nattfoedd | 29.12.2009 10:31 | Danke erstmal für Deine Hilfe! OTL hat geklappt und hier die beiden Files:
OTL.txt: Code:
OTL logfile created on: 29.12.2009 10:13:05 - Run 1
OTL by OldTimer - Version 3.1.20.1 Folder = C:\Users\Clemens\Desktop
64bit-Windows Vista Business Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
6,00 Gb Total Physical Memory | 4,00 Gb Available Physical Memory | 70,00% Memory free
12,00 Gb Paging File | 10,00 Gb Available in Paging File | 85,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 78,12 Gb Total Space | 5,18 Gb Free Space | 6,63% Space Free | Partition Type: NTFS
Drive D: | 390,62 Gb Total Space | 266,28 Gb Free Space | 68,17% Space Free | Partition Type: NTFS
Drive E: | 462,76 Gb Total Space | 64,48 Gb Free Space | 13,93% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: CLEMENS-PC
Current User Name: Clemens
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Clemens\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - D:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Windows\SysWOW64\UAService7.exe (Sony DADC Austria AG.)
PRC - D:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - D:\Programme\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
PRC - D:\Programme\EXPERTool\TBPANEL.exe (Gainward Co.)
PRC - C:\Programme\ASUS Xonar DS Audio\Customapp\AsusAudioCenter.exe (CMedia)
PRC - C:\Programme\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_64server.exe ()
PRC - C:\Program Files (x86)\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe ()
PRC - D:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - D:\Programme\RivaTuner v2.24\RivaTuner.exe ()
PRC - C:\Program Files (x86)\GIGABYTE\ET6\GUI.exe ()
PRC - C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\Clemens\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (TabletServiceWacom) -- C:\Windows\SysNative\Wacom_Tablet.exe ()
SRV:64bit: - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.)
SRV:64bit: - (mi-raysat_3dsmax2010_64) -- C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_64server.exe ()
SRV:64bit: - (UmRdpService) -- C:\Windows\SysNative\umrdp.dll ()
SRV:64bit: - (CscService) -- C:\Windows\SysNative\cscsvc.dll ()
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll ()
SRV:64bit: - (Fax) -- C:\Windows\SysNative\fxssvc.exe ()
SRV:64bit: - (wbengine) -- C:\Windows\SysNative\wbengine.exe ()
SRV:64bit: - (msvsmon90) -- C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe (Microsoft Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (AntiVirService) -- D:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (UserAccess7) SecuROM User Access Service (V7) -- C:\Windows\SysWOW64\UAService7.exe (Sony DADC Austria AG.)
SRV - (AntiVirSchedulerService) -- D:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (mi-raysat_3dsmax2010_32) -- C:\Program Files (x86)\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe ()
SRV - (GEST Service) -- C:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe ()
SRV - (spmd) -- C:\spm\spmdib.exe (mental images GmbH)
SRV - (Microsoft Office Groove Audit Service) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (MSDTC) -- C:\Windows\SysWOW64\Msdtc [2006.11.02 14:34:14 | 00,000,000 | ---D | M]
SRV - (vds) -- C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) -- C:\Windows\SysWOW64\wbem\vss.mof ()
SRV - (IDriverT) -- C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (MDM) -- C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\DRIVERS\avgntflt.sys ()
DRV:64bit: - (wacmoumonitor) -- C:\Windows\SysNative\DRIVERS\wacmoumonitor.sys ()
DRV:64bit: - (atksgt) -- C:\Windows\SysNative\DRIVERS\atksgt.sys ()
DRV:64bit: - (lirsgt) -- C:\Windows\SysNative\DRIVERS\lirsgt.sys ()
DRV:64bit: - (sptd) -- C:\Windows\SysNative\Drivers\sptd.sys ()
DRV:64bit: - (wacomvhid) -- C:\Windows\SysNative\DRIVERS\wacomvhid.sys ()
DRV:64bit: - (cmudaxp) -- C:\Windows\SysNative\drivers\cmudaxp.sys ()
DRV:64bit: - (JRAID) -- C:\Windows\SysNative\DRIVERS\jraid.sys ()
DRV:64bit: - (RTL8169) -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys ()
DRV:64bit: - (Tpkd) -- C:\Windows\SysNative\drivers\Tpkd.sys ()
DRV:64bit: - (adfs) -- C:\Windows\SysNative\drivers\adfs.sys ()
DRV:64bit: - (CSC) -- C:\Windows\SysNative\drivers\csc.sys ()
DRV:64bit: - (wacommousefilter) -- C:\Windows\SysNative\DRIVERS\wacommousefilter.sys ()
DRV:64bit: - (X-Rite) -- C:\Windows\SysNative\DRIVERS\XrUsb64.sys ()
DRV:64bit: - (HdAudAddService) -- C:\Windows\SysNative\drivers\HdAudio.sys ()
DRV - (GVTDrv64) -- C:\Windows\GVTDrv64.sys ()
DRV - (gdrv) -- C:\Windows\gdrv.sys (Windows (R) Server 2003 DDK provider)
DRV - (truecrypt) -- C:\Windows\SysWOW64\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (RivaTuner64) -- D:\Programme\RivaTuner v2.24\RivaTuner64.sys ()
DRV - (CSC) -- C:\Windows\CSC [2009.04.16 21:25:30 | 00,000,000 | ---D | M]
DRV - (cmudaxp) -- C:\Windows\cmudaxp.ini ()
DRV - (monitor) -- C:\Program Files (x86)\Autodesk\Backburner\monitor.exe (Autodesk, Inc.)
