sandrogba | 21.11.2010 15:27 | OTL Lofile:
OTL Logfile: Code:
OTL logfile created on: 21.11.2010 15:09:55 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Dokumente und Einstellungen\Sandro\Desktop\MFtools
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000807 | Country: Schweiz | Language: DES | Date Format: dd.MM.yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 232.83 Gb Total Space | 174.73 Gb Free Space | 75.05% Space Free | Partition Type: FAT32
Computer Name: MANOLO | User Name: Sandro | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010.11.21 12:25:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Sandro\Desktop\MFtools\OTL.exe
PRC - [2010.05.14 11:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2010.02.18 11:43:18 | 000,248,040 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
PRC - [2009.08.06 16:21:34 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2009.07.28 01:19:10 | 000,199,184 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee Security Scan\1.0.150\SSScheduler.exe
PRC - [2009.06.10 17:52:12 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2009.03.29 17:03:10 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009.03.02 12:08:44 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2007.11.13 18:38:28 | 002,510,848 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 2.3\program\soffice.bin
PRC - [2007.11.13 18:38:26 | 002,359,296 | ---- | M] (OpenOffice.org) -- C:\Programme\OpenOffice.org 2.3\program\soffice.exe
PRC - [2007.06.13 14:21:46 | 001,036,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.01.23 12:33:32 | 000,262,144 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\sistray.exe
========== Modules (SafeList) ==========
MOD - [2010.11.21 12:25:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Sandro\Desktop\MFtools\OTL.exe
MOD - [2006.08.25 16:46:44 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010.06.24 16:41:38 | 000,092,008 | ---- | M] (TomTom) [Disabled | Stopped] -- C:\Programme\TomTom HOME 3\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2010.05.14 11:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2009.08.28 19:42:54 | 000,144,672 | ---- | M] (Apple Inc.) [Disabled | Stopped] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009.08.06 16:21:34 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009.08.05 22:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2009.06.10 17:52:12 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- H:\FXDrv32.sys -- (FXDrv32)
DRV - [2009.12.08 17:39:54 | 000,056,816 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009.08.05 22:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2009.06.10 17:52:12 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.04.27 20:11:48 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2009.02.13 11:35:02 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2008.11.02 21:33:18 | 000,717,296 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008.10.07 13:33:00 | 006,133,856 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2008.05.06 22:50:54 | 000,002,368 | ---- | M] (AntiCracking) [Kernel | Auto | Running] -- C:\WINDOWS\system32\SVKP.sys -- (SVKP)
DRV - [2007.04.10 12:04:40 | 004,397,568 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.01.23 05:56:02 | 000,016,896 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srvkp.sys -- (SiSkp)
DRV - [2007.01.23 05:35:18 | 000,317,952 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315)
DRV - [2006.12.20 05:00:00 | 000,041,600 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SiSGbeXP.sys -- (SiSGbeXP)
DRV - [2005.01.07 17:07:18 | 000,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2003.03.25 10:50:46 | 000,004,096 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\siside.sys -- (SiSide)
DRV - [2002.10.17 08:14:46 | 000,049,024 | R--- | M] (Windows (R) 2000 DDK provider) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\sisidex.sys -- (sisidex)
DRV - [2002.08.20 10:19:08 | 000,009,472 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sisperf.sys -- (sisperf)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = ****://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = ****://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = ****://search.live.com/sphome.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = ****://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =****://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "****://www.bing.com/search?FORM=IEFM1&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "****://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..keyword.URL: "****://www.bing.com/search?FORM=IEFM1&q="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Programme\Mozilla Firefox\components [2008.09.14 11:53:48 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2008.09.14 11:53:48 | 000,000,000 | ---D | M]
[2008.09.14 11:53:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\Mozilla\Extensions
[2009.08.01 15:48:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\Mozilla\Extensions\home2@tomtom.com
[2008.09.14 11:53:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\Mozilla\Firefox\Profiles\go5ucfn5.default\extensions
[2009.12.02 20:26:32 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\Mozilla\Firefox\Profiles\go5ucfn5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009.11.29 20:46:34 | 000,002,163 | ---- | M] () -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\Mozilla\Firefox\Profiles\go5ucfn5.default\searchplugins\bing.xml
[2008.09.14 11:53:48 | 000,000,000 | ---D | M] -- C:\Programme\Mozilla Firefox\extensions
[2010.07.10 22:12:04 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.04.12 17:29:20 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.03.22 21:23:08 | 000,001,392 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2010.03.22 21:23:08 | 000,002,344 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml
[2010.03.22 21:23:08 | 000,006,805 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2010.03.22 21:23:08 | 000,001,178 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2010.03.22 21:23:08 | 000,001,105 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2006.02.28 12:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programme\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programme\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programme\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programme\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SiSPower] C:\WINDOWS\System32\SiSPower.dll (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [EPSON Stylus Photo RX585 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICLE.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [swg] C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe (Silicon Integrated Systems Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\McAfee Security Scan.lnk = C:\Programme\McAfee Security Scan\1.0.150\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Dokumente und Einstellungen\Sandro\Startmenü\Programme\Autostart\OpenOffice.org 2.3.lnk = C:\Programme\OpenOffice.org 2.3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki... - C:\Programme\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll (Google Inc.)
