okay, hab alles erledigt! die daten sind wieder sichtbar, der trick mit unsichtbare daten anzeigen hat funktioniert!
ich habe zwei antimalware logs und zwei OTL logfiles. aus meiner sicht schauts schon wieder ganz gut aus! aber die diagnose lasse ich lieber den experten. aja ich befinde mich die ganze zeitim abgesicherten modus, nur zur info. Zitat:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Datenbank Version: 6130
Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385
22.03.2011 11:31:07
mbam-log-2011-03-22 (11-31-07).txt
Art des Suchlaufs: Quick-Scan
Durchsuchte Objekte: 162266
Laufzeit: 7 Minute(n), 31 Sekunde(n)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 1
Infizierte Registrierungsschlüssel: 4
Infizierte Registrierungswerte: 2
Infizierte Dateiobjekte der Registrierung: 3
Infizierte Verzeichnisse: 1
Infizierte Dateien: 10
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
c:\Windows\System32\ikzefrfi.dll (Trojan.Boaxxe) -> Delete on reboot.
Infizierte Registrierungsschlüssel:
HKEY_CLASSES_ROOT\CLSID\{641A3761-0C8C-410E-4BE9-FDB9A3C200E7} (Trojan.Boaxxe) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Bjvzwoti (Trojan.Boaxxe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{641A3761-0C8C-410E-4BE9-FDB9A3C200E7} (Trojan.Boaxxe) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\engel (Backdoor.Bot) -> Value: engel -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\cleansweep.exe (Trojan.Agent) -> Value: cleansweep.exe -> Quarantined and deleted successfully.
Infizierte Dateiobjekte der Registrierung:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallPaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Infizierte Verzeichnisse:
c:\cleansweep.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Infizierte Dateien:
c:\Windows\System32\ikzefrfi.dll (Trojan.Boaxxe) -> Quarantined and deleted successfully.
c:\programdata\34725640.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
c:\Users\erdferkel\AppData\Local\Temp\aroyba.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\Users\erdferkel\AppData\Local\Temp\iuvrsmb.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\erdferkel\local settings\temporary internet files\Content.IE5\61RR2V94\qanarmz[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\erdferkel\local settings\temporary internet files\Content.IE5\8E1NE1PF\dreiizm[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\erdferkel\local settings\temporary internet files\Content.IE5\FI73YBE1\xklypptgx[1].htm (Trojan.Proxy) -> Quarantined and deleted successfully.
c:\Users\erdferkel\local settings\temporary internet files\Content.IE5\N820UMQQ\ererijznnr[1].htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\erdferkel\local settings\temporary internet files\Content.IE5\N820UMQQ\oxybcg[1].htm (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\cleansweep.exe\config.bin (Trojan.Agent) -> Quarantined and deleted successfully.
