Rashtagul | 04.10.2010 09:44 | Hallo,
Vielen Dank schonmal fürs antworten. Also mit Malwarebytes habe ich jetzt nichts gefunden, hier ist die OTL Log. Kaspersky spuckt allerdings mit seiner passiven Überwachung immer noch die selben Trojaner antworten aus, obwohl es manche der Ordner nicht mehr gibt und wenn ich z.B. die userint.exe direkt scanne, keine Trojanerwarnung kommt ?!
OTL Logfile: Code:
OTL logfile created on: 04.10.2010 10:08:56 - Run 2
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Dokumente und Einstellungen\Rashtagul\Desktop\MFTools
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
767,00 Mb Total Physical Memory | 423,00 Mb Available Physical Memory | 55,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 74,00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 37,26 Gb Total Space | 8,67 Gb Free Space | 23,27% Space Free | Partition Type: NTFS
Drive D: | 111,80 Gb Total Space | 32,91 Gb Free Space | 29,44% Space Free | Partition Type: NTFS
Drive E: | 31,25 Gb Total Space | 12,62 Gb Free Space | 40,40% Space Free | Partition Type: NTFS
Drive F: | 6,01 Gb Total Space | 2,81 Gb Free Space | 46,75% Space Free | Partition Type: FAT32
Drive G: | 436,63 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ALEX
Current User Name: Rashtagul
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Dokumente und Einstellungen\Rashtagul\Desktop\MFTools\OTL.exe (OldTimer Tools)
PRC - C:\Dokumente und Einstellungen\Rashtagul\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Programme\OO Software\Defrag\oodag.exe (O&O Software GmbH)
PRC - C:\Programme\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\fpdisp5a.exe (FinePrint Software, LLC)
PRC - C:\Programme\Trust\Trust R-Series Mouse\KMWDSrv.exe (UASSOFT.COM)
PRC - C:\Programme\Trust\Trust R-Series Mouse\KMCONFIG.exe (UASSOFT.COM)
PRC - C:\Programme\Trust\Trust R-Series Mouse\KMProcess.exe (UASSOFT.COM)
PRC - C:\Programme\Trust\Trust R-Series Mouse\StartAutorun.exe (UASSOFT.COM)
PRC - c:\Programme\Gemeinsame Dateien\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Programme\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Programme\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
PRC - C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
PRC - C:\Programme\Brother\Brmfcmon\BrMfcMon.exe (Brother Industries, Ltd.)
PRC - C:\WINDOWS\system32\brsvc01a.exe (brother Industries Ltd)
PRC - C:\WINDOWS\system32\brss01a.exe (brother Industries Ltd)
========== Modules (SafeList) ==========
MOD - C:\Dokumente und Einstellungen\Rashtagul\Desktop\MFTools\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Programme\Gemeinsame Dateien\LogiShrd\LVMVFM\LVPrcInj.dll (Logitech Inc.)
MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (AVP) -- C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
SRV - (O&O Defrag) -- C:\Programme\OO Software\Defrag\oodag.exe (O&O Software GmbH)
SRV - (getPlus(R) Helper) getPlus(R) -- C:\Programme\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (CVPND) -- C:\Programme\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (WLSetupSvc) -- C:\Programme\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (SandraDataSrv) -- C:\Programme\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe (SiSoftware)
SRV - (SandraTheSrv) -- C:\Programme\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe (SiSoftware)
SRV - (KMWDSERVICE) -- C:\Programme\Trust\Trust R-Series Mouse\KMWDSrv.exe (UASSOFT.COM)
SRV - (LVSrvLauncher) -- C:\Programme\Gemeinsame Dateien\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (LVPrcSrv) -- c:\Programme\Gemeinsame Dateien\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (Adobe LM Service) -- C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (IDriverT) -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (CCALib8) -- C:\Programme\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Brother XP spl Service) -- C:\WINDOWS\system32\brsvc01a.exe (brother Industries Ltd)
========== Driver Services (SafeList) ==========
DRV - (ZDPSp50) -- C:\WINDOWS\System32\Drivers\ZDPSp50.sys File not found
DRV - (TTNETDVB) -- C:\WINDOWS\System32\DRIVERS\ttnetdvb.sys File not found
DRV - (SMCWGU(SMC)) SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC) -- C:\WINDOWS\System32\DRIVERS\SMCWGU.sys File not found
DRV - (saa7146) -- C:\WINDOWS\System32\DRIVERS\saa7146.sys File not found
DRV - (oreans32) -- C:\WINDOWS\System32\drivers\oreans32.sys File not found
DRV - (dtscsi) -- C:\WINDOWS\System32\Drivers\dtscsi.sys File not found
DRV - (aitbukne.dll) -- C:\WINDOWS\System32\aitbukne.dll File not found
DRV - (KLIF) -- C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (PnkBstrK) -- C:\WINDOWS\system32\drivers\PnkBstrK.sys ()
DRV - (kl1) -- C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Lab)
DRV - (klmouflt) -- C:\WINDOWS\system32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (klim5) -- C:\WINDOWS\system32\drivers\klim5.sys (Kaspersky Lab)
DRV - (klbg) -- C:\WINDOWS\system32\drivers\klbg.sys (Kaspersky Lab)
DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (cdrbsdrv) -- C:\WINDOWS\System32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (CVPNDRVA) -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (MPE) -- C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (usbaudio) USB-Audiotreiber (WDM) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (DNE) -- C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (truecrypt) -- C:\WINDOWS\system32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (ss_mdm) -- C:\WINDOWS\system32\drivers\ss_mdm.sys (MCCI Corporation)
