![]() |
Anzeige:
|
|
|||||||
| Viren-Forum über Viren, Dialer, Trojaner, Spyware etc. |
|
![]() |
|
|
LinkBack | Themen-Optionen | Ansicht |
|
|
#1 (Direktlink) |
|
War schon mal da
![]() Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
|
Guten Tag
ich bin hier neu registriert, war aber schon oft als Gast hier. Nun habe ich eine Frage: Beim Neustart des Systems kommt automatisch der abgesicherte Modus. Gibt es eine Möglichkeit, diesen abzuschalten und bei Bedarf auf F8 beim Starten zurückzugreifen? Liebe Grüße lillimucki P.S. Windows Vista Home Premium 32bit |
|
|
|
|
|
|
#2 (Direktlink) |
|
Super-Moderator
![]() Registriert seit: 31.10.2005
Ort: N51°26'24''E8°22'42''
Beiträge: 10.173
|
Hallo
Frage ist wieso kommt es nach dem Neustart dazu das der Rechner abgesichert bootet ? Hast du am System etwas geändert und seit wann hast du das Problem ? Hast du im Gerätemanager Warneinträge in Form von ? oder !
__________________
viele Grüsse von sea ![]() ---------------------------------------------------------------------- SUPPORTER DES MONATS FEBRUAR 2010 von PCVISIT ---------------------------------------------------------------------- meine Homepage: http://www.pcdietmar.info Biete auf Wunsch kostenlose Fernwartung/Diagnose per PC Visit an |
|
|
|
|
|
#3 (Direktlink) |
|
War schon mal da
![]() Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
|
Hallo sea
das Problem tritt nur beim Neustart auf. Nicht beim normalen Hochfahren. Es besteht seit ca 3 Wochen. Gestern machte ich einen kompletten Virenscan mit Avast Pro und es wurde 1 infizierte Datei gefunden. Der Versuch über Wiederherstellung vor diesem Zeitraum hat keine Änderung gebracht. Es ist nur lästig, jedesmal den "normalen Start" anzuklicken. Liebe Grüße lillimucki |
|
|
|
|
|
#4 (Direktlink) |
|
Super-Moderator
![]() Registriert seit: 31.10.2005
Ort: N51°26'24''E8°22'42''
Beiträge: 10.173
|
Hallo
![]() Wenn ein Virenverdacht vorliegt sollte das mal genauer unter die Lupe genommen werden.Ich schieb den Beitrag in den Virenbereich. Dort meldet sich dann ein Virenmoderator mit weiteren Anweisungen.
__________________
viele Grüsse von sea ![]() ---------------------------------------------------------------------- SUPPORTER DES MONATS FEBRUAR 2010 von PCVISIT ---------------------------------------------------------------------- meine Homepage: http://www.pcdietmar.info Biete auf Wunsch kostenlose Fernwartung/Diagnose per PC Visit an |
|
|
|
|
|
#5 (Direktlink) |
|
Super-Moderator
![]() Registriert seit: 08.02.2010
Beiträge: 1.728
|
Hallo,
Gehe auf Start --> Gebe unten in der Leiste msconfig ein --> Drücke die Taste Enter --> Wähle im Fenster den Reiter Start aus --> Erstelle ein Screenshot --> "Poste" das Bild. Außerdem reiche das Log mit der Virenmeldung von Avast nach.
__________________
Gruß Leo
|
|
|
|
|
|
|
#6 (Direktlink) |
|
War schon mal da
![]() Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
|
Hallo Leo
hier sind die Bilder: ![]() Das Avast-Protokoll ![]() und das erschien eben noch obendrein: ![]() Vielen Dank für die Hilfe Liebe Grüße lillimucki |
|
|
|
|
|
#7 (Direktlink) |
|
Super-Moderator
![]() Registriert seit: 08.02.2010
Beiträge: 1.728
|
Hm, benutzt du ThreatFire?
Schritt 1 Malwarebytes Anti-Malware Download (Free Version): Malwarebytes : Malwarebytes Anti-Malware is a free download that removes viruses and malware from your computer
Schritt 2 OTL Download: http://oldtimer.geekstogo.com/OTL.exe 1. Doppelklick auf die OTL.exe 2. User von Windows 7 und Vista: Rechtsklick als Administrator ausführen 3. Oben findest Du ein Kästchen mit Ausgabe. Wähle bitte Minimal-Ausgabe 4. Setze einen Haken Oben bei Scanne alle Benutzer. 5. Unter "Extra Registrierung wähle "Benutze SafeList" 6. Rechts unten Haken setzen bei "LOP Prüfung" und "Purity Prüfung " 7. Kopiere in die Textbox (ohen das Wort Code: ) Code:
netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll logevent.dll iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT 8. Klicke "Scan" Es werden 2 Reporte erstellt: OTL.Txt sowie Extras.Txt Bitte beide Logs Posten!
__________________
Gruß Leo
|
|
|
|
|
|
#8 (Direktlink) |
|
War schon mal da
![]() Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
|
Hallo Leoja, ich nutzeThreatFire. Ist das nicht gut?
Hier sind dann die Logfiles. OTL.txt OTL logfile created on: 28.04.2011 20:52:00 - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Downloads Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 0,00 Gb Available Physical Memory | 20,00% Memory free 6,00 Gb Paging File | 4,00 Gb Available in Paging File | 72,00% Paging File free Paging file location(s): c:\pagefile.sys 4092 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 143,19 Gb Total Space | 61,37 Gb Free Space | 42,86% Space Free | Partition Type: NTFS Drive D: | 5,86 Gb Total Space | 0,82 Gb Free Space | 13,97% Space Free | Partition Type: NTFS Drive J: | 1,88 Gb Total Space | 0,11 Gb Free Space | 5,58% Space Free | Partition Type: FAT Computer Name: HEINER-PC | User Name: Heiner | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software) PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software) PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe (Uniblue Systems Limited) PRC - C:\Program Files\Klebezettel NG\klebez.exe (Hollie-Soft) PRC - C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.) PRC - C:\Program Files\Application Updater\ApplicationUpdater.exe (Spigot, Inc.) PRC - C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (Deutsche Telekom AG) PRC - C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) PRC - C:\Program Files\epson\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION) PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe (Speedbit Ltd.) PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe (Speedbit Ltd.) PRC - C:\D - PROGRAMME\AmP\AmP.exe (Mirko Böer) PRC - C:\Program Files\ThreatFire\TFTray.exe (PC Tools) PRC - C:\Program Files\ThreatFire\TFService.exe (PC Tools) PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe () PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe () PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.) PRC - C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe (Blue Onion Software) PRC - C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe (Prolific Technology Inc.) PRC - C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe (Jay Elaraj) PRC - C:\Windows\System32\spool\drivers\w32x86\3\E_FATIEDE.EXE (SEIKO EPSON CORPORATION) PRC - C:\Windows\System32\iashost.exe (Microsoft Corporation) PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation) PRC - C:\Windows\System32\PSIService.exe () ========== Modules (SafeList) ========== MOD - C:\Downloads\OTL.exe (OldTimer Tools) MOD - C:\Program Files\Alwil Software\Avast5\snxhk.dll (AVAST Software) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation) MOD - C:\Program Files\ThreatFire\TFWAH.dll (PC Tools) ========== Win32 Services (SafeList) ========== SRV - (WinExit-Service-Launcher) -- File not found SRV - (TS) -- File not found SRV - (KWOGC) -- File not found SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software) SRV - (JetDrive WindowsClosingService) -- C:\Windows\System32\WindowsClosingService.exe () SRV - (Application Updater) -- C:\Program Files\Application Updater\ApplicationUpdater.exe (Spigot, Inc.) SRV - (Netzmanager Service) -- C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (Deutsche Telekom AG) SRV - (EpsonCustomerResearchParticipation) -- C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION) SRV - (MatSvc) -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation) SRV - (VideoAcceleratorService) -- C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe (Speedbit Ltd.) SRV - (ThreatFire) -- C:\Program Files\ThreatFire\TFService.exe (PC Tools) SRV - (nSvcIp) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe () SRV - (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe () SRV - (SBSDWSCService) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.) SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.) SRV - (PLFlash DeviceIoControl Service) -- C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe (Prolific Technology Inc.) SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (LPDSVC) -- C:\Windows\System32\lpdsvc.dll (Microsoft Corporation) SRV - (WPEServ) -- C:\Program Files\Common Files\wpe\wpeserv.exe (soft Xpansion) SRV - (CLTNetCnService) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation) SRV - (ccSetMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation) SRV - (ccEvtMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation) SRV - (ProtexisLicensing) -- C:\Windows\System32\PSIService.exe () ========== Driver Services (SafeList) ========== DRV - (aswSnx) -- C:\Windows\System32\drivers\aswSnx.sys (AVAST Software) DRV - (aswSP) -- C:\Windows\System32\drivers\aswSP.sys (AVAST Software) DRV - (aswTdi) -- C:\Windows\System32\drivers\aswTdi.sys (AVAST Software) DRV - (aswRdr) -- C:\Windows\System32\drivers\aswRdr.sys (AVAST Software) DRV - (aswMonFlt) -- C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software) DRV - (aswFsBlk) -- C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software) DRV - (jetdrive) -- C:\Windows\System32\drivers\jddrv.sys (Abelssoft GmbH) DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation) DRV - (MBAMSwissArmy) -- C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation) DRV - (TelekomNM3) -- C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) DRV - (MTOnlPktAlyX) -- C:\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\MTOnlPktAlyx.sys (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) DRV - (LUsbFilt) -- C:\Windows\System32\drivers\LUsbFilt.sys (Logitech, Inc.) DRV - (LMouFilt) -- C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.) DRV - (LHidFilt) -- C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.) DRV - (NVNET) -- C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation) DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation) DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys () DRV - (Uim_IM) -- C:\Windows\System32\drivers\Uim_IM.sys (Paragon) DRV - (UimBus) -- C:\Windows\System32\drivers\UimBus.sys (Windows (R) 2000 DDK provider) DRV - (hotcore3) -- C:\Windows\system32\DRIVERS\hotcore3.sys (Paragon Software Group) DRV - (TfSysMon) -- C:\Windows\system32\drivers\TfSysMon.sys (PC Tools) DRV - (TfNetMon) -- C:\Windows\System32\drivers\TfNetMon.sys (PC Tools) DRV - (TfFsMon) -- C:\Windows\system32\drivers\TfFsMon.sys (PC Tools) DRV - (nvstor32) -- C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation) DRV - (RMCAST) RMCAST (Pgm) -- C:\Windows\System32\drivers\rmcast.sys (Microsoft Corporation) DRV - (kbfiltr) -- C:\Windows\System32\drivers\kbfiltr.sys ( ) DRV - (PSI) -- C:\Windows\System32\drivers\psi_mf.sys (Secunia) DRV - (SymEvent) -- C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation) DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation) DRV - (StarOpen) -- C:\Windows\System32\drivers\StarOpen.sys () DRV - (SYMTDI) -- C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation) DRV - (SymIMMP) -- C:\Windows\System32\drivers\SymIM.sys (Symantec Corporation) DRV - (SymIM) -- C:\Windows\System32\drivers\SymIM.sys (Symantec Corporation) DRV - (KS-959) -- C:\Windows\System32\drivers\KS-959.sys (Kingsun Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files\Winload\tbWin0.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {73c7d5b0-7b03-444a-84c7-ce1ba03b5573} - C:\Program Files\Foxit\tbFoxi.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA0.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - Reg Error: Key error. File not found IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = Google Toolbar IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = Google IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Miro Start IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://search.conduit.com?SearchSour...ctid=CT2475029 IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TF = http://search.conduit.com?SearchSour...ctid=CT2431245 IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Google Toolbar IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Google Toolbar IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files\Winload\tbWin0.dll (Conduit Ltd.) IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA0.dll (Conduit Ltd.) IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.) IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - Reg Error: Key error. File not found IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - HKLM\software\mozilla\Firefox\Extensions\\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}: C:\Program Files\SpeedBit Video Downloader\SPFireFox FF - HKLM\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011.04.27 14:02:37 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6b2\extensions\\Components: C:\Program Files\Mozilla Firefox 3.6 Beta 1\components [2010.12.23 11:19:30 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6b2\extensions\\Plugins: C:\Program Files\Mozilla Firefox 3.6 Beta 1\plugins [2011.04.26 16:23:16 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.22 17:13:43 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.04.26 16:23:16 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011.04.11 12:56:22 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2011.04.26 16:23:17 | 000,000,000 | ---D | M] [2009.12.28 10:49:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Extensions [2009.12.28 10:49:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2011.04.28 20:47:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions [2011.03.11 10:21:27 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2011.01.19 10:56:46 | 000,000,000 | ---D | M] (Resurrect Pages) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{0c8fbd76-bdeb-4c52-9b24-d587ce7b9dc3} [2011.04.21 12:21:59 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{1018e4d6-728f-4b20-ad56-37578a4de76b} [2011.01.14 09:34:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{1280606b-2510-4fe0-97ef-9b5a22eafe80} [2011.01.06 10:32:28 | 000,000,000 | ---D | M] (Image Zoom) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68} [2009.08.11 08:35:02 | 000,000,000 | ---D | M] (Minimap Addon) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{398e77b8-2304-11dc-8314-0800200c9a66} [2011.03.22 21:44:44 | 000,000,000 | ---D | M] (Winload Community Toolbar) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{40c3cc16-7269-4b32-9531-17f2950fb06f} [2009.09.09 08:18:15 | 000,000,000 | ---D | M] ("Picnik") -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{5b1fdac4-a239-4933-9c52-b65a2a720b75} [2011.03.23 11:34:01 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2011.04.07 06:35:21 | 000,000,000 | ---D | M] (iMacros for Firefox) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2011.04.18 22:22:28 | 000,000,000 | ---D | M] (Nightly Tester Tools) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29} [2011.01.06 10:32:29 | 000,000,000 | ---D | M] (Context Search) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{902D2C4A-457A-4EF9-AD43-7014562929FF} [2011.03.02 23:38:05 | 000,000,000 | ---D | M] (Password Exporter) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492} [2011.04.02 22:02:39 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2011.03.02 23:38:05 | 000,000,000 | ---D | M] (Bargain Book Mole) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{c7b204cd-707e-4d13-b5c4-8eb3ce6f3f52} [2010.11.16 21:04:21 | 000,000,000 | ---D | M] (COMPUTERBILD-Abzockschutz) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{d49175b3-3fd8-43b8-b28e-da5d47f3c398} [2011.03.08 09:31:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{dc572301-7619-498c-a57d-39143191b318} [2011.04.07 23:01:18 | 000,000,000 | ---D | M] (BitDefender QuickScan) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{e001c731-5e37-4538-a5cb-8168736a2360} [2011.03.16 09:37:24 | 000,000,000 | ---D | M] (Menu Editor) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{EDA7B1D7-F793-4e03-B074-E6F303317FB0} [2011.03.23 21:24:24 | 000,000,000 | ---D | M] (FoxLingo) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66} [2011.04.09 16:34:53 | 000,000,000 | ---D | M] (New Tab King) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{FC5BAC7D-D696-4ba6-B913-CF8F000C33DF} [2010.11.02 11:53:45 | 000,000,000 | ---D | M] (BarTab) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\bartap@philikon.de [2010.11.19 08:10:01 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\de-DE@dictionaries.addons.mozilla.org [2011.03.23 11:33:55 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\engine@conduit.com [2011.03.16 09:46:03 | 000,000,000 | ---D | M] (Mein Gutscheincode Finder) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\finder@meingutscheincode.de [2010.12.29 08:53:01 | 000,000,000 | ---D | M] (Read It Later) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\isreaditlater@ideashower.com [2010.12.11 22:23:26 | 000,000,000 | ---D | M] ("It's All Text!") -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\itsalltext@docwhat.gerf.org [2011.01.12 09:13:20 | 000,000,000 | ---D | M] (NoSquint) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\nosquint@urandom.ca [2011.03.02 23:38:05 | 000,000,000 | ---D | M] (Puzzle) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\puzzle@internauta1024a.pl [2011.03.02 23:38:05 | 000,000,000 | ---D | M] (SkipScreen) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\SkipScreen@SkipScreen [2011.04.28 20:47:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\staged [2011.04.03 20:06:18 | 000,000,000 | ---D | M] (Foxit PDF Creator Toolbar) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\toolbar@ask.com [2011.03.08 09:31:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{dc572301-7619-498c-a57d-39143191b318}\modules\extensions [2008.04.14 17:57:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Sunbird\Profiles\4j8vuwrs.default\extens ions [2011.03.21 18:52:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2010.05.12 07:54:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2011.01.18 11:52:02 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2011.03.11 09:00:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011.03.22 17:13:29 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll [2011.02.02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll [2010.10.19 09:17:16 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll [2007.03.05 14:59:06 | 000,645,504 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll [2007.03.10 01:16:44 | 000,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll [2006.09.26 12:03:14 | 000,098,304 | ---- | M] (Zylom) -- C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll [2011.03.22 17:13:33 | 000,001,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom-de.xml [2011.03.22 17:13:33 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml [2011.03.22 17:13:33 | 000,001,153 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-de.xml [2011.03.22 17:13:33 | 000,006,805 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml [2011.03.22 17:13:33 | 000,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-de.xml [2011.03.22 17:13:33 | 000,001,105 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-de.xml O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) O2 - BHO: (CescrtHlpr Object) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\bh\BabylonToolbar.dll (Babylon BHO) O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O2 - BHO: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files\Winload\tbWin0.dll (Conduit Ltd.) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Foxit Toolbar) - {73c7d5b0-7b03-444a-84c7-ce1ba03b5573} - C:\Program Files\Foxit\tbFoxi.dll (Conduit Ltd.) O2 - BHO: (MyAshampoo Toolbar) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA0.dll (Conduit Ltd.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll (Google Inc.) O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.) O2 - BHO: (no name) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - No CLSID value found. O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0744.0\msneshellx.dll (Microsoft Corp.) O2 - BHO: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O2 - BHO: (no name) - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - No CLSID value found. O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc) O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files\Winload\tbWin0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Foxit Toolbar) - {73c7d5b0-7b03-444a-84c7-ce1ba03b5573} - C:\Program Files\Foxit\tbFoxi.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (no name) - {77709987-486F-4210-BE78-328303B8691C} - No CLSID value found. O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll (Babylon Ltd.) O3 - HKLM\..\Toolbar: (MyAshampoo Toolbar) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.) O3 - HKLM\..\Toolbar: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) O3 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\Toolbar\WebBrowser: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\Toolbar\WebBrowser: (Winload Toolbar) - {40C3CC16-7269-4B32-9531-17F2950FB06F} - C:\Program Files\Winload\tbWin0.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\Toolbar\WebBrowser: (Foxit Toolbar) - {73C7D5B0-7B03-444A-84C7-CE1BA03B5573} - C:\Program Files\Foxit\tbFoxi.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\Toolbar\WebBrowser: (MyAshampoo Toolbar) - {A1E75A0E-4397-4BA8-BB50-E19FB66890F4} - C:\Program Files\MyAshampoo\prxtbMyA0.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\Toolbar\WebBrowser: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Alle meine Passworte] C:\D - PROGRAMME\AmP\AmP.exe (Mirko Böer) O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [NPSStartup] File not found O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.) O4 - HKLM..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe (PC Tools) O4 - HKU\.DEFAULT..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com) O4 - HKU\.DEFAULT..\Run: [T-Online_Software_6\WLAN-Access Finder] C:\Program Files\T-Online\WLAN-Access Finder\ToWLaAcF.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH) O4 - HKU\S-1-5-18..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com) O4 - HKU\S-1-5-18..\Run: [T-Online_Software_6\WLAN-Access Finder] C:\Program Files\T-Online\WLAN-Access Finder\ToWLaAcF.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH) O4 - HKU\S-1-5-19..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-153915148-350753066-3938573312-1000..\Run: [DeskDriveStartup] C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe (Blue Onion Software) O4 - HKU\S-1-5-21-153915148-350753066-3938573312-1000..\Run: [EPSON SX100 Series (Kopie 1)] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE (SEIKO EPSON CORPORATION) O4 - HKU\S-1-5-21-153915148-350753066-3938573312-1000..\Run: [Klebezettel NG] C:\Program Files\Klebezettel NG\klebez.exe (Hollie-Soft) O4 - HKU\S-1-5-21-153915148-350753066-3938573312-1000..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe (Jay Elaraj) O4 - Startup: C:\Users\Heiner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Geburtstagsmahner.lnk = C:\Program Files\ZEHBESOFT\Geburtstagsmahner\GebAlert.exe (ZehbeSoft) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\TabbedBrowsing present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSecurityTab = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStartupSound = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\AdvancedOptions present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\AdvancedOptions present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\AdvancedOptions present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\AdvancedOptions present O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\Software\Policies\Microsoft\Internet Explorer\AdvancedOptions present O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1 O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoShellSearchButton = 0 O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserFolderInStartMenu = 1 O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 67106819 O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67104771 O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0 O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayItemsDisplay = 0 O8 - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files\Free Download Manager\dlselected.htm () O8 - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files\Free Download Manager\dllink.htm () O8 - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files\Free Download Manager\dlfvideo.htm () O9 - Extra Button: WhoisAssistant - {1153C29A-2A1C-12E3-A2A3-00D1A2F21300} - C:\Program Files\WhoisAssistant\WhoisAssistantDirect.exe () O9 - Extra 'Tools' menuitem : &WhoisAssistant starten - {1153C29A-2A1C-12E3-A2A3-00D1A2F21300} - C:\Program Files\WhoisAssistant\WhoisAssistantDirect.exe () O9 - Extra Button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll () O9 - Extra 'Tools' menuitem : Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll () O9 - Extra Button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - Reg Error: Value error. File not found O9 - Extra 'Tools' menuitem : LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - Reg Error: Value error. File not found O9 - Extra Button: Add to Favorites - {9BEF3FB8-E5E0-4494-BC59-7BAC1C9AD503} - Reg Error: Key error. File not found O9 - Extra Button: Open Tidy Favorites - {E3CB497B-E230-4445-8B34-13476822F867} - Reg Error: Key error. File not found O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support) O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/res.../wlscctrl2.cab (Windows Live OneCare safety scanner control) O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} Windows Live OneCare (Windows Live Safety Center Base Module) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_24) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18 - Protocol\Filter\text/html {53B95211-7D77-11D2-9F80-00104B107C96} - Reg Error: Key error. File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Bild006.jpg O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Bild006.