% Space Free | Partition Type: NTFS
Drive I: | 221,62 Gb Total Space | 128,15 Gb Free Space | 57,83% Space Free | Partition Type: NTFS
Computer Name: EFA-E79777A29C9 | User Name: Isa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- H:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "H:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "H:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"H:\Programme\WinTV\WinTV7\WinTV7.exe" = H:\Programme\WinTV\WinTV7\WinTV7.exe:*:Enabled:WinTV7 -- (Hauppauge Computer Works, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{0138F525-6C8A-333F-A105-14AE030B9A54}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{140B5BC3-E263-397D-B1BB-C4095364FB6F}" = Catalyst Control Center InstallProxy
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19A492A0-888F-44A0-9B21-D91700763F62}" = Catalyst Control Center - Branding
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 27
"{26A24AE4-039D-4CA4-87B4-2F83217000FF}" = Java(TM) 7
"{332CC6BF-E6C7-48EE-BA3D-435E576AD67F}" = PaperPort Image Printer
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3686B63F-72CD-C0FB-1348-34DB78ADFC9C}" = CCC Help English
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{45E557D6-2271-4F13-8101-C620B4285AB0}" = Kaspersky Internet Security 2012
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{58288FBC-C7E8-FE33-3009-199C219D3363}" = Catalyst Control Center Graphics Previews Common
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{67CDD5A0-C572-4D2C-A354-6492B51F4138}" = SlimDrivers
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{96B51C0B-D3BE-4DF3-959C-28B22C10CFBB}" = Vodafone Mobile Connect Lite
"{97F32DF8-D66E-446A-A425-C1D7B45C1031}" = Nero 7 Essentials
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3FEC306-FBFF-4B0D-95B9-F9C67C65079E}" = Brother MFL-Pro Suite
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.6
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.2) - Deutsch
"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver
"{B6C89654-A6A2-477C-873B-724EC1C56407}" = ScanSoft PaperPort 11
"{BC30E5E7-047D-4232-A7E8-F2CB7CC7B2E0}_is1" = Emsisoft Anti-Malware
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{D0EC7B14-C363-8FCF-728E-A94144B31518}" = AMD Catalyst Install Manager
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{EB9F3F92-4857-4121-AA6F-1C424AC6C266}_is1" = Screen Recording Suite V2.2.0
"{EFF5ECCC-20B9-68CE-A95A-A1500E4E0FF8}" = ccc-utility
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FA798C4A-FE41-AE67-932F-F00CDAAA7723}" = Catalyst Control Center
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Anti-Twin 2012-02-08 09.40.20" = Anti-Twin (Installation 08.02.2012)
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"AVMFBox" = AVM FRITZ!Box Dokumentation
"Call of Atlantis_is1" = Call of Atlantis
"CCleaner" = CCleaner
"Color Efex Pro 3.0 Stand-Alone Standard" = Color Efex Pro 3.0 Standard
"CubeDrift_is1" = CubeDrift 1.10
"ESET Online Scanner" = ESET Online Scanner v3
"ffdshow_is1" = ffdshow [rev 3154] [2009-12-09]
"Fishdom - Frosty Splash_is1" = Fishdom - Frosty Splash
"Fishdom 2 Deluxe_is1" = Fishdom 2 Deluxe
"GMX Internet Manager" = GMX Internet Manager
"Hauppauge WinTV 7" = Hauppauge WinTV 7
"InstallWIX_{45E557D6-2271-4F13-8101-C620B4285AB0}" = Kaspersky Internet Security 2012
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.60.1.1000
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 7.0.1 (x86 de)" = Mozilla Firefox 7.0.1 (x86 de)
"phonostarRadioPlayer_is1" = phonostar-Player Version 2.01.5
"Photo Stamp Remover_is1" = Photo Stamp Remover 4.2
"Surf & E-Mail-Stick" = Surf & E-Mail-Stick
"VLC media player" = VLC media player 1.1.11
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR 4.01 (32-Bit)
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 20.02.2012 11:14:17 | Computer Name = EFA-E79777A29C9 | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: EFA-E79777A29C9\Isa Checkpoint ID: 1 Error Code: 0x80070005
Error
description: Zugriff verweigert
Error - 20.02.2012 11:14:17 | Computer Name = EFA-E79777A29C9 | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: EFA-E79777A29C9\Isa Checkpoint ID: 1 Error Code: 0x8000ffff
Error
description: Schwerwiegender Fehler
Error - 20.02.2012 11:14:36 | Computer Name = EFA-E79777A29C9 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 20.02.2012 13:15:43 | Computer Name = EFA-E79777A29C9 | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung AcroRd32.exe, Version 10.1.1.33, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 20.02.2012 13:18:01 | Computer Name = EFA-E79777A29C9 | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung firefox.exe, Version 7.0.1.4288, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 20.02.2012 13:31:42 | Computer Name = EFA-E79777A29C9 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 20.02.2012 21:00:12 | Computer Name = EFA-E79777A29C9 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80080005, P2 updateservicemanager-_get_services,
P3 fallbackcheck, P4 1.1.1593.0, P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender,
P8 NIL, P9 NIL, P10 NIL.
Error - 21.02.2012 09:31:37 | Computer Name = EFA-E79777A29C9 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 21.02.2012 11:58:11 | Computer Name = EFA-E79777A29C9 | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 21.02.2012 11:58:28 | Computer Name = EFA-E79777A29C9 | Source = .NET Runtime Optimization Service | ID = 1103
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Tried to start a service that wasn't the latest version of CLR Optimization service.
Will shutdown
[ System Events ]
Error - 21.02.2012 03:34:42 | Computer Name = EFA-E79777A29C9 | Source = DCOM | ID = 10010
Description = Der Server "{E60687F7-01A1-40AA-86AC-DB1CBF673334}" konnte innerhalb
des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error - 21.02.2012 03:34:44 | Computer Name = EFA-E79777A29C9 | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
Error - 21.02.2012 03:35:14 | Computer Name = EFA-E79777A29C9 | Source = DCOM | ID = 10010
Description = Der Server "{E60687F7-01A1-40AA-86AC-DB1CBF673334}" konnte innerhalb
des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error - 21.02.2012 03:35:59 | Computer Name = EFA-E79777A29C9 | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
Error - 21.02.2012 03:36:28 | Computer Name = EFA-E79777A29C9 | Source = DCOM | ID = 10010
Description = Der Server "{E60687F7-01A1-40AA-86AC-DB1CBF673334}" konnte innerhalb
des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error - 21.02.2012 03:36:36 | Computer Name = EFA-E79777A29C9 | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
Error - 21.02.2012 03:37:04 | Computer Name = EFA-E79777A29C9 | Source = DCOM | ID = 10010
Description = Der Server "{E60687F7-01A1-40AA-86AC-DB1CBF673334}" konnte innerhalb
des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error - 21.02.2012 03:37:06 | Computer Name = EFA-E79777A29C9 | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
Error - 21.02.2012 03:37:34 | Computer Name = EFA-E79777A29C9 | Source = DCOM | ID = 10010
Description = Der Server "{E60687F7-01A1-40AA-86AC-DB1CBF673334}" konnte innerhalb
des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error - 21.02.2012 03:37:50 | Computer Name = EFA-E79777A29C9 | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
< End of report > --- --- --- |