| Zitat:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Datenbank Version: 6130
Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385
22.03.2011 12:58:46
mbam-log-2011-03-22 (12-58-46).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Durchsuchte Objekte: 400766
Laufzeit: 43 Minute(n), 19 Sekunde(n)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
Infizierte Dateien:
(Keine bösartigen Objekte gefunden)
| so nun die OTL.txt
OTL Logfile: Code:
OTL logfile created on: 22.03.2011 13:08:32 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\landsau\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 63,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97,56 Gb Total Space | 10,23 Gb Free Space | 10,48% Space Free | Partition Type: NTFS
Drive H: | 498,51 Gb Total Space | 405,90 Gb Free Space | 81,42% Space Free | Partition Type: NTFS
Drive K: | 1397,27 Gb Total Space | 0,04 Gb Free Space | 0,00% Space Free | Partition Type: NTFS
Drive L: | 7317,40 Gb Total Space | 3268,70 Gb Free Space | 44,67% Space Free | Partition Type: NTFS
Drive M: | 1397,27 Gb Total Space | 574,94 Gb Free Space | 41,15% Space Free | Partition Type: NTFS
Drive N: | 465,76 Gb Total Space | 41,82 Gb Free Space | 8,98% Space Free | Partition Type: NTFS
Computer Name: | User Name: landsau | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\landsau\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - H:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\landsau\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (xxajaedb) USB Audio (WDM) -- File not found
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (NIHardwareService) -- C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe (Native Instruments GmbH)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys ()
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (Lbd) -- C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (atksgt) -- C:\Windows\System32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\Windows\System32\drivers\lirsgt.sys ()
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (ivusb) -- C:\Windows\System32\drivers\ivusb.sys (Initio Corporation)
DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (UDXTTM6010) -- C:\Windows\System32\drivers\UDXTTM6010.sys ()
DRV - (TTHID) -- C:\Windows\System32\drivers\Cinergy_Hybrid-Stick_HID.sys (DTV-DVB)
DRV - (a4djavs) -- C:\Windows\System32\drivers\a4djavs.sys (Native Instruments GmbH)
DRV - (a4djusb) -- C:\Windows\System32\drivers\a4djusb.sys (Native Instruments GmbH)
DRV - (volsnap) -- C:\Windows\system32\DRIVERS\volsnap.sys ()
DRV - (vmbus) -- C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WINUSB) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation)
DRV - (netr28u) -- C:\Windows\System32\drivers\netr28u.sys (Ralink Technology Corp.)
DRV - (ipgd) -- C:\Windows\System32\drivers\ipgdnd60.sys (IC Plus Corp.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A0 B1 A9 E7 49 C0 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: piclens@cooliris.com:1.12.0.36605
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2010.12.15 13:12:54 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2010.12.15 13:12:55 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.13 15:40:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.03.13 15:40:50 | 000,000,000 | ---D | M]
[2010.04.26 19:59:51 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\landsau\AppData\Roaming\mozilla\Extensions
[2011.03.22 11:55:33 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\landsau\AppData\Roaming\mozilla\Firefox\Profiles\ib9ih0dw.default\extensions
[2010.06.15 15:42:43 | 000,000,000 | -H-D | M] (Cooliris) -- C:\Users\landsau\AppData\Roaming\mozilla\Firefox\Profiles\ib9ih0dw.default\extensions\piclens@cooliris.com
[2010.11.20 15:55:23 | 000,000,000 | -H-D | M] (vShare) -- C:\Users\landsau\AppData\Roaming\mozilla\Firefox\Profiles\ib9ih0dw.default\extensions\vshare@toolbar
