Jazon123 | 29.06.2012 17:34 | kleines problemchen, OTL war auf einer CD, ich hatte so ein Prob schon mal, nun weiß ch nicht, welche Textdatei ich schicken muss, also wie die heisst.... hier mal der Inhalt von OTL_text :OTL Logfile: Code:
OTL logfile created on: 29.06.2012 13:06:27 - Run 3
OTL by OldTimer - Version 3.2.39.2 Folder = E:\
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19272)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,75 Gb Total Physical Memory | 1,19 Gb Available Physical Memory | 68,01% Memory free
3,76 Gb Paging File | 3,37 Gb Available in Paging File | 89,59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 113,88 Gb Total Space | 3,91 Gb Free Space | 3,43% Space Free | Partition Type: NTFS
Drive D: | 114,00 Gb Total Space | 49,42 Gb Free Space | 43,35% Space Free | Partition Type: NTFS
Drive E: | 702,31 Mb Total Space | 601,93 Mb Free Space | 85,71% Space Free | Partition Type: UDF
Computer Name: CHRISTIANRÜT-PC | User Name: Christian XXXXX | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.03.28 18:29:40 | 000,593,920 | ---- | M] (OldTimer Tools) -- E:\OTL.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (No Company Name) ==========
========== Win32 Services (SafeList) ==========
SRV - [2012.06.23 13:45:18 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.06.19 23:41:22 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.05.08 22:38:32 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.08 22:38:25 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.02.29 09:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.04.19 16:12:22 | 000,009,216 | ---- | M] (Vodafone) [Auto | Stopped] -- C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe -- (VmbService)
SRV - [2011.01.10 16:24:20 | 000,993,848 | ---- | M] (Secunia) [Auto | Stopped] -- C:\Program Files\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
SRV - [2011.01.10 16:24:20 | 000,399,416 | ---- | M] (Secunia) [Auto | Stopped] -- C:\Program Files\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2008.01.19 09:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2006.10.05 18:10:12 | 000,009,216 | ---- | M] (Agere Systems) [Auto | Stopped] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\PCASp50.sys -- (PCASp50)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\nvhbcxey.sys -- (nvhbcxey)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\CHRIST~1\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2012.05.08 22:38:33 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.05.08 22:38:33 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.03.20 19:30:30 | 000,281,760 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2012.03.20 19:30:28 | 000,025,888 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2011.09.16 16:08:07 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2011.04.18 15:43:30 | 000,107,776 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Gt51Ip.sys -- (GT72NDISIPXP)
DRV - [2011.04.18 15:43:30 | 000,064,640 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\gt72ubus.sys -- (GT72UBUS)
DRV - [2011.04.18 15:43:30 | 000,008,064 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\gtptser.sys -- (GTPTSER)
DRV - [2011.04.18 15:43:26 | 000,072,832 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2010.09.01 14:33:12 | 000,080,000 | ---- | M] (Vodafone) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys -- (vodafone_K3805-z_dc_enum)
DRV - [2010.09.01 10:30:58 | 000,015,544 | ---- | M] (Secunia) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\psi_mf.sys -- (PSI)
DRV - [2010.03.11 09:36:26 | 000,024,192 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2010.03.11 09:36:24 | 000,013,184 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\BMLoad.sys -- (BMLoad)
DRV - [2010.02.24 12:22:10 | 000,185,472 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2009.12.17 17:02:20 | 001,203,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009.10.08 16:55:33 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.04.09 14:38:30 | 000,110,592 | ---- | M] (ZTE Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnet.sys -- (ZTEusbnet)
DRV - [2009.04.09 14:38:30 | 000,105,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\zteusbvoice.sys -- (ZTEusbvoice)
DRV - [2009.04.09 14:38:30 | 000,105,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2009.04.09 14:38:30 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2009.04.09 14:38:30 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2009.04.09 14:38:30 | 000,007,680 | R--- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\massfilter.sys -- (massfilter)
DRV - [2007.01.19 01:03:24 | 002,314,752 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006.11.28 21:11:00 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C0 F9 8E F1 F5 16 CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.1&q="
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "hxxp://start.icq.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: KavAntiBanner@Kaspersky.ru:11.0.2.556
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.2.556
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.6&q="
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\Vodafone\Vodafone Mobile Broadband\Optimization Client\addon\ [2012.05.09 10:28:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.19 23:41:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.05.29 17:45:47 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.19 23:41:23 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.05.29 17:45:47 | 000,000,000 | ---D | M]
