Hi,
habe die Windows-Partition platt gemacht und Win7 neu aufgesetzt und nach Anleitung abgesichert.
Jetzt benutze ich Avast und das meldet nichts.
Auch malwarebytes meldet keine Fehler mehr.
Die Daten habe ich auf einen Stick "gerettet". Avast meldet bei einem Scan auch hier keine Vorkommnisse.
Einzig merkwürdig finde ich, das obwohl gelöscht immer wieder eine "AUTORUN.INF" auf dem Stick erscheint. Macht das Win7 automatisch? Ich habe die Autorun-Funktion eigentlich deaktiviert wie beschrieben. Das macht er auch nur wenn der Stick auf FAT formatiert ist, nicht bei NTFS. Die Datei kann ich wegen fehlender Rechte nicht öffnen, auf Ubuntu mit gedit geöffnet steht dort "caacaacaacaacaa\00" drin. Hmm?!
Hier noch die Logs von OTL, bin ich befreit?
OTL: Code:
OTL logfile created on: 12.07.2012 21:20:20 - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\***\Downloads
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,93 Gb Available Physical Memory | 73,28% Memory free
8,00 Gb Paging File | 6,84 Gb Available in Paging File | 85,53% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 49,91 Gb Total Space | 25,68 Gb Free Space | 51,45% Space Free | Partition Type: NTFS
Drive D: | 34,19 Gb Total Space | 34,06 Gb Free Space | 99,62% Space Free | Partition Type: NTFS
Computer Name: *** | User Name: *** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.07.12 21:18:24 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\***\Downloads\OTL.exe
PRC - [2012.07.03 18:21:30 | 004,273,976 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012.07.03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.06.27 09:25:06 | 001,326,176 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\psia.exe
PRC - [2012.01.18 06:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
========== Modules (No Company Name) ==========
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2012.07.03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2011.04.20 02:04:20 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012.06.27 09:25:06 | 001,326,176 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\psia.exe -- (Secunia PSI Agent)
SRV - [2012.06.27 09:25:04 | 000,681,056 | ---- | M] (Secunia) [Auto | Stopped] -- C:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2012.01.18 06:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012.07.03 18:21:52 | 000,958,400 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2012.07.03 18:21:52 | 000,355,856 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2012.07.03 18:21:52 | 000,071,064 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2012.07.03 18:21:52 | 000,059,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2012.07.03 18:21:52 | 000,054,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2012.07.03 18:21:51 | 000,025,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.01.18 06:44:36 | 004,865,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64) Logitech Webcam Pro 9000(UVC)
DRV:64bit: - [2012.01.18 06:44:28 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2011.12.16 16:20:10 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI)
DRV:64bit: - [2011.04.20 02:44:50 | 009,319,936 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2011.04.20 02:44:50 | 009,319,936 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011.04.20 01:22:34 | 000,306,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.03.01 23:05:32 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2005.03.29 01:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 19 4D 53 AA 2C 60 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKCU..\Run: [FileHippo.com] C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe (FileHippo.com)
O4:64bit: - HKLM..\RunOnce: [BrowserChoice] C:\Windows\SysNative\browserchoice.exe (Microsoft Corporation)
O4:64bit: - HKLM..\RunOnce: [MSKSSRV] rundll32.exe streamci,StreamingDeviceSetup {96E080C7-143C-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196} File not found
O4:64bit: - HKLM..\RunOnce: [MSPCLOCK] rundll32.exe streamci,StreamingDeviceSetup {97ebaacc-95bd-11d0-a3ea-00a0c9223196},{53172480-4791-11D0-A5D6-28DB04C10000},{53172480-4791-11D0-A5D6-28DB04C10000} File not found
O4:64bit: - HKLM..\RunOnce: [MSPQM] rundll32.exe streamci,StreamingDeviceSetup {DDF4358E-BB2C-11D0-A42F-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196} File not found
O4:64bit: - HKLM..\RunOnce: [MSTEE.CxTransform] rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},C:\Windows\inf\ksfilter.inf,MSTEE.Interface.Install File not found
O4:64bit: - HKLM..\RunOnce: [MSTEE.Splitter] rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},C:\Windows\inf\ksfilter.inf,MSTEE.Interface.Install File not found
