elreinhard | 24.07.2010 11:51 | Hi Arne, habe OTL heruntergeladen und laufen lassen. Hier die Logfiles:
1) Extras.txt
OTL Logfile: Code:
OTL Extras logfile created on: 24.07.2010 15:10:28 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Dokumente und Einstellungen\Admin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 61,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Programme
Drive C: | 40,00 Gb Total Space | 20,99 Gb Free Space | 52,46% Space Free | Partition Type: NTFS
Drive D: | 65,08 Gb Total Space | 3,51 Gb Free Space | 5,40% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: BIE
Current User Name: Admin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.exe [@ = exefile] -- Reg Error: Key error. File not found
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Programme\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Programme\AVG\AVG9\avgemc.exe" = C:\Programme\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Programme\AVG\AVG9\avgupd.exe" = C:\Programme\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Programme\AVG\AVG9\avgnsx.exe" = C:\Programme\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Programme\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Programme\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Dokumente und Einstellungen\Admin\Anwendungsdaten\Dropbox\bin\Dropbox.exe" = C:\Dokumente und Einstellungen\Admin\Anwendungsdaten\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- ()
"C:\Programme\JustVoip.com\JustVoip\JustVoip.exe" = C:\Programme\JustVoip.com\JustVoip\JustVoip.exe:*:Enabled:JustVoip -- (JustVoip)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{086a7d8c-0a38-4c7f-819a-620275550d5c}" = Nero BurningROM
"{1297C681-92D7-40EF-93BF-03F66EC5105C}" = ThinkPad-Dienstprogramm 'EasyEject'
"{2111B23F-7FDA-4A41-8309-E5A1663CA296}" = Dienstprogramm 'ThinkPad-Tastaturanpassung'
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java(TM) 6 Update 21
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3D289CAC-AD9F-45d9-9D36-524EB7B6C958}" = Lenovo Hard Drive Quick Test
"{43507E5B-94A0-4E56-9C7B-FAAAFBDB5904}" = Intel(R) PROSet/Wireless WiFi-Software
"{44E9D4C2-946C-4378-9354-558803C47A68}" = Client Security - Password Manager
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage System für aktiven Festplattenschutz
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{65706020-7B6F-41F2-8047-FC69579E386A}" = Präsentationsdirektor
"{702e274a-505b-4946-9228-e450349689c2}" = Nero 9
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{7EB114D8-207F-45AE-BABD-1669715F2630}" = ThinkVantage Access Connections
"{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = ThinkPad Bluetooth with Enhanced Data Rate Software
"{8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1" = PDF-Viewer
"{90120000-0010-0407-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (German) 12
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007
"{986F64DC-FF15-449D-998F-EE3BCEC6666A}" = Help Center
"{A0E64EBA-8BF0-49FB-90C0-BB3D781A2016}" = ThinkPad Energie-Manager
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.3 - Deutsch
"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{b78120a0-cf84-4366-a393-4d0a59bc546c}" = Menu Templates - Starter Kit
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF5737AF-8550-4546-A69B-0EA9EF5A9B55}" = ThinkVantage Productivity Center
"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D728E945-256D-4477-B377-6BBA693714AC}" = Ergänzung zu Productivity Center für ThinkPad
"{e498385e-1c51-459a-b45f-1721e37aa1a0}" = Movie Templates - Starter Kit
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG9Uninstall" = AVG Free 9.0
"AwayTask" = Maintenance Manager
"CCleaner" = CCleaner
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_5045&SUBSYS_17AA20DA" = HDAUDIO Soft Data Fax Modem with SmartCP
"DivX Setup.divx.com" = DivX-Setup
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"ie8" = Windows Internet Explorer 8
"JustVoip_is1" = JustVoip
"KLiteCodecPack_is1" = K-Lite Codec Pack 3.7.0 Full
"LENOVO.SMIIF" = Lenovo System Interface Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MiKTeX 2.8" = MiKTeX 2.8
"Mozilla Firefox (3.6.7)" = Mozilla Firefox (3.6.7)
"Mozilla Thunderbird (3.0.4)" = Mozilla Thunderbird (3.0.4)
"OnScreenDisplay" = Anzeige am Bildschirm
"pdfsam" = pdfsam
"Picasa 3" = Picasa 3
"Power Management Driver" = ThinkPad Power Management Driver
"ProInst" = Intel PROSet Wireless
"Shrew Soft VPN Client" = Shrew Soft VPN Client
"TeXnicCenter_is1" = TeXnicCenter Version 1.0 Stable RC1
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"Veetle TV" = Veetle TV 0.9.17
"VLC media player" = VLC media player 1.0.5
"WinEdt 6_is1" = WinEdt 6
"WinRAR archiver" = WinRAR
"Wubi" = Ubuntu
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 21.07.2010 17:32:15 | Computer Name = BIE | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung SZServer.exe, Version 5.0.69.0, fehlgeschlagenes
Modul unknown, Version 0.0.0.0, Fehleradresse 0x00000000.
