OTL Logfile: Code:
OTL Extras logfile created on: 17.09.2010 17:38:38 - Run 2
OTL by OldTimer - Version 3.2.12.1 Folder = C:\Dokumente und Einstellungen\j0rd4n\Desktop\MFTools
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 85,00% Memory free
5,00 Gb Paging File | 4,00 Gb Available in Paging File | 94,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Programme
Drive C: | 931,51 Gb Total Space | 261,69 Gb Free Space | 28,09% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JORDAN
Current User Name: j0rd4n
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_USERS\S-1-5-21-515967899-1284227242-1177238915-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\programme\Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Programme\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDSee 11.0.Browse] -- "C:\Programme\ACD Systems\ACDSee\11.0\ACDSeeQV11.exe" "%1" (ACD Systems)
Directory [Bridge] -- C:\Programme\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"427:TCP" = 427:TCP:LocalSubNet:Enabled:SLP_Port(427)_TCP
"427:UDP" = 427:UDP:LocalSubNet:Enabled:SLP_Port(427)_UDP
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"427:TCP" = 427:TCP:LocalSubNet:Enabled:SLP_Port(427)_TCP
"427:UDP" = 427:UDP:LocalSubNet:Enabled:SLP_Port(427)_UDP
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\programme\ICQ7.2\ICQ.exe" = C:\programme\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2 -- (ICQ, LLC.)
"C:\programme\ICQ7.2\aolload.exe" = C:\programme\ICQ7.2\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)
"C:\Dokumente und Einstellungen\j0rd4n\Lokale Einstellungen\Temp\HP\OJP8500vA909_Basic_12\setup\hpznui01.exe" = C:\Dokumente und Einstellungen\j0rd4n\Lokale Einstellungen\Temp\HP\OJP8500vA909_Basic_12\setup\hpznui01.exe:*:Enabled:hpznui01.exe -- File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\programme\MagicTune Premium\MagicTune.exe" = C:\programme\MagicTune Premium\MagicTune.exe:*:Enabled:MagicTune -- (SEC)
"C:\programme\Trillian\trillian.exe" = C:\programme\Trillian\trillian.exe:*:Enabled:Trillian -- (Cerulean Studios)
"C:\programme\uTorrent\uTorrent.exe" = C:\programme\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\programme\Microsoft Office\Office12\OUTLOOK.EXE" = C:\programme\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\programme\ICQ7.2\ICQ.exe" = C:\programme\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2 -- (ICQ, LLC.)
"C:\programme\ICQ7.2\aolload.exe" = C:\programme\ICQ7.2\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{087A66B8-1F0F-4a8d-A649-0CFE276AA7C0}" = WebReg
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A35B15C-9CCD-4C0C-BD5B-34ABF8C95813}_is1" = ICQ 7.2 Build #3129 Banner Remover 1.0
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0EFC334E-0BFE-4387-8E67-A0DAA54D998D}" = AutoRotation Premium
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{102CBC47-7FDE-4E6C-8A3A-67B79833FAC8}" = BPDSoftware_Ini
"{1545207E-C6F3-31D7-9918-BDBB65075FBF}" = Microsoft .NET Framework 3.5 Language Pack - deu
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{1CB92574-96F2-467B-B793-5CEB35C40C29}" = Image Resizer Powertoy for Windows XP
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2BA00471-0328-3743-93BD-FA813353A783}" = Microsoft .NET Framework 3.0 Service Pack 1
"{2FC099BD-AC9B-33EB-809C-D332E1B27C40}" = Microsoft .NET Framework 3.5
"{300578F9-9EFF-4B93-9AB1-C0E5707EF463}" = ACDSee Foto-Manager 2009
"{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{385B9EE4-D4AC-40f7-AE10-94973A58A57E}" = 8500A909_BasicWeb
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{40A24C8A-9C6D-4E8A-A41E-ADF995EFD848}" = 8500A909_Help_BasicWeb
"{431A5BB6-E5E2-444E-8AF3-70E6BF16DEF6}" = UVC Video Camera
"{46E1B1F2-A279-4356-9B17-029F9CC72EAE}" = Brother MFL-Pro Suite
"{47ECCB1F-2811-49C0-B6A7-26778639ABA0}" = 32 Bit HP CIO Components Installer
"{5791B7D3-8B34-4218-9750-6A8E45D0AD32}" = pdfforge Toolbar v1.1.2
"{57F60D52-630B-43C5-BD20-176F5CD4EED6}" = bpd_scan
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{7EE873AF-46BB-4B5D-BA6F-CFE4B0566E22}" = TuneUp Utilities Language Pack (de-DE)
"{87A9A9A9-FAB7-4224-9328-0FA2058C0FD5}" = Network
"{90120000-0010-0407-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (German) 12
"{90120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{90120000-0014-0000-0000-0000000FF1CE}_PRO_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_PRO_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_PRO_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_PRO_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_PRO_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_PRO_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_PRO_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_PRO_{A0516415-ED61-419A-981D-93596DA74165}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PRO_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PRO_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_PRO_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_PRO_{26454C26-D259-4543-AA60-3189E09C5F76}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CCCFD9C-248F-47FE-9496-1680E3E5C163}" = Scan
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A588FF79-CFDD-4FB1-B2D3-FED2DC884B52}" = Watchtower Library 2009 - Deutsch
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AC13BA3A-336B-45a4-B3FE-2D3058A7B533}" = Toolbox
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.4 - Deutsch
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CEA4C985-9C4E-440c-8C3A-9208E18CC4F9}" = HP Officejet Pro 8500 A909 Series
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}" = TuneUp Utilities
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DCA0A35D-30F1-4ED0-971F-5FFD2F60BB08}" = bcTester 4.8 (de)
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}" = jetAudio Basic VX
"{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"CCleaner" = CCleaner
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"ERUNT_is1" = ERUNT 1.1j
"Fraps" = Fraps (remove only)
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.8
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"ImgBurn" = ImgBurn
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.1.0 (Basic)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5" = Microsoft .NET Framework 3.5
"Microsoft .NET Framework 3.5 Language Pack - deu" = Microsoft .NET Framework 3.5 Language Pack - DEU
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"MPE" = MyPhoneExplorer
"NetLimiter 2 Pro" = NetLimiter 2 Pro (remove only)
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"PRO" = Microsoft Office Professional 2007
"StarCraft II" = StarCraft II
"SystemRequirementsLab" = System Requirements Lab
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"TuneUp Utilities" = TuneUp Utilities
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.4
"web'n'walk Manager" = web'n'walk Manager
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"YInstHelper" = Yahoo! Install Manager
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 17.08.2010 17:40:21 | Computer Name = JORDAN | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung ±¥¶º²*¸¥¼ù²¯², Version 1.6.0.2, fehlgeschlagenes
Modul unknown, Version 0.0.0.0, Fehleradresse 0x00173518.
