Habe nun beide Schritte sorgfältig durch gearbeitet, allerdings hab ich vorher mein Antivirusprogramm geschlossen, hoffe das ist OK. Hat bisschen länger gedauert, da ich mir Zeit gelassen habe um nichts Falsch zu machen. Logfile Schritt 1: Code:
All processes killed
Error: Unable to interpret <:OTL MOD - [2012.11.20 00:26:14 | 000,097,280 | ---- | M] () -- C:\Dokumente und Einstellungen\Leo Nidas\Lokale Einstellungen\Temp\wgsdgsdgdsgsd.exe O4 - Startup: C:\Dokumente und Einstellungen\Leo Nidas\Startmenü\Programme\Autostart\ctfmon.lnk = C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\lsass.exe (Microsoft Corporation) [2012.11.20 00:26:18 | 095,023,320 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\dsgsdgdsgdsgw.pad :commands [Emptytemp]> in the current context!
OTL by OldTimer - Version 3.2.69.0 log created on 11292012_115637
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot... Logfile Schritt 2: Code:
OTL logfile created on: 29.11.2012 12:30:38 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\Leo Nidas\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,75 Gb Total Physical Memory | 2,30 Gb Available Physical Memory | 83,51% Memory free
4,59 Gb Paging File | 4,33 Gb Available in Paging File | 94,34% Paging File free
Paging file location(s): C:\pagefile.sys 2048 4096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 11,72 Gb Total Space | 1,14 Gb Free Space | 9,70% Space Free | Partition Type: NTFS
Drive D: | 286,37 Gb Total Space | 209,62 Gb Free Space | 73,20% Space Free | Partition Type: NTFS
Computer Name: LEONIDAS | User Name: Leo Nidas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.11.29 00:58:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\24960-OTL.exe
PRC - [2012.11.20 00:26:16 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\lsass.exe
PRC - [2012.10.30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe
PRC - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe
PRC - [2010.04.27 18:19:08 | 000,160,424 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\WINDOWS\starter4g.exe
PRC - [2010.04.27 18:18:56 | 000,145,064 | R--- | M] (4G Systems GmbH & Co. KG) -- C:\WINDOWS\service4g.exe
PRC - [2010.04.12 17:03:44 | 000,329,168 | ---- | M] () -- C:\Programme\XSManager\WTGService.exe
PRC - [2009.04.14 10:10:30 | 001,032,192 | ---- | M] (Nokia) -- C:\Programme\Gemeinsame Dateien\Nokia\MPlatform\NokiaMServer.exe
PRC - [2009.03.09 13:44:12 | 000,130,560 | ---- | M] () -- C:\Programme\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2009.03.04 11:25:12 | 000,621,056 | ---- | M] (Nokia.) -- C:\Programme\Nokia\PC Connectivity Solution\ServiceLayer.exe
PRC - [2008.11.26 12:35:00 | 000,119,808 | ---- | M] () -- C:\Programme\Nokia\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2008.04.14 13:00:00 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2012.11.21 09:34:28 | 002,032,640 | ---- | M] () -- C:\Programme\AVAST Software\Avast\defs\12112100\algo.dll
MOD - [2012.11.20 00:26:14 | 000,097,280 | ---- | M] () -- C:\Dokumente und Einstellungen\Leo Nidas\Lokale Einstellungen\Temp\wgsdgsdgdsgsd.exe
MOD - [2010.04.12 17:03:44 | 000,329,168 | ---- | M] () -- C:\Programme\XSManager\WTGService.exe
MOD - [2009.03.09 13:44:12 | 000,130,560 | ---- | M] () -- C:\Programme\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe
MOD - [2008.11.26 12:35:00 | 000,119,808 | ---- | M] () -- C:\Programme\Nokia\PC Connectivity Solution\Transports\NclRSSrv.exe
========== Services (SafeList) ==========
SRV - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012.02.09 13:13:18 | 000,028,992 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2010.04.27 18:18:56 | 000,145,064 | R--- | M] (4G Systems GmbH & Co. KG) [Auto | Running] -- C:\WINDOWS\service4g.exe -- (XS Stick Service)
SRV - [2010.04.12 17:03:44 | 000,329,168 | ---- | M] () [Auto | Running] -- C:\Programme\XSManager\WTGService.exe -- (WTGService)
SRV - [2009.03.04 11:25:12 | 000,621,056 | ---- | M] (Nokia.) [On_Demand | Running] -- C:\Programme\Nokia\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2007.02.05 09:11:18 | 000,075,320 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\SSScsiSV.exe -- (SSScsiSV)
SRV - [2007.02.05 09:11:16 | 000,112,184 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\SsBeSvc.exe -- (SonicStage Back-End Service)
SRV - [2006.12.14 01:21:20 | 000,045,056 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\MSCSPTISRV.exe -- (MSCSPTISRV)
SRV - [2006.12.14 01:02:08 | 000,069,632 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV)
SRV - [2006.12.14 00:46:16 | 000,057,344 | ---- | M] () [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2005.11.14 00:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2000.01.01 01:00:00 | 000,013,312 | ---- | M] (Agere Systems) [Disabled | Stopped] -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012.10.30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012.10.30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012.10.30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012.10.30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2012.10.30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012.10.30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012.10.30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012.08.01 08:26:49 | 000,052,128 | ---- | M] (Siano) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\smsbda.sys -- (smsbda)
