danielpomp | 19.08.2011 15:15 | Windows 7 64bit komplett neu installiert und schon wieder infiziert ? Kann es sein, dass ein Trojaner eine Formatierung der Platte und eine neue OS-Neuinstallation übersteht oder habe ich einfach nur unbegründete Paranoia ?
Habe gestern Win7 neu installiert, bin mir aber nicht sicher, ob alles im grünen Bereich ist.
Gruß D. Code:
OTL logfile created on: 19.08.2011 15:51:55 - Run 2
OTL by OldTimer - Version 3.2.26.5 Folder = B:\Clean Downloads
64bit- An unknown product Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,85 Gb Available Physical Memory | 71,26% Memory free
8,00 Gb Paging File | 6,57 Gb Available in Paging File | 82,16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 59,62 Gb Total Space | 40,17 Gb Free Space | 67,38% Space Free | Partition Type: NTFS
Drive E: | 465,76 Gb Total Space | 23,20 Gb Free Space | 4,98% Space Free | Partition Type: NTFS
Drive F: | 931,50 Gb Total Space | 434,54 Gb Free Space | 46,65% Space Free | Partition Type: NTFS
Drive G: | 465,76 Gb Total Space | 44,30 Gb Free Space | 9,51% Space Free | Partition Type: NTFS
Drive H: | 3,83 Gb Total Space | 3,75 Gb Free Space | 98,07% Space Free | Partition Type: FAT32
Drive I: | 3,04 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive O: | 100,00 Mb Total Space | 70,34 Mb Free Space | 70,34% Space Free | Partition Type: NTFS
Computer Name: MDG-PC | User Name: MGA | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - B:\Clean Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\PCSafeDoctor\pcsafedoctor.exe ()
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\PCSafeDoctor\pcsafedoctor.exe ()
MOD - C:\Program Files (x86)\PCSafeDoctor\spkdll.dll ()
MOD - C:\Program Files (x86)\PCSafeDoctor\ussafe.dll ()
MOD - C:\Program Files (x86)\PCSafeDoctor\opfile.dll ()
MOD - C:\Program Files (x86)\PCSafeDoctor\networkdll.dll ()
MOD - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf ()
MOD - C:\Program Files (x86)\PCSafeDoctor\md5.dll ()
MOD - C:\Program Files (x86)\PCSafeDoctor\zlib1.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirWebService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira GmbH)
SRV - (AntiVirMailService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe (Avira GmbH)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (arusb_win7x) -- C:\Windows\SysNative\drivers\arusb_win7x.sys (Atheros Communications, Inc.)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (e1express) Intel(R) -- C:\Windows\SysNative\drivers\e1e6032e.sys (Intel Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (arusb_lhx) -- C:\Windows\SysNative\drivers\arusb_lhx.sys (Atheros Communications, Inc.)
DRV:64bit: - (MRV6X64P) -- C:\Windows\SysNative\drivers\MRVW13C.sys (Marvell Semiconductor, Inc)
DRV - (RkHit) -- C:\Windows\SysWOW64\drivers\RKHit.sys ()
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D9 97 E9 A7 60 5E CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.08.19 13:18:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011.08.19 13:18:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MGA\AppData\Roaming\mozilla\Extensions
[2011.08.19 15:13:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\MGA\AppData\Roaming\mozilla\Firefox\Profiles\hglm7as3.default\extensions
[2011.08.19 15:13:45 | 000,000,000 | ---D | M] (WOT) -- C:\Users\MGA\AppData\Roaming\mozilla\Firefox\Profiles\hglm7as3.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011.08.19 13:18:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
File not found (No name found) --
() (No name found) -- C:\USERS\MGA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HGLM7AS3.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) -- C:\USERS\MGA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HGLM7AS3.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011.08.12 08:13:04 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.08.12 06:19:37 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.08.12 06:14:12 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011.08.12 06:19:37 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.08.12 06:19:37 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.08.12 06:19:37 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.08.12 06:19:37 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [pcsafedoctor.exe] C:\Program Files (x86)\PCSafeDoctor\pcsafedoctor.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.0.cab (DLM Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011.04.12 11:19:49 | 000,000,122 | R--- | M] () - I:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{34f14361-ca36-11e0-b799-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{34f14361-ca36-11e0-b799-806e6f6e6963}\Shell\AutoRun\command - "" = I:\setup.exe -- [2011.04.12 11:19:49 | 000,106,768 | R--- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.08.19 15:48:36 | 000,000,000 | ---D | C] -- C:\Users\MGA\AppData\Roaming\Malwarebytes