Error - 17.08.2010 17:40:41 | Computer Name = JORDAN | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung ±¥¶º²*¸¥¼ù²¯², Version 1.6.0.2, fehlgeschlagenes
Modul unknown, Version 0.0.0.0, Fehleradresse 0x00173518.
Error - 18.08.2010 05:10:25 | Computer Name = JORDAN | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung framework.exe, Version 1.6.0.2, fehlgeschlagenes
Modul unknown, Version 0.0.0.0, Fehleradresse 0x00172738.
Error - 18.08.2010 07:23:32 | Computer Name = JORDAN | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung ±¥¶º²*¸¥¼ù²¯², Version 1.6.0.2, fehlgeschlagenes
Modul unknown, Version 0.0.0.0, Fehleradresse 0x00173518.
Error - 18.08.2010 07:29:23 | Computer Name = JORDAN | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung ±¥¶º²*¸¥¼ù²¯², Version 1.6.0.2, fehlgeschlagenes
Modul unknown, Version 0.0.0.0, Fehleradresse 0x00173518.
Error - 20.08.2010 18:33:12 | Computer Name = JORDAN | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung nero.exe, Version 7.10.1.0, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 20.08.2010 18:33:13 | Computer Name = JORDAN | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung nero.exe, Version 7.10.1.0, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 20.08.2010 18:39:48 | Computer Name = JORDAN | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung nero.exe, Version 7.10.1.0, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 20.08.2010 18:42:22 | Computer Name = JORDAN | Source = Application Hang | ID = 1002
Description = Stillstehende Anwendung nero.exe, Version 7.10.1.0, Stillstandmodul
hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error - 23.08.2010 11:22:19 | Computer Name = JORDAN | Source = Application Error | ID = 1000
Description = Fehlgeschlagene Anwendung , Version 0.0.0.0, fehlgeschlagenes Modul
unknown, Version 0.0.0.0, Fehleradresse 0x00000000.
[ OSession Events ]
Error - 14.07.2010 13:11:07 | Computer Name = JORDAN | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 42
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 17.09.2010 10:34:47 | Computer Name = JORDAN | Source = Service Control Manager | ID = 7034
Description = Dienst "Gatewaydienst auf Anwendungsebene" wurde unerwartet beendet.
Dies ist bereits 1 Mal passiert.
Error - 17.09.2010 10:34:47 | Computer Name = JORDAN | Source = Service Control Manager | ID = 7034
Description = Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits
1 Mal passiert.
Error - 17.09.2010 10:34:47 | Computer Name = JORDAN | Source = Service Control Manager | ID = 7034
Description = Dienst "StarWind AE Service" wurde unerwartet beendet. Dies ist bereits
1 Mal passiert.
Error - 17.09.2010 10:35:21 | Computer Name = JORDAN | Source = Service Control Manager | ID = 7011
Description = Zeitüberschreitung (30000 ms) beim Warten auf eine Transaktionsrückmeldung
von Dienst nlsvc.
Error - 17.09.2010 10:40:15 | Computer Name = JORDAN | Source = Service Control Manager | ID = 7034
Description = Dienst "NetLimiter" wurde unerwartet beendet. Dies ist bereits 1 Mal
passiert.
Error - 17.09.2010 10:42:07 | Computer Name = JORDAN | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
Error - 17.09.2010 10:59:42 | Computer Name = JORDAN | Source = Service Control Manager | ID = 7034
Description = Dienst "MagicTuneEngine" wurde unerwartet beendet. Dies ist bereits
1 Mal passiert.
Error - 17.09.2010 11:01:00 | Computer Name = JORDAN | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
Error - 17.09.2010 11:08:22 | Computer Name = JORDAN | Source = Service Control Manager | ID = 7034
Description = Dienst "MagicTuneEngine" wurde unerwartet beendet. Dies ist bereits
1 Mal passiert.
Error - 17.09.2010 11:36:16 | Computer Name = JORDAN | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Automatische Updates" wurde mit folgendem Fehler beendet:
%%126
< End of report > --- --- ---
OTL Logfile: Code:
OTL logfile created on: 17.09.2010 17:38:38 - Run 2
OTL by OldTimer - Version 3.2.12.1 Folder = C:\Dokumente und Einstellungen\j0rd4n\Desktop\MFTools
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 85,00% Memory free
5,00 Gb Paging File | 4,00 Gb Available in Paging File | 94,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Programme
Drive C: | 931,51 Gb Total Space | 261,69 Gb Free Space | 28,09% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JORDAN
Current User Name: j0rd4n
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Dokumente und Einstellungen\j0rd4n\Desktop\MFTools\OTL.exe (OldTimer Tools)
PRC - C:\programme\web'n'walk Manager\DataCardMonitor.exe (Huawei Technologies Co., Ltd.)
