Dominic28 | 29.11.2009 13:18 | rest von der OTL.txt Code:
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009.07.14 03:37:08 | 00,000,000 | ---D | M]
NetSvcs: Irmon - C:\Windows\System32\irmon.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L)
Drivers32: VIDC.XFR1 - C:\Windows\System32\xfcodec.dll ()
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (-4294967296)
========== Files/Folders - Created Within 14 Days ==========
[2009.11.29 10:54:01 | 00,000,000 | ---D | C] -- C:\Programme\Trend Micro
[2009.11.24 19:01:43 | 00,000,000 | ---D | C] -- C:\Users\******\Desktop\code28
[2009.11.23 16:17:57 | 00,000,000 | ---D | C] -- C:\Programme\Accessdiver
[2009.11.21 21:12:20 | 00,000,000 | ---D | C] -- C:\Fraps
[2009.11.19 20:40:58 | 00,000,000 | ---D | C] -- C:\Users\******\Documents\DVDVideoSoft
[2009.11.19 20:40:52 | 00,000,000 | ---D | C] -- C:\Programme\DVDVideoSoft
[2009.11.19 20:40:52 | 00,000,000 | ---D | C] -- C:\Programme\Common Files\DVDVideoSoft
[2009.11.19 19:06:43 | 00,000,000 | ---D | C] -- C:\Users\******\AppData\Roaming\Apple Computer
[2009.11.19 19:06:43 | 00,000,000 | ---D | C] -- C:\Users\******\AppData\Local\Apple Computer
[2009.11.19 19:05:52 | 00,000,000 | ---D | C] -- C:\Programme\iPod
[2009.11.19 19:05:51 | 00,000,000 | ---D | C] -- C:\Programme\iTunes
[2009.11.19 19:05:51 | 00,000,000 | ---D | C] -- C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009.11.19 19:05:16 | 00,000,000 | ---D | C] -- C:\Programme\Bonjour
[2009.11.19 19:04:45 | 00,000,000 | ---D | C] -- C:\Programme\QuickTime
[2009.11.19 19:04:45 | 00,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2009.11.15 13:12:25 | 00,000,000 | ---D | C] -- C:\Users\******\AppData\Roaming\ProtectDisc
[2009.11.15 13:10:13 | 00,000,000 | ---D | C] -- C:\Programme\ProtectDisc Driver Installer
[2009.11.15 13:07:19 | 00,000,000 | ---D | C] -- C:\Users\******\Documents\18 WoS Extreme Trucker
[2009.11.15 13:07:08 | 00,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2009.11.15 13:05:43 | 00,000,000 | ---D | C] -- C:\Programme\Cobra 11 - Highway Nights Demo
[2009.11.15 13:05:16 | 00,000,000 | ---D | C] -- C:\Programme\18 Wheels of Steel Extreme Trucker
========== Files - Modified Within 14 Days ==========
[2009.11.29 12:39:07 | 04,980,736 | -HS- | M] () -- C:\Users\******\NTUSER.DAT
[2009.11.29 12:01:00 | 00,000,396 | ---- | M] () -- C:\Windows\tasks\At2.job
[2009.11.29 11:59:18 | 00,000,396 | ---- | M] () -- C:\Windows\tasks\At1.job
[2009.11.29 10:42:40 | 00,712,450 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2009.11.29 10:42:40 | 00,675,208 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009.11.29 10:42:40 | 00,151,600 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2009.11.29 10:42:40 | 00,128,616 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009.11.29 10:42:39 | 01,663,872 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009.11.29 10:42:16 | 00,016,624 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2009.11.29 10:42:16 | 00,016,624 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2009.11.29 10:37:13 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009.11.29 10:37:08 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009.11.29 10:36:41 | 16,100,63872 | -HS- | M] () -- C:\hiberfil.sys
[2009.11.29 01:04:37 | 02,444,173 | -H-- | M] () -- C:\Users\******\AppData\Local\IconCache.db
[2009.11.25 14:11:51 | 02,337,456 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.11.24 19:26:59 | 00,109,216 | ---- | M] () -- C:\Users\******\AppData\Local\GDIPFONTCACHEV1.DAT
[2009.11.23 20:17:56 | 00,027,136 | ---- | M] () -- C:\Users\******\Documents\deutsch.doc
[2009.11.23 20:17:34 | 00,011,112 | ---- | M] () -- C:\Users\******\Documents\deutsch.docx
[2009.11.23 07:40:22 | 00,029,184 | ---- | M] () -- C:\Users\******\Documents\boomtownrats.doc
[2009.11.22 12:17:58 | 00,011,649 | ---- | M] () -- C:\Users\******\Documents\Mein Film.wlmp
[2009.11.21 21:12:20 | 00,000,562 | ---- | M] () -- C:\Users\******\Desktop\Fraps.lnk
[2009.11.20 14:12:18 | 00,001,213 | ---- | M] () -- C:\Users\******\Desktop\DVDVideoSoft Free Studio.lnk
[2009.11.20 14:11:24 | 00,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2009.11.15 19:00:49 | 13,369,86112 | ---- | M] () -- C:\Users\******\Documents\hammer.avi
[2009.11.15 18:54:04 | 13,060,90496 | ---- | M] () -- C:\Users\******\Documents\blondi.avi
[2009.11.15 18:31:16 | 95,733,4016 | ---- | M] () -- C:\Users\******\Documents\andere.avi
[2009.11.15 18:14:14 | 10,368,68608 | ---- | M] () -- C:\Users\******\Documents\geil.avi
[2009.11.15 18:09:26 | 32,954,5216 | ---- | M] () -- C:\Users\******\Documents\nice.avi
[2009.11.15 13:12:44 | 00,004,096 | ---- | M] () -- C:\Users\Public\Documents\00001199.LCS
[2009.11.15 13:10:31 | 00,001,174 | ---- | M] () -- C:\Users\Public\Desktop\Cobra 11 - Highway Nights Demo spielen.lnk
[2009.11.15 13:07:52 | 00,002,359 | ---- | M] () -- C:\Users\Public\Desktop\18 Wheels of Steel Extreme Trucker.lnk
========== Files Created - No Company Name ==========
[2009.11.29 12:00:37 | 00,000,396 | ---- | C] () -- C:\Windows\tasks\At2.job
[2009.11.29 11:59:17 | 00,000,396 | ---- | C] () -- C:\Windows\tasks\At1.job
[2009.11.23 20:17:55 | 00,027,136 | ---- | C] () -- C:\Users\******\Documents\deutsch.doc
[2009.11.23 20:17:34 | 00,011,112 | ---- | C] () -- C:\Users\******\Documents\deutsch.docx
[2009.11.22 13:14:30 | 00,029,184 | ---- | C] () -- C:\Users\******\Documents\boomtownrats.doc
[2009.11.22 12:03:52 | 00,011,649 | ---- | C] () -- C:\Users\******\Documents\Mein Film.wlmp
[2009.11.21 21:12:20 | 00,000,562 | ---- | C] () -- C:\Users\******\Desktop\Fraps.lnk
[2009.11.20 14:11:24 | 00,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2009.11.19 20:40:58 | 00,001,213 | ---- | C] () -- C:\Users\******\Desktop\DVDVideoSoft Free Studio.lnk
[2009.11.15 19:00:54 | 13,369,86112 | ---- | C] () -- C:\Users\******\Documents\hammer.avi
[2009.11.15 18:54:10 | 13,060,90496 | ---- | C] () -- C:\Users\******\Documents\blondi.avi
[2009.11.15 18:31:21 | 95,733,4016 | ---- | C] () -- C:\Users\******\Documents\andere.avi
[2009.11.15 18:14:20 | 10,368,68608 | ---- | C] () -- C:\Users\******\Documents\geil.avi
[2009.11.15 18:09:31 | 32,954,5216 | ---- | C] () -- C:\Users\******\Documents\nice.avi
[2009.11.15 13:12:44 | 00,004,096 | ---- | C] () -- C:\Users\Public\Documents\00001199.LCS
[2009.11.15 13:10:31 | 00,001,174 | ---- | C] () -- C:\Users\Public\Desktop\Cobra 11 - Highway Nights Demo spielen.lnk
[2009.11.15 13:07:52 | 00,002,359 | ---- | C] () -- C:\Users\Public\Desktop\18 Wheels of Steel Extreme Trucker.lnk
[2009.11.07 19:12:43 | 00,000,000 | ---- | C] () -- C:\Users\******\AppData\Roaming\FileOut.cns
[2009.11.07 19:12:43 | 00,000,000 | ---- | C] () -- C:\Users\******\AppData\Roaming\FileIn.cns
[2009.11.07 00:49:41 | 00,000,141 | ---- | C] () -- C:\Users\******\AppData\Roaming\default.rss
[2009.11.07 00:49:30 | 00,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2009.11.06 21:15:43 | 00,004,767 | ---- | C] () -- C:\Windows\Irremote.ini
[2009.11.06 21:06:27 | 00,765,952 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009.11.06 21:06:27 | 00,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009.11.06 20:31:58 | 00,691,696 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2009.11.06 20:21:58 | 00,034,308 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2009.11.06 03:18:24 | 00,041,872 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
[2009.07.14 00:51:43 | 00,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 00:42:10 | 00,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
========== LOP Check ==========
[2009.11.07 01:01:01 | 00,000,000 | ---D | M] -- C:\Users\******\AppData\Roaming\Blender Foundation
[2009.11.08 14:19:51 | 00,000,000 | ---D | M] -- C:\Users\******\AppData\Roaming\DAEMON Tools Lite
[2009.11.07 01:03:49 | 00,000,000 | ---D | M] -- C:\Users\******\AppData\Roaming\FileZilla
[2009.11.08 18:06:02 | 00,000,000 | ---D | M] -- C:\Users\******\AppData\Roaming\GrabIt
[2009.11.28 22:28:14 | 00,000,000 | ---D | M] -- C:\Users\******\AppData\Roaming\ICQ
[2009.11.07 22:56:41 | 00,000,000 | ---D | M] -- C:\Users\******\AppData\Roaming\Notepad++
[2009.11.15 13:12:25 | 00,000,000 | ---D | M] -- C:\Users\******\AppData\Roaming\ProtectDisc
[2009.11.29 11:59:18 | 00,000,396 | ---- | M] () -- C:\Windows\Tasks\At1.job
[2009.11.29 12:01:00 | 00,000,396 | ---- | M] () -- C:\Windows\Tasks\At2.job
[2009.07.14 05:53:46 | 00,009,952 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[2009.07.14 02:16:13 | 00,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\System32\scecli.dll
[2009.07.14 02:16:13 | 00,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[2009.07.14 02:16:02 | 00,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\System32\netlogon.dll
[2009.07.14 02:16:02 | 00,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >
[2009.07.14 02:15:06 | 00,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009.07.14 02:15:06 | 00,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
< %SYSTEMDRIVE%\sceclt.dll /s /md5 >
< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >
< %SYSTEMDRIVE%\logevent.dll /s /md5 >
< %SYSTEMDRIVE%\iaStor.sys /s /md5 >
< %SYSTEMDRIVE%\nvstor.sys /s /md5 >
[2009.07.14 02:20:44 | 00,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\drivers\nvstor.sys
[2009.07.14 02:20:44 | 00,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 02:20:44 | 00,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[2009.07.14 02:26:15 | 00,021,584 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 02:26:15 | 00,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009.07.14 02:26:15 | 00,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >
< %SYSTEMDRIVE%\viasraid.sys /s /md5 >
< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[2009.07.14 02:26:15 | 00,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009.07.14 02:26:15 | 00,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009.07.14 02:26:15 | 00,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >
< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >
< End of report > |