Berlin1892 | 09.06.2010 14:01 | Vielen Dank für deine Hilfe.
Hier Extras.Txt sowie OTL.Txt
Extras.Txt
OTL EXTRAS Logfile:
OTL Logfile: Code:
OTL Extras logfile created on: 09.06.2010 14:42:54 - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Dokumente und Einstellungen\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 79,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 92,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 39,76 Gb Total Space | 12,11 Gb Free Space | 30,45% Space Free | Partition Type: NTFS
Drive D: | 6,81 Gb Total Space | 0,99 Gb Free Space | 14,48% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
Drive F: | 251,51 Gb Total Space | 114,14 Gb Free Space | 45,38% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NAME-F307E50405
Current User Name: HP_Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- Reg Error: Key error.
https [open] -- "C:\Programme\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Programme\concept design\onlineTV 3\onlineTV.exe" = C:\Programme\concept design\onlineTV 3\onlineTV.exe:*:Enabled:onlineTV -- File not found
"C:\Programme\Windows Live\Messenger\wlcsdk.exe" = C:\Programme\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Programme\Mozilla Firefox\firefox.exe" = C:\Programme\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Programme\SopCast\SopCast.exe" = C:\Programme\SopCast\SopCast.exe:*:Enabled:SopCast Main Application -- (w*w.sopcast.com)
"C:\Programme\SopCast\adv\SopAdver.exe" = C:\Programme\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver -- (w*w.sopcast.com)
"C:\Programme\Windows Live\Messenger\wlcsdk.exe" = C:\Programme\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Programme\TVUPlayer\TVUPlayer.exe" = C:\Programme\TVUPlayer\TVUPlayer.exe:*:Enabled:TVUPlayer Component -- (TVU networks)
"C:\Dokumente und Einstellungen\HP_Administrator\Lokale Einstellungen\temp\Temporäres Verzeichnis 1 für u992.zip\u992.exe" = C:\Dokumente und Einstellungen\HP_Administrator\Lokale Einstellungen\temp\Temporäres Verzeichnis 1 für u992.zip\u992.exe:*:Enabled:u992 -- ()
"C:\Programme\uTorrent\uTorrent.exe" = C:\Programme\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Programme\Java\jre6\bin\javaw.exe" = C:\Programme\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Disabled:Windows Explorer -- (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}" = HiJackThis
"{1341D838-719C-4A05-B50F-49420CA1B4BB}" = HP Boot Optimizer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{21AE04E8-EBF6-40DB-9AA9-B7A80C5D057D}" = mkv2vob
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger
"{43602F34-1AA3-44FB-AEB2-D08C2C73743F}" = Paint.NET v3.36
"{45375017-B0F8-44EA-9D5B-2DCE7C84FFC2}" = SA21xx Device Manager
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 2.1
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{53480330-E1D1-41CA-B8F8-7F78644F7F50}" = O&O Defrag Professional Edition
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74EC78BC-B379-4E29-9006-8F161DCAABA6}" = Apple Software Update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C5747-0C40-4930-9AFE-113BCE553101}" = Adobe Stock Photos 1.0
"{7EC19307-7C22-47A8-922B-3FA965291260}" = OpenOffice.org 3.0
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{92DF2F1B-F63C-4D9A-B3E1-B2D11AE29790}" = Windows Presentation Foundation Language Pack (DEU)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}" = QuickTime
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9F7AF7CD-E3D0-4C68-A3BA-C76C359B3AA8}" = LightScribe 1.4.105.1
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.2 - Deutsch
"{B26E3B0D-C2FA-4370-B068-7C476766F029}" = Microsoft Works
"{B3750C5C-6EC7-47A7-B4C7-D2462CCAC02E}" = SPEED-LINK DUAL SHOCK ADAPTER
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BB9AC6BF-71B6-42A4-9689-C17D9F44E79A}" = Brother MFL-Pro Suite
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Die*Sims™*3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU
"{C2D05EDA-8F40-4B00-9C4C-51D89FD873C4}" = SL-6507 2in1 Controller Converter
"{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU
"{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack
"{EBB794ED-D282-4334-92FB-254481EFF514}" = Pro Evolution Soccer 6
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2A7F421-1679-48D5-B918-96999014ED53}" = Microsoft .NET Framework 3.0 German Language Pack
"{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Earth
"{F80239D8-7811-4D5E-B033-0D0BBFE32920}" = HP DigitalMedia Archive
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"7A1E1C4F-CC6F-4BF0-BB81-7CFC3F655564" = GemMaster Mystic
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"Camden Market 3" = Camden Market 3
"CCleaner" = CCleaner
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"foobar2000" = foobar2000 v0.9.6.9
"FUSSBALL MANAGER 08" = FUSSBALL MANAGER 08
"GEN_LYRICS_IE.DLL" = Winamp Lyrics (Explorer Version) v1.22
"getPlus(R)_dll" = getPlus(R)_dll
"Google Chrome" = Google Chrome
"HaaliMkx" = Haali Media Splitter
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{EBB794ED-D282-4334-92FB-254481EFF514}" = Pro Evolution Soccer 6
"JDownloader" = JDownloader
"LibUSB-Win32_is1" = LibUSB-Win32-0.1.10.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.0 German Language Pack" = Microsoft .NET Framework 3.0 German Language Pack
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"Mp3tag" = Mp3tag v2.43
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OpenAL" = OpenAL
"RocketDock_is1" = RocketDock 1.3.5
"SopCast" = SopCast 3.2.4
"ST6UNST #1" = Cover Druckstudio
"SUPER ©" = SUPER © Version 2010.bld.38 (May 2, 2010)
"SystemRequirementsLab" = System Requirements Lab
"TVUPlayer" = TVUPlayer 2.4.9.1
"uTorrent" = µTorrent
"Veetle TV" = Veetle TV 0.9.16
"VLC media player" = VLC media player 0.9.9
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR Archivierer
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xbox_360_CC_Driver" = Xbox 360 Controller for Windows
"XP Codec Pack" = XP Codec Pack
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"Zahlenbuch 1" = Zahlenbuch 1
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 12.05.2010 09:15:37 | Computer Name = NAME-F307E50405 | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung pes6.exe, Version 1.0.0.1, fehlgeschlagenes
Modul pes6.exe, Version 1.0.0.1, Fehleradresse 0x0070c48a.