[2011.08.19 15:48:32 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011.08.19 15:48:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.08.19 15:48:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.08.19 15:48:28 | 000,025,912 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011.08.19 15:48:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.08.19 15:04:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCSafeDoctor
[2011.08.19 15:04:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PCSafeDoctor
[2011.08.19 14:29:58 | 000,000,000 | ---D | C] -- C:\Users\MGA\DoctorWeb
[2011.08.19 14:18:13 | 000,000,000 | ---D | C] -- C:\Users\MGA\AppData\Roaming\Download Manager
[2011.08.19 14:01:16 | 000,000,000 | ---D | C] -- C:\Users\MGA\AppData\Roaming\SUPERAntiSpyware.com
[2011.08.19 14:01:16 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011.08.19 13:53:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2011.08.19 13:53:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip
[2011.08.19 13:45:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
[2011.08.19 13:45:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011.08.19 13:45:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2011.08.19 13:44:59 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Synchronization Services
[2011.08.19 13:44:41 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2011.08.19 13:44:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2011.08.19 13:44:41 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
[2011.08.19 13:44:41 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2011.08.19 13:43:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2011.08.19 13:43:13 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services
[2011.08.19 13:43:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2011.08.19 13:42:46 | 000,000,000 | ---D | C] -- C:\Users\MGA\AppData\Local\Microsoft Help
[2011.08.19 13:42:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2011.08.19 13:42:42 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2011.08.19 13:42:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2011.08.19 13:42:36 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2011.08.19 13:28:41 | 000,000,000 | ---D | C] -- C:\Users\MGA\AppData\Roaming\Avira
[2011.08.19 13:27:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011.08.19 13:27:17 | 000,123,784 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2011.08.19 13:27:17 | 000,088,288 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2011.08.19 13:27:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011.08.19 13:27:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2011.08.19 13:26:10 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2011.08.19 13:18:48 | 000,000,000 | ---D | C] -- C:\Users\MGA\AppData\Roaming\Mozilla
[2011.08.19 13:18:48 | 000,000,000 | ---D | C] -- C:\Users\MGA\AppData\Local\Mozilla
[2011.08.19 13:18:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2011.08.19 13:09:24 | 000,000,000 | -HSD | C] -- C:\Boot
[2011.08.19 13:09:12 | 000,539,136 | ---- | C] (Atheros Communications, Inc.) -- C:\Windows\SysNative\drivers\arusb_lhx.sys
[2011.08.19 13:09:12 | 000,539,136 | ---- | C] (Atheros Communications, Inc.) -- C:\Windows\SysNative\arusb_lhx.sys
[2011.08.19 13:08:25 | 000,769,024 | ---- | C] (Atheros Communications, Inc.) -- C:\Windows\SysNative\drivers\arusb_win7x.sys
[2011.08.19 13:08:25 | 000,769,024 | ---- | C] (Atheros Communications, Inc.) -- C:\Windows\SysNative\arusb_win7x.sys
[2011.08.19 13:08:25 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2011.08.19 13:08:07 | 000,000,000 | ---D | C] -- C:\ProgramData\TP-LINK
[2011.08.19 12:19:58 | 000,000,000 | R--D | C] -- C:\Users\MGA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011.08.19 12:19:58 | 000,000,000 | R--D | C] -- C:\Users\MGA\Searches
[2011.08.19 12:19:58 | 000,000,000 | R--D | C] -- C:\Users\MGA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011.08.19 12:19:53 | 000,000,000 | ---D | C] -- C:\Users\MGA\AppData\Roaming\Identities
[2011.08.19 12:19:51 | 000,000,000 | R--D | C] -- C:\Users\MGA\Contacts
[2011.08.19 12:19:50 | 000,000,000 | ---D | C] -- C:\Users\MGA\AppData\Local\VirtualStore
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\Vorlagen
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\AppData\Local\Verlauf
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\AppData\Local\Temporary Internet Files