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} ****://upload.facebook.com/controls/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} ****://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} ****://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ****://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} ****://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} ****://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 77.109.128.3 77.109.128.3 213.133.129.20
O18 - Protocol\Handler\****\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\****\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\****s\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\****s\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\******\Anwendungsdaten\Mozilla\Firefox\Desktop-Hintergrund.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\******\Anwendungsdaten\Mozilla\Firefox\Desktop-Hintergrund.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003.01.30 11:52:54 | 000,000,086 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O33 - MountPoints2\{932bd2fe-a91e-11dd-a1d1-001c2509b145}\Shell - "" = AutoRun
O33 - MountPoints2\{932bd2fe-a91e-11dd-a1d1-001c2509b145}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{932bd2fe-a91e-11dd-a1d1-001c2509b145}\Shell\AutoRun\command - "" = I:\Install.exe -- File not found
O33 - MountPoints2\{eea190b6-7ea1-11de-a3bf-001c2509b145}\Shell\AutoRun\command - "" = D:\InstallTomTomHOME.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
MsConfig - Services: "TomTomHOMEService"
MsConfig - Services: "iPod Service"
MsConfig - Services: "gusvc"
MsConfig - Services: "gupdate"
MsConfig - Services: "Bonjour Service"
MsConfig - Services: "Apple Mobile Device"
MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Programme\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg: swg - hkey= - key= - C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
MsConfig - StartUpReg: TomTomHOME.exe - hkey= - key= - C:\Programme\TomTom HOME 3\TomTomHOMERunner.exe (TomTom)
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 2
MsConfig - State: "startup" - 2
Drivers32: aux - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)
========== Files/Folders - Created Within 30 Days ==========
[2010.11.21 12:56:19 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\******\Desktop\Gmer
[2010.11.21 12:37:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.11.21 12:36:40 | 000,000,000 | ---D | C] -- C:\Programme\ERUNT
[2010.11.21 12:26:21 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\******\Anwendungsdaten\Malwarebytes
[2010.11.21 12:26:09 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.11.21 12:26:07 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.11.21 12:26:07 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2010.11.21 12:26:07 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2010.11.21 12:24:53 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\******F\Desktop\MFtools
[2010.11.18 15:15:28 | 000,000,000 | -HSD | C] -- C:\FOUND.020
========== Files - Modified Within 30 Days ==========
[2010.11.21 14:35:02 | 000,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.11.21 13:24:06 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.11.21 12:46:46 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.11.21 12:46:46 | 000,001,084 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.11.21 12:46:44 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.11.21 12:45:18 | 000,000,168 | ---- | M] () -- C:\Dokumente und Einstellungen\Sandro\defogger_reenable
[2010.11.21 12:36:42 | 000,000,495 | ---- | M] () -- C:\Dokumente und Einstellungen\Sandro\Desktop\NTREGOPT.lnk
[2010.11.21 12:36:42 | 000,000,476 | ---- | M] () -- C:\Dokumente und Einstellungen\Sandro\Desktop\ERUNT.lnk
[2010.11.21 12:26:12 | 000,000,580 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.11.21 12:24:56 | 000,288,107 | ---- | M] () -- C:\Dokumente und Einstellungen\Sandro\Desktop\Gmer.zip
[2010.11.21 12:24:56 | 000,050,477 | ---- | M] () -- C:\Dokumente und Einstellungen\Sandro\Desktop\defogger.exe
[2010.11.20 08:47:02 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.11.18 21:39:58 | 000,195,534 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010.11.18 17:50:14 | 000,070,656 | ---- | M] () -- C:\Dokumente und Einstellungen\Sandro\Eigene Dateien\Reisebericht. kw 46.10.doc
[2010.11.15 23:25:02 | 000,001,160 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-484061587-839522115-1004Core1cb6f0a4da624e2.job