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk /k:C *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - File not found NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Lexware Info Service.lnk - - File not found MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Quicken 2008 Zahlungserinnerung.lnk - - File not found MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WISO Mein Sparbuch heute.lnk - C:\Program Files\WISO\Sparbuch 2010\meinsparbuchheute.exe - () MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WISO Urteilsmonitor.lnk - C:\Program Files\WISO\Sparbuch 2008\urteilsmonitor.exe - () MsConfig - StartUpFolder: C:^Users^Heiner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Corel Registration.lnk.disabled - - File not found MsConfig - StartUpFolder: C:^Users^Heiner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^klickTel OEM 2008 - Schnellstarter.lnk - C:\Program Files\klickTel\klickTel OEM 2008\KSTART32.EXE - (klickTel AG) MsConfig - StartUpFolder: C:^Users^Heiner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Nettalk.lnk - C:\Program Files\Nettalk6\Nettalk.exe - (Nicolas Kruse) MsConfig - StartUpFolder: C:^Users^Heiner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Secunia PSI (RC4).lnk - C:\Program Files\Secunia\PSI (RC4)\psi.exe - (Secunia) MsConfig - StartUpFolder: C:^Users^Heiner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Wallpapers from MSN.lnk - - File not found MsConfig - StartUpReg: Acronis Scheduler2 Service - hkey= - key= - File not found MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - File not found MsConfig - StartUpReg: AppleSyncNotifier - hkey= - key= - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.) MsConfig - StartUpReg: BabylonToolbar - hkey= - key= - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe (Babylon Ltd.) MsConfig - StartUpReg: BirthdayRemember6 - hkey= - key= - File not found MsConfig - StartUpReg: ccApp - hkey= - key= - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation) MsConfig - StartUpReg: Copernic Desktop Search - Home - hkey= - key= - File not found MsConfig - StartUpReg: DivXUpdate - hkey= - key= - C:\Program Files\DivX\DivX Update\DivXUpdate.exe () MsConfig - StartUpReg: Firefox - hkey= - key= - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) MsConfig - StartUpReg: FreePDF Assistant - hkey= - key= - C:\Program Files\FreePDF_XP\fpassist.exe (shbox.de) MsConfig - StartUpReg: GMX_GMX MultiMessenger - hkey= - key= - File not found MsConfig - StartUpReg: ICQ - hkey= - key= - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) MsConfig - StartUpReg: InfoCockpit - hkey= - key= - C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com) MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.) MsConfig - StartUpReg: MAXA-LockTray - hkey= - key= - C:\Program Files\MAXA-Lock\tray.exe (MAXA Research Int'l Inc.) MsConfig - StartUpReg: mspwr - hkey= - key= - File not found MsConfig - StartUpReg: NBKeyScan - hkey= - key= - C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe (Nero AG) MsConfig - StartUpReg: Ocster Backup - hkey= - key= - File not found MsConfig - StartUpReg: OpwareSE2 - hkey= - key= - C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.) MsConfig - StartUpReg: PikyAgent - hkey= - key= - C:\Program Files\Conceptworld\PikySuite\PikyAgent.exe (Conceptworld Corporation) MsConfig - StartUpReg: PrintDisp - hkey= - key= - File not found MsConfig - StartUpReg: PSUNMain - hkey= - key= - File not found MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.) MsConfig - StartUpReg: Skype - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.) MsConfig - StartUpReg: Spiele Post - hkey= - key= - File not found MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) MsConfig - StartUpReg: ToADiMon.exe - hkey= - key= - C:\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH) MsConfig - StartUpReg: Trend Micro Browser Guard v2.0 Beta - hkey= - key= - File not found MsConfig - StartUpReg: TrueImageMonitor.exe - hkey= - key= - File not found MsConfig - StartUpReg: TVBroadcast - hkey= - key= - File not found MsConfig - StartUpReg: UnlockerAssistant - hkey= - key= - C:\Program Files\Unlocker\UnlockerAssistant.exe () MsConfig - StartUpReg: UVS12 Preload - hkey= - key= - File not found MsConfig - StartUpReg: Windows Defender - hkey= - key= - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) MsConfig - StartUpReg: WinUhr - hkey= - key= - C:\Users\Heiner\Downloads\Mozilla\winuhr\WinUhr.exe (Walter Hintenaus) MsConfig - StartUpReg: Yahoo! Pager - hkey= - key= - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.) MsConfig - State: "startup" - 2 MsConfig - State: "services" - 2 MsConfig - State: "bootini" - 2 SafeBootMin: AppMgmt - Service SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: NTDS - File not found SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: AppMgmt - Service SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - File not found SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: NTDS - File not found SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootNet: WudfPf - Driver SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices ActiveX: {0291E591-EA41-4c82-8106-3DC6CE7F7664} - Reg Error: Value error. ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe" ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Windows Media Player 5.2 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906) ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {2F6EFCE6-10DF-49F9-9E64-9AE3775B2588} - Microsoft .NET Framework 1.1 Security Update (KB2416447) ActiveX: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - Reg Error: Value error. ActiveX: {347B0667-C7ED-429B-BDE3-CC8D3BACAA31} - Reg Error: Value error. ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {A17E30C4-A9BA-11D4-8673-60DB54C10000} - Reg Error: Value error. ActiveX: {AA218328-0EA8-4D70-8972-E987A9190FF4} - Reg Error: Value error. ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Shockwave Flash ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error. ActiveX: {E78BFA60-5393-4C38-82AB-E8019E464EB4} - .NET Framework ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP Geändert von Tunarus (28.04.2011 um 23:21 Uhr) |
|
|
|
|
|
#9 (Direktlink) |
|
War schon mal da
![]() Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
|
hier gehts weiter:
Drivers32: msacm.alf2cd - C:\Windows\System32\alf2cd.acm (NCT Company) Drivers32: msacm.avis - C:\Windows\System32\ff_acm.acm () Drivers32: msacm.divxa32 - C:\Windows\System32\divxa32.acm (Kristal StudioDFileDescription) Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.scg726 - C:\Windows\System32\Scg726.acm (SHARP Corporation) Drivers32: msacm.sl_anet - C:\Windows\System32\sl_anet.acm (Sipro Lab Telecom Inc.) Drivers32: msacm.voxacm160 - C:\Windows\System32\vct3216.acm (Voxware, Inc.) Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.) Drivers32: vidc.dvsd - C:\Windows\System32\mcdvd_32.dll (MainConcept) Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll () Drivers32: vidc.i420 - C:\Windows\System32\i420vfw.dll (www.helixcommunity.org) Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll () Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2011.04.28 15:33:54 | 000,000,000 | ---D | C] -- C:\Users\Heiner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller [2011.04.28 08:32:29 | 000,000,000 | ---D | C] -- C:\UWT [2011.04.27 12:31:43 | 000,000,000 | ---D | C] -- C:\shexview [2011.04.27 07:32:31 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll [2011.04.27 07:32:30 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll [2011.04.27 07:32:26 | 000,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll [2011.04.26 21:22:37 | 000,000,000 | ---D | C] -- C:\DVD-ColdCut [2011.04.26 14:05:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue [2011.04.26 14:05:20 | 000,000,000 | -H-D | C] -- C:\ProgramData\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A} [2011.04.26 14:05:19 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue [2011.04.26 11:14:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [2011.04.26 11:14:17 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2011.04.24 19:30:09 | 000,000,000 | ---D | C] -- C:\0001 - Druck [2011.04.21 08:28:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2011.04.20 12:29:30 | 000,029,056 | ---- | C] (Abelssoft GmbH) -- C:\Windows\System32\drivers\jddrv.sys [2011.04.18 09:42:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FontFrenzy [2011.04.18 09:42:39 | 000,000,000 | ---D | C] -- C:\Program Files\FontFrenzy [2011.04.15 09:50:10 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll [2011.04.15 09:50:09 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2011.04.15 09:50:08 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll [2011.04.15 09:50:06 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe [2011.04.15 09:50:05 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2011.04.15 09:50:05 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2011.04.15 09:50:05 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe [2011.04.15 09:50:05 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll [2011.04.15 09:49:56 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2011.04.15 09:49:56 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll [2011.04.15 09:49:55 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll [2011.04.15 09:49:53 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat [2011.04.15 09:49:53 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll [2011.04.15 09:49:53 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2011.04.15 09:49:52 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2011.04.15 09:49:52 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2011.04.15 09:49:51 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2011.04.15 09:49:51 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2011.04.15 09:49:50 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2011.04.15 09:49:50 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2011.04.15 09:49:50 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe [2011.04.15 09:49:50 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe [2011.04.15 09:49:50 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll [2011.04.15 09:49:50 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2011.04.15 09:49:49 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll [2011.04.15 09:49:47 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2011.04.15 09:49:47 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2011.04.15 09:49:47 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll [2011.04.15 09:49:46 | 001,797,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2011.04.15 09:49:46 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll [2011.04.15 09:49:46 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll [2011.04.15 09:49:46 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll [2011.04.15 09:49:46 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll [2011.04.15 09:49:45 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll [2011.04.15 09:49:45 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2011.04.15 09:49:45 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll [2011.04.15 09:49:45 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2011.04.15 09:49:45 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll [2011.04.15 09:49:45 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2011.04.15 08:41:48 | 000,000,000 | ---D | C] -- C:\Users\Heiner\SecurityScans [2011.04.15 08:34:38 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Baseline Security Analyzer 2 [2011.04.13 13:01:58 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe [2011.04.13 13:01:44 | 001,162,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll [2011.04.13 13:01:42 | 001,136,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll [2011.04.13 13:01:40 | 002,041,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2011.04.13 13:01:34 | 000,292,864 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll [2011.04.13 13:01:33 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll [2011.04.06 12:53:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeOCR [2011.04.06 12:53:44 | 002,680,320 | ---- | C] (HiComponents) -- C:\Windows\System32\ImageEnXLibrary.ocx [2011.04.06 12:53:44 | 001,883,136 | ---- | C] (Debenu Pty Ltd) -- C:\Windows\System32\QuickPDFAX0717.dll [2011.04.06 12:53:44 | 000,000,000 | ---D | C] -- C:\Windows\tessdata [2011.04.06 12:53:44 | 000,000,000 | ---D | C] -- C:\Program Files\FreeOCR [2011.04.06 12:53:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer [2011.04.04 21:32:45 | 000,000,000 | ---D | C] -- C:\OTR_Homeloader [2011.04.04 21:32:29 | 000,000,000 | ---D | C] -- C:\Users\Heiner\AppData\Roaming\OTRHomeloader [2011.04.04 21:32:24 | 000,000,000 | ---D | C] -- C:\Users\Heiner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OTRHomeloader [2011.04.04 21:32:23 | 000,000,000 | ---D | C] -- C:\Program Files\OTRHomeloader [2011.04.02 21:41:25 | 000,000,000 | -HSD | C] -- C:\found.001 [2010.05.10 15:10:41 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Heiner\AppData\Roaming\pcouffin.sys [2008.11.03 16:03:28 | 000,013,880 | ---- | C] ( ) -- C:\Windows\System32\drivers\kbfiltr.sys [1996.11.18 23:15:46 | 000,018,944 | ---- | C] ( ) -- C:\Windows\System32\IMPLODE.DLL [6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.04.28 21:13:42 | 010,747,904 | ---- | M] () -- C:\Users\Heiner\ntuser.dat [2011.04.28 21:00:05 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011.04.28 20:41:56 | 000,000,205 | ---- | M] () -- C:\Users\Heiner\Desktop\READYBOOST (J).lnk [2011.04.28 20:36:39 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011.04.28 20:36:32 | 000,000,334 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job [2011.04.28 20:36:31 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2011.04.28 20:36:22 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011.04.28 20:36:22 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011.04.28 20:36:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011.04.28 20:36:00 | 1877,454,848 | -HS- | M] () -- C:\hiberfil.sys [2011.04.28 20:32:55 | 000,524,288 | -HS- | M] () -- C:\Users\Heiner\ntuser.dat{c73d8214-6e91-11e0-834a-001bfcfaa836}.TMContainer00000000000000000001.regtrans-ms [2011.04.28 20:32:55 | 000,065,536 | -HS- | M] () -- C:\Users\Heiner\ntuser.dat{c73d8214-6e91-11e0-834a-001bfcfaa836}.TM.blf [2011.04.28 20:32:39 | 005,604,485 | -H-- | M] () -- C:\Users\Heiner\AppData\Local\IconCache.db [2011.04.28 17:40:48 | 000,000,793 | ---- | M] () -- C:\Users\Heiner\Desktop\mbam.exe.lnk [2011.04.28 17:37:54 | 000,001,189 | ---- | M] () -- C:\Users\Heiner\AppData\Roaming\vso_ts_preview.xml [2011.04.28 17:29:18 | 000,011,145 | ---- | M] () -- C:\Windows\Heiner8.xlb [2011.04.28 16:05:09 | 000,161,792 | ---- | M] () -- C:\Users\Heiner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.04.28 15:33:54 | 000,001,040 | ---- | M] () -- C:\Users\Heiner\Desktop\Revo Uninstaller.lnk [2011.04.28 14:14:08 | 000,001,553 | ---- | M] () -- C:\Windows\QUICKEN.INI [2011.04.28 11:00:00 | 000,000,436 | ---- | M] () -- C:\Windows\tasks\ASOService.job [2011.04.27 21:38:29 | 000,001,156 | ---- | M] () -- C:\Windows\System32\games.stat [2011.04.27 14:02:42 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [2011.04.27 11:48:30 | 000,002,312 | ---- | M] () -- C:\Windows\Provex.ini [2011.04.26 21:09:15 | 000,360,208 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011.04.26 11:34:22 | 000,100,496 | ---- | M] () -- C:\Users\Heiner\AppData\Local\GDIPFONTCACHEV1.DAT [2011.04.26 11:20:14 | 000,358,172 | ---- | M] () -- C:\Users\Heiner\Documents\cc_20110426_111944.reg [2011.04.26 02:31:50 | 000,001,811 | ---- | M] () -- C:\Users\Public\Desktop\avast! Pro Antivirus.lnk [2011.04.25 18:05:40 | 000,524,288 | -HS- | M] () -- C:\Users\Heiner\ntuser.dat{c73d8214-6e91-11e0-834a-001bfcfaa836}.TMContainer00000000000000000002.regtrans-ms [2011.04.24 18:54:06 | 000,524,288 | -HS- | M] () -- C:\Users\Heiner\ntuser.dat{92dd0609-586f-11e0-8578-f78160efc769}.TMContainer00000000000000000001.regtrans-ms [2011.04.24 18:54:06 | 000,065,536 | -HS- | M] () -- C:\Users\Heiner\ntuser.dat{92dd0609-586f-11e0-8578-f78160efc769}.TM.blf [2011.04.21 08:28:41 | 000,000,824 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk [2011.04.18 19:25:12 | 000,040,112 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2011.04.18 19:25:10 | 000,199,304 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2011.04.18 19:17:46 | 000,441,176 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2011.04.18 19:17:34 | 000,307,288 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2011.04.18 19:16:18 | 000,049,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2011.04.18 19:13:21 | 000,025,432 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2011.04.18 19:13:09 | 000,053,592 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2011.04.18 19:12:58 | 000,019,544 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2011.04.18 15:25:39 | 000,000,986 | ---- | M] () -- C:\Users\Heiner\Desktop\ConvertXtoDVD 4.lnk [2011.04.18 13:43:48 | 000,008,704 | ---- | M] () -- C:\Windows\System32\WindowsClosingService.exe [2011.04.18 13:42:02 | 000,029,056 | ---- | M] (Abelssoft GmbH) -- C:\Windows\System32\drivers\jddrv.sys [2011.04.18 13:42:02 | 000,016,384 | ---- | M] () -- C:\Windows\System32\jddac.dll [2011.04.18 13:42:02 | 000,015,360 | ---- | M] () -- C:\Windows\System32\jdnat.dll [2011.04.18 13:42:02 | 000,006,656 | ---- | M] () -- C:\Windows\System32\jdboot.exe [2011.04.15 17:00:23 | 000,000,402 | ---- | M] () -- C:\Windows\tasks\WebUpdate.job [2011.04.15 09:50:37 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat [2011.04.15 09:50:37 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat [2011.04.15 09:50:10 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll [2011.04.15 09:50:09 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2011.04.15 09:50:08 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll [2011.04.15 09:50:06 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe [2011.04.15 09:50:05 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2011.04.15 09:50:05 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2011.04.15 09:50:05 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe [2011.04.15 09:50:05 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll [2011.04.15 09:49:57 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2011.04.15 09:49:56 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll [2011.04.15 09:49:56 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll [2011.04.15 09:49:54 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat [2011.04.15 09:49:53 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll [2011.04.15 09:49:53 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2011.04.15 09:49:53 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2011.04.15 09:49:52 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2011.04.15 09:49:52 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2011.04.15 09:49:52 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf [2011.04.15 09:49:51 | 001,427,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2011.04.15 09:49:51 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2011.04.15 09:49:50 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2011.04.15 09:49:50 | 000,420,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll [2011.04.15 09:49:50 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe [2011.04.15 09:49:50 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe [2011.04.15 09:49:50 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll [2011.04.15 09:49:50 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2011.04.15 09:49:47 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2011.04.15 09:49:47 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2011.04.15 09:49:47 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll [2011.04.15 09:49:46 | 001,797,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2011.04.15 09:49:46 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll [2011.04.15 09:49:46 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll [2011.04.15 09:49:46 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll [2011.04.15 09:49:46 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll [2011.04.15 09:49:45 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll [2011.04.15 09:49:45 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2011.04.15 09:49:45 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll [2011.04.15 09:49:45 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2011.04.15 09:49:45 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll [2011.04.15 09:49:45 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2011.04.13 13:13:42 | 001,494,818 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI [2011.04.13 13:13:42 | 000,638,510 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2011.04.13 13:13:42 | 000,604,126 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011.04.13 13:13:42 | 000,130,462 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2011.04.13 13:13:42 | 000,107,562 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011.04.08 20:22:55 | 000,000,541 | ---- | M] () -- C:\Users\Heiner\Desktop\speedyfox.exe.lnk [2011.04.08 13:17:57 | 000,005,434 | -H-- | M] () -- C:\ffastun.ffa [2011.04.08 13:17:55 | 001,806,336 | -H-- | M] () -- C:\ffastun.ffo [2011.04.08 13:17:53 | 021,368,832 | -H-- | M] () -- C:\ffastun0.ffx [2011.04.08 13:17:53 | 005,292,032 | -H-- | M] () -- C:\ffastun.ffl [2011.04.03 13:31:21 | 000,000,157 | ---- | M] () -- C:\Windows\ktel.ini [2011.04.01 09:20:04 | 000,524,288 | -HS- | M] () -- C:\Users\Heiner\ntuser.dat{92dd0609-586f-11e0-8578-f78160efc769}.TMContainer00000000000000000002.regtrans-ms [6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] |
|
|
|
|
|
#10 (Direktlink) |
|
War schon mal da
![]() Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
|
...und noch weiter:
[2011.04.15 09:49:52 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf [2011.04.15 08:34:45 | 000,000,999 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Baseline Security Analyzer 2.2.lnk [2011.04.08 20:22:55 | 000,000,541 | ---- | C] () -- C:\Users\Heiner\Desktop\speedyfox.exe.lnk [2011.04.06 12:53:43 | 000,962,560 | ---- | C] () -- C:\Windows\tesseract.exe [2011.03.17 20:23:01 | 000,032,768 | ---- | C] () -- C:\Windows\System32\EcodocLicenceLib.dll [2011.03.16 12:28:54 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll [2011.03.16 00:11:39 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll [2011.03.16 00:11:39 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys [2011.02.21 15:07:11 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat [2011.02.21 12:15:58 | 000,017,136 | ---- | C] () -- C:\Windows\System32\sasnative32.exe [2011.01.26 08:34:31 | 000,000,680 | ---- | C] () -- C:\Users\Heiner\AppData\Local\d3d9caps.dat [2010.08.20 15:07:47 | 000,819,200 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2010.08.20 15:07:38 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2010.06.21 11:08:38 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE [2010.05.31 10:32:57 | 000,110,602 | ---- | C] () -- C:\Windows\System32\xcdsfx32.bin [2010.05.10 15:21:27 | 000,001,189 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\vso_ts_preview.xml [2010.05.10 15:10:41 | 000,087,608 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\inst.exe [2010.05.10 15:10:41 | 000,007,887 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\pcouffin.cat [2010.05.10 15:10:41 | 000,001,144 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\pcouffin.inf [2010.04.01 13:52:37 | 000,000,067 | ---- | C] () -- C:\Windows\swf2avi.INI [2010.03.29 17:31:30 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll [2010.03.22 13:08:01 | 000,005,115 | ---- | C] () -- C:\ProgramData\kbkwknay.ayh [2010.01.22 08:52:21 | 000,000,043 | ---- | C] () -- C:\Windows\gswin32.ini [2010.01.14 10:31:49 | 000,011,164 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin [2009.12.26 11:50:35 | 000,691,200 | ---- | C] () -- C:\Windows\System32\PrintLog.exe [2009.12.26 11:50:35 | 000,524,288 | ---- | C] () -- C:\Windows\System32\PrtPass.exe [2009.12.25 22:35:06 | 001,163,264 | ---- | C] () -- C:\Windows\System32\Ei4rbfL-a77VQ.dll [2009.12.16 13:02:10 | 000,000,530 | ---- | C] () -- C:\Windows\System32\tx151ic.ini [2009.11.02 12:11:07 | 000,000,045 | ---- | C] () -- C:\ProgramData\.SimImages [2009.10.05 14:48:52 | 000,000,705 | ---- | C] () -- C:\Windows\System32\AeroShake.ini [2009.08.08 20:47:21 | 000,000,659 | ---- | C] () -- C:\Windows\unins000.dat [2009.08.03 16:40:51 | 000,000,026 | ---- | C] () -- C:\Windows\NeoSetup.INI [2009.07.21 00:05:16 | 000,000,040 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\lZJoYI4Nl0eqQ3j+wCSiZ5uqvQdWg2FYUxeLS5PJ.trl [2009.05.29 08:03:20 | 000,000,000 | ---- | C] () -- C:\Windows\PROTOCOL.INI [2009.05.27 17:02:49 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2009.05.27 17:01:58 | 000,368,640 | ---- | C] () -- C:\Windows\System32\msjetoledb40.dll [2009.05.27 17:00:53 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2009.05.20 12:09:21 | 000,000,024 | ---- | C] () -- C:\Windows\Bombgolf.ini [2009.02.28 19:17:54 | 000,008,704 | ---- | C] () -- C:\Windows\System32\WindowsClosingService.exe [2009.02.09 19:56:22 | 000,084,480 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2009.02.02 17:54:03 | 000,000,000 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\AVSDVDPlayer.m3u [2008.12.24 21:12:57 | 000,000,339 | ---- | C] () -- C:\Windows\DesktopSchneeFree.ini [2008.11.07 17:09:13 | 000,000,025 | ---- | C] () -- C:\Windows\CDESX100DEFGIPS.ini [2008.11.04 19:46:23 | 000,001,033 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\ShiftN.ini [2008.10.21 11:12:05 | 000,000,736 | ---- | C] () -- C:\Windows\SamsungMaster.INI [2008.10.18 19:10:15 | 000,299,008 | ---- | C] () -- C:\Windows\System32\midas.dll [2008.10.18 19:10:12 | 000,120,320 | ---- | C] () -- C:\Windows\System32\UnzDll.dll [2008.10.18 16:36:27 | 002,963,456 | ---- | C] () -- C:\Program Files\Common FilesDDBACSetup.msi [2008.09.28 20:33:22 | 000,000,041 | ---- | C] () -- C:\Windows\crw.ini [2008.09.22 09:46:15 | 000,000,157 | ---- | C] () -- C:\Windows\ktel.ini [2008.09.12 15:21:02 | 000,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest [2008.08.14 10:48:02 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2008.07.25 16:49:40 | 000,000,027 | ---- | C] () -- C:\Windows\CDE DX4400DEFGIPS.ini [2008.07.21 22:33:08 | 000,000,173 | ---- | C] () -- C:\Windows\CWREGIST.INI [2008.07.11 14:20:09 | 000,230,377 | ---- | C] () -- C:\Windows\System32\XXCOPY16.EXE [2008.07.05 12:13:19 | 000,008,704 | ---- | C] () -- C:\Windows\System32\vidccleaner.exe [2008.07.05 12:09:13 | 000,040,960 | ---- | C] () -- C:\Windows\unS385N.dll [2008.06.28 02:42:44 | 000,013,576 | ---- | C] () -- C:\Windows\System32\wnaspi32.dll [2008.06.16 11:49:01 | 000,073,728 | ---- | C] () -- C:\Windows\AKDeInstall.exe [2008.05.28 13:24:00 | 000,233,542 | ---- | C] () -- C:\Windows\System32\vcdll.dll [2008.05.12 17:12:25 | 000,000,928 | ---- | C] () -- C:\ProgramData\winsys.lng [2008.05.12 17:11:55 | 000,081,920 | ---- | C] () -- C:\Windows\System32\GkSui20.EXE [2008.05.08 18:15:03 | 000,101,936 | ---- | C] () -- C:\Windows\System32\GDIPFONTCACHEV1.DAT [2008.05.08 17:10:40 | 000,162,304 | ---- | C] () -- C:\Windows\System32\ztvunrar36.dll [2008.05.08 17:10:40 | 000,077,312 | ---- | C] () -- C:\Windows\System32\ztvunace26.dll [2008.04.15 21:29:19 | 000,163,840 | ---- | C] () -- C:\Windows\System32\PwrUpCid.dll [2008.03.05 22:53:26 | 000,116,224 | ---- | C] () -- C:\Windows\System32\redmonnt.dll [2008.03.03 15:12:13 | 000,045,056 | ---- | C] () -- C:\Windows\System32\rWinHook.dll [2008.03.02 14:46:43 | 000,003,060 | ---- | C] () -- C:\Windows\tm.ini [2008.02.29 13:03:08 | 000,051,815 | R--- | C] () -- C:\Windows\System32\QPRO200.DLL [2008.02.29 13:03:05 | 000,100,352 | R--- | C] () -- C:\Windows\System32\JUCALC4.DLL [2008.02.29 13:03:05 | 000,100,352 | R--- | C] () -- C:\Windows\System32\Jucalc2.dll [2008.02.29 13:03:05 | 000,100,352 | R--- | C] () -- C:\Windows\System32\Jucalc.dll [2008.02.29 13:03:03 | 000,282,112 | R--- | C] () -- C:\Windows\System32\ASTR.DLL [2008.02.29 13:03:03 | 000,112,640 | R--- | C] () -- C:\Windows\System32\AW300.DLL [2008.02.13 12:37:29 | 000,000,848 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys [2008.02.13 12:29:39 | 001,136,208 | ---- | C] () -- C:\ProgramData\pswi_preloaded.exe [2008.02.06 13:04:53 | 000,045,056 | ---- | C] () -- C:\Windows\System32\unredmon.exe [2008.01.28 19:09:30 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat [2008.01.28 19:09:30 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat [2008.01.28 19:09:30 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat [2008.01.28 19:09:30 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat [2008.01.28 19:09:30 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat [2008.01.28 19:09:30 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat [2008.01.28 19:09:30 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat [2008.01.28 19:09:30 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat [2008.01.28 19:09:30 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat [2008.01.28 19:09:30 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat [2008.01.28 19:09:30 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat [2008.01.28 19:09:30 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat [2008.01.28 19:09:30 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat [2008.01.28 19:09:30 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat [2008.01.28 19:09:30 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat [2008.01.28 19:09:30 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat [2008.01.28 13:47:12 | 000,000,754 | ---- | C] () -- C:\Windows\wiso.ini [2008.01.18 08:14:05 | 000,000,032 | ---- | C] () -- C:\ProgramData\ezsid.dat [2008.01.15 08:40:52 | 000,000,030 | ---- | C] () -- C:\Windows\INTURS.DAT [2008.01.15 08:40:49 | 000,000,024 | ---- | C] () -- C:\Windows\qfnonl.ini [2008.01.15 08:40:00 | 000,000,028 | ---- | C] () -- C:\Windows\ICOA.INI [2008.01.15 08:39:34 | 000,000,000 | ---- | C] () -- C:\Windows\QFN.ini [2008.01.15 08:39:34 | 000,000,000 | ---- | C] () -- C:\Windows\QDQICK.ini [2008.01.15 04:31:00 | 000,000,530 | ---- | C] () -- C:\Windows\System32\tx14_ic.ini [2007.12.19 15:46:35 | 000,060,124 | ---- | C] () -- C:\Windows\System32\tcpmon.ini [2007.12.08 01:40:42 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2007.12.07 22:52:14 | 000,004,246 | ---- | C] () -- C:\Windows\WINAS60.INI [2007.12.07 22:51:15 | 000,201,984 | ---- | C] () -- C:\Windows\PI.EXE [2007.12.05 17:32:37 | 000,000,000 | ---- | C] () -- C:\Windows\distlib.ini [2007.12.03 12:50:03 | 000,003,596 | ---- | C] () -- C:\Windows\System32\buttonstudio.ini [2007.12.01 19:53:20 | 000,008,395 | ---- | C] () -- C:\Windows\mozver.dat [2007.11.30 15:51:40 | 000,694,168 | ---- | C] () -- C:\ProgramData\LUUnInstall.LiveUpdate [2007.11.28 19:59:42 | 003,702,784 | ---- | C] () -- C:\Windows\System32\gsdll32.dll [2007.11.27 17:19:30 | 000,001,553 | ---- | C] () -- C:\Windows\QUICKEN.INI [2007.11.27 17:19:30 | 000,000,904 | ---- | C] () -- C:\Windows\Intuprof.ini [2007.11.27 17:19:25 | 000,005,990 | ---- | C] () -- C:\Windows\icoadb32.dat [2007.11.26 21:52:07 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini [2007.11.26 20:38:25 | 000,002,312 | ---- | C] () -- C:\Windows\Provex.ini [2007.11.26 18:27:30 | 000,000,100 | ---- | C] () -- C:\Windows\HBUser.ini [2007.11.26 17:36:53 | 000,000,094 | ---- | C] () -- C:\Users\Heiner\AppData\Local\fusioncache.dat [2007.11.26 16:20:09 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll [2007.11.26 16:19:28 | 000,006,768 | ---- | C] () -- C:\Windows\mgxoschk.ini [2007.11.26 12:11:04 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll [2007.11.26 09:04:09 | 000,000,132 | ---- | C] () -- C:\Windows\winamp.ini [2007.11.25 18:25:41 | 000,031,028 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\UserTile.png [2007.11.25 09:26:38 | 000,039,095 | ---- | C] () -- C:\Windows\iccsigs.dat [2007.11.25 09:26:37 | 000,112,688 | ---- | C] () -- C:\Windows\System32\shw32.dll [2007.11.25 01:47:28 | 000,161,792 | ---- | C] () -- C:\Users\Heiner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2007.11.25 00:13:48 | 000,000,216 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\wklnhst.dat [2007.11.24 22:59:08 | 000,000,634 | ---- | C] () -- C:\Windows\ODBC.INI [2007.11.24 22:59:07 | 000,000,967 | ---- | C] () -- C:\Windows\ODBCINST.INI [2007.11.24 22:34:47 | 000,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat [2007.11.24 22:34:47 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat [2007.11.24 22:34:47 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini [2007.11.24 22:27:44 | 000,000,027 | ---- | C] () -- C:\Windows\CDE CX3600FGD.ini [2007.11.24 22:20:25 | 000,000,532 | ---- | C] () -- C:\Windows\MAXLINK.INI [2007.11.24 20:01:36 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat [2007.11.24 17:37:57 | 000,100,496 | ---- | C] () -- C:\Users\Heiner\AppData\Local\GDIPFONTCACHEV1.DAT [2007.10.25 18:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys [2007.09.04 12:56:10 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll [2007.03.11 15:10:58 | 006,209,536 | ---- | C] () -- C:\Windows\System32\ImageMagickObject.dll [2006.11.29 04:30:00 | 000,000,530 | ---- | C] () -- C:\Windows\System32\tx13_ic.ini [2006.11.02 21:40:12 | 000,174,656 | ---- | C] () -- C:\Windows\System32\PSIService.exe [2006.11.02 17:33:31 | 000,638,510 | ---- | C] () -- C:\Windows\System32\perfh007.dat [2006.11.02 17:33:31 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat [2006.11.02 17:33:31 | 000,130,462 | ---- | C] () -- C:\Windows\System32\perfc007.dat [2006.11.02 17:33:31 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat [2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006.11.02 14:47:37 | 000,360,208 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006.11.02 12:33:01 | 001,494,818 | ---- | C] () -- C:\Windows\System32\PerfStringBackup.INI [2006.11.02 12:33:01 | 000,604,126 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006.11.02 12:33:01 | 000,107,562 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006.11.02 12:24:31 | 000,001,405 | ---- | C] () -- C:\Windows\msdfmap.ini [2006.11.02 12:23:31 | 000,000,432 | ---- | C] () -- C:\Windows\win.ini [2006.11.02 12:23:31 | 000,000,236 | ---- | C] () -- C:\Windows\system.ini [2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2006.11.02 09:10:37 | 000,053,536 | ---- | C] () -- C:\Windows\System32\dosx.exe [2006.11.02 09:10:02 | 000,000,718 | ---- | C] () -- C:\Windows\System32\mscdexnt.exe [2006.11.02 09:10:00 | 000,002,842 | ---- | C] () -- C:\Windows\System32\redir.exe [2006.11.02 09:09:59 | 000,069,886 | ---- | C] () -- C:\Windows\System32\edit.com [2006.11.02 09:09:59 | 000,019,694 | ---- | C] () -- C:\Windows\System32\GRAPHICS.COM [2006.11.02 09:09:59 | 000,000,882 | ---- | C] () -- C:\Windows\System32\share.exe [2006.11.02 09:09:59 | 000,000,882 | ---- | C] () -- C:\Windows\System32\fastopen.exe [2006.11.02 09:09:57 | 000,014,710 | ---- | C] () -- C:\Windows\System32\KB16.COM [2006.11.02 09:09:56 | 000,007,052 | ---- | C] () -- C:\Windows\System32\nlsfunc.exe [2006.11.02 09:09:55 | 000,039,274 | ---- | C] () -- C:\Windows\System32\mem.exe [2006.11.02 09:09:55 | 000,001,131 | ---- | C] () -- C:\Windows\System32\LOADFIX.COM [2006.11.02 09:09:53 | 000,011,753 | ---- | C] () -- C:\Windows\System32\setver.exe [2006.11.02 09:09:52 | 000,020,634 | ---- | C] () -- C:\Windows\System32\debug.exe [2006.11.02 09:09:51 | 000,008,424 | ---- | C] () -- C:\Windows\System32\exe2bin.exe [2006.11.02 09:09:50 | 000,012,642 | ---- | C] () -- C:\Windows\System32\edlin.exe [2006.11.02 09:09:49 | 000,050,648 | ---- | C] () -- C:\Windows\System32\COMMAND.COM [2006.11.02 09:09:49 | 000,012,498 | ---- | C] () -- C:\Windows\System32\append.exe [2006.11.02 09:09:45 | 000,027,097 | ---- | C] () -- C:\Windows\System32\country.sys [2006.11.02 09:09:44 | 000,042,809 | ---- | C] () -- C:\Windows\System32\KEY01.SYS [2006.11.02 09:09:44 | 000,042,537 | ---- | C] () -- C:\Windows\System32\KEYBOARD.SYS [2006.11.02 09:09:42 | 000,009,029 | ---- | C] () -- C:\Windows\System32\ANSI.SYS [2006.11.02 09:09:41 | 000,004,768 | ---- | C] () -- C:\Windows\System32\HIMEM.SYS [2006.11.02 09:09:40 | 000,029,274 | ---- | C] () -- C:\Windows\System32\NTDOS412.SYS [2006.11.02 09:09:38 | 000,029,370 | ---- | C] () -- C:\Windows\System32\NTDOS411.SYS [2006.11.02 09:09:35 | 000,029,146 | ---- | C] () -- C:\Windows\System32\NTDOS404.SYS [2006.11.02 09:09:31 | 000,029,146 | ---- | C] () -- C:\Windows\System32\NTDOS804.SYS [2006.11.02 09:09:29 | 000,027,866 | ---- | C] () -- C:\Windows\System32\NTDOS.SYS [2006.11.02 09:09:26 | 000,035,536 | ---- | C] () -- C:\Windows\System32\NTIO412.SYS [2006.11.02 09:09:24 | 000,035,776 | ---- | C] () -- C:\Windows\System32\NTIO411.SYS [2006.11.02 09:09:23 | 000,034,672 | ---- | C] () -- C:\Windows\System32\NTIO404.SYS [2006.11.02 09:09:22 | 000,034,672 | ---- | C] () -- C:\Windows\System32\NTIO804.SYS [2006.11.02 09:09:20 | 000,033,952 | ---- | C] () -- C:\Windows\System32\NTIO.SYS [2006.11.02 08:25:08 | 000,013,312 | ---- | C] () -- C:\Windows\System32\win87em.dll [2006.09.29 16:12:12 | 000,303,104 | ---- | C] () -- C:\Windows\System32\dnt27VC8.dll [2006.09.24 22:04:42 | 000,090,112 | ---- | C] () -- C:\Windows\System32\dntvmc27VC8.dll [2006.09.24 22:03:32 | 000,086,016 | ---- | C] () -- C:\Windows\System32\dntvm27VC8.dll [2006.09.21 14:53:28 | 000,282,679 | ---- | C] () -- C:\Windows\System32\dnt27.dll [2006.09.21 14:52:24 | 000,077,882 | ---- | C] () -- C:\Windows\System32\dntvmc27.dll [2006.09.21 14:52:14 | 000,077,881 | ---- | C] () -- C:\Windows\System32\dntvm27.dll [2002.03.17 02:00:00 | 000,007,420 | ---- | C] () -- C:\Windows\UA000107.DLL [1998.05.11 00:00:00 | 000,748,160 | ---- | C] () -- C:\Windows\System32\CO2C40EN.DLL [1997.09.14 02:10:28 | 000,000,304 | ---- | C] () -- C:\Windows\KARTVERW.INI [1996.12.14 01:00:00 | 000,094,208 | ---- | C] () -- C:\Windows\System32\MSENCODE.DLL [1996.12.14 01:00:00 | 000,022,016 | ---- | C] () -- C:\Windows\System32\ODBCSTF.DLL [1996.12.14 01:00:00 | 000,022,016 | ---- | C] () -- C:\Windows\System32\DOCOBJ.DLL [1996.12.14 01:00:00 | 000,012,288 | ---- | C] () -- C:\Windows\System32\HLINKPRX.DLL [1996.11.18 23:15:52 | 000,131,072 | ---- | C] () -- C:\Windows\System32\P2SODBC.DLL [1996.11.18 23:15:50 | 000,054,272 | ---- | C] () -- C:\Windows\System32\P2IRDAO.DLL [1996.11.18 23:15:50 | 000,050,176 | ---- | C] () -- C:\Windows\System32\P2CTDAO.DLL [1996.11.18 23:15:50 | 000,036,352 | ---- | C] () -- C:\Windows\System32\P2BBND.DLL |
|
|
|
|
|
|
#11 (Direktlink) |
|
War schon mal da
![]() Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
|
...und immer weiter bis zum Ende:
========== Files Created - No Company Name ========== [2011.04.28 20:41:56 | 000,000,205 | ---- | C] () -- C:\Users\Heiner\Desktop\READYBOOST (J).lnk [2011.04.28 17:40:48 | 000,000,793 | ---- | C] () -- C:\Users\Heiner\Desktop\mbam.exe.lnk [2011.04.26 21:08:27 | 1877,454,848 | -HS- | C] () -- C:\hiberfil.sys [2011.04.26 14:05:59 | 000,000,334 | ---- | C] () -- C:\Windows\tasks\RegistryBooster.job [2011.04.26 11:20:01 | 000,358,172 | ---- | C] () -- C:\Users\Heiner\Documents\cc_20110426_111944.reg [2011.04.24 19:03:03 | 000,524,288 | -HS- | C] () -- C:\Users\Heiner\ntuser.dat{c73d8214-6e91-11e0-834a-001bfcfaa836}.TMContainer00000000000000000002.regtrans-ms [2011.04.24 19:03:03 | 000,524,288 | -HS- | C] () -- C:\Users\Heiner\ntuser.dat{c73d8214-6e91-11e0-834a-001bfcfaa836}.TMContainer00000000000000000001.regtrans-ms [2011.04.24 19:03:03 | 000,065,536 | -HS- | C] () -- C:\Users\Heiner\ntuser.dat{c73d8214-6e91-11e0-834a-001bfcfaa836}.TM.blf [2011.04.24 18:39:22 | 005,604,485 | -H-- | C] () -- C:\Users\Heiner\AppData\Local\IconCache.db [2011.04.21 08:28:41 | 000,000,824 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk [2011.04.20 12:29:30 | 000,016,384 | ---- | C] () -- C:\Windows\System32\jddac.dll [2011.04.20 12:29:30 | 000,015,360 | ---- | C] () -- C:\Windows\System32\jdnat.dll [2011.04.20 12:29:30 | 000,006,656 | ---- | C] () -- C:\Windows\System32\jdboot.exe ========== LOP Check ========== [2008.10.11 20:09:33 | 000,000,000 | -HSD | M] -- C:\Users\Heiner\AppData\Roaming\.# [2007.11.26 13:03:15 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\1&1 [2010.01.27 14:15:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Acronis [2008.07.11 14:35:25 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ASCOMP Software [2010.08.01 11:20:27 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Ashampoo [2010.08.03 14:11:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\avidemux [2010.11.11 22:10:27 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Balabolka [2008.05.12 23:56:00 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\BirthdayRemember [2008.01.28 13:49:55 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Buhl Data Service [2010.03.18 20:44:23 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Canneverbe Limited [2007.11.26 11:37:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Canon [2008.10.02 20:01:14 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\CDZilla [2010.11.02 21:55:46 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\COMPUTERBILD-Abzockschutz [2010.02.17 12:28:50 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Conceptworld [2009.07.05 20:01:36 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Copernic [2009.01.29 23:13:05 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\CoreFTP [2008.10.18 18:48:04 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Daoisoft [2007.12.03 20:09:54 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DataDesign [2009.01.01 14:36:45 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DeepBurner [2011.03.21 17:55:43 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DreamDale [2008.03.20 22:56:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DTgrafic [2008.01.28 19:53:37 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\EPSON [2010.10.08 19:24:16 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FILEminimizerPictures [2009.08.07 14:06:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FileZilla [2009.07.20 19:20:07 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FinalBurner Video DVD [2010.08.04 13:20:09 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FireShot [2010.02.24 06:32:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FlashGet [2009.02.02 18:07:50 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Flickr [2009.12.14 10:46:23 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Foxit [2010.06.01 15:07:50 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Foxit Software [2011.04.26 11:17:48 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Free Download Manager [2010.03.17 19:24:07 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FreeFLVConverter [2010.04.23 11:01:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\freeTVRadio [2009.07.20 22:11:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\GetRightToGo [2011.03.23 11:57:43 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\GlarySoft [2007.12.22 23:05:33 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\GMX [2008.05.08 17:20:21 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\gtk-2.0 [2010.05.07 01:14:51 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\HandBrake [2010.08.30 10:32:38 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\HDD Thermometer [2010.12.27 09:53:09 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\HTC Home [2010.11.11 22:10:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Hunspell [2009.08.06 11:57:11 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ICQ [2009.08.13 13:57:16 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Intenium [2011.01.06 20:54:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Inventivio [2008.01.11 12:00:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\JAM Software [2010.02.09 09:35:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\JGoodies [2008.04.10 15:35:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\JoJoThumb [2009.01.15 23:20:56 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\jpg-Illuminator [2010.05.12 12:57:32 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\KeePass [2010.03.11 21:11:58 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Keseling [2008.09.22 09:54:18 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\klickTel [2011.01.19 13:16:04 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Leadertech [2008.10.18 16:40:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Lexware [2011.03.21 17:50:40 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\MagicBall4 [2008.12.19 14:52:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Map24 [2010.03.22 13:08:25 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\MOVAVI [2008.12.11 13:08:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\NAVIGON [2008.07.31 19:18:53 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Nettalk [2009.02.02 18:02:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Nokia [2010.04.23 11:05:22 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\OfferBox [2008.08.26 18:04:05 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Open Source Applications Foundation [2008.12.14 19:08:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\OpenOffice.org [2011.04.04 21:32:29 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\OTRHomeloader [2010.05.27 16:55:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Panda Security [2010.12.21 10:50:19 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Participatory Culture Foundation [2009.02.02 18:02:37 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PC Suite [2010.12.21 10:51:33 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PCF-VLC [2010.12.02 10:27:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PCToolsFirewallPlus [2009.08.13 14:06:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Peace Craft [2010.11.18 11:28:54 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PeaceCraft2 [2008.08.26 18:03:07 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Python-Eggs [2010.10.19 11:15:18 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\QuickScan [2010.05.13 21:03:13 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Returnil [2011.03.16 12:20:44 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Samsung [2007.11.24 22:20:34 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ScanSoft [2009.09.12 11:26:34 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ScreenSeven [2008.02.01 00:59:00 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\SimpleScreenshot [2010.03.31 12:51:13 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Software Informer [2010.11.25 21:41:36 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Spamihilator [2011.01.06 20:52:23 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Speak-A-Message [2010.09.09 14:14:51 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\SuperEasy [2010.03.09 09:42:41 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\SuperEasy Software [2011.02.21 12:14:39 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Systweak [2007.11.26 17:45:48 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\T-Online [2007.11.25 00:14:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Template [2009.12.28 10:49:47 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Thunderbird [2007.12.07 09:04:40 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\TuneUp Software [2009.05.21 11:36:21 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\TVcentral-Core [2010.01.27 10:27:24 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Ulead Systems [2011.04.26 14:05:55 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Uniblue [2010.05.10 14:50:41 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Video DVD Maker FREE [2008.11.04 19:31:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ViewPicXXL [2010.11.03 09:16:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Vista Start Menu [2011.04.28 17:38:01 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Vso [2011.01.01 16:23:57 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\René's Homepage [2011.04.26 02:24:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ZSGebmahner [2009.10.11 20:47:49 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Zylom [2011.04.28 11:00:00 | 000,000,436 | ---- | M] () -- C:\Windows\Tasks\ASOService.job [2010.11.06 09:01:13 | 000,000,970 | ---- | M] () -- C:\Windows\Tasks\Paragon File Archive name arc_051110075557617.job [2011.04.28 20:36:32 | 000,000,334 | ---- | M] () -- C:\Windows\Tasks\RegistryBooster.job [2011.04.28 20:33:33 | 000,032,562 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2011.04.15 17:00:23 | 000,000,402 | ---- | M] () -- C:\Windows\Tasks\WebUpdate.job ========== Purity Check ========== ========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. > [2008.10.11 20:09:33 | 000,000,000 | -HSD | M] -- C:\Users\Heiner\AppData\Roaming\.# [2007.11.26 13:03:15 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\1&1 [2010.01.27 14:15:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Acronis [2011.02.15 08:59:05 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Adobe [2010.08.11 14:35:55 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Apple Computer [2008.10.10 11:21:29 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ArcSoft [2008.07.11 14:35:25 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ASCOMP Software [2010.08.01 11:20:27 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Ashampoo [2010.08.03 14:11:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\avidemux [2010.03.20 18:35:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\AVS4YOU [2010.11.11 22:10:27 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Balabolka [2008.05.12 23:56:00 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\BirthdayRemember [2008.01.28 13:49:55 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Buhl Data Service [2010.03.18 20:44:23 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Canneverbe Limited [2007.11.26 11:37:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Canon [2008.10.02 20:01:14 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\CDZilla [2010.11.02 21:55:46 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\COMPUTERBILD-Abzockschutz [2010.02.17 12:28:50 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Conceptworld [2009.07.05 20:01:36 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Copernic [2009.01.29 23:13:05 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\CoreFTP [2008.02.13 14:58:18 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Corel [2008.10.18 18:48:04 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Daoisoft [2007.12.03 20:09:54 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DataDesign [2009.01.01 14:36:45 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DeepBurner [2010.05.23 17:51:54 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Ditto [2010.08.23 20:04:14 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DivX [2011.03.21 17:55:43 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DreamDale [2008.03.20 22:56:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DTgrafic [2010.10.26 18:04:36 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DVD Flick [2009.07.20 20:29:51 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DVD Shrink [2010.12.02 10:05:56 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\dvdcss [2008.01.28 19:53:37 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\EPSON [2008.01.25 21:48:23 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FastStone [2010.10.08 19:24:16 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FILEminimizerPictures [2009.08.07 14:06:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FileZilla [2009.07.20 19:20:07 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FinalBurner Video DVD [2010.08.04 13:20:09 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FireShot [2010.02.24 06:32:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FlashGet [2009.02.02 18:07:50 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Flickr [2009.12.14 10:46:23 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Foxit [2010.06.01 15:07:50 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Foxit Software [2011.04.26 11:17:48 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Free Download Manager [2010.03.17 19:24:07 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FreeFLVConverter [2010.04.23 11:01:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\freeTVRadio [2009.07.20 22:11:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\GetRightToGo [2011.03.23 11:57:43 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\GlarySoft [2007.12.22 23:05:33 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\GMX [2007.11.27 12:06:36 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Google [2008.05.08 17:20:21 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\gtk-2.0 [2010.05.07 01:14:51 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\HandBrake [2010.08.30 10:32:38 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\HDD Thermometer [2008.09.18 22:59:31 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Help [2010.12.27 09:53:09 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\HTC Home [2010.11.11 22:10:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Hunspell [2009.08.06 11:57:11 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ICQ [2009.10.11 20:47:49 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Identities [2008.01.28 13:37:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\InstallShield [2009.08.13 13:57:16 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Intenium [2011.01.06 20:54:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Inventivio [2008.01.11 12:00:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\JAM Software [2010.02.09 09:35:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\JGoodies [2008.04.10 15:35:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\JoJoThumb [2009.01.15 23:20:56 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\jpg-Illuminator [2010.05.12 12:57:32 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\KeePass [2010.03.11 21:11:58 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Keseling [2008.09.22 09:54:18 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\klickTel [2007.12.31 00:21:45 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Lavasoft [2011.01.19 13:16:04 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Leadertech [2008.10.18 16:40:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Lexware [2011.01.19 13:13:29 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Logishrd [2011.01.19 13:16:12 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Logitech [2007.11.24 17:46:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Macromedia [2011.03.21 17:50:40 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\MagicBall4 [2009.03.26 19:32:44 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Malwarebytes [2008.12.19 14:52:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Map24 [2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Media Center Programs [2011.04.26 11:17:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Media Player Classic [2009.05.26 08:04:44 | 000,000,000 | --SD | M] -- C:\Users\Heiner\AppData\Roaming\Microsoft [2010.03.22 13:08:25 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\MOVAVI [2008.04.14 17:57:39 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Mozilla [2008.12.11 13:08:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\NAVIGON [2010.06.15 08:28:14 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\NCH Software [2010.03.17 15:41:16 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Nero [2008.07.31 19:18:53 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Nettalk [2009.02.02 18:02:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Nokia [2010.04.23 11:05:22 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\OfferBox [2008.08.26 18:04:05 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Open Source Applications Foundation [2008.12.14 19:08:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\OpenOffice.org [2008.12.14 18:49:28 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\OpenOffice.org2 [2011.04.04 21:32:29 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\OTRHomeloader [2010.05.27 16:55:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Panda Security [2010.12.21 10:50:19 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Participatory Culture Foundation [2009.02.02 18:02:37 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PC Suite [2010.12.21 10:51:33 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PCF-VLC [2010.12.02 10:27:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PCToolsFirewallPlus [2009.08.13 14:06:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Peace Craft [2010.11.18 11:28:54 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PeaceCraft2 [2008.08.26 18:03:07 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Python-Eggs [2010.10.19 11:15:18 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\QuickScan [2010.03.16 15:45:19 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Real [2010.05.13 21:03:13 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Returnil [2011.03.16 12:20:44 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Samsung [2007.11.24 22:20:34 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ScanSoft [2009.09.12 11:26:34 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ScreenSeven [2008.02.01 00:59:00 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\SimpleScreenshot [2010.07.29 11:55:28 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Skype [2008.08.14 09:23:14 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\skypePM [2010.03.31 12:51:13 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Software Informer [2010.11.25 21:41:36 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Spamihilator [2011.01.06 20:52:23 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Speak-A-Message [2010.09.09 14:14:51 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\SuperEasy [2010.03.09 09:42:41 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\SuperEasy Software [2011.02.21 12:14:39 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Systweak [2007.11.26 17:45:48 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\T-Online [2007.12.11 09:05:14 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Talkback [2007.11.25 00:14:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Template [2009.12.28 10:49:47 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Thunderbird [2007.12.07 09:04:40 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\TuneUp Software [2009.05.21 11:36:21 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\TVcentral-Core [2010.01.27 10:27:24 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Ulead Systems [2011.04.26 14:05:55 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Uniblue [2010.05.10 14:50:41 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Video DVD Maker FREE [2008.11.04 19:31:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ViewPicXXL [2010.11.03 09:16:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Vista Start Menu [2011.04.26 02:24:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\vlc [2011.04.28 17:38:01 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Vso [2011.01.01 16:23:57 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\René's Homepage [2008.01.18 07:45:54 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Yahoo! [2011.04.26 02:24:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ZSGebmahner [2009.10.11 20:47:49 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Zylom < %APPDATA%\*.exe /s > [2010.05.10 15:10:41 | 000,087,608 | ---- | M] () -- C:\Users\Heiner\AppData\Roaming\inst.exe [2010.12.27 09:52:37 | 000,260,096 | ---- | M] (Stealth Software) -- C:\Users\Heiner\AppData\Roaming\HTC Home\HTCHome (x64).exe [2010.12.27 09:52:37 | 000,261,120 | ---- | M] (Stealth Software) -- C:\Users\Heiner\AppData\Roaming\HTC Home\HTCHome.exe [2010.12.27 09:52:38 | 000,165,888 | ---- | M] (Stealth Software) -- C:\Users\Heiner\AppData\Roaming\HTC Home\Updater.exe [2010.12.27 09:51:20 | 000,277,504 | ---- | M] (Stealth Software) -- C:\Users\Heiner\AppData\Roaming\HTC Home\Uninstall\Uninstall.exe [2010.06.17 19:08:22 | 000,010,134 | R--- | M] () -- C:\Users\Heiner\AppData\Roaming\Microsoft\Installer\{116D1725-3193-49AF-8999-036D385F701E}\_07FC79487A9632D69318B3.exe [2011.01.19 13:16:03 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Heiner\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe [2009.02.02 17:32:33 | 000,004,286 | R--- | M] () -- C:\Users\Heiner\AppData\Roaming\Microsoft\Installer\{E2DAB18F-D5D4-435A-B033-6B8D0EAE4D7A}\_497245D8059E20FE841577.exe [2009.02.02 17:32:33 | 000,004,286 | R--- | M] () -- C:\Users\Heiner\AppData\Roaming\Microsoft\Installer\{E2DAB18F-D5D4-435A-B033-6B8D0EAE4D7A}\_6FEFF9B68218417F98F549.exe [2010.02.05 00:49:18 | 000,010,134 | R--- | M] () -- C:\Users\Heiner\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe [2011.02.01 19:04:18 | 000,052,616 | ---- | M] () -- C:\Users\Heiner\AppData\Roaming\Mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\toolbar@ask.com\chrome\content\issigned.exe [2011.03.27 15:04:11 | 003,325,832 | ---- | M] (Ask) -- C:\Users\Heiner\AppData\Roaming\Mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\toolbar@ask.com\chrome\temp\askToolbar.exe [2011.02.21 12:15:19 | 010,341,040 | ---- | M] (Systweak Inc ) -- C:\Users\Heiner\AppData\Roaming\Systweak\ASO3\Installer\aso3setup.exe < %SYSTEMDRIVE%\*.exe > [1997.08.05 01:00:00 | 000,014,123 | ---- | M] () -- C:\DIRSUCHE.EXE [2008.01.28 15:51:20 | 002,254,848 | ---- | M] (Mirko Böer) -- C:\SimpleScreenshot.exe < MD5 for: AGP440.SYS > [2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys [2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys [2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bb eb0d97a\AGP440.sys [2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647b bd2a4c6\AGP440.sys [2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys [2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys < MD5 for: ATAPI.SYS > [2009.04.10 23:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys [2009.04.10 23:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys [2009.04.10 23:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261ea b99e8\atapi.sys [2008.01.18 23:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys [2008.01.18 23:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a218 9ce9c\atapi.sys [2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys [2008.01.19 07:06:48 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys [2008.01.19 07:06:48 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a44247 9c42c\atapi.sys [2008.01.19 06:33:23 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da 31a8b\atapi.sys < MD5 for: CNGAUDIT.DLL > [2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll [2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll < MD5 for: IASTORV.SYS > [2008.01.18 23:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys [2008.01.18 23:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af1152788 7c7fa8f\iaStorV.sys [2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys [2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys < MD5 for: NETLOGON.DLL > [2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll [2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll [2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll [2008.01.18 23:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll < MD5 for: NVSTOR.SYS > [2007.01.05 21:59:42 | 000,035,920 | ---- | M] (NVIDIA Corporation) MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9 -- C:\Windows\System32\drivers\nvstor.sys [2007.01.05 21:59:42 | 000,035,920 | ---- | M] (NVIDIA Corporation) MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_45f67928\nvstor.sys [2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys [2008.01.18 23:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys [2008.01.18 23:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327be fea467\nvstor.sys < MD5 for: NVSTOR32.SYS > [2008.11.12 17:02:46 | 000,146,464 | ---- | M] (NVIDIA Corporation) MD5=1BEF40FDCA53B43E16E1851FAA3440CC -- C:\NVIDIA\nForceWinVistaInt\15.26\IDE\WinVista\sataraid\nvstor32.sys [2009.08.04 18:44:14 | 000,213,024 | ---- | M] (NVIDIA Corporation) MD5=269DE658DEAF032564E8B6430B5BD170 -- C:\NVIDIA\nForceWinVista\15.51\English\IDE\Win7\sataraid\nvstor32.sys [2009.08.04 18:44:14 | 000,213,024 | ---- | M] (NVIDIA Corporation) MD5=269DE658DEAF032564E8B6430B5BD170 -- C:\NVIDIA\nForceWinVista\15.51\English\IDE\WinVista\sataraid\nvstor32.sys [2009.08.04 18:43:40 | 000,213,024 | ---- | M] (NVIDIA Corporation) MD5=3FF57A9A657C9690ECBC8B1E3B6E3979 -- C:\NVIDIA\nForceWinVista\15.51\English\IDE\Win7\sata_ide\nvstor32.sys [2009.08.04 18:43:40 | 000,213,024 | ---- | M] (NVIDIA Corporation) MD5=3FF57A9A657C9690ECBC8B1E3B6E3979 -- C:\NVIDIA\nForceWinVista\15.51\English\IDE\WinVista\sata_ide\nvstor32.sys [2009.08.04 18:43:40 | 000,213,024 | ---- | M] (NVIDIA Corporation) MD5=3FF57A9A657C9690ECBC8B1E3B6E3979 -- C:\Windows\System32\drivers\nvstor32.sys [2009.08.04 18:43:40 | 000,213,024 | ---- | M] (NVIDIA Corporation) MD5=3FF57A9A657C9690ECBC8B1E3B6E3979 -- C:\Windows\System32\DriverStore\FileRepository\nvstor32.inf_dcdb2e54\nvstor32.sy s [2007.07.03 01:37:08 | 000,110,112 | ---- | M] (NVIDIA Corporation) MD5=A1CE1A6FD74C046F029448FCFA5E386D -- C:\Windows\System32\DriverStore\FileRepository\nvstor32.inf_efe24208\nvstor32.sy s [2008.11.12 17:02:18 | 000,146,464 | ---- | M] (NVIDIA Corporation) MD5=BB4DD678706510D9249EED1DA0219900 -- C:\NVIDIA\nForceWinVistaInt\15.26\IDE\WinVista\sata_ide\nvstor32.sys [2008.11.12 17:02:18 | 000,146,464 | ---- | M] (NVIDIA Corporation) MD5=BB4DD678706510D9249EED1DA0219900 -- C:\Windows\System32\DriverStore\FileRepository\nvstor32.inf_b40e17fb\nvstor32.sy s [2007.08.09 19:12:30 | 000,110,624 | ---- | M] (NVIDIA Corporation) MD5=DC5F166422BEEBF195E3E4BB8AB4EE22 -- C:\Windows\System32\DriverStore\FileRepository\nvstor32.inf_99d8b088\nvstor32.sy s [2008.01.26 03:02:02 | 000,140,832 | ---- | M] (NVIDIA Corporation) MD5=FA7B8ECA6E845B244B7E30A9DCD82C6C -- C:\Windows\System32\DriverStore\FileRepository\nvstor32.inf_ef43fd49\nvstor32.sy s < MD5 for: SCECLI.DLL > [2008.01.18 23:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\sce cli.dll [2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\sce cli.dll [2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll [2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\sce cli.dll < MD5 for: USERINIT.EXE > [2008.01.18 23:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe [2008.01.18 23:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe [2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe < MD5 for: WS2IFSL.SYS > [2006.11.02 10:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_4d4fded8cae2956d\ws2ifsl.sys [2008.01.18 21:56:50 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys [2008.01.18 21:56:50 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > [2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV [2006.11.02 12:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV [2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV [2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV [2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [2011.04.15 09:49:56 | 000,353,792 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\dxtmsft.dll [2011.04.15 09:49:56 | 000,223,232 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\dxtrans.dll [2006.11.02 09:10:21 | 000,068,992 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\MMSYSTEM.DLL [2011.04.15 09:49:50 | 000,420,864 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\vbscript.dll [2006.09.18 23:43:37 | 000,013,312 | ---- | M] () Unable to obtain MD5 -- C:\Windows\System32\win87em.dll [2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] ========== Alternate Data Streams ========== @Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:1CA73D29 @Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:7E95B6FD < End of report > |
|
|
|
|
|
#12 (Direktlink) |
|
Super-Moderator
![]() Registriert seit: 08.02.2010
Beiträge: 1.728
|
Kurze Info
Ein Moderator wird gleich die Links in deinem Hostfile löschen. Den es gibt genung neugierige Mitmenschen die gerne auf solche verlockenden Links klicken. Das Log von OTL werd ich mir morgen anschauen. Das schaffe ich heute zeitlich nicht mehr.
