mistertropi | 15.03.2012 20:55 | ok habe nur eine datei bekommen die olt text. das ist der inhalt:OTL Logfile: Code:
OTL logfile created on: 15.03.2012 20:50:42 - Run 1
OTL by OldTimer - Version 3.2.37.0 Folder = C:\Users\alex\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 3,23 Gb Available Physical Memory | 80,83% Memory free
8,00 Gb Paging File | 7,38 Gb Available in Paging File | 92,26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 372,61 Gb Total Space | 103,75 Gb Free Space | 27,84% Space Free | Partition Type: NTFS
Drive D: | 931,52 Gb Total Space | 231,16 Gb Free Space | 24,82% Space Free | Partition Type: NTFS
Drive E: | 4,07 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive F: | 3,69 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive G: | 1863,01 Gb Total Space | 1650,59 Gb Free Space | 88,60% Space Free | Partition Type: NTFS
Drive I: | 931,51 Gb Total Space | 120,24 Gb Free Space | 12,91% Space Free | Partition Type: NTFS
Drive J: | 967,72 Mb Total Space | 765,47 Mb Free Space | 79,10% Space Free | Partition Type: FAT
Computer Name: ALEX-PC | User Name: alex | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\alex\Desktop\OTL.exe (OldTimer Tools)
========== Modules (No Company Name) ==========
========== Win32 Services (SafeList) ==========
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (MSCamSvc) -- C:\Programme\Microsoft LifeCam\MSCamS64.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (VMnetDHCP) -- C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMware NAT Service) -- C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
SRV - (VMAuthdService) -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe (VMware, Inc.)
SRV - (ufad-ws60) -- C:\Program Files (x86)\VMware\VMware Player\vmware-ufad.exe (VMware, Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (atksgt) -- C:\Windows\SysNative\drivers\atksgt.sys ()
DRV:64bit: - (lirsgt) -- C:\Windows\SysNative\drivers\lirsgt.sys ()
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) -- C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (VX1000) -- C:\Windows\SysNative\drivers\VX1000.sys (Microsoft Corporation)
DRV:64bit: - (acedrv11) -- C:\Windows\SysNative\drivers\acedrv11.sys (Protect Software GmbH)
DRV:64bit: - (yukonw7) -- C:\Windows\SysNative\drivers\yk62x64.sys ()
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (xusb21) -- C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (vmx86) -- C:\Windows\SysNative\drivers\vmx86.sys (VMware, Inc.)
DRV:64bit: - (vmkbd) -- C:\Windows\SysNative\drivers\VMkbd.sys (VMware, Inc.)
DRV:64bit: - (hcmon) -- C:\Windows\SysNative\drivers\hcmon.sys (VMware, Inc.)
DRV:64bit: - (VMparport) -- C:\Windows\SysNative\drivers\VMparport.sys (VMware, Inc.)
DRV:64bit: - (VMnetuserif) -- C:\Windows\SysNative\drivers\vmnetuserif.sys (VMware, Inc.)
DRV:64bit: - (vmci) -- C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.)
DRV:64bit: - (VMnetBridge) -- C:\Windows\SysNative\drivers\vmnetbridge.sys (VMware, Inc.)
DRV:64bit: - (VMnetAdapter) -- C:\Windows\SysNative\drivers\vmnetadapter.sys (VMware, Inc.)
DRV:64bit: - (XG762_VS) -- C:\Windows\SysNative\drivers\WlanGZG.sys (Atheros Communications, Inc.)
DRV:64bit: - (ZDCNDIS6a64) -- C:\Windows\SysNative\ZDCNDIS6a64.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (hwpsgt) -- C:\Windows\SysWOW64\drivers\hwpsgt.sys ()
DRV - (lemsgt) -- C:\Windows\SysWOW64\drivers\lemsgt.sys ()
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (vstor2-ws60) -- C:\Program Files (x86)\VMware\VMware Player\vstor2-ws60.sys (VMware, Inc.)
DRV - (ZDCNDIS6a64) -- C:\Windows\SysWOW64\ZDCNDIS6a64.sys (Printing Communications Assoc., Inc. (PCAUSA))
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hiergehtslos.de
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Web Search..."