[2010.11.15 14:46:10 | 000,075,776 | ---- | M] () -- C:\Dokumente und Einstellungen\Sandro\Eigene Dateien\Reisebericht. kw 45.10.doc
[2010.11.10 20:10:10 | 000,078,848 | ---- | M] () -- C:\Dokumente und Einstellungen\Sandro\Eigene Dateien\Reisebericht. kw 44.10.doc
[2010.11.06 00:00:46 | 000,002,277 | ---- | M] () -- C:\Dokumente und Einstellungen\Sandro\Desktop\Google Chrome.lnk
[2010.11.04 17:46:56 | 000,088,068 | ---- | M] () -- C:\Dokumente und Einstellungen\Sandro\Desktop\photo.jpg
[2010.11.04 17:26:02 | 000,110,074 | ---- | M] () -- C:\Dokumente und Einstellungen\Sandro\Eigene Dateien\the winners.php
[2010.11.01 12:07:48 | 000,080,896 | ---- | M] () -- C:\Dokumente und Einstellungen\Sandro\Eigene Dateien\Reisebericht. kw 43.10.doc
[2010.10.31 12:38:54 | 000,118,952 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.10.26 08:48:24 | 000,079,360 | ---- | M] () -- C:\Dokumente und Einstellungen\Sandro\Eigene Dateien\Reisebericht. kw 42.10.doc
========== Files Created - No Company Name ==========
[2010.11.21 12:45:11 | 000,000,168 | ---- | C] () -- C:\Dokumente und Einstellungen\Sandro\defogger_reenable
[2010.11.21 12:36:40 | 000,000,495 | ---- | C] () -- C:\Dokumente und Einstellungen\Sandro\Desktop\NTREGOPT.lnk
[2010.11.21 12:36:40 | 000,000,476 | ---- | C] () -- C:\Dokumente und Einstellungen\Sandro\Desktop\ERUNT.lnk
[2010.11.21 12:26:11 | 000,000,580 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.11.21 12:24:55 | 000,050,477 | ---- | C] () -- C:\Dokumente und Einstellungen\Sandro\Desktop\defogger.exe
[2010.11.21 12:24:54 | 000,288,107 | ---- | C] () -- C:\Dokumente und Einstellungen\Sandro\Desktop\Gmer.zip
[2010.11.18 18:54:02 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.11.18 17:30:06 | 000,070,656 | ---- | C] () -- C:\Dokumente und Einstellungen\Sandro\Eigene Dateien\Reisebericht. kw 46.10.doc
[2010.11.15 10:11:32 | 000,075,776 | ---- | C] () -- C:\Dokumente und Einstellungen\Sandro\Eigene Dateien\Reisebericht. kw 45.10.doc
[2010.11.04 17:46:54 | 000,088,068 | ---- | C] () -- C:\Dokumente und Einstellungen\Sandro\Desktop\photo.jpg
[2010.11.04 17:26:14 | 000,110,074 | ---- | C] () -- C:\Dokumente und Einstellungen\Sandro\Eigene Dateien\the winners.php
[2010.11.01 18:31:09 | 000,078,848 | ---- | C] () -- C:\Dokumente und Einstellungen\Sandro\Eigene Dateien\Reisebericht. kw 44.10.doc
[2010.10.28 18:19:28 | 000,080,896 | ---- | C] () -- C:\Dokumente und Einstellungen\Sandro\Eigene Dateien\Reisebericht. kw 43.10.doc
[2010.02.11 23:00:34 | 000,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini
[2009.05.12 19:40:38 | 000,069,632 | R--- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2009.05.12 19:40:38 | 000,036,864 | R--- | C] () -- C:\WINDOWS\System32\xmlparse.dll
[2008.11.02 20:39:23 | 000,026,624 | ---- | C] () -- C:\Dokumente und Einstellungen\Sandro\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.06.11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008.06.11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008.06.11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008.06.11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008.06.11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008.06.11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008.06.11 09:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008.06.11 09:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008.06.11 09:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008.06.05 08:58:26 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008.05.09 12:34:01 | 000,177,123 | ---- | C] () -- C:\Programme\JoWooD.RPT
[2008.03.01 18:50:46 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2008.03.01 18:50:06 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDE RX585DEFGIPS.ini
[2008.01.27 19:19:21 | 000,092,031 | ---- | C] () -- C:\WINDOWS\VGAsetup.ini
[2008.01.27 19:18:22 | 000,076,557 | ---- | C] () -- C:\WINDOWS\System32\VGAunistlog.ini
[2008.01.27 19:12:38 | 000,139,264 | R--- | C] () -- C:\WINDOWS\System32\IDEproperty.dll
[2008.01.26 17:03:16 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2007.12.04 19:41:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007.12.04 19:41:00 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007.12.04 19:41:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007.12.04 19:41:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007.12.04 19:41:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
========== LOP Check ==========
