helpneeded | 23.10.2012 22:01 | hat geklappt! Code:
OTL logfile created on: 23.10.2012 22:49:22 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\***\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,00 Gb Total Physical Memory | 1,74 Gb Available Physical Memory | 87,28% Memory free
3,85 Gb Paging File | 3,77 Gb Available in Paging File | 98,01% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 460,96 Gb Total Space | 358,09 Gb Free Space | 77,68% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Computer Name: DHWPK82J | User Name: *** | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.10.23 22:47:13 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\***\Desktop\OTL.exe
PRC - [2008.04.14 04:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe -- (de_serv)
SRV - [2012.09.20 19:52:50 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.09.06 03:26:40 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.08.11 16:43:06 | 000,055,184 | ---- | M] (Apple Inc.) [Auto | Stopped] -- C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2012.05.02 01:42:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.02 00:55:21 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Programme\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService)
SRV - [2012.05.02 00:34:34 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2006.05.12 14:21:38 | 000,069,632 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Creative Labs Shared\Service\CreativeLicensing.exe -- (Creative Labs Licensing Service)
SRV - [2005.12.12 17:52:32 | 000,180,224 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Programme\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe -- (ELService)
SRV - [2005.06.17 08:55:58 | 000,086,140 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMon)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | Boot | Stopped] -- system32\drivers\Combo-Fix.sys -- (vkquwexg)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\NETFWDSL.SYS -- (NETFWDSL)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOKUME~1\GNTER(~1\LOKALE~1\Temp\catchme.sys -- (catchme)
DRV - [2012.04.27 10:20:04 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.04.25 00:32:27 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.04.16 21:17:40 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2006.12.08 15:02:50 | 000,275,072 | ---- | M] (Guillemont Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HDvid.sys -- (APL531)
DRV - [2006.11.16 17:01:42 | 000,024,192 | ---- | M] (Guillemot Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\camfilt.sys -- (camfilt)
DRV - [2006.09.18 15:59:08 | 000,090,800 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se27unic.sys -- (se27unic)
DRV - [2006.09.18 15:59:02 | 000,086,560 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SE27obex.sys -- (SE27obex)
DRV - [2006.09.18 15:59:00 | 000,018,704 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se27nd5.sys -- (se27nd5)
DRV - [2006.09.18 15:58:58 | 000,088,688 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SE27mgmt.sys -- (SE27mgmt)
DRV - [2006.09.18 15:58:48 | 000,061,600 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SE27bus.sys -- (SE27bus)
DRV - [2005.12.12 17:52:34 | 000,010,112 | ---- | M] (Intel Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ELhid.sys -- (ELhid)
DRV - [2005.12.12 17:52:34 | 000,007,040 | ---- | M] (Intel Corporation) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\ELmon.sys -- (ELmon)
DRV - [2005.12.12 17:52:34 | 000,006,912 | ---- | M] (Intel Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ELkbd.sys -- (ELkbd)
DRV - [2005.12.12 17:52:34 | 000,006,400 | ---- | M] (Intel Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ELmou.sys -- (ELmou)
DRV - [2005.12.12 17:52:32 | 000,007,808 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ELacpi.sys -- (ELacpi)
DRV - [2005.10.21 07:25:32 | 000,013,396 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MTictwl.sys -- (MagicTune)
DRV - [2005.09.22 19:19:54 | 000,148,608 | ---- | M] (Hauppauge Computer Works, Inc.) [23|25|26]xxx) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hcwPP2.sys -- (hcwPP2)
DRV - [2005.09.08 06:20:00 | 000,094,332 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2005.09.08 06:20:00 | 000,087,036 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2005.09.08 06:20:00 | 000,086,524 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2005.09.08 06:20:00 | 000,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2005.09.08 06:20:00 | 000,014,684 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2005.09.08 06:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2005.09.08 06:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2005.08.25 13:16:52 | 000,005,628 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2005.08.25 13:16:16 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2005.06.06 22:40:48 | 000,180,736 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2005.05.25 23:34:00 | 000,158,464 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTUSFSYN.SYS -- (CTUSFSYN)
DRV - [2005.03.25 17:11:00 | 001,350,272 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sigfilt.sys -- (sigfilt)
DRV - [2005.01.11 01:15:00 | 000,138,752 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTSFM2K.SYS -- (ctsfm2k)
DRV - [2005.01.11 01:15:00 | 000,106,496 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTOSS2K.SYS -- (ossrv)
DRV - [2004.12.23 02:58:00 | 000,008,704 | ---- | M] (Creative Technology Ltd.) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\PFMODNT.SYS -- (PfModNT)
DRV - [2004.06.11 02:00:00 | 000,016,384 | R--- | M] (AVM GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avmunet.sys -- (AVMUNET)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3725954371-1878462329-840030287-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3725954371-1878462329-840030287-1006\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3725954371-1878462329-840030287-1006\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3725954371-1878462329-840030287-1006\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SUNA_de
IE - HKU\S-1-5-21-3725954371-1878462329-840030287-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.10.14 20:48:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins
[2012.10.14 20:48:12 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Extensions
[2012.10.14 20:47:59 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.09.06 03:27:05 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2012.09.06 03:26:22 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.09.06 03:26:22 | 000,002,253 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012.08.18 14:54:51 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-3725954371-1878462329-840030287-1006\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Corel Photo Downloader] C:\Programme\Corel\Corel Photo Album 6\MediaDetect.exe (Corel, Inc.)