Error - 22.07.2010 03:35:07 | Computer Name = BIE | Source = Google Update | ID = 20
Description =
Error - 22.07.2010 09:04:31 | Computer Name = BIE | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung notepad.exe, Version 5.1.2600.5512, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 22.07.2010 09:06:11 | Computer Name = BIE | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung notepad.exe, Version 5.1.2600.5512, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 22.07.2010 09:07:01 | Computer Name = BIE | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung notepad.exe, Version 5.1.2600.5512, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 22.07.2010 09:10:16 | Computer Name = BIE | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung wordpad.exe, Version 5.1.2600.5584, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 22.07.2010 09:35:05 | Computer Name = BIE | Source = Google Update | ID = 20
Description =
Error - 22.07.2010 10:35:05 | Computer Name = BIE | Source = Google Update | ID = 20
Description =
Error - 22.07.2010 11:35:05 | Computer Name = BIE | Source = Google Update | ID = 20
Description =
Error - 23.07.2010 09:03:32 | Computer Name = BIE | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung rundll32.exe, Version 5.1.2600.5512, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
[ OSession Events ]
Error - 14.05.2010 06:48:13 | Computer Name = BIE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 90
seconds with 60 seconds of active time. This session ended with a crash.
Error - 14.05.2010 06:49:32 | Computer Name = BIE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 9
seconds with 0 seconds of active time. This session ended with a crash.
Error - 14.05.2010 07:21:43 | Computer Name = BIE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 9
seconds with 0 seconds of active time. This session ended with a crash.
Error - 15.05.2010 09:29:58 | Computer Name = BIE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 5954
seconds with 1860 seconds of active time. This session ended with a crash.
Error - 15.05.2010 10:03:16 | Computer Name = BIE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 896
seconds with 780 seconds of active time. This session ended with a crash.
Error - 16.05.2010 15:03:05 | Computer Name = BIE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 14
seconds with 0 seconds of active time. This session ended with a crash.
Error - 27.05.2010 08:44:41 | Computer Name = BIE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 503
seconds with 420 seconds of active time. This session ended with a crash.
Error - 27.05.2010 09:11:04 | Computer Name = BIE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 339
seconds with 300 seconds of active time. This session ended with a crash.
Error - 19.07.2010 13:51:00 | Computer Name = BIE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 20
seconds with 0 seconds of active time. This session ended with a crash.
Error - 19.07.2010 13:51:10 | Computer Name = BIE | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 1
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 22.07.2010 06:17:42 | Computer Name = BIE | Source = DCOM | ID = 10010
Description = Der Server "{E60687F7-01A1-40AA-86AC-DB1CBF673334}" konnte innerhalb
des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.
Error - 22.07.2010 13:02:28 | Computer Name = BIE | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
Error - 22.07.2010 21:55:43 | Computer Name = BIE | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
Error - 23.07.2010 02:39:31 | Computer Name = BIE | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
Error - 23.07.2010 02:40:00 | Computer Name = BIE | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
Error - 23.07.2010 13:01:34 | Computer Name = BIE | Source = ialm | ID = 262252
Description = Treiber igxprd32 für display-Gerät \Device\Video0 befindet sich in
einer unendlichen Schleife. Wahrscheinlich funktioniert das Gerät fehlerhaft, oder
die Hardware wurde vom Gerätetreiber nicht ordnungsgemäß programmiert. Wenden Sie
sich an den Hardwarehersteller, um Treiberupdates zu beziehen.
Error - 23.07.2010 14:04:59 | Computer Name = BIE | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
Error - 23.07.2010 14:13:41 | Computer Name = BIE | Source = System Error | ID = 1003
Description = Fehlercode 000000ea, 1. Parameter 87f11020, 2. Parameter 89ae3768,
3. Parameter 89c3c330, 4. Parameter 00000001.
Error - 23.07.2010 22:32:12 | Computer Name = BIE | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
Error - 24.07.2010 06:18:18 | Computer Name = BIE | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
< End of report > --- --- ---
******************************************************
2)OTL.txt
OTL Logfile: Code:
OTL logfile created on: 24.07.2010 15:10:28 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Dokumente und Einstellungen\Admin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 61,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Programme
Drive C: | 40,00 Gb Total Space | 20,99 Gb Free Space | 52,46% Space Free | Partition Type: NTFS
Drive D: | 65,08 Gb Total Space | 3,51 Gb Free Space | 5,40% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: BIE
Current User Name: Admin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Dokumente und Einstellungen\Admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programme\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programme\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programme\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programme\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programme\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programme\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Programme\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Dokumente und Einstellungen\Admin\Anwendungsdaten\Dropbox\bin\Dropbox.exe ()
PRC - C:\Programme\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
PRC - C:\Programme\ThinkPad\Utilities\PWMDBSVC.exe ()
PRC - C:\WINXP\system32\TpShocks.exe (Lenovo.)
PRC - C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
PRC - C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
PRC - C:\Programme\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
PRC - C:\Programme\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
PRC - C:\Programme\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe (Lenovo )
PRC - C:\WINXP\system32\ibmpmsvc.exe (Lenovo.)