DRV - (ss_mdfl) -- C:\WINDOWS\system32\drivers\ss_mdfl.sys (MCCI Corporation)
DRV - (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM) -- C:\WINDOWS\system32\drivers\ss_bus.sys (MCCI Corporation)
DRV - (KMWDFilter) -- C:\WINDOWS\system32\drivers\KMWDFilter.SYS (Windows (R) Codename Longhorn DDK provider)
DRV - (LVPr2Mon) -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (LVMVDrv) -- C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)
DRV - (LVcKap) -- C:\WINDOWS\system32\drivers\Lvckap.sys ()
DRV - (LVUSBSta) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) -- C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (pepifilter) -- C:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (USB28xxBGA) -- C:\WINDOWS\system32\drivers\emBDA.sys (eMPIA Technology, Inc.)
DRV - (USB28xxOEM) -- C:\WINDOWS\system32\drivers\emOEM.sys (eMPIA Technology, Inc.)
DRV - (CVirtA) -- C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)
DRV - (StarOpen) -- C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (eeCtrl) -- C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SSHDRV84) -- C:\WINDOWS\system32\drivers\SSHDRV84.sys ()
DRV - (TT7146KS) TechnoTrend SAA7146 Capture (WDM) -- C:\WINDOWS\system32\drivers\TT7146KS.sys (TechnoTrend AG)
DRV - (vsdatant) -- C:\WINDOWS\system32\vsdatant.sys (Zone Labs LLC)
DRV - (TTLOOPHE) -- C:\WINDOWS\system32\drivers\ttloophe.sys (TechnoTrend AG)
DRV - (BrScnUsb) -- C:\WINDOWS\system32\drivers\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (SAA7146n) TT DVB-PCI driver (SAA7146n) -- C:\WINDOWS\system32\drivers\saa7146n.sys (TechnoTrend AG)
DRV - (rtl8139) NT-Treiber für Realtek RTL8139(A/B/C) -- C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (NETMDUSB) -- C:\WINDOWS\system32\drivers\NETMD033.sys (Sony Corporation)
DRV - (ha10kx2k) -- C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) -- C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) -- C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) -- C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) Creative Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) -- C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ms_mpu401) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (ctljystk) -- C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (PfModNT) -- C:\WINDOWS\system32\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (ASPI32) -- C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://google.icq.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://de.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:de:official"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:1.3.4
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20091209.4
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.4.1
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}:0.15
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q="
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2010.09.04 15:51:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2010.09.19 14:17:47 | 000,000,000 | ---D | M]
[2010.04.14 14:11:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Extensions
[2010.04.14 14:11:30 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.05.28 19:59:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\extensions
[2009.09.02 15:23:49 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009.07.30 00:07:28 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2009.07.03 12:27:04 | 000,000,000 | ---D | M] (Live HTTP Headers) -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}
[2008.10.13 23:42:49 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}
[2010.01.11 12:11:57 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.01.11 12:11:43 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010.05.26 21:53:42 | 000,000,961 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-1.xml
[2009.03.15 23:32:07 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-10.xml
[2009.04.13 15:06:44 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-11.xml
[2009.04.22 22:46:18 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-12.xml
[2009.04.29 16:00:06 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-13.xml
[2009.06.14 15:34:07 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-14.xml
[2009.07.23 00:27:48 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-15.xml
[2009.07.23 11:38:21 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-16.xml
[2009.07.30 12:57:59 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-17.xml
[2009.08.06 16:49:45 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-18.xml
[2008.03.31 09:52:00 | 000,000,618 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-19.xml
[2008.02.12 01:45:15 | 000,000,949 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-2.xml
[2009.11.01 20:14:02 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-20.xml
[2009.12.19 13:17:28 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-21.xml
[2010.01.06 15:16:23 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-22.xml
[2010.02.26 21:36:24 | 000,000,961 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-23.xml
[2010.04.02 10:46:59 | 000,000,961 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-24.xml
[2008.04.20 15:36:29 | 000,000,949 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-3.xml
[2008.07.02 23:29:22 | 000,000,949 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-4.xml
[2008.07.16 20:42:01 | 000,000,949 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-5.xml