PRC - C:\programme\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\programme\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\programme\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
PRC - C:\programme\MagicTune Premium\MagicTune.exe (SEC)
PRC - C:\WINXP\explorer.exe (Microsoft Corporation)
PRC - C:\programme\Brother\Brmfcmon\BrMfcMon.exe (Brother Industries, Ltd.)
PRC - C:\programme\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
PRC - C:\programme\MagicTune Premium\MagicTuneEngine.exe ()
PRC - C:\programme\NetLimiter 2 Pro\NLClient.exe (Locktime Software)
PRC - C:\programme\NetLimiter 2 Pro\nlsvc.exe (Locktime Software)
PRC - C:\WINXP\system32\LckFldService.exe ()
========== Modules (SafeList) ==========
MOD - C:\Dokumente und Einstellungen\j0rd4n\Desktop\MFTools\OTL.exe (OldTimer Tools)
MOD - C:\WINXP\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (wuauserv) -- C:\WINDOWS\system32\wuauserv.dll File not found
SRV - (HidServ) -- C:\WINXP\System32\hidserv.dll File not found
SRV - (TuneUp.Defrag) -- C:\programme\TuneUp Utilities 2010\TuneUpDefragService.exe (TuneUp Software)
SRV - (TuneUp.UtilitiesSvc) -- C:\Programme\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) -- C:\WINXP\system32\uxtuneup.dll (TuneUp Software)
SRV - (SwitchBoard) -- C:\programme\Gemeinsame Dateien\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Application Updater) -- C:\Programme\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (StarWindServiceAE) -- C:\programme\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
SRV - (odserv) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (HPSLPSVC) -- C:\programme\hp officejet pro 8500\Digital Imaging\bin\HPSLPSVC32.DLL (Hewlett-Packard Co.)
SRV - (MagicTuneEngine) -- C:\programme\MagicTune Premium\MagicTuneEngine.exe ()
SRV - (nlsvc) -- C:\programme\NetLimiter 2 Pro\nlsvc.exe (Locktime Software)
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (LckFldService) -- C:\WINXP\system32\LckFldService.exe ()
========== Driver Services (SafeList) ==========
DRV - (catchme) -- C:\ComboFix\catchme.sys File not found
DRV - (sptd) -- C:\WINXP\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (nv) -- C:\WINXP\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (TuneUpUtilitiesDrv) -- C:\programme\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (JRAID) -- C:\WINXP\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (Cam3820) -- C:\WINXP\system32\drivers\cam3820a.sys (CamVendor)
DRV - (MagicTune) -- C:\WINXP\system32\drivers\MTiCtwl.sys (Samsung Electronics, Inc. )
DRV - (HDAudBus) -- C:\WINXP\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider)
DRV - (hwdatacard) -- C:\WINXP\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ADIHdAudAddService) -- C:\WINXP\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (nltdi) -- C:\WINXP\system32\drivers\nltdi.sys (Locktime Software)
DRV - (RTLE8023xp) -- C:\WINXP\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (SenFiltService) -- C:\WINXP\system32\drivers\senfilt.sys (Sensaura)
DRV - (magicpvt) -- C:\WINXP\system32\drivers\magicpvt.sys (Samsung Electronics, Inc.)
DRV - (BrScnUsb) -- C:\WINXP\system32\drivers\BrScnUsb.sys (Brother Industries Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-515967899-1284227242-1177238915-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKU\S-1-5-21-515967899-1284227242-1177238915-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-515967899-1284227242-1177238915-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-515967899-1284227242-1177238915-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 38 22 E6 99 63 1D CB 01 [binary data]
IE - HKU\S-1-5-21-515967899-1284227242-1177238915-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\programme\Firefox\components [2010.09.17 12:07:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\programme\Firefox\plugins [2010.09.17 12:07:56 | 000,000,000 | ---D | M]
[2010.09.12 21:17:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Mozilla\Extensions
[2010.09.17 11:46:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Mozilla\Firefox\Profiles\3fl2ynqy.default\extensions
[2010.09.12 21:20:15 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Mozilla\Firefox\Profiles\3fl2ynqy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.09.13 00:55:06 | 000,004,140 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Mozilla\Firefox\Profiles\3fl2ynqy.default\searchplugins\youtube.xml
O1 HOSTS File: ([2010.09.17 16:41:56 | 000,000,027 | ---- | M]) - C:\WINXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DataCardMonitor] C:\programme\web'n'walk Manager\DataCardMonitor.exe (Huawei Technologies Co., Ltd.)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Status Monitor.lnk = C:\programme\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-515967899-1284227242-1177238915-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-515967899-1284227242-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-515967899-1284227242-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-515967899-1284227242-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Programme\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINXP\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\j0rd4n\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\j0rd4n\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.07.07 00:54:47 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINXP\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINXP\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found
NetSvcs: wuauserv - C:\WINDOWS\system32\wuauserv.dll File not found
MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Status Monitor.lnk - C:\programme\Brother\Brmfcmon\BrMfcWnd.exe - (Brother Industries, Ltd.)
MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^j0rd4n^Startmenü^Programme^Autostart^Client Default.lnk - C:\programme\Samurize\Client.exe - (Samurize.com)
MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^j0rd4n^Startmenü^Programme^Autostart^ERUNT AutoBackup.lnk - C:\programme\ERUNT\AUTOBACK.EXE - ()
MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^j0rd4n^Startmenü^Programme^Autostart^HFS.lnk - C:\downloads\apps\hfs_2.2f.155.exe - ()
MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^j0rd4n^Startmenü^Programme^Autostart^Trillian.lnk - C:\programme\Trillian\trillian.exe - (Cerulean Studios)
MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^j0rd4n^Startmenü^Programme^Autostart^uTorrent.lnk - C:\programme\uTorrent\uTorrent.exe - (BitTorrent, Inc.)
MsConfig - StartUpFolder: C:^Dokumente und Einstellungen^j0rd4n^Startmenü^Programme^Autostart^Yahoo! Widgets.lnk - C:\programme\Yahoo Widgets\YahooWidgets.exe - (Yahoo! Inc.)
MsConfig - StartUpReg: 36X Raid Configurer - hkey= - key= - File not found
MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: AdobeAAMUpdater-1.0 - hkey= - key= - C:\programme\Gemeinsame Dateien\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: AdobeCS5ServiceManager - hkey= - key= - C:\programme\Gemeinsame Dateien\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: BluetoothAuthenticationAgent - hkey= - key= - File not found
MsConfig - StartUpReg: ControlCenter3 - hkey= - key= - C:\programme\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
MsConfig - StartUpReg: ctfmon.exe - hkey= - key= - File not found
MsConfig - StartUpReg: Fraps - hkey= - key= - C:\programme\Fraps\fraps.exe (Beepa P/L)
MsConfig - StartUpReg: JMB36X IDE Setup - hkey= - key= - C:\WINXP\RaidTool\xInsIDE.exe ()
MsConfig - StartUpReg: MagicRotation - hkey= - key= - C:\programme\MagicRotation\MagicPvt.exe (Samsung Electronics, Inc.)
MsConfig - StartUpReg: NvCplDaemon - hkey= - key= - File not found
MsConfig - StartUpReg: NvMediaCenter - hkey= - key= - File not found
MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Programme\QuickTime\QTTask.exe (Apple Inc.)
MsConfig - StartUpReg: RunUVC - hkey= - key= - C:\Programme\UVC Video Camera\EffectDir\UVCtray.exe (Alcor Micro Corp.)
MsConfig - StartUpReg: SoundMAXPnP - hkey= - key= - C:\programme\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
MsConfig - StartUpReg: SwitchBoard - hkey= - key= - C:\programme\Gemeinsame Dateien\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: UVCSti - hkey= - key= - C:\Programme\UVC Video Camera\UVCSti.exe (Alcor Micro Corp.)
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 1
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {0291E591-EA41-4c82-8106-3DC6CE7F7664} - Reg Error: Value error.
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - Reg Error: Value error.
ActiveX: {347B0667-C7ED-429B-BDE3-CC8D3BACAA31} - Reg Error: Value error.
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML-Datenbindung für Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINXP\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Sicherheitsupdate für Windows XP (KB923789)
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINXP\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINXP\system32\Rundll32.exe c:\WINXP\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} -
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINXP\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINXP\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINXP\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINXP\system32\rundll32.exe" "C:\WINXP\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
ActiveX: >{99820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: Microsoft Base Smart Card Crypto Provider Package -
Drivers32: msacm.iac2 - C:\WINXP\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINXP\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINXP\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINXP\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINXP\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINXP\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\WINXP\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - C:\WINXP\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINXP\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINXP\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINXP\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)
========== Files/Folders - Created Within 30 Days ==========
[2010.09.17 13:03:29 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\j0rd4n\DoctorWeb
[2010.09.17 12:07:00 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\j0rd4n\Recent
[2010.09.17 12:04:57 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\ATF-Cleaner.exe
[2010.09.17 00:18:06 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\search-Dateien
[2010.09.16 21:19:32 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINXP\SWXCACLS.exe
[2010.09.16 21:19:32 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINXP\SWREG.exe
[2010.09.16 21:19:32 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINXP\SWSC.exe
[2010.09.16 21:19:32 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINXP\NIRCMD.exe
[2010.09.16 21:13:38 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.09.16 12:42:27 | 000,000,000 | ---D | C] -- C:\programme\gmer
[2010.09.16 12:19:39 | 000,000,000 | ---D | C] -- C:\programme\ERUNT
[2010.09.16 12:14:29 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINXP\System32\drivers\mbamswissarmy.sys
[2010.09.16 12:14:28 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINXP\System32\drivers\mbam.sys