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de"
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.8.20100713041928
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8153
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..keyword.URL: "hxxp://vshare.toolbarhome.com/search.aspx?srch=ku&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011.03.01 15:51:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011.03.01 15:51:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 7\components [2012.02.19 18:37:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 7\plugins [2012.02.19 18:37:21 | 000,000,000 | ---D | M]
[2010.12.12 13:45:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\alex\AppData\Roaming\mozilla\Extensions
[2012.02.19 18:57:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\alex\AppData\Roaming\mozilla\Firefox\Profiles\p7k57rx7.default\extensions
[2012.02.19 18:57:56 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\alex\AppData\Roaming\mozilla\Firefox\Profiles\p7k57rx7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010.12.12 13:39:54 | 000,000,000 | ---D | M] (vShare) -- C:\Users\alex\AppData\Roaming\mozilla\Firefox\Profiles\p7k57rx7.default\extensions\vshare@toolbar
[2010.12.12 13:40:08 | 000,001,583 | ---- | M] () -- C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\p7k57rx7.default\searchplugins\web-search.xml
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4:64bit: - HKLM..\Run: [VX1000] C:\Windows\vVX1000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LifeCam] C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [VMware hqtray] C:\Program Files (x86)\VMware\VMware Player\hqtray.exe (VMware, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
F3:64bit: - HKCU WinNT: Load - (C:\Users\alex\LOCALS~1\Temp\msxrxourz.exe) - C:\Users\alex\LOCALS~1\Temp\msxrxourz.exe ()
F3 - HKCU WinNT: Load - (C:\Users\alex\LOCALS~1\Temp\msxrxourz.exe) - C:\Users\alex\LOCALS~1\Temp\msxrxourz.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Program Files (x86)\VMware\VMware Player\x64\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Program Files (x86)\VMware\VMware Player\x64\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.95.117.252 193.175.207.252
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2B2B97CC-9B93-42F1-B819-8BE3B41C42A3}: DhcpNameServer = 194.95.117.252 193.175.207.252
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{948AC0B4-7331-4B34-B586-176691E52961}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.12.14 10:00:22 | 000,008,192 | ---- | M] (Microsoft) - G:\AutoOff.exe -- [ NTFS ]
O32 - AutoRun File - [2010.11.02 14:29:16 | 000,000,073 | ---- | M] () - G:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009.12.14 09:00:22 | 000,008,192 | ---- | M] (Microsoft) - I:\AutoOff.exe -- [ NTFS ]
O32 - AutoRun File - [2010.01.20 11:02:34 | 000,000,065 | ---- | M] () - I:\autorun.unf -- [ NTFS ]
O33 - MountPoints2\{cc172ed1-05f5-11e0-8066-0016e681e22d}\Shell - "" = AutoRun
O33 - MountPoints2\{cc172ed1-05f5-11e0-8066-0016e681e22d}\Shell\AutoRun\command - "" = H:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012.03.15 20:16:10 | 000,000,000 | ---D | C] -- C:\Users\alex\AppData\Local\ElevatedDiagnostics
[2012.03.15 19:59:05 | 000,594,432 | ---- | C] (OldTimer Tools) -- C:\Users\alex\Desktop\OTL.exe
[2012.03.15 19:45:20 | 000,000,000 | ---D | C] -- C:\Users\alex\AppData\Roaming\kodak
[2012.03.15 19:45:11 | 000,000,000 | ---D | C] -- C:\Users\alex\Local Settings
[2012.03.15 11:40:54 | 000,000,000 | ---D | C] -- C:\Users\alex\AppData\Roaming\UAs
[2012.03.15 11:40:11 | 000,000,000 | ---D | C] -- C:\Users\alex\AppData\Roaming\xmldm
[2012.03.15 11:33:52 | 000,000,000 | ---D | C] -- C:\Users\alex\AppData\Roaming\kock
[2012.02.29 23:43:03 | 000,178,800 | ---- | C] (Sony DADC Austria AG.) -- C:\Windows\SysWow64\CmdLineExt_x64.dll
[2012.02.22 12:32:14 | 000,000,000 | ---D | C] -- C:\Users\alex\AppData\Local\SKIDROW
[2012.02.21 16:30:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Meridian93
[2012.02.21 16:30:22 | 000,000,000 | ---D | C] -- C:\Users\alex\AppData\Roaming\Meridian93
[2012.02.14 21:21:24 | 000,000,000 | ---D | C] -- C:\Users\alex\Documents\Paradox Interactive
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\alex\AppData\Roaming\*.tmp files -> C:\Users\alex\AppData\Roaming\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.03.15 19:57:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.03.15 19:57:04 | 3220,037,632 | -HS- | M] () -- C:\hiberfil.sys
[2012.03.15 16:59:05 | 000,013,232 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.03.15 16:59:05 | 000,013,232 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.15 16:51:46 | 000,300,136 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.03.15 16:30:05 | 001,621,618 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.03.15 16:30:05 | 000,699,554 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.03.15 16:30:05 | 000,654,872 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.03.15 16:30:05 | 000,149,376 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.03.15 16:30:05 | 000,122,330 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.03.15 15:57:08 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Users\alex\Desktop\OTL.exe
[2012.03.15 11:40:18 | 000,000,016 | ---- | M] () -- C:\Users\alex\AppData\Roaming\blckdom.res
[2012.03.12 12:58:30 | 000,058,235 | ---- | M] () -- C:\Users\alex\Desktop\lebenslauf korrig..pdf
[2012.03.11 19:52:52 | 000,061,736 | ---- | M] () -- C:\Users\alex\Desktop\antrag_aug_2012.pdf
[2012.03.11 19:52:34 | 000,045,471 | ---- | M] () -- C:\Users\alex\Desktop\merkblatt_aug_2012.pdf
[2012.03.03 20:31:08 | 006,253,711 | ---- | M] () -- C:\Users\alex\Desktop\DSCI0035.JPG
[2012.03.03 20:29:57 | 006,253,711 | ---- | M] () -- C:\Users\alex\Desktop\DSCI0037.JPG
[2012.03.03 20:29:44 | 006,253,711 | ---- | M] () -- C:\Users\alex\Desktop\DSCI0034.JPG
[2012.03.03 20:29:23 | 006,253,711 | ---- | M] () -- C:\Users\alex\Desktop\DSCI0033.JPG
[2012.03.03 17:57:55 | 000,008,478 | ---- | M] () -- C:\Users\alex\Desktop\g.odt
[2012.02.29 23:43:03 | 000,178,800 | ---- | M] (Sony DADC Austria AG.) -- C:\Windows\SysWow64\CmdLineExt_x64.dll
[2012.02.29 23:41:17 | 000,000,796 | ---- | M] () -- C:\Users\alex\Desktop\Eastern Front Launcher.lnk
[2012.02.21 03:05:27 | 001,598,576 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\alex\AppData\Roaming\*.tmp files -> C:\Users\alex\AppData\Roaming\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.03.15 11:40:18 | 000,000,016 | ---- | C] () -- C:\Users\alex\AppData\Roaming\blckdom.res
[2012.03.12 21:42:50 | 728,940,544 | ---- | C] () -- C:\Users\alex\Desktop\gvd-zhmdp-xvid.avi
[2012.03.11 19:52:51 | 000,061,736 | ---- | C] () -- C:\Users\alex\Desktop\antrag_aug_2012.pdf
[2012.03.11 19:52:31 | 000,045,471 | ---- | C] () -- C:\Users\alex\Desktop\merkblatt_aug_2012.pdf
[2012.03.03 20:27:35 | 006,253,711 | ---- | C] () -- C:\Users\alex\Desktop\DSCI0035.JPG
[2012.03.03 20:26:49 | 006,253,711 | ---- | C] () -- C:\Users\alex\Desktop\DSCI0037.JPG
[2012.03.03 20:26:44 | 006,253,711 | ---- | C] () -- C:\Users\alex\Desktop\DSCI0034.JPG
[2012.03.03 20:26:38 | 006,253,711 | ---- | C] () -- C:\Users\alex\Desktop\DSCI0033.JPG
[2012.02.29 23:41:17 | 000,000,796 | ---- | C] () -- C:\Users\alex\Desktop\Eastern Front Launcher.lnk
[2012.02.29 21:15:10 | 000,008,478 | ---- | C] () -- C:\Users\alex\Desktop\g.odt
[2012.02.19 18:37:24 | 000,001,229 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011.09.02 13:12:33 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll
[2011.09.02 13:12:33 | 000,000,205 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.dll
[2011.06.15 23:37:30 | 000,137,344 | ---- | C] () -- C:\Windows\SysWow64\drivers\hwpsgt.sys
[2011.06.15 23:37:30 | 000,009,472 | ---- | C] () -- C:\Windows\SysWow64\drivers\lemsgt.sys
[2011.03.27 20:14:36 | 001,598,576 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.01.21 18:26:03 | 000,154,624 | ---- | C] () -- C:\Windows\unswat.exe
[2011.01.21 18:25:03 | 000,000,713 | ---- | C] () -- C:\Windows\SIERRA.INI
[2010.12.14 10:37:53 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
========== LOP Check ==========
[2011.04.09 19:37:46 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\2K Sports
[2012.02.06 22:37:18 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\A2 Entertainment
[2011.07.09 19:07:24 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Alarmstufe Rot 3 Der Aufstand
[2012.02.10 17:48:38 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Alawar
[2012.01.13 16:32:16 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Alawar Entertainment
[2011.06.15 21:01:01 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\aliasworlds
[2011.06.15 23:37:38 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Ascaron Entertainment
[2011.03.05 00:19:11 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Awem
[2011.02.21 10:58:25 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Be a King 2
[2011.01.10 12:23:23 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\BlamGames
[2011.01.31 16:43:21 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\CasualForge
[2010.12.12 16:18:57 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\DAEMON Tools Lite
[2012.01.02 16:04:40 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\dekovir
[2011.03.20 13:02:45 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\DivoGames
[2011.02.13 00:22:05 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Friday's games
[2011.05.07 13:16:15 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\GoldSunGames
[2011.06.26 17:13:06 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Green Clover Games
[2011.09.30 21:10:51 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\HdO Adventure
[2011.08.10 21:52:25 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\IBAGroup
[2011.06.16 10:24:09 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\InImages
[2011.06.13 10:12:19 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Islands2
[2011.11.18 11:31:56 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\JaiboGames
[2011.04.15 10:04:56 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Kalypso Media
[2012.03.15 11:33:52 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\kock
[2011.04.09 14:35:36 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Leadertech
[2012.02.21 16:30:22 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Meridian93
[2011.05.29 13:10:04 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Merscom
[2011.06.09 12:31:50 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\NevoSoft
[2010.12.03 21:47:06 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\OpenOffice.org
[2011.08.25 22:49:57 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\PathToSuccess_DE
[2011.06.23 12:32:38 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Ph03nixNewMedia
[2011.05.31 10:14:58 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\PlayFirst
[2012.01.27 11:31:37 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Playrix Entertainment
[2011.07.07 16:45:18 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Red Alert 3
[2011.02.16 10:17:16 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Roads Of Rome
[2011.02.03 11:06:50 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Rock Manager
[2011.02.21 10:58:46 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\RTS
[2011.03.30 20:43:19 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\The Creative Assembly
[2011.03.19 19:15:39 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Tropico 3
[2012.03.15 11:40:54 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\UAs
[2011.12.05 00:55:18 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Ubisoft
[2011.06.13 21:09:04 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\UClick
[2011.11.07 01:54:16 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\VC 2 Paradise Resort
[2011.11.23 14:52:51 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Virtual City
[2011.04.14 17:40:06 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\WB Games
[2011.08.26 10:17:13 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\WendigoStudios
[2012.01.07 18:33:03 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\Winter Sports 2011
[2011.05.19 08:31:30 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\World-Loom
[2012.03.15 11:40:54 | 000,000,000 | ---D | M] -- C:\Users\alex\AppData\Roaming\xmldm
[2011.12.07 12:16:08 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:D0AB0B4A
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:3B07E6F4
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:3571475C
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:C9BC8592
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:F5FC5DCE
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:06C34166
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:4A1628E5
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:04560D68
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:7AF9CAEB
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:12EA4DC9
< End of report > --- --- --- |