Error - 12.05.2010 13:30:17 | Computer Name = NAME-F307E50405 | Source = ESENT | ID = 490
Description = svchost (1212) Versuch, Datei "C:\WINDOWS\system32\CatRoot2\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\catdb"
für den Lese-/Schreibzugriff zu öffnen, ist mit Systemfehler 32 (0x00000020): "Der
Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet
wird. " fehlgeschlagen. Fehler -1032 (0xfffffbf8) beim Öffnen von Dateien.
Error - 13.05.2010 10:38:59 | Computer Name = NAME-F307E50405 | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung pes6.exe, Version 1.0.0.1, fehlgeschlagenes
Modul stadium.dll, Version 6.6.4.0, Fehleradresse 0x000025fe.
Error - 16.05.2010 17:55:27 | Computer Name = NAME-F307E50405 | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung pes6.exe, Version 1.0.0.1, fehlgeschlagenes
Modul pes6.exe, Version 1.0.0.1, Fehleradresse 0x0025b12d.
Error - 18.05.2010 14:13:13 | Computer Name = NAME-F307E50405 | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung pes6.exe, Version 1.0.0.1, fehlgeschlagenes
Modul pes6.exe, Version 1.0.0.1, Fehleradresse 0x0025b12d.
Error - 21.05.2010 14:03:35 | Computer Name = NAME-F307E50405 | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung pes6.exe, Version 1.0.0.1, fehlgeschlagenes
Modul pes6.exe, Version 1.0.0.1, Fehleradresse 0x0070c48a.
Error - 22.05.2010 08:45:10 | Computer Name = NAME-F307E50405 | Source = Avira AntiVir | ID = 4118
Description = AUSNAHMEFEHLER beim Aufruf der Funktion <Scan> für die Datei C:\Dokumente
und Einstellungen\HP_Administrator\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\Cache\0E2FFFF8d01.
[ACCESS_VIOLATION Exception!! EIP = 0x1abc29c] Bitte Avira informieren und die
obige Datei übersenden!
Error - 28.05.2010 15:49:37 | Computer Name = NAME-F307E50405 | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung pes6.exe, Version 1.0.0.1, fehlgeschlagenes
Modul pes6.exe, Version 1.0.0.1, Fehleradresse 0x00483e2e.
Error - 30.05.2010 15:23:15 | Computer Name = NAME-F307E50405 | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung pes6.exe, Version 1.0.0.1, fehlgeschlagenes
Modul pes6.exe, Version 1.0.0.1, Fehleradresse 0x00483e2e.
Error - 30.05.2010 15:37:46 | Computer Name = NAME-F307E50405 | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung pes6.exe, Version 1.0.0.1, fehlgeschlagenes
Modul kserv.dll, Version 6.6.4.0, Fehleradresse 0x000538e3.
[ System Events ]
Error - 08.06.2010 01:11:12 | Computer Name = NAME-F307E50405 | Source = nv | ID = 11141134
Description = Unknown error on CMDre 00000000 00000640 00000102 00000004 00000084
Error - 08.06.2010 07:36:06 | Computer Name = NAME-F307E50405 | Source = nv | ID = 11141134
Description = Unknown error on CMDre 00000000 00000640 00000102 00000004 00000084
Error - 08.06.2010 11:43:36 | Computer Name = NAME-F307E50405 | Source = nv | ID = 11141134
Description = Unknown error on CMDre 00000000 00000640 00000101 00000004 00000084
Error - 08.06.2010 13:43:29 | Computer Name = NAME-F307E50405 | Source = nv | ID = 11141134
Description = Unknown error on CMDre 00000000 00000640 00000101 00000004 00000084
Error - 08.06.2010 13:46:32 | Computer Name = NAME-F307E50405 | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk6\D.