DRV - [2012.08.01 08:26:48 | 000,103,424 | ---- | M] (Mobile Connector) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmnsusbser.sys -- (cmnsusbser)
DRV - [2012.05.13 11:50:51 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2012.04.06 06:16:18 | 007,746,048 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2012.01.18 14:55:56 | 000,016,472 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\pwdrvio.sys -- (pwdrvio)
DRV - [2012.01.18 14:55:54 | 000,011,104 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\pwdspio.sys -- (pwdspio)
DRV - [2010.01.06 14:09:40 | 001,596,768 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\athw.sys -- (AR5416)
DRV - [2009.05.13 08:06:48 | 000,014,392 | ---- | M] (ASUS) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor)
DRV - [2008.11.05 00:19:00 | 001,753,984 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\snp2uvc.sys -- (SNP2UVC)
DRV - [2008.08.26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.04.14 13:00:00 | 000,225,664 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2008.04.14 13:00:00 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008.04.14 13:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2008.04.14 13:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2008.04.13 23:16:24 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MPE.sys -- (MPE)
DRV - [2000.01.01 01:00:00 | 006,360,680 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2000.01.01 01:00:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2000.01.01 01:00:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2000.01.01 01:00:00 | 001,203,776 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2000.01.01 01:00:00 | 000,222,672 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2000.01.01 01:00:00 | 000,101,392 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtihdXP3.sys -- (AtiHDAudioService)
DRV - [2000.01.01 01:00:00 | 000,099,856 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2000.01.01 01:00:00 | 000,009,096 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\amdide.sys -- (amdide)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1844237615-573735546-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.google.de/ [binary data]
IE - HKU\S-1-5-21-1844237615-573735546-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-1844237615-573735546-682003330-1003\..\SearchScopes,DefaultScope = {E88E0043-C9D4-4e33-8555-FEE4F5B63060}
IE - HKU\S-1-5-21-1844237615-573735546-682003330-1003\..\SearchScopes\{E88E0043-C9D4-4e33-8555-FEE4F5B63060}: "URL" = hxxp://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb
IE - HKU\S-1-5-21-1844237615-573735546-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}:6.0.32
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programme\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Programme\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mozilla.zeniko.ch/SumatraPDF_Browser_Plugin: C:\Programme\SumatraPDF\npPdfViewer.dll (Simon Bünzli)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Programme\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@mozilla.zeniko.ch/SumatraPDF_Browser_Plugin: C:\Programme\SumatraPDF\npPdfViewer.dll (Simon Bünzli)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.05.13 04:36:58 | 000,000,000 | ---D | M]
[2012.05.13 04:43:25 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\Mozilla\Extensions
[2012.10.28 11:43:52 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\Mozilla\Firefox\Profiles\vi4bc75p.default\extensions
[2012.09.20 20:47:14 | 000,000,000 | ---D | M] (Спутник @Mail.Ru) -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\Mozilla\Firefox\Profiles\vi4bc75p.default\extensions\{37964A3C-4EE8-47b1-8321-34DE2C39BA4D}
[2012.09.16 07:11:25 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\Mozilla\Firefox\Profiles\vi4bc75p.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.07.25 07:16:14 | 000,741,958 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\Mozilla\Firefox\Profiles\vi4bc75p.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012.05.13 04:38:41 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.05.13 04:38:41 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}
