Code:
OTL logfile created on: 23.05.2010 00:22:49 - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Users\Win\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 59,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 77,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 29,29 Gb Total Space | 9,56 Gb Free Space | 32,62% Space Free | Partition Type: NTFS
Drive D: | 566,87 Gb Total Space | 483,36 Gb Free Space | 85,27% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 232,88 Gb Total Space | 30,31 Gb Free Space | 13,01% Space Free | Partition Type: NTFS
Computer Name: WIN-PC
Current User Name: Win
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Files/Folders - Created Within 30 Days ==========
[2010.05.23 00:21:23 | 000,571,904 | ---- | C] (OldTimer Tools) -- C:\Users\Win\Desktop\OTL.exe
[2010.05.23 00:16:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\trend micro
[2010.05.23 00:16:55 | 000,000,000 | ---D | C] -- C:\rsit
[2010.05.19 12:13:28 | 000,000,000 | ---D | C] -- C:\Users\Win\AppData\Roaming\LolClient
[2010.05.14 23:59:51 | 000,000,000 | ---D | C] -- C:\Users\Win\AppData\Roaming\Avira
[2010.05.14 23:47:43 | 000,116,568 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2010.05.14 23:47:43 | 000,081,072 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2010.05.14 23:47:43 | 000,051,992 | ---- | C] (AVIRA GmbH) -- C:\Windows\SysWow64\drivers\avgntdd.sys
[2010.05.14 23:47:43 | 000,017,016 | ---- | C] (AVIRA GmbH) -- C:\Windows\SysWow64\drivers\avgntmgr.sys
[2010.05.14 23:47:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2010.05.14 23:47:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2010.05.14 21:31:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2010.05.09 04:34:48 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2010.05.09 04:28:35 | 000,000,000 | ---D | C] -- C:\Users\Win\AppData\Local\Fallout3
[2010.05.09 04:16:07 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\xlive
[2010.05.09 04:13:56 | 000,178,800 | ---- | C] (Sony DADC Austria AG.) -- C:\Windows\SysWow64\CmdLineExt_x64.dll
[2010.05.08 12:50:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ask.com
[2010.05.08 12:49:24 | 000,000,000 | ---D | C] -- C:\Users\Win\AppData\Roaming\uTorrent
[2010.05.08 01:52:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2010.05.07 20:42:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Ubisoft
[2010.05.07 20:24:53 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2010.05.05 21:13:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Vg
[2010.05.05 14:48:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\vghd
[2010.05.04 21:21:40 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2010.05.04 20:59:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mplayer
[2010.05.04 20:59:21 | 000,305,152 | ---- | C] (InstallShield Software Corporation) -- C:\Windows\IsUninst.exe
[2010.05.04 20:26:06 | 000,000,000 | ---D | C] -- C:\Users\Win\AppData\Roaming\Winamp
[2010.05.03 20:30:37 | 000,086,016 | ---- | C] (MindVision Software) -- C:\Windows\unvise32.exe
[2010.05.02 11:54:02 | 000,000,000 | ---D | C] -- C:\Users\Win\Documents\My Games
[2010.05.01 21:44:21 | 000,000,000 | ---D | C] -- C:\Users\Win\Documents\Prototype
[2010.05.01 20:05:14 | 000,000,000 | ---D | C] -- C:\Users\Win\AppData\Local\Ascaron Entertainment
[2010.05.01 20:04:24 | 000,000,000 | RH-D | C] -- C:\Users\Win\AppData\Roaming\SecuROM
[2010.04.28 22:21:30 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browserchoice.exe
[2010.04.28 16:14:18 | 000,223,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fvevol.sys