DRV - (WinI2C-DDC) -- D:\Programme\iColorDisplay\ddcdrv.sys (Nicomsoft Ltd.)
DRV - (Cardex) -- C:\Windows\SysWOW64\drivers\TBPanelx64.sys (Windows (R) Server 2003 DDK provider)
DRV - (speedfan) -- C:\Windows\SysWOW64\speedfan.sys (Windows (R) Server 2003 DDK provider)
DRV - (Tcpip) -- C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (mpsdrv) -- C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\..\URLSearchHook: {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\SysWOW64\dvmurl.dll (DeviceVM Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (de)"
FF - prefs.js..browser.startup.homepage: "[...]xyzspiegel.de/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.2
FF - prefs.js..extensions.enabledItems: battlefieldheroespatcher@ea.com:4.0.27.0
FF - prefs.js..extensions.enabledItems: {c50ca3c4-5656-43c2-a061-13e717f73fc8}:3.0.8
FF - prefs.js..extensions.enabledItems: {df4e4df5-5cb7-46b0-9aef-6c784c3249f8}:1.0.4
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.9.27
FF - prefs.js..extensions.enabledItems: OberonGameHost@OberonGames.com:1.0.5.1344
FF - prefs.js..extensions.enabledItems: {B17C1C5A-04B1-11DB-9804-B622A1EF5492}:1.2
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Components: D:\Programme\FireFox3\components [2009.12.16 20:34:30 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Plugins: D:\Programme\FireFox3\plugins [2009.12.16 20:34:30 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components: D:\Programme\Thunderbird\components [2009.10.02 11:51:39 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins: D:\Programme\Thunderbird\plugins [2009.12.04 22:17:36 | 00,000,000 | ---D | M]
[2009.04.17 17:09:49 | 00,000,000 | ---D | M] -- C:\Users\Clemens\AppData\Roaming\mozilla\Extensions
[2009.12.28 23:17:01 | 00,000,000 | ---D | M] -- C:\Users\Clemens\AppData\Roaming\mozilla\Firefox\Profiles\zrt4vass.default\extensions
[2009.12.18 15:29:33 | 00,000,000 | ---D | M] (WebMail Notifier) -- C:\Users\Clemens\AppData\Roaming\mozilla\Firefox\Profiles\zrt4vass.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
[2009.12.28 23:16:59 | 00,000,000 | ---D | M] (NoScript) -- C:\Users\Clemens\AppData\Roaming\mozilla\Firefox\Profiles\zrt4vass.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009.08.13 19:26:39 | 00,000,000 | ---D | M] (Password Exporter) -- C:\Users\Clemens\AppData\Roaming\mozilla\Firefox\Profiles\zrt4vass.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
[2009.12.18 15:29:33 | 00,000,000 | ---D | M] (Fast Video Download (with SearchMenu)) -- C:\Users\Clemens\AppData\Roaming\mozilla\Firefox\Profiles\zrt4vass.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
[2009.12.18 15:29:33 | 00,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Clemens\AppData\Roaming\mozilla\Firefox\Profiles\zrt4vass.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009.10.11 22:19:16 | 00,000,000 | ---D | M] (Fox!Box [de]) -- C:\Users\Clemens\AppData\Roaming\mozilla\Firefox\Profiles\zrt4vass.default\extensions\{df4e4df5-5cb7-46b0-9aef-6c784c3249f8}
[2009.10.08 18:23:44 | 00,000,000 | ---D | M] -- C:\Users\Clemens\AppData\Roaming\mozilla\Firefox\Profiles\zrt4vass.default\extensions\battlefieldheroespatcher@ea.com
[2009.04.17 20:33:19 | 00,000,000 | ---D | M] -- C:\Users\Clemens\AppData\Roaming\mozilla\Firefox\Profiles\zrt4vass.default\extensions\moveplayer@movenetworks.com
[2009.07.14 19:41:24 | 00,000,000 | ---D | M] -- C:\Users\Clemens\AppData\Roaming\mozilla\Firefox\Profiles\zrt4vass.default\extensions\OberonGameHost@OberonGames.com
O1 HOSTS File: (794 bytes) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O4:64bit: - HKLM..\Run: [Cmaudio8788] C:\Windows\Syswow64\cmicnfgp.DLL (C-Media Corporation)
O4:64bit: - HKLM..\Run: [RivaTuner] D:\Programme\RivaTuner v2.24\RivaTunerWrapper.exe ()
O4:64bit: - HKLM..\Run: [RivaTunerStartupDaemon] D:\Programme\RivaTuner v2.24\RivaTunerWrapper.exe ()
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] D:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [EasyTuneVI] C:\Program Files (x86)\GIGABYTE\ET6\ETcall.exe ()
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [QuickTime Task] D:\Programme\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [DAEMON Tools Lite] D:\Programme\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [EPSON Stylus D120 Series] C:\Windows\SysWow64\spool\DRIVERS\x64\3\E_IATICCE.EXE File not found
O4 - HKCU..\Run: [GAINWARD] D:\Programme\EXPERTool\TBPanel.exe (Gainward Co.)
