Hier erstmal der Code von OTL oder wie das Programm heißt:
OTL Logfile: Code:
OTL logfile created on: 5/8/2012 7:49:36 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,023.00 Mb Total Physical Memory | 827.00 Mb Available Physical Memory | 81.00% Memory free
906.00 Mb Paging File | 839.00 Mb Available in Paging File | 93.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 58.59 Gb Total Space | 50.92 Gb Free Space | 86.90% Space Free | Partition Type: NTFS
Drive D: | 15.93 Gb Total Space | 12.84 Gb Free Space | 80.65% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet003
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand] -- -- (AppMgmt)
SRV - [2012/05/06 06:47:16 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/04/04 09:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/06/28 09:25:39 | 000,269,480 | ---- | M] (Avira GmbH) [Auto] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011/04/27 06:31:31 | 000,136,360 | ---- | M] (Avira GmbH) [Auto] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2003/07/28 06:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2003/06/19 17:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (i2omgmt)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - [2012/04/04 09:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/06/28 09:25:40 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011/06/28 09:25:40 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010/06/17 09:27:02 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010/06/17 09:26:52 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2007/05/06 21:00:00 | 000,537,600 | ---- | M] (AVM Berlin) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\fpcibase.sys -- (fpcibase)
DRV - [2007/05/06 21:00:00 | 000,053,632 | ---- | M] (AVM GmbH) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\avmcowan.sys -- (AVMCOWAN)
DRV - [2004/08/03 17:32:32 | 000,084,480 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ac97via.sys -- (VIAudio) VIA AC'97 Audiocontroller (WDM)
DRV - [2004/02/18 11:51:08 | 000,610,988 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2003/12/11 11:54:14 | 000,391,424 | ---- | M] (Sensaura Ltd) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS -- (ALCXSENS)
DRV - [2001/08/17 07:13:48 | 000,037,568 | ---- | M] (AVM GmbH) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\avmwan.sys -- (AVMWAN)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Anwender_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012/05/06 06:47:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2012/05/06 06:47:19 | 000,000,000 | ---D | M]
[2010/10/15 14:24:47 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012/05/06 06:47:17 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2012/05/06 06:47:13 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/05/06 06:47:13 | 000,002,252 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2012/05/06 06:47:13 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2012/05/06 06:47:13 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/05/06 06:47:13 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/05/06 06:47:13 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2004/08/04 08:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Programme\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [OpwareSE4] C:\Programme\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Scansoft, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegedit = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Anwender_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKU\Anwender_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O7 - HKU\Anwender_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegedit = 1
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O27 - HKLM IFEO\msconfig.exe: Debugger - P9KDMF.EXE File not found
O27 - HKLM IFEO\regedit.exe: Debugger - P9KDMF.EXE File not found
O27 - HKLM IFEO\taskmgr.exe: Debugger - P9KDMF.EXE File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/10/15 14:06:47 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/05/06 06:47:22 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Maintenance Service
[2012/05/06 06:47:22 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Mozilla
[2012/05/06 06:31:14 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhid.sys
[2012/05/04 15:21:27 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012/05/04 14:50:48 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Anwender\Anwendungsdaten\Malwarebytes
[2012/05/04 14:50:44 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012/05/04 14:50:42 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2012/05/04 14:50:41 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/05/04 14:50:41 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2012/05/04 07:33:24 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Anwender\Anwendungsdaten\Yald
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/05/08 11:45:11 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/05/08 11:34:28 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/05/06 06:47:21 | 000,000,702 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Mozilla Firefox.lnk
[2012/05/04 15:47:45 | 000,005,019 | ---- | M] () -- C:\Dokumente und Einstellungen\Anwender\Desktop\Report_kaspersky
[2012/05/04 14:50:44 | 000,000,756 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/04 14:50:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012/05/04 07:38:12 | 000,544,994 | ---- | M] () -- C:\Dokumente und Einstellungen\LocalService\Eigene Dateien\locked-12140001.jpg.rfqh