[2011.02.16 16:35:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian XXXXX\AppData\Roaming\mozilla\Extensions
[2012.05.02 16:56:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian XXXXX\AppData\Roaming\mozilla\Firefox\Profiles\l0j9eh5h.default\extensions
[2011.05.09 07:19:20 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Christian XXXXX\AppData\Roaming\mozilla\Firefox\Profiles\l0j9eh5h.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.03.28 19:27:25 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Christian XXXXX\AppData\Roaming\mozilla\Firefox\Profiles\l0j9eh5h.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.08.31 21:01:09 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Christian XXXXX\AppData\Roaming\mozilla\Firefox\Profiles\l0j9eh5h.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.08.21 19:28:58 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\Christian XXXXX\AppData\Roaming\mozilla\Firefox\Profiles\l0j9eh5h.default\extensions\de-DE@dictionaries.addons.mozilla.org
[2012.06.23 19:04:11 | 000,000,950 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin-1.xml
[2011.09.20 22:20:11 | 000,000,950 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin-10.xml
[2011.09.25 16:16:41 | 000,000,950 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin-11.xml
[2011.10.01 10:56:38 | 000,000,950 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin-12.xml
[2011.10.21 08:19:58 | 000,000,950 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin-13.xml
[2011.11.08 10:30:38 | 000,000,950 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin-14.xml
[2011.07.05 21:08:16 | 000,000,950 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin-2.xml
[2011.08.18 17:30:21 | 000,000,950 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin-3.xml
[2011.08.20 20:14:05 | 000,000,950 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin-4.xml
[2011.08.21 16:13:22 | 000,000,950 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin-5.xml
[2011.09.01 19:48:51 | 000,000,950 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin-6.xml
[2011.09.08 07:51:51 | 000,000,950 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin-7.xml
[2011.09.09 07:15:58 | 000,000,950 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin-8.xml
[2011.09.16 14:18:32 | 000,000,950 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin-9.xml
[2011.06.23 08:51:30 | 000,001,056 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Mozilla\Firefox\Profiles\l0j9eh5h.default\searchplugins\icqplugin.xml
[2012.04.20 07:29:31 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2012.05.09 10:28:17 | 000,000,000 | ---D | M] (Bytemobile Optimization Client) -- C:\PROGRAM FILES\VODAFONE\VODAFONE MOBILE BROADBAND\OPTIMIZATION CLIENT\ADDON
File not found (No name found) -- C:\USERS\CHRISTIAN RüTTGER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\L0J9EH5H.DEFAULT\EXTENSIONS\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
File not found (No name found) -- C:\USERS\CHRISTIAN RüTTGER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\L0J9EH5H.DEFAULT\EXTENSIONS\DE-DE@DICTIONARIES.ADDONS.MOZILLA.ORG
File not found (No name found) -- C:\USERS\CHRISTIAN RüTTGER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\L0J9EH5H.DEFAULT\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM.XPI
[2012.06.19 23:41:23 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.11.10 06:54:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010.03.08 12:24:04 | 000,103,168 | ---- | M] (Midasplayer Ltd) -- C:\Program Files\mozilla firefox\plugins\npmidas.dll
[2012.06.19 23:41:21 | 000,001,525 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012.06.19 23:41:21 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.06.19 23:41:21 | 000,000,935 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012.06.19 23:41:21 | 000,001,166 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012.06.19 23:41:21 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012.06.19 23:41:21 | 000,001,121 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2012.03.28 21:03:27 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKCU..\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Christian XXXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote Inhaltsverzeichnis.onetoc2 ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Christian XXXXX\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {23A70515-51F4-4FFD-9CAA-5F31B83452E0} https://elias.kabeldeutschland.de/ecommunications_deu/21211/applets/SiebelAx_HI_Client.cab (Siebel High Interactivity Framework)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{791D4CE4-A3E7-417E-B014-85C5A657DEE9}: DhcpNameServer = 172.25.101.130 10.32.29.18
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{97F6F8F7-B12C-4A0F-A703-662802A77D26}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012.06.24 01:42:43 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\Macromedia
[2012.06.23 13:05:16 | 002,422,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2012.06.23 13:05:16 | 000,045,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2012.06.23 13:04:43 | 000,577,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2012.06.23 13:04:43 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2012.06.23 13:04:43 | 000,035,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2012.06.23 13:04:31 | 000,171,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2012.06.23 13:04:31 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2012.06.22 13:51:18 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{A379CF4A-936E-4069-8962-9E496AEC14E3}