O4 - HKCU..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\SideBar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} [...]java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [...]java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [...]java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} [...]icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab (Oberon Flash Game Host)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.05.15 06:46:37 | 00,000,019 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - comfile [open] -- "%1" %* File not found 64bit: O35 - exefile [open] -- "%1" %* File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2009.12.29 10:12:05 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Users\Clemens\Desktop\OTL.exe
[2009.12.28 13:46:58 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\trend micro
[2009.12.28 13:46:57 | 00,000,000 | ---D | C] -- C:\rsit
[2009.12.28 13:30:29 | 00,000,000 | ---D | C] -- C:\Lop SD
[2009.12.28 11:29:25 | 00,000,000 | ---D | C] -- C:\Users\Clemens\AppData\Roaming\Malwarebytes
[2009.12.28 11:29:22 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2009.12.28 11:29:21 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009.12.28 11:24:43 | 00,000,000 | ---D | C] -- C:\32788R22FWJFW
[2009.12.27 22:00:56 | 00,000,000 | -HSD | C] -- C:\Users\Clemens\AppData\Roaming\SystemProc
[2009.12.21 12:05:58 | 00,216,064 | RHS- | C] (MONOGRAM Multimedia, s.r.o.) -- C:\Windows\SysWow64\nbDX.dll
[2009.12.21 12:05:58 | 00,169,472 | RHS- | C] (Gabest) -- C:\Windows\SysWow64\MatroskaDX.ax
[2009.12.21 12:05:58 | 00,163,328 | RHS- | C] (Gabest) -- C:\Windows\SysWow64\flvDX.dll
[2009.12.21 12:05:58 | 00,161,792 | RHS- | C] (Gabest) -- C:\Windows\SysWow64\RealMediaDX.ax
[2009.12.21 12:05:58 | 00,123,904 | RHS- | C] (CoreCodec) -- C:\Windows\SysWow64\AVCDX.ax
[2009.12.21 12:05:58 | 00,090,112 | RHS- | C] (-) -- C:\Windows\SysWow64\TTADSSplitter.ax
[2009.12.21 12:05:58 | 00,090,112 | RHS- | C] (-) -- C:\Windows\SysWow64\TTADSDecoder.ax
[2009.12.21 12:05:58 | 00,031,232 | RHS- | C] (Hans Mayerl) -- C:\Windows\SysWow64\msfDX.dll
[2009.12.14 17:58:04 | 01,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_42.dll
[2009.12.10 00:13:31 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshhttp.dll
[2009.12.10 00:13:30 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\httpapi.dll
[2009.12.09 08:34:40 | 00,833,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wininet.dll
[2009.12.09 08:34:40 | 00,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2009.12.09 08:34:39 | 00,671,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstime.dll
[2009.12.09 08:34:39 | 00,458,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
[2009.12.09 08:34:39 | 00,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2009.12.09 08:34:39 | 00,389,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iedkcs32.dll
[2009.12.09 08:34:39 | 00,380,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2009.12.09 08:34:39 | 00,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
[2009.12.09 08:34:39 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2009.12.09 08:34:38 | 00,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieencode.dll
[2009.12.09 08:34:38 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsproxy.dll
[2009.12.09 08:29:25 | 00,281,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\raschap.dll
[2009.12.09 08:29:25 | 00,244,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rastls.dll
[2009.12.05 00:03:56 | 00,000,000 | ---D | C] -- C:\Users\Clemens\AppData\Local\Apple Computer
[2009.12.04 23:02:11 | 00,839,680 | ---- | C] ([...]xyzmp3dev.org/) -- C:\Windows\SysWow64\lameACM.acm
[2009.12.04 23:02:11 | 00,118,784 | ---- | C] (fccHandler) -- C:\Windows\SysWow64\ac3acm.acm
[2009.12.04 23:02:10 | 00,070,656 | ---- | C] (xyzhelixcommunity.org) -- C:\Windows\SysWow64\yv12vfw.dll