PRC - C:\Programme\ShrewSoft\VPN Client\dtpd.exe ()
PRC - C:\Programme\ShrewSoft\VPN Client\iked.exe ()
PRC - C:\Programme\ShrewSoft\VPN Client\ipsecd.exe ()
PRC - C:\Programme\Lenovo\ZOOM\TpScrex.exe (Lenovo Group Limited)
PRC - C:\Programme\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
PRC - C:\Programme\Intel\WiFi\bin\S24EvMon.exe (Intel(R) Corporation)
PRC - C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
PRC - C:\Programme\Lenovo\HOTKEY\tpfnf6r.exe (Lenovo Group Limited)
PRC - C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Programme\ThinkPad\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Programme\Lenovo\NPDIRECT\tpfnf7sp.exe (Lenovo Group Limited)
PRC - C:\Programme\ThinkVantage\PrdCtr\LPMGR.EXE (Lenovo Group Limited)
PRC - C:\Programme\ThinkVantage\PrdCtr\LPMLCHK.EXE (Lenovo Group Limited)
PRC - C:\Programme\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
PRC - C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\WINXP\system32\igfxext.exe (Intel Corporation)
PRC - C:\Programme\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Programme\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Ltd.)
PRC - C:\Programme\Gemeinsame Dateien\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Programme\Lenovo\Client Security Solution\cssauth.exe (Lenovo Group Limited)
PRC - C:\WINXP\explorer.exe (Microsoft Corporation)
PRC - C:\WINXP\system32\tp4mon.exe (IBM Corporation)
PRC - C:\WINXP\system32\IPSSVC.EXE (Lenovo Group Limited)
PRC - C:\Programme\Lenovo\AwayTask\AwaySch.EXE (Lenovo Group Limited)
PRC - C:\Programme\Digital Line Detect\DLG.exe (Avanquest Software )
PRC - C:\WINXP\system32\TpKmpSvc.exe ()
========== Modules (SafeList) ==========
MOD - C:\Dokumente und Einstellungen\Admin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINXP\system32\BtMmHook.dll (Broadcom Corporation.)
MOD - C:\WINXP\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (wuauserv) -- C:\WINDOWS\system32\wuauserv.dll File not found
SRV - (HidServ) -- C:\WINXP\System32\hidserv.dll File not found
SRV - (avg9emc) -- C:\Programme\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) -- C:\Programme\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (DozeSvc) -- C:\Programme\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
SRV - (Power Manager DBC Service) -- C:\Programme\ThinkPad\Utilities\PWMDBSVC.exe ()
SRV - (AcSvc) -- C:\Programme\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
SRV - (AcPrfMgrSvc) -- C:\Programme\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
SRV - (IBMPMSVC) -- C:\WINXP\system32\ibmpmsvc.exe (Lenovo.)
SRV - (dtpd) -- C:\Programme\ShrewSoft\VPN Client\dtpd.exe ()
SRV - (iked) -- C:\Programme\ShrewSoft\VPN Client\iked.exe ()
SRV - (ipsecd) -- C:\Programme\ShrewSoft\VPN Client\ipsecd.exe ()
SRV - (TPHDEXLGSVC) -- C:\WINXP\system32\TPHDEXLG.exe (Lenovo.)
SRV - (EvtEng) Intel(R) -- C:\Programme\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
SRV - (S24EventMonitor) Intel(R) -- C:\Programme\Intel\WiFi\bin\S24EvMon.exe (Intel(R) Corporation)
SRV - (RegSrvc) Intel(R) -- C:\Programme\Gemeinsame Dateien\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
SRV - (btwdins) -- C:\Programme\ThinkPad\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (TPHKSVC) -- C:\Programme\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
SRV - (LENOVO.MICMUTE) -- C:\Programme\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
SRV - (Nero BackItUp Scheduler 4.0) -- C:\Programme\Gemeinsame Dateien\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (ThinkVantage Registry Monitor Service) -- C:\Programme\Gemeinsame Dateien\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
SRV - (IPSSVC) -- C:\WINXP\system32\IPSSVC.EXE (Lenovo Group Limited)
SRV - (odserv) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (TpKmpSVC) -- C:\WINXP\system32\TpKmpSvc.exe ()
========== Driver Services (SafeList) ==========
DRV - (AvgTdiX) -- C:\WINXP\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) -- C:\WINXP\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) -- C:\WINXP\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (sptd) -- C:\WINXP\System32\Drivers\sptd.sys ()
DRV - (psadd) -- C:\WINXP\system32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (DozeHDD) -- C:\WINXP\System32\DRIVERS\DozeHDD.sys (Lenovo.)
DRV - (TPPWRIF) -- C:\WINXP\system32\drivers\TPPWRIF.SYS ()
DRV - (pflt) -- C:\WINXP\system32\drivers\vfilter.sys (Shrew Soft Inc)
DRV - (vnet) -- C:\WINXP\system32\drivers\virtualnet.sys (Shrew Soft Inc)
DRV - (IBMPMDRV) -- C:\WINXP\system32\drivers\ibmpmdrv.sys (Lenovo.)
