Christian16 | 26.09.2010 17:26 | Extras.Txt:
"OTL Logfile: Code:
OTL Extras logfile created on: 26.09.2010 18:13:57 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Downloads
Windows XP Professional Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
511,00 Mb Total Physical Memory | 109,00 Mb Available Physical Memory | 21,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 53,00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 76,68 Gb Total Space | 6,09 Gb Free Space | 7,95% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1,86 Gb Total Space | 1,86 Gb Free Space | 99,90% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RENAS
Current User Name: christian
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Programme\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Programme\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{02C23509-87A8-4CFA-B6B9-713A078404AA}" = ESET NOD32 Antivirus
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"{13AD0F5B-FF8C-4625-851D-A83D4BE74716}" = Smart Menus (Windows Live Toolbar)
"{151ACDE2-C3AC-43AA-A77E-12A5D8B2A934}" = Popupblocker (Windows Live Toolbar)
"{18388EF8-E0A3-442B-8BFE-E2F1B3D05C91}" = iTunes
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22B099A6-55E1-4605-8401-05564320101C}" = Windows Live Outlook-Toolbar (Windows Live Toolbar)
"{279DB581-239C-4E13-97F8-0F48E40BE75C}" = Windows Live Messenger
"{28E151E2-A495-4C41-A94C-D3682E10F57E}" = Windows Live Toolbar
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A521923-1EDC-4EAC-83CF-4B2EAE132E84}_is1" = Duden Korrektor für OpenOffice.org
"{3A75BDE6-418E-4DB9-8601-C9E5225E0059}" = Feederkennung (Windows Live Toolbar)
"{3AF0CCF7-3D25-470A-91D3-ABBBA7F30327}" = OneCare Advisor (Windows Live Toolbar)
"{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}" = Google Earth
"{41482020-29DF-11D6-AFCB-0040052179B6}" = Virtua Tennis Demo
"{42095863-98D1-4A49-BDF8-638DE8A5F316}" = Sound Blaster Audigy 2
"{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{56F3E1FF-54FE-4384-A153-6CCABA097814}" = Creative MediaSource
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{6266BA75-45FA-4B1A-B21F-E04A90C273E5}" = Windows Live Toolbar-Erweiterung (Windows Live Toolbar)
"{672D0014-71A9-45EF-B10E-DEF7426961A6}" = Sibelius Scorch (Firefox, Opera, Netscape only)
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C503E58-B2BC-11D5-978A-0050BA84F5F7}" = Neverwinter Nights
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{A625D45F-1DC4-47FB-ABCF-6B27684AA717}" = OpenOffice.org 2.3
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio
"{CECFDD53-35DB-4235-9363-7964A0C88E0E}" = Samsung PC Studio
"{CF455208-C302-4FB3-B21D-F7CBB03DDE5A}" = Asheron's Call: Throne of Destiny
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{DA2C339B-A405-439B-AD24-07765EF9F233}" = Browsen mit Registerkarten (Windows Live Toolbar)
"{E0D51394-1D45-460A-B62D-383BC4F8B335}" = QuickTime
"{EB7E5D86-B84C-41A8-8BDA-7C854CA46153}" = Creative MuVo V100
"{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}" = Command and Conquer(TM) Generäle Die Stunde Null
"{FE67075F-48D5-42A8-863C-3FA7C5651BE1}" = Anno 1701 Demo
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Asheron's Call 2.0" = Asheron's Call 2
"AudibleManager" = AudibleManager
"AVS DVDMenu Editor_is1" = AVS DVDMenu Editor 1.2.1.19
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.2
"AVS4YOU Video ReMaker_is1" = AVS Video ReMaker 2.4
"Baphomets Fluch - Der schlafende Drache Demo" = Baphomets Fluch - Der schlafende Drache Demo
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Desperados 1.0" = Desperados 1.0
"Diablo II" = Diablo II
"DPF-1.1.0.413_is1" = Duden Proof Factory 1.1.0.413
"EAX Unified" = EAX Unified
"Everest Poker" = Everest Poker (Remove Only)
"ExpressBurn" = Express Burn
"Free FLV Converter_is1" = Free FLV Converter V 3.1
"Google Desktop" = Google Desktop
"Hamachi" = Hamachi 1.0.3.0
"Heroes of Might and Magic® III" = Heroes of Might and Magic® III Complete
"ICQToolbar" = ICQ Toolbar
"InstallShield_{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"InstallShield_{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}" = Command and Conquer(TM) Generäle Die Stunde Null
"InterVideo WinDVD" = InterVideo WinDVD
"IrfanView" = IrfanView (remove only)
"Launch of the Screaming Narwhal" = Tales of Monkey Island - Launch of the Screaming Narwhal
"LucasArts' Curse of Monkey Island" = LucasArts' Curse of Monkey Island
"LucasArts' Monkey4" = LucasArts' Monkey4
"Mafia" = Mafia
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"mIRC" = mIRC
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"Musicnotes Combined Installer_is1" = Musicnotes Software Suite 1.0
"Musicnotes Player" = Musicnotes Player
"NVIDIA Display Driver" = NVIDIA Display Driver
"Pharao" = Pharao
"PlayerRecoveryDriver" = Player Recovery Drivers
"Project IGI" = Project IGI
"RealPlayer 6.0" = RealPlayer
"SAMSUNG CDMA Modem" = SAMSUNG CDMA Modem Driver Set
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"ScummVM_is1" = ScummVM 0.10.0
"Sibelius Scorch Plugin" = Sibelius Scorch Plugin
"SysInfo" = Creative-Systeminformationen
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"tunebite_is1" = tunebite 3.0.1.8
"VideoReDo-Plus_is1" = VideoReDo/Plus Version 2.5.3.501
"WaveLabPro" = WaveLab 6
"WavePad" = WavePad Uninstall
"Windows Live Toolbar" = Windows Live Toolbar
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinRAR archiver" = WinRAR
"World of Warcraft" = World of Warcraft
"Yawle_0.3b" = YAWLE 0.5b
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1659004503-1604221776-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Steam App 10" = Counter-Strike
"Warcraft III" = Warcraft III: All Products
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 20.09.2010 07:29:47 | Computer Name = RENAS | Source = EventSystem | ID = 4609
Description = Das COM+-Ereignissystem hat einen ungültigen Rückgabecode während
der internen Verarbeitung erkannt. HRESULT war 8007041F von Zeile 44 von d:\nt_qxp\com\com1x\src\events\tier1\eventsystemobj.cpp.