O4 - HKLM..\Run: [CTSysVol] C:\Programme\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DMXLauncher] C:\Programme\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [HerculesCamService] C:\Programme\Hercules\Hercules DualPix HD Webcam\CamService.exe ()
O4 - HKLM..\Run: [IAAnotif] C:\Programme\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [MBMon] C:\WINDOWS\System32\CTMBHA.DLL ()
O4 - HKLM..\Run: [MSKDetectorExe] C:\Programme\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKU\S-1-5-21-3725954371-1878462329-840030287-1006..\Run: [Creative Detector] C:\Programme\Creative\MediaSource\Detector\CTDetect.exe (Creative Technology Ltd)
O4 - HKU\S-1-5-21-3725954371-1878462329-840030287-1006..\Run: [SetDefaultMIDI] C:\WINDOWS\MIDIDEF.EXE (Creative Technology Ltd)
O4 - HKU\S-1-5-21-3725954371-1878462329-840030287-1006..\Run: [swg] "C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" File not found
O4 - HKLM..\RunOnce: [Del412296] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [DeleteOnReboot] C:\WINDOWS\DeleteOnReboot.bat ()
O4 - HKLM..\RunOnce: [Purge] C:\Dokumente und Einstellungen\***\Desktop\adwcleaner.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3725954371-1878462329-840030287-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3725954371-1878462329-840030287-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-3725954371-1878462329-840030287-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-3725954371-1878462329-840030287-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Programme\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} hxxp://us-download.mcafee.com/products/protected/mvt/mvt.cab (McAfee Virtual Technician Control Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A061E586-CE2A-4FBF-9E07-37F5E79679C5}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PEVSystemStart - Service
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: procexp90.Sys - Driver
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PEVSystemStart - Service
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: procexp90.Sys - Driver
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {0213C6AF-5562-4D09-884C-2ADCFC8C2F35} - Microsoft .NET Framework 1.1 Security Update (KB2656353)
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {14F4D1F6-79E4-4256-A10B-3CCD138698C6} - Microsoft .NET Framework 1.0 Hotfix (KB2656378)
ActiveX: {1897C549-AE52-4571-8996-44854F5612B2} - Microsoft .NET Framework 1.1 Security Update (KB2656370)
ActiveX: {1BC46932-21B2-4130-86E0-B4EB4F7A7A7B} - Microsoft .NET Framework 1.0 Hotfix (KB887998)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {29E7D24F-BF30-45E7-8A40-AD27AFD8F5C6} - Microsoft .NET Framework 1.0 Hotfix (KB979904)
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {339E9413-F230-4F0F-ADDD-17914D95FD6D} - Microsoft .NET Framework 1.0 Hotfix (KB2604042)
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {407408d4-94ed-4d86-ab69-a7f649d112ee} - %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection QuickLaunchShortcut 640 %systemroot%\inf\mcdftreg.inf
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4F00D11B-8327-4C55-B7DA-B8D8C10F28A8} - Microsoft .NET Framework 1.0 Hotfix (KB2572066)
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {8BF1B8CD-9A6C-4382-A454-CC769B913F48} - Microsoft .NET Framework 1.0 Hotfix (KB2656378)
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {BDE0FA43-6952-4BA8-8C58-09AF690F88E1} - Microsoft .NET Framework 1.0 Hotfix (KB930494)
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C314CE45-3392-3B73-B4E1-139CD41CA933} - .NET Framework
ActiveX: {C3C986D6-06B1-43BF-90DD-BE30756C00DE} - RevokedRootsUpdate
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E78BFA60-5393-4C38-82AB-E8019E464EB4} - .NET Framework
ActiveX: {E8EA5BD6-D931-4001-ABF6-81BAA500360A} - Microsoft .NET Framework 1.0 Hotfix (KB953295)
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EA29D410-CE41-4953-A862-2DE706A1DAD7} - Microsoft .NET Framework 1.0 Service Pack 3
ActiveX: {FDC11A6F-17D1-48f9-9EA3-9051954BAA24} - .NET Framework
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
ActiveX: KB910393 - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\EasyCDBlock.inf,PerUserInstall
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Unable to start System Restore Service. Error code 10
========== Files/Folders - Created Within 30 Days ==========
[2012.10.22 21:52:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012.10.22 21:46:19 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012.10.22 21:46:19 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012.10.22 21:46:19 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012.10.22 21:46:19 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012.10.22 21:46:14 | 000,000,000 | --SD | C] -- C:\ComboFix
[2012.10.22 21:43:30 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Avira
[2012.10.22 21:43:06 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.10.22 21:43:02 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\***\Startmenü\Programme\Verwaltung
[2012.10.22 21:43:02 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\***\Eigene Dateien\Eigene Videos
