Logfile of random's system information tool 1.04 (written by random/random)
Run by Hannah at 2008-10-14 22:20:22
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 14 GB (19%) free of 76 GB
Total RAM: 1021 MB (26% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:20:48, on 14.10.2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Hannah\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Hannah.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.de/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: peltodgx - {59B4236E-2A39-4942-8278-980630D6D26F} - C:\Windows\peltodgx.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WISO Urteilsmonitor.lnk = C:\Program Files\WISO\Sparbuch 2008\urteilsmonitor.exe
O8 - Extra context menu item: Nach Microsoft &Excel exportieren -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} -
http://www.webtip.ch/cgi-bin/toshiba/tr ... w.ebay.de/ (file missing)
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) -
http://upload.facebook.com/controls/Fac ... oader5.cabO16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) -
https://wm3137.agencynet.de/iNotes6W.cabO16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://www3.snapfish.de/SnapfishActivia.cabO16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) -
http://picasaweb.google.de/s/v/30.66/uploader2.cabO16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) -
http://upload.facebook.com/controls/Fac ... oader3.cabO16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDow ... eqlab2.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cabO16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) -
http://as.photoprintit.de/ips-opdata/op ... loader.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: ProcShMsg - {029723B9-D921-287C-091F-047D482A7390} - C:\Program Files\subpcw\ProcShMsg.dll (file missing)
O23 - Service: Avira AntiVir Personal - Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatisches LiveUpdate - Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Kennwortprüfung (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 11338 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Norton Internet Security - Vollständige Systemprüfung ausführen - Hannah.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}]
C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll [2006-10-23 96984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2007-05-10 722472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0\bin\ssv.dll [2007-03-13 501384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{90222687-F593-4738-B738-FBEE9C7B26DF} - Show Norton Toolbar - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll [2006-10-23 565960]
{59B4236E-2A39-4942-8278-980630D6D26F} - peltodgx - C:\Windows\peltodgx.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-01-18 4349952]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2006-12-20 411768]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2006-12-07 55416]
"SmoothView"=C:\Program Files\Toshiba\SmoothView\SmoothView.exe [2007-01-29 509496]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2007-01-17 534648]
"KeNotify"=C:\Program Files\TOSHIBA\Utilities\KeNotify.exe [2006-11-06 34352]
"HWSetup"=C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [2006-11-01 413696]
"SVPWUTIL"=C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe [2006-11-01 438272]
"NDSTray.exe"=NDSTray.exe []
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2007-01-09 115816]
"osCheck"=C:\Program Files\Norton Internet Security\osCheck.exe [2006-10-27 22696]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-02-02 835584]
"Toshiba Registration"=C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe [2007-02-19 571024]
"Camera Assistant Software"=C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe [2007-02-13 405504]
"Symantec PIF AlertEng"=C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2008-01-29 583048]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe []
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-07-22 116040]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-05-27 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-07-30 289064]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2007-12-22 86016]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-12-22 8470528]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-12-22 81920]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"=C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [2006-11-13 413696]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2007-05-10 23395880]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe [2008-02-26 443968]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe ASO-616B5711-6DAE-4795-A05F-39A1E5104020 []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
WISO Urteilsmonitor.lnk - C:\Program Files\WISO\Sparbuch 2008\urteilsmonitor.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
ProcShMsg - {029723B9-D921-287C-091F-047D482A7390} - C:\Program Files\subpcw\ProcShMsg.dll []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispScrSavPage"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2008-10-14 22:20:22 ----D---- C:\rsit
2008-10-14 15:29:42 ----D---- C:\Users\Hannah\AppData\Roaming\Malwarebytes
2008-10-14 15:29:33 ----D---- C:\ProgramData\Malwarebytes
2008-10-14 15:29:32 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-13 09:15:12 ----D---- C:\Program Files\Hiro-Media
2008-10-13 09:15:11 ----D---- C:\ProgramData\Hiro-Media
2008-10-12 18:40:54 ----D---- C:\Program Files\Trend Micro
2008-09-29 13:05:31 ----D---- C:\ProgramData\Avira
2008-09-29 13:05:31 ----D---- C:\Program Files\Avira
2008-09-29 11:29:05 ----D---- C:\ProgramData\WindowsSearch
2008-09-29 10:52:34 ----D---- C:\Program Files\subpcw
2008-09-29 10:52:31 ----D---- C:\ProgramData\cjwdgjeb
2008-09-24 18:46:28 ----D---- C:\ProgramData\Adobe
2008-09-24 18:45:37 ----D---- C:\Program Files\Common Files\Adobe
2008-09-23 09:05:59 ----A---- C:\Windows\system32\wups2.dll
2008-09-23 09:05:59 ----A---- C:\Windows\system32\wucltux.dll
2008-09-23 09:05:59 ----A---- C:\Windows\system32\wuaueng.dll
2008-09-23 09:05:59 ----A---- C:\Windows\system32\wuauclt.exe
2008-09-23 09:05:04 ----A---- C:\Windows\system32\wups.dll
2008-09-23 09:05:04 ----A---- C:\Windows\system32\wudriver.dll
2008-09-23 09:05:04 ----A---- C:\Windows\system32\wuapi.dll
2008-09-23 09:04:30 ----A---- C:\Windows\system32\wuwebv.dll
2008-09-23 09:04:30 ----A---- C:\Windows\system32\wuapp.exe
2008-09-20 03:02:47 ----A---- C:\Windows\system32\msshooks.dll
2008-09-20 03:02:46 ----A---- C:\Windows\system32\msscb.dll
2008-09-20 03:02:42 ----A---- C:\Windows\system32\SearchFilterHost.exe
2008-09-20 03:02:42 ----A---- C:\Windows\system32\propdefs.dll
2008-09-20 03:02:42 ----A---- C:\Windows\system32\msstrc.dll
2008-09-20 03:02:42 ----A---- C:\Windows\system32\mssitlb.dll
2008-09-20 03:02:41 ----A---- C:\Windows\system32\thawbrkr.dll
2008-09-20 03:02:41 ----A---- C:\Windows\system32\srchadmin.dll
2008-09-20 03:02:41 ----A---- C:\Windows\system32\propsys.dll
2008-09-20 03:02:41 ----A---- C:\Windows\system32\mssprxy.dll
2008-09-20 03:02:41 ----A---- C:\Windows\system32\msshsq.dll
2008-09-20 03:02:41 ----A---- C:\Windows\system32\korwbrkr.dll
2008-09-20 03:02:39 ----A---- C:\Windows\system32\xmlfilter.dll
2008-09-20 03:02:39 ----A---- C:\Windows\system32\wsepno.dll
2008-09-20 03:02:39 ----A---- C:\Windows\system32\rtffilt.dll
2008-09-20 03:02:39 ----A---- C:\Windows\system32\offfilt.dll
2008-09-20 03:02:39 ----A---- C:\Windows\system32\nlhtml.dll
2008-09-20 03:02:39 ----A---- C:\Windows\system32\msscntrs.dll
2008-09-20 03:02:39 ----A---- C:\Windows\system32\mimefilt.dll
2008-09-20 03:02:38 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2008-09-20 03:02:38 ----A---- C:\Windows\system32\SearchIndexer.exe
2008-09-20 03:02:38 ----A---- C:\Windows\system32\chtbrkr.dll
2008-09-20 03:02:38 ----A---- C:\Windows\system32\chsbrkr.dll
2008-09-20 03:02:37 ----A---- C:\Windows\system32\tquery.dll
2008-09-20 03:02:37 ----A---- C:\Windows\system32\mssvp.dll
2008-09-20 03:02:37 ----A---- C:\Windows\system32\mssrch.dll
2008-09-20 03:02:37 ----A---- C:\Windows\system32\mssphtb.dll
2008-09-20 03:02:37 ----A---- C:\Windows\system32\mssph.dll
2008-09-19 16:17:23 ----A---- C:\Windows\system32\emdmgmt.dll