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\Startmenü
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\SendTo
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\Recent
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\Netzwerkumgebung
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\Lokale Einstellungen
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\Documents\Eigene Videos
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\Documents\Eigene Musik
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\Eigene Dateien
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\Documents\Eigene Bilder
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\Druckumgebung
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\Cookies
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\AppData\Local\Anwendungsdaten
[2011.08.19 12:19:49 | 000,000,000 | -HSD | C] -- C:\Users\MGA\Anwendungsdaten
[2011.08.19 12:19:48 | 000,000,000 | --SD | C] -- C:\Users\MGA\AppData\Roaming\Microsoft
[2011.08.19 12:19:48 | 000,000,000 | R--D | C] -- C:\Users\MGA\Videos
[2011.08.19 12:19:48 | 000,000,000 | R--D | C] -- C:\Users\MGA\Saved Games
[2011.08.19 12:19:48 | 000,000,000 | R--D | C] -- C:\Users\MGA\Pictures
[2011.08.19 12:19:48 | 000,000,000 | R--D | C] -- C:\Users\MGA\Music
[2011.08.19 12:19:48 | 000,000,000 | R--D | C] -- C:\Users\MGA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011.08.19 12:19:48 | 000,000,000 | R--D | C] -- C:\Users\MGA\Links
[2011.08.19 12:19:48 | 000,000,000 | R--D | C] -- C:\Users\MGA\Favorites
[2011.08.19 12:19:48 | 000,000,000 | R--D | C] -- C:\Users\MGA\Downloads
[2011.08.19 12:19:48 | 000,000,000 | R--D | C] -- C:\Users\MGA\Documents
[2011.08.19 12:19:48 | 000,000,000 | R--D | C] -- C:\Users\MGA\Desktop
[2011.08.19 12:19:48 | 000,000,000 | R--D | C] -- C:\Users\MGA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011.08.19 12:19:48 | 000,000,000 | -H-D | C] -- C:\Users\MGA\AppData
[2011.08.19 12:19:48 | 000,000,000 | ---D | C] -- C:\Users\MGA\AppData\Local\Temp
[2011.08.19 12:19:48 | 000,000,000 | ---D | C] -- C:\Users\MGA\AppData\Local\Microsoft
[2011.08.19 12:19:48 | 000,000,000 | ---D | C] -- C:\Users\MGA\AppData\Roaming\Media Center Programs
[2011.08.19 10:37:12 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2011.08.19 09:40:03 | 000,000,000 | ---D | C] -- C:\Program Files\Lexmark
[2011.08.19 09:38:38 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2011.08.19 09:38:25 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2011.08.19 09:17:35 | 000,000,000 | ---D | C] -- C:\ProgNoInstall
[2011.08.19 09:03:42 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2011.08.19 09:02:49 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2011.08.19 09:02:49 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2011.08.19 09:02:49 | 000,000,000 | -HSD | C] -- C:\Recovery
[2011.08.19 09:02:49 | 000,000,000 | -HSD | C] -- C:\Programme
[2011.08.19 09:02:49 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2011.08.19 09:02:49 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2011.08.19 09:02:49 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2011.08.19 09:02:49 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2011.08.19 09:02:49 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2011.08.19 09:02:49 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2011.08.19 09:02:49 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2011.08.19 09:02:49 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
========== Files - Modified Within 30 Days ==========
[2011.08.19 15:48:32 | 000,001,121 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.08.19 15:13:29 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.08.19 15:13:29 | 000,643,628 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2011.08.19 15:13:29 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.08.19 15:13:29 | 000,126,188 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2011.08.19 15:13:29 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.08.19 15:09:04 | 000,019,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.08.19 15:09:04 | 000,019,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.08.19 15:08:54 | 000,414,968 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.08.19 15:08:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.08.19 15:08:46 | 3220,017,152 | -HS- | M] () -- C:\hiberfil.sys
[2011.08.19 15:05:08 | 000,000,022 | ---- | M] () -- C:\Windows\tpcsd
[2011.08.19 15:04:51 | 000,001,067 | ---- | M] () -- C:\Users\MGA\Desktop\pcsafedoctor.lnk
[2011.08.19 14:59:04 | 000,002,068 | ---- | M] () -- C:\Users\MGA\Desktop\Start Download Manager.lnk