[2009.12.04 22:54:04 | 00,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2009.12.04 22:53:58 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2009.12.04 22:53:17 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2009.12.04 22:53:17 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\AGEIA
[2009.12.04 22:53:07 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2009.12.04 22:53:02 | 00,000,000 | ---D | C] -- C:\Programme\NVIDIA Corporation
[2009.12.04 22:52:09 | 04,241,000 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2009.12.04 22:52:09 | 00,076,392 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2009.12.04 22:52:07 | 14,064,232 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2009.12.04 22:52:06 | 09,333,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll
[2009.12.04 22:52:06 | 02,243,176 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2009.12.04 22:52:05 | 04,001,384 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2009.12.04 22:52:05 | 01,989,224 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2009.12.04 22:52:04 | 11,381,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2009.12.04 22:52:03 | 01,249,896 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
[2009.12.04 22:52:01 | 00,000,000 | ---D | C] -- C:\NVIDIA
[10 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Users\Clemens\AppData\Local\*.tmp files -> C:\Users\Clemens\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2009.12.29 10:13:44 | 04,980,736 | -HS- | M] () -- C:\Users\Clemens\ntuser.dat
[2009.12.29 10:12:08 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Users\Clemens\Desktop\OTL.exe
[2009.12.29 10:08:26 | 00,069,263 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2009.12.29 10:08:25 | 00,069,263 | ---- | M] () -- C:\ProgramData\nvModes.001
[2009.12.29 10:08:25 | 00,030,528 | ---- | M] () -- C:\Windows\GVTDrv64.sys
[2009.12.29 10:08:25 | 00,000,004 | ---- | M] () -- C:\Windows\SysWow64\GVTunner.ref
[2009.12.29 10:08:20 | 00,024,072 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\Windows\gdrv.sys
[2009.12.29 10:08:01 | 00,003,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009.12.29 10:08:01 | 00,003,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009.12.29 10:08:01 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009.12.29 10:07:58 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009.12.28 23:44:17 | 00,524,288 | -HS- | M] () -- C:\Users\Clemens\ntuser.dat{5e155425-4d00-11de-b41e-00241d160ede}.TMContainer00000000000000000001.regtrans-ms
[2009.12.28 23:44:17 | 00,065,536 | -HS- | M] () -- C:\Users\Clemens\ntuser.dat{5e155425-4d00-11de-b41e-00241d160ede}.TM.blf
[2009.12.28 23:43:51 | 04,720,474 | -H-- | M] () -- C:\Users\Clemens\AppData\Local\IconCache.db
[2009.12.28 22:15:11 | 00,000,434 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{64BB3058-FB6B-44DD-8337-5FB88C292CF6}.job
[2009.12.28 13:38:21 | 00,002,453 | ---- | M] () -- C:\Users\Clemens\Desktop\HiJackThis.lnk
[2009.12.28 13:32:27 | 01,566,478 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2009.12.28 13:32:27 | 00,675,162 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2009.12.28 13:32:27 | 00,633,688 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2009.12.28 13:32:27 | 00,146,282 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2009.12.28 13:32:27 | 00,118,694 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2009.12.28 13:32:24 | 00,077,312 | ---- | M] () -- C:\mbr.exe
[2009.12.28 13:30:12 | 00,501,736 | ---- | M] () -- C:\Users\Clemens\Desktop\LopSD.exe
[2009.12.28 11:29:25 | 00,000,609 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009.12.28 11:18:50 | 00,000,685 | ---- | M] () -- C:\Users\Clemens\Desktop\CCleaner.lnk
[2009.12.28 10:19:05 | 03,867,535 | ---- | M] () -- C:\Users\Clemens\Desktop\CoFi.exe
[2009.12.27 15:20:58 | 00,202,752 | ---- | M] () -- C:\Users\Clemens\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.12.26 19:49:17 | 00,000,540 | ---- | M] () -- C:\Users\Clemens\LWHUB8.CFG