[2010.04.28 16:14:16 | 001,446,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2010.04.28 16:14:16 | 000,153,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ksecpkg.sys
[2010.04.26 21:31:24 | 010,916,608 | ---- | C] (Sonix Co. Ltd.) -- C:\Windows\SysNative\drivers\snpstd3.sys
[2010.04.26 21:31:24 | 010,526,464 | ---- | C] (Sonix Co. Ltd.) -- C:\Windows\SysWow64\drivers\snpstd3.sys
[2010.04.26 21:31:24 | 000,980,992 | ---- | C] ( ) -- C:\Windows\SysNative\vsnpstd3.dll
[2010.04.26 21:31:24 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\amcap.exe
[2010.04.26 21:31:23 | 000,163,840 | ---- | C] ( ) -- C:\Windows\SysWow64\rsnpstd3.dll
[2010.04.26 21:31:23 | 000,061,440 | ---- | C] ( ) -- C:\Windows\SysWow64\vsnpstd3.dll
[2010.04.26 21:31:23 | 000,053,248 | ---- | C] ( ) -- C:\Windows\csnpstd3.dll
[2010.04.26 21:31:23 | 000,018,944 | ---- | C] ( ) -- C:\Windows\SysNative\csnpstd3.dll
[2010.04.26 21:31:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\snpstd3
[2010.04.26 21:31:09 | 000,000,000 | ---D | C] -- C:\Users\Win\AppData\Roaming\InstallShield
[2010.04.25 20:14:39 | 000,000,000 | ---D | C] -- C:\Program Files\DivX
[2010.04.25 20:07:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DivX
[2010.04.25 20:07:19 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.05.23 00:33:06 | 001,572,864 | -HS- | M] () -- C:\Users\Win\ntuser.dat
[2010.05.23 00:21:27 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Users\Win\Desktop\OTL.exe
[2010.05.20 23:22:01 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.05.20 23:21:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.05.20 23:21:15 | 2415,370,240 | -HS- | M] () -- C:\hiberfil.sys
[2010.05.20 23:17:25 | 001,737,031 | -H-- | M] () -- C:\Users\Win\AppData\Local\IconCache.db
[2010.05.20 21:46:47 | 000,000,211 | ---- | M] () -- C:\Users\Win\Desktop\Portal.url
[2010.05.20 19:11:17 | 000,001,091 | ---- | M] () -- C:\Users\Win\Desktop\League of Legends.lnk
[2010.05.20 14:58:07 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010.05.20 14:58:07 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010.05.14 23:55:20 | 000,524,288 | -HS- | M] () -- C:\Users\Win\ntuser.dat{fd38baff-5f9a-11df-8571-001e8cce0630}.TMContainer00000000000000000002.regtrans-ms
[2010.05.14 23:55:20 | 000,524,288 | -HS- | M] () -- C:\Users\Win\ntuser.dat{fd38baff-5f9a-11df-8571-001e8cce0630}.TMContainer00000000000000000001.regtrans-ms
[2010.05.14 23:55:20 | 000,065,536 | -HS- | M] () -- C:\Users\Win\ntuser.dat{fd38baff-5f9a-11df-8571-001e8cce0630}.TM.blf
[2010.05.14 23:48:32 | 000,002,070 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2010.05.14 21:41:55 | 000,007,607 | ---- | M] () -- C:\Users\Win\AppData\Local\Resmon.ResmonCfg
[2010.05.09 04:13:56 | 000,178,800 | ---- | M] (Sony DADC Austria AG.) -- C:\Windows\SysWow64\CmdLineExt_x64.dll
[2010.05.08 01:59:22 | 000,000,701 | ---- | M] () -- C:\Users\Public\Desktop\Dark Messiah of Might and Magic im Mehrspielermodus spielen.lnk
[2010.05.08 01:17:03 | 000,000,887 | ---- | M] () -- C:\Users\Public\Desktop\Dark Messiah of Might and Magic spielen.lnk
[2010.05.07 21:12:30 | 000,524,288 | -HS- | M] () -- C:\Users\Win\ntuser.dat{f7f8d103-5a04-11df-8615-001e8cce0630}.TMContainer00000000000000000002.regtrans-ms
[2010.05.07 21:12:30 | 000,524,288 | -HS- | M] () -- C:\Users\Win\ntuser.dat{f7f8d103-5a04-11df-8615-001e8cce0630}.TMContainer00000000000000000001.regtrans-ms
[2010.05.07 21:12:30 | 000,065,536 | -HS- | M] () -- C:\Users\Win\ntuser.dat{f7f8d103-5a04-11df-8615-001e8cce0630}.TM.blf