DRV - (IBMTPCHK) -- C:\WINXP\system32\drivers\IBMBLDID.sys ()
DRV - (ANC) -- C:\WINXP\system32\drivers\ANC.sys (IBM Corp.)
DRV - (Shockprf) -- C:\WINXP\System32\DRIVERS\Apsx86.sys (Lenovo.)
DRV - (TPDIGIMN) -- C:\WINXP\System32\DRIVERS\ApsHM86.sys (Lenovo.)
DRV - (NETw5x32) Intel(R) -- C:\WINXP\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (s24trans) -- C:\WINXP\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (TSMAPIP) -- C:\WINXP\system32\drivers\TSMAPIP.SYS ()
DRV - (BTKRNL) -- C:\WINXP\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWUSB) -- C:\WINXP\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (ialm) -- C:\WINXP\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (TPHKDRV) -- C:\WINXP\system32\drivers\TPHKDRV.sys (Lenovo Group Limited)
DRV - (lenovo.smi) -- C:\WINXP\system32\drivers\smiif32.sys (Lenovo Group Limited)
DRV - (HDAudBus) -- C:\WINXP\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider)
DRV - (usbaudio) USB-Audiotreiber (WDM) -- C:\WINXP\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (TVTI2C) -- C:\WINXP\system32\drivers\tvti2c.sys (Lenovo (United States) Inc.)
DRV - (b57w2k) -- C:\WINXP\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (HdAudAddService) -- C:\WINXP\system32\drivers\CHDAudN.sys (Conexant Systems Inc.)
DRV - (HSF_DPV) -- C:\WINXP\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) -- C:\WINXP\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINXP\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (PROCDD) -- C:\WINXP\system32\drivers\PROCDD.SYS (Lenovo Group Limited)
DRV - (atmeltpm) -- C:\WINXP\system32\drivers\atmeltpm.sys (Atmel, Inc.)
DRV - (TwoTrack) -- C:\WINXP\system32\drivers\TwoTrack.sys (IBM Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = EE 63 EC 27 0C 2A CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.7\extensions\\Components: C:\Programme\Mozilla Firefox\components [2010.07.21 03:41:36 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.7\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2010.07.21 21:51:50 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2010.04.27 17:35:03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins [2010.07.09 11:39:28 | 000,000,000 | ---D | M]
[2010.03.23 07:35:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Admin\Anwendungsdaten\Mozilla\Extensions
[2010.03.23 07:35:42 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Admin\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.07.24 15:00:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Admin\Anwendungsdaten\Mozilla\Firefox\Profiles\a2qabsvq.default\extensions
[2010.07.11 03:26:09 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Dokumente und Einstellungen\Admin\Anwendungsdaten\Mozilla\Firefox\Profiles\a2qabsvq.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.07.24 15:00:10 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2010.07.21 21:51:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.07.21 21:51:38 | 000,423,656 | ---- | M] (Oracle) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.01.16 05:45:29 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.01.16 05:45:29 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.01.16 05:45:29 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.01.16 05:45:29 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.01.16 05:45:29 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2010.07.21 14:11:51 | 000,000,027 | ---- | M]) - C:\WINXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programme\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (IePasswordManagerHelper Class) - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Programme\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O4 - HKLM..\Run: [ACTray] C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
O4 - HKLM..\Run: [ACWLIcon] C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Programme\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AwaySch] C:\Programme\Lenovo\AwayTask\AwaySch.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [cssauth] C:\Programme\Lenovo\Client Security Solution\cssauth.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [DivXUpdate] C:\Programme\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EZEJMNAP] C:\Programme\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Ltd.)
