Logfile of random's system information tool 1.06 (written by random/random)
Run by Psycho at 2010-01-19 00:27:53
Microsoft Windows XP Professional Service Pack 2
System drive C: has 6 GB (31%) free of 20 GB
Total RAM: 2047 MB (79% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:27:54, on 19.01.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Winamp\winampa.exe
C:\Programme\Razer\razertra.exe
C:\Programme\Razer\Diamondback\razerhid.exe
C:\Programme\Java\jre6\bin\jusched.exe
C:\Programme\Miranda IM\miranda32.exe
C:\Programme\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Programme\Razer\Diamondback\razertra.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Razer\Diamondback\razerofa.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Dokumente und Einstellungen\Psycho\Eigene Dateien\Downloads\RSIT.exe
C:\Programme\trend micro\Psycho.exe
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FlashGet\getflash.dll
O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe
O4 - HKLM\..\Run: [razertra] C:\Programme\Razer\razertra.exe
O4 - HKLM\..\Run: [Diamondback] C:\Programme\Razer\Diamondback\razerhid.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre6\bin\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-21-527237240-606747145-1801674531-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'papa')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Miranda IM.lnk = C:\Programme\Miranda IM\miranda32.exe
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/micr...?1192064717312
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/micr...?1192064703718
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload.adobe.com/pub/shoc...sh/swflash.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Programme\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 4503 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-05-12 308856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Programme\Java\jre6\bin\jp2ssv.dll [2009-12-06 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-06 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
gFlash Class - C:\PROGRA~1\FlashGet\getflash.dll [2006-09-12 126976]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"=C:\Programme\Winamp\winampa.exe [2008-01-15 37376]
"razertra"=C:\Programme\Razer\razertra.exe [2004-10-03 208896]
"Diamondback"=C:\Programme\Razer\Diamondback\razerhid.exe [2007-02-14 147456]
"Adobe Reader Speed Launcher"=C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
"SunJavaUpdateSched"=C:\Programme\Java\jre6\bin\jusched.exe [2009-12-06 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
C:\Programme\D-Tools\daemon.exe -lang 1033 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Programme\QuickTime\QTTask.exe [2008-09-06 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2007-03-21 16126464]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-02-25 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe [2008-05-12 185896]
C:\Dokumente und Einstellungen\Psycho\Startmenü\Programme\Autostart
Miranda IM.lnk - C:\Programme\Miranda IM\miranda32.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-02-25 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2004-08-03 240128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Programme\Steam\Steam.exe"="C:\Programme\Steam\Steam.exe:*:Enabled:Steam"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Eine DLL-Datei als Anwendung ausführen"
"C:\Programme\Miranda IM\miranda32.exe"="C:\Programme\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"E:\quake3\quake3.exe"="E:\quake3\quake3.exe:*:Enabled:quake3"
"D:\Spiele\Quake III Arena\quake3.exe"="D:\Spiele\Quake III Arena\quake3.exe:*:Enabled:quake3"
"D:\Spiele\Steam\SteamApps\hullebaer\half-life 2 deathmatch\hl2.exe"="D:\Spiele\Steam\SteamApps\hullebaer\half-life 2 deathmatch\hl2.exe:*:Enabled:hl2"
"D:\Spiele\Crysis\Bin32\Crysis.exe"="D:\Spiele\Crysis\Bin32\Crysis.exe:*:Enabled:Crysis_32"
"D:\Spiele\Crysis\Bin32\CrysisDedicatedServer.exe"="D:\Spiele\Crysis\Bin32\CrysisDedicatedServer.exe:*:Enabled:CrysisDedicatedServer_32"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"D:\Spiele\Star Wars Battlefront\GameData\battlefront.exe"="D:\Spiele\Star Wars Battlefront\GameData\battlefront.exe:*:Enabled:Star Wars(TM): Battlefront(TM)"
"C:\Programme\Messenger\msmsgs.exe"="C:\Programme\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Programme\Soulseek\slsk.exe"="C:\Programme\Soulseek\slsk.exe:*:Enabled:SoulSeek"
"C:\Programme\Wimpomat2\Wimpomat2.exe"="C:\Programme\Wimpomat2\Wimpomat2.exe:*:Enabled:Wimpomat 2.0"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"D:\Spiele\ANNO1602\1602.exe"="D:\Spiele\ANNO1602\1602.exe:*:Enabled:1602"
"D:\Spiele\Warcraft III\war3.exe"="D:\Spiele\Warcraft III\war3.exe:*:Enabled:Warcraft III"
"C:\Programme\SPSSInc\SPSS16\spss.exe"="C:\Programme\SPSSInc\SPSS16\spss.exe:*:Disabled:SPSS 16.0 for Windows (1033:exe)"
"C:\Programme\SPSSInc\SPSS16\SPSSWinWrapIDE.exe"="C:\Programme\SPSSInc\SPSS16\SPSSWinWrapIDE.exe:*:Disabled:SPSS Basic Script Editor (1033)"
"C:\Programme\SPSSInc\SPSS16\spss.com"="C:\Programme\SPSSInc\SPSS16\spss.com:*:Disabled:SPSS 16.0 for Windows (1033:com)"
"C:\Dokumente und Einstellungen\Psycho\Lokale Einstellungen\Temp\Blizzard Launcher Temporary - 0f021a20\Launcher.exe"="C:\Dokumente und Einstellungen\Psycho\Lokale Einstellungen\Temp\Blizzard Launcher Temporary - 0f021a20\Launcher.exe:*:Enabled:Blizzard Launcher"
"C:\Dokumente und Einstellungen\Psycho\Lokale Einstellungen\Temp\Blizzard Launcher Temporary - 5c4a8e70\Launcher.exe"="C:\Dokumente und Einstellungen\Psycho\Lokale Einstellungen\Temp\Blizzard Launcher Temporary - 5c4a8e70\Launcher.exe:*:Enabled:Blizzard Launcher"
"D:\Spiele\World of Warcraft Public Test 2\Launcher.exe"="D:\Spiele\World of Warcraft Public Test 2\Launcher.exe:*:Enabled:Blizzard Launcher"
"D:\Spiele\World of Warcraft\Launcher.exe"="D:\Spiele\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher"
"C:\Programme\Curse\CurseClient.exe"="C:\Programme\Curse\CurseClient.exe:*:Enabled:Curse Client"
"D:\Spiele\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe"="D:\Spiele\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"D:\Spiele\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe"="D:\Spiele\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"D:\Spiele\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enGB-downloader.exe"="D:\Spiele\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"D:\Spiele\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enGB-downloader.exe"="D:\Spiele\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"D:\Spiele\Warcraft III\Warcraft III.exe"="D:\Spiele\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Programme\Skype\Phone\Skype.exe"="C:\Programme\Skype\Phone\Skype.exe:*:Enabled:Skype"
"D:\Spiele\Black & White\runblack.exe"="D:\Spiele\Black & White\runblack.exe:*:Enabled:lh"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 3 months======
2010-01-18 23:02:55 ----D---- C:\rsit
2010-01-18 22:23:33 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-01-17 23:48:16 ----D---- C:\Programme\CleanUp!
2010-01-13 07:22:13 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-01-13 07:22:08 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-01-11 16:48:22 ----D---- C:\Programme\TrendMicro
2010-01-03 21:00:59 ----D---- C:\Dokumente und Einstellungen\Psycho\Anwendungsdaten\TS3Client
2010-01-03 21:00:51 ----D---- C:\Programme\TeamSpeak 3 Client
2009-12-31 14:54:43 ----A---- C:\WINDOWS\system32\krl32mainweq.dll
2009-12-31 14:53:33 ----A---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\sysReserve.ini
2009-12-10 03:03:02 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2009-12-10 03:02:56 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2009-12-10 03:02:45 ----HDC---- C:\WINDOWS\$NtUninstallKB976325$
2009-12-10 03:02:39 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2009-12-10 03:02:34 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2009-12-10 03:02:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2009-12-09 13:10:45 ----D---- C:\Dokumente und Einstellungen\Psycho\Anwendungsdaten\Mumble
2009-12-09 13:09:44 ----D---- C:\Programme\Mumble
2009-12-06 18:17:40 ----D---- C:\WINDOWS\Sun
2009-12-06 17:57:51 ----A---- C:\WINDOWS\system32\javaws.exe
2009-12-06 17:57:51 ----A---- C:\WINDOWS\system32\javaw.exe
2009-12-06 17:57:51 ----A---- C:\WINDOWS\system32\java.exe
2009-12-06 17:57:51 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-12-06 17:57:39 ----D---- C:\Programme\Java
2009-12-06 17:56:38 ----D---- C:\Dokumente und Einstellungen\Psycho\Anwendungsdaten\Sun
2009-11-26 00:06:32 ----HDC---- C:\WINDOWS\$NtUninstallKB976098-v2$
2009-11-26 00:06:27 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2009-11-12 02:15:36 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2009-11-05 02:00:32 ----HDC---- C:\WINDOWS\$NtUninstallKB976749$
2009-11-01 17:49:33 ----A---- C:\WINDOWS\system32\lsdelete.exe
2009-11-01 16:53:40 ----HDC---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-23 01:18:29 ----HDC---- C:\WINDOWS\$NtUninstallKB974455$
======List of files/folders modified in the last 3 months======
2010-01-19 00:27:53 ----D---- C:\Programme\Trend Micro
2010-01-19 00:26:22 ----D---- C:\° lunatic
2010-01-19 00:19:59 ----D---- C:\WINDOWS
2010-01-18 23:11:14 ----D---- C:\WINDOWS\system32
2010-01-18 23:08:34 ----RD---- C:\Programme
2010-01-18 23:07:53 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy
2010-01-18 23:07:51 ----D---- C:\WINDOWS\Prefetch
2010-01-18 22:58:02 ----D---- C:\WINDOWS\system32\drivers
2010-01-18 22:55:10 ----D---- C:\unzipped
2010-01-18 22:51:06 ----HD---- C:\Programme\InstallShield Installation Information
2010-01-18 22:51:06 ----D---- C:\Programme\T-Online
2010-01-18 22:51:06 ----D---- C:\Programme\Gemeinsame Dateien\Marmiko Shared
2010-01-18 22:39:13 ----D---- C:\WINDOWS\Temp
2010-01-18 22:23:29 ----SHD---- C:\WINDOWS\CSC
2010-01-18 21:27:51 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-18 21:25:39 ----SD---- C:\WINDOWS\Tasks
2010-01-18 21:23:00 ----D---- C:\WINDOWS\Debug
2010-01-18 21:05:15 ----HD---- C:\WINDOWS\inf
2010-01-18 21:05:15 ----D---- C:\WINDOWS\system32\CatRoot
2010-01-18 00:32:14 ----D---- C:\WINDOWS\security
2010-01-17 23:50:26 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-17 23:49:26 ----D---- C:\WINDOWS\system32\usmt
2010-01-17 23:49:00 ----D---- C:\Programme\Vegas Pro 8.0
2010-01-17 23:48:52 ----D---- C:\Programme\FlashGet
2010-01-17 23:48:46 ----D---- C:\Programme\3DMark2001 Pro
2010-01-17 21:19:18 ----D---- C:\Dokumente und Einstellungen\Psycho\Anwendungsdaten\dvdcss
2010-01-17 15:44:23 ----D---- C:\Programme\Internet Explorer
2010-01-17 15:42:23 ----SHD---- C:\WINDOWS\Installer
2010-01-17 15:40:59 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2010-01-17 04:14:28 ----D---- C:\Downloads
2010-01-16 21:16:13 ----A---- C:\WINDOWS\I_VIEW32.INI
2010-01-13 16:32:13 ----D---- C:\WINDOWS\AppPatch
2010-01-13 07:22:12 ----HD---- C:\WINDOWS\$hf_mig$
2010-01-11 22:26:46 ----SHD---- C:\System Volume Information
2010-01-11 22:26:46 ----D---- C:\WINDOWS\system32\Restore
2010-01-11 21:59:42 ----D---- C:\Programme\Mozilla Firefox
2010-01-11 16:48:23 ----SD---- C:\Dokumente und Einstellungen\Psycho\Anwendungsdaten\Microsoft
2010-01-05 01:17:46 ----A---- C:\WINDOWS\system32\MRT.exe
2009-12-27 14:25:53 ----A---- C:\WINDOWS\cdplayer.ini
2009-12-24 10:09:31 ----A---- C:\WINDOWS\KMSTMVM.ini
2009-12-21 10:52:34 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-12-13 16:00:46 ----D---- C:\Dokumente und Einstellungen\Psycho\Anwendungsdaten\OpenOffice.org2
2009-12-12 19:06:26 ----D---- C:\Dokumente und Einstellungen\Psycho\Anwendungsdaten\teamspeak2
2009-12-09 13:09:53 ----D---- C:\WINDOWS\WinSxS
2009-12-03 17:10:37 ----RSD---- C:\WINDOWS\assembly
2009-12-03 17:10:37 ----D---- C:\WINDOWS\system32\DirectX
2009-11-26 13:19:05 ----D---- C:\Programme\Miranda IM
2009-11-24 00:38:08 ----D---- C:\Dokumente und Einstellungen\Psycho\Anwendungsdaten\Skype
2009-11-24 00:03:09 ----D---- C:\Dokumente und Einstellungen\Psycho\Anwendungsdaten\skypePM
2009-11-01 16:55:21 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-11-01 16:53:30 ----D---- C:\Programme\Lavasoft
2009-11-01 16:53:30 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Lavasoft
2009-11-01 16:38:50 ----D---- C:\Programme\Gemeinsame Dateien
2009-10-29 06:44:10 ----A---- C:\WINDOWS\system32\wininet.dll
2009-10-29 06:44:09 ----A---- C:\WINDOWS\system32\urlmon.dll
2009-10-29 06:44:07 ----A---- C:\WINDOWS\system32\shdocvw.dll
2009-10-29 06:44:05 ----A---- C:\WINDOWS\system32\pngfilt.dll
2009-10-29 06:44:05 ----A---- C:\WINDOWS\system32\mstime.dll
2009-10-29 06:44:05 ----A---- C:\WINDOWS\system32\msrating.dll
2009-10-29 06:44:05 ----A---- C:\WINDOWS\system32\mshtmled.dll
2009-10-29 06:44:04 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-10-29 06:44:00 ----A---- C:\WINDOWS\system32\jsproxy.dll
2009-10-29 06:44:00 ----A---- C:\WINDOWS\system32\inseng.dll
2009-10-29 06:44:00 ----A---- C:\WINDOWS\system32\iepeers.dll
2009-10-29 06:44:00 ----A---- C:\WINDOWS\system32\extmgr.dll
2009-10-29 06:44:00 ----A---- C:\WINDOWS\system32\dxtrans.dll
2009-10-29 06:44:00 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2009-10-29 06:43:59 ----A---- C:\WINDOWS\system32\cdfview.dll
2009-10-29 06:43:59 ----A---- C:\WINDOWS\system32\browseui.dll
2009-10-28 16:07:15 ----N---- C:\WINDOWS\system32\tzchange.exe
2009-10-28 01:43:16 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2009-10-21 07:00:37 ----A---- C:\WINDOWS\system32\strmfilt.dll
2009-10-21 07:00:37 ----A---- C:\WINDOWS\system32\httpapi.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Intel-Prozessortreiber; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-03 40192]
R3 Arp1394;1394-ARP-Clientprotokoll; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller; C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 38656]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-02-25 3565568]
R3 ATIAVAIW;ATI T200 Unified AVStream service; C:\WINDOWS\system32\DRIVERS\atinavt2.sys [2009-02-04 170496]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Microsoft HID Class-Treiber; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-03-26 4395008]
R3 mouhid;Maus-HID-Treiber; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-18 12288]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394-Netzwerktreiber; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824]
R3 Razerlow;Razerlow USB Filter Driver; C:\WINDOWS\System32\Drivers\Razerlow.sys [2005-04-24 13225]
R3 usbehci;Miniporttreiber für erweiterten Microsoft USB 2.0-Hostcontroller; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;USB2-aktivierter Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Miniporttreiber für universellen Microsoft USB-Hostcontroller; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 CCDECODE;Untertiteldecoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 MIINPazX;MIINPazX NDIS Protocol Driver; \??\C:\PROGRA~1\GEMEIN~1\MARMIK~1\MInfraIS\MIINPazX.SYS []
S3 MPE;BDA MPE-Filter; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-Konvertierung; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 MTOnlPktAlyX;MTOnlPktAlyX NDIS Protocol Driver; \??\C:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis1\MTOnlPktAlyX.SYS []
S3 NABTSFEC;NABTS/FEC VBI-Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV-/Videoverbindung; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 nm;Netzwerkmonitortreiber; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2004-08-03 40320]
S3 razerusb;razerusb; C:\WINDOWS\system32\DRIVERS\razerusb.sys [2004-10-02 39832]
S3 SCR33x USB Smart Card Reader;SCR33x USB Smart Card Reader; C:\WINDOWS\system32\DRIVERS\SCR33X2K.sys [2005-08-25 45568]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 STC2DFU;STCII DFU Adapter; C:\WINDOWS\system32\DRIVERS\Stc2Dfu.SYS [2004-10-25 7796]
S3 streamip;BDA-IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 tap0801;TAP-Win32 Adapter V8; C:\WINDOWS\system32\DRIVERS\tap0801.sys [2006-10-01 26624]
S3 usbccgp;Microsoft Standard-USB-Haupttreiber; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Microsoft USB-Druckerklasse; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;USB-Massenspeichertreiber; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 vaxscsi;vaxscsi; C:\WINDOWS\System32\Drivers\vaxscsi.sys [2007-11-01 223128]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext-Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-02-25 602112]
R2 JavaQuickStarterService;Java Quick Starter; C:\Programme\Java\jre6\bin\jqs.exe [2009-12-06 153376]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2007-11-17 66872]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-03 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-02-25 593920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Programme\Lavasoft\Ad-Aware\AAWService.exe [2009-12-20 1181328]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------