[2008.03.01 18:49:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\EPSON
[2008.03.01 18:53:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\UDL
[2009.03.17 22:58:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009.03.29 17:10:08 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TrackMania
[2009.08.01 15:49:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TomTom
[2009.12.26 22:31:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2008.03.17 07:40:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\EPSON
[2008.05.01 13:55:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\EasyTax
[2008.08.20 15:20:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\.Kanton ZH
[2008.11.02 21:33:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\DAEMON Tools
[2009.03.06 21:18:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\SecondLife
[2009.03.28 16:59:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\Publish Providers
[2009.03.28 16:59:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\NetMedia Providers
[2009.03.28 17:07:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\Sony
[2009.08.01 15:48:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\TomTom
[2010.06.28 14:44:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Sandro\Anwendungsdaten\SoundSpectrum
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[1998.05.15 20:01:00 | 000,222,390 | RHS- | M] () -- C:\IO.SYS
[1998.05.15 20:01:00 | 000,069,079 | RHS- | M] () -- C:\DRVSPACE.BIN
[2001.11.05 21:34:58 | 000,000,006 | RHS- | M] () -- C:\MSDOS.SYS
[1998.05.15 20:01:00 | 000,096,360 | -HS- | M] () -- C:\COMMAND.COM
[1999.06.24 17:56:22 | 000,028,976 | ---- | M] () -- C:\CDROM.SYS
[2007.01.30 16:26:26 | 000,000,049 | ---- | M] () -- C:\CONFIG.SYS
[2002.04.18 17:21:22 | 000,021,180 | ---- | M] () -- C:\MSCDEX.EXE
[2003.01.30 11:52:54 | 000,000,086 | ---- | M] () -- C:\AUTOEXEC.BAT
[1998.05.15 20:01:00 | 000,033,447 | ---- | M] () -- C:\HIMEM.SYS
[1998.05.15 20:01:00 | 000,020,023 | ---- | M] () -- C:\KEYB.COM
[1998.05.15 20:01:00 | 000,034,566 | ---- | M] () -- C:\KEYBOARD.SYS
[1998.05.15 20:01:00 | 000,031,942 | ---- | M] () -- C:\KEYBRD2.SYS
[1998.05.15 20:01:00 | 000,126,695 | ---- | M] () -- C:\EMM386.EXE
[2008.01.26 16:47:50 | 000,000,082 | -HS- | M] () -- C:\BOOTLOG.PRV
[2009.01.09 10:53:10 | 000,000,082 | -H-- | M] () -- C:\BOOTLOG.TXT
[2007.01.30 15:51:56 | 000,000,303 | ---- | M] () -- C:\1.BAT
[2004.02.06 13:40:42 | 000,000,253 | ---- | M] () -- C:\MENU.BAT
[2007.01.30 15:21:18 | 000,000,288 | ---- | M] () -- C:\2.BAT
[2007.01.30 15:22:26 | 000,000,305 | ---- | M] () -- C:\3.BAT
[2003.01.30 17:31:56 | 000,129,098 | -HS- | M] () -- C:\LOGO.SYS
[2006.02.28 12:00:00 | 000,004,952 | RHS- | M] () -- C:\bootfont.bin
[2006.02.28 12:00:00 | 000,251,184 | RHS- | M] () -- C:\ntldr
[2006.02.28 12:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008.01.26 17:01:02 | 000,000,512 | -HS- | M] () -- C:\bootsect.dos
[2010.10.10 13:33:24 | 000,000,238 | -HS- | M] () -- C:\boot.ini
[2010.11.21 12:46:40 | 1560,281,088 | -HS- | M] () -- C:\pagefile.sys
[2010.11.18 18:55:10 | 000,020,228 | ---- | M] () -- C:\AVSCAN-Virenreport 20101118-170726-0E6AB5EB.txt
[2009.11.23 21:58:46 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2009.11.23 21:58:46 | 000,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
[2009.11.24 08:16:52 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2009.11.24 08:16:52 | 000,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
[2009.11.24 21:12:54 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2009.11.24 21:12:54 | 000,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2009.11.25 19:18:20 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2009.11.25 19:18:20 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
[2009.11.26 22:19:04 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2009.11.26 22:19:04 | 000,000,268 | -H-- | M] () -- C:\sqmdata04.sqm
[2009.11.27 20:07:22 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2009.11.27 20:07:22 | 000,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
[2009.11.28 10:04:10 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2009.11.28 10:04:10 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
[2009.11.28 14:16:40 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2009.11.28 14:16:40 | 000,000,268 | -H-- | M] () -- C:\sqmdata07.sqm
[2009.11.28 16:10:16 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2009.11.28 16:10:16 | 000,000,268 | -H-- | M] () -- C:\sqmdata08.sqm