[2010.09.16 12:14:28 | 000,000,000 | ---D | C] -- C:\programme\Malwarebytes' Anti-Malware
[2010.09.16 12:12:54 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\MFTools
[2010.09.16 00:27:29 | 000,000,000 | ---D | C] -- C:\programme\CCleaner
[2010.09.15 16:25:32 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Application Updater
[2010.09.15 15:54:04 | 000,000,000 | -H-D | C] -- C:\WINXP\ie8
[2010.09.15 15:14:07 | 000,000,000 | ---D | C] -- C:\WINXP\System32\appmgmt
[2010.09.15 15:07:28 | 000,000,000 | ---D | C] -- C:\programme\HijackThis
[2010.09.15 14:58:02 | 000,000,000 | ---D | C] -- C:\WINXP\pss
[2010.09.15 14:22:31 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.09.15 14:20:52 | 000,000,000 | ---D | C] -- C:\WINXP\ERDNT
[2010.09.15 10:04:27 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Malwarebytes
[2010.09.15 10:04:19 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2010.09.12 21:17:24 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Mozilla
[2010.09.12 21:17:19 | 000,000,000 | ---D | C] -- C:\programme\Firefox
[2010.09.07 17:15:41 | 000,000,000 | ---D | C] -- C:\programme\bcTester 4.8 (de)
[2010.09.03 23:50:06 | 000,101,120 | R--- | C] (Huawei Technologies Co., Ltd.) -- C:\WINXP\System32\drivers\ewusbmdm.sys
[2010.09.03 23:50:06 | 000,024,448 | R--- | C] (Huawei Tech. Co., Ltd.) -- C:\WINXP\System32\drivers\ewdcsc.sys
[2010.09.03 23:49:49 | 000,000,000 | ---D | C] -- C:\programme\web'n'walk Manager
[2010.09.02 15:24:03 | 000,000,000 | ---D | C] -- C:\programme\Free YouTube to MP3 Converter
[2010.08.31 13:28:58 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\vlc
[2010.08.28 00:42:23 | 000,662,288 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\MSCOMCT2.OCX
[2010.08.28 00:42:23 | 000,137,000 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\MSMAPI32.OCX
[2010.08.28 00:42:22 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\MSCMCDE.DLL
[2010.08.28 00:42:22 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\MSCC2DE.DLL
[2010.08.28 00:42:22 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\MSMPIDE.DLL
[2010.08.28 00:42:22 | 000,000,000 | ---D | C] -- C:\programme\PDFCreator
[2010.08.23 17:19:46 | 000,000,000 | ---D | C] -- C:\WINXP\hpojp8500a909
[2010.08.23 17:19:11 | 000,271,704 | R--- | C] (Hewlett-Packard) -- C:\WINXP\System32\hpzids01.dll
[2010.08.23 17:19:11 | 000,118,272 | ---- | C] (Hewlett-Packard Company) -- C:\WINXP\System32\hpf3l082.dll
[2010.08.23 17:18:38 | 000,966,656 | R--- | C] (Hewlett-Packard Co.) -- C:\WINXP\System32\hpwtiop4.dll
[2010.08.23 17:18:38 | 000,741,376 | R--- | C] (Hewlett-Packard) -- C:\WINXP\System32\hpwwiax5.dll
[2010.08.23 17:18:38 | 000,364,544 | R--- | C] (Hewlett-Packard) -- C:\WINXP\System32\hppldcoi.dll
[2010.08.23 17:18:38 | 000,309,760 | R--- | C] (Microsoft Corporation) -- C:\WINXP\System32\difxapi.dll
[2010.08.23 17:18:38 | 000,294,912 | R--- | C] (Hewlett-Packard Co.) -- C:\WINXP\System32\hpovst11.dll
[2010.08.23 17:18:38 | 000,007,040 | ---- | C] (Microsoft Corporation) -- C:\WINXP\System32\dllcache\serscan.sys
[2010.08.23 17:17:54 | 000,000,000 | ---D | C] -- C:\programme\Gemeinsame Dateien\HP
[2010.08.23 17:17:54 | 000,000,000 | ---D | C] -- C:\programme\Gemeinsame Dateien\Hewlett-Packard
[2010.08.23 17:17:53 | 000,000,000 | ---D | C] -- C:\programme\Hewlett-Packard
[2010.08.23 17:17:33 | 000,000,000 | ---D | C] -- C:\programme\hp officejet pro 8500
[2010.08.23 17:17:33 | 000,000,000 | ---D | C] -- C:\programme\HP
[2010.08.21 00:47:04 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\COWON
[2010.08.21 00:45:47 | 000,000,000 | ---D | C] -- C:\programme\Gemeinsame Dateien\COWON
[2010.08.21 00:45:46 | 000,000,000 | ---D | C] -- C:\programme\JetAudio
[2010.08.19 02:02:19 | 000,000,000 | ---D | C] -- C:\upp
[2010.05.28 17:43:29 | 000,810,952 | ---- | C] (Charles DeWeese) -- C:\programme\FlashSfv.exe
[2010.03.23 21:03:34 | 000,319,792 | ---- | C] (BitTorrent, Inc.) -- C:\programme\uTorrent.exe
[2 C:\WINXP\System32\*.tmp files -> C:\WINXP\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.09.17 17:36:06 | 000,000,006 | -H-- | M] () -- C:\WINXP\tasks\SA.DAT
[2010.09.17 17:36:03 | 000,002,048 | --S- | M] () -- C:\WINXP\bootstat.dat
[2010.09.17 17:36:02 | 000,000,016 | ---- | M] () -- C:\WINXP\System32\magicpvt.dat
[2010.09.17 17:35:52 | 000,000,032 | ---- | M] () -- C:\WINXP\System32\driver.dat
[2010.09.17 17:08:33 | 005,242,880 | -H-- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\NTUSER.DAT
[2010.09.17 17:08:21 | 000,000,820 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Status Monitor.lnk
[2010.09.17 16:42:02 | 000,000,260 | ---- | M] () -- C:\WINXP\system.ini
[2010.09.17 16:41:56 | 000,000,027 | ---- | M] () -- C:\WINXP\System32\drivers\etc\hosts
[2010.09.17 16:33:16 | 003,846,517 | R--- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\ComboFix.exe
[2010.09.17 12:15:04 | 049,598,848 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\drweb-cureit.exe
[2010.09.17 12:07:30 | 000,021,098 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Eigene Dateien\cc_20100917_120716.reg
[2010.09.17 12:04:57 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\ATF-Cleaner.exe
[2010.09.17 10:50:39 | 000,002,603 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\Microsoft Office Outlook 2007.lnk
[2010.09.17 00:18:06 | 000,046,863 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\search.htm
[2010.09.16 23:17:28 | 000,024,064 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.09.16 12:39:08 | 000,000,020 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\defogger_reenable