O4 - HKLM..\Run: [LENOVO.TPFNF6R] C:\Programme\Lenovo\HOTKEY\tpfnf6r.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [LPMailChecker] C:\Programme\ThinkVantage\PrdCtr\LPMLCHK.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [LPManager] C:\Programme\ThinkVantage\PrdCtr\LPMGR.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [PWRMGRTR] C:\Programme\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [TPFNF7] C:\Programme\Lenovo\NPDIRECT\TPFNF7SP.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Programme\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPKMAPHELPER] C:\Programme\ThinkPad\Utilities\TpKmapAp.exe (Lenovo)
O4 - HKLM..\Run: [TpShocks] C:\WINXP\System32\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [TrackPointSrv] C:\WINXP\System32\tp4mon.exe (IBM Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [Urijubemobel] C:\WINXP\qlapiant.DLL File not found
O4 - Startup: C:\Dokumente und Einstellungen\Admin\Startmenü\Programme\Autostart\Dropbox.lnk = C:\Dokumente und Einstellungen\Admin\Anwendungsdaten\Dropbox\bin\Dropbox.exe ()
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\BTTray.lnk = C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Digital Line Detect.lnk = C:\Programme\Digital Line Detect\DLG.exe (Avanquest Software )
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Programme\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1268847754661 (WUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programme\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINXP\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINXP\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINXP\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\tpfnf2: DllName - C:\Programme\Lenovo\HOTKEY\notifyf2.dll - C:\Programme\Lenovo\HOTKEY\notifyf2.dll ()
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Admin\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Admin\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.03.17 21:07:19 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{567b3718-53b9-11df-be87-001c259079ed}\Shell - "" = AutoRun
O33 - MountPoints2\{567b3718-53b9-11df-be87-001c259079ed}\Shell\Auto\command - "" = serivces.exe
O33 - MountPoints2\{567b3718-53b9-11df-be87-001c259079ed}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ==========
[2010.07.24 15:06:42 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Admin\Desktop\OTL.exe
[2010.07.22 12:12:25 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Admin\Eigene Dateien
[2010.07.22 12:12:25 | 000,000,000 | ---D | C] -- D:\Access Connections
[2010.07.22 03:07:36 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINXP\System32\drivers\mbamswissarmy.sys
[2010.07.22 03:07:35 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINXP\System32\drivers\mbam.sys
[2010.07.22 03:07:35 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2010.07.22 02:27:09 | 000,000,000 | R--D | C] -- D:\Eigene Musik
[2010.07.22 02:27:09 | 000,000,000 | R--D | C] -- D:\Eigene Bilder
[2010.07.22 02:27:09 | 000,000,000 | ---D | C] -- D:\Simply Super Software
[2010.07.22 02:27:09 | 000,000,000 | ---D | C] -- D:\Shrew Soft VPN
[2010.07.22 02:27:09 | 000,000,000 | ---D | C] -- D:\Downloads
[2010.07.22 02:10:06 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2010.07.22 01:52:42 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SITEguard
[2010.07.22 01:51:53 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\iS3
[2010.07.22 01:51:52 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\STOPzilla!
[2010.07.22 01:04:54 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
[2010.07.22 00:51:19 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\ztvcabinet.dll
[2010.07.22 00:51:18 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Simply Super Software
[2010.07.22 00:37:03 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Admin\Desktop\remove-vundo-virtumonde-Dateien
[2010.07.22 00:34:29 | 006,153,648 | ---- | C] (Malwarebytes Corporation ) -- C:\Dokumente und Einstellungen\Admin\Desktop\mbam-setup.exe
[2010.07.21 21:52:08 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Sun
[2010.07.21 21:52:07 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Java
[2010.07.21 21:51:50 | 000,423,656 | ---- | C] (Oracle) -- C:\WINXP\System32\deployJava1.dll
[2010.07.21 21:51:50 | 000,153,376 | ---- | C] (Oracle) -- C:\WINXP\System32\javaws.exe
[2010.07.21 21:51:50 | 000,145,184 | ---- | C] (Oracle) -- C:\WINXP\System32\javaw.exe
[2010.07.21 21:51:50 | 000,145,184 | ---- | C] (Oracle) -- C:\WINXP\System32\java.exe
[2010.07.21 21:51:50 | 000,073,728 | ---- | C] (Oracle) -- C:\WINXP\System32\javacpl.cpl
[2010.07.21 21:51:33 | 000,000,000 | ---D | C] -- C:\Programme\Java
[2010.07.21 20:23:52 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.07.21 18:51:05 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Admin\Desktop\index-Dateien
[2010.07.21 17:48:30 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Admin\Desktop\topic330703-Dateien
[2010.07.21 14:49:50 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Admin\Anwendungsdaten\Malwarebytes
[2010.07.21 14:49:38 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2010.07.21 14:26:55 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010.07.21 14:19:26 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\Admin\Recent