[2012/05/04 07:38:12 | 000,029,496 | ---- | M] () -- C:\Dokumente und Einstellungen\LocalService\Eigene Dateien\locked-dunkel-koblenz.sff.bpns
[2012/05/04 07:38:03 | 000,031,709 | ---- | M] () -- C:\Dokumente und Einstellungen\Anwender\Eigene Dateien\locked-VFIdPnKK.htm.part.tppf
[2012/05/04 07:38:03 | 000,000,572 | ---- | M] () -- C:\Dokumente und Einstellungen\Anwender\Eigene Dateien\locked-spider.sav.nkqz
[2012/05/04 07:37:53 | 000,042,569 | ---- | M] () -- C:\Dokumente und Einstellungen\Anwender\Eigene Dateien\locked-.facebook_-751141721-1.jpg.nlky
[2012/05/04 07:34:18 | 006,054,412 | ---- | M] () -- C:\Dokumente und Einstellungen\Anwender\Desktop\locked-Desktop.7z.lftz
[2012/05/04 07:34:12 | 000,000,079 | ---- | M] () -- C:\Dokumente und Einstellungen\Anwender\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\locked-Desktop anzeigen.scf.foyu
[2012/05/03 23:52:20 | 000,481,078 | ---- | M] () -- C:\WINDOWS\System32\winsh325
[2012/05/03 23:41:54 | 000,481,078 | ---- | M] () -- C:\WINDOWS\System32\winsh324
[2012/05/03 23:27:28 | 000,481,078 | ---- | M] () -- C:\WINDOWS\System32\winsh323
[2012/05/03 23:26:12 | 000,481,078 | ---- | M] () -- C:\WINDOWS\System32\winsh322
[2012/05/03 23:23:16 | 000,481,078 | ---- | M] () -- C:\WINDOWS\System32\winsh321
[2012/05/03 23:20:38 | 000,481,078 | ---- | M] () -- C:\WINDOWS\System32\winsh320
[2012/04/12 07:58:54 | 000,002,347 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Adobe Reader X.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/05/06 06:47:21 | 000,000,702 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Mozilla Firefox.lnk
[2012/05/04 15:47:45 | 000,005,019 | ---- | C] () -- C:\Dokumente und Einstellungen\Anwender\Desktop\Report_kaspersky
[2012/05/04 14:50:44 | 000,000,756 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/04 07:33:30 | 000,481,078 | ---- | C] () -- C:\WINDOWS\System32\winsh325
[2012/05/04 07:33:30 | 000,481,078 | ---- | C] () -- C:\WINDOWS\System32\winsh324
[2012/05/04 07:33:30 | 000,481,078 | ---- | C] () -- C:\WINDOWS\System32\winsh323
[2012/05/04 07:33:30 | 000,481,078 | ---- | C] () -- C:\WINDOWS\System32\winsh322
[2012/05/04 07:33:30 | 000,481,078 | ---- | C] () -- C:\WINDOWS\System32\winsh321
[2012/05/04 07:33:30 | 000,481,078 | ---- | C] () -- C:\WINDOWS\System32\winsh320
[2011/06/09 15:19:23 | 000,005,632 | ---- | C] () -- C:\Dokumente und Einstellungen\Anwender\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/28 06:05:34 | 000,010,593 | ---- | C] () -- C:\WINDOWS\CSTBox.INI
[2010/12/04 13:05:37 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2010/12/04 13:05:30 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2010/12/04 13:05:09 | 000,003,192 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2010/12/04 13:05:08 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/11/03 04:11:58 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\IPPCPUID.DLL
[2010/11/03 04:11:36 | 000,011,776 | ---- | C] () -- C:\WINDOWS\System32\pmsbfn32.dll
[2010/11/03 04:09:17 | 000,000,411 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2010/10/15 15:38:53 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/10/15 14:56:19 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/10/15 14:54:54 | 000,134,072 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/15 14:40:16 | 000,232,968 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2010/10/15 14:40:13 | 000,232,968 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2010/10/15 14:40:13 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2010/10/15 14:39:40 | 002,195,030 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2010/10/15 14:24:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/10/15 14:09:09 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010/10/15 14:03:29 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/04 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 08:00:00 | 000,320,094 | ---- | C] () -- C:\WINDOWS\System32\perfh007.dat
[2004/08/04 08:00:00 | 000,314,508 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/04 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 08:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\perfi007.dat
[2004/08/04 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 08:00:00 | 000,049,174 | ---- | C] () -- C:\WINDOWS\System32\perfc007.dat
[2004/08/04 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 08:00:00 | 000,040,836 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/04 08:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\perfd007.dat
[2004/08/04 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 08:00:00 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2004/08/04 08:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 08:00:00 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/08/04 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2003/02/20 11:53:42 | 000,005,702 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/10/18 20:16:24 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/10/18 20:15:28 | 000,004,518 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
========== LOP Check ==========
[2010/11/03 04:29:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Anwender\Anwendungsdaten\Canon
[2012/05/04 07:33:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Anwender\Anwendungsdaten\CoreFTP
[2012/05/04 07:33:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Anwender\Anwendungsdaten\FRITZ!