[2010.09.16 12:32:26 | 000,000,910 | ---- | M] () -- C:\WINXP\win.ini
[2010.09.16 12:32:26 | 000,000,324 | RHS- | M] () -- C:\boot.ini
[2010.09.16 12:19:39 | 000,000,591 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\NTREGOPT.lnk
[2010.09.16 12:19:39 | 000,000,572 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\ERUNT.lnk
[2010.09.16 12:14:31 | 000,000,676 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.09.16 12:13:23 | 000,050,477 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\defogger.exe
[2010.09.16 12:12:58 | 000,284,915 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\Gmer.zip
[2010.09.16 12:12:39 | 000,388,607 | ---- | M] () -- C:\Load.exe
[2010.09.16 00:27:30 | 000,000,654 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\CCleaner.lnk
[2010.09.16 00:15:04 | 000,001,456 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Lokale Einstellungen\Anwendungsdaten\Adobe Für Web speichern 12.0 Prefs
[2010.09.15 16:17:03 | 003,566,496 | ---- | M] () -- C:\WINXP\System32\FNTCACHE.DAT
[2010.09.15 16:04:57 | 001,005,754 | ---- | M] () -- C:\WINXP\System32\PerfStringBackup.INI
[2010.09.15 16:04:57 | 000,452,314 | ---- | M] () -- C:\WINXP\System32\perfh007.dat
[2010.09.15 16:04:57 | 000,435,396 | ---- | M] () -- C:\WINXP\System32\perfh009.dat
[2010.09.15 16:04:57 | 000,081,122 | ---- | M] () -- C:\WINXP\System32\perfc007.dat
[2010.09.15 16:04:57 | 000,068,292 | ---- | M] () -- C:\WINXP\System32\perfc009.dat
[2010.09.15 15:07:28 | 000,001,544 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\HijackThis.lnk
[2010.09.15 14:52:16 | 000,000,041 | ---- | M] () -- C:\WINXP\System32\mslck.dat
[2010.09.13 16:20:38 | 004,422,910 | ---- | M] () -- C:\Bewerbung.pdf
[2010.09.12 21:17:21 | 000,001,492 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2010.09.12 12:15:31 | 000,002,206 | ---- | M] () -- C:\WINXP\System32\wpa.dbl
[2010.09.10 17:14:20 | 003,416,192 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\Mario Elevator music.mp3
[2010.09.09 14:25:23 | 000,002,499 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\Microsoft Office Word 2007.lnk
[2010.09.09 13:30:51 | 000,000,432 | ---- | M] () -- C:\WINXP\BRWMARK.INI
[2010.09.07 18:22:35 | 000,000,101 | ---- | M] () -- C:\WINXP\bctester_de.INI
[2010.09.04 13:46:55 | 021,693,481 | ---- | M] () -- C:\Stiftung Warentest 09-2010.pdf
[2010.09.03 23:50:12 | 000,000,774 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\web'n'walk Manager.lnk
[2010.09.02 15:41:31 | 000,000,792 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\FreeYouTubeToMP3Converter.exe.lnk
[2010.08.28 13:58:12 | 000,012,057 | ---- | M] () -- C:\brief dienst.docx
[2010.08.28 00:42:25 | 000,000,678 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\PDFCreator.lnk
[2010.08.23 17:20:12 | 000,154,100 | ---- | M] () -- C:\WINXP\hpwins22.dat
[2010.08.21 00:45:53 | 000,001,468 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\jetAudio.lnk
[2 C:\WINXP\System32\*.tmp files -> C:\WINXP\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.09.17 12:13:59 | 049,598,848 | ---- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\drweb-cureit.exe
[2010.09.17 12:07:21 | 000,021,098 | ---- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\Eigene Dateien\cc_20100917_120716.reg
[2010.09.17 00:18:04 | 000,046,863 | ---- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\search.htm
[2010.09.16 21:19:32 | 000,256,512 | ---- | C] () -- C:\WINXP\PEV.exe
[2010.09.16 21:19:32 | 000,098,816 | ---- | C] () -- C:\WINXP\sed.exe
[2010.09.16 21:19:32 | 000,080,412 | ---- | C] () -- C:\WINXP\grep.exe
[2010.09.16 21:19:32 | 000,077,312 | ---- | C] () -- C:\WINXP\MBR.exe
[2010.09.16 21:19:32 | 000,068,096 | ---- | C] () -- C:\WINXP\zip.exe
[2010.09.16 18:37:35 | 003,846,517 | R--- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\ComboFix.exe
[2010.09.16 12:39:17 | 000,000,820 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Status Monitor.lnk
[2010.09.16 12:38:59 | 000,000,020 | ---- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\defogger_reenable
[2010.09.16 12:19:39 | 000,000,591 | ---- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\NTREGOPT.lnk
[2010.09.16 12:19:39 | 000,000,572 | ---- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\ERUNT.lnk
[2010.09.16 12:14:31 | 000,000,676 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.09.16 12:13:23 | 000,050,477 | ---- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\defogger.exe
[2010.09.16 12:12:57 | 000,284,915 | ---- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\Gmer.zip
[2010.09.16 12:12:36 | 000,388,607 | ---- | C] () -- C:\Load.exe
[2010.09.16 00:27:30 | 000,000,654 | ---- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\CCleaner.lnk
[2010.09.15 15:07:28 | 000,001,544 | ---- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\HijackThis.lnk
[2010.09.15 14:22:36 | 000,000,208 | ---- | C] () -- C:\Boot.bak
[2010.09.15 14:22:34 | 000,262,448 | RHS- | C] () -- C:\cmldr
[2010.09.12 21:17:21 | 000,001,492 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2010.09.10 15:59:27 | 003,416,192 | ---- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\Mario Elevator music.mp3
[2010.09.07 17:17:48 | 000,000,101 | ---- | C] () -- C:\WINXP\bctester_de.INI
[2010.09.04 13:46:17 | 021,693,481 | ---- | C] () -- C:\Stiftung Warentest 09-2010.pdf
[2010.09.03 23:50:12 | 000,000,774 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\web'n'walk Manager.lnk
[2010.09.03 19:13:12 | 005,375,836 | ---- | C] () -- C:\Kyra - Wirklich Alles (Prod. by TeeAge-Beatz).mp3
[2010.09.02 15:41:31 | 000,000,792 | ---- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\Desktop\FreeYouTubeToMP3Converter.exe.lnk
[2010.08.28 00:42:25 | 000,000,678 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\PDFCreator.lnk
[2010.08.28 00:42:23 | 000,116,224 | ---- | C] () -- C:\WINXP\System32\pdfcmnnt.dll
[2010.08.23 23:58:12 | 310,473,230 | ---- | C] () -- C:\Starcraft2-Wings_of_Liberty-Strategy_Guide.pdf
[2010.08.23 17:16:18 | 000,000,409 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\hpzinstall.log
[2010.08.23 17:16:17 | 000,154,100 | ---- | C] () -- C:\WINXP\hpwins22.dat
[2010.08.23 17:16:17 | 000,001,075 | ---- | C] () -- C:\WINXP\hpwmdl22.dat
[2010.08.21 00:45:53 | 000,001,468 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\jetAudio.lnk
[2010.08.04 16:22:38 | 000,187,816 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2010.07.07 17:39:22 | 000,001,456 | ---- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\Lokale Einstellungen\Anwendungsdaten\Adobe Für Web speichern 12.0 Prefs
[2010.07.07 14:12:42 | 000,165,376 | ---- | C] () -- C:\WINXP\System32\unrar.dll
[2010.07.07 12:47:32 | 000,000,432 | ---- | C] () -- C:\WINXP\BRWMARK.INI
[2010.07.07 12:47:12 | 000,000,114 | ---- | C] () -- C:\WINXP\System32\BRLMW03A.INI
[2010.07.07 02:52:44 | 000,024,064 | ---- | C] () -- C:\Dokumente und Einstellungen\j0rd4n\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.07.07 01:05:45 | 000,001,769 | ---- | C] () -- C:\WINXP\Language_trs.ini
[2009.07.09 19:13:24 | 000,000,059 | ---- | C] () -- C:\WINXP\System32\cam3820.ini
========== LOP Check ==========
[2010.07.07 02:33:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ACD Systems
[2010.07.07 02:25:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Locktime
[2010.07.07 17:35:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\regid.1986-12.com.adobe
[2010.07.07 03:46:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software
[2010.07.07 03:46:07 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2010.07.07 02:34:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\ACD Systems
[2010.09.15 16:25:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Application Updater
[2010.08.21 00:47:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\COWON
[2010.09.02 15:24:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\DVDVideoSoftIEHelpers
[2010.08.30 20:35:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\ICQ
[2010.07.07 13:09:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\ImgBurn
[2010.07.07 02:27:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Locktime
[2010.08.16 18:03:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\MyPhoneExplorer
[2010.07.08 22:54:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\pdfforge
[2010.07.08 22:54:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Search Settings
[2010.07.27 15:05:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\TS3Client
[2010.07.07 03:47:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\TuneUp Software
[2010.09.17 13:03:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\uTorrent
[2010.07.18 21:44:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Watchtower
[2010.07.07 03:17:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Windows Search
========== Purity Check ==========
========== Custom Scans ==========
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.07.07 02:34:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\ACD Systems
[2010.07.11 00:09:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Adobe
[2010.08.10 21:17:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Ahead
[2010.09.15 16:25:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Application Updater
[2010.07.08 18:26:18 | 000,000,000 | R--D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Brother
[2010.08.21 00:47:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\COWON
[2010.09.09 16:18:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\dvdcss
[2010.09.02 15:24:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\DVDVideoSoftIEHelpers
[2010.08.30 20:35:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\ICQ
[2010.07.07 01:03:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Identities
[2010.07.07 13:09:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\ImgBurn
[2010.07.07 02:03:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\InstallShield
[2010.07.07 02:27:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Locktime
[2010.07.07 01:33:43 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Macromedia
[2010.09.15 10:04:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Malwarebytes
[2010.09.14 12:21:42 | 000,000,000 | --SD | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Microsoft
[2010.09.12 21:17:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Mozilla
[2010.08.16 18:03:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\MyPhoneExplorer
[2010.07.08 22:54:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\pdfforge
[2010.07.08 22:54:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Search Settings
[2010.08.10 13:44:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Skype
[2010.07.07 02:41:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Sun
[2010.07.27 15:05:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\TS3Client
[2010.07.07 03:47:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\TuneUp Software
[2010.08.17 23:38:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\U3
[2010.09.17 13:03:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\uTorrent
[2010.09.02 01:18:28 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\vlc
[2010.07.18 21:44:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Watchtower