[2009.12.26 19:48:07 | 00,031,171 | ---- | M] () -- C:\Users\Clemens\LWM8.cfg
[2009.12.23 14:06:18 | 00,370,070 | ---- | M] () -- C:\Windows\hd_ico.ico
[2009.12.23 14:06:04 | 00,138,978 | ---- | M] () -- C:\Windows\hd_ico.ico.part
[2009.12.23 14:04:51 | 00,047,774 | ---- | M] () -- C:\Windows\hd_ico.png
[2009.12.23 10:37:15 | 00,001,219 | ---- | M] () -- C:\Users\Clemens\Desktop\Filme.lnk
[2009.12.23 09:35:00 | 03,320,000 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2009.12.23 09:34:17 | 00,162,072 | ---- | M] () -- C:\Users\Clemens\AppData\Local\GDIPFONTCACHEV1.DAT
[2009.12.23 03:02:09 | 00,000,219 | ---- | M] () -- C:\Windows\win.ini
[2009.12.19 22:20:06 | 00,000,491 | ---- | M] () -- C:\Users\Clemens\BandSaw.cfg
[2009.12.18 20:01:54 | 00,256,403 | ---- | M] () -- C:\Users\Clemens\Desktop\wheezle1.jpg
[2009.12.17 22:53:58 | 00,017,496 | ---- | M] () -- C:\Users\Clemens\LW8.cfg
[2009.12.14 18:23:26 | 00,118,452 | ---- | M] () -- C:\Users\Clemens\LWEXT8.cfg
[2009.12.14 17:58:20 | 01,892,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_42.dll
[2009.12.07 18:23:08 | 00,074,880 | ---- | M] () -- C:\Windows\SysNative\drivers\avgntflt.sys
[2009.12.04 22:51:01 | 00,000,732 | ---- | M] () -- C:\Users\Clemens\AppData\Local\d3d9caps64.dat
[2009.12.03 20:29:02 | 00,003,582 | ---- | M] () -- C:\Users\Clemens\AppData\Roaming\iColorDisplay3.prefs
[2009.12.03 20:19:37 | 00,000,488 | ---- | M] () -- C:\Users\Clemens\AppData\Roaming\iColorDisplay3.lic
[2009.12.03 19:25:24 | 00,000,682 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuatoCalibrationLoader.lnk
[2009.12.03 16:14:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2009.12.03 16:13:58 | 00,022,104 | ---- | M] () -- C:\Windows\SysNative\drivers\mbam.sys
[10 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Users\Clemens\AppData\Local\*.tmp files -> C:\Users\Clemens\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2009.12.29 10:08:25 | 00,000,004 | ---- | C] () -- C:\Windows\SysWow64\GVTunner.ref
[2009.12.28 13:38:01 | 00,002,453 | ---- | C] () -- C:\Users\Clemens\Desktop\HiJackThis.lnk
[2009.12.28 13:32:24 | 00,077,312 | ---- | C] () -- C:\mbr.exe
[2009.12.28 13:30:11 | 00,501,736 | ---- | C] () -- C:\Users\Clemens\Desktop\LopSD.exe
[2009.12.28 11:29:25 | 00,000,609 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009.12.28 11:29:21 | 00,022,104 | ---- | C] () -- C:\Windows\SysNative\drivers\mbam.sys
[2009.12.28 11:18:50 | 00,000,685 | ---- | C] () -- C:\Users\Clemens\Desktop\CCleaner.lnk
[2009.12.28 10:18:46 | 03,867,535 | ---- | C] () -- C:\Users\Clemens\Desktop\CoFi.exe
[2009.12.23 14:06:16 | 00,370,070 | ---- | C] () -- C:\Windows\hd_ico.ico
[2009.12.23 14:05:52 | 00,138,978 | ---- | C] () -- C:\Windows\hd_ico.ico.part
[2009.12.23 14:04:50 | 00,047,774 | ---- | C] () -- C:\Windows\hd_ico.png
[2009.12.23 10:36:54 | 00,001,219 | ---- | C] () -- C:\Users\Clemens\Desktop\Filme.lnk
[2009.12.21 12:05:58 | 00,120,832 | RHS- | C] () -- C:\Windows\SysWow64\MPCDx.ax
[2009.12.21 12:05:58 | 00,107,520 | RHS- | C] () -- C:\Windows\SysWow64\RLMPCDec.ax
[2009.12.21 12:05:58 | 00,097,280 | RHS- | C] () -- C:\Windows\SysWow64\FLACDX.ax
[2009.12.21 12:05:58 | 00,070,656 | RHS- | C] () -- C:\Windows\SysWow64\RLAPEDec.ax
[2009.12.21 12:05:57 | 00,227,328 | RHS- | C] () -- C:\Windows\SysWow64\ac3DX.ax
[2009.12.18 20:01:47 | 00,256,403 | ---- | C] () -- C:\Users\Clemens\Desktop\wheezle1.jpg
[2009.12.15 18:09:50 | 00,024,521 | ---- | C] () -- C:\Users\Clemens\Documents\Sample EN.gtd - backup 2.gt~
[2009.12.15 18:09:48 | 00,024,679 | ---- | C] () -- C:\Users\Clemens\Documents\Sample CZ.gtd
[2009.12.15 18:09:48 | 00,024,521 | ---- | C] () -- C:\Users\Clemens\Documents\Sample EN.gtd
[2009.12.10 00:13:31 | 00,032,768 | ---- | C] () -- C:\Windows\SysNative\nshhttp.dll
[2009.12.10 00:13:30 | 00,610,304 | ---- | C] () -- C:\Windows\SysNative\drivers\http.sys
[2009.12.10 00:13:30 | 00,033,792 | ---- | C] () -- C:\Windows\SysNative\httpapi.dll