[2011.03.22 11:08:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2010.10.16 20:38:54 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010.12.15 13:16:33 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010.12.15 13:12:54 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\HTML5VIDEO
[2010.12.15 13:12:55 | 000,000,000 | ---D | M] (DivX HiQ) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\WPA
[2010.12.15 13:16:25 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.03.03 19:06:04 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.03.03 19:06:04 | 000,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.03.03 19:06:04 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.03.03 19:06:04 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.03.03 19:06:04 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O3 - HKLM\..\Toolbar: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\PROGRA~1\TerraTec\TERRAT~1\THCDES~1.DLL (TerraTec Electronic GmbH)
O3 - HKCU\..\Toolbar\WebBrowser: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] h:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [WinampAgent] H:\Programme\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Remote Control Editor] C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe (Elgato Systems)
O4 - HKLM..\RunOnce: [GrpConv] C:\Windows\System32\grpconv.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] h:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\landsau\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (CRLDownloadWrapper Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.200.1
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009.09.17 12:12:56 | 000,000,000 | RH-D | M] - K:\autorun -- [ NTFS ]
O32 - AutoRun File - [2002.10.17 03:56:50 | 000,000,036 | RH-- | M] () - K:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009.09.17 12:12:56 | 000,000,000 | R--D | M] - M:\autorun -- [ NTFS ]
O32 - AutoRun File - [2002.10.17 03:56:50 | 000,000,036 | RH-- | M] () - M:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2007.07.02 07:34:56 | 000,000,045 | ---- | M] () - N:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{6c1865ff-ac22-11df-8093-40618601ac44}\Shell - "" = AutoRun
O33 - MountPoints2\{6c1865ff-ac22-11df-8093-40618601ac44}\Shell\AutoRun\command - "" = "L:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.03.22 12:15:56 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\landsau\Desktop\OTL.exe
[2011.03.22 11:50:34 | 000,000,000 | ---D | C] -- C:\avrescue
[2011.03.22 11:07:15 | 000,000,000 | ---D | C] -- C:\Users\landsau\AppData\Roaming\Malwarebytes
[2011.03.22 11:06:53 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.03.22 11:06:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.03.22 11:06:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.03.22 11:06:45 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.03.22 10:48:51 | 000,000,000 | ---D | C] -- C:\Users\landsau\AppData\Roaming\Avira
[2011.03.22 10:47:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011.03.22 10:47:12 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011.03.22 10:47:12 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2011.03.22 10:47:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011.03.22 10:47:11 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011.03.22 10:39:58 | 000,000,000 | ---D | C] -- C:\ProgramData\{870E601A-FE70-4098-94B2-6E9963FCAA51}
[2011.03.21 22:09:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Diagnostic
[2011.03.21 22:09:13 | 000,000,000 | -H-D | C] -- C:\Users\landsau\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Diagnostic
[2011.03.21 21:59:50 | 000,000,000 | -H-D | C] -- C:\Users\landsau\AppData\Roaming\updates
[2011.03.21 13:55:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FM Genie Scout 11
[2011.03.16 21:23:18 | 000,000,000 | ---D | C] -- C:\Users\landsau\Documents\Native Instruments
