regina111 | 03.05.2012 19:09 | Hi,
vielen Dank erstmal für die Hilfe!!
Das Einfügen der Datei hat funktioniert, PC neugestartet, ohne die CD. Windows fährt hoch, Einloggen ist möglich. Hier ist die Log-Datei: Code:
OTL logfile created on: 5/3/2012 2:07:54 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,023.00 Mb Total Physical Memory | 813.00 Mb Available Physical Memory | 79.00% Memory free
907.00 Mb Paging File | 852.00 Mb Available in Paging File | 94.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 48.83 Gb Total Space | 22.28 Gb Free Space | 45.63% Space Free | Partition Type: NTFS
Drive D: | 184.05 Gb Total Space | 57.39 Gb Free Space | 31.18% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto] -- -- (yeaowuyi)
SRV - [2012/04/27 00:27:34 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/04/19 01:25:23 | 000,253,088 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2011/06/28 09:38:57 | 000,269,480 | ---- | M] (Avira GmbH) [Auto] -- C:\Programme\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011/05/01 01:37:21 | 000,136,360 | ---- | M] (Avira GmbH) [Auto] -- C:\Programme\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010/07/04 14:07:40 | 000,238,952 | ---- | M] (Teruten) [Auto] -- C:\WINDOWS\system32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2010/01/07 18:51:02 | 000,380,928 | ---- | M] (Spigot, Inc.) [Auto] -- C:\Programme\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2010/01/02 06:43:51 | 000,435,016 | ---- | M] (TuneUp Software) [On_Demand] -- C:\Programme\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2009/12/09 08:42:14 | 001,044,808 | ---- | M] (TuneUp Software) [Auto] -- C:\Programme\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2009/12/09 08:38:30 | 000,030,024 | ---- | M] (TuneUp Software) [Auto] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2008/11/03 20:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008/04/07 04:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand] -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2007/10/19 07:21:16 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto] -- C:\Programme\Gemeinsame Dateien\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)
SRV - [2007/10/19 07:19:22 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto] -- C:\Programme\Gemeinsame Dateien\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2007/10/19 07:17:28 | 000,186,904 | ---- | M] (Logitech Inc.) [Auto] -- C:\Programme\Gemeinsame Dateien\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer)
SRV - [2006/10/26 08:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2006/10/19 07:52:24 | 000,061,440 | ---- | M] (Hewlett-Packard Company) [Auto] -- C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe -- (LightScribeService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (InCDRm)
DRV - File not found [Kernel | System] -- -- (InCDPass)
DRV - File not found [Kernel | System] -- -- (i2omgmt)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - [2011/06/28 09:39:03 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011/06/28 09:39:03 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010/11/10 03:12:41 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\seehcri.sys -- (seehcri)
DRV - [2010/11/10 03:12:12 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2010/11/10 03:12:12 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ggflt.sys -- (ggflt)
DRV - [2010/06/14 04:32:54 | 000,036,608 | ---- | M] () [Kernel | On_Demand] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2010/04/26 22:25:20 | 000,132,424 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2010/04/26 22:25:20 | 000,104,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2010/04/26 22:25:20 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2009/10/14 02:24:44 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand] -- C:\Programme\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2009/05/11 06:49:19 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009/05/11 04:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2007/11/02 09:22:38 | 000,105,896 | ---- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\s217unic.sys -- (s217unic) Sony Ericsson Device 217 USB Ethernet Emulation SEMC217 (WDM)
DRV - [2007/11/02 09:22:38 | 000,103,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\s217mgmt.sys -- (s217mgmt) Sony Ericsson Device 217 USB WMC Device Management Drivers (WDM)
DRV - [2007/11/02 09:22:38 | 000,100,008 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\s217obex.sys -- (s217obex)
DRV - [2007/11/02 09:22:38 | 000,024,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\s217nd5.sys -- (s217nd5) Sony Ericsson Device 217 USB Ethernet Emulation SEMC217 (NDIS)
DRV - [2007/11/02 09:22:36 | 000,109,992 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\s217mdm.sys -- (s217mdm)
DRV - [2007/11/02 09:22:36 | 000,083,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\s217bus.sys -- (s217bus) Sony Ericsson Device 217 driver (WDM)
DRV - [2007/11/02 09:22:36 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\s217mdfl.sys -- (s217mdfl)
DRV - [2007/10/19 07:16:30 | 002,109,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Lvckap.sys -- (LVcKap)
DRV - [2007/10/11 22:00:42 | 000,041,752 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007/10/11 21:55:58 | 001,279,000 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2007/10/11 21:55:58 | 000,013,848 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
DRV - [2007/10/11 12:59:24 | 000,025,624 | ---- | M] () [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2007/10/11 12:59:02 | 002,142,488 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LVMVdrv.sys -- (LVMVDrv)
DRV - [2007/09/27 11:44:20 | 000,096,832 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2007/09/17 10:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2006/05/19 03:44:52 | 003,965,056 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2006/02/26 17:46:20 | 000,081,408 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2004/08/03 17:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) NT-Treiber für Realtek RTL8139(A/B/C)
DRV - [2004/04/30 03:37:02 | 000,160,640 | ---- | M] ( ) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\a347bus.sys -- (a347bus)
DRV - [2004/04/30 03:33:00 | 000,005,248 | ---- | M] ( ) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\a347scsi.sys -- (a347scsi)
DRV - [2003/03/25 05:50:46 | 000,004,096 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\siside.sys -- (SiSide)
DRV - [2002/10/17 03:14:46 | 000,049,024 | R--- | M] (Windows (R) 2000 DDK provider) [File_System | Boot] -- C:\WINDOWS\system32\drivers\sisidex.sys -- (sisidex)
DRV - [2002/08/20 05:19:08 | 000,009,472 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot] -- C:\WINDOWS\system32\drivers\sisperf.sys -- (sisperf)
DRV - [2001/08/17 08:51:32 | 000,018,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\irsir.sys -- (irsir)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Rick_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\Rick_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\Rick_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.ask.com/?l=dis&o=14672
IE - HKU\Rick_ON_C\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\Rick_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\Rick_ON_C\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\Rick_ON_C\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Programme\Search Settings\SearchSettings.dll (Spigot, Inc.)
IE - HKU\Rick_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\systemprofile_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Programme\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.3: C:\Programme\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Programme\Microsoft Silverlight\3.0.40818.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Programme\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012/04/27 00:27:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2012/04/11 05:08:11 | 000,000,000 | ---D | M]
[2012/02/23 04:35:17 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012/04/27 00:27:34 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2008/09/03 20:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Programme\mozilla firefox\plugins\npbittorrent.dll
[2010/04/22 01:14:38 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\mozilla firefox\plugins\npdeployJava1.dll
[2012/02/16 07:02:53 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/02/16 06:48:01 | 000,002,252 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2009/09/21 06:24:16 | 000,001,329 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\crawlersrch.xml
[2012/02/16 07:02:53 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2012/02/16 07:02:53 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/02/16 07:02:53 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/02/16 07:02:53 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2004/08/04 08:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (XTTBPos00 Class) - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Programme\ICQToolbar\toolbaru.dll (IE Toolbar)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Anmelde-Hilfsprogramm) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (SearchSettings Class) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Programme\Search Settings\SearchSettings.dll (Spigot, Inc.)
O3 - HKU\Rick_ON_C\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\Rick_ON_C\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKU\Rick_ON_C\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Programme\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Programme\Gemeinsame Dateien\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Programme\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SearchSettings] C:\Programme\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKU\Rick_ON_C..\Run: [AutoStartNPSAgent] C:\Programme\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKU\Rick_ON_C..\Run: [E45636AA] C:\WINDOWS\system32\2841E071E45636AA7121.exe ()
O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] File not found
O4 - HKU\.DEFAULT..\RunOnce: [TSClientMSIUninstaller] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\LocalService_ON_C..\RunOnce: [nltide_2] File not found
O4 - HKU\LocalService_ON_C..\RunOnce: [TSClientMSIUninstaller] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\LocalService_ON_C..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_C..\RunOnce: [nltide_2] File not found
O4 - HKU\NetworkService_ON_C..\RunOnce: [TSClientMSIUninstaller] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_C..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\systemprofile_ON_C..\RunOnce: [nltide_2] File not found
O4 - HKU\systemprofile_ON_C..\RunOnce: [TSClientMSIUninstaller] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\systemprofile_ON_C..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegedit = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Rick_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\Rick_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\Rick_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
O7 - HKU\Rick_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\Rick_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\Rick_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKU\Rick_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\Rick_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKU\Rick_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\Rick_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1
O7 - HKU\Rick_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O7 - HKU\Rick_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\Rick_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegedit = 1
O7 - HKU\systemprofile_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Programme\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1192988956187 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1192988947546 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\2841E071E45636AA7121.exe) - C:\WINDOWS\system32\2841E071E45636AA7121.exe ()
O27 - HKLM IFEO\msconfig.exe: Debugger - P9KDMF.EXE File not found
O27 - HKLM IFEO\regedit.exe: Debugger - P9KDMF.EXE File not found
O27 - HKLM IFEO\taskmgr.exe: Debugger - P9KDMF.EXE File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/10/21 13:00:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/05/03 00:41:48 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\Rick\Recent
[2012/05/03 00:34:26 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\Rrrrrr
[2012/05/03 00:33:24 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Rick\Desktop\Lieferschein
[2012/05/01 13:07:42 | 000,000,000 | ---D | C] -- C:\Programme\uTorrent
[2012/05/01 13:07:06 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\uTorrent
[2012/04/29 09:28:26 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Rick\Desktop\Neuer Ordner
[2012/04/29 09:18:50 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Rick\Desktop\ebay
[2012/04/29 08:57:34 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Rick\Desktop\bilder ebay
[2012/04/27 00:27:39 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Mozilla
[2012/04/27 00:27:38 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Maintenance Service
[2012/04/23 01:24:48 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Rick\Startmenü\Programme\Google Chrome
[2012/04/10 01:32:26 | 000,418,464 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/04/07 01:32:09 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\Rick\Desktop\www.torrent.to...German_TOP100_Single_Charts_02_04_2012-MCG
[2007/10/22 05:42:39 | 000,160,640 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347bus.sys
[2007/10/22 05:42:39 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347scsi.sys
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Dokumente und Einstellungen\Rick\*.tmp files -> C:\Dokumente und Einstellungen\Rick\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/05/03 04:39:01 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/05/03 03:28:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/05/03 03:21:50 | 000,000,496 | ---- | M] () -- C:\WINDOWS\tasks\Automatische Problemsuche.job
[2012/05/03 03:11:24 | 000,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2012/05/03 00:54:00 | 000,001,769 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Logitech QuickCam.lnk
[2012/05/03 00:54:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Logitech
[2012/05/03 00:46:49 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata19.sqm.dddd
[2012/05/03 00:46:49 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata18.sqm.pppp
[2012/05/03 00:46:49 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata17.sqm.iiii
[2012/05/03 00:46:49 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata16.sqm.uvvv
[2012/05/03 00:46:49 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata15.sqm.mmmm
[2012/05/03 00:46:49 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata14.sqm.aaaa
[2012/05/03 00:46:49 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata13.sqm.uuuu
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt19.sqm.onnn
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt18.sqm.ffff
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt17.sqm.dddd
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt16.sqm.nooo
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt15.sqm.paaa
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt14.sqm.tttt
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt13.sqm.cyyy
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt12.sqm.zrrr
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt11.sqm.cccc
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt10.sqm.leee
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt09.sqm.jqqq
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt08.sqm.xxxx
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt07.sqm.ffff
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt06.sqm.llll
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt05.sqm.dfff
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt04.sqm.rggg
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt03.sqm.kwww
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt02.sqm.slll
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt01.sqm.jjjj
[2012/05/03 00:46:49 | 000,000,244 | ---- | M] () -- C:\locked-sqmnoopt00.sqm.hhhh
[2012/05/03 00:46:48 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata12.sqm.pppp
[2012/05/03 00:46:48 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata11.sqm.mmmm
[2012/05/03 00:46:48 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata10.sqm.mppp