[2009.12.09 08:34:42 | 05,686,272 | ---- | C] () -- C:\Windows\SysNative\mshtml.dll
[2009.12.09 08:34:40 | 07,005,696 | ---- | C] () -- C:\Windows\SysNative\ieframe.dll
[2009.12.09 08:34:40 | 01,426,432 | ---- | C] () -- C:\Windows\SysNative\urlmon.dll
[2009.12.09 08:34:40 | 01,032,704 | ---- | C] () -- C:\Windows\SysNative\wininet.dll
[2009.12.09 08:34:40 | 00,208,896 | ---- | C] () -- C:\Windows\SysNative\occache.dll
[2009.12.09 08:34:39 | 01,129,984 | ---- | C] () -- C:\Windows\SysNative\mstime.dll
[2009.12.09 08:34:39 | 00,580,608 | ---- | C] () -- C:\Windows\SysNative\msfeeds.dll
[2009.12.09 08:34:39 | 00,485,376 | ---- | C] () -- C:\Windows\SysNative\html.iec
[2009.12.09 08:34:39 | 00,480,256 | ---- | C] () -- C:\Windows\SysNative\iedkcs32.dll
[2009.12.09 08:34:39 | 00,422,400 | ---- | C] () -- C:\Windows\SysNative\ieapfltr.dll
[2009.12.09 08:34:39 | 00,375,296 | ---- | C] () -- C:\Windows\SysNative\iertutil.dll
[2009.12.09 08:34:39 | 00,267,776 | ---- | C] () -- C:\Windows\SysNative\ieaksie.dll
[2009.12.09 08:34:39 | 00,086,528 | ---- | C] () -- C:\Windows\SysNative\ieencode.dll
[2009.12.09 08:34:39 | 00,032,768 | ---- | C] () -- C:\Windows\SysNative\ieUnatt.exe
[2009.12.09 08:34:38 | 01,383,424 | ---- | C] () -- C:\Windows\SysNative\mshtml.tlb
[2009.12.09 08:34:38 | 00,032,256 | ---- | C] () -- C:\Windows\SysNative\jsproxy.dll
[2009.12.09 08:29:25 | 00,295,936 | ---- | C] () -- C:\Windows\SysNative\raschap.dll
[2009.12.09 08:29:25 | 00,280,576 | ---- | C] () -- C:\Windows\SysNative\rastls.dll
[2009.12.04 23:02:11 | 00,000,414 | ---- | C] () -- C:\Windows\SysWow64\lame_acm.xml
[2009.12.04 23:02:11 | 00,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2009.12.04 23:02:10 | 00,881,664 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2009.12.04 23:02:10 | 00,205,824 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2009.12.04 23:02:09 | 00,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2009.12.04 23:02:09 | 00,000,547 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll.manifest
[2009.12.04 22:56:53 | 00,069,263 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009.12.04 22:56:24 | 00,069,263 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009.12.04 22:52:09 | 13,694,056 | ---- | C] () -- C:\Windows\SysNative\drivers\nvlddmkm.sys
[2009.12.04 22:52:09 | 05,915,752 | ---- | C] () -- C:\Windows\SysNative\nvwgf2umx.dll
[2009.12.04 22:52:09 | 00,076,904 | ---- | C] () -- C:\Windows\SysNative\OpenCL.dll
[2009.12.04 22:52:09 | 00,011,240 | ---- | C] () -- C:\Windows\SysNative\drivers\nvBridge.kmd
[2009.12.04 22:52:09 | 00,008,862 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2009.12.04 22:52:07 | 19,223,144 | ---- | C] () -- C:\Windows\SysNative\nvoglv64.dll
[2009.12.04 22:52:06 | 11,775,080 | ---- | C] () -- C:\Windows\SysNative\nvd3dumx.dll
[2009.12.04 22:52:05 | 05,347,944 | ---- | C] () -- C:\Windows\SysNative\nvcuda.dll
[2009.12.04 22:52:05 | 02,332,264 | ---- | C] () -- C:\Windows\SysNative\nvcuvid.dll
[2009.12.04 22:52:05 | 02,028,136 | ---- | C] () -- C:\Windows\SysNative\nvcuvenc.dll
[2009.12.04 22:52:03 | 15,874,664 | ---- | C] () -- C:\Windows\SysNative\nvcompiler.dll
[2009.12.04 22:52:03 | 01,541,736 | ---- | C] () -- C:\Windows\SysNative\nvapi64.dll
[2009.12.04 22:52:03 | 00,202,344 | ---- | C] () -- C:\Windows\SysNative\nvcod178.dll
[2009.12.04 22:52:03 | 00,202,344 | ---- | C] () -- C:\Windows\SysNative\nvcod.dll
[2009.12.03 19:31:29 | 00,000,488 | ---- | C] () -- C:\Users\Clemens\AppData\Roaming\iColorDisplay3.lic
[2009.12.03 19:28:18 | 00,003,582 | ---- | C] () -- C:\Users\Clemens\AppData\Roaming\iColorDisplay3.prefs
[2009.12.03 19:28:18 | 00,000,033 | ---- | C] () -- C:\Users\Clemens\AppData\Roaming\iCDPresets.txt
[2009.12.03 19:27:58 | 00,033,600 | ---- | C] () -- C:\Windows\SysNative\drivers\XrUsb64.sys
[2009.12.03 19:25:24 | 00,000,682 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuatoCalibrationLoader.lnk
[2009.11.26 19:36:49 | 00,237,568 | ---- | C] () -- C:\Windows\SysWow64\glut32.dll
