Blitzknall | 27.05.2011 08:35 | Und der nächste Log!!
Gruß,
TomOTL Logfile: Code:
OTL logfile created on: 27.05.2011 09:18:09 - Run 2
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Dokumente und Einstellungen\Tom\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
510,98 Mb Total Physical Memory | 157,73 Mb Available Physical Memory | 30,87% Memory free
1,22 Gb Paging File | 0,94 Gb Available in Paging File | 77,39% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 145,46 Gb Total Space | 50,10 Gb Free Space | 34,44% Space Free | Partition Type: NTFS
Computer Name: ROCKETMAN | User Name: Tom | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Dokumente und Einstellungen\Tom\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
PRC - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Programme\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Gemeinsame Dateien\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
PRC - C:\Programme\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Programme\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Dokumente und Einstellungen\Tom\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (LiveUpdate Notice Ex) -- File not found
SRV - (HidServ) -- File not found
SRV - (AppMgmt) -- File not found
SRV - (Akamai) -- c:\Programme\Gemeinsame Dateien\Akamai\netsession_win_8832f4b.dll ()
SRV - (sdCoreService) -- C:\Programme\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) -- C:\Programme\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (SwitchBoard) -- C:\Programme\Gemeinsame Dateien\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (NMSAccessU) -- C:\Programme\CDBurnerXP\NMSAccessU.exe ()
SRV - (p2pgasvc) -- C:\WINDOWS\SYSTEM32\p2pgasvc.dll (Microsoft Corporation)
SRV - (LiveUpdate Notice Service) -- C:\Programme\Gemeinsame Dateien\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (LiveUpdate) -- C:\Programme\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatisches LiveUpdate - Scheduler) -- C:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (IDriverT) -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (MDM) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NetSvc) -- C:\Programme\Intel\NCS\Sync\NetSvc.exe (Intel(R) Corporation)
========== Driver Services (SafeList) ==========
DRV - (pctplsg) -- C:\WINDOWS\SYSTEM32\DRIVERS\pctplsg.sys (PC Tools)
DRV - (PCTCore) -- C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (Tcpip6) -- C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys (Microsoft Corporation)
DRV - (pctgntdi) -- C:\WINDOWS\SYSTEM32\DRIVERS\pctgntdi.sys (PC Tools)
DRV - (tbhsd) -- C:\WINDOWS\SYSTEM32\DRIVERS\tbhsd.sys (RapidSolution Software AG)
DRV - (StarOpen) -- C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (FTSER2K) -- C:\WINDOWS\SYSTEM32\DRIVERS\ftser2k.sys (FTDI Ltd.)
DRV - (acedrv10) -- C:\WINDOWS\SYSTEM32\DRIVERS\ACEDRV10.sys (Protect Software GmbH)
DRV - (acehlp10) -- C:\WINDOWS\SYSTEM32\DRIVERS\acehlp10.sys (Protect Software GmbH)
DRV - (SE27bus) Sony Ericsson Device 039 Driver driver (WDM) -- C:\WINDOWS\SYSTEM32\DRIVERS\SE27bus.sys (MCCI)
DRV - (FTDIBUS) -- C:\WINDOWS\SYSTEM32\DRIVERS\ftdibus.sys (FTDI Ltd.)
DRV - (iAimFP4) -- C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel(R) Corporation)
DRV - (iAimFP3) -- C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel(R) Corporation)
DRV - (iAimTV4) -- C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel(R) Corporation)
DRV - (iAimTV3) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel(R) Corporation)
DRV - (iAimTV1) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel(R) Corporation)
DRV - (iAimTV0) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel(R) Corporation)
DRV - (iAimFP0) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel(R) Corporation)
DRV - (iAimFP1) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel(R) Corporation)
DRV - (iAimFP2) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel(R) Corporation)
DRV - (i81x) -- C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel(R) Corporation)
DRV - (P17) -- C:\WINDOWS\SYSTEM32\DRIVERS\P17.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) -- C:\WINDOWS\SYSTEM32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) -- C:\WINDOWS\SYSTEM32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (PfModNT) -- C:\WINDOWS\SYSTEM32\DRIVERS\Pfmodnt.sys (Creative Technology Ltd.)