2008-09-19 16:17:23 ----A---- C:\Windows\system32\dataclen.dll
2008-09-19 16:17:23 ----A---- C:\Windows\system32\cdd.dll
2008-09-19 16:17:20 ----A---- C:\Windows\system32\rpcrt4.dll
2008-09-19 16:17:19 ----A---- C:\Windows\system32\ntoskrnl.exe
2008-09-19 16:17:19 ----A---- C:\Windows\system32\ntkrnlpa.exe
2008-09-19 16:17:18 ----A---- C:\Windows\system32\pacerprf.dll
2008-09-19 16:17:16 ----A---- C:\Windows\system32\wshext.dll
2008-09-19 16:17:16 ----A---- C:\Windows\system32\vbscript.dll
2008-09-19 16:17:16 ----A---- C:\Windows\system32\jscript.dll
2008-09-19 16:17:15 ----A---- C:\Windows\system32\wscript.exe
2008-09-19 16:17:15 ----A---- C:\Windows\system32\scrrun.dll
2008-09-19 16:17:15 ----A---- C:\Windows\system32\scrobj.dll
2008-09-19 16:17:15 ----A---- C:\Windows\system32\cscript.exe
2008-09-15 14:26:03 ----D---- C:\PerfLogs
======List of files/folders modified in the last 1 months======
2008-10-14 22:20:34 ----D---- C:\Windows\Prefetch
2008-10-14 22:19:52 ----D---- C:\Windows\Temp
2008-10-14 22:13:43 ----D---- C:\Users\Hannah\AppData\Roaming\Skype
2008-10-14 22:07:04 ----D---- C:\Windows
2008-10-14 20:16:48 ----D---- C:\Windows\System32
2008-10-14 15:30:40 ----D---- C:\Windows\system32\drivers
2008-10-14 15:29:33 ----HD---- C:\ProgramData
2008-10-14 15:29:32 ----RD---- C:\Program Files
2008-10-14 15:24:06 ----D---- C:\Users\Hannah\AppData\Roaming\UseNeXT
2008-10-14 12:55:35 ----SD---- C:\Users\Hannah\AppData\Roaming\Microsoft
2008-10-14 12:55:34 ----SHD---- C:\Windows\Installer
2008-10-14 12:52:15 ----SHD---- C:\System Volume Information
2008-10-13 13:49:00 ----D---- C:\Windows\inf
2008-10-13 13:49:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
2008-10-11 08:39:10 ----D---- C:\Windows\system32\catroot2
2008-10-10 23:35:23 ----D---- C:\Users\Hannah\AppData\Roaming\dvdcss
2008-10-02 18:32:08 ----D---- C:\Program Files\Norton Internet Security
2008-09-29 11:03:17 ----D---- C:\Program Files\Common Files\Symantec Shared
2008-09-29 11:03:15 ----D---- C:\Program Files\Symantec
2008-09-27 06:22:48 ----D---- C:\Windows\rescache
2008-09-27 06:06:24 ----D---- C:\ProgramData\NOS
2008-09-27 06:06:23 ----SD---- C:\Windows\Downloaded Program Files
2008-09-27 06:06:23 ----D---- C:\Program Files\NOS
2008-09-27 06:05:14 ----D---- C:\Windows\system32\de-DE
2008-09-24 22:49:16 ----D---- C:\Windows\winsxs
2008-09-24 18:45:37 ----D---- C:\Program Files\Common Files
2008-09-24 18:45:37 ----D---- C:\Program Files\Adobe
2008-09-23 09:06:55 ----D---- C:\Windows\system32\catroot
2008-09-20 08:09:21 ----D---- C:\Program Files\UseNeXT
2008-09-20 03:13:27 ----D---- C:\Windows\PolicyDefinitions
2008-09-15 17:43:35 ----D---- C:\Program Files\eMule.de 0.46c v17
2008-09-15 15:24:16 ----D---- C:\Windows\Logs
2008-09-15 14:49:58 ----D---- C:\Windows\Microsoft.NET
2008-09-15 14:49:53 ----RSD---- C:\Windows\assembly
2008-09-15 14:44:19 ----D---- C:\Windows\system32\WDI
2008-09-15 14:42:39 ----ASH---- C:\Program Files\desktop.ini
2008-09-15 14:42:35 ----SHD---- C:\Boot
2008-09-15 14:30:15 ----D---- C:\Program Files\Windows Sidebar
2008-09-15 14:30:15 ----D---- C:\Program Files\Windows Calendar
2008-09-15 14:30:15 ----D---- C:\Program Files\Movie Maker
2008-09-15 14:30:14 ----D---- C:\Program Files\Windows Mail
2008-09-15 14:30:13 ----D---- C:\Program Files\Windows Media Player
2008-09-15 14:30:13 ----D---- C:\Program Files\Internet Explorer
2008-09-15 14:30:12 ----D---- C:\Program Files\Windows Collaboration
2008-09-15 14:30:11 ----D---- C:\Program Files\Windows Journal
2008-09-15 14:30:10 ----D---- C:\Program Files\Windows Photo Gallery
2008-09-15 14:30:02 ----D---- C:\Program Files\Windows Defender
2008-09-15 14:30:02 ----D---- C:\Program Files\Common Files\System
2008-09-15 14:30:01 ----D---- C:\Windows\servicing
2008-09-15 14:30:00 ----D---- C:\Windows\ehome
2008-09-15 14:29:38 ----D---- C:\Windows\MSAgent
2008-09-15 14:29:36 ----D---- C:\Windows\DigitalLocker
2008-09-15 14:29:35 ----D---- C:\Windows\L2Schemas
2008-09-15 14:29:35 ----D---- C:\Windows\IME
2008-09-15 14:29:32 ----D---- C:\Windows\system32\XPSViewer
2008-09-15 14:29:32 ----D---- C:\Windows\system32\ko-KR