[2011.08.19 13:26:04 | 000,123,784 | ---- | M] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2011.08.19 13:26:03 | 000,088,288 | ---- | M] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2011.08.19 13:18:47 | 000,001,146 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.08.19 13:07:15 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011.08.19 09:40:35 | 000,177,271 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2011.08.19 09:40:35 | 000,177,271 | ---- | M] () -- C:\Windows\SysNative\license.rtf
========== Files Created - No Company Name ==========
[2011.08.19 15:48:32 | 000,001,121 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.08.19 15:05:08 | 000,000,022 | ---- | C] () -- C:\Windows\tpcsd
[2011.08.19 15:04:51 | 000,001,067 | ---- | C] () -- C:\Users\MGA\Desktop\pcsafedoctor.lnk
[2011.08.19 15:04:45 | 000,034,736 | ---- | C] () -- C:\Windows\SysWow64\drivers\RKHit.sys
[2011.08.19 14:18:35 | 000,002,068 | ---- | C] () -- C:\Users\MGA\Desktop\Start Download Manager.lnk
[2011.08.19 13:18:47 | 000,001,158 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011.08.19 13:18:47 | 000,001,146 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.08.19 13:17:49 | 000,383,786 | RHS- | C] () -- C:\bootmgr
[2011.08.19 13:09:12 | 000,027,772 | ---- | C] () -- C:\Windows\SysNative\arusb_lhx.inf
[2011.08.19 13:09:12 | 000,011,487 | ---- | C] () -- C:\Windows\SysNative\arusb_lhx.cat
[2011.08.19 13:08:25 | 000,046,904 | ---- | C] () -- C:\Windows\SysNative\arusb_win7x.inf
[2011.08.19 13:08:25 | 000,008,826 | ---- | C] () -- C:\Windows\SysNative\arusb_win7x.cat
[2011.08.19 13:07:15 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011.08.19 12:20:03 | 000,001,417 | ---- | C] () -- C:\Users\MGA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011.08.19 12:20:00 | 000,001,451 | ---- | C] () -- C:\Users\MGA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011.08.19 09:40:30 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011.08.19 09:40:26 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011.08.19 09:38:26 | 3220,017,152 | -HS- | C] () -- C:\hiberfil.sys
[2009.07.14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2009.07.14 07:08:49 | 000,002,898 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report > Code:
OTL Extras logfile created on: 19.08.2011 13:52:14 - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = B:\Clean Downloads
64bit- An unknown product Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 1,92 Gb Available Physical Memory | 48,01% Memory free
8,00 Gb Paging File | 5,78 Gb Available in Paging File | 72,24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 59,62 Gb Total Space | 40,51 Gb Free Space | 67,95% Space Free | Partition Type: NTFS
Drive D: | 100,00 Mb Total Space | 70,34 Mb Free Space | 70,34% Space Free | Partition Type: NTFS
Drive E: | 465,76 Gb Total Space | 25,67 Gb Free Space | 5,51% Space Free | Partition Type: NTFS
Drive F: | 931,50 Gb Total Space | 434,54 Gb Free Space | 46,65% Space Free | Partition Type: NTFS
Drive G: | 465,76 Gb Total Space | 44,30 Gb Free Space | 9,51% Space Free | Partition Type: NTFS
Drive H: | 3,83 Gb Total Space | 3,75 Gb Free Space | 98,07% Space Free | Partition Type: FAT32
Drive I: | 3,04 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Computer Name: MDG-PC | User Name: MGA | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{90140000-0015-0407-1000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0016-0407-1000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0018-0407-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0019-0407-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-001A-0407-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001B-0407-1000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0410-1000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-002C-0407-1000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0407-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (German) 2010
"{90140000-0044-0407-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010
"{90140000-006E-0407-1000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-00A1-0407-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00BA-0407-1000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010
"{91140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{E74A1D67-FFFE-4A15-9287-50B3C0465454}" = TL-WN821N-Drahtlos-Tool
"7-Zip" = 7-Zip 9.20
"Avira AntiVir Desktop" = Avira AntiVir Premium
"Mozilla Firefox 6.0 (x86 de)" = Mozilla Firefox 6.0 (x86 de)
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 19.08.2011 07:53:40 | Computer Name = MDG-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL".