[2011.03.16 21:19:44 | 000,000,000 | ---D | C] -- C:\ProgramData\{47803536-1938-4D3F-86D6-F4876B645542}
[2011.03.16 21:19:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Native Instruments
[2011.03.16 21:19:10 | 000,000,000 | ---D | C] -- C:\ProgramData\{20EFD19B-675C-417B-A498-B0161D72FF88}
[2011.03.16 21:19:08 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Native Instruments
[2011.03.16 21:18:30 | 000,000,000 | ---D | C] -- C:\ProgramData\{B5F0C192-874D-49A8-88D7-8431E3714756}
[2011.03.11 17:19:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wave Editor
[2011.03.11 17:13:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
[2011.03.11 17:13:37 | 000,000,000 | ---D | C] -- C:\Program Files\Vstplugins
[2011.03.11 17:00:23 | 000,000,000 | -H-D | C] -- C:\Users\landsau\AppData\Roaming\Sony
[2011.03.11 17:00:23 | 000,000,000 | -H-D | C] -- C:\Users\landsau\AppData\Local\Sony
[2011.03.11 16:58:56 | 000,000,000 | ---D | C] -- C:\Program Files\Sony
[2011.03.11 16:50:14 | 000,000,000 | ---D | C] -- C:\Users\landsau\Documents\DVDVideoSoft
[2011.03.11 16:50:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
[2011.03.11 16:50:00 | 000,000,000 | -H-D | C] -- C:\Users\landsau\AppData\Roaming\DVDVideoSoft
[2011.03.11 16:49:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DVDVideoSoft
[2011.03.09 10:57:14 | 001,074,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2011.03.09 10:57:14 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2011.03.09 10:57:11 | 000,850,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
[2011.03.09 10:57:11 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2011.03.09 10:57:11 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2011.03.09 10:57:11 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2011.03.08 20:21:43 | 000,000,000 | -H-D | C] -- C:\Users\landsau\AppData\Local\Apps
[2011.02.28 19:16:37 | 000,000,000 | ---D | C] -- C:\Users\landsau\Documents\My Games
[2011.02.28 19:14:57 | 003,485,696 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_p4.dll
[2011.02.28 19:14:57 | 000,839,680 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_vml_p4.dll
[2011.02.28 19:14:57 | 000,532,480 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_vml_p3.dll
[2011.02.28 19:14:57 | 000,512,000 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_vml_def.dll
[2011.02.28 19:14:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Ripple Sound
[2011.02.28 19:14:56 | 002,793,472 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_p3.dll
[2011.02.28 19:14:56 | 002,441,216 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_def.dll
[2011.02.28 19:14:56 | 002,174,976 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_lapack32.dll
[2011.02.28 19:14:56 | 002,125,824 | ---- | C] (Intel Corporation) -- C:\Windows\System32\mkl_lapack64.dll
[2011.02.28 19:14:56 | 000,872,448 | ---- | C] (Blue Ripple Sound Limited) -- C:\Windows\System32\rapture3d_oal.dll
[2011.02.28 19:14:56 | 000,184,320 | ---- | C] (Intel Corporation) -- C:\Windows\System32\libguide40.dll
[2011.02.28 19:14:55 | 000,000,000 | ---D | C] -- C:\Program Files\BRS
[2011.02.21 19:43:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Solidshield
[4 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011.03.22 12:15:58 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\landsau\Desktop\OTL.exe
[2011.03.22 11:57:59 | 000,692,038 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.03.22 11:57:59 | 000,650,212 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.03.22 11:57:59 | 000,145,404 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.03.22 11:57:59 | 000,119,282 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.03.22 11:53:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.03.22 11:53:20 | 2415,370,240 | -HS- | M] () -- C:\hiberfil.sys