DRV - (omci) -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (ASPI32) -- C:\WINDOWS\SYSTEM32\DRIVERS\ASPI32.SYS (Adaptec)
DRV - (ASPI) -- C:\WINDOWS\SYSTEM32\DRIVERS\ASPI32.SYS (Adaptec)
DRV - (EL90XBC) -- C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)
DRV - (Sentinel) -- C:\WINDOWS\System32\Drivers\SENTINEL.SYS ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.lyserg-band.de/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1601497&SearchSource=3&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de"
FF - prefs.js..extensions.enabledItems: 2020Player@2020Technologies.com:4.5.4.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {B0D70E72-2FC1-4b9f-A3D4-5921C854D906}:1.2
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Programme\Mozilla Firefox\components [2011.05.06 16:53:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2011.05.06 16:53:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Components: C:\Programme\Mozilla Thunderbird\components [2011.05.03 22:11:59 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Plugins: C:\Programme\Mozilla Thunderbird\plugins [2010.03.27 21:52:42 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Netscape 7.1\Extensions\\Components: C:\Programme\Netscape\Netscape\Components [2010.08.07 17:33:14 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Netscape 7.1\Extensions\\Plugins: C:\Programme\Netscape\Netscape\Plugins [2010.07.31 14:10:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Netscape Navigator 9.0.0.6\extensions\\Components: C:\Programme\Netscape\Navigator 9\components [2008.10.23 23:43:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Netscape Navigator 9.0.0.6\extensions\\Plugins: C:\Programme\Netscape\Navigator 9\plugins [2010.01.26 13:12:30 | 000,000,000 | ---D | M]
[2010.11.30 09:49:44 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Mozilla\Extensions
[2010.11.30 09:49:44 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.05.25 22:17:18 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Mozilla\Firefox\Profiles\6mogmq4p.default\extensions
[2009.01.31 21:57:16 | 000,000,000 | ---D | M] ("ColorfulTabs") -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Mozilla\Firefox\Profiles\6mogmq4p.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2009.09.02 14:41:39 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Mozilla\Firefox\Profiles\6mogmq4p.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.05.07 13:58:44 | 000,000,000 | ---D | M] ("Biet-O-Matic Firefox Erweiterung") -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Mozilla\Firefox\Profiles\6mogmq4p.default\extensions\{B0D70E72-2FC1-4b9f-A3D4-5921C854D906}
[2011.01.19 23:05:23 | 000,000,000 | ---D | M] (20-20 3D Viewer) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Mozilla\Firefox\Profiles\6mogmq4p.default\extensions\2020Player@2020Technologies.com
[2009.12.20 13:40:31 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Mozilla\Firefox\Profiles\6mogmq4p.default\extensions\moveplayer@movenetworks.com
[2009.01.31 21:43:25 | 000,000,000 | ---D | M] (NASA Night Launch) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Mozilla\Firefox\Profiles\6mogmq4p.default\extensions\nasanightlaunch@example.com
[2011.05.25 22:17:18 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2010.07.31 14:10:36 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.07.31 14:09:53 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAMME\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2008.09.04 02:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npbittorrent.dll
[2010.07.31 14:09:49 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
[2009.04.08 04:06:28 | 000,122,880 | ---- | M] (AB) -- C:\Programme\Mozilla Firefox\plugins\NPOP7PlugIn.dll
[2008.04.07 20:55:00 | 000,000,909 | ---- | M] () -- C:\Programme\Mozilla Firefox\searchplugins\conduit.xml
O1 HOSTS File: ([2011.05.26 20:31:16 | 000,000,027 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Programme\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Programme\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Programme\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Programme\Gemeinsame Dateien\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Programme\Gemeinsame Dateien\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CTSysVol] C:\Programme\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Programme\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Programme\Gemeinsame Dateien\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Programme\Gemeinsame Dateien\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [UpdateManager] C:\Programme\Gemeinsame Dateien\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download by Orbit - C:\Programme\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Programme\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Programme\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Programme\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CAB (Reg Error: Key error.)
O16 - DPF: {00000161-0000-0010-8000-00AA00389B71} hxxp://codecs.microsoft.com/codecs/i386/msaudio.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\bt2 {1730B77B-F429-498f-9B15-4514D83C8294} - File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\application/x-bt2 {6E1DDCE8-76BC-4390-9488-806E8FB1AD77} - File not found
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Tom\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Tom\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.07.25 15:26:37 | 000,335,856 | ---- | M] () - C:\Auto1.JPG -- [ NTFS ]
O32 - AutoRun File - [2007.07.25 15:27:41 | 000,363,912 | ---- | M] () - C:\Auto2.JPG -- [ NTFS ]
O32 - AutoRun File - [2002.09.11 14:48:26 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0
SafeBootMin: AppMgmt - File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sdauxservice - C:\Programme\Spyware Doctor\pctsAuxs.exe (PC Tools)
SafeBootMin: sdcoreservice - C:\Programme\Spyware Doctor\pctsSvc.exe (PC Tools)
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: AppMgmt - File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sdauxservice - C:\Programme\Spyware Doctor\pctsAuxs.exe (PC Tools)
SafeBootNet: sdcoreservice - C:\Programme\Spyware Doctor\pctsSvc.exe (PC Tools)
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608555} - Internet Explorer Classes for Java
