Skoigoth | 06.10.2011 14:25 | Bin nach Anleitung vorgegangen, hier die logs.
OTL Logfile: Code:
OTL logfile created on: 10/6/2011 5:26:42 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 80.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 94.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 74.52 Gb Total Space | 23.48 Gb Free Space | 31.51% Space Free | Partition Type: NTFS
Drive D: | 298.09 Gb Total Space | 218.84 Gb Free Space | 73.41% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet003
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto] -- -- (PhotoshopElementsDeviceConnect)
SRV - File not found [Auto] -- -- (PenCommService)
SRV - File not found [Auto] -- -- (AdobeActiveFileMonitor)
SRV - [2011/10/04 16:09:13 | 000,186,016 | ---- | M] (Symantec Corporation) [Auto] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr)
SRV - [2011/10/04 05:33:20 | 000,177,824 | ---- | M] (Symantec Corporation) [Auto] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe -- (ccSetMgr)
SRV - [2011/10/04 05:33:20 | 000,098,304 | ---- | M] (Canon Inc.) [Auto] -- C:\Programme\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2011/10/04 05:33:20 | 000,020,112 | ---- | M] (Symantec Corporation) [Auto] -- C:\Programme\Symantec AntiVirus\DefWatch.exe -- (DefWatch)
SRV - [2007/11/04 15:02:18 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2006/06/01 15:06:00 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2005/12/21 13:23:28 | 000,173,200 | ---- | M] (symantec) [Auto] -- C:\Programme\Symantec AntiVirus\SavRoam.exe -- (SavRoam)
SRV - [2005/12/21 13:22:52 | 001,779,856 | ---- | M] () [Auto] -- C:\Programme\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2005/11/09 10:41:20 | 000,083,616 | ---- | M] (Symantec Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc)
SRV - [2005/10/19 12:39:34 | 000,214,672 | ---- | M] (Symantec Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe -- (SNDSrvc)
SRV - [2005/03/30 16:48:22 | 000,992,864 | ---- | M] (Symantec Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (i2omgmt)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - [2011/10/04 16:12:33 | 000,000,000 | ---- | M] () [Kernel | On_Demand] -- C:\WINDOWS\3203397148 -- (1cf6efbe)
DRV - [2011/08/18 03:53:46 | 001,576,312 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\VirusDefs\20111002.004\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/08/18 03:53:46 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\VirusDefs\20111002.004\NAVENG.SYS -- (NAVENG)
DRV - [2011/07/28 04:00:00 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011/07/28 04:00:00 | 000,105,592 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2010/12/07 02:10:48 | 000,020,480 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\PulseUsb.sys -- (PulseUsb)
DRV - [2008/04/13 14:40:46 | 000,062,976 | ---- | M] () [Kernel | System] -- C:\WINDOWS\system32\drivers\cdrom.sys -- (Cdrom)
DRV - [2007/02/03 05:32:36 | 000,041,504 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007/02/03 05:25:56 | 001,075,360 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Camdrl.sys -- (CamDrL) Logitech QuickCam Pro 3000(CamDrl)
DRV - [2005/10/19 12:39:04 | 000,195,728 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2005/10/19 12:38:58 | 000,024,720 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2005/09/16 19:20:06 | 000,108,168 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Programme\Symantec\SYMEVENT.SYS -- (SymEvent)
DRV - [2005/08/26 09:22:50 | 000,053,896 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Programme\Symantec AntiVirus\Savrtpel.sys -- (SAVRTPEL)
DRV - [2005/08/26 09:22:48 | 000,334,984 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Programme\Symantec AntiVirus\savrt.sys -- (SAVRT)
DRV - [2005/03/30 16:48:20 | 000,372,832 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Programme\Gemeinsame Dateien\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2005/03/17 12:30:10 | 000,132,608 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2005/03/09 09:53:00 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005/02/08 17:33:06 | 000,970,240 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/10/28 05:05:00 | 000,369,024 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2004/09/21 14:53:18 | 002,278,784 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/08/03 12:29:50 | 000,019,455 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wVchNTxx.sys -- (iAimFP4)
DRV - [2004/08/03 12:29:48 | 000,012,063 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wSiINTxx.sys -- (iAimFP3)
DRV - [2004/08/03 12:29:46 | 000,025,471 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV10nt.sys -- (iAimTV5)
DRV - [2004/08/03 12:29:46 | 000,023,615 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wCh7xxNT.sys -- (iAimTV4)
DRV - [2004/08/03 12:29:46 | 000,022,271 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV06nt.sys -- (iAimTV6)
DRV - [2004/08/03 12:29:44 | 000,033,599 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV04nt.sys -- (iAimTV3)
DRV - [2004/08/03 12:29:44 | 000,019,551 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV02NT.sys -- (iAimTV1)
DRV - [2004/08/03 12:29:42 | 000,029,311 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wATV01nt.sys -- (iAimTV0)
DRV - [2004/08/03 12:29:42 | 000,011,871 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV09NT.sys -- (iAimFP7)
DRV - [2004/08/03 12:29:40 | 000,011,807 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV07nt.sys -- (iAimFP5)
DRV - [2004/08/03 12:29:40 | 000,011,295 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV08NT.sys -- (iAimFP6)
DRV - [2004/08/03 12:29:38 | 000,161,020 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x)
DRV - [2004/08/03 12:29:38 | 000,012,415 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV01nt.sys -- (iAimFP0)
DRV - [2004/08/03 12:29:38 | 000,012,127 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV02NT.sys -- (iAimFP1)
DRV - [2004/08/03 12:29:38 | 000,011,775 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\wADV05NT.sys -- (iAimFP2)
DRV - [2002/04/04 02:32:06 | 000,028,416 | R--- | M] (LSI Logic) [Kernel | Disabled] -- C:\WINDOWS\system32\DRIVERS\symmpi.sys -- (Symmpi)
DRV - [2001/08/17 07:53:32 | 000,003,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\qv2kux.sys -- (QV2KUX)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\christina_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\christina_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\christina_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\christina_ON_C\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\christina_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\christina_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ext.slsupport.de;wsus.slsupport.de;www.slsupport.de;mail.slsupport.de;www.beauty-and-kids.de;nbg.slsupport.de;banking.bayernlb.de;192.168.*.*;;<local>
IE - HKU\christina_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = proxy01.slsupport.de:8080
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
IE - HKU\pamela_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hp.com
IE - HKU\pamela_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\pamela_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ext.slsupport.de;wsus.slsupport.de;www.slsupport.de;mail.slsupport.de;www.beauty-and-kids.de;nbg.slsupport.de;banking.bayernlb.de;192.168.*.*;<local>
IE - HKU\pamela_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = proxy01.slsupport.de:8080
IE - HKU\Tina_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/
IE - HKU\Tina_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Dokumente und Einstellungen\christina\Anwendungsdaten\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks)
O1 HOSTS File: ([2004/08/03 22:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKU\Administrator_ON_C\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\christina_ON_C\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\christina_ON_C\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\pamela_ON_C\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\Tina_ON_C\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [ccApp] C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [OrderReminder] C:\Programme\Hewlett-Packard\OrderReminder\OrderReminder.exe (Hewlett-Packard)
O4 - HKLM..\Run: [PDFPrint] C:\Programme\pdf24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [SetRefresh] C:\Programme\Compaq\SetRefresh\SetRefresh.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [Update] C:\WINDOWS\system32\0.3662170036287826.exe ()
O4 - HKLM..\Run: [vptray] C:\Programme\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKU\christina_ON_C..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\christina_ON_C..\Run: [ICQ] File not found
O4 - HKU\pamela_ON_C..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\Tina_ON_C..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\Tina_ON_C..\Run: [ceek.exe] C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\Epaqk\ceek.exe ()
O4 - HKU\Tina_ON_C..\Run: [ICQ] C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O4 - HKU\Tina_ON_C..\Run: [svchoct.exe] C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\Microsoft\svchoct.exe (Company 'gora-sah')
O4 - HKU\pamela_ON_C..\RunOnce: [] File not found
O4 - HKU\pamela_ON_C..\RunOnce: [ICQ Lite] File not found
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\christina_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\christina_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\pamela_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\pamela_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\Tina_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0\bin\NPJPI150.dll (Sun Microsystems, Inc.)
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - File not found
O9 - Extra 'Tools' menuitem : ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - File not found
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} hxxp://www.lokalisten.de/iup/ImageUploader4.cab (Image Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} https://asp.photoprintit.de/microsite/3101/defaults/activex/ips/IPSUploader4.cab (IPSUploader4 Control)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = slsupport.de
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\Tina_ON_C Winlogon: Shell - (C:\Dokumente und Einstellungen\Tina\Lokale Einstellungen\Anwendungsdaten\1cf6efbe\X) - C:\Dokumente und Einstellungen\Tina\Lokale Einstellungen\Anwendungsdaten\1cf6efbe\X ()
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/23 04:08:25 | 000,000,000 | ---D | M] - D:\Autobrand -- [ NTFS ]
O32 - AutoRun File - [2009/10/18 18:21:04 | 000,000,000 | ---D | M] - D:\Automatenfotos -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{799a2a1e-8e15-11e0-84e6-001617c767df}\Shell - "" = AutoRun
O33 - MountPoints2\{799a2a1e-8e15-11e0-84e6-001617c767df}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{799a2a1e-8e15-11e0-84e6-001617c767df}\Shell\AutoRun\command - "" = G:\DataTraveler101R.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
File not found -- C:\WINDOWS\System32\
[2011/10/04 15:01:30 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\Ozor
[2011/10/04 15:01:30 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\Epaqk
[2011/10/03 19:54:25 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\Tina\Lokale Einstellungen\Anwendungsdaten\1cf6efbe
[2011/09/28 12:04:01 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dshowext.ax
[2011/09/28 12:04:01 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dshowext.ax
[2011/09/28 12:02:42 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\Engelmann Media
[2011/09/28 12:02:41 | 000,000,000 | ---D | C] -- C:\Programme\Engelmann Media
[2011/09/28 12:02:41 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Engelmann Media
[2011/09/28 12:02:40 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\HDX4
[2011/09/21 03:59:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
File not found -- C:\WINDOWS\System32\
[2011/10/04 16:12:33 | 000,000,000 | ---- | M] () -- C:\WINDOWS\3203397148
[2011/10/04 16:12:25 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/10/04 16:12:07 | 1541,984,256 | -HS- | M] () -- C:\hiberfil.sys
[2011/10/04 14:44:43 | 000,129,024 | ---- | M] () -- C:\WINDOWS\System32\0.3662170036287826.exe
[2011/10/04 14:44:42 | 000,084,480 | ---- | M] () -- C:\Dokumente und Einstellungen\Tina\Desktop\0.4146250320184266.exe
[2011/10/04 05:36:27 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/10/04 05:30:10 | 000,000,000 | -HS- | M] () -- C:\WINDOWS\{2521BB91-29B1-4d7e-9137-AC9875D77735}
[2011/10/02 20:46:32 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2011/10/02 20:17:47 | 000,002,641 | ---- | M] () -- C:\Dokumente und Einstellungen\Tina\.recently-used.xbel
[2011/10/02 19:00:12 | 000,000,151 | ---- | M] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2011/10/02 18:34:34 | 000,066,561 | ---- | M] () -- C:\Dokumente und Einstellungen\Tina\Desktop\paola3.jpg
[2011/10/02 18:31:30 | 000,057,516 | ---- | M] () -- C:\Dokumente und Einstellungen\Tina\Desktop\paola1.jpg
[2011/10/02 18:30:37 | 000,066,260 | ---- | M] () -- C:\Dokumente und Einstellungen\Tina\Desktop\paola2.jpg
[2011/09/29 16:53:05 | 000,000,119 | ---- | M] () -- C:\Dokumente und Einstellungen\Tina\default.pls
[2011/09/29 04:31:05 | 000,002,509 | ---- | M] () -- C:\Dokumente und Einstellungen\Tina\Desktop\Microsoft Office Word 2003.lnk
[2011/09/28 18:10:42 | 000,183,800 | ---- | M] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2011/09/28 12:02:44 | 000,000,877 | ---- | M] () -- C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Photomizer SE.lnk
[2011/09/28 12:02:44 | 000,000,859 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Photomizer SE.lnk
[2011/09/28 12:02:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Engelmann Media
[2011/09/25 04:31:05 | 000,311,565 | ---- | M] () -- C:\Dokumente und Einstellungen\Tina\Desktop\1. Versuch 26.08.pdf
[2011/09/25 04:18:50 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/09/23 16:14:18 | 000,002,545 | ---- | M] () -- C:\Dokumente und Einstellungen\Tina\Desktop\Microsoft Office PowerPoint 2003.lnk
[2011/09/16 09:11:53 | 000,364,777 | ---- | M] () -- C:\Dokumente und Einstellungen\Tina\Desktop\pamela_tattoo.jpg
[2011/09/14 03:29:02 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/09/09 05:11:59 | 000,604,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\crypt32.dll
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/10/04 14:44:45 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\0.3662170036287826.exe
[2011/10/04 14:44:41 | 000,084,480 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\Desktop\0.4146250320184266.exe
[2011/10/04 05:30:10 | 000,000,000 | -HS- | C] () -- C:\WINDOWS\{2521BB91-29B1-4d7e-9137-AC9875D77735}
[2011/10/03 19:54:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\3203397148
[2011/10/02 20:17:47 | 000,002,641 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\.recently-used.xbel
[2011/10/02 18:35:09 | 000,066,561 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\Desktop\paola3.jpg