Error - 08.06.2010 14:35:11 | Computer Name = NAME-F307E50405 | Source = nv | ID = 11141134
Description = Unknown error on CMDre 00000000 00000640 00000101 00000004 00000084
Error - 08.06.2010 16:08:44 | Computer Name = NAME-F307E50405 | Source = nv | ID = 11141134
Description = Unknown error on CMDre 00000000 00000640 00000102 00000004 00000084
Error - 09.06.2010 06:14:12 | Computer Name = NAME-F307E50405 | Source = nv | ID = 11141134
Description = Unknown error on CMDre 00000000 00000640 00000102 00000004 00000084
Error - 09.06.2010 07:07:38 | Computer Name = NAME-F307E50405 | Source = nv | ID = 11141134
Description = Unknown error on CMDre 00000000 00000640 00000101 00000004 00000084
Error - 09.06.2010 08:24:03 | Computer Name = NAME-F307E50405 | Source = nv | ID = 11141134
Description = Unknown error on CMDre 00000000 00000640 00000102 00000004 00000084
< End of report > --- --- ---
--- --- ---
OTL.Txt
OTL Logfile: Code:
OTL logfile created on: 09.06.2010 14:42:54 - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Dokumente und Einstellungen\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 79,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 92,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 39,76 Gb Total Space | 12,11 Gb Free Space | 30,45% Space Free | Partition Type: NTFS
Drive D: | 6,81 Gb Total Space | 0,99 Gb Free Space | 14,48% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
Drive F: | 251,51 Gb Total Space | 114,14 Gb Free Space | 45,38% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NAME-F307E50405
Current User Name: HP_Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010.06.09 14:40:46 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\OTL.exe
PRC - [2009.08.05 21:24:28 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2009.06.09 22:13:02 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2009.03.02 12:08:43 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2008.04.14 04:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.09.02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Programme\RocketDock\RocketDock.exe
PRC - [2007.05.11 03:09:48 | 001,050,120 | ---- | M] (O&O Software GmbH) -- C:\WINDOWS\system32\oodag.exe
PRC - [2006.06.21 05:08:48 | 000,049,152 | ---- | M] (Hewlett-Packard Company) -- C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
PRC - [2006.04.13 10:05:00 | 000,090,112 | ---- | M] (Sonic Solutions) -- C:\Programme\HP DigitalMedia Archive\DMAScheduler.exe
PRC - [2005.08.03 00:19:16 | 000,058,880 | ---- | M] (Microsoft) -- C:\WINDOWS\arservice.exe
PRC - [2005.03.09 20:50:18 | 000,018,944 | ---- | M] (hxxp://libusb-win32.sourceforge.net) -- C:\WINDOWS\system32\libusbd-nt.exe
PRC - [2002.04.12 01:00:00 | 000,057,344 | ---- | M] (brother Industries Ltd) -- C:\WINDOWS\system32\brsvc01a.exe
PRC - [2001.12.13 01:01:00 | 000,045,056 | ---- | M] (brother Industries Ltd) -- C:\WINDOWS\system32\brss01a.exe
========== Modules (SafeList) ==========
MOD - [2010.06.09 14:40:46 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\OTL.exe
MOD - [2008.04.14 04:21:06 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
MOD - [2007.09.02 14:57:36 | 000,069,632 | ---- | M] () -- C:\Programme\RocketDock\RocketDock.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (MessengerDot3svc)
SRV - File not found [On_Demand | Stopped] -- -- (FirebirdServerMAGIXInstance)
SRV - [2010.06.08 19:20:28 | 001,181,328 | ---- | M] (Lavasoft) [On_Demand | Stopped] -- C:\Programme\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2009.08.05 21:24:28 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009.06.09 22:13:02 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2007.05.11 03:09:48 | 001,050,120 | ---- | M] (O&O Software GmbH) [Auto | Running] -- C:\WINDOWS\system32\oodag.exe -- (O&O Defrag)
SRV - [2006.06.21 05:08:48 | 000,049,152 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe -- (LightScribeService)
SRV - [2005.08.03 00:19:16 | 000,058,880 | ---- | M] (Microsoft) [Auto | Running] -- C:\WINDOWS\arservice.exe -- (ARSVC)
SRV - [2005.04.04 00:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2005.03.09 20:50:18 | 000,018,944 | ---- | M] (hxxp://libusb-win32.sourceforge.net) [Auto | Running] -- C:\WINDOWS\system32\libusbd-nt.exe -- (libusbd)
SRV - [2002.04.12 01:00:00 | 000,057,344 | ---- | M] (brother Industries Ltd) [Auto | Running] -- C:\WINDOWS\system32\brsvc01a.exe -- (Brother XP spl Service)
========== Driver Services (SafeList) ==========
DRV - [2009.12.07 19:58:08 | 000,056,816 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009.12.02 15:19:06 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2009.06.09 22:13:02 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.04.27 20:57:01 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2009.02.18 14:44:00 | 006,308,224 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2009.02.13 11:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2008.08.06 11:12:10 | 004,755,968 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008.04.13 20:45:34 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\irbus.sys -- (IrBus)
DRV - [2008.04.13 18:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008.03.26 13:48:08 | 000,022,016 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2008.03.26 13:48:06 | 000,054,400 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2007.10.27 14:59:05 | 000,685,816 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2006.07.01 23:30:28 | 000,043,520 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006.06.01 15:15:20 | 000,509,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\xnacc.sys -- (xnacc)
DRV - [2005.12.13 02:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PS2.sys -- (Ps2)
DRV - [2005.10.05 19:44:06 | 000,468,768 | ---- | M] (Liteon Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wn5301.sys -- (WN5301)