[2012/05/03 00:46:48 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata09.sqm.qqqq
[2012/05/03 00:46:48 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata08.sqm.pppp
[2012/05/03 00:46:48 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata07.sqm.ibbb
[2012/05/03 00:46:48 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata06.sqm.paaa
[2012/05/03 00:46:48 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata05.sqm.pppp
[2012/05/03 00:46:48 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata04.sqm.buui
[2012/05/03 00:46:48 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata03.sqm.bbbb
[2012/05/03 00:46:48 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata02.sqm.uvvv
[2012/05/03 00:46:48 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata01.sqm.pmmp
[2012/05/03 00:46:48 | 000,000,268 | ---- | M] () -- C:\locked-sqmdata00.sqm.zrrr
[2012/05/03 00:46:44 | 000,000,539 | ---- | M] () -- C:\locked-IPH.PH.biii
[2012/05/03 00:45:56 | 007,411,096 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Eigene Dateien\locked-R94481.EXE.zrrr
[2012/05/03 00:45:55 | 004,255,056 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Eigene Dateien\locked-R79733.EXE.nhhh
[2012/05/03 00:45:55 | 002,944,016 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Eigene Dateien\locked-R58201.EXE.yyyy
[2012/05/03 00:45:55 | 001,283,448 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Eigene Dateien\locked-R78727.EXE.xttt
[2012/05/03 00:45:11 | 007,411,096 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Eigene Dateien\locked-dell.nnnn
[2012/05/03 00:45:10 | 078,514,560 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Eigene Dateien\locked-175.16_geforce_winxp_32bit_international_whql.exe.zzrz
[2012/05/03 00:45:07 | 005,477,972 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-Sean Paul 'She Doesn't Mind' [AUDIO].mp3.cyyy
[2012/05/03 00:45:07 | 000,879,984 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-uTorrent_3.1.3.27120.exe.rzzz
[2012/05/03 00:45:04 | 005,400,230 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-RIO Like I Love You.mp3.hnnn
[2012/05/03 00:45:02 | 173,838,160 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-New_PC_Studio_1.5.1.10064_2.exe.yccc
[2012/05/03 00:44:57 | 002,171,023 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-Mia und Leo.JPG.fyyy
[2012/05/03 00:44:57 | 001,570,849 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-mia.JPG.rggg
[2012/05/03 00:44:57 | 000,808,878 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-Lukas.jpg.cyyy
[2012/05/03 00:44:11 | 007,760,776 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-Jason Derulo - It Girl.mp3.appp
[2012/05/03 00:44:11 | 005,623,420 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-Jason Derulo Breathing Offiicial Song.mp3.biii
[2012/05/03 00:44:11 | 000,346,070 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-Jason Derulo.mp3.hhhh
[2012/05/03 00:44:09 | 005,573,265 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-Fort Minor Where'd You Go (feat Holly Brook Jonah Matranga).mp3.hnnn
[2012/05/03 00:44:04 | 023,957,048 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-chrome_installer.exe.slll
[2012/05/03 00:44:04 | 002,138,530 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-CIMG1050.JPG.kkkk
[2012/05/03 00:44:04 | 002,075,985 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-CIMG1049.JPG.vuuu
[2012/05/03 00:43:56 | 006,025,216 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-56 - Journey - Who's Crying Now.mp3.cccc
[2012/05/03 00:43:56 | 000,022,649 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-58937_eA.jpg.oooo
[2012/05/03 00:43:54 | 008,648,450 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-001 - Rihanna - We found love.mp3.vvuu
[2012/05/03 00:43:54 | 000,000,169 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\locked-default.pls.cyyy
[2012/05/03 00:43:49 | 000,000,037 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\locked-Spin Chat Preferences.hnnn
[2012/05/03 00:43:39 | 000,000,760 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\locked-setup_ldm.iss.fddd
[2012/05/03 00:41:53 | 000,000,079 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\locked-Desktop anzeigen.scf.fyyy
[2012/05/03 00:36:06 | 000,006,543 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\locked-.recently-used.xbel.rggg
[2012/05/03 00:34:40 | 000,000,305 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\locked-addr_file.html.lsss
[2012/05/03 00:34:40 | 000,000,040 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\locked-.zreglib.grrr
[2012/05/03 00:33:46 | 000,054,784 | -H-- | M] () -- C:\WINDOWS\System32\2841E071E45636AA7121.exe
[2012/05/03 00:29:13 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/05/02 00:40:44 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/05/01 13:07:43 | 000,000,628 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/05/01 13:07:43 | 000,000,610 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\µTorrent.lnk
[2012/04/30 11:29:50 | 000,481,078 | ---- | M] () -- C:\WINDOWS\System32\winsh321
[2012/04/30 11:29:30 | 000,481,078 | ---- | M] () -- C:\WINDOWS\System32\winsh320
[2012/04/30 11:28:00 | 000,481,078 | ---- | M] () -- C:\WINDOWS\System32\winsh323
[2012/04/30 11:26:42 | 000,481,078 | ---- | M] () -- C:\WINDOWS\System32\winsh322
[2012/04/28 15:19:22 | 000,141,312 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/26 12:38:10 | 000,481,078 | ---- | M] () -- C:\WINDOWS\System32\winsh325
[2012/04/26 12:37:48 | 000,481,078 | ---- | M] () -- C:\WINDOWS\System32\winsh324
[2012/04/23 01:24:50 | 000,002,357 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Desktop\Google Chrome.lnk
[2012/04/23 01:24:50 | 000,002,335 | ---- | M] () -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/04/21 18:15:21 | 000,000,476 | ---- | M] () -- C:\WINDOWS\tasks\Automatische Wartung.job
[2012/04/19 01:25:23 | 000,418,464 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/04/19 01:25:23 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/04/14 07:00:50 | 000,004,662 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2012/04/14 06:54:15 | 000,000,255 | ---- | M] () -- C:\WINDOWS\wcx_ftp.ini
[2012/04/11 05:08:12 | 000,002,347 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Adobe Reader 9.lnk
[2012/04/11 05:08:12 | 000,001,709 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader 9.lnk
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Dokumente und Einstellungen\Rick\*.tmp files -> C:\Dokumente und Einstellungen\Rick\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/05/03 00:54:00 | 000,001,769 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Logitech QuickCam.lnk
[2012/05/03 00:34:33 | 000,481,078 | ---- | C] () -- C:\WINDOWS\System32\winsh325
[2012/05/03 00:34:33 | 000,481,078 | ---- | C] () -- C:\WINDOWS\System32\winsh324
[2012/05/03 00:34:33 | 000,481,078 | ---- | C] () -- C:\WINDOWS\System32\winsh323
[2012/05/03 00:34:33 | 000,481,078 | ---- | C] () -- C:\WINDOWS\System32\winsh322
[2012/05/03 00:34:33 | 000,481,078 | ---- | C] () -- C:\WINDOWS\System32\winsh321
[2012/05/03 00:34:33 | 000,481,078 | ---- | C] () -- C:\WINDOWS\System32\winsh320
[2012/05/03 00:33:46 | 000,054,784 | -H-- | C] () -- C:\WINDOWS\System32\2841E071E45636AA7121.exe
[2012/05/01 13:07:43 | 000,000,628 | ---- | C] () -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/05/01 13:07:43 | 000,000,610 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\µTorrent.lnk
[2012/05/01 13:06:54 | 000,879,984 | ---- | C] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-uTorrent_3.1.3.27120.exe.rzzz
[2012/04/23 01:24:50 | 000,002,357 | ---- | C] () -- C:\Dokumente und Einstellungen\Rick\Desktop\Google Chrome.lnk
[2012/04/23 01:24:50 | 000,002,335 | ---- | C] () -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/04/11 05:08:12 | 000,001,709 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader 9.lnk
[2012/04/10 01:32:27 | 000,000,884 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/04/06 16:29:16 | 005,573,265 | ---- | C] () -- C:\Dokumente und Einstellungen\Rick\Desktop\locked-Fort Minor Where'd You Go (feat Holly Brook Jonah Matranga).mp3.hnnn
[2011/04/26 05:08:14 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/11/09 04:18:04 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/11/09 04:18:04 | 000,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/11/09 04:17:51 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\$_hpcst$.hpc
[2010/07/15 01:06:16 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2010/01/09 07:04:39 | 000,000,760 | ---- | C] () -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\locked-setup_ldm.iss.fddd
[2009/12/23 05:50:52 | 000,000,037 | ---- | C] () -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\locked-Spin Chat Preferences.hnnn
[2009/11/13 05:23:18 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2009/06/07 07:27:20 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\vbzlib1.dll
[2009/04/29 08:37:53 | 000,059,500 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/02/18 05:01:30 | 000,418,816 | ---- | C] () -- C:\WINDOWS\System32\wlsppc.dll
[2009/01/19 17:44:24 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2008/11/14 14:43:39 | 000,006,543 | ---- | C] () -- C:\Dokumente und Einstellungen\Rick\locked-.recently-used.xbel.rggg
[2008/11/10 06:41:05 | 000,000,040 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\locked-.zreglib.grrr
[2008/11/10 06:40:39 | 000,034,308 | ---- | C] () -- C:\WINDOWS\System32\Chip.dll
[2008/03/19 14:48:07 | 000,000,034 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/11/06 02:54:00 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2007/10/31 19:56:20 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/10/30 04:19:00 | 000,000,101 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2007/10/26 01:20:34 | 000,000,169 | ---- | C] () -- C:\Dokumente und Einstellungen\Rick\locked-default.pls.cyyy
[2007/10/25 12:26:10 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/10/21 16:15:41 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS78.DLL
[2007/10/21 15:12:48 | 000,000,255 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2007/10/21 14:03:52 | 000,001,261 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2007/10/21 13:53:30 | 000,004,662 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2007/10/21 13:50:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2007/10/21 13:50:26 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2007/10/21 13:49:06 | 000,266,208 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2007/10/21 13:48:08 | 000,000,305 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\locked-addr_file.html.lsss
[2007/10/21 13:43:54 | 000,141,312 | ---- | C] () -- C:\Dokumente und Einstellungen\Rick\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/10/21 13:42:51 | 000,000,008 | ---- | C] () -- C:\WINDOWS\System32\nvModes.dat
[2007/10/21 13:09:04 | 000,040,960 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2007/10/21 13:08:43 | 000,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2007/10/21 13:08:37 | 000,000,164 | R--- | C] () -- C:\WINDOWS\avrack.ini
[2007/10/21 13:06:28 | 000,139,264 | R--- | C] () -- C:\WINDOWS\System32\IDEproperty.dll
[2007/10/21 13:01:50 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2007/10/21 12:56:20 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2007/10/21 12:55:56 | 000,271,264 | ---- | C] () -- C:\WINDOWS\System32\vbrun100.dll
[2007/10/11 12:59:24 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2006/11/17 05:29:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006/11/17 05:29:00 | 001,622,016 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2006/11/17 05:29:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006/11/17 05:29:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2006/11/17 05:29:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006/11/17 05:29:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006/11/17 05:29:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006/11/17 05:29:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2006/11/17 05:29:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2006/11/17 05:29:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006/11/17 05:29:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2004/08/04 08:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/04 08:00:00 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2004/08/04 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 08:00:00 | 000,452,310 | ---- | C] () -- C:\WINDOWS\System32\perfh007.dat
[2004/08/04 08:00:00 | 000,435,396 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/04 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 08:00:00 | 000,269,480 | ---- | C] () -- C:\WINDOWS\System32\perfi007.dat
[2004/08/04 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 08:00:00 | 000,081,118 | ---- | C] () -- C:\WINDOWS\System32\perfc007.dat
[2004/08/04 08:00:00 | 000,068,292 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/04 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 08:00:00 | 000,034,478 | ---- | C] () -- C:\WINDOWS\System32\perfd007.dat
[2004/08/04 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 08:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 08:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/04 08:00:00 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/08/04 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2010/05/18 08:41:28 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config\systemprofile\Anwendungsdaten\Application Updater
[2008/03/19 14:45:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\AD ON Multimedia
[2012/03/13 05:55:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\AnvSoft
[2012/05/03 00:40:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\BitTorrent
[2007/10/30 09:43:16 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\CD-LabelPrint
[2011/07/05 01:31:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\com.socialbox.socialbox
[2012/05/03 00:40:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\FileZilla
[2010/05/18 08:41:24 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\FreeVideoConverter
[2012/05/03 00:40:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\FRITZ!
[2008/11/14 14:43:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\gtk-2.0
[2010/10/22 11:48:30 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\ICQ
[2007/10/23 01:48:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\ICQ Toolbar
[2012/05/03 00:41:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\LimeWire
[2011/08/20 05:47:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\OpenCandy
[2010/11/09 04:20:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\PC Suite
[2012/05/03 00:34:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\Rrrrrr
[2012/01/01 10:39:31 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\Samsung
[2010/05/18 10:13:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\Search Settings
[2011/04/26 05:05:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\Shareaza
[2010/01/02 06:42:25 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\TuneUp Software
[2012/05/03 00:50:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\uTorrent
[2011/01/07 04:12:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\Rick\Anwendungsdaten\XMedia Recode
[2007/11/01 07:21:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Buena Vista Games
[2007/10/21 16:15:04 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\CanonBJ
[2009/12/16 08:50:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ICQ
[2010/11/09 04:20:51 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Suite
[2011/12/30 11:18:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Samsung
[2008/11/10 05:50:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SlySoft
[2008/05/29 05:38:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Sony
[2012/03/13 09:39:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
[2010/01/02 06:42:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software
[2008/02/06 11:27:31 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Viewpoint
[2012/05/03 00:35:54 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2012/05/03 03:21:50 | 000,000,496 | ---- | M] () -- C:\WINDOWS\Tasks\Automatische Problemsuche.job
[2012/04/21 18:15:21 | 000,000,476 | ---- | M] () -- C:\WINDOWS\Tasks\Automatische Wartung.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 163 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:FB1B13D8
@Alternate Data Stream - 16 bytes -> C:\Dokumente und Einstellungen\Rick\Eigene Dateien\Shareaza Downloads:Shareaza.GUID
@Alternate Data Stream - 150 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:D1B5B4F1
< End of report > Die Dateien sind zum Teil immernoch gelocked. Wie geht es weiter? |