[2010.05.07 20:53:28 | 000,000,603 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2010.05.07 20:42:10 | 000,107,832 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010.05.07 20:42:05 | 002,337,865 | ---- | M] () -- C:\Windows\SysWow64\pbsvc.exe
[2010.05.07 20:42:05 | 000,066,872 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010.05.07 20:25:06 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010.05.07 20:25:06 | 000,643,628 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2010.05.07 20:25:06 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010.05.07 20:25:06 | 000,126,188 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2010.05.07 20:25:06 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010.05.07 20:22:13 | 000,000,005 | ---- | M] () -- C:\Windows\treeskp.sys
[2010.05.07 20:22:13 | 000,000,005 | ---- | M] () -- C:\Windows\sbacknt.bin
[2010.05.05 21:10:48 | 000,000,000 | ---- | M] () -- C:\Users\Win\AppData\Roaming\chrtmp
[2010.05.05 14:48:58 | 000,152,904 | ---- | M] () -- C:\Windows\SysWow64\vghd.scr
[2010.05.04 20:59:55 | 000,000,424 | ---- | M] () -- C:\Windows\QIII.INI
[2010.05.04 20:26:11 | 000,000,657 | ---- | M] () -- C:\Users\Public\Desktop\Winamp.lnk
[2010.04.26 21:31:24 | 000,000,461 | ---- | M] () -- C:\Windows\win.ini
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.05.23 00:28:50 | 000,002,097 | ---- | C] () -- C:\Users\Win\Desktop\hjtscanlist.zip
[2010.05.20 21:46:47 | 000,000,211 | ---- | C] () -- C:\Users\Win\Desktop\Portal.url
[2010.05.20 19:11:17 | 000,001,091 | ---- | C] () -- C:\Users\Win\Desktop\League of Legends.lnk
[2010.05.14 23:48:32 | 000,002,070 | ---- | C] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2010.05.14 23:35:25 | 000,524,288 | -HS- | C] () -- C:\Users\Win\ntuser.dat{fd38baff-5f9a-11df-8571-001e8cce0630}.TMContainer00000000000000000002.regtrans-ms
[2010.05.14 23:35:25 | 000,524,288 | -HS- | C] () -- C:\Users\Win\ntuser.dat{fd38baff-5f9a-11df-8571-001e8cce0630}.TMContainer00000000000000000001.regtrans-ms
[2010.05.14 23:35:24 | 000,065,536 | -HS- | C] () -- C:\Users\Win\ntuser.dat{fd38baff-5f9a-11df-8571-001e8cce0630}.TM.blf
[2010.05.14 21:41:55 | 000,007,607 | ---- | C] () -- C:\Users\Win\AppData\Local\Resmon.ResmonCfg
[2010.05.08 01:59:22 | 000,000,701 | ---- | C] () -- C:\Users\Public\Desktop\Dark Messiah of Might and Magic im Mehrspielermodus spielen.lnk
[2010.05.08 01:17:03 | 000,000,887 | ---- | C] () -- C:\Users\Public\Desktop\Dark Messiah of Might and Magic spielen.lnk
[2010.05.07 20:42:05 | 002,337,865 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2010.05.07 20:42:05 | 000,107,832 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010.05.07 20:42:05 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010.05.07 20:20:05 | 000,524,288 | -HS- | C] () -- C:\Users\Win\ntuser.dat{f7f8d103-5a04-11df-8615-001e8cce0630}.TMContainer00000000000000000002.regtrans-ms
[2010.05.07 20:20:03 | 000,524,288 | -HS- | C] () -- C:\Users\Win\ntuser.dat{f7f8d103-5a04-11df-8615-001e8cce0630}.TMContainer00000000000000000001.regtrans-ms
[2010.05.07 20:20:03 | 000,065,536 | -HS- | C] () -- C:\Users\Win\ntuser.dat{f7f8d103-5a04-11df-8615-001e8cce0630}.TM.blf
[2010.05.05 21:10:48 | 000,000,000 | ---- | C] () -- C:\Users\Win\AppData\Roaming\chrtmp
[2010.05.05 14:49:00 | 000,000,005 | ---- | C] () -- C:\Windows\treeskp.sys
[2010.05.05 14:49:00 | 000,000,005 | ---- | C] () -- C:\Windows\sbacknt.bin
[2010.05.05 14:48:58 | 000,152,904 | ---- | C] () -- C:\Windows\SysWow64\vghd.scr
[2010.05.04 20:59:55 | 000,000,424 | ---- | C] () -- C:\Windows\QIII.INI