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vektorgrafik-Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2cc9d512-6db6-4f1c-8979-9a41fae88de0} - Q837009
ActiveX: {2F6EFCE6-10DF-49F9-9E64-9AE3775B2588} - Microsoft .NET Framework 1.1 Security Update (KB2416447)
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Erweitertes Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015C} - Microsoft DirectX
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {689e5762-8d75-4346-90cf-bc1902c32d63} - KB896688
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {795d0712-722c-43ec-906a-fc5e678eada9} - Q831167
ActiveX: {82ced0ff-a00d-4405-ba5f-ef4699159333} - KB896727
ActiveX: {8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Taskplaner
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {eddbec60-89cb-44ef-8291-0850fd28ff6a} - Q832894
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60b49e34-c7cc-11d0-8953-00a0c90347ff} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\SYSTEM32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (hxxp://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: SENTINEL - C:\WINDOWS\System32\SNTI386.DLL ()
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\WINDOWS\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\Ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\WINDOWS\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: VIDC.X264 - x264vfw.dll File not found
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\Iyvu9_32.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2011.05.26 23:11:25 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011.05.26 20:13:31 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011.05.26 20:10:18 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011.05.26 20:10:18 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011.05.26 20:10:18 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011.05.26 20:10:18 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011.05.26 20:07:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011.05.26 19:10:32 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011.05.26 18:53:28 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.05.24 20:48:26 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Tom\Desktop\OTL.exe
[2011.05.08 16:22:19 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\GridinSoft
[2011.05.08 16:22:15 | 000,000,000 | ---D | C] -- C:\Programme\GridinSoft Trojan Killer
[2011.05.08 16:10:50 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\Tom\Recent
[2011.05.08 16:10:08 | 000,258,560 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Tom\Desktop\OTH.scr
[2011.05.08 15:50:59 | 000,059,664 | --S- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\TfSysMon.sys
[2011.05.08 15:50:58 | 000,051,984 | --S- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\TfFsMon.sys
[2011.05.08 15:50:58 | 000,033,552 | --S- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\TfNetMon.sys
[2011.05.08 12:06:02 | 000,000,000 | ---D | C] -- C:\Programme\VirKil
[2011.05.07 13:55:24 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\BOM
[2011.05.07 13:55:05 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Biet-O-Matic
[2011.05.07 13:55:04 | 000,209,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Tabctl32.ocx
[2011.05.07 13:55:04 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Mscmcde.dll
[2011.05.07 13:55:04 | 000,125,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vb6de.dll
[2011.05.07 13:55:04 | 000,115,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msinet.ocx
[2011.05.07 13:55:04 | 000,109,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Mswinsck.ocx
[2011.05.07 13:55:04 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Tabctde.dll
[2011.05.07 13:55:04 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winskde.dll
[2011.05.07 13:55:04 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\stdftde.dll
[2011.05.07 13:55:03 | 000,000,000 | ---D | C] -- C:\Programme\Biet-O-Matic
[2011.05.02 09:50:30 | 000,954,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc40.dll
[2011.05.02 09:50:30 | 000,953,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc40u.dll
[2011.05.02 09:50:03 | 000,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comctl32.dll
[2011.05.02 09:49:34 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011.05.02 09:43:42 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab.exe
[2011.05.01 12:36:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2011.05.01 12:36:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\de
[2011.05.01 12:15:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2010.11.05 23:25:01 | 017,671,448 | ---- | C] (DVDVideoSoft Limited. ) -- C:\Programme\FreeVideoToFlashConverter.exe
[2010.11.05 22:22:30 | 000,423,936 | ---- | C] (Feñiz 2001) -- C:\Programme\Conversor.exe
[2008.05.06 12:34:00 | 000,136,704 | ---- | C] (HR) -- C:\Programme\AVRootLoader.dll
[2004.10.21 13:38:58 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\A3d.dll
[2004.02.12 10:40:24 | 001,264,330 | ---- | C] (Macromedia, Inc.) -- C:\Programme\yetisports1.exe
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011.05.27 08:06:05 | 000,001,170 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2011.05.27 08:05:25 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2011.05.27 08:05:24 | 535,875,584 | -HS- | M] () -- C:\hiberfil.sys
[2011.05.26 23:21:51 | 000,002,353 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\ACDSee 3.1 SR-1.lnk
[2011.05.26 23:19:31 | 000,024,064 | ---- | M] () -- C:\Dokumente und Einstellungen\Tom\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.05.26 20:31:16 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\ETC\hosts
[2011.05.26 20:13:36 | 000,000,327 | RHS- | M] () -- C:\BOOT.INI
[2011.05.26 19:15:12 | 000,002,965 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LUUnInstall.LiveUpdate
[2011.05.26 18:52:26 | 004,353,961 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Desktop\ComboFix.exe
[2011.05.24 20:48:34 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Tom\Desktop\OTL.exe
[2011.05.22 15:29:05 | 000,000,493 | ---- | M] () -- C:\WINDOWS\ROCKSIM.INI
[2011.05.22 15:28:57 | 000,000,634 | ---- | M] () -- C:\WINDOWS\wrasp.ini
[2011.05.22 14:53:16 | 000,001,125 | ---- | M] () -- C:\WINDOWS\Winamp.ini