[2010.07.21 14:01:00 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.07.21 13:56:27 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINXP\SWXCACLS.exe
[2010.07.21 13:56:27 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINXP\SWREG.exe
[2010.07.21 13:56:27 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINXP\SWSC.exe
[2010.07.21 13:56:27 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINXP\NIRCMD.exe
[2010.07.21 13:55:49 | 000,000,000 | ---D | C] -- C:\WINXP\ERDNT
[2010.07.21 13:47:57 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.07.21 13:44:05 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Admin\Desktop\51943-virtumonde-dll-Dateien
[2010.07.21 13:44:00 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Admin\Desktop\vundofixx-Dateien
[2010.07.18 01:40:11 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Admin\Desktop\m
[2010.07.15 21:37:45 | 000,012,536 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINXP\System32\avgrsstx.dll
[2010.07.15 02:20:46 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Admin\Desktop\Delo
[2010.07.12 12:21:37 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Admin\Desktop\greenjobs
[2010.07.09 16:34:23 | 000,000,000 | ---D | C] -- C:\Programme\CCleaner
[2010.07.09 11:33:10 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\NetworkService\Anwendungsdaten\Macromedia
[2010.07.09 05:02:32 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Adobe
[2010.07.09 05:02:21 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\NetworkService\Anwendungsdaten\Sun
[2010.07.09 04:38:30 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2010.07.09 02:32:44 | 000,000,000 | ---D | C] -- C:\Programme\Spybot - Search & Destroy
[2010.07.09 02:32:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy
[2010.07.08 18:38:29 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\NetworkService\Anwendungsdaten\Adobe
[2010.07.06 18:45:52 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Admin\Desktop\reweb2.ReWEB-Dateien
[2010.06.29 01:04:22 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Admin\Desktop\Bewerbungsmappe
[2010.06.28 01:45:18 | 000,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\mstee.sys
[2010.06.28 01:45:14 | 000,010,880 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\ndisip.sys
[2010.06.28 01:45:11 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\ipsink.ax
[2010.06.28 01:45:11 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\ipsink.ax
[2010.06.28 01:45:11 | 000,015,232 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\streamip.sys
[2010.06.28 01:45:09 | 000,011,136 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\slip.sys
[2010.06.28 01:45:07 | 000,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\wstcodec.sys
[2010.06.28 01:45:04 | 000,085,248 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\nabtsfec.sys
[2010.06.28 01:45:02 | 000,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\ccdecode.sys
[2010.06.28 01:44:55 | 000,060,032 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\drivers\USBAUDIO.sys
[2010.06.28 01:44:55 | 000,060,032 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\usbaudio.sys
[2010.06.28 01:44:47 | 000,121,984 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\usbvideo.sys
[2010.06.28 01:44:47 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\kswdmcap.ax
[2010.06.28 01:44:47 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\kswdmcap.ax
[2010.06.28 01:44:47 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\kstvtune.ax
[2010.06.28 01:44:47 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\kstvtune.ax
[2010.06.28 01:44:47 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\vfwwdm32.dll
[2010.06.28 01:44:47 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\vfwwdm32.dll
[2010.06.28 01:44:47 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\ksxbar.ax
[2010.06.28 01:44:47 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\ksxbar.ax
[2010.06.28 01:44:47 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\vidcap.ax
[2010.06.28 01:44:47 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\vidcap.ax
[2010.06.28 01:44:46 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dshowext.ax
[2010.06.28 01:44:46 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\dshowext.ax
[2010.06.28 01:44:42 | 000,032,128 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\usbccgp.sys
[7 C:\WINXP\*.tmp files -> C:\WINXP\*.tmp -> ]
[1 C:\WINXP\System32\*.tmp files -> C:\WINXP\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.07.24 15:05:49 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Admin\Desktop\OTL.exe
[2010.07.24 15:05:01 | 000,001,088 | ---- | M] () -- C:\WINXP\tasks\GoogleUpdateTaskMachineUA.job
[2010.07.24 14:54:07 | 062,436,221 | ---- | M] () -- C:\WINXP\System32\drivers\Avg\incavi.avm
[2010.07.24 14:50:26 | 000,000,300 | ---- | M] () -- C:\WINXP\tasks\PMTask.job
[2010.07.24 14:48:25 | 000,002,206 | ---- | M] () -- C:\WINXP\System32\wpa.dbl
[2010.07.24 14:48:23 | 000,001,084 | ---- | M] () -- C:\WINXP\tasks\GoogleUpdateTaskMachineCore.job