Die
abhängige Assemblierung "Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.08""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 19.08.2011 07:53:40 | Computer Name = MDG-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL".
Die
abhängige Assemblierung "Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.08""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 19.08.2011 07:53:42 | Computer Name = MDG-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL".
Die
abhängige Assemblierung "Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.08""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 19.08.2011 07:53:43 | Computer Name = MDG-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL".
Die
abhängige Assemblierung "Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.08""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 19.08.2011 07:53:50 | Computer Name = MDG-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL".
Die
abhängige Assemblierung "Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.08""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 19.08.2011 07:53:52 | Computer Name = MDG-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL".
Die
abhängige Assemblierung "Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.08""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 19.08.2011 07:53:53 | Computer Name = MDG-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL".
Die
abhängige Assemblierung "Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.08""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 19.08.2011 07:53:55 | Computer Name = MDG-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL".
Die
abhängige Assemblierung "Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.08""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 19.08.2011 07:54:00 | Computer Name = MDG-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL".
Die
abhängige Assemblierung "Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.08""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 19.08.2011 07:54:03 | Computer Name = MDG-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL".
Die
abhängige Assemblierung "Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.08""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
[ System Events ]
Error - 19.08.2011 06:49:50 | Computer Name = MDG-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Superfetch" wurde mit folgendem Fehler beendet: %%1062
Error - 19.08.2011 07:27:32 | Computer Name = MDG-PC | Source = Service Control Manager | ID = 7006
Description = Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers
fehlgeschlagen: %%5
Error - 19.08.2011 07:27:40 | Computer Name = MDG-PC | Source = Service Control Manager | ID = 7006
Description = Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers
fehlgeschlagen: %%5
Error - 19.08.2011 07:27:41 | Computer Name = MDG-PC | Source = Service Control Manager | ID = 7006
Description = Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers
fehlgeschlagen: %%5
Error - 19.08.2011 07:36:26 | Computer Name = MDG-PC | Source = Application Popup | ID = 1060
Description = Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\Users\MGA\AppData\Local\Temp\mbr.sys
nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version
des Treibers zu erhalten.
Error - 19.08.2011 07:36:46 | Computer Name = MDG-PC | Source = Application Popup | ID = 1060
Description = Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\Users\MGA\AppData\Local\Temp\mbr.sys
nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version
des Treibers zu erhalten.
Error - 19.08.2011 07:36:46 | Computer Name = MDG-PC | Source = Application Popup | ID = 1060
Description = Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\Users\MGA\AppData\Local\Temp\mbr.sys
nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version
des Treibers zu erhalten.
Error - 19.08.2011 07:37:04 | Computer Name = MDG-PC | Source = Application Popup | ID = 1060
Description = Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\Users\MGA\AppData\Local\Temp\mbr.sys
nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version
des Treibers zu erhalten.
Error - 19.08.2011 07:37:04 | Computer Name = MDG-PC | Source = Application Popup | ID = 1060
Description = Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\Users\MGA\AppData\Local\Temp\mbr.sys
nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version
des Treibers zu erhalten.
< End of report > |