2008-09-15 14:29:32 ----D---- C:\Windows\system32\da-DK
2008-09-15 14:29:32 ----D---- C:\Windows\system32\com
2008-09-15 14:29:31 ----D---- C:\Windows\system32\en-US
2008-09-15 14:28:54 ----D---- C:\Windows\system32\it-IT
2008-09-15 14:28:54 ----D---- C:\Windows\system32\el-GR
2008-09-15 14:28:53 ----D---- C:\Windows\system32\oobe
2008-09-15 14:28:50 ----D---- C:\Windows\system32\sysprep
2008-09-15 14:28:50 ----D---- C:\Windows\system32\migration
2008-09-15 14:28:37 ----D---- C:\Windows\system32\AdvancedInstallers
2008-09-15 14:28:35 ----D---- C:\Windows\system32\sv-SE
2008-09-15 14:28:35 ----D---- C:\Windows\system32\ru-RU
2008-09-15 14:28:35 ----D---- C:\Windows\system32\ias
2008-09-15 14:28:35 ----D---- C:\Windows\system32\fr-FR
2008-09-15 14:28:34 ----D---- C:\Windows\system32\setup
2008-09-15 14:28:34 ----D---- C:\Windows\system32\he-IL
2008-09-15 14:28:33 ----D---- C:\Windows\system32\SLUI
2008-09-15 14:28:33 ----D---- C:\Windows\system32\pt-PT
2008-09-15 14:28:33 ----D---- C:\Windows\system32\hu-HU
2008-09-15 14:28:33 ----D---- C:\Windows\system32\fi-FI
2008-09-15 14:28:33 ----D---- C:\Windows\system32\cs-CZ
2008-09-15 14:28:27 ----D---- C:\Windows\system32\zh-CN
2008-09-15 14:28:27 ----D---- C:\Windows\system32\manifeststore
2008-09-15 14:28:27 ----D---- C:\Windows\system32\es-ES
2008-09-15 14:28:26 ----D---- C:\Windows\system32\zh-TW
2008-09-15 14:28:26 ----D---- C:\Windows\system32\pl-PL
2008-09-15 14:28:26 ----D---- C:\Windows\system32\ja-JP
2008-09-15 14:28:25 ----D---- C:\Windows\system32\ro-RO
2008-09-15 14:28:11 ----D---- C:\Windows\system32\tr-TR
2008-09-15 14:28:10 ----D---- C:\Windows\system32\wbem
2008-09-15 14:28:07 ----D---- C:\Windows\system32\nl-NL
2008-09-15 14:28:07 ----D---- C:\Windows\system32\nb-NO
2008-09-15 14:28:07 ----D---- C:\Windows\system32\ar-SA
2008-09-15 14:28:03 ----D---- C:\Windows\system32\migwiz
2008-09-15 14:28:01 ----D---- C:\Windows\system32\pt-BR
2008-09-15 14:26:33 ----RSD---- C:\Windows\Fonts
2008-09-15 14:26:33 ----D---- C:\Windows\AppPatch
2008-09-15 14:26:09 ----D---- C:\Windows\Boot
2008-09-15 14:26:05 ----D---- C:\Windows\system32\Boot
2008-09-15 14:12:10 ----D---- C:\Windows\system32\RTCOM
2008-09-15 13:44:39 ----A---- C:\Windows\system32\ifxcardm.dll
2008-09-15 13:44:32 ----A---- C:\Windows\system32\axaltocm.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys [2007-02-27 11840]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2008-06-27 75072]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2008-09-17 371248]
R1 IDSvix86;Symantec Intrusion Prevention Driver; \??\C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20081009.001\IDSvix86.sys [2008-09-12 270384]
R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [2007-04-14 418104]
R1 SRTSP;SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [2007-11-30 279088]
R1 SRTSPX;SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [2007-11-30 43696]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2007-11-08 21248]
R1 SYMTDI;SYMTDI; C:\Windows\System32\Drivers\SYMTDI.SYS [2006-10-24 185744]
R3 AgereSoftModem;TOSHIBA V92 Software Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2006-11-28 1161888]
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys [2008-05-20 52032]
R3 CmBatt;Treiber für Microsoft-ACPI-Kontrollmethodenkompatible Batterie; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-19 14208]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-17 99376]
R3 GEARAspiWDM;GEARAspiWDM; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2008-01-29 16168]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-01-18 1729632]
R3 NAVENG;NAVENG; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20081014.002\NAVENG.SYS [2008-09-17 89104]
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20081014.002\NAVEX15.SYS [2008-09-17 873552]
R3 NETw4v32;Intel(R) Wireless WiFi Link Adaptertreiber für Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-09-26 2251776]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-12-22 7604256]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-04 59392]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-19 88576]