Wenden Sie sich an den Microsoft-Produktsuppor
Error - 21.09.2010 18:16:38 | Computer Name = RENAS | Source = EventSystem | ID = 4609
Description = Das COM+-Ereignissystem hat einen ungültigen Rückgabecode während
der internen Verarbeitung erkannt. HRESULT war 8007041F von Zeile 44 von d:\nt_qxp\com\com1x\src\events\tier1\eventsystemobj.cpp.
Wenden Sie sich an den Microsoft-Produktsuppor
Error - 22.09.2010 15:27:47 | Computer Name = RENAS | Source = EventSystem | ID = 4609
Description = Das COM+-Ereignissystem hat einen ungültigen Rückgabecode während
der internen Verarbeitung erkannt. HRESULT war 8007041F von Zeile 44 von d:\nt_qxp\com\com1x\src\events\tier1\eventsystemobj.cpp.
Wenden Sie sich an den Microsoft-Produktsuppor
Error - 22.09.2010 16:23:57 | Computer Name = RENAS | Source = EventSystem | ID = 4609
Description = Das COM+-Ereignissystem hat einen ungültigen Rückgabecode während
der internen Verarbeitung erkannt. HRESULT war 8007041F von Zeile 44 von d:\nt_qxp\com\com1x\src\events\tier1\eventsystemobj.cpp.
Wenden Sie sich an den Microsoft-Produktsuppor
Error - 23.09.2010 07:02:13 | Computer Name = RENAS | Source = EventSystem | ID = 4609
Description = Das COM+-Ereignissystem hat einen ungültigen Rückgabecode während
der internen Verarbeitung erkannt. HRESULT war 8007041F von Zeile 44 von d:\nt_qxp\com\com1x\src\events\tier1\eventsystemobj.cpp.
Wenden Sie sich an den Microsoft-Produktsuppor
Error - 23.09.2010 09:50:59 | Computer Name = RENAS | Source = EventSystem | ID = 4609
Description = Das COM+-Ereignissystem hat einen ungültigen Rückgabecode während
der internen Verarbeitung erkannt. HRESULT war 8007041F von Zeile 44 von d:\nt_qxp\com\com1x\src\events\tier1\eventsystemobj.cpp.
Wenden Sie sich an den Microsoft-Produktsuppor
Error - 24.09.2010 12:27:08 | Computer Name = RENAS | Source = EventSystem | ID = 4609
Description = Das COM+-Ereignissystem hat einen ungültigen Rückgabecode während
der internen Verarbeitung erkannt. HRESULT war 8007041F von Zeile 44 von d:\nt_qxp\com\com1x\src\events\tier1\eventsystemobj.cpp.
Wenden Sie sich an den Microsoft-Produktsuppor
Error - 26.09.2010 11:28:20 | Computer Name = RENAS | Source = crypt32 | ID = 131083
Description = Die Extrahierung der Drittanbieterstammlisten aus der automatischen
Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
ist fehlgeschlagen mit dem Fehler: 0x800b0101.
Error - 26.09.2010 11:28:20 | Computer Name = RENAS | Source = crypt32 | ID = 131083
Description = Die Extrahierung der Drittanbieterstammlisten aus der automatischen
Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
ist fehlgeschlagen mit dem Fehler: 0x800b0101.
Error - 26.09.2010 11:36:03 | Computer Name = RENAS | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung explorer.exe, Version 6.0.2800.1106, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
[ System Events ]
Error - 23.09.2010 09:50:59 | Computer Name = RENAS | Source = DCOM | ID = 10005
Description = Bei DCOM ist der Fehler "%1055" aufgetreten, als der Dienst "netman"
mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 23.09.2010 09:50:59 | Computer Name = RENAS | Source = DCOM | ID = 10005
Description = Bei DCOM ist der Fehler "%1055" aufgetreten, als der Dienst "iPod
Service" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden:
{063D34A4-BF84-4B8D-B699-E8CA06504DDE}
Error - 24.09.2010 05:15:02 | Computer Name = RENAS | Source = Dhcp | ID = 1002
Description = Die IP-Adresslease 192.168.1.36 für die Netzwerkkarte mit der Netzwerkadresse
000B6AD51997 wurde durch den DHCP-Server 192.168.1.1 abgelehnt (der DHCP-Server
hat eine DHCPNACK-Meldung gesendet).
Error - 24.09.2010 12:27:08 | Computer Name = RENAS | Source = DCOM | ID = 10005
Description = Bei DCOM ist der Fehler "%1055" aufgetreten, als der Dienst "iPod
Service" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden:
{063D34A4-BF84-4B8D-B699-E8CA06504DDE}
Error - 24.09.2010 12:27:08 | Computer Name = RENAS | Source = DCOM | ID = 10005
Description = Bei DCOM ist der Fehler "%1055" aufgetreten, als der Dienst "netman"
mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 24.09.2010 12:27:08 | Computer Name = RENAS | Source = DCOM | ID = 10005
Description = Bei DCOM ist der Fehler "%1055" aufgetreten, als der Dienst "netman"
mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 24.09.2010 12:27:08 | Computer Name = RENAS | Source = DCOM | ID = 10005
Description = Bei DCOM ist der Fehler "%1055" aufgetreten, als der Dienst "EventSystem"
mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 25.09.2010 09:25:40 | Computer Name = RENAS | Source = SideBySide | ID = 16842784
Description = Abhängige Assemblierung "Microsoft.VC90.MFC" konnte nicht gefunden
werden. "Last Error": Die referenzierte Assemblierung ist nicht auf dem Computer
installiert.
Error - 25.09.2010 09:25:40 | Computer Name = RENAS | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly ist für Microsoft.VC90.MFC fehlgeschlagen.
Referenzfehlermeldung:
Die referenzierte Assemblierung ist nicht auf dem Computer installiert. .
Error - 25.09.2010 09:25:40 | Computer Name = RENAS | Source = SideBySide | ID = 16842811
Description = Generate Activation Context ist für C:\DOKUME~1\CHRIST~1\LOKALE~1\Temp\RarSFX0\redist.dll
fehlgeschlagen. Referenzfehlermeldung: Der Vorgang wurde erfolgreich beendet. .
< End of report > --- --- ---
"
OTL.Txt
"OTL Logfile: Code:
OTL logfile created on: 26.09.2010 18:13:57 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Downloads
Windows XP Professional Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
511,00 Mb Total Physical Memory | 109,00 Mb Available Physical Memory | 21,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 53,00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 76,68 Gb Total Space | 6,09 Gb Free Space | 7,95% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1,86 Gb Total Space | 1,86 Gb Free Space | 99,90% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RENAS
Current User Name: christian
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Napster\napster.exe (Napster)
PRC - C:\Programme\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
PRC - C:\Programme\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\ICQ6Toolbar\ICQ Service.exe ()
PRC - C:\Programme\OpenOffice.org 2.3\program\soffice.bin (OpenOffice.org)
PRC - C:\Programme\OpenOffice.org 2.3\program\soffice.exe (OpenOffice.org)
PRC - C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation)
PRC - C:\Programme\Gemeinsame Dateien\DKOO\dpfserv.exe (Bibliographisches Institut & F. A. Brockhaus AG)
PRC - C:\Programme\Creative\Shared Files\Software Update\AutoUpdate.exe (Creative Technology Ltd)
PRC - C:\Programme\Creative\Shared Files\CTSched.exe (Creative Technology Ltd)
PRC - C:\Programme\tunebite\tunebite.exe (RapidSolution Software AG)
PRC - C:\WINDOWS\system32\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Programme\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Programme\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1891_x-ww_7d3bbc01\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\dsound.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\CTAGENT.DLL (Creative Technology Ltd)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) -- C:\WINDOWS\System32\hidserv.dll File not found
SRV - (EHttpSrv) -- C:\Programme\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)
SRV - (ekrn) -- C:\Programme\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
SRV - (ICQ Service) -- C:\Programme\ICQ6Toolbar\ICQ Service.exe ()
SRV - (GoogleDesktopManager-061008-081103) -- C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (DPFService) -- C:\Programme\Gemeinsame Dateien\DKOO\dpfserv.exe (Bibliographisches Institut & F. A. Brockhaus AG)
SRV - (usnjsvc) -- C:\Programme\MSN Messenger\usnsvc.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (epfwtdir) -- C:\WINDOWS\system32\drivers\epfwtdir.sys (ESET)
DRV - (ehdrv) -- C:\WINDOWS\system32\drivers\ehdrv.sys (ESET)
DRV - (eamon) -- C:\WINDOWS\system32\drivers\eamon.sys (ESET)
DRV - (hamachi) -- C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (Cdralw2k) -- C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (tbhsd) -- C:\WINDOWS\system32\drivers\tbhsd.sys (RapidSolution Software AG)
DRV - (ss_mdm) -- C:\WINDOWS\system32\drivers\ss_mdm.sys (MCCI)
DRV - (ss_mdfl) -- C:\WINDOWS\system32\drivers\ss_mdfl.sys (MCCI)
DRV - (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM) -- C:\WINDOWS\system32\drivers\ss_bus.sys (MCCI)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (viaagp1) -- C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (ctdvda2k) -- C:\WINDOWS\system32\drivers\ctdvda2k.sys ()
DRV - (hap16v2k) -- C:\WINDOWS\system32\drivers\HAP16V2K.SYS (Creative Technology Ltd)
DRV - (emupia) -- C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) -- C:\WINDOWS\system32\drivers\CTSFM2K.SYS (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) -- C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (ctac32k) -- C:\WINDOWS\system32\drivers\CTAC32K.SYS (Creative Technology Ltd)
DRV - (efipsk) -- C:\Dokumente und Einstellungen\christian\Lokale Einstellungen\Temp\efipsk.sys ()
DRV - (PfModNT) -- C:\WINDOWS\system32\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (ctprxy2k) -- C:\WINDOWS\system32\drivers\CTPRXY2K.SYS (Creative Technology Ltd)
DRV - (ossrv) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (ctgame) -- C:\WINDOWS\system32\drivers\ctgame.sys (Creative Technology Ltd.)
DRV - (WFsys) -- C:\WINDOWS\system32\drivers\wfsys.sys (Leadtek Research Inc.)
DRV - (rtl8139) NT-Treiber für Realtek RTL8139(A/B/C) -- C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation )
DRV - (VIAPFD) -- C:\WINDOWS\System32\Drivers\VIAPFD.SYS (VIA Technologies. Inc.)
DRV - (Aspi32) -- C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1659004503-1604221776-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = hxxp://google.icq.com
IE - HKU\S-1-5-21-1659004503-1604221776-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://google.icq.com
IE - HKU\S-1-5-21-1659004503-1604221776-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKU\S-1-5-21-1659004503-1604221776-839522115-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1659004503-1604221776-839522115-1003\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-1659004503-1604221776-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q="
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Programme\Mozilla Firefox\components [2010.08.28 22:31:28 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2010.09.15 12:27:27 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Programme\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010.09.26 17:31:06 | 000,000,000 | ---D | M]
[2009.05.24 22:40:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Extensions
[2010.09.26 17:35:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\extensions
[2010.09.02 19:43:41 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010.09.22 00:42:45 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\searchplugins\icqplugin-1.xml
[2009.12.24 14:42:20 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\searchplugins\icqplugin-10.xml
[2010.02.24 13:01:05 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\searchplugins\icqplugin-11.xml
[2010.04.04 15:14:17 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\searchplugins\icqplugin-12.xml
[2008.07.19 20:46:09 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\searchplugins\icqplugin-2.xml
[2008.10.02 13:15:09 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\searchplugins\icqplugin-3.xml
[2008.12.06 13:47:36 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\searchplugins\icqplugin-4.xml
[2008.12.22 12:09:57 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\searchplugins\icqplugin-5.xml
[2009.06.13 11:45:31 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\searchplugins\icqplugin-6.xml
[2009.07.23 12:40:18 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\searchplugins\icqplugin-7.xml
[2009.08.08 13:42:10 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\searchplugins\icqplugin-8.xml
[2009.09.17 20:32:01 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\searchplugins\icqplugin-9.xml
[2009.07.13 17:12:02 | 000,000,944 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla\Firefox\Profiles\89thpzh1.default\searchplugins\icqplugin.xml
[2010.09.26 16:05:40 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2007.05.17 13:21:23 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Programme\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009.07.15 21:05:42 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2009.05.07 17:27:36 | 000,283,952 | ---- | M] (Musicnotes, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npmusicn.dll
[2010.07.20 17:21:40 | 000,106,192 | ---- | M] ( ) -- C:\Programme\Mozilla Firefox\plugins\npstrlnk.dll
[2009.11.24 14:14:50 | 010,437,264 | ---- | M] (PDFTron Systems Inc.) -- C:\Programme\Mozilla Firefox\plugins\PDFNetC.dll
[2009.11.28 13:10:18 | 000,107,760 | ---- | M] () -- C:\Programme\Mozilla Firefox\plugins\ScorchPDFWrapper.dll
[2010.02.23 23:01:37 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.02.23 23:01:37 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2008.10.02 01:04:16 | 000,000,686 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\GoogleDesktopMozilla.png
[2008.10.02 01:04:16 | 000,000,531 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\GoogleDesktopMozilla.src
[2010.02.23 23:01:37 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.02.23 23:01:37 | 000,000,986 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.02.23 23:01:37 | 000,000,801 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2001.08.18 21:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (XTTBPos00 Class) - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Programme\ICQToolbar\tbu24\toolbaru.dll (IE Toolbar)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programme\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programme\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-1659004503-1604221776-839522115-1003\..\Toolbar\WebBrowser: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKU\S-1-5-21-1659004503-1604221776-839522115-1003\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programme\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [AsioReg] C:\WINDOWS\System32\CTASIO.DLL (Creative Technology Ltd)
O4 - HKLM..\Run: [CTDVDDet] C:\Programme\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTStartup] C:\Programme\Creative\Splash Screen\CTEaxSpl.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [CTSysVol] C:\Programme\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [egui] C:\Programme\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [Google Desktop Search] C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [NapsterShell] C:\Programme\Napster\napster.exe (Napster)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SBDrvDet] C:\Programme\Creative\SB Drive Det\SBDrvDet.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [WMC_AutoUpdate] File not found
O4 - HKU\S-1-5-21-1659004503-1604221776-839522115-1003..\Run: [Creative Software Update] C:\Programme\Creative\Shared Files\Software Update\AutoUpdate.exe (Creative Technology Ltd)
O4 - HKU\S-1-5-21-1659004503-1604221776-839522115-1003..\Run: [CreativeTaskScheduler] C:\Programme\Creative\Shared Files\CTSched.exe (Creative Technology Ltd)
O4 - HKU\S-1-5-21-1659004503-1604221776-839522115-1003..\Run: [tunebite.exe] C:\Programme\tunebite\tunebite.exe (RapidSolution Software AG)
O4 - Startup: C:\Dokumente und Einstellungen\christian\Startmenü\Programme\Autostart\OpenOffice.org 2.0.lnk = C:\Programme\OpenOffice.org 2.0\program\quickstart.exe File not found
O4 - Startup: C:\Dokumente und Einstellungen\christian\Startmenü\Programme\Autostart\OpenOffice.org 2.3.lnk = C:\Programme\OpenOffice.org 2.3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1659004503-1604221776-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &ICQ Toolbar Search - C:\Programme\ICQToolbar\toolbaru.dll (ICQ Inc.)
O8 - Extra context menu item: &Windows Live Search - C:\Programme\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: In neuer Registerkarte im Hintergrund öffnen - C:\Programme\Windows Live Toolbar\Components\de-de\msntabres.dll.mui (Microsoft Corporation)
O8 - Extra context menu item: In neuer Registerkarte im Vordergrund öffnen - C:\Programme\Windows Live Toolbar\Components\de-de\msntabres.dll.mui (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_02\bin\npjpi160_02.dll (Sun Microsystems, Inc.)
O9 - Extra Button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe File not found
O9 - Extra 'Tools' menuitem : ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe File not found
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm ()
O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm ()
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15108/CTPID.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Programme\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\christian\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\christian\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.05.17 18:18:09 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2007.05.16 22:50:05 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.VIA -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608555} - Internet Explorer Classes for Java
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offlinebrowsingpaket
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015C} - Microsoft DirectX
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer-Hilfe
ActiveX: {4d64f3ba-f112-4efe-a02e-96680859937c} - KB918899
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection %SystemRoot%\INF\msmsgs.inf,BLC.Install.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5b7bf89d-d196-4c32-a303-a57b8ab7f18d} - KB918439
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsererweiterungen
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - Zugang zu MSN Site
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - %SystemRoot%\system32\ie4uinit.exe
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\System32\Rundll32.exe C:\WINDOWS\System32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML-Datenbindung
ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} -
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer-Hauptschriftarten
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player 9 ActiveX
ActiveX: {dd772a76-bef3-44d7-8b39-502c8504c1f1} - KB925486
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML-Hilfe
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {f15ee071-deb7-4cbb-951f-431c98338d8e} - KB911567
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corp.)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16620634377289728)
========== Files/Folders - Created Within 30 Days ==========
[2010.09.26 17:32:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2010.09.26 17:30:59 | 000,000,000 | ---D | C] -- C:\Programme\ESET
[2010.09.26 17:30:59 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET
[2010.09.26 15:12:42 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\christian\Eigene Dateien\Simply Super Software
[2010.09.19 21:07:59 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\christian\Desktop\mum arm
[2010.09.14 17:02:13 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DivX
[2010.08.28 22:37:33 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\christian\Desktop\auf mp3 player
[2010.08.28 22:31:14 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Roxio Shared
