OTL Logfile: Code:
OTL logfile created on: 12.09.2010 22:29:31 - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Dokumente und Einstellungen\Mario\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 80,00% Memory free
5,00 Gb Paging File | 4,00 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 56,64 Gb Total Space | 11,66 Gb Free Space | 20,59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 88,09 Gb Total Space | 65,99 Gb Free Space | 74,92% Space Free | Partition Type: NTFS
Drive G: | 88,16 Gb Total Space | 53,19 Gb Free Space | 60,34% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: AMD6000
Current User Name: Mario
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Dokumente und Einstellungen\Mario\Desktop\OTL.exe (OldTimer Tools)
PRC - F:\teamspeak2\ts3client_win32.exe (TeamSpeak Systems GmbH)
PRC - C:\WINDOWS\system32\npkcmsvc.exe (INCA Internet Co., Ltd.)
PRC - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Programme\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA Corporation)
PRC - C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA Corporation)
PRC - C:\Programme\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Dokumente und Einstellungen\Mario\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (NIHardwareService) -- C:\Programme\Gemeinsame Dateien\Native Instruments\Hardware\NIHardwareService.exe File not found
SRV - (HidServ) -- C:\WINDOWS\System32\hidserv.dll File not found
SRV - (Akamai) -- C:/Programme/Gemeinsame Dateien/Akamai/rswin_3746.dll ()
SRV - (npkcmsvc) -- C:\WINDOWS\system32\npkcmsvc.exe (INCA Internet Co., Ltd.)
SRV - (getPlusHelper) getPlus(R) -- C:\Programme\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (npggsvc) -- C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (Application Updater) -- C:\Programme\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (AntiVirService) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (FLEXnet Licensing Service) -- C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (odserv) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (UxTuneUp) -- C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software GmbH)
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (nSvcIp) -- C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA Corporation)
SRV - (nSvcLog) -- C:\Programme\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA Corporation)
SRV - (ForcewareWebInterface) -- C:\Programme\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe (Apache Software Foundation)
SRV - (IDriverT) -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (MDM) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (XDva359) -- C:\WINDOWS\System32\XDva359.sys File not found
DRV - (XDva349) -- C:\WINDOWS\System32\XDva349.sys File not found
DRV - (SCREAMINGBDRIVER) -- C:\WINDOWS\System32\drivers\ScreamingBAudio.sys File not found
DRV - (GarenaPEngine) -- C:\DOKUME~1\Mario\LOKALE~1\Temp\VFD12.tmp File not found
DRV - (EagleNT) -- C:\WINDOWS\System32\drivers\EagleNT.sys File not found
DRV - (catchme) -- C:\DOKUME~1\Mario\LOKALE~1\Temp\catchme.sys File not found
DRV - (sptd) -- C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (npkcrypt) -- C:\WINDOWS\system32\npkcrypt.sys (INCA Internet Co., Ltd.)
DRV - (PSI) -- C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (avgio) -- C:\Programme\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (adfs) -- C:\WINDOWS\System32\drivers\adfs.sys (Adobe Systems, Inc.)