[2011.05.16 21:42:39 | 000,000,800 | ---- | M] () -- C:\Dokumente und Einstellungen\Tom\Desktop\Youtube Downloader HD.lnk
[2011.05.14 02:00:01 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-ROCKETMAN-Tom.job
[2011.05.08 16:01:58 | 000,000,232 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\~19062564
[2011.05.08 16:01:57 | 000,000,152 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\~19062564r
[2011.05.08 15:57:59 | 003,526,392 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.05.08 12:48:38 | 000,258,560 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Tom\Desktop\OTH.scr
[2011.05.08 02:22:09 | 000,000,344 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\19062564
[2011.05.02 10:31:19 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011.05.02 10:19:54 | 000,463,834 | ---- | M] () -- C:\WINDOWS\System32\PERFH007.DAT
[2011.05.02 10:19:54 | 000,445,370 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2011.05.02 10:19:54 | 000,086,216 | ---- | M] () -- C:\WINDOWS\System32\PERFC007.DAT
[2011.05.02 10:19:54 | 000,072,576 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2011.05.01 12:24:50 | 000,251,712 | RHS- | M] () -- C:\NTLDR
[2011.05.01 11:01:40 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011.05.26 20:23:27 | 000,002,353 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\ACDSee 3.1 SR-1.lnk
[2011.05.26 20:23:27 | 000,001,632 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Thunderbird.lnk
[2011.05.26 20:23:27 | 000,001,566 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk
[2011.05.26 20:13:36 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011.05.26 20:13:33 | 000,262,448 | RHS- | C] () -- C:\cmldr
[2011.05.26 20:10:18 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011.05.26 20:10:18 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011.05.26 20:10:18 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011.05.26 20:10:18 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011.05.26 20:10:18 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011.05.26 19:15:12 | 000,002,965 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LUUnInstall.LiveUpdate
[2011.05.26 18:49:43 | 004,353,961 | R--- | C] () -- C:\Dokumente und Einstellungen\Tom\Desktop\ComboFix.exe
[2011.05.08 02:22:41 | 000,000,152 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\~19062564r
[2011.05.08 02:22:40 | 000,000,232 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\~19062564
[2011.05.08 02:22:08 | 000,000,344 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\19062564
[2011.04.24 20:08:34 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.04.16 10:47:23 | 000,650,752 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011.04.16 10:47:23 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010.11.05 22:22:30 | 000,000,157 | ---- | C] () -- C:\Programme\Perfiles.ini
[2010.11.05 22:18:01 | 000,145,408 | ---- | C] () -- C:\Programme\gray.avi
[2010.11.05 22:18:01 | 000,010,530 | ---- | C] () -- C:\Programme\demo.ssa
[2010.11.05 22:17:56 | 000,038,463 | ---- | C] () -- C:\Programme\Subtitler.vdf
[2010.10.19 01:11:36 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI
[2010.05.04 23:05:41 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[2010.02.28 22:31:01 | 000,000,034 | ---- | C] () -- C:\WINDOWS\System32\Converter_sysquict.dat
[2010.02.28 22:29:04 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010.02.28 22:28:53 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010.01.03 14:47:36 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll.old
[2009.12.22 13:00:11 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2009.10.10 20:07:27 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\AVEQT.dll
[2009.09.14 00:13:30 | 000,018,321 | ---- | C] () -- C:\Programme\COPYING
[2009.03.19 20:08:19 | 000,272,896 | ---- | C] () -- C:\WINDOWS\System32\advddr32.exe
[2009.02.10 14:23:09 | 000,000,590 | ---- | C] () -- C:\WINDOWS\tlknw9.ini
[2008.12.13 19:15:23 | 000,000,049 | ---- | C] () -- C:\WINDOWS\System32\polynet.dll
[2008.07.10 11:38:58 | 001,936,896 | ---- | C] () -- C:\Programme\Altimax.exe
[2008.05.25 20:57:25 | 000,164,980 | ---- | C] () -- C:\WINDOWS\Audio Converter Pro Uninstaller.exe
[2008.04.22 17:12:00 | 000,006,290 | ---- | C] () -- C:\Programme\AVRootloader.dev
[2008.03.28 22:27:16 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2008.03.28 22:27:09 | 000,006,768 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2008.02.25 01:19:36 | 000,005,567 | ---- | C] () -- C:\WINDOWS\rules.dat
[2007.10.08 13:21:18 | 000,394,240 | ---- | C] () -- C:\WINDOWS\System32\Smab.dll
[2007.10.08 13:21:17 | 000,502,784 | ---- | C] () -- C:\WINDOWS\x2.64.exe
[2007.10.08 13:21:17 | 000,240,128 | ---- | C] () -- C:\WINDOWS\System32\x.264.exe
[2007.10.08 13:21:17 | 000,217,073 | ---- | C] () -- C:\WINDOWS\meta4.exe
[2007.10.08 13:21:17 | 000,066,560 | ---- | C] () -- C:\WINDOWS\MOTA113.exe
[2007.10.08 13:21:17 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2007.04.23 19:49:11 | 000,000,136 | ---- | C] () -- C:\Dokumente und Einstellungen\Tom\Lokale Einstellungen\Anwendungsdaten\fusioncache.dat
[2007.04.23 19:44:20 | 000,000,290 | ---- | C] () -- C:\WINDOWS\BUHL.INI
[2007.03.17 12:12:58 | 000,000,197 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2007.02.02 07:12:49 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\com.fxpansion.fxshared.dll
[2006.05.24 11:04:14 | 000,000,133 | ---- | C] () -- C:\WINDOWS\System32\ftdiun2k.ini
[2006.05.24 10:40:42 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\ftdiunin.exe
[2006.05.10 00:04:38 | 000,001,735 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\QTSBandwidthCache
[2005.12.19 16:47:47 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\redmonnt.dll
[2005.12.19 16:47:47 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\unredmon.exe
[2005.11.14 11:28:20 | 000,000,209 | ---- | C] () -- C:\WINDOWS\render.ini
[2005.11.03 01:14:41 | 000,001,298 | ---- | C] () -- C:\WINDOWS\ikMap.INI
[2005.09.22 00:30:05 | 000,001,375 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP WMA V9.1 Codec.dat
[2005.09.22 00:21:40 | 000,026,914 | ---- | C] () -- C:\WINDOWS\CDMaster.ini
[2005.09.22 00:21:39 | 000,111,104 | ---- | C] () -- C:\WINDOWS\System32\Nviewlib.dll
[2005.09.22 00:21:39 | 000,018,944 | ---- | C] () -- C:\WINDOWS\System32\vcedit.dll
