Danke!
Umstellung hat funktioniert, danach konnte von der CD gebootet werden.
Die Datei otl.txt ist erstellt worden und hat sich automatisch geöffnet, die DAtei extras.txt ist nicht erzeugt worden. Ich habe 2 Versuche gestartet und hinterher auch automatisch nach der Datei suchen lassen, sie ist nicht da.
Hier der Inhalt von olt.txt:
OTL Logfile: Code:
OTL logfile created on: 12/27/2012 5:14:31 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Windows Vista (TM) Home Premium Service Pack 2 (Version = 6.0.6002) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 391.47 Gb Total Space | 363.60 Gb Free Space | 92.88% Space Free | Partition Type: NTFS
Drive G: | 97.66 Gb Total Space | 95.22 Gb Free Space | 97.51% Space Free | Partition Type: NTFS
Drive H: | 442.38 Gb Total Space | 414.17 Gb Free Space | 93.62% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV - [2012/12/26 09:57:57 | 000,192,512 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Users\Jörg\wgsdgsdgdsgsd.dll -- (Winmgmt)
SRV - [2012/12/23 12:34:10 | 000,085,280 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012/12/23 12:33:14 | 000,565,024 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE -- (AntiVirWebService)
SRV - [2012/12/23 12:33:03 | 000,400,160 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService)
SRV - [2012/12/23 12:33:01 | 000,109,344 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012/12/23 12:33:00 | 000,656,672 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto] -- C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe -- (AntiVirFirewallService)
SRV - [2012/12/11 13:26:12 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/12/05 16:59:32 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/11/09 05:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/07/27 15:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2009/06/18 08:19:30 | 000,935,208 | ---- | M] (Nero AG) [Auto] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2008/01/20 21:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/20 21:23:24 | 000,365,568 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2008/01/20 21:23:24 | 000,167,936 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2005/11/17 08:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand] -- C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand] -- -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand] -- -- (IpInIp)
DRV - [2012/12/23 12:34:52 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2012/12/23 12:34:51 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2012/12/23 12:34:50 | 000,134,336 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012/12/23 12:34:50 | 000,083,944 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012/12/23 12:34:49 | 000,112,584 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\Windows\System32\drivers\avfwot.sys -- (avfwot)
DRV - [2012/12/23 12:34:49 | 000,092,008 | ---- | M] (Avira GmbH) [Kernel | On_Demand] -- C:\Windows\System32\drivers\avfwim.sys -- (avfwim)
DRV - [2008/07/22 03:21:08 | 000,015,872 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2008/07/07 20:32:52 | 001,050,656 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2007/07/30 03:50:56 | 000,908,832 | ---- | M] (NXP Semiconductors Germany GmbH) [Kernel | On_Demand] -- C:\Windows\System32\drivers\PhilCap.sys -- (PhilCap)
DRV - [2007/02/05 03:22:02 | 000,134,888 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\RtHDMIV.sys -- (RTHDMIAzAudService)
DRV - [2006/11/30 08:18:18 | 000,027,416 | ---- | M] (X10 Wireless Technology, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\x10ufx2.sys -- (XUIF)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Jörg_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.spiegel.de/
IE - HKU\Jörg_ON_C\Software\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\Jörg_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.spiegel.de"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\System32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/12/05 16:59:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/12/05 16:59:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/12/05 15:40:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2012/09/14 15:11:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jörg\AppData\Roaming\Mozilla\Extensions
[2012/09/14 15:11:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jörg\AppData\Roaming\Mozilla\Extensions\songbird@songbirdnest.com
[2012/12/25 03:09:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jörg\AppData\Roaming\Mozilla\Firefox\Profiles\1xl7j3jn.default\extensions
[2012/11/21 18:47:54 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Jörg\AppData\Roaming\Mozilla\Firefox\Profiles\1xl7j3jn.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/12/20 19:27:23 | 000,000,000 | ---D | M] (Flash and Video Download) -- C:\Users\Jörg\AppData\Roaming\Mozilla\Firefox\Profiles\1xl7j3jn.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
[2012/09/09 07:19:19 | 000,002,057 | ---- | M] () -- C:\Users\Jörg\AppData\Roaming\Mozilla\Firefox\Profiles\1xl7j3jn.default\searchplugins\youtube-videosuche.xml
[2012/12/05 16:59:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
File not found (No name found) -- C:\USERS\JöRG\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1XL7J3JN.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
File not found (No name found) -- C:\USERS\JöRG\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1XL7J3JN.DEFAULT\EXTENSIONS\{B9DB16A4-6EDC-47EC-A1F4-B86292ED211D}
File not found (No name found) -- C:\USERS\JöRG\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1XL7J3JN.DEFAULT\EXTENSIONS\{BEE6EB20-01E0-EBD1-DA83-080329FB9A3A}
[2012/12/05 16:59:32 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/06/28 10:42:00 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2012/09/05 21:07:37 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/09/05 21:07:37 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/09/05 21:07:37 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012/09/05 21:07:37 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/09/05 21:07:37 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/09/05 21:07:37 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKU\Jörg_ON_C\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [MedionVFD] C:\Program Files\Medion Info Display\MdionLCMLH.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Philips Device Listener] C:\Program Files\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [TrayServer] C:\Program Files\MAGIX\Movies_on_DVD_TV_Edition\Trayserver.exe (MAGIX AG)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKU\LocalService_ON_C..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\NetworkService_ON_C..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Jörg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk = X:\I386\SYSTEM32\RUNDLL32.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Free YouTube Download - C:\Users\Jörg\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - File not found
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{23d10878-fe91-11e1-9d21-0024215968a8}\Shell - "" = AutoRun
O33 - MountPoints2\{23d10878-fe91-11e1-9d21-0024215968a8}\Shell\AutoRun\command - "" = J:\Setup.exe
O33 - MountPoints2\{4b8ffe24-f923-11e1-9cd1-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{4b8ffe24-f923-11e1-9cd1-806e6f6e6963}\Shell\AutoRun\command - "" = D:\reatogoMenu.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/12/26 16:08:09 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012/12/24 04:52:15 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/12/23 12:39:38 | 000,000,000 | ---D | C] -- C:\Users\Jörg\AppData\Roaming\Avira
[2012/12/23 12:39:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012/12/23 12:39:07 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2012/12/23 12:39:06 | 000,134,336 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012/12/23 12:39:06 | 000,112,584 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avfwot.sys
[2012/12/23 12:39:06 | 000,092,008 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avfwim.sys
[2012/12/23 12:39:06 | 000,083,944 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2012/12/23 12:39:06 | 000,036,552 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012/12/23 12:39:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012/12/23 12:39:05 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2012/12/21 10:54:40 | 000,293,376 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2012/12/21 10:54:40 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2012/12/12 17:32:06 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012/12/12 17:32:05 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2012/12/12 17:32:05 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012/12/12 17:32:05 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012/12/12 17:32:05 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012/12/12 17:32:04 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012/12/12 17:32:04 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2012/12/12 17:32:04 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012/12/12 17:32:04 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012/12/12 17:32:03 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012/12/12 16:51:19 | 002,048,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012/12/12 16:51:17 | 000,376,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpnet.dll
[2012/12/12 16:51:17 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpnsvr.exe
[2012/12/12 16:51:14 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012/12/10 16:20:55 | 000,000,000 | ---D | C] -- C:\Users\Jörg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hardcopy - Bildschirmausdruck
[2012/12/10 16:20:51 | 000,000,000 | ---D | C] -- C:\Program Files\Hardcopy
[2012/12/10 16:20:39 | 001,707,520 | ---- | C] (www.sw4you.de Siegfried Weckmann) -- C:\Windows\SwSetupu.exe
[2012/12/08 08:20:35 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2012/12/08 08:20:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/12/08 08:20:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2012/12/05 16:59:28 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012/12/05 15:40:26 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
[2012/11/29 02:12:34 | 000,000,000 | ---D | C] -- C:\Users\Jörg\Desktop\AK
========== Files - Modified Within 30 Days ==========
[2012/12/27 09:59:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/12/27 09:58:52 | 095,023,320 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012/12/27 09:57:59 | 000,000,680 | ---- | M] () -- C:\Users\Jörg\AppData\Local\d3d9caps.dat
[2012/12/27 09:57:52 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/27 09:57:52 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/26 18:25:15 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/26 11:22:15 | 000,288,056 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/12/26 09:58:05 | 000,002,887 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.js
[2012/12/26 09:58:05 | 000,000,884 | ---- | M] () -- C:\Users\Jörg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk
[2012/12/26 06:48:36 | 000,036,577 | ---- | M] () -- C:\Users\Jörg\Desktop\121213.jpg
[2012/12/26 05:16:34 | 000,617,456 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012/12/26 05:16:34 | 000,586,568 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/12/26 05:16:34 | 000,122,258 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012/12/26 05:16:34 | 000,100,640 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/12/23 12:39:28 | 000,001,847 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012/12/23 12:39:28 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012/12/23 12:34:52 | 000,028,520 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2012/12/23 12:34:51 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2012/12/23 12:34:50 | 000,134,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2012/12/23 12:34:50 | 000,083,944 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2012/12/23 12:34:49 | 000,112,584 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avfwot.sys
[2012/12/23 12:34:49 | 000,092,008 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avfwim.sys
[2012/12/23 09:17:05 | 001,959,043 | ---- | M] () -- C:\Users\Jörg\Desktop\bellers_sarrazin.pdf
[2012/12/18 18:36:49 | 000,021,401 | ---- | M] () -- C:\Users\Jörg\Desktop\eu afrika.nvc
[2012/12/18 18:33:58 | 002,564,850 | ---- | M] () -- C:\Users\Jörg\Desktop\v_2010_03_01_kohte_faber.pdf
[2012/12/18 18:16:54 | 000,018,944 | ---- | M] () -- C:\Users\Jörg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/12/18 17:35:19 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012/12/17 13:48:24 | 010,796,186 | ---- | M] () -- C:\Users\Jörg\Desktop\ltv_15_1071.pdf
[2012/12/16 08:12:54 | 000,034,304 | ---- | M] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2012/12/16 05:50:29 | 000,293,376 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2012/12/13 11:15:24 | 000,254,380 | ---- | M] () -- C:\Users\Jörg\Desktop\Kurzkommentar_SchulG.pdf
[2012/12/12 15:57:41 | 000,119,789 | ---- | M] () -- C:\Users\Jörg\Desktop\45169-1x2-galerie.jpg
[2012/12/11 15:50:29 | 001,718,888 | ---- | M] () -- C:\Users\Jörg\Desktop\gesamtausgabe schule von a bis z 2012 stand 1-8-12.pdf
[2012/12/11 13:26:08 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/12/11 13:26:08 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/12/10 16:12:42 | 001,600,793 | ---- | M] () -- C:\Users\Jörg\Desktop\stötzel.xps
[2012/12/10 13:18:32 | 000,524,072 | ---- | M] () -- C:\Users\Jörg\Desktop\IP_05_Rüttgers.pdf
[2012/12/08 08:20:35 | 000,001,880 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2012/12/08 08:20:35 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/12/06 12:47:46 | 001,201,276 | ---- | M] () -- C:\Users\Jörg\Desktop\1_640x480.mp4
[2012/12/05 16:06:49 | 000,000,182 | ---- | M] () -- C:\Users\Jörg\AppData\Roaming\default.rss
[2012/12/05 16:04:02 | 159,781,873 | ---- | M] () -- C:\Users\Jörg\Desktop\Quarks _ Co_ Bist Du reich genug - vom 12.04.2011.flv
[2012/12/05 15:22:16 | 036,521,645 | ---- | M] () -- C:\Users\Jörg\Desktop\Mit offenen Karten - Ungleiche Globalisierung - Juni 2007.flv
[2012/12/05 13:45:19 | 023,464,466 | ---- | M] () -- C:\Users\Jörg\Desktop\Doppelbelastung - Studium und Nebenjob.flv
[2012/12/01 15:05:09 | 003,060,923 | ---- | M] () -- C:\Users\Jörg\Desktop\9T0HXR.pdf
[2012/11/30 12:20:26 | 000,022,084 | ---- | M] () -- C:\Users\Jörg\Desktop\airberlin - Flüge nach 2 Berlin und Düsseldorf _ airberlin.pdf
[2012/11/30 12:19:18 | 000,599,311 | ---- | M] () -- C:\Users\Jörg\Desktop\airberlin - Flüge nach Berlin und Düsseldorf _ airberlin.pdf
========== Files Created - No Company Name ==========
[2012/12/26 09:58:05 | 000,002,887 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.js
[2012/12/26 09:58:05 | 000,000,884 | ---- | C] () -- C:\Users\Jörg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk
[2012/12/26 09:58:01 | 095,023,320 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012/12/26 06:48:35 | 000,036,577 | ---- | C] () -- C:\Users\Jörg\Desktop\121213.jpg
[2012/12/23 12:39:28 | 000,001,847 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012/12/23 09:17:05 | 001,959,043 | ---- | C] () -- C:\Users\Jörg\Desktop\bellers_sarrazin.pdf
[2012/12/18 18:33:58 | 002,564,850 | ---- | C] () -- C:\Users\Jörg\Desktop\v_2010_03_01_kohte_faber.pdf
[2012/12/18 16:07:59 | 000,021,401 | ---- | C] () -- C:\Users\Jörg\Desktop\eu afrika.nvc
[2012/12/17 13:48:24 | 010,796,186 | ---- | C] () -- C:\Users\Jörg\Desktop\ltv_15_1071.pdf
[2012/12/13 11:15:24 | 000,254,380 | ---- | C] () -- C:\Users\Jörg\Desktop\Kurzkommentar_SchulG.pdf
[2012/12/12 15:57:41 | 000,119,789 | ---- | C] () -- C:\Users\Jörg\Desktop\45169-1x2-galerie.jpg
[2012/12/11 15:50:23 | 001,718,888 | ---- | C] () -- C:\Users\Jörg\Desktop\gesamtausgabe schule von a bis z 2012 stand 1-8-12.pdf
[2012/12/10 16:12:35 | 001,600,793 | ---- | C] () -- C:\Users\Jörg\Desktop\stötzel.xps
[2012/12/10 13:18:32 | 000,524,072 | ---- | C] () -- C:\Users\Jörg\Desktop\IP_05_Rüttgers.pdf
[2012/12/06 12:46:51 | 001,201,276 | ---- | C] () -- C:\Users\Jörg\Desktop\1_640x480.mp4
[2012/12/05 15:29:15 | 159,781,873 | ---- | C] () -- C:\Users\Jörg\Desktop\Quarks _ Co_ Bist Du reich genug - vom 12.04.2011.flv
[2012/12/05 15:15:01 | 036,521,645 | ---- | C] () -- C:\Users\Jörg\Desktop\Mit offenen Karten - Ungleiche Globalisierung - Juni 2007.flv
[2012/12/05 13:41:57 | 023,464,466 | ---- | C] () -- C:\Users\Jörg\Desktop\Doppelbelastung - Studium und Nebenjob.flv
[2012/12/01 15:05:09 | 003,060,923 | ---- | C] () -- C:\Users\Jörg\Desktop\9T0HXR.pdf
[2012/11/30 12:20:26 | 000,022,084 | ---- | C] () -- C:\Users\Jörg\Desktop\airberlin - Flüge nach 2 Berlin und Düsseldorf _ airberlin.pdf
[2012/11/30 12:19:18 | 000,599,311 | ---- | C] () -- C:\Users\Jörg\Desktop\airberlin - Flüge nach Berlin und Düsseldorf _ airberlin.pdf
[2012/11/25 11:26:38 | 000,000,000 | ---- | C] () -- C:\Users\Jörg\AppData\Roaming\downloads.m3u
[2012/09/27 13:46:08 | 000,000,552 | ---- | C] () -- C:\Users\Jörg\AppData\Local\d3d8caps.dat
[2012/09/14 15:42:48 | 000,000,182 | ---- | C] () -- C:\Users\Jörg\AppData\Roaming\default.rss
[2012/09/14 15:42:31 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2012/09/09 04:45:15 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2012/09/09 04:44:37 | 000,007,119 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2012/09/09 03:28:04 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2012/09/09 03:28:04 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2012/09/09 03:27:47 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2012/09/08 07:27:11 | 000,089,430 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