[2012.04.21 02:18:00 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2012.04.21 02:54:08 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.04.21 02:54:08 | 000,002,252 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.04.21 02:54:08 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2012.04.21 02:54:08 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.04.21 02:54:08 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.04.21 02:54:08 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - homepage: hxxp://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: hxxp://www.google.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Programme\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Programme\Google\Chrome\Application\23.0.1271.64\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Programme\Google\Chrome\Application\23.0.1271.64\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programme\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programme\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Programme\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Programme\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U32 (Enabled) = C:\Programme\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.320.5 (Enabled) = C:\WINDOWS\system32\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Programme\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: SumatraPDF Browser Plugin (Enabled) = C:\Programme\SumatraPDF\npPdfViewer.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Programme\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Dokumente und Einstellungen\Leo Nidas\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google-Suche = C:\Dokumente und Einstellungen\Leo Nidas\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Google Mail = C:\Dokumente und Einstellungen\Leo Nidas\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2011.10.14 15:53:40 | 000,000,030 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 secure.tune-up.com
O4 - HKLM..\Run: [avast] C:\Programme\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [Nokia FastStart] C:\Programme\Nokia\Nokia Music\NokiaMusic.exe (Nokia)
O4 - HKLM..\Run: [NokiaMServer] C:\Programme\Gemeinsame Dateien\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [starter4g] C:\WINDOWS\starter4g.exe (4G Systems GmbH & Co. KG)
O4 - HKU\S-1-5-21-1844237615-573735546-682003330-1003..\Run: [ccleaner] C:\Programme\CCleaner\CCleaner.exe (Piriform Ltd)
O4 - Startup: C:\Dokumente und Einstellungen\Leo Nidas\Startmenü\Programme\Autostart\ctfmon.lnk = C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\lsass.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1844237615-573735546-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1844237615-573735546-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O7 - HKU\S-1-5-21-1844237615-573735546-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKU\S-1-5-21-1844237615-573735546-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1844237615-573735546-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1336881659109 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4432AF63-0EA9-4EE3-97F3-46C5BE5CF915}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\Leo Nidas\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\Leo Nidas\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2012.05.13 04:25:12 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012.11.29 12:04:45 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\Leo Nidas\Recent
[2012.11.29 11:56:37 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.11.29 00:58:31 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\24960-OTL.exe
[2012.11.28 20:29:18 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2012.11.23 06:23:47 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Leo Nidas\Lokale Einstellungen\Anwendungsdaten\IsolatedStorage
[2012.11.23 06:19:33 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\Nseries
[2012.11.23 06:18:49 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Leo Nidas\Lokale Einstellungen\Anwendungsdaten\Nokia
[2012.11.23 06:18:48 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Suite
[2012.11.23 06:18:47 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\PC Suite
[2012.11.23 06:18:42 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\Nokia
[2012.11.23 06:18:23 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Nokia Software Updater
[2012.11.23 06:17:41 | 000,000,000 | ---D | C] -- C:\Programme\MSXML 6.0
[2012.11.23 06:15:46 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\muvee Technologies
[2012.11.23 06:15:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\Globalization
[2012.11.23 06:14:34 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Nokia
[2012.11.23 06:12:57 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Nokia
[2012.11.23 06:12:40 | 000,018,816 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\pccsmcfd.sys
[2012.11.23 06:11:56 | 000,090,624 | ---- | C] (Nokia) -- C:\WINDOWS\System32\nmwcdcls.dll
[2012.11.23 06:11:55 | 000,000,000 | ---D | C] -- C:\Programme\Nokia
[2012.11.21 12:19:41 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NokiaMusic
[2012.11.20 00:26:16 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\lsass.exe
[2012.11.18 18:32:56 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Magic Workstation
[2012.11.18 18:32:52 | 000,000,000 | ---D | C] -- C:\Programme\Magic Workstation
[2012.10.31 09:43:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
[2012.10.31 09:43:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[16 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.11.29 12:10:04 | 000,000,131 | -H-- | M] () -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\.~lock.Dokument.odt#