[2012.10.22 21:22:46 | 004,987,615 | R--- | C] (Swearware) -- C:\Dokumente und Einstellungen\***\Desktop\ComboFix.exe
[2012.10.19 21:39:44 | 002,213,464 | ---- | C] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\***\Desktop\tdsskiller.exe
[2012.10.16 13:37:24 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\***\Desktop\OTL.exe
[2012.10.15 20:10:00 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Temp
[2012.10.15 20:10:00 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Adobe
[2012.10.14 20:49:06 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Eigene Dateien\Downloads
[2012.10.14 20:48:04 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\Mozilla
[2012.10.14 20:48:04 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla
[2012.10.14 20:48:01 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Maintenance Service
[2012.10.14 20:48:01 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Mozilla
[2012.10.14 20:47:04 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\MozillaFirefoxPackages
[2012.10.14 20:47:01 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Browser Manager
[2012.10.14 20:46:58 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox
[2012.10.13 23:40:12 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Malwarebytes
[2012.10.13 23:40:00 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Eigene Dateien\My PSP Files
[2012.10.12 10:02:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\elsterformular
[2012.10.08 18:40:02 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Adobe
[2012.10.08 18:35:04 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen\***\PrivacIE
========== Files - Modified Within 30 Days ==========
[2012.10.23 22:47:13 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\***\Desktop\OTL.exe
[2012.10.23 22:44:57 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.10.23 22:44:30 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.10.22 21:22:56 | 004,987,615 | R--- | M] (Swearware) -- C:\Dokumente und Einstellungen\***\Desktop\ComboFix.exe
[2012.10.19 21:39:45 | 002,213,464 | ---- | M] (Kaspersky Lab ZAO) -- C:\Dokumente und Einstellungen\***\Desktop\tdsskiller.exe
[2012.10.17 20:58:50 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012.10.17 19:59:35 | 000,000,140 | ---- | M] () -- C:\WINDOWS\DeleteOnReboot.bat
[2012.10.17 17:51:12 | 000,538,941 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Desktop\adwcleaner.exe
[2012.10.14 20:48:01 | 000,000,696 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2012.10.14 20:46:18 | 001,114,760 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Desktop\Firefox_Setup_15.0.1.exe
[2012.10.13 23:40:01 | 000,006,216 | -HS- | M] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2012.10.05 16:52:00 | 000,001,104 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.05 16:52:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.10.05 09:52:00 | 000,001,100 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
========== Files Created - No Company Name ==========
[2012.10.22 21:46:19 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012.10.22 21:46:19 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012.10.22 21:46:19 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012.10.22 21:46:19 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012.10.22 21:46:19 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012.10.17 20:51:12 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012.10.17 19:59:29 | 000,000,140 | ---- | C] () -- C:\WINDOWS\DeleteOnReboot.bat
[2012.10.17 17:51:12 | 000,538,941 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Desktop\adwcleaner.exe
[2012.10.14 20:48:01 | 000,000,702 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Mozilla Firefox.lnk
[2012.10.14 20:48:01 | 000,000,696 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2012.10.14 20:45:43 | 001,114,760 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Desktop\Firefox_Setup_15.0.1.exe
[2012.07.31 23:19:40 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2012.02.17 10:11:30 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2010.12.22 01:19:48 | 000,042,424 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010.04.30 22:47:06 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\$_hpcst$.hpc
[2010.03.31 21:17:47 | 001,456,640 | ---- | C] () -- C:\Programme\Gemeinsame Dateien\Falk Navi-Manager.msi
[2007.05.19 03:16:05 | 000,000,305 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\addr_file.html
[2006.05.26 01:25:20 | 000,000,692 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\FASTWiz.html
[2006.05.26 01:20:49 | 000,000,146 | ---- | C] () -- C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
========== ZeroAccess Check ==========
[2005.08.20 01:54:48 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 04:22:25 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.02.09 12:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008.04.14 04:22:32 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012.09.21 12:18:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012.10.14 20:47:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Browser Manager