[2005.09.22 00:21:39 | 000,009,728 | ---- | C] () -- C:\WINDOWS\System32\vorbisfile.dll
[2005.09.22 00:21:38 | 000,120,832 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2005.09.22 00:21:38 | 000,107,008 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005.09.22 00:21:38 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2005.09.22 00:21:38 | 000,020,992 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2005.08.25 16:04:51 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2005.07.31 14:28:13 | 000,000,084 | ---- | C] () -- C:\WINDOWS\WSST_Screen_Saver.ini
[2005.07.31 14:28:12 | 000,180,224 | ---- | C] () -- C:\WINDOWS\UninstallWSST.exe
[2005.07.31 14:18:34 | 018,416,367 | ---- | C] () -- C:\WINDOWS\Nero Burning Rom Screensaver.dat
[2005.05.29 13:45:25 | 000,000,112 | ---- | C] () -- C:\WINDOWS\ActiveSkin.INI
[2005.05.24 12:41:52 | 000,000,516 | ---- | C] () -- C:\WINDOWS\ltN1.ini
[2005.05.07 12:31:22 | 000,064,512 | ---- | C] () -- C:\WINDOWS\System32\drivers\SENTINEL.SYS
[2005.05.07 12:31:22 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\RNBOVDD.DLL
[2005.05.07 12:31:21 | 000,038,400 | ---- | C] () -- C:\WINDOWS\System32\SNTI386.DLL
[2005.05.07 12:31:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MTSTACK.INI
[2005.05.07 12:31:18 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\MTSTACK.EXE
[2005.03.30 14:08:41 | 000,000,049 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2005.03.30 14:08:23 | 000,000,307 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2005.03.04 00:33:29 | 000,130,048 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall.exe
[2005.03.04 00:33:29 | 000,035,342 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP Music Converter.dat
[2005.01.30 16:08:39 | 000,000,293 | ---- | C] () -- C:\WINDOWS\FlgtProf.ini
[2004.11.11 21:01:12 | 000,000,493 | ---- | C] () -- C:\WINDOWS\ROCKSIM.INI
[2004.11.03 23:48:18 | 000,000,634 | ---- | C] () -- C:\WINDOWS\wrasp.ini
[2004.10.28 23:27:59 | 000,001,125 | ---- | C] () -- C:\WINDOWS\Winamp.ini
[2004.10.28 22:51:24 | 000,037,376 | ---- | C] () -- C:\WINDOWS\System32\VbVfw.dll
[2004.10.28 22:13:04 | 000,024,064 | ---- | C] () -- C:\Dokumente und Einstellungen\Tom\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004.10.28 20:41:13 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2004.10.28 20:41:02 | 000,087,184 | ---- | C] () -- C:\WINDOWS\NSUninst.exe
[2004.10.28 20:40:49 | 000,087,184 | ---- | C] () -- C:\WINDOWS\GREUninstall.exe
[2004.10.28 20:40:45 | 000,008,828 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2004.10.27 22:44:57 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\BW32000C.DLL
[2004.10.27 22:44:57 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\BW320007.DLL
[2004.10.21 13:42:59 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004.10.21 13:40:21 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004.10.21 13:39:05 | 001,048,576 | ---- | C] () -- C:\WINDOWS\System32\SFMAN.DAT
[2004.10.21 13:39:05 | 000,000,231 | ---- | C] () -- C:\WINDOWS\AC3API.INI
[2004.10.21 13:38:58 | 000,060,928 | ---- | C] () -- C:\WINDOWS\System32\P17.dll
[2004.10.21 13:38:58 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\P17CPI.dll
[2004.10.21 13:38:58 | 000,003,278 | ---- | C] () -- C:\WINDOWS\System32\LudaP17.ini
[2004.10.21 13:38:58 | 000,000,029 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2004.10.21 13:38:53 | 000,000,072 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2004.10.21 13:38:03 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004.10.21 13:35:17 | 000,000,849 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004.10.21 13:25:04 | 000,002,048 | --S- | C] () -- C:\WINDOWS\BOOTSTAT.DAT
[2004.10.21 13:24:00 | 000,463,834 | ---- | C] () -- C:\WINDOWS\System32\PERFH007.DAT
[2004.10.21 13:24:00 | 000,445,370 | ---- | C] () -- C:\WINDOWS\System32\PERFH009.DAT
[2004.10.21 13:24:00 | 000,086,216 | ---- | C] () -- C:\WINDOWS\System32\PERFC007.DAT
[2004.10.21 13:24:00 | 000,072,576 | ---- | C] () -- C:\WINDOWS\System32\PERFC009.DAT
[2004.10.21 13:23:53 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2004.10.21 13:23:45 | 000,003,776 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004.10.21 13:10:18 | 000,000,619 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004.03.26 17:59:22 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004.03.06 18:07:20 | 000,012,942 | ---- | C] () -- C:\Programme\cdmaster32.xml
[2004.03.06 17:55:26 | 000,000,361 | ---- | C] () -- C:\Programme\FILE_ID.DIZ
[2004.03.06 17:52:52 | 000,010,338 | ---- | C] () -- C:\Programme\whats.new
[2004.02.29 23:27:50 | 000,004,630 | ---- | C] () -- C:\Programme\Register.frm
[2003.04.22 16:37:50 | 000,000,141 | ---- | C] () -- C:\WINDOWS\System32\DLBKPLC.INI
[2003.02.20 18:53:42 | 000,005,702 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2003.01.07 22:15:26 | 000,000,255 | ---- | C] () -- C:\WINDOWS\System32\dlbkcoin.ini
[2002.11.13 20:40:22 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbkvs.dll
[2002.09.11 14:53:22 | 003,526,392 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2002.09.11 14:47:42 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2002.09.11 14:44:56 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2002.09.11 10:46:36 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN
[2002.09.11 10:46:36 | 000,004,594 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT
[2002.08.29 06:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\MLANG.DAT
[2002.08.29 06:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\PERFI009.DAT
[2002.08.29 06:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\PERFI007.DAT
[2002.08.29 06:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\DSSEC.DAT
[2002.08.29 06:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\MIB.BIN
[2002.08.29 06:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\PERFD007.DAT
[2002.08.29 06:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\PERFD009.DAT
[2002.08.29 06:00:00 | 000,027,377 | ---- | C] () -- C:\WINDOWS\System32\rqpnhohab.exe
[2002.08.29 06:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2002.08.29 06:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\NOISE.DAT
[2001.02.15 00:00:00 | 000,287,744 | ---- | C] () -- C:\WINDOWS\uno364mi.dll
[2001.02.15 00:00:00 | 000,109,568 | ---- | C] () -- C:\WINDOWS\vos364mi.dll
[2001.02.15 00:00:00 | 000,091,648 | ---- | C] () -- C:\WINDOWS\osl364mi.dll
[2001.02.15 00:00:00 | 000,000,207 | ---- | C] () -- C:\WINDOWS\uno.ini
[1980.01.01 01:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
========== Custom Scans ==========
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2005.06.30 18:07:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\.bt2
[2005.03.13 13:17:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\ACD Systems
[2005.03.18 17:14:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\ACDInTouch
[2010.10.15 17:55:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Acoustica Premium
[2010.11.23 22:44:21 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Adobe
[2005.09.28 23:09:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Apple Computer
[2009.05.31 22:06:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\BDEDIT
[2008.04.26 17:03:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\BDHTHELP
[2011.05.08 02:23:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\BitTorrent
[2011.05.08 21:17:38 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\BOM
[2007.12.13 11:05:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Buhl Data Service GmbH
[2009.12.22 13:00:43 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Canneverbe_Limited
[2004.10.21 13:42:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Creative
[2004.12.09 17:29:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\CyberLink
[2009.08.27 20:03:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\DNA
[2010.10.05 11:14:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\dvdcss
[2010.11.05 23:26:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\DVDVideoSoft
[2005.08.07 14:22:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Google
[2009.09.29 13:25:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\GrabPro
[2004.11.08 23:09:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Help
[2004.10.21 13:08:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Identities
[2004.10.21 13:40:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Jasc Software Inc
[2004.11.01 21:45:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Leadertech
[2005.09.07 21:21:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Macromedia
[2008.08.28 04:44:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Malwarebytes
[2010.02.28 23:31:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Media Player Classic
[2009.11.22 19:27:57 | 000,000,000 | --SD | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft
[2010.01.16 13:29:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Move Networks
[2009.09.29 13:22:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Moyea
[2008.09.17 00:35:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Mozilla
[2008.03.28 22:09:40 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Netscape
[2011.05.09 05:11:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Orbit
[2009.10.11 16:40:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\PACE Anti-Piracy
[2008.08.28 04:16:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\PC Tools
[2011.04.17 00:11:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\ProgSense
[2008.08.31 22:29:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Real
[2006.04.11 22:10:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\River Past G4
[2008.05.25 20:57:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\River Past G5
[2004.11.01 21:46:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Sonic
[2008.03.29 23:48:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Sony Ericsson
[2004.10.21 13:33:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Sun
[2007.04.23 19:50:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\tax
[2010.08.09 13:57:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\TeamViewer
[2008.03.29 23:50:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Teleca
[2010.11.30 09:49:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Thunderbird
[2010.08.06 11:20:03 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\TS3Client
[2011.05.14 13:50:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\vlc
[2010.10.15 00:02:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\WordToPDF
[2010.08.13 23:37:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Youtube Downloader HD
< %APPDATA%\*.exe /s >
[2008.03.08 01:02:28 | 001,523,040 | ---- | M] (Adobe Systems Incorporated) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
[2009.08.30 19:35:21 | 001,924,440 | ---- | M] (Adobe Systems Incorporated) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
[2007.08.10 21:50:10 | 000,026,694 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\ARPPRODUCTICON.exe
[2007.08.10 21:50:10 | 000,026,694 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
[2007.08.10 21:50:10 | 000,026,694 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
[2007.08.10 21:50:10 | 000,026,694 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\UNINST_Uninstall_G_3DE5E7D47B88403CA3FD2017A8240C5B.exe
[2008.12.13 19:14:38 | 000,068,335 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{8904ACA8-CEB6-4286-BC3B-6F5A14654CC6}\_0B6DD62BFA40EE44243865.exe
[2008.12.13 19:14:38 | 000,029,926 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{8904ACA8-CEB6-4286-BC3B-6F5A14654CC6}\_1393CAF646846775718621.exe
[2008.12.13 19:14:38 | 000,025,214 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{8904ACA8-CEB6-4286-BC3B-6F5A14654CC6}\_15597E315244491DFD2033.exe
[2008.12.13 19:14:38 | 000,029,926 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{8904ACA8-CEB6-4286-BC3B-6F5A14654CC6}\_25EDEED4AB8FC277769FC7.exe
[2008.12.13 19:14:38 | 000,026,694 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{8904ACA8-CEB6-4286-BC3B-6F5A14654CC6}\_2E5081E7A2E168D60285BB.exe
[2008.12.13 19:14:38 | 000,053,793 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{8904ACA8-CEB6-4286-BC3B-6F5A14654CC6}\_636E72E222D2409B4DBBD8.exe
[2008.12.13 19:14:38 | 000,009,662 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{8904ACA8-CEB6-4286-BC3B-6F5A14654CC6}\_8194872C52BD2351B9EC48.exe
[2008.12.13 19:14:38 | 000,107,453 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{8904ACA8-CEB6-4286-BC3B-6F5A14654CC6}\_A0D86B4722A18424070902.exe
[2008.12.13 19:14:38 | 000,004,286 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{8904ACA8-CEB6-4286-BC3B-6F5A14654CC6}\_A775647795E52BAF0370A0.exe
[2008.12.13 19:14:38 | 000,015,086 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{8904ACA8-CEB6-4286-BC3B-6F5A14654CC6}\_BEC06949FE511FFDE2BA1D.exe
[2008.12.13 19:14:38 | 000,053,310 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{8904ACA8-CEB6-4286-BC3B-6F5A14654CC6}\_D9C6388C1C894A969526E7.exe
[2008.12.13 19:14:38 | 000,065,434 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{8904ACA8-CEB6-4286-BC3B-6F5A14654CC6}\_DF081CFC6920C6B3B58C70.exe
[2008.12.13 19:14:38 | 000,115,606 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{8904ACA8-CEB6-4286-BC3B-6F5A14654CC6}\_EB733251A0374F7FF07466.exe
[2008.12.13 19:14:38 | 000,150,689 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{8904ACA8-CEB6-4286-BC3B-6F5A14654CC6}\_F74FD493BA5E75B1E3742E.exe
[2007.04.23 19:46:35 | 000,003,638 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{98AFD394-F5D0-40A1-AC84-020DE6B2D4E1}\ARPPRODUCTICON.exe
[2007.04.23 19:46:36 | 000,045,056 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{98AFD394-F5D0-40A1-AC84-020DE6B2D4E1}\NewShortcut10_FE2DFC05CD1F4CCDB7A69854173E2F92.exe
[2007.04.23 19:46:35 | 000,040,960 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{98AFD394-F5D0-40A1-AC84-020DE6B2D4E1}\NewShortcut11_FE2DFC05CD1F4CCDB7A69854173E2F92.exe
[2007.04.23 19:46:36 | 000,049,152 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{98AFD394-F5D0-40A1-AC84-020DE6B2D4E1}\NewShortcut13_FE2DFC05CD1F4CCDB7A69854173E2F92.exe
[2007.04.23 19:46:35 | 000,045,056 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{98AFD394-F5D0-40A1-AC84-020DE6B2D4E1}\NewShortcut23_FE2DFC05CD1F4CCDB7A69854173E2F92.exe
[2007.04.23 19:46:35 | 000,045,056 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{98AFD394-F5D0-40A1-AC84-020DE6B2D4E1}\NewShortcut3_FE2DFC05CD1F4CCDB7A69854173E2F92.exe
[2007.04.23 19:46:36 | 000,045,056 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{98AFD394-F5D0-40A1-AC84-020DE6B2D4E1}\NewShortcut4_FE2DFC05CD1F4CCDB7A69854173E2F92.exe
[2007.04.23 19:46:36 | 000,045,056 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{98AFD394-F5D0-40A1-AC84-020DE6B2D4E1}\NewShortcut5_FE2DFC05CD1F4CCDB7A69854173E2F92.exe
[2007.04.23 19:46:36 | 000,045,056 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{98AFD394-F5D0-40A1-AC84-020DE6B2D4E1}\NewShortcut7_FE2DFC05CD1F4CCDB7A69854173E2F92.exe
[2007.04.23 19:46:36 | 000,045,056 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{98AFD394-F5D0-40A1-AC84-020DE6B2D4E1}\NewShortcut8_FE2DFC05CD1F4CCDB7A69854173E2F92.exe
[2007.04.23 19:46:36 | 000,045,056 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{98AFD394-F5D0-40A1-AC84-020DE6B2D4E1}\NewShortcut9_FE2DFC05CD1F4CCDB7A69854173E2F92.exe
[2007.04.23 19:46:36 | 000,045,056 | R--- | M] (Macrovision Corporation) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{98AFD394-F5D0-40A1-AC84-020DE6B2D4E1}\ShortcutGesetz.phc_FE2DFC05CD1F4CCDB7A69854173E2F92.exe
[2007.04.23 19:48:45 | 000,010,134 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{9F45E494-BFFB-4E85-B821-59BF40636640}\ARPPRODUCTICON.exe
[2007.04.23 19:48:45 | 000,009,062 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{9F45E494-BFFB-4E85-B821-59BF40636640}\NewShortcut1_9F45E494BFFB4E85B82159BF40636640.exe
[2007.04.23 19:48:45 | 000,009,062 | R--- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Microsoft\Installer\{9F45E494-BFFB-4E85-B821-59BF40636640}\NewShortcut2_9F45E494BFFB4E85B82159BF40636640.exe
[2008.08.09 11:01:29 | 006,287,800 | ---- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Real\Update\setup\data\ff\firefoxgoogletoolbarsetup.exe
[2008.08.09 11:01:35 | 000,755,816 | ---- | M] () -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Real\Update\setup\data\gds\GOOGLE_DESKTOP\gdssetup.exe
[2008.08.09 11:01:42 | 001,240,104 | ---- | M] (Google) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Real\Update\setup\data\gtb\GOOGLE_TOOLBAR\googletoolbarinstaller.exe
[2008.08.09 11:01:49 | 001,240,104 | ---- | M] (Google) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Real\Update\setup\data\gtb_gds\GOOGLE_TOOLBAR\googletoolbarinstaller.exe
[2008.08.09 11:02:56 | 013,743,624 | ---- | M] (RealNetworks, Inc.) -- C:\Dokumente und Einstellungen\Tom\Anwendungsdaten\Real\Update\setup\data\rp\RealPlayer11GOLD_de.exe
< %SYSTEMDRIVE%\*.exe >
[2009.02.23 20:35:38 | 035,124,856 | ---- | M] ( ) -- C:\AdbeRdr90_en_US.exe
[2003.04.14 22:54:58 | 001,961,777 | ---- | M] () -- C:\aReaker_space.exe
[2005.11.28 01:57:06 | 000,771,414 | ---- | M] () -- C:\areaker_space_install.exe
[2005.09.14 13:08:23 | 002,459,378 | ---- | M] ( ) -- C:\audacity-win-1.2.3.exe
[2006.04.11 22:05:22 | 006,346,648 | ---- | M] () -- C:\audioconverter_wmf_setup.exe
[2007.07.21 00:43:24 | 006,513,440 | ---- | M] () -- C:\dap85.exe
[2004.10.28 22:53:18 | 007,680,064 | ---- | M] () -- C:\DivX521XP2K.exe
[2005.03.04 00:33:03 | 001,934,096 | ---- | M] () -- C:\dMC-r11.exe
[2006.02.13 23:04:56 | 063,826,688 | ---- | M] (Macromedia ) -- C:\Dreamweaver8-de.exe
[2008.03.08 21:55:23 | 024,697,978 | ---- | M] () -- C:\DrumagogDemo.exe
[2009.03.19 19:42:47 | 001,379,841 | ---- | M] (NeSoft ) -- C:\freedvdripper.exe
[2005.08.07 14:22:23 | 010,958,640 | ---- | M] (InstallShield Software Corporation) -- C:\GoogleEarth.exe
[2005.02.04 19:52:09 | 014,619,920 | ---- | M] (Honestech ) -- C:\hteditor50engdemo.exe
[2006.08.14 17:42:04 | 001,355,912 | ---- | M] () -- C:\install_flash_player.exe
[2005.09.28 23:02:50 | 034,039,576 | ---- | M] (Apple Computer, Inc. ) -- C:\iTunesSetup.exe
[2006.04.11 22:00:56 | 009,429,960 | ---- | M] (DeskShare ) -- C:\mediaconverter.exe
[2007.07.26 15:58:04 | 001,556,652 | ---- | M] ( ) -- C:\PDFzuWordPro_Testversion.exe
[2009.01.19 23:29:13 | 027,066,664 | ---- | M] (Microsoft Corporation) -- C:\PowerPointViewer.exe
[2007.05.28 23:44:19 | 013,206,192 | ---- | M] (Webroot Software, Inc. ) -- C:\SpySweeperRegSetup_DE.exe
[2007.05.28 21:39:06 | 013,206,400 | ---- | M] (Webroot Software, Inc. ) -- C:\ssftrialsnrsetup1_1922458785.exe
[2007.10.08 13:08:00 | 028,088,869 | ---- | M] (eRightSoft ) -- C:\SUPERsetup.exe
[2001.05.24 12:59:30 | 000,162,304 | ---- | M] () -- C:\UNWISE.EXE
[2005.02.04 16:25:10 | 001,145,061 | ---- | M] () -- C:\wrar342d.exe
[2004.12.15 21:55:57 | 002,609,152 | ---- | M] () -- C:\wz90gev.exe