[2012.11.29 12:01:13 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.11.29 11:45:22 | 000,002,549 | ---- | M] () -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\Dokument.odt
[2012.11.29 01:49:47 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.11.29 01:38:04 | 000,302,592 | ---- | M] () -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\khku7s76.exe
[2012.11.29 01:37:01 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012.11.29 00:58:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\24960-OTL.exe
[2012.11.29 00:45:56 | 000,000,168 | ---- | M] () -- C:\Dokumente und Einstellungen\Leo Nidas\defogger_reenable
[2012.11.28 23:17:50 | 095,023,320 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\dsgsdgdsgdsgw.pad
[2012.11.28 15:29:17 | 000,011,959 | ---- | M] () -- C:\Dokumente und Einstellungen\Leo Nidas\Eigene Dateien\Putzplan.odt
[2012.11.23 06:18:23 | 000,001,879 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Nokia Software Updater.lnk
[2012.11.23 06:17:20 | 000,457,918 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2012.11.23 06:17:20 | 000,441,724 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.11.23 06:17:20 | 000,084,080 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2012.11.23 06:17:20 | 000,071,366 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012.11.23 06:17:07 | 000,001,880 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Nokia Music.lnk
[2012.11.23 06:16:08 | 000,001,823 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Nokia Photos.lnk
[2012.11.23 06:14:48 | 000,001,824 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Nokia Ovi Suite.lnk
[2012.11.23 06:08:57 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2012.11.20 00:26:23 | 000,001,094 | ---- | M] () -- C:\Dokumente und Einstellungen\Leo Nidas\Startmenü\Programme\Autostart\ctfmon.lnk
[2012.11.18 18:32:57 | 000,000,701 | ---- | M] () -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\Magic Workstation.lnk
[2012.11.18 18:32:57 | 000,000,654 | ---- | M] () -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\MWS Online Play.lnk
[2012.11.08 19:23:01 | 000,001,783 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Google Chrome.lnk
[2012.11.03 09:50:25 | 007,520,317 | ---- | M] () -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\02. Kriebel & die Kumpels ft. Gossenboss mit Zett, KoolErik, Joca & Canabeatz.mp3
[2012.11.03 00:42:15 | 000,003,001 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012.11.03 00:42:15 | 000,000,308 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012.10.31 09:43:18 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2012.10.30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012.10.30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012.10.30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012.10.30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012.10.30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012.10.30 23:51:57 | 000,089,752 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012.10.30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012.10.30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012.10.30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012.10.30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[16 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.11.29 12:10:04 | 000,000,131 | -H-- | C] () -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\.~lock.Dokument.odt#
[2012.11.29 11:45:51 | 000,002,549 | ---- | C] () -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\Dokument.odt
[2012.11.29 01:38:03 | 000,302,592 | ---- | C] () -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\khku7s76.exe
[2012.11.29 00:45:37 | 000,000,168 | ---- | C] () -- C:\Dokumente und Einstellungen\Leo Nidas\defogger_reenable
[2012.11.25 14:08:38 | 000,011,959 | ---- | C] () -- C:\Dokumente und Einstellungen\Leo Nidas\Eigene Dateien\Putzplan.odt
[2012.11.23 06:18:23 | 000,001,879 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Nokia Software Updater.lnk
[2012.11.23 06:17:07 | 000,001,880 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Nokia Music.lnk
[2012.11.23 06:16:08 | 000,001,823 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Nokia Photos.lnk
[2012.11.23 06:14:48 | 000,001,824 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Nokia Ovi Suite.lnk
[2012.11.20 00:26:23 | 000,001,094 | ---- | C] () -- C:\Dokumente und Einstellungen\Leo Nidas\Startmenü\Programme\Autostart\ctfmon.lnk
[2012.11.20 00:26:18 | 095,023,320 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\dsgsdgdsgdsgw.pad
[2012.11.18 18:32:57 | 000,000,701 | ---- | C] () -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\Magic Workstation.lnk
[2012.11.18 18:32:57 | 000,000,654 | ---- | C] () -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\MWS Online Play.lnk
[2012.11.11 10:52:43 | 007,520,317 | ---- | C] () -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\02. Kriebel & die Kumpels ft. Gossenboss mit Zett, KoolErik, Joca & Canabeatz.mp3
[2012.11.09 06:05:03 | 003,566,876 | ---- | C] () -- C:\Dokumente und Einstellungen\Leo Nidas\Desktop\6. Kontonummer.mp3