[2010/10/15 14:59:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Anwender\Anwendungsdaten\FRITZ!fax für FRITZ!Box
[2011/04/28 06:06:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Anwender\Anwendungsdaten\NewSoft
[2010/11/03 04:09:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Anwender\Anwendungsdaten\ScanSoft
[2012/05/04 07:34:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Anwender\Anwendungsdaten\TeamViewer
[2012/05/04 15:40:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Anwender\Anwendungsdaten\Yald
[2011/07/25 05:41:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\FRITZ!
[2010/10/15 14:47:36 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonBJ
[2010/10/15 14:59:56 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ISDNWatch
[2010/11/03 04:09:17 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ScanSoft
[2010/12/04 13:01:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\WinZip
========== Purity Check ==========
< End of report > --- --- ---
so dann malwarbytes:
das steht alles unter log dateien: Code:
2012/05/04 20:53:02 +0200 BUERO Anwender MESSAGE Starting protection
2012/05/04 20:53:09 +0200 BUERO Anwender MESSAGE Protection started successfully
2012/05/04 20:53:12 +0200 BUERO Anwender MESSAGE Starting IP protection
2012/05/04 20:53:26 +0200 BUERO Anwender MESSAGE IP Protection started successfully
2012/05/04 21:08:27 +0200 BUERO Anwender MESSAGE Executing scheduled update: Daily
2012/05/04 21:08:28 +0200 BUERO Anwender MESSAGE Database already up-to-date Code:
2012/05/06 12:30:46 +0200 BUERO Anwender MESSAGE Starting protection
2012/05/06 12:31:03 +0200 BUERO Anwender MESSAGE Protection started successfully
2012/05/06 12:31:06 +0200 BUERO Anwender MESSAGE Starting IP protection
2012/05/06 12:31:19 +0200 BUERO Anwender MESSAGE IP Protection started successfully
2012/05/06 12:40:40 +0200 BUERO Anwender MESSAGE Executing scheduled update: Daily
2012/05/06 12:40:57 +0200 BUERO Anwender MESSAGE Starting database refresh
2012/05/06 12:40:57 +0200 BUERO Anwender MESSAGE Scheduled update executed successfully: database updated from version v2012.05.04.05 to version v2012.05.06.03
2012/05/06 12:40:57 +0200 BUERO Anwender MESSAGE Stopping IP protection
2012/05/06 12:40:57 +0200 BUERO Anwender MESSAGE IP Protection stopped
2012/05/06 12:41:05 +0200 BUERO Anwender MESSAGE Database refreshed successfully
2012/05/06 12:41:05 +0200 BUERO Anwender MESSAGE Starting IP protection
2012/05/06 12:41:16 +0200 BUERO Anwender MESSAGE IP Protection started successfully
2012/05/06 17:33:27 +0200 BUERO MESSAGE Starting protection
2012/05/06 17:33:50 +0200 BUERO MESSAGE Protection started successfully
2012/05/06 17:33:53 +0200 BUERO Anwender MESSAGE Starting IP protection
2012/05/06 17:34:05 +0200 BUERO (null) MESSAGE IP Protection started successfully
2012/05/06 17:35:20 +0200 BUERO MESSAGE Starting protection
2012/05/06 17:35:39 +0200 BUERO MESSAGE Protection started successfully
2012/05/06 17:35:42 +0200 BUERO MESSAGE Starting IP protection
2012/05/06 17:35:51 +0200 BUERO Anwender MESSAGE IP Protection started successfully
2012/05/06 17:38:15 +0200 BUERO MESSAGE Starting protection