O4:64bit: - HKLM..\RunOnce: [WDM_DRMKAUD] rundll32.exe streamci,StreamingDeviceSetup {EEC12DB6-AD9C-4168-8658-B03DAEF417FE},{ABD61E00-9350-47e2-A632-4438B90C6641},{FFBB6E3F-CCFE-4D84-90D9-421418B03A8E},C:\Windows\inf\WDMAUDIO.inf,WDM_DRMKAUD.Interface.Install File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 81.173.194.69 81.173.194.77 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6119F54D-7525-441A-9A20-6A92BF43543A}: DhcpNameServer = 81.173.194.69 81.173.194.77 192.168.1.1
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012.07.13 00:18:35 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2012.07.13 00:18:22 | 000,000,000 | -HSD | C] -- C:\Boot
[2012.07.12 17:42:14 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\WindowsUpdate
[2012.07.12 17:10:15 | 000,025,232 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012.07.12 17:10:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012.07.12 17:10:14 | 000,355,856 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2012.07.12 17:10:13 | 000,054,072 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2012.07.12 17:10:11 | 000,958,400 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2012.07.12 17:10:11 | 000,059,728 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2012.07.12 17:10:08 | 000,071,064 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012.07.12 17:10:07 | 000,285,328 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2012.07.12 16:52:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2012.07.12 16:27:15 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview
[2012.07.12 16:26:41 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders
[2012.07.12 16:26:38 | 000,000,000 | ---D | C] -- C:\cd0578272692b3f3f6fcb5a62f72
[2012.07.12 16:25:05 | 000,116,224 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\fms.dll
[2012.07.12 16:24:50 | 000,093,696 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysWow64\fms.dll
[2012.07.12 15:41:00 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012.07.12 15:32:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\logishrd
[2012.07.12 15:16:16 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\Secunia PSI
[2012.07.12 15:16:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Secunia
[2012.07.12 15:15:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileHippo.com
[2012.07.12 15:12:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Panda Security
[2012.07.12 15:12:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Panda USB Vaccine
[2012.07.12 15:12:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
[2012.07.12 15:08:37 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.07.12 15:08:36 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2012.07.12 15:08:24 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2012.07.12 15:08:24 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012.07.12 15:07:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\logishrd
[2012.07.12 14:49:19 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2012.07.12 14:42:30 | 000,000,000 | R--D | C] -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012.07.12 14:42:30 | 000,000,000 | R--D | C] -- C:\Users\***\Searches
[2012.07.12 14:42:30 | 000,000,000 | R--D | C] -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012.07.12 14:42:30 | 000,000,000 | -H-D | C] -- C:\Users\***\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012.07.12 14:42:20 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Identities
[2012.07.12 14:42:13 | 000,000,000 | R--D | C] -- C:\Users\***\Contacts
[2012.07.12 14:42:12 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\VirtualStore
[2012.07.12 14:42:08 | 000,000,000 | --SD | C] -- C:\Users\***\AppData\Roaming\Microsoft
[2012.07.12 14:42:08 | 000,000,000 | R--D | C] -- C:\Users\***\Videos
[2012.07.12 14:42:08 | 000,000,000 | R--D | C] -- C:\Users\***\Saved Games
[2012.07.12 14:42:08 | 000,000,000 | R--D | C] -- C:\Users\***\Pictures
[2012.07.12 14:42:08 | 000,000,000 | R--D | C] -- C:\Users\***\Music
[2012.07.12 14:42:08 | 000,000,000 | R--D | C] -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012.07.12 14:42:08 | 000,000,000 | R--D | C] -- C:\Users\***\Links
[2012.07.12 14:42:08 | 000,000,000 | R--D | C] -- C:\Users\***\Favorites
[2012.07.12 14:42:08 | 000,000,000 | R--D | C] -- C:\Users\***\Downloads
[2012.07.12 14:42:08 | 000,000,000 | R--D | C] -- C:\Users\***\Documents
[2012.07.12 14:42:08 | 000,000,000 | R--D | C] -- C:\Users\***\Desktop
[2012.07.12 14:42:08 | 000,000,000 | R--D | C] -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\AppData\Local\Temporary Internet Files
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\Templates
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\Start Menu
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\SendTo
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\Recent
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\PrintHood