[2009.11.17 18:23:10 | 00,000,053 | R--- | C] () -- C:\Windows\SysWow64\cmasiop.ini
[2009.11.17 18:23:03 | 00,139,264 | R--- | C] () -- C:\Windows\SysWow64\VmixP8.dll
[2009.11.17 18:22:49 | 00,041,410 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.cfl
[2009.11.17 18:22:29 | 00,000,862 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.imi
[2009.11.17 18:22:27 | 00,004,967 | R--- | C] () -- C:\Windows\Cmicnfgp.ini.cfg
[2009.10.27 23:22:13 | 00,027,648 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2009.10.17 17:52:28 | 00,000,315 | ---- | C] () -- C:\Windows\doom3.ini
[2009.10.09 14:47:32 | 00,178,176 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2009.10.09 12:57:17 | 00,146,432 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2009.10.09 12:57:17 | 00,072,704 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2009.10.06 15:36:08 | 00,185,418 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_SqlPubWiz.msi2416.txt
[2009.10.06 15:36:05 | 00,283,618 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_WinSDK_RefInt_x64_MSI2410.txt
[2009.10.06 15:36:00 | 00,735,094 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_WinSDK_NetFxTools_x64_MSI23FF.txt
[2009.10.06 15:35:54 | 00,440,252 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_WinSDK_Win32Tools_x64_MSI23EC.txt
[2009.10.06 15:35:38 | 05,358,576 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_WinSDK_Build_x64_MSI23B8.txt
[2009.10.06 15:35:34 | 00,653,468 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_WinSDK_Tools_x64_MSI23AA.txt
[2009.10.06 15:35:31 | 00,252,652 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_CrystalReports2007LangPack_x64_MSI23A1.txt
[2009.10.06 15:35:10 | 00,551,574 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_CrystalReports2007LangPack_MSI235C.txt
[2009.10.06 15:34:47 | 02,486,258 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_CrystalReports2007_x64_MSI2311.txt
[2009.10.06 15:33:52 | 04,636,286 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_CrystalReports2007_MSI225D.txt
[2009.10.06 15:33:48 | 01,258,434 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_RDBG_AMD64_MSI2250.txt
[2009.10.06 15:33:28 | 01,448,396 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009.10.06 15:31:45 | 00,291,922 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_64bitEmulator_MSI20BF.txt
[2009.10.06 15:31:30 | 05,146,448 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_WMSP_5_0_MSI208E.txt
[2009.10.06 15:31:15 | 07,062,270 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_WMPPC_5_0_MSI205D.txt
[2009.10.06 15:31:11 | 00,736,770 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_SSCEDeviceRuntime_MSI2050.txt
[2009.10.06 15:31:08 | 00,332,994 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_SQLCEToolsForVS2007_MSI2046.txt
[2009.10.06 15:31:05 | 00,377,600 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_SSCERuntime_MSI203C.txt
[2009.10.06 15:31:03 | 00,297,174 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_VSTOR_LP_MSI2035.txt
[2009.10.06 15:30:58 | 00,944,454 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_VSTOR20_LP_MSI2025.txt
[2009.10.06 15:30:45 | 00,843,820 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_VSTOR_MSI1FFB.txt
[2009.10.06 15:30:36 | 01,047,898 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_NETCFSetupv35_MSI1FDA.txt
[2009.10.06 15:30:27 | 01,014,268 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_NETCFSetupv2_MSI1FC0.txt
[2009.10.06 15:24:56 | 52,955,438 | ---- | C] () -- C:\Users\Clemens\AppData\Local\VSMsiLog1B87.txt
[2009.10.06 15:23:56 | 00,343,146 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_DexplorerLP90_retMSI1AC3.txt
[2009.10.06 15:23:17 | 02,863,912 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_Dexplorer90_retMSI1A44.txt
[2009.10.06 15:23:15 | 00,368,326 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_PreReq_AMD64_MSI1A3D.txt