DRV - (hamachi) -- C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider)
DRV - (ADIHdAudAddService) -- C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (se44unic) Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (WDM) -- C:\WINDOWS\system32\drivers\se44unic.sys (MCCI)
DRV - (se44obex) -- C:\WINDOWS\system32\drivers\se44obex.sys (MCCI)
DRV - (se44nd5) Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (NDIS) -- C:\WINDOWS\system32\drivers\se44nd5.sys (MCCI)
DRV - (se44mgmt) Sony Ericsson Device 068 USB WMC Device Management Drivers (WDM) -- C:\WINDOWS\system32\drivers\se44mgmt.sys (MCCI)
DRV - (se44mdm) -- C:\WINDOWS\system32\drivers\se44mdm.sys (MCCI)
DRV - (se44mdfl) -- C:\WINDOWS\system32\drivers\se44mdfl.sys (MCCI)
DRV - (se44bus) Sony Ericsson Device 068 driver (WDM) -- C:\WINDOWS\system32\drivers\se44bus.sys (MCCI)
DRV - (mcdbus) -- C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (nvata) -- C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (sfsync04) StarForce Protection Synchronization Driver (version 4.x) -- C:\WINDOWS\System32\drivers\sfsync04.sys (Protection Technology (StarForce))
DRV - (nvnetbus) -- C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (sfdrv01a) StarForce Protection Environment Driver (version 1.x.a) -- C:\WINDOWS\System32\drivers\sfdrv01a.sys (Protection Technology (StarForce))
DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology (StarForce))
DRV - (SenFiltService) -- C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (MarvinBus) -- C:\WINDOWS\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (MTsensor) -- C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (PQNTDrv) -- C:\WINDOWS\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "hxxp://start.icq.com/"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.3
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q="
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Programme\Mozilla Firefox\components [2010.08.11 01:47:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2010.08.25 13:30:27 | 000,000,000 | ---D | M]
[2008.11.14 02:35:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Mozilla\Extensions
[2010.08.28 17:05:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Mozilla\Firefox\Profiles\7l95x0th.default\extensions
[2009.09.26 09:51:11 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Mozilla\Firefox\Profiles\7l95x0th.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.06.17 20:18:32 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Mozilla\Firefox\Profiles\7l95x0th.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010.05.01 20:10:05 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Mozilla\Firefox\Profiles\7l95x0th.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010.08.28 17:05:39 | 000,000,961 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Mozilla\Firefox\Profiles\7l95x0th.default\searchplugins\icqplugin-1.xml
[2009.04.07 00:44:30 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Mozilla\Firefox\Profiles\7l95x0th.default\searchplugins\icqplugin-2.xml
[2009.04.26 16:22:12 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Mozilla\Firefox\Profiles\7l95x0th.default\searchplugins\icqplugin-3.xml
[2009.04.29 19:30:31 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Mozilla\Firefox\Profiles\7l95x0th.default\searchplugins\icqplugin-4.xml
[2009.06.12 13:38:24 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Mozilla\Firefox\Profiles\7l95x0th.default\searchplugins\icqplugin-5.xml
[2009.07.25 18:23:42 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Mozilla\Firefox\Profiles\7l95x0th.default\searchplugins\icqplugin-6.xml
[2009.08.13 14:31:56 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Mozilla\Firefox\Profiles\7l95x0th.default\searchplugins\icqplugin-7.xml
[2009.10.17 23:04:10 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Mozilla\Firefox\Profiles\7l95x0th.default\searchplugins\icqplugin-8.xml
[2009.03.01 14:02:44 | 000,000,944 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Mozilla\Firefox\Profiles\7l95x0th.default\searchplugins\icqplugin.xml
[2010.08.28 17:05:39 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2009.03.14 17:04:29 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.05.03 19:04:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.04.12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.01.14 00:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npwachk.dll
[2010.03.15 19:18:25 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.03.15 19:18:25 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.03.15 19:18:25 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.03.15 19:18:25 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.03.15 19:18:25 | 000,000,801 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2010.08.28 22:17:29 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Programme\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SoundMAXPnP] C:\Programme\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - Startup: C:\Dokumente und Einstellungen\Mario\Startmenü\Programme\Autostart\ERUNT AutoBackup.lnk = C:\Programme\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Free YouTube Download - C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\DVDVideoSoftIEHelpers\youtubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} hxxp://www.srtest.com/srl_bin/sysreqlab_srl.cab (System Requirements Lab Class)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} hxxp://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab (Reg Error: Key error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab (DLM Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1208174604234 (WUWebControl Class)
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} hxxp://www.acclaim.com/cabs/acclaim_v5.cab (GameLauncher Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1208174678421 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} hxxp://clubgames.pogo.com/online2/pogop/diner_dash_flo_on_the_go/ddfotg.1.0.0.33.cab (CPlayFirstddfotgControl Object)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} hxxp://update.nprotect.net/keycrypt/cabal/npkcx_inca.cab (NPKCX Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Mario\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Mario\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.04.12 14:50:18 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010.09.12 22:28:26 | 000,576,000 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Mario\Desktop\OTL.exe
[2010.09.11 20:59:55 | 000,000,000 | ---D | C] -- C:\Lop SD
[2010.09.10 15:38:06 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.09.10 15:19:47 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.09.10 15:19:47 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.09.10 15:19:47 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.09.10 15:19:47 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.09.06 13:06:47 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmen³
[2010.09.06 12:13:49 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Akamai
[2010.09.03 00:10:51 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.09.03 00:10:50 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.09.02 02:43:27 | 000,000,000 | ---D | C] -- C:\Programme\ERUNT
[2010.08.23 15:16:13 | 000,000,000 | ---D | C] -- C:\Programme\NewBlue
[2010.08.23 11:28:07 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\Toolbar4
[2010.08.18 22:13:28 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\eSellerate
[2010.03.29 18:41:35 | 000,299,304 | ---- | C] (INCA Internet Co., Ltd.) -- C:\Programme\gameguard.des
========== Files - Modified Within 30 Days ==========
[2010.09.12 22:28:30 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Mario\Desktop\OTL.exe
[2010.09.12 22:01:09 | 000,127,919 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\noShow.JPG
[2010.09.12 20:54:27 | 000,084,080 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\321impact.zip
[2010.09.12 19:01:25 | 009,961,472 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\ntuser.dat
[2010.09.12 10:25:52 | 000,204,928 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010.09.12 10:25:49 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.09.12 10:22:41 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.09.12 10:22:40 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.09.11 20:26:50 | 000,000,190 | -HS- | M] () -- C:\Dokumente und Einstellungen\Mario\ntuser.ini
[2010.09.11 14:06:37 | 001,078,680 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.09.11 14:06:37 | 000,462,662 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2010.09.11 14:06:37 | 000,444,164 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.09.11 14:06:37 | 000,085,534 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2010.09.11 14:06:37 | 000,072,040 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.09.10 17:10:26 | 000,049,682 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\page_05_03.jpg
[2010.09.10 15:31:10 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.09.09 15:32:50 | 000,054,197 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\your_cats_dance_better_than_you.jpg
[2010.09.08 23:22:05 | 000,189,733 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\Shot00057.PNG
[2010.09.07 12:10:20 | 000,054,896 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\ScreenShot0907120930.PNG
[2010.09.06 16:31:01 | 000,609,429 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\Super Secret.rar
[2010.09.06 16:18:04 | 000,000,569 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\BlackShot.lnk
[2010.09.06 13:06:49 | 000,000,550 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\LOCO.lnk
[2010.09.05 01:48:22 | 001,502,970 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\DogLegHumpPedoBear.gif
[2010.09.05 01:42:56 | 000,027,270 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\katze.jpg
[2010.09.05 01:42:22 | 000,011,080 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\hässlich.jpg
[2010.09.04 13:08:17 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.09.04 12:32:21 | 000,209,920 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.09.04 12:18:06 | 004,077,696 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\Snow white Sky (After Effects Text Animation).mp3
[2010.09.04 11:42:55 | 006,152,320 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\Frozen Plasma - Forgotten Earth [S.E.].mp3
[2010.09.03 00:18:55 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\defogger_reenable
[2010.09.02 02:43:35 | 000,000,749 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Startmenü\Programme\Autostart\ERUNT AutoBackup.lnk
[2010.09.02 00:11:56 | 009,855,333 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\TS3 Soundpack.rar
[2010.08.31 16:13:39 | 000,000,349 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Dokumente\PCLECHAL.INI
[2010.08.31 16:00:54 | 000,001,917 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.08.30 10:44:40 | 000,199,315 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Eigene Dateien\ts3_clientui-win32-12040-2010-08-30 10_44_39.875000.dmp
[2010.08.28 22:17:29 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.08.27 03:04:26 | 000,127,280 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT
[2010.08.26 10:00:23 | 002,261,360 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.08.26 00:24:59 | 000,002,928 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Eigene Dateien\news.htm
[2010.08.25 14:01:11 | 000,000,359 | ---- | M] () -- C:\WINDOWS\CleaningLab.INI
[2010.08.23 12:30:04 | 000,000,437 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Desktop\Fraps.lnk
[2010.08.17 14:05:12 | 000,012,433 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Eigene Dateien\member.htm
[2010.08.17 13:44:16 | 000,001,145 | ---- | M] () -- C:\Dokumente und Einstellungen\Mario\Eigene Dateien\conatct.htm
========== Files Created - No Company Name ==========
[2010.09.12 22:01:09 | 000,127,919 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\noShow.JPG
[2010.09.12 20:54:26 | 000,084,080 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\321impact.zip
[2010.09.12 16:26:58 | 000,049,682 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\page_05_03.jpg
[2010.09.10 15:19:47 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.09.10 15:19:47 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.09.10 15:19:47 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.09.09 15:33:10 | 000,054,197 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\your_cats_dance_better_than_you.jpg
[2010.09.08 23:19:07 | 000,189,733 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\Shot00057.PNG
[2010.09.07 12:10:20 | 000,054,896 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\ScreenShot0907120930.PNG
[2010.09.06 16:30:58 | 000,609,429 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\Super Secret.rar
[2010.09.06 16:18:04 | 000,000,569 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\BlackShot.lnk
[2010.09.06 13:06:48 | 000,000,550 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\LOCO.lnk
[2010.09.05 01:48:47 | 001,502,970 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\DogLegHumpPedoBear.gif
[2010.09.05 01:44:34 | 000,011,080 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\hässlich.jpg
[2010.09.05 01:43:59 | 000,027,270 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\katze.jpg
[2010.09.04 12:17:46 | 004,077,696 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\Snow white Sky (After Effects Text Animation).mp3
[2010.09.04 11:42:32 | 006,152,320 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\Frozen Plasma - Forgotten Earth [S.E.].mp3
[2010.09.03 00:18:55 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\defogger_reenable
[2010.09.02 02:43:35 | 000,000,749 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Startmenü\Programme\Autostart\ERUNT AutoBackup.lnk
[2010.09.02 00:11:42 | 009,855,333 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\TS3 Soundpack.rar
[2010.08.31 16:00:50 | 000,001,917 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2010.08.30 10:44:39 | 000,199,315 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Eigene Dateien\ts3_clientui-win32-12040-2010-08-30 10_44_39.875000.dmp
[2010.08.23 12:30:04 | 000,000,437 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Desktop\Fraps.lnk
[2010.07.24 12:47:35 | 000,528,760 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2010.05.04 01:09:02 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2010.05.04 01:09:02 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2010.05.04 01:09:02 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2010.03.29 18:41:35 | 001,860,480 | ---- | C] () -- C:\Programme\cabalmain.exe
[2010.03.29 18:41:35 | 001,349,455 | ---- | C] () -- C:\Programme\unins000.exe
[2010.03.29 18:41:35 | 000,092,783 | ---- | C] () -- C:\Programme\unins000.dat
[2010.03.29 18:41:35 | 000,003,428 | ---- | C] () -- C:\Programme\xdata.enc
[2010.02.17 17:52:30 | 000,000,153 | ---- | C] () -- C:\WINDOWS\abfindungsrechner.INI
[2010.02.02 19:10:40 | 000,000,126 | ---- | C] () -- C:\WINDOWS\magix.ini
[2010.01.17 10:02:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VIDEOD~1.INI
[2009.12.16 22:54:52 | 000,484,352 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2009.10.23 22:13:00 | 000,000,492 | ---- | C] () -- C:\WINDOWS\PT2Key-eng.ini
[2009.06.10 04:46:41 | 000,000,075 | ---- | C] () -- C:\WINDOWS\PT2Key-ger.ini
[2009.03.28 01:59:21 | 000,000,040 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ra3.ini
[2009.01.18 21:11:40 | 000,001,091 | ---- | C] () -- C:\WINDOWS\cPVAS.INI
[2009.01.18 20:59:52 | 000,001,250 | ---- | C] () -- C:\WINDOWS\PVAStrumento.ini
[2009.01.16 15:56:46 | 001,015,808 | ---- | C] () -- C:\WINDOWS\System32\MPEG4Evfw.dll
[2008.12.21 02:53:40 | 000,000,035 | ---- | C] () -- C:\WINDOWS\WorldBuilder.INI
[2008.12.17 17:43:46 | 000,589,824 | ---- | C] () -- C:\WINDOWS\System32\INICRYPTOSDK.dll
[2008.10.07 10:13:30 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008.10.07 10:13:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008.09.28 04:50:18 | 000,000,028 | ---- | C] () -- C:\WINDOWS\Robota.INI
[2008.09.28 04:49:40 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\mgxasio2.dll
[2008.09.28 04:48:55 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2008.09.28 04:47:53 | 000,006,768 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2008.08.16 05:51:28 | 000,000,144 | ---- | C] () -- C:\WINDOWS\Eudcedit.ini
[2008.06.12 15:33:24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MusicEditor.INI
[2008.05.17 20:51:58 | 000,000,359 | ---- | C] () -- C:\WINDOWS\CleaningLab.INI
[2008.05.13 21:24:01 | 000,138,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008.05.12 20:55:12 | 000,000,316 | ---- | C] () -- C:\WINDOWS\game.ini
[2008.04.27 11:47:27 | 000,209,920 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.04.27 04:58:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CLEANI~1.INI
[2008.04.22 17:30:43 | 000,022,328 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Anwendungsdaten\PnkBstrK.sys
[2008.04.21 15:15:42 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.04.14 14:54:08 | 000,000,138 | ---- | C] () -- C:\Dokumente und Einstellungen\Mario\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2008.04.13 08:06:16 | 000,000,508 | ---- | C] () -- C:\WINDOWS\Ulead32.ini
[2008.04.13 07:13:41 | 000,000,305 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\addr_file.html
[2008.04.13 07:11:18 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008.04.12 14:57:42 | 000,000,804 | ---- | C] () -- C:\WINDOWS\System32\AsusSetup.ini
[2008.04.12 14:57:42 | 000,000,276 | ---- | C] () -- C:\WINDOWS\System32\raidmgmt.ini
[2008.04.12 14:57:28 | 000,014,129 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2008.04.12 14:57:20 | 000,005,810 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2008.04.12 14:57:19 | 000,013,881 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008.04.12 14:57:11 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008.04.12 14:52:47 | 000,001,082 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2008.02.08 18:20:32 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\winOGL.dll
[2007.09.17 01:07:00 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007.09.17 01:07:00 | 001,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007.09.17 01:07:00 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007.09.17 01:07:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007.09.17 01:07:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007.06.27 17:13:51 | 000,512,000 | ---- | C] () -- C:\WINDOWS\System32\RegisterDialog.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 498 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:05EE1EEF
@Alternate Data Stream - 152 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:DFC5A2B2
< End of report > --- --- ---
OTL Logfile: Code:
OTL Extras logfile created on: 12.09.2010 22:29:31 - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Dokumente und Einstellungen\Mario\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 80,00% Memory free
5,00 Gb Paging File | 4,00 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 56,64 Gb Total Space | 11,66 Gb Free Space | 20,59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 88,09 Gb Total Space | 65,99 Gb Free Space | 74,92% Space Free | Partition Type: NTFS
Drive G: | 88,16 Gb Total Space | 53,19 Gb Free Space | 60,34% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: AMD6000
Current User Name: Mario
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Programme\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Programme\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Programme\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Programme\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"28910:TCP" = 28910:TCP:*:Enabled:c&c
"29900:TCP" = 29900:TCP:*:Enabled:c&c
"29920:TCP" = 29920:TCP:*:Enabled:c&c
"4321:UDP" = 4321:UDP:*:Enabled:c&c
"27900:UDP" = 27900:UDP:*:Enabled:c&c
"26000:UDP" = 26000:UDP:*:Enabled:empire
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
"59066:TCP" = 59066:TCP:*:Enabled:Pando Media Booster
"59066:UDP" = 59066:UDP:*:Enabled:Pando Media Booster
"12000:UDP" = 12000:UDP:*:Enabled:Blackshot
"10002:UDP" = 10002:UDP:*:Enabled:Blackshot
"10005:UDP" = 10005:UDP:*:Enabled:Blackshot
"12000:TCP" = 12000:TCP:*:Enabled:Blackshot
"30001:TCP" = 30001:TCP:*:Enabled:Blackshot
"23:TCP" = 23:TCP:*:Enabled:Blackshot
"1033:TCP" = 1033:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Programme\FlashFXP\FlashFXP.exe" = C:\Programme\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (IniCom Networks, Inc.)
"G:\Programme\combatarms\Combat Arms\CombatArms.exe" = G:\Programme\combatarms\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe -- File not found
"G:\Programme\combatarms\Combat Arms\Engine.exe" = G:\Programme\combatarms\Combat Arms\Engine.exe:*Enabled:Engine.exe -- File not found
"G:\combatARMS\Combat Arms EU\CombatArms.exe" = G:\combatARMS\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe -- File not found
"G:\combatARMS\Combat Arms EU\Engine.exe" = G:\combatARMS\Combat Arms EU\Engine.exe:*Enabled:Engine.exe -- File not found
"C:\Programme\Windows Live\Messenger\wlcsdk.exe" = C:\Programme\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Programme\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe" = C:\Programme\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server -- (Apache Software Foundation)
"C:\Programme\FlashFXP\FlashFXP.exe" = C:\Programme\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (IniCom Networks, Inc.)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\Programme\Hamachi\hamachi.exe" = C:\Programme\Hamachi\hamachi.exe:*:Enabled:Hamachi Client -- (LogMeIn Inc.)
"C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NexonUS\NGM\NGM.exe" = C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager -- (Nexon)
"C:\Programme\EA Games\Command and Conquer Generäle\game.dat" = C:\Programme\EA Games\Command and Conquer Generäle\game.dat:*:Enabled:game -- ()
"C:\Programme\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Programme\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Programme\Microsoft Office\Office12\GROOVE.EXE" = C:\Programme\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove -- (Microsoft Corporation)
"C:\Programme\Microsoft Office\Office12\ONENOTE.EXE" = C:\Programme\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation)
"C:\Programme\Electronic Arts\EADM\Core.exe" = C:\Programme\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager -- (Electronic Arts)
"C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.3.game" = C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.3.game:*:Enabled:Command & Conquer™ Red Alert™ 3 -- (Electronic Arts Inc.)
"C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.4.game" = C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.4.game:*:Enabled:Command & Conquer™ Red Alert™ 3 -- (Electronic Arts Inc.)
"F:\Programme\Nero 7\Nero Home\NeroHome.exe" = F:\Programme\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home -- (Nero AG)
"C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.5.game" = C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.5.game:*:Enabled:Command & Conquer™ Red Alert™ 3 -- (Electronic Arts Inc.)
"C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.6.game" = C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.6.game:*:Enabled:Command & Conquer™ Red Alert™ 3 -- (Electronic Arts Inc.)
"C:\Dokumente und Einstellungen\Mario\Desktop\leecher.exe" = C:\Dokumente und Einstellungen\Mario\Desktop\leecher.exe:*:Enabled:SBF Loader -- ()
"C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NexonEU\NGM\NGM.exe" = C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NexonEU\NGM\NGM.exe:*:Enabled:Nexon Game Manager -- (Nexon)
"C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.7.game" = C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.7.game:*:Enabled:Command & Conquer™ Red Alert™ 3 -- (Electronic Arts Inc.)
"C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.8.game" = C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.8.game:*:Enabled:Command & Conquer™ Red Alert™ 3 -- (Electronic Arts Inc.)
"C:\Programme\ICQ6.5\ICQ.exe" = C:\Programme\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.)
"G:\Metin2\metin2.bin" = G:\Metin2\metin2.bin:*:Enabled:metin2 -- ()
"C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.9.game" = C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.9.game:*:Enabled:Command & Conquer™ Red Alert™ 3 -- (Electronic Arts Inc.)
"C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.10.game" = C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.10.game:*:Enabled:Command & Conquer™ Red Alert™ 3 -- (Electronic Arts Inc.)
"C:\Programme\Java\jre6\bin\java.exe" = C:\Programme\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Programme\Gemeinsame Dateien\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Programme\Gemeinsame Dateien\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 -- (Adobe Systems Incorporated)
"C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.11.game" = C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.11.game:*:Enabled:Command & Conquer™ Red Alert™ 3 -- (Electronic Arts Inc.)
"C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.12.game" = C:\Programme\Electronic Arts\Alarmstufe Rot 3\Data\ra3_1.12.game:*:Enabled:Command & Conquer™ Red Alert™ 3 -- (Electronic Arts Inc.)
"G:\BLACK_SHOOT\BlackShot\Blackshot\system\BlackShot.exe" = G:\BLACK_SHOOT\BlackShot\Blackshot\system\BlackShot.exe:*:Enabled:BlackShot -- (Vertigo Games)
"C:\Programme\TeamViewer\Version5\TeamViewer.exe" = C:\Programme\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application -- (TeamViewer GmbH)
"G:\Metin2\metin2client.bin" = G:\Metin2\metin2client.bin:*:Enabled:metin2client -- ()
"C:\Programme\Adobe\Adobe After Effects CS4\Support Files\AfterFX.exe" = C:\Programme\Adobe\Adobe After Effects CS4\Support Files\AfterFX.exe:*:Enabled:Adobe After Effects CS4 -- (Adobe Systems Incorporated)
"F:\PINNACLE STUDIO 14\Programs\RM.exe" = F:\PINNACLE STUDIO 14\Programs\RM.exe:*:Enabled:Render Manager -- (Pinnacle Systems)
"F:\PINNACLE STUDIO 14\Programs\Studio.exe" = F:\PINNACLE STUDIO 14\Programs\Studio.exe:*:Enabled:Studio -- (Pinnacle Systems)
"F:\PINNACLE STUDIO 14\Programs\umi.exe" = F:\PINNACLE STUDIO 14\Programs\umi.exe:*:Enabled:umi -- (Pinnacle Systems)
"G:\eFusion\BlackShot\system\BlackShot.exe" = G:\eFusion\BlackShot\system\BlackShot.exe:*:Enabled:BlackShot -- (Vertigo Games)
"C:\Programme\Windows Live\Messenger\wlcsdk.exe" = C:\Programme\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"G:\Alaplaya\LOCO\System\LOCO.exe" = G:\Alaplaya\LOCO\System\LOCO.exe:*:Enabled:LOCO -- ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.4 - Deutsch
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"Akamai" = Akamai NetSession Interface
"BlackShot" = BlackShot Á¦°Å
"ERUNT_is1" = ERUNT 1.1j
"Fraps" = Fraps (remove only)
"HijackThis" = HijackThis 2.0.2
"LOCO" = LOCO EU
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"NewBlue Art Blends 2.0 for Vegas" = NewBlue Art Blends 2.0 for Vegas
"NewBlue Art Effects 2.0 for Vegas" = NewBlue Art Effects 2.0 for Vegas
"NewBlue Film Effects for Vegas" = NewBlue Film Effects for Vegas
"NewBlue Motion Blends 2.0 for Vegas" = NewBlue Motion Blends 2.0 for Vegas
"NewBlue Motion Effects 2.0 for Vegas" = NewBlue Motion Effects 2.0 for Vegas
"NewBlue Video Essentials 1.0 for Windows" = NewBlue Video Essentials 1.0 for Windows
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Erkennungs-Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 02.09.2010 18:30:00 | Computer Name = AMD6000 | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung OTL.exe, Version 3.2.11.0, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 03.09.2010 18:54:46 | Computer Name = AMD6000 | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung ts3client_win32.exe, Version 1.0.0.0, fehlgeschlagenes
Modul fmodex.dll, Version 0.4.31.2, Fehleradresse 0x0007fb8c.
Error - 04.09.2010 05:52:16 | Computer Name = AMD6000 | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung moviemk.exe, Version 2.1.4028.0, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 04.09.2010 15:17:41 | Computer Name = AMD6000 | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung iexplore.exe, Version 8.0.6001.18702, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 06.09.2010 09:55:21 | Computer Name = AMD6000 | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung Patcher.exe, Version 1.1.2.33, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 08.09.2010 10:22:24 | Computer Name = AMD6000 | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung Patcher.exe, Version 1.1.2.33, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 09.09.2010 03:28:32 | Computer Name = AMD6000 | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung javaw.exe, Version 6.0.200.2, fehlgeschlagenes
Modul java.dll, Version 6.0.200.2, Fehleradresse 0x00005875.
Error - 09.09.2010 17:22:53 | Computer Name = AMD6000 | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung iexplore.exe, Version 8.0.6001.18702, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 10.09.2010 11:23:16 | Computer Name = AMD6000 | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung gimp-2.6.exe, Version 0.0.0.0, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 10.09.2010 15:20:02 | Computer Name = AMD6000 | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung blackshot.exe, Version 0.0.3.113, fehlgeschlagenes
Modul , Version 0.0.0.0, Fehleradresse 0x00000000.
[ OSession Events ]
Error - 28.06.2009 05:30:50 | Computer Name = AMD6000 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 5
seconds with 0 seconds of active time. This session ended with a crash.
Error - 28.06.2009 05:31:02 | Computer Name = AMD6000 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.
Error - 28.06.2009 05:31:11 | Computer Name = AMD6000 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 5
seconds with 0 seconds of active time. This session ended with a crash.
Error - 28.06.2009 05:31:23 | Computer Name = AMD6000 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 8
seconds with 0 seconds of active time. This session ended with a crash.
Error - 28.06.2009 05:31:38 | Computer Name = AMD6000 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 07.09.2010 12:44:19 | Computer Name = AMD6000 | Source = W32Time | ID = 39452701
Description = Der Zeitanbieter "NtpClient" wurde für die Zeiterfassung von mehreren
Zeitquellen konfiguriert. Es ist jedoch Keine der Quellen verfügbar. Innerhalb der
nächsten 15 Minuten wird kein Versuch unternommen, eine Verbindung mit der Quelle
herzustellen. Der NtpClient verfügt über keine Quelle mit genauer Zeit.
Error - 08.09.2010 02:02:41 | Computer Name = AMD6000 | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NIHardwareService" wurde aufgrund folgenden Fehlers nicht
gestartet: %%2
Error - 08.09.2010 07:53:00 | Computer Name = AMD6000 | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NIHardwareService" wurde aufgrund folgenden Fehlers nicht
gestartet: %%2
Error - 08.09.2010 13:03:22 | Computer Name = AMD6000 | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NIHardwareService" wurde aufgrund folgenden Fehlers nicht
gestartet: %%2
Error - 10.09.2010 05:10:44 | Computer Name = AMD6000 | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NIHardwareService" wurde aufgrund folgenden Fehlers nicht
gestartet: %%2
Error - 10.09.2010 09:24:10 | Computer Name = AMD6000 | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NIHardwareService" wurde aufgrund folgenden Fehlers nicht
gestartet: %%2
Error - 10.09.2010 09:38:42 | Computer Name = AMD6000 | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NIHardwareService" wurde aufgrund folgenden Fehlers nicht
gestartet: %%2
Error - 11.09.2010 08:02:35 | Computer Name = AMD6000 | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NIHardwareService" wurde aufgrund folgenden Fehlers nicht
gestartet: %%2
Error - 11.09.2010 14:58:28 | Computer Name = AMD6000 | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NIHardwareService" wurde aufgrund folgenden Fehlers nicht
gestartet: %%2
Error - 12.09.2010 04:23:56 | Computer Name = AMD6000 | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NIHardwareService" wurde aufgrund folgenden Fehlers nicht
gestartet: %%2
< End of report > --- --- --- |