[2011.01.19 18:39:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\elsterformular
[2006.05.25 12:29:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MVTLogs
[2007.05.18 11:03:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Teleca
[2010.12.17 01:39:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012.10.12 10:02:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\elsterformular
========== Purity Check ==========
========== Custom Scans ==========
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2012.10.15 20:10:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Adobe
[2011.08.19 00:32:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Apple Computer
[2012.10.22 21:43:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Avira
[2006.05.12 14:26:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Corel
[2012.10.12 10:02:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\elsterformular
[2009.06.01 12:09:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Google
[2005.08.20 02:05:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Identities
[2006.10.25 13:58:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Macromedia
[2012.10.13 23:40:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Malwarebytes
[2006.05.26 01:21:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\McAfee.com Personal Firewall
[2012.10.17 20:03:38 | 000,000,000 | --SD | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Microsoft
[2012.10.14 20:48:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla
[2012.10.14 20:47:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\MozillaFirefoxPackages
[2006.05.12 14:16:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Sun
< %APPDATA%\*.exe /s >
[2012.10.12 23:54:32 | 000,565,760 | ---- | M] () -- C:\Dokumente und Einstellungen\***\Anwendungsdaten\MozillaFirefoxPackages\UninstallPackages\Uninstall.exe
< %SYSTEMDRIVE%\*.exe >
[2001.05.24 12:59:30 | 000,162,304 | ---- | M] () -- C:\UNWISE.EXE
< %systemroot%\Installer\*. /s >
[2006.05.12 14:25:33 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$
[2008.12.20 20:36:53 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\tsclientmsitrans
[2006.05.12 14:26:52 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{075473F5-846A-448B-BCB3-104AA1760205}
[2012.06.15 01:45:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{0E64B098-8018-4256-BA23-C316A43AD9B0}
[2012.09.21 12:19:08 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{0F6F6876-6334-4977-B5DD-CFC12E193420}
[2006.05.12 14:26:08 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
[2006.05.12 14:26:07 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{1A15507A-8551-4626-915D-3D5FA095CC1B}
[2006.05.12 14:25:07 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{1D3C662A-F6C6-4767-A788-7AA43A9A1317}
[2009.11.18 21:52:43 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{205C6BDD-7B73-42DE-8505-9A093F35A238}
[2006.05.12 14:26:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{21657574-BD54-48A2-9450-EB03B2C7FC29}
[2012.08.31 18:06:11 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{26A24AE4-039D-4CA4-87B4-2F83216035FF}
[2011.11.18 10:32:55 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}
[2006.05.12 14:26:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
[2005.08.20 02:06:00 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}
[2006.11.15 00:02:28 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
[2009.11.18 21:53:09 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{41E654A9-26D0-4EAC-854B-0FA824FFFABB}
[2006.05.12 14:21:25 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}
[2006.05.12 14:21:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{4CEA6811-DFAD-4892-828D-49941FE3B779}
[2011.10.10 13:56:42 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}
[2009.11.18 21:52:48 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{52B97218-98CB-4B8B-9283-D213C85E1AA4}
[2006.05.12 14:21:36 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
[2006.05.12 14:21:27 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}
[2009.11.18 21:52:38 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{5FC68772-6D56-41C6-9DF1-24E868198AE6}
[2012.09.21 12:12:02 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{63EC2120-1742-4625-AA47-C6A8AEC9C64C}
[2006.05.12 14:25:05 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{74F7662C-B1DB-489E-A8AC-07A06B24978B}
[2011.09.01 09:26:03 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}
[2011.11.07 00:20:07 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{79155F2B-9895-49D7-8612-D92580E0DE5B}
[2008.11.12 20:48:40 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
[2006.05.12 14:25:42 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{8A9B8148-DDD7-448F-BD6C-358386D32354}
[2006.05.12 14:21:34 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{8C22F265-DE76-44D1-8A79-A71D819137DA}
[2006.05.12 14:21:35 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{903CE8F7-6C7B-41E6-A1CF-3BF1176264EC}
[2011.11.18 18:59:43 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{926BD0E8-24A3-41D2-AF9B-340F1A37ED12}