DRV - [2005.06.29 17:03:18 | 000,175,104 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ftsata2.sys -- (ftsata2)
DRV - [2005.06.22 23:30:52 | 000,044,224 | R--- | M] (BVRP Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BVRPMPR5.SYS -- (BVRPMPR5)
DRV - [2005.03.09 20:50:16 | 000,033,792 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\libusb0.sys -- (libusb0)
DRV - [2004.10.15 13:50:20 | 000,015,295 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BrScnUsb.sys -- (BrScnUsb)
DRV - [2004.08.13 20:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2004.08.03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) NT-Treiber für Realtek RTL8139(A/B/C)
DRV - [2003.11.05 07:45:12 | 000,017,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\bb-run.sys -- (bb-run)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DE_DE&c=64&bd=PAVILION&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/firefox"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.47.4
FF - prefs.js..extensions.enabledItems: de-AT@dictionaries.addons.mozilla.org:2.0.1
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.9
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.5.3
FF - prefs.js..extensions.enabledItems: firefox@tvunetworks.com:2
FF - prefs.js..extensions.enabledItems: 4
FF - prefs.js..extensions.enabledItems: 9
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {5B52016C-D097-4aec-BE61-9F129D8FDDBA}:2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: Strata40@SpewBoy.au:0.6.2
FF - prefs.js..extensions.enabledItems: {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.90
FF - prefs.js..keyword.URL: "hxxp://search.yahoo.com/search?ei=UTF-8&fr=vmn&type=vendio&p="
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 9666
FF - prefs.js..network.proxy.socks: "localhost"
FF - prefs.js..network.proxy.socks_port: 9050
FF - prefs.js..network.proxy.socks_remote_dns: true
FF - prefs.js..network.proxy.ssl: "localhost"
FF - prefs.js..network.proxy.ssl_port: 9666
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Programme\Mozilla Firefox\components [2010.04.03 11:55:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2010.06.08 18:17:34 | 000,000,000 | ---D | M]
[2008.08.29 16:58:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Extensions
[2010.06.08 18:17:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions
[2010.04.09 12:45:20 | 000,000,000 | ---D | M] (Vista-aero) -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
[2010.04.28 07:36:02 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.02.26 21:47:18 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\{5B52016C-D097-4aec-BE61-9F129D8FDDBA}
[2007.10.21 21:33:57 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\{c36177c0-224a-11da-8cd6-0800200c9a66}
[2010.04.30 18:54:36 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.04.09 12:45:24 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2010.04.09 12:45:27 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010.02.13 09:24:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\de-AT@dictionaries.addons.mozilla.org
[2009.10.26 00:22:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\firefox@tvunetworks.com
[2009.12.05 18:22:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\moveplayer@movenetworks.com
[2010.04.20 19:28:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\personas@christopher.beard
[2010.04.20 19:28:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\Strata40@SpewBoy.au
[2007.02.22 18:05:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\videodowloader@videodownloader(2).net
[2010.04.09 12:45:20 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}\chrome\mozapps\extensions
[2010.04.20 19:28:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\extensions\Strata40@SpewBoy.au\chrome\mozapps\extensions
[2010.02.04 17:45:40 | 000,002,254 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\searchplugins\askcom.xml
[2010.01.27 22:30:46 | 000,002,503 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\searchplugins\ixquick-https.xml
[2009.10.10 20:52:06 | 000,000,779 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\searchplugins\kicker.xml
[2008.02.09 16:00:40 | 000,001,959 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\searchplugins\lastfm.xml
[2007.06.02 16:58:27 | 000,001,067 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\searchplugins\wikipedia-deutsch.xml
[2007.05.20 13:37:46 | 000,002,109 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\searchplugins\youtube-video-search.xml
[2007.12.11 22:20:53 | 000,002,108 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\dmjslg8g.default\searchplugins\youtube-videosuche.xml
[2010.06.08 18:17:58 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2010.06.08 18:17:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.06.08 18:17:20 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.03.29 21:43:43 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.03.29 21:43:44 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.03.29 21:43:44 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.03.29 21:43:44 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.03.29 21:43:44 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.05.09 15:59:26 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AlwaysReady Power Message APP] C:\WINDOWS\arpwrmsg.exe (Microsoft)
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [combofix] C:\ComboFix\CF21618.cfx File not found
O4 - HKLM..\Run: [ControlCenter2.0] C:\Programme\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DMAScheduler] c:\Programme\HP DigitalMedia Archive\DMAScheduler.exe (Sonic Solutions)
O4 - HKLM..\Run: [ftutil2] C:\WINDOWS\System32\ftutil2.dll (Promise Technology, Inc.)
O4 - HKLM..\Run: [HPBootOp] C:\Programme\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe (O&O Software GmbH)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SetDefPrt] C:\Programme\Brother\Brmfl05a\BrStDvPt.exe (Brother Industories, Ltd.)