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\NetHood
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\Documents\My Videos
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\Documents\My Pictures
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\Documents\My Music
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\My Documents
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\Local Settings
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\AppData\Local\History
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\Cookies
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\Application Data
[2012.07.12 14:42:08 | 000,000,000 | -HSD | C] -- C:\Users\***\AppData\Local\Application Data
[2012.07.12 14:42:08 | 000,000,000 | -H-D | C] -- C:\Users\***\AppData
[2012.07.12 14:42:08 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\Temp
[2012.07.12 14:42:08 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\Microsoft
[2012.07.12 14:42:08 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Media Center Programs
[2012.07.12 14:41:55 | 000,000,000 | -HSD | C] -- C:\Recovery
[2012.07.12 14:22:02 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012.07.12 14:19:55 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2012.07.12 14:19:22 | 000,000,000 | -HSD | C] -- C:\System Volume Information
========== Files - Modified Within 30 Days ==========
[2012.07.13 00:18:23 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2012.07.12 21:17:42 | 000,000,000 | ---- | M] () -- C:\Users\***\defogger_reenable
[2012.07.12 21:09:00 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1915811251-3298005370-531009630-1003UA.job
[2012.07.12 21:08:56 | 000,726,316 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.07.12 21:08:56 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.07.12 21:08:56 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.07.12 21:05:10 | 000,010,112 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.12 21:05:10 | 000,010,112 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.12 21:04:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.12 21:04:08 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\lvuvc.hs
[2012.07.12 21:04:07 | 3220,578,304 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.12 17:12:31 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012.07.12 17:10:15 | 000,001,922 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012.07.12 17:09:00 | 000,001,072 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1915811251-3298005370-531009630-1003Core.job
[2012.07.12 16:48:51 | 000,274,464 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.07.12 15:16:12 | 000,001,106 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012.07.12 15:15:53 | 000,001,969 | ---- | M] () -- C:\Users\***\Desktop\Update Checker.lnk
[2012.07.12 15:06:08 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2012.07.12 15:06:06 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2012.07.12 14:48:36 | 000,001,437 | ---- | M] () -- C:\Users\***\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012.07.12 14:22:16 | 000,042,049 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2012.07.12 14:22:16 | 000,042,049 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2012.07.12 14:21:07 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2012.07.03 18:21:52 | 000,958,400 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2012.07.03 18:21:52 | 000,355,856 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2012.07.03 18:21:52 | 000,071,064 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012.07.03 18:21:52 | 000,059,728 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2012.07.03 18:21:52 | 000,054,072 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2012.07.03 18:21:51 | 000,025,232 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012.07.03 18:21:32 | 000,041,224 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.07.03 18:21:28 | 000,227,648 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2012.07.03 18:21:18 | 000,285,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
========== Files Created - No Company Name ==========
[2012.07.13 00:18:23 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK
[2012.07.13 00:18:22 | 000,383,786 | RHS- | C] () -- C:\bootmgr
[2012.07.12 21:17:42 | 000,000,000 | ---- | C] () -- C:\Users\***\defogger_reenable
[2012.07.12 17:10:15 | 000,001,922 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012.07.12 17:10:07 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2012.07.12 17:04:58 | 000,001,124 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1915811251-3298005370-531009630-1003UA.job
[2012.07.12 17:04:55 | 000,001,072 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1915811251-3298005370-531009630-1003Core.job