[2012.10.31 09:43:18 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2012.10.10 16:11:12 | 000,532,480 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2012.08.01 18:47:13 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll
[2012.05.13 14:52:58 | 000,158,232 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2012.05.13 11:13:33 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2012.05.13 11:13:33 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2012.05.13 11:13:32 | 000,601,728 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2012.05.13 08:00:53 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2012.05.13 07:04:19 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativvaxx.dat
[2012.05.13 06:13:46 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc.dll
[2012.05.13 06:13:46 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\drivers\sncduvc.sys
[2012.05.13 06:13:46 | 000,015,497 | ---- | C] () -- C:\WINDOWS\snp2uvc.ini
[2012.05.13 06:13:44 | 001,753,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\snp2uvc.sys
[2012.05.13 06:02:33 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTEQEX0.dat
[2012.05.13 05:56:54 | 000,001,769 | ---- | C] () -- C:\WINDOWS\Language_trs.ini
[2012.05.13 05:16:40 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012.05.13 05:03:54 | 000,922,184 | ---- | C] () -- C:\WINDOWS\System32\pwNative.exe
[2012.05.13 05:03:53 | 000,016,472 | ---- | C] () -- C:\WINDOWS\System32\pwdrvio.sys
[2012.05.13 05:03:53 | 000,011,104 | ---- | C] () -- C:\WINDOWS\System32\pwdspio.sys
[2012.05.13 04:57:48 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012.05.13 04:39:29 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2012.05.13 04:35:41 | 000,080,416 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2012.05.13 04:26:52 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012.05.13 04:23:07 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012.05.13 02:42:45 | 000,457,918 | ---- | C] () -- C:\WINDOWS\System32\perfh007.dat
[2012.05.13 02:42:45 | 000,441,724 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2012.05.13 02:42:45 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2012.05.13 02:42:45 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\perfi007.dat
[2012.05.13 02:42:45 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\perfd007.dat
[2012.05.13 02:42:45 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2012.05.13 02:42:41 | 000,084,080 | ---- | C] () -- C:\WINDOWS\System32\perfc007.dat
[2012.05.13 02:42:41 | 000,071,366 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2012.05.13 02:39:34 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2012.05.13 02:39:29 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2012.05.13 02:38:43 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2012.05.13 02:38:38 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2012.05.13 02:37:47 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2012.05.13 02:37:21 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2012.05.13 02:37:19 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2012.05.13 02:37:01 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2011.05.24 22:44:26 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\OVDecode.dll
========== ZeroAccess Check ==========
[2012.05.13 05:48:50 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 13:00:00 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2008.04.14 13:00:00 | 000,472,064 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 13:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012.05.13 05:24:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AVAST Software
[2012.05.13 10:05:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DAEMON Tools Lite
[2012.05.13 11:45:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Guard.Mail.Ru
[2012.11.21 12:19:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NokiaMusic
[2012.11.28 18:01:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Suite
[2012.05.13 10:00:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TrackMania
[2012.05.13 09:34:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software
[2012.11.26 16:14:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\PC Suite
[2012.11.28 22:53:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\DAEMON Tools Lite
[2012.05.13 12:03:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\DRPSu
[2012.05.13 13:04:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\LibreOffice
[2012.11.23 06:18:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\Nokia
[2012.11.23 06:19:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\Nseries
[2012.11.23 06:18:47 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\PC Suite
[2012.05.13 06:06:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\SumatraPDF
[2012.05.13 09:34:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\TuneUp Software
[2012.08.04 18:46:51 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Leo Nidas\Anwendungsdaten\XSManager
[2012.08.01 08:26:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\XSManager
[2012.05.13 11:40:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\{DCD48218-E972-4d0c-9E5F-43462BC13E3B}
========== Purity Check ==========
< End of report > |