[2008.10.03 14:42:30 | 000,000,949 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-6.xml
[2008.11.17 00:55:15 | 000,000,949 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-7.xml
[2009.02.09 19:15:53 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-8.xml
[2009.02.09 20:18:24 | 000,000,950 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin-9.xml
[2008.03.31 09:52:00 | 000,000,168 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin.gif
[2008.03.31 09:52:00 | 000,000,618 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin.src
[2007.07.25 23:04:52 | 000,000,951 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Profiles\1ueaafb9.default\searchplugins\icqplugin.xml
[2010.05.28 20:01:21 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
O1 HOSTS File: ([2001.08.18 14:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (WebSpeechBHO Class) - {83A30C59-3A50-49E6-9DAF-4923C4EA3C23} - C:\Programme\Gemeinsame Dateien\WebSpeech.4.0\LgxIEBar.dll (G DATA Software AG)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Programme\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVP] C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [ControlCenter2.0] C:\Programme\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [FinePrint Dispatcher v5] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe (FinePrint Software, LLC)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [KMCONFIG] C:\Programme\Trust\Trust R-Series Mouse\StartAutorun.exe KMConfig.exe File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [SetDefPrt] C:\Programme\Brother\Brmfl05a\BrStDvPt.exe (Brother Industories, Ltd.)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Status Monitor.lnk = C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95
O8 - Extra context menu item: Add to Anti-Banner - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O9 - Extra Button: WebSpeech - {1CE4DE72-7FCC-4eb8-8F66-AE6A56A0A54D} - C:\Programme\Gemeinsame Dateien\WebSpeech.4.0\LgxIEBar.dll (G DATA Software AG)
O9 - Extra 'Tools' menuitem : Seite/Markierung vorlesen (WebSpeech) - {1CE4DE72-7FCC-4eb8-8F66-AE6A56A0A54D} - C:\Programme\Gemeinsame Dateien\WebSpeech.4.0\LgxIEBar.dll (G DATA Software AG)
O9 - Extra Button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Programme\ICQ\Icq.exe (ICQ Inc.)
O9 - Extra 'Tools' menuitem : ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Programme\ICQ\Icq.exe (ICQ Inc.)
O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Programme\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Programme\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D00E9550-440D-4EF8-BFCE-174300890C05} hxxp://www.gomusic.ru/cabs/xdownloader.cab (DMList Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 2010\kloehk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Desktop Hintergrund.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\Mozilla\Firefox\Desktop Hintergrund.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005.12.25 13:52:28 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2002.03.23 18:03:41 | 000,000,000 | -H-- | M] () - D:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2002.12.13 14:03:24 | 000,679,936 | R--- | M] () - G:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2002.12.10 13:31:12 | 000,000,083 | R--- | M] () - G:\Autorun.inf -- [ CDFS ]
O33 - MountPoints2\{b177a2dc-9c93-11df-a668-00d05c000000}\Shell\AutoRun\command - "" = J:\Menu.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (OODBS) - C:\WINDOWS\System32\OODBS.exe (O&O Software GmbH)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010.09.29 17:21:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.09.29 17:20:46 | 000,000,000 | ---D | C] -- C:\Programme\ERUNT
[2010.09.29 17:06:41 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\MFTools
[2010.09.28 06:42:13 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Thomalla
[2010.09.27 19:37:38 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.09.27 19:37:33 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.09.19 14:26:33 | 000,000,000 | ---D | C] -- C:\key
[2010.09.19 14:26:19 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\KIs key
[2010.09.19 14:15:48 | 000,000,000 | ---D | C] -- C:\Programme\Kaspersky Lab
[2010.09.19 14:15:48 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab
[2010.09.19 14:13:56 | 000,296,976 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2010.09.19 14:03:25 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab Setup Files
[2010.09.19 13:57:54 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\KAspersky
[2010.09.18 06:39:50 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NVIDIA
[2010.09.05 15:36:36 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Rashtagul\Eigene Dateien\My Art
[2005.12.25 14:39:41 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll
[3 C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp files -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.10.04 09:43:04 | 000,001,224 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-1078145449-839522115-1003UA.job