[2012/09/08 07:27:11 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
[2012/09/08 07:27:11 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat
[2012/09/08 07:27:11 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat
[2012/09/08 07:27:11 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
[2012/09/08 07:27:11 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat
[2012/09/08 07:27:11 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat
[2012/09/08 07:27:11 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat
[2012/09/08 07:27:11 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat
[2012/09/08 07:27:11 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat
[2012/09/08 07:27:11 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat
[2012/09/08 07:27:11 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat
[2012/09/08 07:27:11 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat
[2012/09/08 07:27:11 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat
[2012/09/08 07:27:11 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat
[2012/09/08 07:27:11 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat
[2012/09/08 07:27:11 | 000,000,099 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2012/09/08 07:24:50 | 000,000,025 | ---- | C] () -- C:\Windows\CDE DX4200EFGIPSD.ini
[2012/09/08 05:58:57 | 000,018,944 | ---- | C] () -- C:\Users\Jörg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/08 02:59:26 | 000,004,767 | ---- | C] () -- C:\Windows\Irremote.ini
[2012/09/07 15:06:15 | 000,009,760 | ---- | C] () -- C:\Windows\System32\716xCoInstaller.dll
[2012/09/07 15:05:08 | 000,004,984 | R--- | C] () -- C:\Windows\System32\drivers\nvphy.bin
[2012/09/07 14:43:33 | 000,000,680 | ---- | C] () -- C:\Users\Jörg\AppData\Local\d3d9caps.dat
[2008/01/21 02:15:58 | 000,617,456 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2008/01/21 02:15:58 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2008/01/21 02:15:58 | 000,122,258 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2008/01/21 02:15:58 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006/11/02 07:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,288,056 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,586,568 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,100,640 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 05:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2005/02/24 23:15:00 | 000,159,744 | ---- | C] () -- C:\Windows\System32\EPSPTDV.DLL
========== LOP Check ==========
[2012/09/08 08:44:37 | 000,000,000 | ---D | M] -- C:\Users\Jörg\AppData\Roaming\DVDVideoSoft
[2012/09/08 08:44:26 | 000,000,000 | ---D | M] -- C:\Users\Jörg\AppData\Roaming\DVDVideoSoftIEHelpers
[2012/09/08 12:03:44 | 000,000,000 | ---D | M] -- C:\Users\Jörg\AppData\Roaming\EPSON
[2012/09/14 15:11:18 | 000,000,000 | ---D | M] -- C:\Users\Jörg\AppData\Roaming\Philips-Songbird
[2012/09/09 04:32:49 | 000,000,000 | ---D | M] -- C:\Users\Jörg\AppData\Roaming\TerraTec
[2012/09/07 16:57:46 | 000,000,000 | ---D | M] -- C:\Users\Jörg\AppData\Roaming\Thunderbird
[2012/09/07 14:41:58 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2012/09/07 14:59:53 | 000,000,000 | ---D | M] -- C:\ProgramData\AzureWave
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2012/09/07 14:41:58 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
[2012/09/07 14:41:58 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2012/09/09 04:46:13 | 000,000,000 | ---D | M] -- C:\ProgramData\MAGIX
[2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2012/09/07 14:41:58 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
[2006/11/02 08:02:04 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2012/09/09 04:33:30 | 000,000,000 | ---D | M] -- C:\ProgramData\TerraTec
[2012/09/08 07:30:40 | 000,000,000 | ---D | M] -- C:\ProgramData\UDL
[2012/09/07 14:41:58 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
[2012/11/20 15:03:58 | 000,000,000 | ---D | M] -- C:\ProgramData\WinZip
[2012/09/14 15:10:31 | 000,000,000 | ---D | M] -- C:\ProgramData\{F0489EF2-D393-4114-85BA-A94D71D89543}
[2012/12/27 09:59:21 | 000,032,534 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 64 bytes -> C:\Users\Jörg\Desktop\DuckTales 90 - Die Entdeckung der Inflation Ganze Folge.mp4:TOC.WMV
< End of report > --- --- ---
[\Code] |