[2012.07.12 16:25:34 | 000,347,904 | ---- | C] () -- C:\Windows\SysNative\systemsf.ebd
[2012.07.12 16:24:39 | 000,010,429 | ---- | C] () -- C:\Windows\SysNative\ScavengeSpace.xml
[2012.07.12 16:24:33 | 000,105,559 | ---- | C] () -- C:\Windows\SysWow64\RacRules.xml
[2012.07.12 16:24:33 | 000,105,559 | ---- | C] () -- C:\Windows\SysNative\RacRules.xml
[2012.07.12 16:24:27 | 000,146,389 | ---- | C] () -- C:\Windows\SysWow64\printmanagement.msc
[2012.07.12 16:24:27 | 000,001,041 | ---- | C] () -- C:\Windows\SysWow64\tcpbidi.xml
[2012.07.12 15:32:43 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\drivers\lvuvc.hs
[2012.07.12 15:16:12 | 000,001,106 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012.07.12 15:16:12 | 000,001,069 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2012.07.12 15:15:53 | 000,001,999 | ---- | C] () -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Update Checker.lnk
[2012.07.12 15:15:53 | 000,001,969 | ---- | C] () -- C:\Users\***\Desktop\Update Checker.lnk
[2012.07.12 15:06:08 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2012.07.12 15:06:06 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2012.07.12 14:48:36 | 000,001,437 | ---- | C] () -- C:\Users\***\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012.07.12 14:42:36 | 000,001,443 | ---- | C] () -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.07.12 14:42:36 | 000,001,409 | ---- | C] () -- C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012.07.12 14:42:08 | 000,000,290 | ---- | C] () -- C:\Users\***\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012.07.12 14:42:08 | 000,000,272 | ---- | C] () -- C:\Users\***\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012.07.12 14:22:13 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012.07.12 14:22:06 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012.07.12 14:21:07 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.07.12 14:19:22 | 3220,578,304 | -HS- | C] () -- C:\hiberfil.sys
[2012.01.18 06:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2012.01.18 06:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2012.01.18 06:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2011.03.17 17:51:46 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
========== LOP Check ==========
[2009.07.14 07:08:49 | 000,003,342 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report > EXTRAS Code:
OTL Extras logfile created on: 12.07.2012 21:20:20 - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\***\Downloads
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,93 Gb Available Physical Memory | 73,28% Memory free
8,00 Gb Paging File | 6,84 Gb Available in Paging File | 85,53% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 49,91 Gb Total Space | 25,68 Gb Free Space | 51,45% Space Free | Partition Type: NTFS
Drive D: | 34,19 Gb Total Space | 34,06 Gb Free Space | 99,62% Space Free | Partition Type: NTFS
Computer Name: *** | User Name: *** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{099BBEFD-56A1-4B25-BFB7-D546AF07AED9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{18BFB4AA-A4D8-4478-A568-2848B646ED8C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{285C1EEE-9E60-49B4-8AC2-7D6F30E09596}" = lport=445 | protocol=6 | dir=in | app=system |
"{342A3FD2-050B-4011-AEAD-6FED9B4A1077}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{41C4E8D7-CA4B-45F5-BFD0-12836C7BDE58}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{66494ABE-CD00-44D7-9208-12FA5BE794A1}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{7E19E266-21C6-4EEF-9C71-E400999A8DB1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7F54235D-2198-4823-ACE5-EA16D16DF261}" = rport=445 | protocol=6 | dir=out | app=system |
"{805FDFC3-D44C-4368-8C9F-2425BBA37536}" = rport=137 | protocol=17 | dir=out | app=system |
"{832C639F-20E1-41A5-97C4-051907FE4BF9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8C60EFF8-3C44-4B50-A0F9-0BEA1BD13E58}" = lport=138 | protocol=17 | dir=in | app=system |
"{90FE7E59-554C-464D-9705-E12627A098D8}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9BABD8AE-BAB0-4EEC-AB82-5F5CE94798C3}" = lport=10243 | protocol=6 | dir=in | app=system |
"{A6682ACF-8629-4935-BF96-883259485881}" = rport=138 | protocol=17 | dir=out | app=system |
"{A7CEC462-3AF9-4452-834A-CEF3A3ACC187}" = lport=2869 | protocol=6 | dir=in | app=system |
"{AB7D07C0-7E66-4AFA-A5BB-19B5B8FB92D5}" = rport=139 | protocol=6 | dir=out | app=system |
"{AF240036-FD8B-46F4-B0FE-481734DCE705}" = lport=139 | protocol=6 | dir=in | app=system |
"{BFE2B293-AAD8-42DD-81A5-F7F176529CB2}" = rport=10243 | protocol=6 | dir=out | app=system |
"{D4C62035-EC12-47BA-932F-883C4ED91DE3}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E9EA752B-F948-439D-8759-406B1665233C}" = lport=137 | protocol=17 | dir=in | app=system |