[2010.10.04 08:12:00 | 000,000,470 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2010.10.04 03:20:29 | 001,004,852 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.10.04 03:20:29 | 000,451,970 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2010.10.04 03:20:29 | 000,435,260 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.10.04 03:20:29 | 000,080,928 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2010.10.04 03:20:29 | 000,068,156 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.10.04 02:12:03 | 000,000,470 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2010.10.03 23:49:45 | 000,063,804 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010.10.03 23:49:28 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2010.10.03 23:49:25 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.10.03 23:49:18 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.10.03 23:48:57 | 000,421,677 | ---- | M] () -- C:\WINDOWS\System32\oodbs.lor
[2010.10.03 23:46:56 | 000,025,296 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000001-00001102-00000002-80651102}.rfx
[2010.10.03 23:46:56 | 000,025,296 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000001-00001102-00000002-80651102}.rfx
[2010.10.03 23:46:56 | 000,016,516 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000002-80651102}.rfx
[2010.10.03 23:46:56 | 000,016,516 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000002-00000000-00000001-00001102-00000002-80651102}.rfx
[2010.10.03 23:46:56 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2010.10.03 23:46:56 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm
[2010.10.03 23:46:56 | 000,000,024 | ---- | M] () -- C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000001-00001102-00000002-80651102}.dat
[2010.10.03 23:46:56 | 000,000,024 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000002-00000000-00000001-00001102-00000002-80651102}.dat
[2010.10.03 23:46:00 | 009,302,016 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\ntuser.dat
[2010.10.03 23:46:00 | 000,000,300 | -HS- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\ntuser.ini
[2010.10.03 22:43:15 | 000,001,172 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-1078145449-839522115-1003Core.job
[2010.10.03 20:12:00 | 000,000,470 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2010.10.03 14:12:01 | 000,000,470 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010.10.03 14:12:01 | 000,000,470 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2010.10.03 13:28:29 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.10.02 19:13:56 | 000,009,524 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Kaspersky.zip
[2010.10.02 11:59:11 | 000,002,243 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Skype.lnk
[2010.09.29 17:42:10 | 000,000,020 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\defogger_reenable
[2010.09.29 17:20:49 | 000,000,591 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\NTREGOPT.lnk
[2010.09.29 17:20:49 | 000,000,572 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\ERUNT.lnk
[2010.09.29 17:07:19 | 000,284,915 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Gmer.zip
[2010.09.29 17:07:19 | 000,050,477 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\defogger.exe
[2010.09.29 17:04:49 | 000,388,977 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Load.exe
[2010.09.27 19:37:43 | 000,000,676 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.09.24 14:47:00 | 000,002,396 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Google Chrome.lnk
[2010.09.22 21:54:36 | 000,126,976 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.09.20 22:46:14 | 000,682,831 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Ausarbeitung_CCLM_Bostel_Felix_Entwurf.odt
[2010.09.19 14:50:00 | 000,113,933 | ---- | M] () -- C:\WINDOWS\System32\drivers\klin.dat
[2010.09.19 14:50:00 | 000,097,549 | ---- | M] () -- C:\WINDOWS\System32\drivers\klick.dat
[2010.09.19 14:37:21 | 000,604,140 | -HS- | M] () -- C:\WINDOWS\System32\drivers\ISwift3.dat
[2010.09.19 14:13:56 | 000,296,976 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2010.09.19 13:22:18 | 000,000,718 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\.wtav
[2010.09.15 07:18:32 | 000,000,801 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.09.15 07:17:35 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.09.12 15:40:34 | 000,020,480 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\LPS-Stimulationsessay mit Tabelle, 10.09.10.xls
[2010.09.07 18:08:55 | 001,812,232 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Inflammasome_Netea et al 2009.pdf
[2010.09.06 18:22:27 | 001,088,128 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Re Article about the Inflammasome.eml
[2010.09.06 18:21:43 | 000,786,139 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Annu Rev Immunol 2009 Martinon.pdf
[2010.09.06 17:40:23 | 000,001,709 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader 9.lnk
[2010.09.05 15:37:25 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LauncherAccess.dt
[2010.09.04 17:05:35 | 009,239,754 | ---- | M] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\StefanieThieleDissertation.pdf
[3 C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp files -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.10.02 19:13:56 | 000,009,524 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Kaspersky.zip
[2010.09.29 17:55:45 | 000,293,376 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\gmer.exe
[2010.09.29 17:41:48 | 000,000,020 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\defogger_reenable
[2010.09.29 17:20:49 | 000,000,591 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\NTREGOPT.lnk
[2010.09.29 17:20:49 | 000,000,572 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\ERUNT.lnk
[2010.09.29 17:06:50 | 000,050,477 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\defogger.exe
[2010.09.29 17:06:49 | 000,284,915 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Gmer.zip