[2009.10.06 15:23:05 | 00,609,960 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_NET_Framework35_LangPack_MSI1A1D.txt
[2009.10.06 15:23:00 | 00,034,086 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_depcheck_NETFX_EXP_35.txt
[2009.10.06 15:22:59 | 00,075,526 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_dotnetfx35install_lp.txt
[2009.10.06 15:22:59 | 00,000,002 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_dotnetfx35error_lp.txt
[2009.10.06 15:22:50 | 00,839,124 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_VC_MinRed_MSI19EC.txt
[2009.10.06 15:21:50 | 00,227,189 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_depcheck_VS_PRO_90.txt
[2009.10.06 15:21:46 | 00,663,570 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_install_vs_procore_90.txt
[2009.10.06 15:21:46 | 00,031,784 | ---- | C] () -- C:\Users\Clemens\AppData\Local\uxeventlog.txt
[2009.10.06 15:21:46 | 00,000,002 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_error_vs_procore_90.txt
[2009.09.30 20:09:34 | 00,415,900 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_vcredistMSI2094.txt
[2009.09.30 20:09:34 | 00,011,406 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_vcredistUI2094.txt
[2009.09.07 16:14:13 | 00,004,096 | -H-- | C] () -- C:\Users\Clemens\AppData\Local\keyfile3.drm
[2009.08.31 13:27:13 | 00,000,084 | ---- | C] () -- C:\Windows\winamp.ini
[2009.08.03 00:21:54 | 00,197,912 | ---- | C] () -- C:\Windows\SysWow64\physxcudart_20.dll
[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll
[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll
[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll
[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll
[2009.08.03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll
[2009.08.03 00:21:52 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll
[2009.08.03 00:21:52 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll
[2009.05.15 21:46:18 | 00,118,188 | ---- | C] () -- C:\ProgramData\LWEXT8.cfg
[2009.05.15 21:46:18 | 00,025,760 | ---- | C] () -- C:\ProgramData\LWM8.cfg
[2009.05.15 21:46:18 | 00,017,486 | ---- | C] () -- C:\ProgramData\LW8.cfg
[2009.05.15 19:54:09 | 00,000,688 | ---- | C] () -- C:\Windows\ODBC.INI
[2009.04.17 23:40:48 | 00,202,752 | ---- | C] () -- C:\Users\Clemens\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.04.17 21:37:59 | 00,003,972 | ---- | C] () -- C:\Windows\SysWow64\drivers\PciBus.sys
[2009.04.17 21:01:33 | 00,030,528 | ---- | C] () -- C:\Windows\GVTDrv64.sys
[2009.04.17 17:53:33 | 00,000,880 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009.04.17 17:11:51 | 00,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2009.04.17 16:47:59 | 00,419,366 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_vcredistMSI5C34.txt
[2009.04.17 16:47:58 | 00,011,390 | ---- | C] () -- C:\Users\Clemens\AppData\Local\dd_vcredistUI5C34.txt
[2009.04.16 21:32:33 | 00,000,732 | ---- | C] () -- C:\Users\Clemens\AppData\Local\d3d9caps64.dat
[2009.03.12 07:30:20 | 00,000,516 | R--- | C] () -- C:\Windows\cmudaxp.ini
[2009.02.12 08:11:45 | 00,007,718 | ---- | C] () -- C:\Windows\cadx2.ini
[2008.01.21 03:48:25 | 00,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2008.01.21 03:48:07 | 00,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2007.01.10 08:44:26 | 01,457,024 | R--- | C] () -- C:\Windows\SysWow64\SSCProt.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 507 bytes -> C:\ProgramData\TEMP:05EE1EEF
< End of report >
:eek::eek::eek:
Leider sieht die Sache wohl doch nicht so gut aus, wie ich in der Zwischenzeit dachte - gerade im Moment beim Erstellen des Beitrags sprang mein AntiVir plötzlich an und meldete mir eine der Dateien. Die sollte eigtl schon entfernt gewesen sein - bedeutet das, ich habe mich reinfiziert oder haben sowohl AntiVir, als auch Anti-Malware die Datei bei den späteren Suchdurchläufen gestern nicht finden können? http://bildupload.sro.at/a/thumbs/antivir_fund.jpg |