"{F20B21A6-89F8-4F82-8551-2402126C13E4}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1457F931-060D-4615-A1F0-867AC11E1971}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{221F2570-E1DB-4CE8-8107-B4E350A79AE7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2486F137-6D22-4BF2-838D-C6A6928ABDCA}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3B6AF9FA-7CFA-43EC-83E0-D61C60EDD43A}" = protocol=6 | dir=out | app=system |
"{42C84B8E-27D1-4D96-A5C6-256A54B8F2A9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{616EF8CA-F628-4024-87A5-4DDC0E1DB193}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8B6FE0CE-0C49-4F5B-B4A9-05473C849C1F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{B1D5E156-50A7-43E8-94F3-1FD534492282}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B880270F-993C-45B3-A945-A6DB585934F1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C30E8108-601E-4932-80A7-EEB555F007EE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CD4C1A42-4302-4EBC-A120-D2D3CACA358F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{D0482F66-9D92-412D-A292-48275F2F4887}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{D8C3390C-1352-4398-841E-0158AB1C134E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E3224C9F-8454-42C8-9F56-6C2F19C89B9F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{E5A7E9E9-3C3A-47D8-BD20-C921EA12DFB7}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E6DF8D7C-D215-4349-B820-C4B4090EAEFA}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{F8764346-9F1D-4C88-BD90-E152B7653D37}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{FD4E6A97-1417-4AFB-9F7C-29D1709CC1E0}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{FF8637F2-D390-40D1-BDA4-CA5920239876}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1" = Panda USB Vaccine 1.0.1.4
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"avast" = avast! Free Antivirus
"FileHippo.com" = FileHippo.com Update Checker
"Secunia PSI" = Secunia PSI (3.0.0.2004)
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 12.07.2012 10:46:25 | Computer Name = *** | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 12.07.2012 10:46:28 | Computer Name = *** | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 12.07.2012 10:46:28 | Computer Name = *** | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 12.07.2012 10:46:28 | Computer Name = *** | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 12.07.2012 10:46:29 | Computer Name = *** | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 12.07.2012 10:46:29 | Computer Name = *** | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 12.07.2012 10:46:29 | Computer Name = *** | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 12.07.2012 10:52:11 | Computer Name = *** | Source = MsiInstaller | ID = 11704
Description =
Error - 12.07.2012 11:03:55 | Computer Name = *** | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16447 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: aa8 Start
Time: 01cd603f7df57f28 Termination Time: 2 Application Path: C:\Program Files (x86)\Internet
Explorer\iexplore.exe Report Id:
Error - 12.07.2012 11:10:07 | Computer Name = *** | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\AVAST Software\Avast\asOutExt64.dll".
Dependent
Assembly Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
could not be found. Please use sxstrace.exe for detailed diagnosis.
[ System Events ]
Error - 12.07.2012 10:07:31 | Computer Name = *** | Source = DCOM | ID = 10010
Description =
Error - 12.07.2012 10:09:43 | Computer Name = *** | Source = Service Control Manager | ID = 7023
Description = The Windows Modules Installer service terminated with the following
error: %%16405
Error - 12.07.2012 10:10:02 | Computer Name = *** | Source = DCOM | ID = 10010
Description =
Error - 12.07.2012 10:35:10 | Computer Name = *** | Source = DCOM | ID = 10010
Description =
Error - 12.07.2012 10:46:15 | Computer Name = *** | Source = DCOM | ID = 10010
Description =
Error - 12.07.2012 11:01:30 | Computer Name = *** | Source = DCOM | ID = 10010
Description =
Error - 12.07.2012 11:19:35 | Computer Name = *** | Source = DCOM | ID = 10010
Description =
Error - 12.07.2012 11:56:46 | Computer Name = *** | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070005: Security Update for Microsoft .NET Framework 4 on XP, Server
2003, Vista, Windows 7, Server 2008, Server 2008 R2 for x64 (KB2686827).
Error - 12.07.2012 11:56:51 | Computer Name = *** | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070005: Security Update for Microsoft .NET Framework 4 on XP, Server
2003, Vista, Windows 7, Server 2008, Server 2008 R2 for x64 (KB2656405).
Error - 12.07.2012 12:08:49 | Computer Name = *** | Source = DCOM | ID = 10010
Description =
< End of report > |