[2010.05.04 20:26:11 | 000,000,657 | ---- | C] () -- C:\Users\Public\Desktop\Winamp.lnk
[2010.05.02 18:41:44 | 000,113,216 | ---- | C] () -- C:\Users\Win\AppData\Roaming\KB8888239.log
[2010.04.26 21:31:24 | 000,835,584 | ---- | C] () -- C:\Windows\vsnpstd3.exe
[2010.04.26 21:31:24 | 000,356,352 | ---- | C] () -- C:\Windows\tsnpstd3.exe
[2010.04.26 21:31:24 | 000,020,480 | ---- | C] () -- C:\Windows\FixCamera.exe
[2010.04.26 21:31:24 | 000,015,498 | ---- | C] () -- C:\Windows\snpstd3.ini
[2010.04.26 21:31:24 | 000,013,023 | ---- | C] () -- C:\Windows\snpstd3.src
[2010.03.06 16:28:03 | 000,005,632 | ---- | C] () -- C:\Windows\SysWow64\drivers\StarOpen.sys
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2007.11.26 21:56:28 | 000,151,415 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
========== LOP Check ==========
[2010.02.18 13:41:27 | 000,000,000 | ---D | M] -- C:\Users\Win\AppData\Roaming\Acreon
[2010.02.22 17:13:05 | 000,000,000 | ---D | M] -- C:\Users\Win\AppData\Roaming\DAEMON Tools Lite
[2010.05.19 18:11:08 | 000,000,000 | ---D | M] -- C:\Users\Win\AppData\Roaming\ICQ
[2010.05.19 12:13:28 | 000,000,000 | ---D | M] -- C:\Users\Win\AppData\Roaming\LolClient
[2010.02.25 00:22:33 | 000,000,000 | ---D | M] -- C:\Users\Win\AppData\Roaming\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
[2010.02.17 13:00:01 | 000,000,000 | ---D | M] -- C:\Users\Win\AppData\Roaming\Opera
[2010.03.07 15:28:29 | 000,000,000 | ---D | M] -- C:\Users\Win\AppData\Roaming\PC Suite
[2010.04.09 17:06:24 | 000,000,000 | ---D | M] -- C:\Users\Win\AppData\Roaming\Samsung
[2010.05.09 04:22:34 | 000,000,000 | ---D | M] -- C:\Users\Win\AppData\Roaming\uTorrent
[2009.07.14 07:08:49 | 000,031,878 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >
Extras.txt:
Code:
OTL Extras logfile created on: 23.05.2010 00:22:49 - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Users\Win\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 59,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 77,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 29,29 Gb Total Space | 9,56 Gb Free Space | 32,62% Space Free | Partition Type: NTFS
Drive D: | 566,87 Gb Total Space | 483,36 Gb Free Space | 85,27% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 232,88 Gb Total Space | 30,31 Gb Free Space | 13,01% Space Free | Partition Type: NTFS
Computer Name: WIN-PC
Current User Name: Win
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "D:\Anwendungen\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Anwendungen\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Anwendungen\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "D:\Anwendungen\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Anwendungen\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Anwendungen\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{55C09FC1-D2D8-495A-BD80-D6725F0DCA58}" = Logitech GamePanel Software 3.04.137
"{9EFC40E3-5F31-4F75-8445-286273F74D8E}" = Apple Mobile Device Support
"{B812FCC0-6192-4BFA-A9C6-1E8578F255DA}" = iTunes
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2296}_is1" = SiSoftware Sandra Lite 2010c
"{D8CE69B0-9274-4b8c-BA49-0FF6A20A3C65}" = SAMSUNG SYMBIAN USB Download Driver
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG USB Mobile Device" = SAMSUNG USB Mobile Device Software
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{155F4A0E-76ED-45A2-91FB-FF2A2133C31A}" = Risen
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1A0D2EFC-C4FC-446A-8BC3-57A54CE5EADD}" = Opera 10.53
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 18