[2009.11.29 15:33:00 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2009.11.29 15:33:00 | 000,000,268 | -H-- | M] () -- C:\sqmdata09.sqm
[2009.11.20 21:47:42 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2009.11.20 21:47:42 | 000,000,268 | -H-- | M] () -- C:\sqmdata10.sqm
[2009.11.21 01:18:02 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2009.11.21 01:18:02 | 000,000,268 | -H-- | M] () -- C:\sqmdata11.sqm
[2009.11.21 09:06:16 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2009.11.21 09:06:16 | 000,000,268 | -H-- | M] () -- C:\sqmdata12.sqm
[2009.11.21 15:57:48 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2009.11.21 15:57:48 | 000,000,268 | -H-- | M] () -- C:\sqmdata13.sqm
[2009.11.21 18:56:22 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2009.11.21 18:56:22 | 000,000,268 | -H-- | M] () -- C:\sqmdata14.sqm
[2009.11.22 00:55:16 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2009.11.22 00:55:16 | 000,000,268 | -H-- | M] () -- C:\sqmdata15.sqm
[2009.11.22 13:01:28 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2009.11.22 13:01:28 | 000,000,268 | -H-- | M] () -- C:\sqmdata16.sqm
[2009.11.22 14:51:38 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2009.11.22 14:51:38 | 000,000,268 | -H-- | M] () -- C:\sqmdata17.sqm
[2009.11.22 18:12:34 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2009.11.22 18:12:34 | 000,000,268 | -H-- | M] () -- C:\sqmdata18.sqm
[2009.11.22 21:33:38 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2009.11.22 21:33:38 | 000,000,268 | -H-- | M] () -- C:\sqmdata19.sqm
[2009.03.07 02:10:08 | 000,000,024 | ---- | M] () -- C:\url_history.xml
< %systemroot%\system32\*.wt >
< %systemroot%\system32\*.ruy >
< %systemroot%\Fonts\*.com >
[2006.04.18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006.06.29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006.04.18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006.06.29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008.01.26 17:17:32 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008.07.06 11:50:04 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2008.07.06 13:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.scr >
[2009.07.10 13:10:44 | 000,307,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008.06.02 22:13:38 | 000,177,123 | ---- | M] () -- C:\Programme\JoWooD.RPT
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2008.01.26 17:01:00 | 000,430,080 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
[2008.01.26 17:01:00 | 000,638,976 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2008.01.26 17:01:00 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
< %systemroot%\system32\user32.dll /md5 >
[2007.03.08 16:36:30 | 000,579,072 | ---- | M] (Microsoft Corporation) MD5=492E166CFD26A50FB9160DB536FF7D2B -- C:\WINDOWS\system32\user32.dll
< %systemroot%\system32\ws2_32.dll /md5 >
[2006.02.28 12:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=D569240A22421D5F670BB6FB6DD522B5 -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\system32\ws2help.dll /md5 >
[2006.02.28 12:00:00 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=B3ADA72D1E3E10A8F6430669DFC38ED0 -- C:\WINDOWS\system32\ws2help.dll
< MD5 for: EXPLORER.EXE >
[2006.02.28 12:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=22FE1BE02EADDE1632E478E4125639E0 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007.06.13 14:10:08 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=331ED93570BAF3CFE30340298762CD56 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2008.04.14 04:22:46 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E -- C:\WINDOWS\SoftwareDistribution\Download\d7ca437757bb79190d8fe0f22734e38b\explorer.exe
[2007.06.13 14:21:46 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=64D320C0E301EEDC5A4ADBBDC5024F7F -- C:\WINDOWS\explorer.exe
[2007.06.13 14:21:46 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=64D320C0E301EEDC5A4ADBBDC5024F7F -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: WINLOGON.EXE >
[2006.02.28 12:00:00 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2006.02.28 12:00:00 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\system32\winlogon.exe
[2008.04.14 04:23:06 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\SoftwareDistribution\Download\d7ca437757bb79190d8fe0f22734e38b\winlogon.exe
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-28 20:15:29
< End of report > --- --- --- |