[2011/10/02 18:32:25 | 000,066,260 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\Desktop\paola2.jpg
[2011/10/02 18:32:14 | 000,057,516 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\Desktop\paola1.jpg
[2011/09/29 16:55:26 | 046,445,814 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\Desktop\Family Guy 03x06 - Death Lives.mp4
[2011/09/29 16:54:37 | 050,045,674 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\Desktop\Family Guy 02x02 - Holy Crap.mp4
[2011/09/29 16:52:06 | 043,360,824 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\Desktop\Family Guy 03x17 - Brian Wallows and Peter's Swallows.mp4
[2011/09/29 16:51:50 | 040,865,942 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\Desktop\Family Guy 03x19 - Stuck Together, Torn Apart.mp4
[2011/09/28 18:10:42 | 000,183,800 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2011/09/28 12:02:44 | 000,000,877 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Photomizer SE.lnk
[2011/09/28 12:02:44 | 000,000,859 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Photomizer SE.lnk
[2011/09/25 04:31:05 | 000,311,565 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\Desktop\1. Versuch 26.08.pdf
[2011/09/20 10:00:28 | 000,364,777 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\Desktop\pamela_tattoo.jpg
[2011/09/08 06:01:39 | 047,804,984 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\Desktop\Family Guy 04x03 - Blind Ambition.mp4
[2011/06/22 12:06:17 | 000,005,120 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/20 10:59:30 | 000,000,119 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\default.pls
[2011/03/16 14:15:30 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\Tina\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2011/01/11 08:56:21 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/06/29 16:12:04 | 000,000,096 | ---- | C] () -- C:\WINDOWS\VPPLAYS.INI
[2010/06/28 07:56:08 | 000,015,514 | ---- | C] () -- C:\Dokumente und Einstellungen\christina\.recently-used.xbel
[2009/11/02 15:50:02 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2008/02/28 11:16:09 | 000,000,010 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2008/01/15 12:23:42 | 000,001,783 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\QTSBandwidthCache
[2008/01/10 11:54:06 | 000,442,368 | R--- | C] () -- C:\WINDOWS\System32\zshp1018.exe
[2008/01/10 11:54:06 | 000,106,496 | R--- | C] () -- C:\WINDOWS\System32\vshp1018.dll
[2008/01/07 11:59:41 | 000,009,277 | R--- | C] () -- C:\WINDOWS\AmvTransform.ini
[2008/01/07 11:59:41 | 000,008,157 | R--- | C] () -- C:\WINDOWS\AmvPlayer.ini
[2008/01/07 11:59:41 | 000,007,454 | R--- | C] () -- C:\WINDOWS\Disktool.INI
[2008/01/07 11:59:41 | 000,003,677 | R--- | C] () -- C:\WINDOWS\SoundCon.INI
[2008/01/07 11:59:41 | 000,000,170 | R--- | C] () -- C:\WINDOWS\settings.ini
[2008/01/07 11:59:40 | 000,008,913 | R--- | C] () -- C:\WINDOWS\fwupgrade.ini
[2007/10/03 11:14:41 | 000,000,027 | ---- | C] () -- C:\WINDOWS\ZigarettenS.ini
[2007/10/03 11:14:19 | 000,000,153 | ---- | C] () -- C:\WINDOWS\Zigarettenschachtel-Spruch.ini
[2007/07/01 16:39:19 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\pxhpinst.exe
[2007/03/31 06:45:43 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\pamela\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2007/02/08 09:26:46 | 000,000,517 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2007/02/08 09:26:23 | 000,000,248 | ---- | C] () -- C:\WINDOWS\KLETT.INI
[2007/02/03 03:59:04 | 000,050,127 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2007/01/10 08:54:40 | 000,000,338 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2006/11/26 19:01:31 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2006/11/18 10:50:56 | 000,222,720 | ---- | C] () -- C:\Dokumente und Einstellungen\christina\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/11/05 16:19:15 | 000,000,103 | ---- | C] () -- C:\Dokumente und Einstellungen\christina\default.pls
[2006/11/05 16:18:52 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006/11/05 12:55:34 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\christina\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2006/11/04 11:22:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2006/11/04 10:44:07 | 000,001,040 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/10/23 13:47:43 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2006/10/23 13:46:44 | 000,073,845 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/10/23 13:45:53 | 000,000,796 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006/10/23 05:06:50 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/10/23 04:58:44 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006/10/23 04:58:44 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006/10/23 04:58:44 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006/10/23 04:58:44 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006/10/23 04:58:44 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006/10/23 04:58:44 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006/10/23 04:57:59 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2006/10/23 04:54:32 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2006/06/01 15:06:00 | 000,005,702 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2004/09/16 08:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 08:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\ADFUUD.SYS