[2005.05.01 15:24:38 | 000,635,569 | ---- | M] (XviD Team (Koepi) ) -- C:\XviD-1.0.3-20122004.exe
< MD5 for: AGP440.SYS >
[2005.11.09 11:08:50 | 022,286,026 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:AGP440.sys
[2011.05.01 12:12:19 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp3.cab:AGP440.sys
[2005.11.09 11:08:50 | 022,286,026 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2011.05.01 12:12:19 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys
[2004.08.04 08:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2001.08.17 14:58:00 | 000,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\I386\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2002.08.29 06:00:00 | 010,180,476 | ---- | M] () .cab file -- C:\I386\sp1.cab:atapi.sys
[2002.08.29 06:00:00 | 010,180,476 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp1.cab:atapi.sys
[2005.11.09 11:08:50 | 022,286,026 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp2.cab:atapi.sys
[2011.05.01 12:12:19 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\I386\sp3.cab:atapi.sys
[2005.11.09 11:08:50 | 022,286,026 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2011.05.01 12:12:19 | 023,898,261 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2002.08.29 02:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\SYSTEM32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2002.08.29 02:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\SYSTEM32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys
[2004.08.04 07:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2003.04.23 10:29:54 | 000,087,296 | ---- | M] (Microsoft Corporation) MD5=E52B3B3F78C9AE85806CE49DCDD80C18 -- C:\I386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 04:22:10 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINDOWS\SYSTEM32\eventlog.dll
[2004.08.04 09:57:18 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=B932C077D5A65B71B4512544AC404CB4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2002.08.29 06:00:00 | 000,049,152 | ---- | M] (Microsoft Corporation) MD5=B9358A1FB66CF656328FD8B792B2CCC4 -- C:\I386\EVENTLOG.DLL
< MD5 for: NETLOGON.DLL >
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 04:22:19 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINDOWS\SYSTEM32\netlogon.dll
[2002.08.29 06:00:00 | 000,399,360 | ---- | M] (Microsoft Corporation) MD5=BCA549B21E651111CE7BAD0FC8C45F4B -- C:\I386\NETLOGON.DLL
[2004.08.04 09:57:30 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=D27395EDCD3416AFD125A9370DCB585C -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2009.02.06 20:46:10 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ED4BBAD725A21632FB205452749FC8F5 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009.02.06 20:46:10 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=ED4BBAD725A21632FB205452749FC8F5 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
< MD5 for: SCECLI.DLL >
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:22:23 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINDOWS\SYSTEM32\scecli.dll
[2004.08.04 09:57:33 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=64DC26B3CF7BCCAD431CE360A4C625D5 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2002.08.29 06:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=ADD49C10F5DADFA81912D124FE1C9A99 -- C:\I386\SCECLI.DLL
< MD5 for: USER32.DLL >
[2005.03.02 20:09:46 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=3751D7CF0E0A113D84414992146BCE6A -- C:\WINDOWS\$hf_mig$\KB890859\SP2GDR\user32.dll
[2007.03.08 17:36:30 | 000,579,072 | ---- | M] (Microsoft Corporation) MD5=492E166CFD26A50FB9160DB536FF7D2B -- C:\WINDOWS\$NtServicePackUninstall$\user32.dll
[2005.03.02 20:19:56 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=4C90159A69A5FD3EB39C71411F28FCFF -- C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
[2007.03.08 17:48:39 | 000,579,584 | ---- | M] (Microsoft Corporation) MD5=78785EFF8CB90CEC1862A4CCFD9A3C3A -- C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\ERDNT\cache\user32.dll
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\ServicePackFiles\i386\user32.dll
[2008.04.14 04:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\SYSTEM32\user32.dll
[2002.11.22 21:28:16 | 000,530,432 | ---- | M] (Microsoft Corporation) MD5=DB15B2FE24ECCE331EA3A954F6F90448 -- C:\I386\user32.dll
< MD5 for: USERINIT.EXE >
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 04:23:03 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINDOWS\SYSTEM32\userinit.exe
[2002.08.29 06:00:00 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=BEBD3F08461F9A88E5ABCE0CB9707000 -- C:\I386\USERINIT.EXE
[2004.08.04 09:58:16 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=D1E53DC57143F2584B1DD53B036C0633 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004.08.04 09:58:19 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2002.08.29 06:00:00 | 000,521,728 | ---- | M] (Microsoft Corporation) MD5=616896B708286DA98D6A099293F181D7 -- C:\I386\WINLOGON.EXE
[2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 04:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\SYSTEM32\winlogon.exe
< MD5 for: WS2IFSL.SYS >
[2002.08.29 06:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\I386\WS2IFSL.SYS
[2002.08.29 06:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2002.09.11 14:35:14 | 000,094,208 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2002.09.11 14:35:14 | 000,606,208 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2002.09.11 14:35:14 | 000,385,024 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 167 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:DFC5A2B2
@Alternate Data Stream - 125 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:0F8F5844
@Alternate Data Stream - 1172 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft:hQrGbuE20pECXGFLH
@Alternate Data Stream - 117 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:ECF5194F
@Alternate Data Stream - 1148 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft:1LfUZYmD0DtF6CKNBBMXiE1pH
@Alternate Data Stream - 1122 bytes -> C:\Programme\Gemeinsame Dateien\System:nEsSv52fXceOZa12hEIXy
@Alternate Data Stream - 112 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:5BB923A2
@Alternate Data Stream - 109 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:A8ADE5D8
< End of report > --- --- --- |