O4 - HKLM..\Run: [TkBellExe] File not found
O4 - HKCU..\Run: [{DBF3D42E-6479-82F3-403E-3DB491CC4CF7}] C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\Xyhew\osmu.exe File not found
O4 - HKCU..\Run: [RocketDock] C:\Programme\RocketDock\RocketDock.exe ()
O4 - Startup: C:\Dokumente und Einstellungen\HP_Administrator\Startmenü\Programme\Autostart\Last.fm Helper.lnk = C:\Programme\Last.fm\LastFMHelper.exe File not found
O4 - Startup: C:\Dokumente und Einstellungen\HP_Administrator\Startmenü\Programme\Autostart\uefa.com Meldungen.lnk = C:\DOKUME~1\HP_ADM~1\LOKALE~1\Temp\Tempor\uefa-alerts.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Hilfe zu Verbindungen - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Hilfe zu Verbindungen - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1256568601359 (MUCatalogWebControl Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/DE-DE/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} https://secure.gopetslive.com/dev/GoPetsWeb.cab (GoPetsWeb Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\HP_Administrator\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\HP_Administrator\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005.10.12 14:01:16 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001.07.27 08:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (oodbs) - C:\WINDOWS\System32\oodbs.exe (O&O Software GmbH)
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2005.11.15 07:11:04 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55745656140070912)
========== Files/Folders - Created Within 90 Days ==========
[2010.06.09 14:40:46 | 000,571,904 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\OTL.exe
[2010.06.03 21:31:00 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Google
[2010.06.03 21:26:36 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\HP_Administrator\Lokale Einstellungen\Anwendungsdaten\Temp
[2010.06.03 21:26:35 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Google
[2010.06.03 21:26:28 | 000,000,000 | ---D | C] -- C:\Programme\Google
[2010.06.03 20:10:46 | 000,369,152 | ---- | C] (The Public) -- C:\WINDOWS\System32\avisynth.dll
[2010.06.03 20:10:43 | 000,070,656 | ---- | C] (w*w.helixcommunity.org) -- C:\WINDOWS\System32\yv12vfw.dll
[2010.06.03 20:10:43 | 000,070,656 | ---- | C] (w*w.helixcommunity.org) -- C:\WINDOWS\System32\i420vfw.dll
[2010.06.03 20:06:27 | 000,216,064 | RHS- | C] (MONOGRAM Multimedia, s.r.o.) -- C:\WINDOWS\System32\nbDX.dll
[2010.06.03 20:06:27 | 000,186,880 | RHS- | C] (RadLight) -- C:\WINDOWS\System32\RLOgg.ax
[2010.06.03 20:06:27 | 000,169,472 | RHS- | C] (Gabest) -- C:\WINDOWS\System32\MatroskaDX.ax
[2010.06.03 20:06:27 | 000,161,792 | RHS- | C] (Gabest) -- C:\WINDOWS\System32\RealMediaDX.ax
[2010.06.03 20:06:27 | 000,092,672 | RHS- | C] (RadLight) -- C:\WINDOWS\System32\RLVorbisDec.ax
[2010.06.03 20:06:27 | 000,090,112 | RHS- | C] (-) -- C:\WINDOWS\System32\TTADSSplitter.ax
[2010.06.03 20:06:27 | 000,090,112 | RHS- | C] (-) -- C:\WINDOWS\System32\TTADSDecoder.ax
[2010.06.03 20:06:27 | 000,067,584 | RHS- | C] (RadLight, LLC) -- C:\WINDOWS\System32\RLTheoraDec.ax
[2010.06.03 20:06:27 | 000,031,232 | RHS- | C] (Hans Mayerl) -- C:\WINDOWS\System32\msfDX.dll
[2010.06.03 20:06:26 | 000,179,200 | RHS- | C] (Gabest) -- C:\WINDOWS\System32\DiracSplitter.ax
[2010.06.03 20:06:26 | 000,163,328 | RHS- | C] (Gabest) -- C:\WINDOWS\System32\flvDX.dll
[2010.06.03 20:04:36 | 000,123,904 | RHS- | C] (CoreCodec) -- C:\WINDOWS\System32\AVCDX.ax
[2010.06.03 20:04:19 | 000,000,000 | ---D | C] -- C:\Programme\eRightSoft
[2010.06.03 19:47:34 | 000,000,000 | ---D | C] -- C:\Programme\AviSynth 2.5
[2010.06.03 19:44:03 | 000,000,000 | ---D | C] -- C:\Programme\MeGUI
[2010.05.30 11:57:58 | 000,000,000 | ---D | C] -- C:\Programme\Haali
[2010.05.25 19:45:57 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\WinRAR
[2010.05.24 12:56:18 | 000,000,000 | ---D | C] -- C:\Programme\mkv2vob
[2010.05.23 16:57:34 | 000,000,000 | ---D | C] -- C:\Programme\JDownloader
[2010.05.22 14:59:35 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\**********
[2010.05.14 17:39:35 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\HP_Administrator\Eigene Dateien\Neuer Ordner
[2010.04.25 21:21:14 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\lame
[2010.04.16 20:31:40 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\Sixaxis_PS3_Win32_Driver_For_PC
[2010.03.19 22:52:42 | 000,000,000 | ---D | C] -- C:\Programme\uTorrent
[2010.03.19 22:52:11 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\uTorrent
[2004.11.24 21:25:52 | 000,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll
========== Files - Modified Within 90 Days ==========
[2010.06.09 14:40:46 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\OTL.exe
[2010.06.09 14:31:00 | 000,001,108 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.06.09 14:24:58 | 000,000,188 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.DAT
[2010.06.09 14:24:19 | 000,001,374 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.06.09 14:23:51 | 000,204,026 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010.06.09 14:23:46 | 000,001,104 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.06.09 14:23:42 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.06.09 14:23:38 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.06.09 14:23:36 | 2146,684,928 | -HS- | M] () -- C:\hiberfil.sys