[2010.07.24 14:48:19 | 000,025,169 | ---- | M] () -- C:\WINXP\System32\PROCDB.INI
[2010.07.24 14:48:11 | 000,000,380 | ---- | M] () -- C:\WINXP\System32\IPSCtrl.INI
[2010.07.24 14:47:59 | 000,000,006 | -H-- | M] () -- C:\WINXP\tasks\SA.DAT
[2010.07.24 14:47:57 | 000,002,048 | --S- | M] () -- C:\WINXP\bootstat.dat
[2010.07.24 14:47:55 | 2137,436,160 | -HS- | M] () -- C:\hiberfil.sys
[2010.07.24 07:33:38 | 004,718,592 | -H-- | M] () -- C:\Dokumente und Einstellungen\Admin\NTUSER.DAT
[2010.07.24 07:33:38 | 000,000,190 | -HS- | M] () -- C:\Dokumente und Einstellungen\Admin\ntuser.ini
[2010.07.24 07:33:31 | 004,312,686 | -H-- | M] () -- C:\Dokumente und Einstellungen\Admin\Lokale Einstellungen\Anwendungsdaten\IconCache.db
[2010.07.24 01:13:55 | 000,000,200 | ---- | M] () -- C:\WINXP\vwr.INI
[2010.07.23 16:04:31 | 004,563,109 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\folien_markov_switching.pdf
[2010.07.23 15:17:50 | 000,291,835 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\art3.pdf
[2010.07.23 13:26:00 | 000,060,020 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\Spybot_screenshot.JPG
[2010.07.22 03:37:33 | 000,023,076 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\Spybot - Search & Destroy scan report.pdf
[2010.07.22 03:07:38 | 000,000,676 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.07.22 02:37:34 | 065,890,018 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\reg.reg
[2010.07.22 01:55:30 | 000,016,384 | -H-- | M] () -- D:\SZKGFS.dat
[2010.07.22 01:55:30 | 000,016,384 | -H-- | M] () -- C:\SZKGFS.dat
[2010.07.22 01:46:46 | 078,708,793 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\Bewerbungen.rar
[2010.07.22 00:37:04 | 000,043,172 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\remove-vundo-virtumonde.htm
[2010.07.21 21:51:38 | 000,423,656 | ---- | M] (Oracle) -- C:\WINXP\System32\deployJava1.dll
[2010.07.21 21:51:38 | 000,153,376 | ---- | M] (Oracle) -- C:\WINXP\System32\javaws.exe
[2010.07.21 21:51:38 | 000,145,184 | ---- | M] (Oracle) -- C:\WINXP\System32\javaw.exe
[2010.07.21 21:51:38 | 000,145,184 | ---- | M] (Oracle) -- C:\WINXP\System32\java.exe
[2010.07.21 21:51:38 | 000,073,728 | ---- | M] (Oracle) -- C:\WINXP\System32\javacpl.cpl
[2010.07.21 18:51:06 | 000,095,933 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\index.htm
[2010.07.21 17:48:32 | 000,141,049 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\topic330703.html
[2010.07.21 14:49:11 | 006,153,648 | ---- | M] (Malwarebytes Corporation ) -- C:\Dokumente und Einstellungen\Admin\Desktop\mbam-setup.exe
[2010.07.21 14:36:03 | 000,000,227 | ---- | M] () -- C:\WINXP\system.ini
[2010.07.21 14:11:51 | 000,000,027 | ---- | M] () -- C:\WINXP\System32\drivers\etc\hosts
[2010.07.21 14:01:08 | 000,000,304 | RHS- | M] () -- C:\boot.ini
[2010.07.21 13:46:13 | 003,739,613 | R--- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\ComboFix.exe
[2010.07.21 13:44:24 | 000,017,393 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\vundofixx.html
[2010.07.21 13:44:06 | 000,057,623 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\51943-virtumonde-dll.html
[2010.07.21 03:44:58 | 000,011,773 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\Lia.docx
[2010.07.19 14:24:11 | 000,036,864 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\Kopie von 28-Kw-10 Berufsanfänger u. Praktikanten.xls
[2010.07.18 16:31:24 | 000,098,600 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\kreditrisiko.pdf
[2010.07.18 01:28:11 | 000,002,237 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Skype.lnk
[2010.07.17 16:01:53 | 000,054,474 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\photo.JPG
[2010.07.17 15:58:37 | 000,126,171 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\bfoto.JPG
[2010.07.15 21:37:47 | 000,243,024 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINXP\System32\drivers\avgtdix.sys
[2010.07.15 21:37:45 | 000,012,536 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINXP\System32\avgrsstx.dll
[2010.07.15 21:37:39 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINXP\System32\drivers\avgldx86.sys
[2010.07.09 11:39:28 | 000,001,705 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader 9.lnk
[2010.07.09 06:07:45 | 000,000,664 | ---- | M] () -- C:\WINXP\System32\d3d9caps.dat
[2010.07.09 02:32:53 | 000,000,905 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\Spybot - Search & Destroy.lnk
[2010.07.06 18:45:52 | 000,028,296 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\reweb2.ReWEB.htm
[2010.07.05 21:28:07 | 000,134,928 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\jobsearch.ftl
[2010.07.05 18:57:44 | 000,011,089 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\anschreiben.docx
[2010.06.28 22:20:33 | 000,009,216 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.06.28 02:29:42 | 000,010,185 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\003902205721333.docx
[2010.06.28 01:57:52 | 001,263,523 | ---- | M] () -- C:\Dokumente und Einstellungen\Admin\Desktop\dog.docx
[7 C:\WINXP\*.tmp files -> C:\WINXP\*.tmp -> ]
[1 C:\WINXP\System32\*.tmp files -> C:\WINXP\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.07.23 16:04:31 | 004,563,109 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\folien_markov_switching.pdf