[2012.06.22 13:51:06 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{E2D78559-92B5-41AD-9EF4-91D083195707}
[2012.06.12 23:12:29 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{EE28B60E-AD19-4614-A830-C48DA4D661F9}
[2012.06.12 23:12:26 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{71271475-139C-414A-A8DB-3656FCC4B982}
[2012.06.12 21:20:01 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.06.12 21:20:01 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.06.12 21:19:58 | 000,629,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012.06.12 21:19:57 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012.06.12 21:19:57 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2012.06.12 21:19:57 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2012.06.12 21:19:57 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2012.06.12 21:19:57 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.06.12 21:19:56 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.06.12 21:19:56 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2012.06.12 21:19:56 | 000,174,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2012.06.12 21:19:56 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012.06.12 21:19:56 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2012.06.12 21:19:56 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2012.06.12 21:19:56 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2012.06.12 21:19:56 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2012.06.12 21:19:56 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2012.06.12 21:19:56 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2012.06.12 21:19:40 | 002,045,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012.06.12 20:23:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012.06.12 20:22:19 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012.06.12 20:22:13 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012.06.12 09:48:28 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{6AF4F212-59AC-4845-BA78-C68605AEBDE5}
[2012.06.12 09:48:25 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{FA0EE5A7-919E-47BD-AB79-6ED91304BC2E}
[2012.06.11 21:21:36 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{7D518EF4-1474-4005-A919-F0737FB87FBD}
[2012.06.11 21:21:34 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{65BB7AEB-8E77-4D2E-853F-2E13EFEFFEA1}
[2012.06.11 19:19:30 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{37F77635-884D-4733-B51E-B7C81131A0F9}
[2012.06.11 19:19:27 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{90A71DAE-7033-4322-94EE-9E480F80B506}
[2012.06.08 10:42:10 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{F00F6FB9-4329-40C1-9754-36BC7DB31F71}
[2012.06.08 10:42:08 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{978DDD4C-A7C5-4457-ABD3-C9F489DC3195}
[2012.06.08 03:10:54 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{9EABEE93-FEDB-4B5B-BE0A-7D500E0A8411}
[2012.06.08 03:10:52 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{099E2132-E6AD-4D0E-B7D9-8A2B4D7A9412}
[2012.06.08 01:53:21 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{C9E556EF-E3CF-4F72-B72D-6D9D3DE64F6D}
[2012.06.08 01:53:18 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{93363BC8-0C47-4FC8-BBB7-4825D4CF248B}
[2012.06.05 08:05:14 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{88482AFD-B1C1-4585-9387-63D2AA201823}
[2012.06.05 08:05:11 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{BC8E98BD-F9F0-4E3F-A7B7-57D511D90764}
[2012.06.04 23:06:23 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{5483A4FB-B409-47D2-9BF1-7351302D7C95}
[2012.06.04 23:06:21 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{BE71464D-637B-4BD7-A52E-ACEBAA2C27BB}
[2012.06.04 20:17:12 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{A4117D65-9DCC-496B-8C81-723F3BD50624}
[2012.06.04 20:17:10 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{A6213BBA-1F21-4FB3-A36C-2F30E10E1110}
[2012.06.04 19:23:26 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{437801AC-3A93-4F5D-8C60-E4A06A7A66AD}
[2012.06.04 19:23:23 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{3C753D8D-46F1-4375-A337-65CC43624E59}
[2012.05.31 08:18:32 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{DFA781C0-78AE-441F-8D5E-085E06CF46F5}
[2012.05.31 08:18:29 | 000,000,000 | ---D | C] -- C:\Users\Christian XXXXX\AppData\Local\{50BFBDFE-9F51-4896-9956-6EAD29EEBCB6}
========== Files - Modified Within 30 Days ==========
[2012.06.29 11:11:30 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.06.29 11:11:21 | 000,631,488 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.06.29 11:11:21 | 000,598,512 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.06.29 11:11:21 | 000,126,908 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.06.29 11:11:21 | 000,104,526 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.06.29 11:06:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.06.29 11:02:49 | 004,503,728 | ---- | M] () -- C:\ProgramData\l_0_00_re.pad
[2012.06.29 10:58:52 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.06.29 10:58:51 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.06.29 10:22:24 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.06.29 09:45:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.06.28 17:57:49 | 000,001,728 | ---- | M] () -- C:\Users\Christian XXXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk
[2012.06.23 13:45:18 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.06.23 13:45:18 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.06.22 14:29:44 | 000,405,661 | ---- | M] () -- C:\Users\Christian XXXXX\Desktop\eddy verkauf.JPG
[2012.06.13 17:50:55 | 000,377,720 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.06.12 20:23:58 | 000,001,664 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.06.03 00:19:33 | 000,045,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2012.06.03 00:19:32 | 000,035,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2012.06.03 00:19:23 | 000,577,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2012.06.03 00:12:32 | 002,422,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2012.06.03 00:12:13 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2012.06.02 15:19:42 | 000,171,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2012.06.02 15:12:20 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
========== Files Created - No Company Name ==========
[2012.06.28 17:57:49 | 000,001,728 | ---- | C] () -- C:\Users\Christian XXXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk
[2012.06.28 17:57:48 | 004,503,728 | ---- | C] () -- C:\ProgramData\l_0_00_re.pad
[2012.06.22 14:31:18 | 000,405,661 | ---- | C] () -- C:\Users\Christian XXXXX\Desktop\eddy verkauf.JPG
[2012.06.12 20:23:58 | 000,001,664 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.04.22 16:45:24 | 000,000,020 | ---- | C] () -- C:\Windows\mafosav.INI
[2012.04.09 12:46:46 | 000,178,176 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2012.03.28 20:47:04 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.03.28 20:47:04 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.03.28 20:47:04 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.03.28 20:47:04 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.03.28 20:47:04 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.03.20 19:30:30 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2012.03.20 19:30:28 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2012.03.17 16:49:07 | 000,000,982 | ---- | C] () -- C:\Windows\wiso.ini
[2011.07.17 15:30:44 | 000,000,680 | ---- | C] () -- C:\Users\Christian XXXXX\AppData\Local\d3d9caps.dat
[2011.06.06 20:50:11 | 000,032,608 | ---- | C] () -- C:\Windows\king-uninstall.exe
[2011.04.18 15:39:56 | 000,226,364 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2011.04.10 17:24:06 | 000,006,656 | ---- | C] () -- C:\Users\Christian XXXXX\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.02.17 16:35:38 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011.02.17 15:11:31 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.02.17 15:11:30 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011.02.17 15:10:15 | 000,062,976 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.02.16 12:35:20 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2011.02.16 12:34:42 | 000,000,000 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
========== LOP Check ==========
[2012.03.17 16:54:53 | 000,000,000 | ---D | M] -- C:\Users\Christian XXXXX\AppData\Roaming\Buhl Data Service
[2011.08.31 21:01:19 | 000,000,000 | ---D | M] -- C:\Users\Christian XXXXX\AppData\Roaming\DVDVideoSoft
[2011.08.31 21:01:08 | 000,000,000 | ---D | M] -- C:\Users\Christian XXXXX\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.09.07 09:40:46 | 000,000,000 | ---D | M] -- C:\Users\Christian XXXXX\AppData\Roaming\Firefly Studios
[2012.03.28 19:53:56 | 000,000,000 | ---D | M] -- C:\Users\Christian XXXXX\AppData\Roaming\Kalypso Media
[2012.03.27 14:05:06 | 000,000,000 | ---D | M] -- C:\Users\Christian XXXXX\AppData\Roaming\ProtectDISC
[2012.03.20 22:15:31 | 000,000,000 | ---D | M] -- C:\Users\Christian XXXXX\AppData\Roaming\Red Alert 3
[2012.04.09 12:47:30 | 000,000,000 | ---D | M] -- C:\Users\Christian XXXXX\AppData\Roaming\Video DVD Maker FREE
[2012.05.09 10:43:41 | 000,000,000 | ---D | M] -- C:\Users\Christian XXXXX\AppData\Roaming\Vodafone
[2012.05.09 10:49:52 | 000,000,000 | ---D | M] -- C:\Users\Christian XXXXX\AppData\Roaming\Vodafone Mobile Broadband
[2012.06.29 10:22:20 | 000,032,514 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 164 bytes -> C:\Users\Christian XXXXX\Desktop\gerichtskasse.TIF:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 164 bytes -> C:\Users\Christian XXXXX\Desktop\eddy verkauf.JPG:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:3B75B877
< End of report > --- --- ---
zip datei erfolgreich geladen
oder war es das:
All processes killed
========== OTL ==========
C:\Users\Christian XXXXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk moved successfully.
========== COMMANDS ==========
[EMPTYFLASH]
User: All Users
User: Christian XXXXX
->Flash cache emptied: 0 bytes
User: Default
User: Default User
User: Public
Total Flash Files Cleaned = 0,00 mb
[EMPTYTEMP]
User: All Users
User: Christian XXXXX
->Temp folder emptied: 33353 bytes
->Temporary Internet Files folder emptied: 88038 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 55372746 bytes
->Flash cache emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 61107478 bytes
RecycleBin emptied: 240679059 bytes
Total Files Cleaned = 341,00 mb
OTL by OldTimer - Version 3.2.39.2 log created on 06292012_181930 |