[2010.06.09 14:23:35 | 002,680,423 | ---- | M] () -- C:\WINDOWS\System32\oodbs.lor
[2010.06.09 13:20:18 | 000,000,470 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2010.06.09 12:31:50 | 000,001,788 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Google Chrome.lnk
[2010.06.08 22:23:15 | 015,466,496 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\ntuser.dat
[2010.06.08 19:30:59 | 000,000,470 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010.06.08 19:30:58 | 000,000,470 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2010.06.08 19:30:58 | 000,000,470 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2010.06.08 19:30:58 | 000,000,470 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2010.06.07 22:06:03 | 000,000,235 | --S- | M] () -- C:\WINDOWS\System32\781926501.dat
[2010.06.03 21:28:18 | 000,001,898 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Google Earth.lnk
[2010.06.03 20:06:28 | 000,001,664 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\SUPER © Uninstall.lnk
[2010.06.03 20:06:28 | 000,001,640 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\SUPER ©.lnk
[2010.06.03 19:28:51 | 303,060,253 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\Lena_02.mp4
[2010.06.02 21:37:19 | 000,000,004 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\dhxiuw.dat
[2010.05.25 12:25:00 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.05.24 12:56:22 | 000,001,714 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\mkv2vob.lnk
[2010.05.23 16:57:48 | 000,000,763 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\JDownloader.lnk
[2010.05.17 21:57:20 | 000,019,090 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\35 - 175 zanderfilet.odt
[2010.05.17 21:21:42 | 000,023,117 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\getränke.odt
[2010.05.15 18:54:26 | 000,118,272 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.05.14 13:33:03 | 000,001,720 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader 9.lnk
[2010.05.13 10:29:49 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.04.29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.04.29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.04.28 12:14:31 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2010.04.22 19:14:46 | 001,195,212 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.04.22 19:14:46 | 000,506,228 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2010.04.22 19:14:46 | 000,478,570 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.04.22 19:14:46 | 000,106,022 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2010.04.22 19:14:46 | 000,087,352 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.04.16 20:30:23 | 000,000,700 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\Verknüpfung mit PES6.lnk
[2010.04.12 08:34:31 | 001,584,805 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\Präsentations orig.odp
[2010.04.03 21:50:57 | 000,000,600 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\PUTTY.RND
[2010.03.21 19:57:24 | 000,435,200 | ---- | M] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\U995.exe
[2010.03.19 22:52:43 | 000,000,621 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\µTorrent.lnk
========== Files Created - No Company Name ==========
[2010.06.08 14:40:22 | 000,015,880 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2010.06.03 21:28:43 | 000,001,788 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Google Chrome.lnk
[2010.06.03 21:28:18 | 000,001,898 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Google Earth.lnk
[2010.06.03 21:26:32 | 000,001,108 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.06.03 21:26:32 | 000,001,104 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.06.03 20:10:43 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2010.06.03 20:06:28 | 000,001,664 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\SUPER © Uninstall.lnk
[2010.06.03 20:06:28 | 000,001,640 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\SUPER ©.lnk
[2010.06.03 20:06:27 | 000,120,832 | RHS- | C] () -- C:\WINDOWS\System32\MPCDx.ax
[2010.06.03 20:06:27 | 000,051,712 | RHS- | C] () -- C:\WINDOWS\System32\RLSpeexDec.ax
[2010.06.03 20:06:26 | 000,097,280 | RHS- | C] () -- C:\WINDOWS\System32\FLACDX.ax
[2010.06.03 20:04:36 | 000,227,328 | RHS- | C] () -- C:\WINDOWS\System32\ac3DX.ax
[2010.06.03 20:04:36 | 000,081,920 | RHS- | C] () -- C:\WINDOWS\System32\aac_parser.ax
[2010.06.03 19:19:35 | 303,060,253 | ---- | C] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\Lena_02.mp4
[2010.06.02 21:37:22 | 000,000,235 | --S- | C] () -- C:\WINDOWS\System32\781926501.dat
[2010.06.02 21:37:19 | 000,000,004 | ---- | C] () -- C:\Dokumente und Einstellungen\HP_Administrator\Anwendungsdaten\dhxiuw.dat
[2010.05.24 12:56:22 | 000,001,714 | ---- | C] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\mkv2vob.lnk
[2010.05.23 16:57:48 | 000,000,763 | ---- | C] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\JDownloader.lnk