2012/05/06 17:38:33 +0200 BUERO MESSAGE Protection started successfully
2012/05/06 17:38:36 +0200 BUERO MESSAGE Starting IP protection
2012/05/06 17:38:48 +0200 BUERO Anwender MESSAGE IP Protection started successfully
2012/05/06 17:43:57 +0200 BUERO MESSAGE Starting protection
2012/05/06 17:44:13 +0200 BUERO MESSAGE Protection started successfully
2012/05/06 17:44:16 +0200 BUERO MESSAGE Starting IP protection
2012/05/06 17:44:33 +0200 BUERO Anwender MESSAGE IP Protection started successfully
2012/05/06 17:45:48 +0200 BUERO MESSAGE Starting protection
2012/05/06 17:46:04 +0200 BUERO MESSAGE Protection started successfully
2012/05/06 17:46:07 +0200 BUERO MESSAGE Starting IP protection
2012/05/06 17:46:23 +0200 BUERO Anwender MESSAGE IP Protection started successfully
2012/05/06 17:47:38 +0200 BUERO MESSAGE Starting protection
2012/05/06 17:47:52 +0200 BUERO MESSAGE Protection started successfully
2012/05/06 17:47:55 +0200 BUERO MESSAGE Starting IP protection
2012/05/06 17:48:11 +0200 BUERO Anwender MESSAGE IP Protection started successfully
2012/05/06 17:51:34 +0200 BUERO MESSAGE Starting protection
2012/05/06 17:51:56 +0200 BUERO MESSAGE Protection started successfully
2012/05/06 17:51:59 +0200 BUERO MESSAGE Starting IP protection
2012/05/06 17:52:13 +0200 BUERO Anwender MESSAGE IP Protection started successfully
2012/05/06 17:56:01 +0200 BUERO MESSAGE Starting protection
2012/05/06 17:56:16 +0200 BUERO MESSAGE Protection started successfully
2012/05/06 17:56:19 +0200 BUERO MESSAGE Starting IP protection
2012/05/06 17:56:33 +0200 BUERO Anwender MESSAGE IP Protection started successfully
2012/05/06 18:49:23 +0200 BUERO MESSAGE Starting protection
2012/05/06 18:49:37 +0200 BUERO MESSAGE Protection started successfully
2012/05/06 18:49:40 +0200 BUERO MESSAGE Starting IP protection
2012/05/06 18:50:01 +0200 BUERO Anwender MESSAGE IP Protection started successfully Code:
2012/05/08 17:34:35 +0200 BUERO MESSAGE Starting protection
2012/05/08 17:34:49 +0200 BUERO MESSAGE Protection started successfully
2012/05/08 17:34:50 +0200 BUERO MESSAGE Executing scheduled update: Daily
2012/05/08 17:34:53 +0200 BUERO MESSAGE Starting IP protection
2012/05/08 17:35:02 +0200 BUERO ERROR Scheduled update failed: Host not found failed with error code 0
2012/05/08 17:35:18 +0200 BUERO Anwender MESSAGE IP Protection started successfully
2012/05/08 19:55:46 +0200 BUERO MESSAGE Starting protection
2012/05/08 19:55:59 +0200 BUERO MESSAGE Protection started successfully
2012/05/08 19:56:03 +0200 BUERO MESSAGE Starting IP protection
2012/05/08 19:56:25 +0200 BUERO Anwender MESSAGE IP Protection started successfully
2012/05/08 20:02:18 +0200 BUERO Anwender MESSAGE Starting database refresh
2012/05/08 20:02:18 +0200 BUERO Anwender MESSAGE Stopping IP protection
2012/05/08 20:02:18 +0200 BUERO Anwender MESSAGE IP Protection stopped
2012/05/08 20:02:29 +0200 BUERO Anwender MESSAGE Database refreshed successfully
2012/05/08 20:02:29 +0200 BUERO Anwender MESSAGE Starting IP protection
2012/05/08 20:02:50 +0200 BUERO Anwender MESSAGE IP Protection started successfully aber ich glaube nicht, dass es das ist was du meinst...:headbang: |