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5A96225D-A3B7-4535-AE49-3BF217999669}" = RPG Maker Fonts
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{929CE49F-1CA7-4CF3-A9A1-6D757443C63F}" = Microsoft Games for Windows - LIVE Redistributable
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A8E2EF8F-73EF-4DD8-BB38-31FCCAF50103}" = Dark Messiah
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{CB6075D9-F912-40AE-BEA6-E590DA24F16B}" = Adobe Photoshop Elements 7.0
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{E10DB5DA-E576-40EA-A7FC-1CB2A7B283A6}" = NVIDIA PhysX
"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = USB PC Camera-168
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{FD416706-875C-4B0B-A23A-9E740DAE029E}" = Tom Clancy's Rainbow Six Vegas 2
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 7" = Adobe Photoshop Elements 7.0
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"DivX Setup.divx.com" = DivX-Setup
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.2
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.3
"HD Tune_is1" = HD Tune 2.55
"ICQToolbar" = ICQ Toolbar
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"Knights of The Temple II" = Knights of The Temple II
"League of Legends_is1" = League of Legends
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"PunkBusterSvc" = PunkBuster Services
"Quake 3 Arena Demo" = Quake 3 Arena Demo
"Quake III Arena" = Quake III Arena
"Steam App 400" = Portal
"Uninstall_is1" = Uninstall 1.0.0.1
"uTorrent" = µTorrent
"Vampires Dawn 2" = Vampires Dawn 2
"vghd" = VirtuaGirl
"WheelMouse" = A4Tech iWheelWorks V7.37
"Winamp" = Winamp
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 14.05.2010 15:37:26 | Computer Name = Win-PC | Source = Application Hang | ID = 1002
Description = Programm opera.exe, Version 10.53.3374.0 kann nicht mehr unter Windows
ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: fe0 Startzeit:
01caf39aab98a408 Endzeit: 12 Anwendungspfad: D:\Anwendungen\Opera\opera.exe Berichts-ID:
17b7f791-5f90-11df-a4a9-001e8cce0630
Error - 14.05.2010 16:07:46 | Computer Name = Win-PC | Source = Application Hang | ID = 1002
Description = Programm avp.exe, Version 8.0.0.506 kann nicht mehr unter Windows
ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: ca0 Startzeit:
01caf39f1f75e878 Endzeit: 20 Anwendungspfad: D:\Anwendungen\Kaspersky\avp.exe Berichts-ID:
50044989-5f94-11df-a4a9-001e8cce0630
Error - 14.05.2010 16:08:42 | Computer Name = Win-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: avp.exe, Version: 8.0.0.506, Zeitstempel:
0x49f966a4 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel:
0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x004b37ec ID des fehlerhaften Prozesses:
0x89c Startzeit der fehlerhaften Anwendung: 0x01caf39fdb4792b8 Pfad der fehlerhaften
Anwendung: D:\Anwendungen\Kaspersky\avp.exe Pfad des fehlerhaften Moduls: unknown
Berichtskennung:
7d875d50-5f94-11df-a4a9-001e8cce0630
Error - 14.05.2010 16:59:46 | Computer Name = Win-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: avp.exe, Version: 8.0.0.506, Zeitstempel:
0x49f966a4 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel:
0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x02385f24 ID des fehlerhaften Prozesses:
0x750 Startzeit der fehlerhaften Anwendung: 0x01caf3a83bc5f1e0 Pfad der fehlerhaften
Anwendung: D:\Anwendungen\Kaspersky\avp.exe Pfad des fehlerhaften Moduls: unknown
Berichtskennung:
9fe2f100-5f9b-11df-8571-001e8cce0630
Error - 14.05.2010 17:04:15 | Computer Name = Win-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: avp.exe, Version: 8.0.0.506, Zeitstempel:
0x49f966a4 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel:
0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x02355f24 ID des fehlerhaften Prozesses:
0x6f4 Startzeit der fehlerhaften Anwendung: 0x01caf3a882c41400 Pfad der fehlerhaften
Anwendung: D:\Anwendungen\Kaspersky\avp.exe Pfad des fehlerhaften Moduls: unknown
Berichtskennung:
4096f0d8-5f9c-11df-8571-001e8cce0630
Error - 14.05.2010 17:44:48 | Computer Name = Win-PC | Source = MsiInstaller | ID = 10005
Description =
Error - 14.05.2010 17:45:27 | Computer Name = Win-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Users\Win\AppData\Local\Temp\RarSFX1\redist.dll".
Die
abhängige Assemblierung "Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.30729.4148""
konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm
"sxstrace.exe".
Error - 14.05.2010 18:10:42 | Computer Name = Win-PC | Source = Application Hang | ID = 1002
Description = Programm iw4mp.exe, Version 0.0.0.0 kann nicht mehr unter Windows
ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 7f4 Startzeit:
01caf3b188d3e6f0 Endzeit: 42 Anwendungspfad: d:\anwendungen\steam\steamapps\common\call
of duty modern warfare 2\iw4mp.exe Berichts-ID:
Error - 14.05.2010 19:27:50 | Computer Name = Win-PC | Source = Application Hang | ID = 1002
Description = Programm iw4sp.exe, Version 0.0.0.0 kann nicht mehr unter Windows
ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: c44 Startzeit:
01caf3bc5a16df10 Endzeit: 225 Anwendungspfad: d:\anwendungen\steam\steamapps\common\call
of duty modern warfare 2\iw4sp.exe Berichts-ID:
Error - 14.05.2010 23:41:53 | Computer Name = Win-PC | Source = SideBySide | ID = 16842815
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\Program Files
(x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Fehler in Manifest- oder
Richtliniendatei "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe
AIR.dll" in Zeile 3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
des "version"-Attributs im assemblyIdentity-Element ist ungültig.
[ System Events ]
Error - 19.05.2010 01:54:22 | Computer Name = Win-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
NVIDIA Stereoscopic 3D Driver Service erreicht.
Error - 19.05.2010 01:54:22 | Computer Name = Win-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "NVIDIA Stereoscopic 3D Driver Service" wurde aufgrund
folgenden Fehlers nicht gestartet: %%1053
Error - 19.05.2010 01:54:30 | Computer Name = Win-PC | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
StarOpen
Error - 19.05.2010 01:55:34 | Computer Name = Win-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
Windows Search erreicht.
Error - 19.05.2010 01:55:34 | Computer Name = Win-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht
gestartet: %%1053
Error - 19.05.2010 01:55:38 | Computer Name = Win-PC | Source = DCOM | ID = 10005
Description =
Error - 19.05.2010 01:56:51 | Computer Name = Win-PC | Source = DCOM | ID = 10005
Description =
Error - 19.05.2010 01:56:51 | Computer Name = Win-PC | Source = Service Control Manager | ID = 7009
Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst
SSDP-Suche erreicht.
Error - 19.05.2010 01:56:51 | Computer Name = Win-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "SSDP-Suche" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error - 19.05.2010 01:56:51 | Computer Name = Win-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "UPnP-Gerätehost" ist vom Dienst "SSDP-Suche" abhängig,
der aufgrund folgenden Fehlers nicht gestartet wurde: %%1053
< End of report >
HJTscanlist: