Flitzpiepe12 | 13.12.2010 19:00 | Hi Swiss, erstmal danke für die schnelle Hilfe.
Anbei die gewünschten Daten:OTL Logfile: Code:
OTL logfile created on: 13.12.2010 18:26:31 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Dokumente und Einstellungen\OlaSim\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
511,00 Mb Total Physical Memory | 257,00 Mb Available Physical Memory | 50,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 52,00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 48,83 Gb Total Space | 32,94 Gb Free Space | 67,47% Space Free | Partition Type: NTFS
Drive D: | 100,21 Gb Total Space | 54,59 Gb Free Space | 54,47% Space Free | Partition Type: NTFS
Computer Name: OLASIM-3WQHQZHB | User Name: OlaSim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010.12.13 18:22:03 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\OlaSim\Desktop\OTL.exe
PRC - [2010.12.01 14:49:56 | 001,589,208 | ---- | M] (PC Tools) -- C:\Programme\PC Tools Security\pctsGui.exe
PRC - [2010.11.19 06:57:14 | 001,150,936 | ---- | M] (PC Tools) -- C:\Programme\PC Tools Security\pctsSvc.exe
PRC - [2010.11.10 13:28:22 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2010.11.10 13:28:16 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.11.10 13:28:16 | 000,267,944 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2010.03.15 14:02:36 | 000,366,840 | ---- | M] (PC Tools) -- C:\Programme\PC Tools Security\pctsAuxs.exe
PRC - [2010.01.14 21:10:54 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009.09.22 20:31:44 | 000,065,536 | ---- | M] () -- C:\WINDOWS\ditexp.exe
PRC - [2008.04.14 03:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004.06.04 11:53:00 | 000,327,680 | ---- | M] () -- C:\Programme\Siemens\Gigaset USB Adapter 54\GigasetUSBMonitor.exe
PRC - [2004.04.26 13:26:00 | 000,295,001 | ---- | M] (Conexant Systems, Inc.) -- C:\Programme\Siemens\Gigaset USB Adapter 54\PRISMSVR.exe
PRC - [2002.08.28 12:43:26 | 000,073,728 | ---- | M] () -- C:\WINDOWS\Dit.exe
========== Modules (SafeList) ==========
MOD - [2010.12.13 18:22:03 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\OlaSim\Desktop\OTL.exe
MOD - [2010.08.23 17:11:46 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2010.08.04 13:19:26 | 000,157,768 | ---- | M] (PC Tools) -- C:\Programme\PC Tools Security\smum32.dll
MOD - [2010.08.04 13:19:26 | 000,150,576 | ---- | M] (PC Tools) -- C:\Programme\PC Tools Security\PCTGMhk.dll
MOD - [2009.08.13 14:55:39 | 001,748,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll
MOD - [2008.04.14 03:22:25 | 000,025,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shfolder.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe -- (Automatisches LiveUpdate - Scheduler)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010.11.19 06:57:14 | 001,150,936 | ---- | M] (PC Tools) [Auto | Running] -- C:\Programme\PC Tools Security\pctsSvc.exe -- (sdCoreService)
SRV - [2010.11.10 13:28:22 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010.11.10 13:28:16 | 000,267,944 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010.03.15 14:02:36 | 000,366,840 | ---- | M] (PC Tools) [Auto | Running] -- C:\Programme\PC Tools Security\pctsAuxs.exe -- (sdAuxService)
SRV - [2009.04.23 20:18:13 | 001,838,592 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager)
SRV - [2008.04.14 03:22:12 | 000,036,864 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\iprip.dll -- (Iprip)
SRV - [2001.11.12 12:31:48 | 000,020,480 | ---- | M] (X10) [On_Demand | Stopped] -- C:\Programme\Common Files\X10\Common\X10nets.exe -- (x10nets)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\Tools\Winflash\WinFlash.sys -- (WINFLASH)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\SRTSPL.SYS -- (SRTSPL)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\avfsfilter.sys -- (AVFSFilter)
DRV - [2010.11.25 10:43:00 | 000,239,168 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2010.11.10 13:28:23 | 000,126,856 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2010.11.10 13:28:23 | 000,060,936 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.09.22 09:20:43 | 000,015,781 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\mdc8021x.sys -- (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2010.07.16 14:59:54 | 000,656,320 | ---- | M] (PC Tools) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\pctEFA.sys -- (pctEFA)
DRV - [2010.07.16 14:59:54 | 000,338,880 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\pctDS.sys -- (pctDS)
DRV - [2009.05.11 11:49:20 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009.05.11 09:12:50 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2006.02.20 16:59:36 | 000,083,344 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810obex.sys -- (w810obex)
DRV - [2006.02.20 16:59:34 | 000,094,064 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mdm.sys -- (w810mdm)
DRV - [2006.02.20 16:59:34 | 000,085,408 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mgmt.sys -- (w810mgmt) Sony Ericsson W810 USB WMC Device Management Drivers (WDM)
DRV - [2006.02.20 16:59:32 | 000,008,336 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mdfl.sys -- (w810mdfl)
DRV - [2006.02.20 16:59:28 | 000,058,288 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810bus.sys -- (w810bus) Sony Ericsson W810 Driver driver (WDM)
DRV - [2004.06.02 02:43:00 | 000,379,232 | R--- | M] (Siemens AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SE4501D.sys -- (SE4501D)
DRV - [2003.06.25 16:40:14 | 000,587,264 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2003.03.20 14:01:46 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2001.08.17 14:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2003.04.02 13:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programme\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Programme\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\irprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [Cmaudio] File not found
O4 - HKLM..\Run: [Dit] C:\WINDOWS\Dit.exe ()
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Programme\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [Google Desktop Search] C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [ISTray] C:\Programme\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PCMService] C:\Programme\Medion Home Cinema XL II\PowerCinema\PCMService.exe ()
O4 - HKLM..\Run: [PRISMSVR.EXE] C:\Programme\Siemens\Gigaset USB Adapter 54\PRISMSVR.EXE (Conexant Systems, Inc.)
O4 - HKLM..\Run: [tray"] C:\Programme\CodedColor\byngo.exe File not found
O4 - HKCU..\Run: [Getdo] File not found
O4 - HKCU..\Run: [Setinx] C:\Dokumente und Einstellungen\OlaSim\Anwendungsdaten\Adobe\Update\widnat.exe ()
O4 - HKLM..\RunOnce: [SymLnch] C:\Dokumente und Einstellungen\OlaSim\Anwendungsdaten\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymLnch\SymLnch.exe File not found
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Gigaset WLAN Adapter Monitor.lnk = C:\Programme\Siemens\Gigaset USB Adapter 54\GigasetUSBMonitor.exe ()
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Scanner Finder.lnk = C:\Programme\ScanWizard 5\ScannerFinder.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Winamp Search - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Easy-WebPrint - Drucken - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint - Vorschau - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - C:\Programme\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Programme\Gemeinsame Dateien\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Programme\Gemeinsame Dateien\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Programme\Gemeinsame Dateien\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Programme\Gemeinsame Dateien\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1185130763109 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1185129964890 (MUWebControl Class)
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} hxxp://static.ak.studivz.net/photouploader/ImageUploader4.cab?nocache=20071219-1 (Image Uploader Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} Seite nicht gefunden | Facebook (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} Java Plug-in Technology (Java Plug-in 1.4.2)
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} hxxp://static.pe.studivz.net/photouploader/ImageUploader5.cab?nocache=1215201940 (Image Uploader Control)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} Java Plug-in Technology (Java Plug-in 1.4.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.144,85.255.112.5
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL) - C:\Programme\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\OlaSim\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\OlaSim\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.07.22 18:31:53 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{fa4cf8de-9f1a-11df-8f51-0001e309ed59}\Shell\AutoRun\command - "" = K:\Launcher.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - C:\WINDOWS\system32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (121610800690364416)
========== Files/Folders - Created Within 30 Days ==========
[2010.12.13 18:21:52 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\OlaSim\Desktop\OTL.exe
[2010.12.13 16:17:21 | 000,656,320 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctEFA.sys
[2010.12.13 16:17:21 | 000,338,880 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctDS.sys
[2010.12.13 16:17:20 | 000,249,616 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[2010.12.13 16:17:15 | 000,239,168 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2010.12.13 16:17:15 | 000,160,448 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2010.12.13 16:17:05 | 000,070,536 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
[2010.12.13 16:16:30 | 000,000,000 | ---D | C] -- C:\Programme\PC Tools Security
[2010.12.13 16:16:30 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\PC Tools
[2010.12.13 16:16:30 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\OlaSim\Anwendungsdaten\PC Tools
[2010.12.13 16:16:26 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
[2010.12.13 16:13:52 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Tools
[2010.12.04 02:00:51 | 000,000,000 | -HSD | C] -- C:\found.000
[2010.11.16 12:34:07 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\OlaSim\Recent
[2009.05.18 18:04:21 | 003,338,496 | ---- | C] (Unity Technologies ApS) -- C:\Programme\UnityWebPlayer.exe
[2008.11.02 16:16:11 | 002,879,953 | ---- | C] (OneStopSoft.com ) -- C:\Programme\YT.exe
[2008.10.25 17:30:02 | 009,341,888 | ---- | C] (Nullsoft, Inc.) -- C:\Programme\winamp5541_full_emusic-7plus_de-de.exe
[2008.06.03 17:27:37 | 007,252,235 | ---- | C] (DVD Video Soft Limited. ) -- C:\Programme\FreeVideoToMp3Converter.exe
[2008.03.23 20:16:27 | 027,586,458 | ---- | C] (eRightSoft ) -- C:\Programme\SUPERsetup200825.exe
[2008.03.23 19:57:06 | 023,344,432 | ---- | C] (Apple Inc.) -- C:\Programme\QuickTimeInstaller.exe
[2007.12.10 19:54:05 | 002,725,528 | ---- | C] (Piriform Ltd) -- C:\Programme\ccsetup202.exe
[2007.12.07 18:17:53 | 008,750,208 | ---- | C] (Nullsoft, Inc.) -- C:\Programme\winamp55_full_emusic-7plus_de-de.exe
[2007.09.07 16:36:51 | 001,473,284 | ---- | C] (MAGIX AG) -- C:\Programme\ALDI_Foto_Buch_sued_D.2.exe
[2007.09.03 19:04:33 | 023,258,280 | ---- | C] (MAGIX AG) -- C:\Programme\foto_manager_sued_d.exe
[2007.07.23 17:17:37 | 006,221,304 | ---- | C] (Nullsoft, Inc.) -- C:\Programme\winamp.exe
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.12.13 18:22:03 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\OlaSim\Desktop\OTL.exe
[2010.12.13 16:17:45 | 000,732,734 | ---- | M] () -- C:\WINDOWS\System32\drivers\Cat.DB
[2010.12.13 16:17:13 | 000,001,614 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Spyware Doctor.lnk
[2010.12.13 16:13:51 | 000,512,992 | ---- | M] () -- C:\Dokumente und Einstellungen\OlaSim\Desktop\sdsetup[1].exe
[2010.12.13 15:39:00 | 000,448,470 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2010.12.13 15:39:00 | 000,432,356 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.12.13 15:39:00 | 000,079,910 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2010.12.13 15:39:00 | 000,067,312 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.12.13 15:35:05 | 000,001,044 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2010.12.13 15:34:52 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.12.12 21:22:58 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.11.25 10:53:58 | 000,160,448 | ---- | M] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2010.11.25 10:43:00 | 000,239,168 | ---- | M] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2010.11.25 10:42:10 | 000,070,536 | ---- | M] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
[2010.11.17 10:19:50 | 000,249,616 | ---- | M] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.12.13 16:17:22 | 000,732,734 | ---- | C] () -- C:\WINDOWS\System32\drivers\Cat.DB
[2010.12.13 16:17:13 | 000,001,614 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Spyware Doctor.lnk
[2010.12.13 16:13:52 | 000,512,992 | ---- | C] () -- C:\Dokumente und Einstellungen\OlaSim\Desktop\sdsetup[1].exe
[2008.12.12 11:00:58 | 000,000,029 | ---- | C] () -- C:\WINDOWS\coolacm.ini
[2008.11.02 16:06:44 | 003,558,791 | ---- | C] () -- C:\Programme\youtubedownloader.exe
[2008.03.23 20:18:30 | 000,399,360 | ---- | C] () -- C:\WINDOWS\System32\Smab.dll
[2008.03.23 20:18:29 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2008.03.03 19:10:57 | 000,000,037 | ---- | C] () -- C:\WINDOWS\iltwain.ini
[2007.12.10 20:06:10 | 000,949,560 | ---- | C] () -- C:\Programme\srwa5-1.62.2.exe
[2007.11.07 20:28:59 | 000,180,003 | ---- | C] () -- C:\Programme\mp3DC206.exe
[2007.09.07 17:01:07 | 000,074,793 | ---- | C] () -- C:\Dokumente und Einstellungen\OlaSim\Anwendungsdaten\mdb.bin
[2007.09.03 19:06:07 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2007.09.03 19:05:42 | 000,006,768 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2007.08.18 11:10:41 | 000,030,208 | ---- | C] () -- C:\Dokumente und Einstellungen\OlaSim\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.08.14 21:34:43 | 000,000,035 | ---- | C] () -- C:\WINDOWS\Ulead32.INI
[2007.07.26 18:59:09 | 000,000,000 | ---- | C] () -- C:\WINDOWS\longfile.INI
[2007.07.26 18:58:58 | 001,371,436 | R--- | C] () -- C:\WINDOWS\System32\VBAR2132.DLL
[2007.07.26 18:54:14 | 000,021,504 | ---- | C] () -- C:\WINDOWS\System32\scpext.dll
[2007.07.26 18:40:51 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.07.23 17:44:25 | 000,000,036 | ---- | C] () -- C:\WINDOWS\coolmp3.ini
[2007.07.23 17:44:25 | 000,000,028 | ---- | C] () -- C:\WINDOWS\wordpad.ini
[2007.07.23 17:44:24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\COOLSYS.INI
[2007.07.23 17:44:13 | 000,000,027 | ---- | C] () -- C:\WINDOWS\winzip32.ini
[2007.07.23 17:44:02 | 000,010,677 | ---- | C] () -- C:\WINDOWS\coolkb2k.ini
[2007.07.23 17:42:53 | 000,005,786 | ---- | C] () -- C:\WINDOWS\COOL.INI
[2007.07.22 19:26:24 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2007.07.22 19:25:34 | 000,000,040 | ---- | C] () -- C:\WINDOWS\System32\mscandc.ini
[2007.07.22 19:15:52 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2007.07.22 19:12:01 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\CNMVS64.DLL
[2007.07.22 19:08:36 | 000,285,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\Onsio.sys
[2007.07.22 19:08:36 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\drivers\Onsreged.sys
[2007.07.22 18:56:02 | 000,003,548 | R--- | C] () -- C:\WINDOWS\System32\drivers\WinFlash.sys
[2007.07.22 18:50:05 | 000,040,960 | ---- | C] () -- C:\Programme\Uninstall_PCM.exe
[2007.07.22 18:44:25 | 000,001,279 | ---- | C] () -- C:\WINDOWS\ATICIM.INI
[2007.07.22 18:41:14 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007.07.22 18:40:43 | 000,065,536 | ---- | C] () -- C:\WINDOWS\Dit.DLL
[2007.07.22 18:40:43 | 000,000,208 | ---- | C] () -- C:\WINDOWS\Dit.INI
[2007.07.22 18:39:46 | 000,000,092 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2007.07.22 18:39:46 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2007.07.22 18:39:44 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\cmirmdrv.dll
[2007.07.22 18:39:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Wininit.ini
[2007.07.22 18:39:43 | 000,064,957 | ---- | C] () -- C:\WINDOWS\Cmuda.ini
[2007.07.22 18:39:41 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CMIRmDriver.dll
[2003.06.25 16:27:50 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll
========== LOP Check ==========
[2007.09.30 12:00:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\byngo
[2007.09.30 12:00:59 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CCPublisher
[2010.11.04 09:11:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\clp
[2007.10.24 19:04:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CodedColor
[2007.09.03 19:07:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MAGIX
[2009.05.20 15:09:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PCSettings
[2010.09.22 09:22:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Prism
[2008.04.18 16:24:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SuperEasy Software
[2007.08.24 20:14:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Teleca
[2010.12.13 16:51:34 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
[2007.10.24 19:04:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\OlaSim\Anwendungsdaten\Byngo
[2007.10.24 19:04:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\OlaSim\Anwendungsdaten\CCPublisher
[2010.12.13 15:07:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\OlaSim\Anwendungsdaten\Fighters
[2008.10.26 12:34:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\OlaSim\Anwendungsdaten\streamripper
[2008.05.13 19:17:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\OlaSim\Anwendungsdaten\SuperEasy Software
[2007.08.24 20:16:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\OlaSim\Anwendungsdaten\Teleca
[2010.12.13 17:45:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\OlaSim\Anwendungsdaten\TrusteerHelp
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2007.07.22 18:31:53 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2007.07.22 21:39:28 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2003.04.02 13:00:00 | 000,004,952 | RHS- | M] () -- C:\bootfont.bin
[2007.07.22 18:31:53 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2008.03.30 19:51:17 | 000,000,190 | ---- | M] () -- C:\drwtsn32.log
[2007.07.22 18:31:53 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2008.08.23 16:51:13 | 000,000,051 | ---- | M] () -- C:\log.txt
[2007.07.22 18:31:53 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2007.07.22 21:33:33 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009.05.22 19:11:48 | 000,251,712 | RHS- | M] () -- C:\ntldr
[2010.12.13 15:34:49 | 805,306,368 | -HS- | M] () -- C:\pagefile.sys
[2008.08.15 22:01:17 | 000,000,092 | ---- | M] () -- C:\ResumeOmgApDeliveryMgrCntrl_SonicStage_EmdDownloadObj.dmf
< %systemroot%\system32\*.wt >
< %systemroot%\system32\*.ruy >
< %systemroot%\Fonts\*.com >
[2006.04.18 14:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006.06.29 13:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006.04.18 14:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006.06.29 13:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2007.07.22 18:31:39 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004.04.23 06:00:00 | 000,017,920 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD64.DLL
[2004.04.23 06:00:00 | 000,054,272 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP64.DLL
[2008.07.06 13:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008.07.06 11:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
[2010.08.14 09:39:24 | 000,000,004 | ---- | M] () -- C:\Dokumente und Einstellungen\OlaSim\Anwendungsdaten\Adobe\Update\flacor.dat
[2010.10.25 14:50:19 | 000,259,584 | ---- | M] () -- C:\Dokumente und Einstellungen\OlaSim\Anwendungsdaten\Adobe\Update\widnat.exe
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2007.09.07 16:37:06 | 001,473,284 | ---- | M] (MAGIX AG) -- C:\Programme\ALDI_Foto_Buch_sued_D.2.exe
[2007.12.10 19:54:08 | 002,725,528 | ---- | M] (Piriform Ltd) -- C:\Programme\ccsetup202.exe
[2007.09.03 19:05:38 | 023,258,280 | ---- | M] (MAGIX AG) -- C:\Programme\foto_manager_sued_d.exe
[2008.06.03 17:27:44 | 007,252,235 | ---- | M] (DVD Video Soft Limited. ) -- C:\Programme\FreeVideoToMp3Converter.exe
[2007.11.07 20:29:03 | 000,180,003 | ---- | M] () -- C:\Programme\mp3DC206.exe
[2008.03.23 19:57:09 | 023,344,432 | ---- | M] (Apple Inc.) -- C:\Programme\QuickTimeInstaller.exe
[2007.12.10 20:06:13 | 000,949,560 | ---- | M] () -- C:\Programme\srwa5-1.62.2.exe
[2008.03.23 20:16:55 | 027,586,458 | ---- | M] (eRightSoft ) -- C:\Programme\SUPERsetup200825.exe
[2003.08.14 18:13:12 | 000,040,960 | ---- | M] () -- C:\Programme\Uninstall_PCM.exe
[2009.05.18 18:04:26 | 003,338,496 | ---- | M] (Unity Technologies ApS) -- C:\Programme\UnityWebPlayer.exe
[2007.07.23 17:17:47 | 006,221,304 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\winamp.exe
[2008.10.25 17:30:07 | 009,341,888 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\winamp5541_full_emusic-7plus_de-de.exe
[2007.12.07 18:17:57 | 008,750,208 | ---- | M] (Nullsoft, Inc.) -- C:\Programme\winamp55_full_emusic-7plus_de-de.exe
[2008.11.02 16:06:48 | 003,558,791 | ---- | M] () -- C:\Programme\youtubedownloader.exe
[2008.11.02 16:16:16 | 002,879,953 | ---- | M] (OneStopSoft.com ) -- C:\Programme\YT.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2007.07.22 20:24:39 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2007.07.22 20:24:39 | 000,606,208 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2007.07.22 20:24:39 | 000,434,176 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\user32.dll /md5 >
[2008.04.14 03:22:31 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINDOWS\system32\user32.dll
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\ws2_32.dll /md5 >
[2008.04.14 03:22:32 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=6A35E2D6F5F052C84EC2CEB296389439 -- C:\WINDOWS\system32\ws2_32.dll
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\ws2help.dll /md5 >
[2008.04.14 03:22:32 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=C7D8A0517CBF16B84F657DE87EBE9D4B -- C:\WINDOWS\system32\ws2help.dll
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< MD5 for: EXPLORER.EXE >
[2004.08.04 08:57:53 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=22FE1BE02EADDE1632E478E4125639E0 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007.06.13 14:10:08 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=331ED93570BAF3CFE30340298762CD56 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2008.04.14 03:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E -- C:\WINDOWS\explorer.exe
[2008.04.14 03:22:45 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007.06.13 14:21:45 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=64D320C0E301EEDC5A4ADBBDC5024F7F -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: WINLOGON.EXE >
[2004.08.04 08:58:19 | 000,507,392 | ---- | M] (Microsoft Corporation) MD5=2B6A0BAF33A9918F09442D873848FF72 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 03:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 03:23:05 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINDOWS\system32\winlogon.exe
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-11 09:32:39
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 149 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:DFC5A2B2
< End of report > --- --- --- |