[2010.09.29 17:04:48 | 000,388,977 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Load.exe
[2010.09.27 19:37:43 | 000,000,676 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.09.20 21:41:41 | 000,682,831 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Ausarbeitung_CCLM_Bostel_Felix_Entwurf.odt
[2010.09.19 14:37:21 | 000,604,140 | -HS- | C] () -- C:\WINDOWS\System32\drivers\ISwift3.dat
[2010.09.19 14:19:39 | 000,113,933 | ---- | C] () -- C:\WINDOWS\System32\drivers\klin.dat
[2010.09.19 14:19:39 | 000,097,549 | ---- | C] () -- C:\WINDOWS\System32\drivers\klick.dat
[2010.09.18 05:33:41 | 000,000,718 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\.wtav
[2010.09.12 15:32:15 | 000,020,480 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\LPS-Stimulationsessay mit Tabelle, 10.09.10.xls
[2010.09.07 18:08:52 | 001,812,232 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Inflammasome_Netea et al 2009.pdf
[2010.09.06 18:22:27 | 001,088,128 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Re Article about the Inflammasome.eml
[2010.09.06 18:21:43 | 000,786,139 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\Annu Rev Immunol 2009 Martinon.pdf
[2010.09.04 17:05:29 | 009,239,754 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Desktop\StefanieThieleDissertation.pdf
[2010.07.19 22:02:49 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LauncherAccess.dt
[2010.07.19 21:50:44 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2010.04.08 14:43:06 | 000,015,873 | ---- | C] () -- C:\WINDOWS\System32\Inetde.dll
[2008.10.30 21:35:57 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\Change.dll
[2008.10.03 16:48:28 | 000,339,456 | ---- | C] () -- C:\WINDOWS\System32\Tx32.dll
[2008.07.18 16:29:38 | 000,022,328 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008.06.21 11:07:08 | 000,028,812 | ---- | C] () -- C:\WINDOWS\System32\cms32_nt.dll
[2008.06.21 11:07:07 | 000,017,732 | ---- | C] () -- C:\WINDOWS\System32\cms32_95.dll
[2008.06.21 11:07:07 | 000,012,050 | ---- | C] () -- C:\WINDOWS\System32\cms16.dll
[2008.06.16 16:08:04 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008.06.16 16:08:02 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008.06.02 21:23:17 | 000,000,548 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\AutoGK.ini
[2008.04.17 10:08:56 | 000,197,408 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll
[2008.04.17 10:08:44 | 000,193,312 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2007.11.06 23:05:49 | 000,001,267 | ---- | C] () -- C:\WINDOWS\DVB-TV.INI
[2007.10.29 00:15:49 | 000,000,752 | ---- | C] () -- C:\WINDOWS\TT_DVB_SAT.INI
[2007.10.21 11:41:37 | 000,000,030 | ---- | C] () -- C:\WINDOWS\System32\brss01a.ini
[2007.10.21 11:41:36 | 000,000,027 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2007.10.21 11:41:35 | 000,000,468 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2007.10.04 13:57:01 | 000,001,516 | ---- | C] () -- C:\WINDOWS\vtplus32.ini
[2007.10.04 13:56:43 | 000,031,786 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2007.10.04 13:54:52 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\dmcrypto.dll
[2007.10.04 13:51:02 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\hcwChDB.dll
[2007.10.04 13:50:12 | 000,002,114 | ---- | C] () -- C:\WINDOWS\HCWPNP.INI
[2007.10.04 13:48:10 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\bdadll.dll
[2007.10.04 13:48:04 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007.09.10 14:07:02 | 000,000,227 | ---- | C] () -- C:\WINDOWS\Missing.ini
[2007.09.01 13:03:32 | 000,016,709 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Anwendungsdaten\ekiga.conf
[2007.09.01 12:34:20 | 000,050,127 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2007.05.22 00:59:34 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\SDL.dll
[2007.03.18 13:18:46 | 000,532,480 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2007.02.17 18:30:35 | 000,343,446 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Svclog.log
[2007.02.06 17:45:04 | 000,025,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007.02.06 17:42:40 | 001,691,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys
[2006.11.24 23:26:04 | 000,182,272 | ---- | C] () -- C:\WINDOWS\patchw32.dll
[2006.10.20 20:51:28 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2006.10.16 13:41:45 | 000,000,149 | ---- | C] () -- C:\WINDOWS\wpd99.drv
[2006.10.16 13:41:12 | 000,000,028 | ---- | C] () -- C:\WINDOWS\pdf995.ini
[2006.10.16 13:37:39 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\pdfmona.dll
[2006.10.16 13:37:39 | 000,051,716 | ---- | C] () -- C:\WINDOWS\System32\pdf995mon.dll
[2006.09.24 14:01:27 | 000,048,234 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2006.09.04 11:27:00 | 000,000,305 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\addr_file.html
[2006.08.21 15:46:14 | 000,000,235 | ---- | C] () -- C:\WINDOWS\BRAINBOX.INI
[2006.08.21 15:32:33 | 000,000,139 | ---- | C] () -- C:\WINDOWS\KMBJACK.INI
[2006.08.07 22:59:42 | 000,001,203 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006.08.07 22:56:30 | 000,000,290 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2006.07.10 23:13:06 | 000,000,039 | ---- | C] () -- C:\WINDOWS\System32\TEVPXCW60.DLL
[2006.07.10 23:13:06 | 000,000,039 | ---- | C] () -- C:\WINDOWS\TDEVXCW60.DLL
[2006.07.10 23:13:06 | 000,000,038 | ---- | C] () -- C:\WINDOWS\iltwain.ini
[2006.06.10 10:58:48 | 000,000,112 | ---- | C] () -- C:\WINDOWS\ActiveSkin.INI