[2010.05.16 22:06:42 | 000,019,090 | ---- | C] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\35 - 175 zanderfilet.odt
[2010.05.16 21:25:18 | 000,023,117 | ---- | C] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\getränke.odt
[2010.04.16 20:30:23 | 000,000,700 | ---- | C] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\Verknüpfung mit PES6.lnk
[2010.04.12 08:34:30 | 001,584,805 | ---- | C] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\Präsentations orig.odp
[2010.03.28 23:37:25 | 000,001,720 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader 9.lnk
[2010.03.21 19:57:24 | 000,435,200 | ---- | C] () -- C:\Dokumente und Einstellungen\HP_Administrator\Desktop\U995.exe
[2010.03.19 22:52:43 | 000,000,621 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\µTorrent.lnk
[2010.02.06 17:27:32 | 000,350,208 | ---- | C] () -- C:\WINDOWS\System32\Rivet200.dll
[2009.04.01 15:21:00 | 000,000,316 | ---- | C] () -- C:\WINDOWS\game.ini
[2009.03.31 15:48:30 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2009.03.31 15:48:21 | 000,028,503 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2009.03.31 15:48:13 | 000,010,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008.12.19 17:15:58 | 004,338,246 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008.12.17 19:41:18 | 000,884,237 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2008.12.17 19:22:58 | 000,093,184 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2008.12.17 19:22:48 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008.12.17 19:17:34 | 000,239,247 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2008.12.17 18:59:54 | 000,560,802 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2008.12.11 13:27:02 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008.10.07 13:33:00 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008.10.07 13:33:00 | 001,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008.10.07 13:33:00 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008.10.07 13:33:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008.10.07 13:33:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008.10.07 09:13:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008.09.20 16:15:13 | 000,033,792 | ---- | C] () -- C:\WINDOWS\System32\drivers\libusb0.sys
[2008.06.05 08:58:26 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008.02.14 21:17:39 | 000,000,000 | ---- | C] () -- C:\WINDOWS\oodcnt.INI
[2007.09.11 20:06:44 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007.05.04 17:16:54 | 000,006,642 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2007.05.01 18:28:34 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007.04.10 10:43:55 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2007.02.24 18:49:08 | 000,000,024 | ---- | C] () -- C:\WINDOWS\LogonStudio.ini
[2007.02.24 18:48:19 | 000,187,392 | ---- | C] () -- C:\WINDOWS\System32\JPGUtils.dll
[2007.02.24 17:59:51 | 000,000,021 | ---- | C] () -- C:\WINDOWS\WB.ini
[2007.02.24 17:57:08 | 000,006,910 | ---- | C] () -- C:\WINDOWS\langorig.ini
[2007.02.24 17:56:29 | 000,026,288 | ---- | C] () -- C:\WINDOWS\System32\wbload.dll
[2007.02.06 00:52:52 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2007.01.10 19:34:28 | 000,000,206 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007.01.10 18:55:05 | 000,000,468 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2007.01.10 18:55:05 | 000,000,030 | ---- | C] () -- C:\WINDOWS\System32\brss01a.ini
[2007.01.10 18:55:05 | 000,000,027 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2007.01.10 18:53:40 | 000,000,205 | ---- | C] () -- C:\WINDOWS\Brpfx04a.ini
[2007.01.10 18:53:40 | 000,000,092 | ---- | C] () -- C:\WINDOWS\brpcfx.ini
[2007.01.10 18:47:33 | 000,008,192 | ---- | C] () -- C:\WINDOWS\suecmdial.dll
[2006.06.16 04:58:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2006.01.02 18:35:42 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006.01.02 18:11:14 | 000,028,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBkey.sys
[2006.01.02 18:04:26 | 000,014,377 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2006.01.02 18:04:20 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2006.01.02 17:46:33 | 000,000,849 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2006.01.02 17:24:51 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2005.08.05 22:26:04 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005.08.03 00:19:16 | 000,050,176 | ---- | C] () -- C:\WINDOWS\armcex.dll
[2005.04.26 03:05:50 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\vbzlib.dll
[2004.10.03 19:50:54 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004.07.26 22:08:20 | 000,001,262 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2001.06.21 13:13:48 | 000,081,332 | ---- | C] () -- C:\WINDOWS\System32\bass.dll
[1996.04.03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2007.04.04 11:54:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avg7
[2009.04.01 11:25:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Codemasters
[2007.05.04 17:19:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MAGIX
[2008.03.17 19:51:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MailFrontier
[2009.06.08 20:23:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Messenger Plus!