R3 SYMDNS;SYMDNS; C:\Windows\System32\Drivers\SYMDNS.SYS [2006-10-24 11792]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2008-09-29 123952]
R3 SYMFW;SYMFW; C:\Windows\System32\Drivers\SYMFW.SYS [2006-10-24 144784]
R3 SYMIDS;SYMIDS; C:\Windows\System32\Drivers\SYMIDS.SYS [2006-10-24 38928]
R3 SYMNDISV;SYMNDISV; C:\Windows\System32\Drivers\SYMNDISV.SYS [2006-10-24 37008]
R3 SYMREDRV;SYMREDRV; C:\Windows\System32\Drivers\SYMREDRV.SYS [2006-10-24 26384]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-02-02 182328]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 16128]
R3 tifm21;tifm21; C:\Windows\system32\drivers\tifm21.sys [2006-07-06 168448]
R3 usbvideo;USB-Videogerät (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2006-11-02 132352]
R3 UVCFTR;UVCFTR; C:\Windows\system32\DRIVERS\UVCFTR_S.SYS [2007-01-26 17712]
S3 athr;Atheros Extensible Drahtlos-LAN-Gerätetreiber; C:\Windows\system32\DRIVERS\athr.sys [2006-11-02 467456]
S3 drmkaud;Microsoft Kernel-DRM-Audioentschlüsselung; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 HdAudAddService;Microsoft 1.1 UAA-Funktionstreiber für High Definition Audio-Dienst; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Proxy für Streaming Clock; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Proxy für Streaming Quality Manager; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-Konvertierung; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adaptertreiber für Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-12-19 1786880]
S3 SRTSPL;SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [2007-11-30 317616]
S3 Tosrfcom;Tosrfcom; C:\Windows\system32\drivers\Tosrfcom.sys []
S3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys [2006-10-23 9216]
S3 TpChoice;Touch Pad Detection Filter driver; C:\Windows\system32\DRIVERS\TpChoice.sys []
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2008-07-22 32000]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-19 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S4 KR10I;KR10I; C:\Windows\system32\drivers\kr10i.sys [2007-01-18 219392]
S4 KR10N;KR10N; C:\Windows\system32\drivers\kr10n.sys [2007-01-18 211072]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Planer; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-06-12 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-09-29 149761]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-07-22 116040]
R2 Automatisches LiveUpdate - Scheduler;Automatisches LiveUpdate - Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2007-01-10 554616]
R2 Bonjour Service;Bonjour-Dienst; C:\Program Files\Bonjour\mDNSResponder.exe [2007-07-24 229376]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2007-01-09 108648]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2007-01-09 108648]
R2 CFSvcs;ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [2006-11-14 40960]
R2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2007-01-09 108648]
R2 LiveUpdate Notice Ex;LiveUpdate Notice Service Ex; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2007-01-09 108648]
R2 SymAppCore;Symantec AppCore Service; C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe [2006-09-20 46736]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2006-05-25 114688]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2006-12-20 428152]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-02 118784]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2006-08-23 49152]
R3 iPod Service;iPod-Dienst; C:\Program Files\iPod\bin\iPodService.exe [2008-07-30 532264]
S2 LiveUpdate Notice Service;LiveUpdate Notice Service; C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2008-01-29 583048]
S3 comHost;COM Host; C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [2006-10-13 49296]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-04 136120]
S3 ISPwdSvc;Symantec IS Kennwortprüfung; C:\Program Files\Norton Internet Security\isPwdSvc.exe [2006-10-27 80552]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2007-01-10 2918008]
S3 Symantec Core LC;Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [2008-05-07 1251720]
-----------------EOF-----------------