[2010.08.28 22:31:14 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Napster Shared
[2007.05.17 18:43:38 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.09.26 17:52:05 | 000,000,254 | ---- | M] () -- C:\WINDOWS\tasks\Auf Updates für Windows Live Toolbar prüfen.job
[2010.09.26 17:27:56 | 004,456,448 | -H-- | M] () -- C:\Dokumente und Einstellungen\christian\NTUSER.DAT
[2010.09.26 15:56:55 | 004,481,358 | ---- | M] () -- C:\WINDOWS\{00000000-00000000-0000000B-00001102-00000004-10021102}.CDF
[2010.09.26 15:56:45 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.09.26 15:56:13 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.09.26 15:56:11 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.09.26 15:56:10 | 536,399,872 | -HS- | M] () -- C:\hiberfil.sys
[2010.09.26 15:16:03 | 000,030,180 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000000-00000000-0000000B-00001102-00000004-10021102}.rfx
[2010.09.26 15:16:03 | 000,030,180 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000000-00000000-0000000B-00001102-00000004-10021102}.rfx
[2010.09.26 15:16:03 | 000,030,168 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000000-00000000-0000000B-00001102-00000004-10021102}.rfx
[2010.09.26 15:16:03 | 000,030,168 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000000-00000000-0000000B-00001102-00000004-10021102}.rfx
[2010.09.26 15:16:03 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2010.09.26 15:16:03 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm
[2010.09.26 15:16:03 | 000,000,288 | ---- | M] () -- C:\WINDOWS\System32\DVCStateBkp-{00000000-00000000-0000000B-00001102-00000004-10021102}.dat
[2010.09.26 15:16:03 | 000,000,288 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000000-00000000-0000000B-00001102-00000004-10021102}.dat
[2010.09.26 15:15:56 | 000,000,192 | -HS- | M] () -- C:\Dokumente und Einstellungen\christian\ntuser.ini
[2010.09.26 15:15:51 | 000,000,268 | -H-- | M] () -- C:\sqmdata16.sqm
[2010.09.26 15:15:50 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2010.09.25 18:20:36 | 000,000,268 | -H-- | M] () -- C:\sqmdata15.sqm
[2010.09.25 18:20:36 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2010.09.24 22:39:11 | 000,000,268 | -H-- | M] () -- C:\sqmdata14.sqm
[2010.09.24 22:39:11 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2010.09.24 17:42:10 | 000,000,268 | -H-- | M] () -- C:\sqmdata13.sqm
[2010.09.24 17:42:10 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2010.09.24 11:26:46 | 000,000,268 | -H-- | M] () -- C:\sqmdata12.sqm
[2010.09.24 11:26:46 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2010.09.23 16:07:52 | 000,000,268 | -H-- | M] () -- C:\sqmdata11.sqm
[2010.09.23 16:07:52 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2010.09.23 14:45:05 | 000,000,268 | -H-- | M] () -- C:\sqmdata10.sqm
[2010.09.23 14:45:05 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2010.09.22 22:29:37 | 000,000,268 | -H-- | M] () -- C:\sqmdata09.sqm
[2010.09.22 22:29:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2010.09.22 22:22:29 | 000,000,268 | -H-- | M] () -- C:\sqmdata08.sqm
[2010.09.22 22:22:29 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2010.09.22 01:30:00 | 000,000,268 | -H-- | M] () -- C:\sqmdata07.sqm
[2010.09.22 01:30:00 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2010.09.21 16:10:17 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
[2010.09.21 16:10:17 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2010.09.20 15:57:34 | 000,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
[2010.09.20 15:57:34 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2010.09.20 13:39:40 | 000,000,268 | -H-- | M] () -- C:\sqmdata04.sqm
[2010.09.20 13:39:40 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2010.09.20 00:30:38 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
[2010.09.20 00:30:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2010.09.19 22:12:59 | 000,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2010.09.19 22:12:59 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2010.09.19 21:40:04 | 000,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
[2010.09.19 21:40:04 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2010.09.19 21:34:07 | 000,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
[2010.09.19 21:34:06 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2010.09.19 16:13:21 | 000,000,268 | -H-- | M] () -- C:\sqmdata19.sqm
[2010.09.19 16:13:21 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2010.09.18 23:11:47 | 000,000,268 | -H-- | M] () -- C:\sqmdata18.sqm
[2010.09.18 23:11:47 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2010.09.18 13:39:29 | 000,000,268 | -H-- | M] () -- C:\sqmdata17.sqm
[2010.09.18 13:39:29 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2010.09.14 18:41:58 | 000,000,035 | ---- | M] () -- C:\WINDOWS\worldbuilder.INI
[2010.09.06 14:32:34 | 000,030,432 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Desktop\neuerstudienverlaufsplan.pdf
[2010.09.02 11:26:55 | 000,050,991 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Desktop\nebenfaecher2.pdf
[2010.08.30 23:20:25 | 001,313,014 | ---- | M] () -- C:\Dokumente und Einstellungen\christian\Desktop\[Free-scores.com]_rachmaninoff-sergei-prelude-g-672.pdf
[2010.08.30 23:20:14 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2010.08.28 22:29:41 | 000,001,541 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Napster.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.09.14 18:41:58 | 000,000,035 | ---- | C] () -- C:\WINDOWS\worldbuilder.INI
[2010.09.06 14:32:54 | 000,030,432 | ---- | C] () -- C:\Dokumente und Einstellungen\christian\Desktop\neuerstudienverlaufsplan.pdf
[2010.09.02 11:26:56 | 000,050,991 | ---- | C] () -- C:\Dokumente und Einstellungen\christian\Desktop\nebenfaecher2.pdf
[2010.08.30 23:20:25 | 001,313,014 | ---- | C] () -- C:\Dokumente und Einstellungen\christian\Desktop\[Free-scores.com]_rachmaninoff-sergei-prelude-g-672.pdf
[2008.07.26 05:47:39 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2008.07.26 05:47:39 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2008.07.26 05:47:39 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2008.04.25 11:18:47 | 000,000,291 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2008.02.07 15:00:24 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2008.01.14 19:34:43 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2007.08.28 01:15:51 | 002,067,140 | R--- | C] () -- C:\WINDOWS\System32\avcodec.dll
[2007.08.21 02:26:52 | 000,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2007.08.21 02:26:52 | 000,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2007.08.16 00:33:14 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007.08.16 00:30:26 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007.06.14 23:35:18 | 000,048,128 | ---- | C] () -- C:\Dokumente und Einstellungen\christian\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.06.09 20:47:04 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007.05.17 18:44:44 | 000,000,231 | ---- | C] () -- C:\WINDOWS\AC3API.INI
[2007.05.17 18:43:44 | 000,065,710 | ---- | C] () -- C:\WINDOWS\System32\Emu10kx.ini
[2007.05.17 18:43:44 | 000,000,029 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2007.05.17 18:43:32 | 000,005,515 | ---- | C] () -- C:\WINDOWS\System32\ENSDEF.INI
[2007.05.17 18:43:32 | 000,000,180 | ---- | C] () -- C:\WINDOWS\System32\KILL.INI
[2007.05.17 18:42:55 | 000,292,224 | ---- | C] () -- C:\WINDOWS\System32\drivers\ctdvda2k.sys
[2007.05.17 18:41:45 | 000,000,136 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2007.05.17 18:18:14 | 000,032,768 | R--- | C] () -- C:\WINDOWS\System32\VIAIDE2K.dll
[2007.05.17 18:16:57 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2003.10.06 15:16:00 | 000,027,136 | ---- | C] () -- C:\WINDOWS\System32\nvcod.dll
========== LOP Check ==========
[2010.09.26 17:30:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ESET
[2009.07.15 21:05:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ICQ
[2009.07.28 22:30:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Musicnotes
[2007.05.17 19:27:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Napster
[2008.02.10 19:13:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NCH Swift Sound
[2007.05.31 17:59:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\.doos
[2010.09.18 13:30:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\ICQ
[2007.09.05 22:06:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\ICQ Toolbar
[2007.05.17 12:07:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\ICQLite
[2007.05.17 18:46:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\InterTrust
[2008.02.10 19:13:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\NCH Swift Sound
[2007.11.06 19:34:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\ScummVM
[2010.09.01 19:48:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\tunebite
[2008.01.08 23:06:03 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\VideoReDoPlus
[2010.09.26 17:52:05 | 000,000,254 | ---- | M] () -- C:\WINDOWS\Tasks\Auf Updates für Windows Live Toolbar prüfen.job
========== Purity Check ==========
========== Custom Scans ==========
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2007.05.31 17:59:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\.doos
[2008.12.25 16:53:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Adobe
[2007.06.17 21:27:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Apple Computer
[2008.01.08 23:11:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\AVS4YOU
[2007.08.20 23:19:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Creative
[2007.11.22 21:23:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\DivX
[2007.07.29 10:57:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Google
[2009.09.15 10:57:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Hamachi
[2010.09.18 13:30:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\ICQ
[2007.09.05 22:06:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\ICQ Toolbar
[2007.05.17 12:07:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\ICQLite
[2007.05.16 23:04:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Identities
[2009.03.14 22:33:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\InstallShield
[2007.05.17 18:46:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\InterTrust
[2007.05.17 12:06:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Macromedia
[2007.10.28 14:10:06 | 000,000,000 | --SD | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Microsoft
[2007.12.17 21:17:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\mIRC
[2009.05.24 22:40:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Mozilla
[2008.02.10 19:13:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\NCH Swift Sound
[2010.09.26 15:56:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\OpenOffice.org2
[2007.09.30 16:54:31 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Real
[2007.05.17 19:27:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Roxio
[2007.11.06 19:34:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\ScummVM
[2009.09.06 11:17:30 | 000,000,000 | RH-D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\SecuROM
[2009.01.11 14:20:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Sibelius Software
[2010.03.25 11:37:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Skype
[2010.03.25 11:37:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\skypePM
[2007.08.29 01:29:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Sun
[2007.08.11 00:02:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\teamspeak2
[2010.09.01 19:48:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\tunebite
[2008.01.08 23:06:03 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\VideoReDoPlus
[2007.10.08 20:00:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\WinRAR
< %APPDATA%\*.exe /s >
[2007.07.29 10:56:56 | 000,026,694 | R--- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\ARPPRODUCTICON.exe
[2007.07.29 10:56:56 | 000,026,694 | R--- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
[2007.07.29 10:56:56 | 000,026,694 | R--- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
[2007.07.29 10:56:56 | 000,026,694 | R--- | M] () -- C:\Dokumente und Einstellungen\christian\Anwendungsdaten\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\UNINST_Uninstall_G_3DE5E7D47B88403CA3FD2017A8240C5B.exe
< %SYSTEMDRIVE%\*.exe >
[2007.05.31 17:14:55 | 046,416,184 | ---- | M] (Bibliographisches Institut & F. A. Brockhaus AG ) -- C:\dkoo-3-5-1.exe
[2006.12.09 10:19:06 | 098,012,107 | ---- | M] () -- C:\OOo_2.0.4_Win32Intel_install_de.exe
[2006.03.25 16:45:22 | 004,856,840 | ---- | M] (RapidSolution Software AG ) -- C:\tunebit.exe
[2006.08.03 15:23:50 | 008,037,624 | ---- | M] (RapidSolution Software AG ) -- C:\tunebite-2.exe
< MD5 for: AGP440.SYS >
[2004.08.04 08:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\agp440.sys
< MD5 for: ATAPI.SYS >
[2002.08.29 03:52:58 | 010,180,476 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.04 07:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2004.08.04 09:57:18 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\eventlog.dll
[2002.08.29 03:43:22 | 000,049,152 | ---- | M] (Microsoft Corporation) MD5=B9358A1FB66CF656328FD8B792B2CCC4 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2002.08.29 03:43:22 | 000,049,152 | ---- | M] (Microsoft Corporation) MD5=B9358A1FB66CF656328FD8B792B2CCC4 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2002.08.29 03:43:36 | 001,007,104 | ---- | M] (Microsoft Corporation) MD5=22B0A56E6C5847292437078B484EC61B -- C:\WINDOWS\explorer.exe
[2002.08.29 03:43:36 | 001,007,104 | ---- | M] (Microsoft Corporation) MD5=22B0A56E6C5847292437078B484EC61B -- C:\WINDOWS\system32\dllcache\explorer.exe
[2004.08.04 09:57:53 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=22FE1BE02EADDE1632E478E4125639E0 -- C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\explorer.exe
< MD5 for: NETLOGON.DLL >
[2002.08.29 03:43:26 | 000,399,360 | ---- | M] (Microsoft Corporation) MD5=BCA549B21E651111CE7BAD0FC8C45F4B -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2002.08.29 03:43:26 | 000,399,360 | ---- | M] (Microsoft Corporation) MD5=BCA549B21E651111CE7BAD0FC8C45F4B -- C:\WINDOWS\system32\netlogon.dll
[2004.08.04 09:57:30 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004.08.04 09:57:33 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\scecli.dll
[2002.08.29 03:43:30 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=ADD49C10F5DADFA81912D124FE1C9A99 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2002.08.29 03:43:30 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=ADD49C10F5DADFA81912D124FE1C9A99 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: USER32.DLL >
[2005.03.02 20:09:46 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=3751D7CF0E0A113D84414992146BCE6A -- C:\WINDOWS\$hf_mig$\KB890859\SP2GDR\user32.dll
[2005.03.02 20:19:56 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
[2004.08.04 09:57:36 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=56785FD5236D7B22CF471A6DA9DB46D8 -- C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\user32.dll
[2005.03.02 20:21:03 | 000,562,688 | ---- | M] (Microsoft Corporation) MD5=DEF116925E1EA04691EC6362F197451E -- C:\WINDOWS\system32\dllcache\user32.dll
[2005.03.02 20:21:03 | 000,562,688 | ---- | M] (Microsoft Corporation) MD5=DEF116925E1EA04691EC6362F197451E -- C:\WINDOWS\system32\user32.dll
[2002.08.29 03:43:32 | 000,561,664 | ---- | M] (Microsoft Corporation) MD5=E3DAFFDB1C86C1AEAC1B205F6CF67009 -- C:\WINDOWS\$NtUninstallKB890859$\user32.dll
< MD5 for: USERINIT.EXE >
[2002.08.29 03:43:42 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=BEBD3F08461F9A88E5ABCE0CB9707000 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2002.08.29 03:43:42 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=BEBD3F08461F9A88E5ABCE0CB9707000 -- C:\WINDOWS\system32\userinit.exe
[2004.08.04 09:58:16 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004.08.04 09:58:19 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\SoftwareDistribution\Download\84e71ea11258afcace4e790f6b073745\winlogon.exe
[2002.08.29 03:43:42 | 000,521,728 | ---- | M] (Microsoft Corporation) MD5=616896B708286DA98D6A099293F181D7 -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2002.08.29 03:43:42 | 000,521,728 | ---- | M] (Microsoft Corporation) MD5=616896B708286DA98D6A099293F181D7 -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2IFSL.SYS >
[2001.08.18 21:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\dllcache\ws2ifsl.sys
[2001.08.18 21:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\system32\drivers\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2007.05.17 00:35:40 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2007.05.17 00:35:40 | 000,630,784 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2007.05.17 00:35:40 | 000,405,504 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< End of report > --- --- ---
" |