[2008.03.25 20:20:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
[2007.02.17 15:10:25 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software
[2007.07.31 13:43:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\WindowsLiveInstaller
[2007.01.25 17:14:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\WinZip
[2010.01.26 20:17:21 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
[2010.06.08 19:30:58 | 000,000,470 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job
[2010.06.08 19:30:58 | 000,000,470 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job
[2010.06.08 19:30:58 | 000,000,470 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job
[2010.06.09 13:20:18 | 000,000,470 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job
[2010.06.08 19:30:59 | 000,000,470 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010.06.09 14:23:35 | 000,000,668 | ---- | M] () -- C:\aaw7boot.log
[2005.10.12 14:01:16 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2007.01.10 19:00:07 | 000,000,211 | RHS- | M] () -- C:\BOOT.BAK
[2009.03.31 15:49:06 | 000,000,303 | RHS- | M] () -- C:\boot.ini
[2004.08.09 23:00:00 | 000,004,952 | RHS- | M] () -- C:\bootfont.bin
[2004.08.09 23:00:00 | 000,262,448 | RHS- | M] () -- C:\cmldr
[2010.01.26 21:07:54 | 000,019,068 | ---- | M] () -- C:\ComboFix.txt
[2005.10.12 14:01:16 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2007.04.22 20:39:55 | 000,001,166 | ---- | M] () -- C:\crashAddress.txt
[2010.06.09 14:23:36 | 2146,684,928 | -HS- | M] () -- C:\hiberfil.sys
[2005.10.12 14:01:16 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010.06.02 21:39:57 | 000,000,158 | ---- | M] () -- C:\mbam-error.txt
[2005.10.12 14:01:16 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004.08.09 23:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008.09.17 18:02:20 | 000,251,712 | RHS- | M] () -- C:\ntldr
[2010.06.09 14:23:35 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2008.10.07 20:44:57 | 000,000,232 | -H-- | M] () -- C:\sqmdata00.sqm
[2008.10.07 21:12:20 | 000,000,232 | -H-- | M] () -- C:\sqmdata01.sqm
[2008.10.07 21:14:51 | 000,000,232 | -H-- | M] () -- C:\sqmdata02.sqm
[2008.10.23 23:10:36 | 000,000,232 | -H-- | M] () -- C:\sqmdata03.sqm
[2008.10.24 09:45:30 | 000,000,232 | -H-- | M] () -- C:\sqmdata04.sqm
[2008.07.02 17:14:14 | 000,000,232 | -H-- | M] () -- C:\sqmdata05.sqm
[2008.08.07 20:50:02 | 000,000,232 | -H-- | M] () -- C:\sqmdata06.sqm
[2008.08.22 00:03:46 | 000,000,232 | -H-- | M] () -- C:\sqmdata07.sqm
[2008.08.22 12:34:35 | 000,000,232 | -H-- | M] () -- C:\sqmdata08.sqm
[2008.08.22 13:21:57 | 000,000,232 | -H-- | M] () -- C:\sqmdata09.sqm
[2008.08.22 14:24:29 | 000,000,232 | -H-- | M] () -- C:\sqmdata10.sqm
[2008.08.22 20:30:14 | 000,000,232 | -H-- | M] () -- C:\sqmdata11.sqm
[2008.08.22 23:18:59 | 000,000,232 | -H-- | M] () -- C:\sqmdata12.sqm
[2008.08.23 15:03:01 | 000,000,232 | -H-- | M] () -- C:\sqmdata13.sqm
[2008.08.23 18:11:29 | 000,000,232 | -H-- | M] () -- C:\sqmdata14.sqm
[2008.08.23 23:08:21 | 000,000,232 | -H-- | M] () -- C:\sqmdata15.sqm
[2008.08.24 15:18:50 | 000,000,268 | -H-- | M] () -- C:\sqmdata16.sqm
[2008.09.07 22:47:02 | 000,000,232 | -H-- | M] () -- C:\sqmdata17.sqm
[2008.09.08 12:22:36 | 000,000,232 | -H-- | M] () -- C:\sqmdata18.sqm
[2008.09.08 17:47:20 | 000,000,232 | -H-- | M] () -- C:\sqmdata19.sqm
[2008.10.07 20:44:57 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2008.10.07 21:12:20 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2008.10.07 21:14:51 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2008.10.23 23:10:36 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2008.10.24 09:45:30 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2008.07.02 17:14:14 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2008.08.07 20:50:02 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2008.08.22 00:03:46 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2008.08.22 12:34:35 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2008.08.22 13:21:57 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2008.08.22 14:24:29 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2008.08.22 20:30:14 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2008.08.22 23:18:59 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2008.08.23 15:03:01 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2008.08.23 18:11:29 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2008.08.23 23:08:21 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2008.08.24 15:18:50 | 000,000,172 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2008.09.07 22:47:02 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2008.09.08 12:22:36 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2008.09.08 17:47:20 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2008.11.15 16:40:12 | 000,108,356 | ---- | M] () -- C:\test.log
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2005.10.12 15:50:30 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2005.10.12 15:50:30 | 000,663,552 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2005.10.12 15:50:30 | 000,430,080 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\drivers\*.sys /90 >
[2010.04.29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys
[2010.04.29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
< %systemroot%\system32\user32.dll /md5 >
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll
< %systemroot%\system32\ws2_32.dll /md5 >
[2008.04.14 04:22:32 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=6A35E2D6F5F052C84EC2CEB296389439 -- C:\WINDOWS\system32\ws2_32.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 294 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:05EE1EEF
@Alternate Data Stream - 105 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:052A05A1
< End of report > --- --- ---
GMER reiche ich gleich nach (editiere es hier rein).
Edit: Wie richte ich AntiVir so ein, dass es nach einem Neustart immer noch deaktiviert bleibt? Wenn ich es einfach so deaktiviere, dann startet es wieder bei einem Neustart, aber die Programme sollen ja aus bleiben bei der Ausführung von GMER. |