[2006.06.01 11:22:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006.06.01 11:22:00 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006.06.01 11:22:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006.06.01 11:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006.06.01 11:22:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006.06.01 11:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006.05.31 00:39:48 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2006.03.12 15:06:53 | 000,000,457 | ---- | C] () -- C:\Programme\INSTALL.LOG
[2006.01.22 15:17:36 | 000,076,800 | ---- | C] () -- C:\WINDOWS\System32\drivers\SSHDRV84.sys
[2006.01.03 12:19:29 | 000,126,976 | ---- | C] () -- C:\Dokumente und Einstellungen\Rashtagul\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006.01.02 14:48:16 | 000,000,507 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005.12.25 14:40:49 | 000,000,231 | ---- | C] () -- C:\WINDOWS\AC3API.INI
[2005.12.25 14:39:55 | 000,037,727 | ---- | C] () -- C:\WINDOWS\System32\Emu10kx.ini
[2005.12.25 14:39:55 | 000,000,029 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2005.12.25 14:39:46 | 000,000,180 | ---- | C] () -- C:\WINDOWS\System32\KILL.INI
[2005.12.25 14:39:29 | 000,000,307 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2005.12.10 04:06:00 | 000,196,608 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2005.07.12 15:44:42 | 000,015,872 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD64.DLL
[2004.03.23 17:38:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD.dll
[2003.02.20 18:53:42 | 000,005,702 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002.10.16 00:54:04 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2001.08.18 14:00:00 | 000,533,568 | ---- | C] () -- C:\WINDOWS\System32\msfjaspn.dll
[2000.07.22 17:49:46 | 000,431,104 | ---- | C] () -- C:\WINDOWS\System32\VFCodec.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 128 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:857F3067
@Alternate Data Stream - 115 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:4F636E25
@Alternate Data Stream - 107 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:949483BD
@Alternate Data Stream - 104 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:507C73B7
< End of report > --- --- ---
OTL Logfile: Code:
OTL Extras logfile created on: 04.10.2010 10:08:56 - Run 2
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Dokumente und Einstellungen\Rashtagul\Desktop\MFTools
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
767,00 Mb Total Physical Memory | 423,00 Mb Available Physical Memory | 55,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 74,00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 37,26 Gb Total Space | 8,67 Gb Free Space | 23,27% Space Free | Partition Type: NTFS
Drive D: | 111,80 Gb Total Space | 32,91 Gb Free Space | 29,44% Space Free | Partition Type: NTFS
Drive E: | 31,25 Gb Total Space | 12,62 Gb Free Space | 40,40% Space Free | Partition Type: NTFS
Drive F: | 6,01 Gb Total Space | 2,81 Gb Free Space | 46,75% Space Free | Partition Type: FAT32
Drive G: | 436,63 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ALEX
Current User Name: Rashtagul
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Programme\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" File not found
https [open] -- "C:\Programme\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" File not found
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Programme\FlashFXP\flashfxp.exe" = C:\Programme\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 -- File not found
"C:\Programme\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Programme\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger -- (Logitech Inc.)
"C:\Programme\ICQ7.1\ICQ.exe" = C:\Programme\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1 -- (ICQ, LLC.)
"C:\Programme\ICQ7.1\aolload.exe" = C:\Programme\ICQ7.1\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Programme\FlashFXP\flashfxp.exe" = C:\Programme\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 -- File not found
"C:\Programme\ICQLite\ICQLite.exe" = C:\Programme\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite -- File not found
"C:\Programme\LimeWire\LimeWire.exe" = C:\Programme\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- File not found
"C:\Programme\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Programme\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger -- (Logitech Inc.)
"D:\Gizmo\Gizmo Project\mDNSResponder.exe" = D:\Gizmo\Gizmo Project\mDNSResponder.exe:*:Enabled:Bonjour -- File not found
"C:\Programme\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe" = C:\Programme\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe:*:Enabled:SiSoftware Database Agent Service -- (SiSoftware)
"C:\Programme\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe" = C:\Programme\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service -- (SiSoftware)
"C:\Programme\ICQ6\ICQ.exe" = C:\Programme\ICQ6\ICQ.exe:*:Enabled:ICQ6 -- File not found
"E:\pro Evolution Soccer 2008\PES2008.exe" = E:\pro Evolution Soccer 2008\PES2008.exe:*:Enabled:Pro Evolution Soccer 2008 -- File not found
"C:\Programme\Valve\hl.exe" = C:\Programme\Valve\hl.exe:*:Enabled:Half-Life Launcher -- (Valve)
"C:\Programme\Valve\hlds.exe" = C:\Programme\Valve\hlds.exe:*:Enabled:HLDS Launcher -- (Valve)
"E:\Programme\Azureus\Azureus.exe" = E:\Programme\Azureus\Azureus.exe:*:Enabled:Azureus -- (Azureus Inc)
"C:\Programme\Vuze\Azureus.exe" = C:\Programme\Vuze\Azureus.exe:*:Enabled:Azureus -- (Vuze Inc.)