[2012.08.19 02:10:15 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{95120000-00AF-0407-0000-0000000FF1CE}
[2010.03.31 21:13:47 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}
[2007.12.16 23:07:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{A462952C-29F7-43E4-ACA2-5CAB61401BA4}
[2006.05.12 14:26:44 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
[2009.06.02 17:47:42 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{AC76BA86-7AD7-1031-7B44-A00000000001}
[2012.08.17 13:21:10 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{AC76BA86-7AD7-1031-7B44-AA1000000001}
[2012.05.03 15:27:39 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{AED2DD42-9853-407E-A6BC-8A1D6B715909}
[2006.05.12 14:26:48 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{B12665F4-4E93-4AB4-B7FC-37053B524629}
[2007.08.15 15:14:24 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{C04E32E0-0416-434D-AFB9-6969D703A9EF}
[2012.05.03 15:27:14 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}
[2012.09.21 12:13:05 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}
[2012.08.16 13:53:06 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\{e2377294-2caf-7fd9-746e-5ad80a113f7e}
[2005.08.23 21:47:08 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{E78BFA60-5393-4C38-82AB-E8019E464EB4}
[2006.05.12 14:24:44 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{EDDDC607-91D9-4758-9F57-265FDCD8A772}
[2009.11.25 18:07:19 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
[2011.09.16 19:33:36 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed
[2011.12.17 02:51:24 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\00002159FA0070400000000000F01FEC
[2009.11.27 18:56:27 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C
[2012.06.18 09:18:13 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A
[2009.11.28 18:24:29 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\26DDC2EC4210AC63483DF9D4FCC5B59D
[2009.11.27 18:57:49 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\2D482C2C7DB643B30B5C2BACDE61D87F
[2009.11.27 18:57:40 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\54EC413C293337B34B1E31C94DC19A33
[2011.09.16 19:33:36 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA71301B744AA0100000010
[2006.05.12 14:25:34 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245
[2009.11.27 18:54:51 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3
[2009.11.20 17:01:30 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\00002159FA0070400000000000F01FEC\12.0.4518
[2012.08.19 02:07:10 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\00002159FA0070400000000000F01FEC\12.0.6612
[2009.11.27 18:56:27 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729
[2012.06.18 09:18:22 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219
[2012.05.13 02:21:20 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\26DDC2EC4210AC63483DF9D4FCC5B59D\3.5.30729
[2009.11.27 18:57:49 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\2D482C2C7DB643B30B5C2BACDE61D87F\3.2.30729
[2009.11.27 18:57:40 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\54EC413C293337B34B1E31C94DC19A33\2.2.30729
[2012.08.17 13:20:33 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA71301B744AA0100000010\10.1.0
[2006.05.12 14:25:33 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0
[2009.11.27 18:54:51 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2005.08.20 01:42:36 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2005.08.20 01:42:36 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2005.08.20 01:42:36 | 000,417,792 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Installer\*. /s >
[2006.05.12 14:25:33 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$
[2008.12.20 20:36:53 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\tsclientmsitrans
[2006.05.12 14:26:52 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{075473F5-846A-448B-BCB3-104AA1760205}
[2012.06.15 01:45:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{0E64B098-8018-4256-BA23-C316A43AD9B0}
[2012.09.21 12:19:08 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{0F6F6876-6334-4977-B5DD-CFC12E193420}
[2006.05.12 14:26:08 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
[2006.05.12 14:26:07 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{1A15507A-8551-4626-915D-3D5FA095CC1B}
[2006.05.12 14:25:07 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{1D3C662A-F6C6-4767-A788-7AA43A9A1317}
[2009.11.18 21:52:43 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{205C6BDD-7B73-42DE-8505-9A093F35A238}
[2006.05.12 14:26:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{21657574-BD54-48A2-9450-EB03B2C7FC29}
[2012.08.31 18:06:11 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{26A24AE4-039D-4CA4-87B4-2F83216035FF}
[2011.11.18 10:32:55 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}
[2006.05.12 14:26:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
[2005.08.20 02:06:00 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}
[2006.11.15 00:02:28 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
[2009.11.18 21:53:09 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{41E654A9-26D0-4EAC-854B-0FA824FFFABB}
[2006.05.12 14:21:25 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}
[2006.05.12 14:21:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{4CEA6811-DFAD-4892-828D-49941FE3B779}
[2011.10.10 13:56:42 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}
[2009.11.18 21:52:48 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{52B97218-98CB-4B8B-9283-D213C85E1AA4}
[2006.05.12 14:21:36 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
[2006.05.12 14:21:27 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}
[2009.11.18 21:52:38 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{5FC68772-6D56-41C6-9DF1-24E868198AE6}
[2012.09.21 12:12:02 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{63EC2120-1742-4625-AA47-C6A8AEC9C64C}
[2006.05.12 14:25:05 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{74F7662C-B1DB-489E-A8AC-07A06B24978B}
[2011.09.01 09:26:03 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}
[2011.11.07 00:20:07 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{79155F2B-9895-49D7-8612-D92580E0DE5B}
[2008.11.12 20:48:40 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
[2006.05.12 14:25:42 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{8A9B8148-DDD7-448F-BD6C-358386D32354}
[2006.05.12 14:21:34 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{8C22F265-DE76-44D1-8A79-A71D819137DA}
[2006.05.12 14:21:35 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{903CE8F7-6C7B-41E6-A1CF-3BF1176264EC}
[2011.11.18 18:59:43 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{926BD0E8-24A3-41D2-AF9B-340F1A37ED12}
[2012.08.19 02:10:15 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{95120000-00AF-0407-0000-0000000FF1CE}
[2010.03.31 21:13:47 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}
[2007.12.16 23:07:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{A462952C-29F7-43E4-ACA2-5CAB61401BA4}
[2006.05.12 14:26:44 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
[2009.06.02 17:47:42 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{AC76BA86-7AD7-1031-7B44-A00000000001}
[2012.08.17 13:21:10 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{AC76BA86-7AD7-1031-7B44-AA1000000001}
[2012.05.03 15:27:39 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{AED2DD42-9853-407E-A6BC-8A1D6B715909}
[2006.05.12 14:26:48 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{B12665F4-4E93-4AB4-B7FC-37053B524629}
[2007.08.15 15:14:24 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{C04E32E0-0416-434D-AFB9-6969D703A9EF}
[2012.05.03 15:27:14 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}
[2012.09.21 12:13:05 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}
[2012.08.16 13:53:06 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\{e2377294-2caf-7fd9-746e-5ad80a113f7e}
[2005.08.23 21:47:08 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{E78BFA60-5393-4C38-82AB-E8019E464EB4}
[2006.05.12 14:24:44 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{EDDDC607-91D9-4758-9F57-265FDCD8A772}
[2009.11.25 18:07:19 | 000,000,000 | ---D | M] -- C:\WINDOWS\Installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
[2011.09.16 19:33:36 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed
[2011.12.17 02:51:24 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\00002159FA0070400000000000F01FEC
[2009.11.27 18:56:27 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C
[2012.06.18 09:18:13 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A
[2009.11.28 18:24:29 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\26DDC2EC4210AC63483DF9D4FCC5B59D
[2009.11.27 18:57:49 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\2D482C2C7DB643B30B5C2BACDE61D87F
[2009.11.27 18:57:40 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\54EC413C293337B34B1E31C94DC19A33
[2011.09.16 19:33:36 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA71301B744AA0100000010
[2006.05.12 14:25:34 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245
[2009.11.27 18:54:51 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3
[2009.11.20 17:01:30 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\00002159FA0070400000000000F01FEC\12.0.4518
[2012.08.19 02:07:10 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\00002159FA0070400000000000F01FEC\12.0.6612
[2009.11.27 18:56:27 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729
[2012.06.18 09:18:22 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219
[2012.05.13 02:21:20 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\26DDC2EC4210AC63483DF9D4FCC5B59D\3.5.30729
[2009.11.27 18:57:49 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\2D482C2C7DB643B30B5C2BACDE61D87F\3.2.30729
[2009.11.27 18:57:40 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\54EC413C293337B34B1E31C94DC19A33\2.2.30729
[2012.08.17 13:20:33 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA71301B744AA0100000010\10.1.0
[2006.05.12 14:25:33 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0
[2009.11.27 18:54:51 | 000,000,000 | -HSD | M] -- C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729
< End of report > Vielen Dank für deine Hilfe!! |