[2004/08/09 02:20:34 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/09 02:05:00 | 000,463,074 | ---- | C] () -- C:\WINDOWS\System32\perfh007.dat
[2004/08/09 02:05:00 | 000,444,586 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/09 02:05:00 | 000,085,964 | ---- | C] () -- C:\WINDOWS\System32\perfc007.dat
[2004/08/09 02:05:00 | 000,072,462 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/09 02:01:16 | 001,564,056 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/09 01:54:14 | 000,004,429 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/09 01:49:14 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/03 22:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/03 22:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/03 22:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\perfi007.dat
[2004/08/03 22:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/03 22:00:00 | 000,062,976 | ---- | C] () -- C:\WINDOWS\System32\drivers\cdrom.sys
[2004/08/03 22:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/03 22:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\perfd007.dat
[2004/08/03 22:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/03 22:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/03 22:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/03 22:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2002/05/28 04:55:42 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2002/05/28 04:54:40 | 000,004,605 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
========== LOP Check ==========
[2008/02/21 07:41:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\AmuletAdventure
[2008/02/20 09:43:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\Big Fish Games
[2010/06/19 13:48:40 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\Crossword Compiler Deutsch 8
[2009/03/11 13:59:31 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\digital publishing
[2009/12/09 13:09:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\fotobuch.de AG
[2010/05/05 10:53:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\FreeMoviesToDVD
[2010/06/21 16:37:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\gtk-2.0
[2009/11/01 17:23:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\GTM_Bodie
[2009/11/02 13:20:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\HdO Adventure
[2011/03/03 13:17:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\ICQ
[2007/02/13 13:41:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\ICQLite
[2007/02/17 07:44:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\InterVideo
[2009/10/09 06:19:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\Mobipocket
[2010/04/23 17:18:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\NCH Swift Sound
[2010/03/25 18:04:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\Recordpad
[2009/08/20 18:25:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\Reflexive 3 Days Zoo Mystery
[2011/03/16 11:23:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\TeamViewer
[2010/12/28 09:22:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\christina\Anwendungsdaten\Temp
[2011/09/28 12:02:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\Engelmann Media
[2011/10/04 15:01:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\Epaqk
[2011/07/15 06:35:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\go
[2011/08/29 17:27:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\gtk-2.0
[2011/10/02 17:26:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\ICQ
[2011/06/03 15:14:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\Kingston
[2011/10/04 16:08:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\Ozor
[2011/06/21 03:59:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tina\Anwendungsdaten\XnView
[2009/11/02 13:57:43 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AdventureChronicles1
[2011/07/15 06:36:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Easybits GO
[2007/07/10 14:41:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\espionServerData
[2009/12/09 13:09:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\fotobuch.de AG
[2009/11/01 16:11:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\GameHouse
[2009/11/01 18:17:40 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Gogii
[2010/06/19 13:40:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ICQ
[2010/12/28 09:36:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Livescribe
[2009/12/24 11:11:25 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MumboJumbo
[2010/04/23 17:18:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NCH Swift Sound
[2008/03/02 14:13:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
[2010/03/28 18:03:01 | 000,000,294 | ---- | M] () -- C:\WINDOWS\Tasks\expressripShakeIcon.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 128 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:861A898F
@Alternate Data Stream - 119 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:B623B5B8
@Alternate Data Stream - 115 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:981884E7
@Alternate Data Stream - 109 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:0D31DA45
< End of report > --- --- --- |