"C:\Programme\ICQ\Icq.exe" = C:\Programme\ICQ\Icq.exe:*:Enabled:ICQ -- (ICQ Inc.)
"C:\Dokumente und Einstellungen\Rashtagul\Desktop\Wiesseraldeer\Weisseradler-Script 1.071\mirc.exe" = C:\Dokumente und Einstellungen\Rashtagul\Desktop\Wiesseraldeer\Weisseradler-Script 1.071\mirc.exe:*:Enabled:mIRC -- (mIRC Co. Ltd.)
"C:\Programme\ICQ7.1\ICQ.exe" = C:\Programme\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1 -- (ICQ, LLC.)
"C:\Programme\ICQ7.1\aolload.exe" = C:\Programme\ICQ7.1\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)
"D:\Warcraft III\Warcraft III.exe" = D:\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III -- ()
"C:\Programme\EA GAMES\Battlefield 1942\BF1942.exe" = C:\Programme\EA GAMES\Battlefield 1942\BF1942.exe:*:Enabled:BF1942 -- ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0A2A5039-B37F-489D-B1DC-A5258DF9E697}" = FIFA 08
"{190BF7E6-59C5-45E2-B9CE-E8E7245A5B4D}" = TMPGEnc Plus 2.5
"{2227E1FA-01F5-483C-AB0E-2A308E900B3D}" = InterVideo FilterSDK for Hauppauge
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 13
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{34E89C10-3E14-4396-A58C-72047CD458AD}" = TMPGEnc 4.0 XPress
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{3DC5CD53-8BEE-4FD7-900E-3A5F02964251}" = WinTV Nexus
"{4C271126-C295-4828-A901-5910AE0C258B}" = Cisco Systems VPN Client 5.0.03.0530
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}" = Battlefield 1942
"{718666FC-C0A7-4DE7-9120-8F1746A90588}" = Trust R-Series Mouse
"{71BFC818-0CED-42D6-9C87-5142918957EE}" = ICQ7.1
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7A7B0BF3-2F00-4F03-8A9B-6ABCC07B90C6}" = Windows Live installer
"{7D2370AC-D8E6-4996-986A-19824F8A167C}" = Logitech QuickCam
"{86B3F2D6-AC2B-4E88-8AE1-F2F77F781B0C}" = EndNote X3
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{8FB1A5EA-7DA8-4D57-80FB-BD923CCCC852}" = OpenOffice.org 2.1
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9115E7DB-3B29-445A-802D-11E0AA945B7F}" = Sound Blaster Live!
"{949576CE-4627-11D6-A7FE-0050FC21662B}" = Hotel Gigant
"{9600B88C-BE14-4BEA-A529-F5F312900BA3}" = Samsung PC Studio 3
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}" = Counter-Strike 1.6
"{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = Kaspersky Internet Security 2010
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A44413DC-17D5-4F0B-A128-8B590B20323C}" = Windows Messenger 5.1
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.4 - Deutsch
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{BB9AC6BF-71B6-42A4-9689-C17D9F44E79A}" = Brother MFL-Pro Suite
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2096}_is1" = SiSoftware Sandra Lite XIIc
"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D057AA08-8CBF-42E3-9EAB-23B8FED1C279}" = Battlefield 1942: The Road To Rome
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D48EAA77-E526-41EB-894C-BD6A17EABD95}" = TMPGEnc 3.0 XPress
"{D75814C1-5AA5-4198-BFF6-093A226D9F0D}" = O&O Defrag Professional
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
"{F00B1410-E832-4B0C-85E2-6E0F010C2A87}" = InterVideo FilterSDK for Techno Trend
"{F39A5F71-E8FD-96B7-58B7-C0E12D9F5FC5}" = Antivirus 2010
"{F5F5ABB8-87EA-47A7-8CC6-E68AFC2D3BC0}" = TMPGEnc Sound Player
"6194C28A8F62DD817EA1B918E6E46E806A21B452" = Windows-Treiberpaket - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
"65B6FE5418CE28F4D72543FB2D964C3CEC83F161" = Windows-Treiberpaket - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
"7-Zip" = 7-Zip 4.57
"82A44D22-9452-49FB-00FB-CEC7DCAF7E23" = EA SPORTS online 2005
"8461-7759-5462-8226" = Vuze
"Acoustica MP3 CD Burner" = Acoustica MP3 CD Burner
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"CCleaner" = CCleaner
"Cicil 2007 - Elearning" = Cicil 2007 - Elearning
"CSCLIB" = Canon Camera Support Core Library
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX-Setup
"EAX Unified" = EAX Unified
"EOS Utility" = Canon Utilities EOS Utility
"ERUNT_is1" = ERUNT 1.1j
"ffdshow_is1" = ffdshow [rev 2019] [2008-06-22]