[2011.03.22 11:06:53 | 000,000,746 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.03.22 11:06:53 | 000,000,746 | ---- | M] () -- C:\Users\landsau\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011.03.22 10:47:19 | 000,002,016 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2011.03.22 07:47:00 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.03.22 07:40:19 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.03.22 07:40:19 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.03.21 23:17:15 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.03.21 23:10:08 | 000,309,360 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.03.21 22:09:24 | 000,000,128 | ---- | M] () -- C:\ProgramData\~34725640r
[2011.03.21 22:09:24 | 000,000,104 | ---- | M] () -- C:\ProgramData\~34725640
[2011.03.21 22:09:23 | 000,000,635 | ---- | M] () -- C:\Users\landsau\Desktop\Windows Diagnostic.lnk
[2011.03.21 22:09:11 | 000,000,344 | ---- | M] () -- C:\ProgramData\34725640
[2011.03.16 21:19:42 | 000,000,743 | ---- | M] () -- C:\Users\Public\Desktop\Traktor.lnk
[2011.03.16 21:19:09 | 000,001,094 | ---- | M] () -- C:\Users\Public\Desktop\Controller Editor.lnk
[2011.03.16 21:18:27 | 000,001,059 | ---- | M] () -- C:\Users\Public\Desktop\Service Center.lnk
[2011.03.13 15:40:52 | 000,001,913 | -H-- | M] () -- C:\Users\landsau\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011.03.13 15:40:52 | 000,001,889 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.03.11 17:19:17 | 000,000,629 | -H-- | M] () -- C:\Users\landsau\Application Data\Microsoft\Internet Explorer\Quick Launch\Wave Editor.lnk
[2011.03.11 17:19:17 | 000,000,629 | ---- | M] () -- C:\Users\landsau\Desktop\Wave Editor.lnk
[2011.03.11 17:17:01 | 000,002,560 | ---- | M] () -- C:\Users\landsau\Documents\Register Sound Forge.htm
[2011.03.11 17:13:40 | 000,001,934 | ---- | M] () -- C:\Users\Public\Desktop\Sound Forge 9.0.lnk
[2011.03.11 16:50:14 | 000,001,201 | ---- | M] () -- C:\Users\landsau\Desktop\DVDVideoSoft Free Studio.lnk
[2011.03.11 16:50:04 | 000,000,945 | ---- | M] () -- C:\Users\landsau\Desktop\Free Video to MP3 Converter.lnk
[2011.03.11 14:03:18 | 000,024,320 | ---- | M] () -- C:\Users\landsau\Desktop\1322113.jpg
[2011.03.04 16:11:12 | 000,137,656 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011.03.04 14:36:34 | 000,061,960 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011.03.02 20:42:37 | 000,000,580 | ---- | M] () -- C:\Users\landsau\Desktop\UseNeXT.lnk
[2011.02.28 19:14:27 | 000,445,016 | ---- | M] (Creative Labs) -- C:\Windows\System32\wrap_oal.dll
[2011.02.28 19:14:27 | 000,109,144 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\System32\OpenAL32.dll
[2011.02.27 15:45:53 | 000,263,681 | ---- | M] () -- C:\Users\landsau\Desktop\pt_.pdf
[2011.02.21 20:05:03 | 000,001,811 | ---- | M] () -- C:\Users\landsau\Desktop\N1.lnk
[4 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011.03.22 11:06:53 | 000,000,746 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.03.22 11:06:53 | 000,000,746 | ---- | C] () -- C:\Users\landsau\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011.03.22 10:47:19 | 000,002,016 | ---- | C] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2011.03.21 22:09:24 | 000,000,128 | ---- | C] () -- C:\ProgramData\~34725640r
[2011.03.21 22:09:24 | 000,000,104 | ---- | C] () -- C:\ProgramData\~34725640
[2011.03.21 22:09:23 | 000,000,635 | ---- | C] () -- C:\Users\landsau\Desktop\Windows Diagnostic.lnk
[2011.03.21 22:09:11 | 000,000,344 | ---- | C] () -- C:\ProgramData\34725640
[2011.03.16 21:19:42 | 000,000,743 | ---- | C] () -- C:\Users\Public\Desktop\Traktor.lnk
[2011.03.16 21:19:09 | 000,001,094 | ---- | C] () -- C:\Users\Public\Desktop\Controller Editor.lnk
[2011.03.16 21:18:27 | 000,001,059 | ---- | C] () -- C:\Users\Public\Desktop\Service Center.lnk
[2011.03.11 17:19:17 | 000,000,629 | -H-- | C] () -- C:\Users\landsau\Application Data\Microsoft\Internet Explorer\Quick Launch\Wave Editor.lnk
[2011.03.11 17:19:17 | 000,000,629 | ---- | C] () -- C:\Users\landsau\Desktop\Wave Editor.lnk
[2011.03.11 16:50:14 | 000,001,201 | ---- | C] () -- C:\Users\landsau\Desktop\DVDVideoSoft Free Studio.lnk
[2011.03.11 16:50:04 | 000,000,945 | ---- | C] () -- C:\Users\landsau\Desktop\Free Video to MP3 Converter.lnk
[2010.12.21 13:09:51 | 000,106,756 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2010.11.04 19:18:27 | 000,763,584 | ---- | C] () -- C:\Windows\System32\drivers\UDXTTM6010.sys
[2010.10.14 01:36:44 | 000,179,263 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2010.09.26 16:39:10 | 000,010,240 | -H-- | C] () -- C:\Users\landsau\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.09.15 08:51:44 | 000,002,142 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010.09.06 20:09:13 | 000,000,066 | ---- | C] () -- C:\Windows\3DWarehouseClient.INI
[2010.07.07 14:23:30 | 000,000,192 | -H-- | C] () -- C:\Users\landsau\AppData\Roaming\default.rss
[2010.07.06 17:27:59 | 000,004,767 | ---- | C] () -- C:\Windows\Irremote.ini
[2010.04.28 12:10:33 | 000,278,984 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2010.04.28 12:10:32 | 000,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2010.03.10 13:49:16 | 000,692,038 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2010.03.10 13:49:16 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2010.03.10 13:49:16 | 000,145,404 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2010.03.10 13:49:16 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2010.03.10 13:40:54 | 000,000,170 | ---- | C] () -- C:\ProgramData\nvUnsupRes.dat
[2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 05:33:53 | 000,309,360 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 03:05:48 | 000,650,212 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 03:05:48 | 000,119,282 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 01:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.07.14 00:11:34 | 000,245,328 | ---- | C] () -- C:\Windows\System32\drivers\volsnap.sys
[2009.07.14 00:11:12 | 001,659,648 | ---- | C] () -- C:\Windows\System32\auswloxf.dat
[2009.07.14 00:11:12 | 000,633,600 | ---- | C] () -- C:\Windows\System32\ecgfxgim.dat
[2009.07.14 00:11:12 | 000,152,320 | ---- | C] () -- C:\Windows\System32\gupdchna.dat
[2009.07.14 00:11:12 | 000,151,296 | ---- | C] () -- C:\Windows\System32\cshsqkfk.dat
[2009.07.14 00:11:12 | 000,050,432 | ---- | C] () -- C:\Windows\System32\vsarhoyt.dat
[2009.07.14 00:11:12 | 000,039,680 | ---- | C] () -- C:\Windows\System32\sgzcundw.dat
[2009.07.14 00:11:12 | 000,034,560 | ---- | C] () -- C:\Windows\System32\sqetwtbs.dat
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009.05.25 03:32:14 | 000,013,931 | ---- | C] () -- C:\Windows\System32\RaCoInst.dat
[2002.10.15 23:54:04 | 000,153,088 | ---- | C] () -- C:\Windows\System32\unrar.dll
< End of report > --- --- ---
hier die extra.txt
OTL Logfile: Code:
OTL Extras logfile created on: 22.03.2011 13:08:32 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Erdferkel\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 63,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97,56 Gb Total Space | 10,23 Gb Free Space | 10,48% Space Free | Partition Type: NTFS
Drive H: | 498,51 Gb Total Space | 405,90 Gb Free Space | 81,42% Space Free | Partition Type: NTFS
Drive K: | 1397,27 Gb Total Space | 0,04 Gb Free Space | 0,00% Space Free | Partition Type: NTFS
Drive L: | 7317,40 Gb Total Space | 3268,70 Gb Free Space | 44,67% Space Free | Partition Type: NTFS
Drive M: | 1397,27 Gb Total Space | 574,94 Gb Free Space | 41,15% Space Free | Partition Type: NTFS
Drive N: | 465,76 Gb Total Space | 41,82 Gb Free Space | 8,98% Space Free | Partition Type: NTFS
Computer Name: MEDIONPC | User Name: Erdferkel | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDSee Pro 3.Manage] -- "C:\Program Files\ACD Systems\ACDSee Pro\3.0\ACDSeeQVPro3.exe" "%1" (ACD Systems International Inc.)
Directory [AddToPlaylistVLC] -- "H:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "H:\Programme\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "H:\Programme\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "H:\Programme\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "H:\Programme\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{013CCA52-DA56-4133-AC2B-1988A9568C30}" = Native Instruments Audio 4 DJ Driver
"{0711500B-9912-4D60-9A49-C577B4503D42}" = Nero Recode Help
"{07FF7593-9DEA-40B5-9F87-F557E65BBF60}" = Nero Recode
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0886900B-B2F3-452C-B580-60F1253F7F80}" = Native Instruments Controller Editor
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B8565BA-BAD5-4732-B122-5FD78EFC50A9}" = Native Instruments Service Center
"{1122AAC4-AAAA-43BF-B2D4-3C8C12378952}" = Nero InfoTool
"{11A84FCA-C3C7-4AFD-A797-111DB8569DBC}" = Nero BurningROM
"{12345674-DE9A-677A-CCEE-666356D89777}" = Nero BurnRights
"{177ADA1F-6D3B-404A-99DA-D7E0E2A36621}_is1" = Videograbber 2010
"{1B040683-C390-4711-ABC7-DA8D85E470E7}" = NeroBurningROM
"{1B280FAF-AE10-4E31-A41A-DB3917D651DC}" = ACDSee Pro 3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FDA5A37-B22D-43FF-B582-B8964050DC13}" = Microsoft Games for Windows - LIVE Redistributable
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java(TM) 6 Update 23
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2AAC4085-DCBF-417B-AEBD-182197839240}" = Native Instruments Traktor
"{2D3455A8-3B15-41A8-99F8-0D4215746463}" = Nero StartSmart
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3097B151-1F61-4211-A4CC-D70127B226AE}" = SoundTrax
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3F30CC51-0788-487B-AA83-7214A239C0C0}" = Nero Disc Copy Gadget Help
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D42353B-533F-4306-AD0B-7FEF292ADE04}" = Nero CoverDesigner Help
"{4E8C27C2-D727-4C00-A90E-C3F6376EEE70}" = Nero ControlCenter
"{548F99E0-14CC-4D53-A7D6-4A62A5F2C748}" = Nero PhotoSnap
"{56BE5CC9-95E6-4128-ABEA-968414CA9C80}" = DolbyFiles
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A62A775-A29A-4CE1-BBC2-4A9CD0B211EF}" = Nero Live Help
"{5AE12194-3EAA-40DF-B2BF-FE1D6B78BBF4}" = Nero Vision
"{5C2E8A0F-80E2-4C68-8CC0-D8D16E7196BF}" = Nero RescueAgent Help
"{5C42EAB8-54F9-423A-948C-1CBEF25F8DB4}" = Nero PhotoSnap Help
"{5C9BB0B3-E830-4814-BBA4-D93535E1C7B9}" = Nero Live
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{61FFF5E3-1D08-4F66-AC29-EF61963F2619}" = pCon.planner 6
"{63B9BAB5-F36A-4A3B-9E5C-68A7F212BFB9}" = TerraTec Home Cinema
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75321954-2589-11DC-DDCC-E98356D81493}" = Nero DriveSpeed
"{753973C4-B961-43BF-B2D4-3C8C92F7216E}" = Nero DriveSpeed
"{758799AB-2DAD-4BBB-83C3-D69A60D12363}_is1" = Emergence Viewer 1.5.2.549
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78523651-D8B1-11DC-CCEE-741589645873}" = Nero DiscSpeed
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86A4C6D9-29EE-4719-AFA1-BA3341862B83}" = Microsoft Games for Windows - LIVE
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{8C654BD0-1949-43DE-84F2-EC2A1ABB0CB4}" = Nero ShowTime
"{90120000-001A-0000-0000-0000000FF1CE}" = Microsoft Office Outlook 2007
"{90120000-001A-0000-0000-0000000FF1CE}_OUTLOOK_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0000-0000-0000000FF1CE}_OUTLOOK_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_OUTLOOK_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_OUTLOOK_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_OUTLOOK_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_OUTLOOK_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_OUTLOOK_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_OUTLOOK_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center
"{943CC0C0-2253-4FE0-9493-DD386F7857FD}" = Nero Express
"{948FFAAE-C57F-447B-9B07-3721E950BFDC}" = Nero ShowTime
"{961D53EA-40DC-4156-AD74-25684CE05F81}" = Nero Installer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A875B56-A35C-46BA-A3AA-DF8D03EE9F2F}" = Nero ControlCenter
"{9F3523F8-DAD7-AE52-6DA7-45CDDDF33726}" = Advertising Center
"{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
"{A73BEC3C-40A0-480E-87EF-EFCD33629088}" = NeroExpress
"{A8399F58-234A-48C6-BA55-30C15738BF3C}" = Nero CoverDesigner
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAA12554-2589-11DC-92EF-E98356D81493}" = Nero InfoTool
"{AABBCC54-D8B1-11DC-92EF-E98356D81493}" = Nero DiscSpeed
"{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3 - Deutsch
"{B2C12C8D-65DC-40BD-B309-5ADB0C6C8D8F}" = Nero WaveEditor
"{B96C2601-52F5-4D5D-816A-63469EA311EF}" = "Nero SoundTrax Help
"{BCD82AB5-670D-4242-90FA-1F97103C16CD}" = Movie Templates - Starter Kit
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C911A0C2-2236-3164-AA47-F2566C01AE5E}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{C99C89A3-119A-45E6-B26E-DD5643CAA0C5}" = Menu Templates - Starter Kit
"{ca43c673-b052-4801-b5b8-9e420e5c3b19}" = Nero 9
"{CD1826A5-CFCC-4C6E-9F9D-E181876162EA}" = Nero Rescue Agent
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.3.22 Game
"{D7C206B6-1A63-4389-A8B1-8F607D0BFF1F}" = Nero StartSmart Help
"{DB0F5549-0EEE-4421-A1B2-08FB1468D7F1}" = calibre
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{DFFC0648-BC4B-47D1-93D2-6CA6B9457641}" = OpenOffice.org 3.2
"{E4A8DD87-A746-4443-BF25-CAF99CED6767}" = Nero Disc Copy Gadget
"{E86156E5-9859-440D-8876-26CED1349802}" = Nero WaveEditor Help
"{EA9FFE54-D8B1-11DC-92EF-E98356D81493}" = Nero BurnRights
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F53F6769-AC46-49E3-ABE3-2C8AFD39D0DD}" = Nero Vision
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 7_is1" = AVS Video Converter 7
"Badaboom" = Badaboom 1.2.1.74
"Cinergy Hybrid Stick" = Cinergy Hybrid Stick V1.00.08.06a
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09
"ComicRack" = ComicRack v0.9.134
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"Direct MP3 Joiner_is1" = Direct MP3 Joiner version 3.0.2.9
"Direct WAV MP3 Splitter_is1" = Direct WAV MP3 Splitter version 2.6.0.22
"DirPrinter_is1" = DirPrinter - Deinstallation
"DivX Setup.divx.com" = DivX-Setup
"Free DVD MP3 Ripper_is1" = Free DVD MP3 Ripper 1.12
"Free Video to MP3 Converter_is1" = Free Video to MP3 Converter version 4.2.17.305
"JDownloader" = JDownloader
"Keseling DirPrinter 3.1.1_is1" = Keseling DirPrinter 3.1.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15)
"Native Instruments Audio 4 DJ Driver" = Native Instruments Audio 4 DJ Driver
"Native Instruments Controller Editor" = Native Instruments Controller Editor
"Native Instruments Service Center" = Native Instruments Service Center
"Native Instruments Traktor" = Native Instruments Traktor
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"OpenAL" = OpenAL
"OUTLOOK" = Microsoft Office Outlook 2007
"pCon.planner 6" = pCon.planner 6
"Poser 8_is1" = Poser 8 (8.0.0.10157)
"QuickPar" = QuickPar 0.9
"Synology Assistant" = Synology Assistant (remove only)
"TeraCopy_is1" = TeraCopy 2.12
"TightVNC_is1" = TightVNC 1.3.10
"TmNationsForever_is1" = TmNationsForever Update 2010-03-15
"Ultra Audio Ripper_is1" = Ultra Audio Ripper 2.0
"Uninstall_is1" = Uninstall 1.0.0.1
"Universal Document Converter_is1" = Universal Document Converter (Demo)
"Video Thumbnails Maker" = Video Thumbnails Maker by Scorp (remove only)
"VLC media player" = VLC media player 1.1.7
"vShare" = vShare Plugin
"Wave Editor_is1" = Wave Editor 3.1.0.0
"Winamp" = Winamp
"WinRAR archiver" = WinRAR
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Erkennungs-Plug-in
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report > --- --- --- |