[2010.07.23 15:17:50 | 000,291,835 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\art3.pdf
[2010.07.23 13:26:00 | 000,060,020 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\Spybot_screenshot.JPG
[2010.07.22 03:37:32 | 000,023,076 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\Spybot - Search & Destroy scan report.pdf
[2010.07.22 03:07:38 | 000,000,676 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.07.22 02:37:29 | 065,890,018 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\reg.reg
[2010.07.22 01:55:30 | 000,016,384 | -H-- | C] () -- D:\SZKGFS.dat
[2010.07.22 01:55:30 | 000,016,384 | -H-- | C] () -- C:\SZKGFS.dat
[2010.07.22 01:45:40 | 078,708,793 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\Bewerbungen.rar
[2010.07.22 00:51:19 | 000,162,304 | ---- | C] () -- C:\WINXP\System32\ztvunrar36.dll
[2010.07.22 00:51:19 | 000,153,088 | ---- | C] () -- C:\WINXP\System32\UNRAR3.dll
[2010.07.22 00:51:19 | 000,075,264 | ---- | C] () -- C:\WINXP\System32\unacev2.dll
[2010.07.22 00:37:03 | 000,043,172 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\remove-vundo-virtumonde.htm
[2010.07.21 21:49:12 | 2137,436,160 | -HS- | C] () -- C:\hiberfil.sys
[2010.07.21 18:51:04 | 000,095,933 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\index.htm
[2010.07.21 17:48:29 | 000,141,049 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\topic330703.html
[2010.07.21 14:01:08 | 000,000,234 | ---- | C] () -- C:\Boot.bak
[2010.07.21 14:01:03 | 000,262,448 | ---- | C] () -- C:\cmldr
[2010.07.21 13:56:27 | 000,256,512 | ---- | C] () -- C:\WINXP\PEV.exe
[2010.07.21 13:56:27 | 000,098,816 | ---- | C] () -- C:\WINXP\sed.exe
[2010.07.21 13:56:27 | 000,080,412 | ---- | C] () -- C:\WINXP\grep.exe
[2010.07.21 13:56:27 | 000,077,312 | ---- | C] () -- C:\WINXP\MBR.exe
[2010.07.21 13:56:27 | 000,068,096 | ---- | C] () -- C:\WINXP\zip.exe
[2010.07.21 13:45:49 | 003,739,613 | R--- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\ComboFix.exe
[2010.07.21 13:44:24 | 000,017,393 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\vundofixx.html
[2010.07.21 13:44:05 | 000,057,623 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\51943-virtumonde-dll.html
[2010.07.21 12:00:46 | 000,011,995 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\hs_err_pid5316.log
[2010.07.20 19:54:57 | 000,011,773 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\Lia.docx
[2010.07.19 14:24:10 | 000,036,864 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\Kopie von 28-Kw-10 Berufsanfänger u. Praktikanten.xls
[2010.07.18 16:31:24 | 000,098,600 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\kreditrisiko.pdf
[2010.07.17 15:59:42 | 000,054,474 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\photo.JPG
[2010.07.17 15:58:37 | 000,126,171 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\bfoto.JPG
[2010.07.09 11:39:28 | 000,001,705 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader 9.lnk
[2010.07.09 06:07:45 | 000,000,664 | ---- | C] () -- C:\WINXP\System32\d3d9caps.dat
[2010.07.09 02:32:53 | 000,000,905 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\Spybot - Search & Destroy.lnk
[2010.07.06 18:45:52 | 000,028,296 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\reweb2.ReWEB.htm
[2010.07.05 21:28:06 | 000,134,928 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\jobsearch.ftl
[2010.06.28 01:45:47 | 001,263,523 | ---- | C] () -- C:\Dokumente und Einstellungen\Admin\Desktop\dog.docx
[2010.05.29 16:16:20 | 000,000,200 | ---- | C] () -- C:\WINXP\vwr.INI
[2010.03.20 19:58:07 | 000,116,224 | ---- | C] () -- C:\WINXP\System32\pdfcmnnt.dll
[2010.03.17 23:17:55 | 000,717,296 | ---- | C] () -- C:\WINXP\System32\drivers\sptd.sys
[2010.03.17 23:17:05 | 000,164,352 | ---- | C] () -- C:\WINXP\System32\unrar.dll
[2010.03.17 23:17:02 | 003,596,288 | ---- | C] () -- C:\WINXP\System32\qt-dx331.dll
[2010.03.17 23:17:02 | 001,559,040 | ---- | C] () -- C:\WINXP\System32\xvidcore.dll
[2010.03.17 23:17:02 | 000,282,624 | ---- | C] () -- C:\WINXP\System32\xvidvfw.dll
[2010.03.17 23:17:01 | 000,007,680 | ---- | C] () -- C:\WINXP\System32\ff_vfw.dll
[2010.03.17 23:17:01 | 000,000,547 | ---- | C] () -- C:\WINXP\System32\ff_vfw.dll.manifest
[2010.03.17 23:00:24 | 000,004,224 | ---- | C] () -- C:\WINXP\System32\drivers\IBMBLDID.sys
[2010.03.17 22:59:03 | 000,004,442 | ---- | C] () -- C:\WINXP\System32\drivers\TPPWRIF.SYS
[2010.03.17 22:01:25 | 000,004,608 | ---- | C] () -- C:\WINXP\System32\drivers\TSMAPIP.SYS
[2009.08.14 11:47:34 | 002,854,976 | ---- | C] () -- C:\WINXP\System32\btwicons.dll
[2007.06.19 14:13:40 | 000,000,380 | ---- | C] () -- C:\WINXP\System32\IPSCtrl.INI
[2007.01.29 11:36:32 | 000,025,169 | ---- | C] () -- C:\WINXP\System32\PROCDB.INI
[2005.02.17 12:41:32 | 000,000,603 | ---- | C] () -- C:\WINXP\System32\BTNeighborhood.dll.manifest
[2005.02.17 12:41:30 | 000,000,593 | ---- | C] () -- C:\WINXP\System32\btcss.dll.manifest
[2001.11.14 13:56:00 | 001,802,240 | ---- | C] () -- C:\WINXP\System32\lcppn21.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 102 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:CB0AACC9
< End of report > --- --- ---
Bin gespannt auf deine Antwort!
Liebe Grüße, Reinhard |