"FinePrint" = FinePrint
"Freiburger Histo-CD_is1" = Freiburger Histo-CD 3.1
"GMailFS" = GMail Drive Shell Extension
"GSpot" = GSpot Codec Information Appliance
"Hijack This_is1" = Hijack This 1.99.1
"HijackThis" = HijackThis 1.99.1
"ICQ" = ICQ
"ie8" = Windows Internet Explorer 8
"InstallShield_{190BF7E6-59C5-45E2-B9CE-E8E7245A5B4D}" = TMPGEnc Plus 2.5
"InstallShield_{718666FC-C0A7-4DE7-9120-8F1746A90588}" = Trust R-Series Mouse
"InstallWIX_{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = Kaspersky Internet Security 2010
"InterActual Player" = InterActual Player
"lgx4.lgx.server" = G DATA Logox 4 Speechengine
"LiveUpdate" = LiveUpdate 2.7 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"mIRC" = mIRC
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Thunderbird (3.1.2)" = Mozilla Thunderbird (3.1.2)
"NVIDIA Drivers" = NVIDIA Drivers
"Pdf995" = Pdf995
"PhotoStitch" = Canon Utilities PhotoStitch
"Primal Pictures Interactive Spine" = Primal Pictures Interactive Spine
"QcDrv" = Logitech® Camera-Treiber
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 6.0" = RealPlayer
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"ResearchSoft Direct Export Helper" = ResearchSoft Direct Export Helper
"RouterControl" = RouterControl 1.91
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"ToolbarICQToolbar.ICQToolbarObjectIEToolbar" = ICQ Toolbar
"TrueCrypt" = TrueCrypt
"VLC media player" = VideoLAN VLC media player 0.8.6h
"VobSub" = VobSub v2.23 (Remove Only)
"VTPlus32 für WinTV (German)" = VTPlus32 für WinTV (German)
"WebLab Viewer" = WebLab Viewer
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGTK-2_is1" = GTK+ 2.10.6-1 runtime environment
"ws4.webspeech" = G DATA WebSpeech 4
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"pdfsam" = pdfsam
"Warcraft III" = Warcraft III
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 29.09.2010 16:43:15 | Computer Name = ALEX | Source = Google Update | ID = 20
Description =
Error - 29.09.2010 17:43:14 | Computer Name = ALEX | Source = Google Update | ID = 20
Description =
Error - 29.09.2010 18:43:20 | Computer Name = ALEX | Source = Google Update | ID = 20
Description =
Error - 29.09.2010 19:43:14 | Computer Name = ALEX | Source = Google Update | ID = 20
Description =
Error - 29.09.2010 20:43:14 | Computer Name = ALEX | Source = Google Update | ID = 20
Description =
Error - 29.09.2010 21:43:22 | Computer Name = ALEX | Source = Google Update | ID = 20
Description =
Error - 29.09.2010 22:43:14 | Computer Name = ALEX | Source = Google Update | ID = 20
Description =
Error - 29.09.2010 23:43:14 | Computer Name = ALEX | Source = Google Update | ID = 20
Description =
Error - 30.09.2010 00:43:14 | Computer Name = ALEX | Source = Google Update | ID = 20
Description =
Error - 30.09.2010 01:43:14 | Computer Name = ALEX | Source = Google Update | ID = 20
Description =
[ System Events ]
Error - 04.10.2010 04:35:24 | Computer Name = ALEX | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\D.
Error - 04.10.2010 04:35:30 | Computer Name = ALEX | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\D.
Error - 04.10.2010 04:35:35 | Computer Name = ALEX | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\D.
Error - 04.10.2010 04:35:41 | Computer Name = ALEX | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\D.
Error - 04.10.2010 04:35:47 | Computer Name = ALEX | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\D.
Error - 04.10.2010 04:35:55 | Computer Name = ALEX | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\D.
Error - 04.10.2010 04:36:00 | Computer Name = ALEX | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\D.
Error - 04.10.2010 04:36:06 | Computer Name = ALEX | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\D.
Error - 04.10.2010 04:36:12 | Computer Name = ALEX | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\D.
Error - 04.10.2010 04:36:18 | Computer Name = ALEX | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk0\D.
< End of report > --- --- --- |