[2010.07.07 03:17:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Windows Search
[2010.07.07 01:56:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\WinRAR
< %APPDATA%\*.exe /s >
[2010.07.07 14:38:12 | 000,010,134 | R--- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Microsoft\Installer\{431A5BB6-E5E2-444E-8AF3-70E6BF16DEF6}\ARPPRODUCTICON.exe
[2010.07.07 14:38:13 | 000,040,960 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Microsoft\Installer\{431A5BB6-E5E2-444E-8AF3-70E6BF16DEF6}\IS_VIDEOCAP_SHORTC_431A5BB6E5E2444E8AF370E6BF16DEF6.exe
[2010.07.07 14:38:12 | 000,040,960 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Microsoft\Installer\{431A5BB6-E5E2-444E-8AF3-70E6BF16DEF6}\IS_VIDEOCAP_SHORTC_431A5BB6E5E2444E8AF370E6BF16DEF6_1.exe
[2010.07.07 14:38:13 | 000,040,960 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Microsoft\Installer\{431A5BB6-E5E2-444E-8AF3-70E6BF16DEF6}\RunUVC.exe1_431A5BB6E5E2444E8AF370E6BF16DEF6.exe
[2010.07.07 14:38:13 | 000,040,960 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Microsoft\Installer\{431A5BB6-E5E2-444E-8AF3-70E6BF16DEF6}\RunUVC.exe21_431A5BB6E5E2444E8AF370E6BF16DEF6.exe
[2010.07.07 14:38:13 | 000,040,960 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Microsoft\Installer\{431A5BB6-E5E2-444E-8AF3-70E6BF16DEF6}\RunUVC.exe2_431A5BB6E5E2444E8AF370E6BF16DEF6.exe
[2010.07.07 14:38:13 | 000,040,960 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Microsoft\Installer\{431A5BB6-E5E2-444E-8AF3-70E6BF16DEF6}\RunUVC.exe_431A5BB6E5E2444E8AF370E6BF16DEF6.exe
[2010.07.07 14:38:12 | 000,008,854 | R--- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\Microsoft\Installer\{431A5BB6-E5E2-444E-8AF3-70E6BF16DEF6}\UNINST_Uninstall_C_431A5BB6E5E2444E8AF370E6BF16DEF6.exe
[2006.12.14 10:00:02 | 000,110,592 | ---- | M] () -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\U3\temp\cleanup.exe
[2007.02.12 17:46:54 | 003,096,576 | -H-- | M] (SanDisk Corporation) -- C:\Dokumente und Einstellungen\j0rd4n\Anwendungsdaten\U3\temp\Launchpad Removal.exe
< %SYSTEMDRIVE%\*.exe >
[2010.09.16 12:12:39 | 000,388,607 | ---- | M] () -- C:\Load.exe
< MD5 for: AGP440.SYS >
[2010.02.09 19:12:44 | 017,817,310 | ---- | M] () .cab file -- C:\WINXP\Driver Cache\i386\sp3.cab:AGP440.sys
< MD5 for: ATAPI.SYS >
[2010.02.09 19:12:44 | 017,817,310 | ---- | M] () .cab file -- C:\WINXP\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINXP\ERDNT\cache\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINXP\system32\dllcache\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINXP\system32\drivers\atapi.sys
[2008.04.14 11:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINXP\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINXP\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008.04.14 11:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINXP\ERDNT\cache\eventlog.dll
[2008.04.14 11:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINXP\system32\dllcache\eventlog.dll
[2008.04.14 11:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINXP\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 11:00:00 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=698B949EC4BACAC8ADE0C3C202230270 -- C:\WINXP\explorer.exe
< MD5 for: NETLOGON.DLL >
[2008.04.14 11:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINXP\ERDNT\cache\netlogon.dll
[2008.04.14 11:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINXP\system32\dllcache\netlogon.dll
[2008.04.14 11:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINXP\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2008.04.14 11:00:00 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINXP\ERDNT\cache\scecli.dll
[2008.04.14 11:00:00 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINXP\system32\dllcache\scecli.dll
[2008.04.14 11:00:00 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINXP\system32\scecli.dll
< MD5 for: USER32.DLL >
[2008.04.14 11:00:00 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINXP\ERDNT\cache\user32.dll
[2008.04.14 11:00:00 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINXP\system32\dllcache\user32.dll
[2008.04.14 11:00:00 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINXP\system32\user32.dll
< MD5 for: USERINIT.EXE >
[2008.04.14 11:00:00 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINXP\ERDNT\cache\userinit.exe
[2008.04.14 11:00:00 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINXP\system32\dllcache\userinit.exe
[2008.04.14 11:00:00 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINXP\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2008.04.14 11:00:00 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=3DBEA7173E3FD34900D800533E5E5964 -- C:\WINXP\system32\winlogon.exe
< MD5 for: WS2IFSL.SYS >
[2008.04.14 11:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINXP\system32\dllcache\ws2ifsl.sys
[2008.04.14 11:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINXP\system32\drivers\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2010.07.07 02:39:34 | 000,094,208 | ---- | M] () -- C:\WINXP\system32\config\default.sav
[2010.07.07 02:39:34 | 001,093,632 | ---- | M] () -- C:\WINXP\system32\config\software.sav
[2010.07.07 02:39:34 | 000,458,752 | ---- | M] () -- C:\WINXP\system32\config\system.sav
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009.08.03 19:28:46 | 000,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINXP\system32\dxtmsft.dll
[2009.08.03 19:28:46 | 000,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINXP\system32\dxtrans.dll
[2 C:\WINXP\system32\*.tmp files -> C:\WINXP\system32\*.tmp -> ]
< End of report > --- --- --- |