__________________
Gruß Leo
|
|
|
|
|
|
#13 (Direktlink) |
|
War schon mal da
![]() Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
|
Und nun die Extras:
OTL Extras logfile created on: 28.04.2011 20:52:00 - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Downloads Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 0,00 Gb Available Physical Memory | 20,00% Memory free 6,00 Gb Paging File | 4,00 Gb Available in Paging File | 72,00% Paging File free Paging file location(s): c:\pagefile.sys 4092 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 143,19 Gb Total Space | 61,37 Gb Free Space | 42,86% Space Free | Partition Type: NTFS Drive D: | 5,86 Gb Total Space | 0,82 Gb Free Space | 13,97% Space Free | Partition Type: NTFS Drive J: | 1,88 Gb Total Space | 0,11 Gb Free Space | 5,58% Space Free | Partition Type: FAT Computer Name: HEINER-PC | User Name: Heiner | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [Browse with &IrfanView] -- "C:\Program Files\iview410g\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [Durchsuchen mit &IrfanView] -- "C:\Program Files\iview410g\i_view32.exe" "%1 /thumbs" (Irfan Skiljan) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Directory [Unstopcp] -- "C:\Datenrettung CD-DVD\Roadkil.Net\UnstopCpy_5_2_Win2K_UP.exe" "%1" * (Roadkil.Net) Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" Directory [Winamp.Play] -- "C:\Program Files\Winamp\Winamp.exe" "%1" Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 1 "InternetSettingsDisableNotify" = 1 "AutoUpdateDisableNotify" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 1 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-153915148-350753066-3938573312-1000] "EnableNotifications" = 1 "EnableNotificationsRef" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir ewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DefaultOutboundAction" = 0 "DefaultInboundAction" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir ewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DefaultOutboundAction" = 0 "DefaultInboundAction" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir ewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DefaultOutboundAction" = 0 "DefaultInboundAction" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir ewallPolicy\FirewallRules] "{190C5382-2844-46F0-8708-2B9F116B7707}" = lport=445 | protocol=6 | dir=in | app=system | "{2284A150-AB0D-4665-90F1-864344CC6930}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{2D02807E-472A-4DF8-8008-B526C24FC64C}" = lport=139 | protocol=6 | dir=in | app=system | "{3CBB23E3-314A-4E14-B1AE-36C89562211E}" = lport=445 | protocol=6 | dir=in | app=system | "{59CDE329-0052-45F6-9FAB-EA70AB3B0137}" = lport=rpc | protocol=6 | dir=in | app=c:\windows\system32\vdsldr.exe | "{681A550A-EA2C-4F39-9998-97611FEEE672}" = rport=137 | protocol=17 | dir=out | app=system | "{688D4605-8574-4087-B64B-4425C3C5D102}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{93FAFAD3-FC9E-4E0D-B0D8-31D622B92F01}" = lport=137 | protocol=17 | dir=in | app=system | "{9643BA87-279D-4D73-9E86-BC3200623CEA}" = rport=445 | protocol=6 | dir=out | app=system | "{986EE4AF-86FD-4969-A50D-B517DD12668C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{A4A2EB55-CB10-4B95-AEAD-5A7E7778D2FC}" = lport=rpc | protocol=6 | dir=in | svc=vds | app=c:\windows\system32\vds.exe | "{C0708B4C-5FBE-482E-AF04-FC89D74BD3F2}" = lport=rpc | protocol=6 | dir=in | app=c:\windows\system32\services.exe | "{C4F8620C-9343-4075-8181-361547F4C553}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe | "{C93A236F-E66E-470D-86ED-FE0991914B6E}" = lport=138 | protocol=17 | dir=in | app=system | "{E4A478F2-D103-45A4-93BD-86ED1B248D58}" = lport=2869 | protocol=6 | dir=in | app=system | "{E4EC8BC0-DF76-4B7A-B9F9-37874ADB4D34}" = rport=138 | protocol=17 | dir=out | app=system | "{E7CFE094-BA47-4B0D-9EC9-D9907046D0A0}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=datei- und druckerfreigabe (spoolerdienst - rpc-epmap) | "{E8E88AC4-C9EB-4F75-9D88-9DAFED44023F}" = rport=139 | protocol=6 | dir=out | app=system | "{EF722AB7-4831-4356-965D-8F2B437CD3E1}" = lport=rpc | protocol=6 | dir=in | svc=* | app=c:\windows\system32\svchost.exe | "{F6599DB0-2961-4E31-A512-4D9D8C9365AF}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{F9BA4B07-E70C-4F53-8DE9-6CAC3A1A87CB}" = lport=445 | protocol=6 | dir=in | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir ewallPolicy\FirewallRules] "{0A27D42E-19A9-4372-9F10-3C213DF883C6}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) | "{1A7A76BA-1DFA-4945-9FE2-5FB16D2DB39F}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | "{32BA0E6C-EB38-4E18-A270-1834E4DBC321}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) | "{354C188E-F533-4FB9-9DBF-EA80BAF0676B}" = protocol=58 | dir=out | name=datei- und druckerfreigabe (echoanforderung - icmpv6 ausgehend) | "{39A471AC-D97F-4081-8AF5-DA8C0F09E17F}" = protocol=6 | dir=out | app=%systemroot%\system32\msra.exe | "{4201C0F6-DF13-458A-AA4B-2CC3E180332D}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe | "{45CDEE4D-6A16-4FEE-8BA7-49A443D9C7B5}" = protocol=6 | dir=in | app=c:\program files\smart pc utilities\vista services optimizer\servicesoptimizer.exe | "{514EB1A7-E7E6-454E-9814-96519C6E2B02}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) | "{6C1B1B9A-B644-4836-A3CA-2A0F45D67892}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) | "{7240C3C1-4C41-44BB-90CE-FD75D86EE57F}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe | "{7BBC6197-3BEF-4A5A-80A9-1276C57C5CA9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{7CCB871C-9F58-4697-8F7E-DD3A87AF2247}" = protocol=6 | dir=in | app=c:\program files\smart pc utilities\vista services optimizer\webupdate.exe | "{823F4366-5D8E-416C-B01C-E771CAAF9A7D}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) | "{84936D85-0099-4DC1-8514-8662B834D9AA}" = protocol=17 | dir=in | app=c:\program files\smart pc utilities\vista services optimizer\webupdate.exe | "{8515CB08-6EB3-46FF-84D4-C25F329D6DC5}" = protocol=1 | dir=out | name=datei- und druckerfreigabe (echoanforderung - icmpv4 ausgehend) | "{888E331B-FC98-4182-B66F-A9B30ED24BA2}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) | "{94E4F1A8-B91B-41AC-BF71-ECF8263B1ED0}" = protocol=58 | dir=in | name=datei- und druckerfreigabe (echoanforderung - icmpv6 eingehend) | "{96D565C3-2682-4D6D-A9B5-FF5B7D07DEF7}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{9E3C71D8-8064-4B08-9FAC-CE81C3AEBC9B}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe | "{B6B41BA0-394E-4BE2-A309-8DE2FEA95C9C}" = protocol=1 | dir=in | name=sisoftware deployment agent service (icmp-in) | "{BF64FB08-07D2-400F-B17D-B51E7C472BE5}" = protocol=1 | dir=in | name=datei- und druckerfreigabe (echoanforderung - icmpv4 eingehend) | "{BF82C2D6-F950-451D-9540-B0ED13438FED}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe | "{C26DEA38-24DD-46AB-A148-63DE2AB26EF1}" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe | "{CE66ECFD-1DFF-4C87-901E-381F0E44C19B}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe | "{D43BA01B-F82B-4C6F-8D91-CF371309DD14}" = protocol=6 | dir=in | app=%systemroot%\system32\msra.exe | "{E1A9991B-53ED-4E7C-B092-95A0337B1D32}" = protocol=17 | dir=in | app=c:\program files\smart pc utilities\vista services optimizer\servicesoptimizer.exe | "TCP Query User{076D0914-C4DB-45CE-A22E-9E1210CA296F}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "TCP Query User{46FBEC16-CA29-4548-A61D-192EB9B2E62C}C:\nof 7\fusion.exe" = protocol=6 | dir=in | app=c:\nof 7\fusion.exe | "TCP Query User{9FC97A35-8FF4-4F06-B6B4-CF28BC3F57A7}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe | "TCP Query User{BA4F7EBF-EB5A-4F08-870D-578CD550F66B}C:\program files\klebezettel ng\klebez.exe" = protocol=6 | dir=in | app=c:\program files\klebezettel ng\klebez.exe | "UDP Query User{125FE2CE-D5B6-4EFC-BAEA-7F50C8858CAB}C:\program files\klebezettel ng\klebez.exe" = protocol=17 | dir=in | app=c:\program files\klebezettel ng\klebez.exe | "UDP Query User{4234D505-5655-4F92-BFF0-2D5ED66D65DB}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe | "UDP Query User{44A435C3-870C-4EBE-831F-5865A887AF44}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "UDP Query User{7463C81B-4031-4A4D-9087-C6C54173A476}C:\nof 7\fusion.exe" = protocol=17 | dir=in | app=c:\nof 7\fusion.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{00C58EBE-223E-4AB6-8AE9-38F27F4420BD}" = WISO Sparbuch 2009 "{00D0200F-3B4D-4A2F-869E-533ED835A943}" = Hervorhebe-Funktion (Windows Live Toolbar) "{01CCDA56-6D59-4915-8BE2-752376E80E82}" = Hide-My-Address "{048DB452-C8B0-4A8D-89AF-84A6B149E1EE}" = Meine Software "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack "{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA}" = Uniblue RegistryBooster "{0EE4030A-8FD4-4798-A21D-17E525B1F7CF}" = Corel Snapfire "{108A39BF-4ED1-4293-B11A-06BD521FB8F7}" = FreeOCR 3.0 "{116D1725-3193-49AF-8999-036D385F701E}" = Desktop Restore "{119B7481-0216-40D2-A5CC-C3E1F461ECC1}" = Windows Live Fotogalerie "{12665B01-3F3A-4433-B179-9D8E352D7547}" = Try Corel Snapfire muvee autoProducer add on "{13CD417D-F1F1-4AC4-945D-FDDEB884756F}" = Microsoft Baseline Security Analyzer 2.2 "{15AC0C5D-A6FB-4CE2-8CD0-28179EEB5625}" = Nokia Connectivity Cable Driver "{18A5DFF2-8A95-49F3-873F-743CB5549F3D}" = Canon ScanGear Starter "{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1 "{1C63DD23-6554-4A1F-8D0D-B5A6B49D8015}" = Corel Graphics Suite 11 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{2119BCD0-09CA-403B-92A1-35A13C33E179}" = Epson Customer Research Participation "{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86 "{218761F6-CBF6-4973-B910-A33E6563A1EA}" = Windows Live Toolbar-Erweiterung (Windows Live Toolbar) "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{23B265D4-42E0-405B-B285-1782F629E049}" = 5CentSMS "{23B72D50-1C7E-491C-8086-9E060051D316}" = Manual CanoScan LiDE 60 "{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = Media Player Classic - Home Cinema v. 1.3.1249.0 "{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 24 "{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2 "{295C31E5-3F91-498E-9623-DA24D2FA2B6A}" = T-Online WLAN-Access Finder "{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes "{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour "{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support "{2DD6C198-FA9A-40B4-8DE5-CE5206E3EB34}" = Smart Menus (Windows Live Toolbar) "{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component "{319786B7-D72F-43B3-99C1-E93724ED17D3}" = Lexware online banking 4.90 "{3744B641-61DE-417F-BCDC-9CCED4224DF8}" = LightScribe System Software "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll "{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg "{43B74FAB-FB58-447D-8D3A-5F638AF36FD1}" = Netzmanager "{46B70DEB-97B3-4E38-B746-EC16905E6A8F}" = WISO Sparbuch 2010 "{485DF5E7-8379-4BFA-BAE1-9B8DBFE0D6B4}" = Paragon Backup & Recovery™ 10 Home "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4B6F67C5-D103-4329-A70A-F80BEEC26B70}" = Marco Polo TravelRouting Europe 2003 "{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update "{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}" = Microsoft Works "{4F81901F-3655-4340-8227-F687F69A3C79}}_is1" = Klebezettel NG (Version 2.9.9) "{54B1E5A3-1B29-4582-A226-172A1FC7BA6C}" = Windows Live Family Safety "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime "{5A166C0B-9557-4364-A057-F946D674E6AC}" = Windows Live Mail "{5C474A83-A45F-470C-9AC8-2BD1C251BF9A}" = Skype™ 4.2 "{5C98D841-6392-41F1-A80E-B1A741F32A95}" = DSL-Speedtest "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call "{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5 "{65883ddf-2152-4cb7-8e13-b99194b13498}" = Nero BackItUp "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{69097103-1F00-469D-BDE7-CAF50E241647}" = 5CentSMS "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{70B7A167-0B88-445D-A3EA-97C73AA88CAC}" = Windows Live Toolbar "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser und SDK "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{735DEB9C-61BD-4D31-994B-92395BBB4E45}" = Microsoft XML Parser "{7373184D-8E8F-4308-912A-3901071FA1AD}" = LightScribe Applications "{738D0F96-2F2A-4650-B7C7-2C724D662091}" = 5CentSMS "{75c53f52-398b-4d66-b28a-f9ef170b3b34}" = Nero BackItUp "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites für Windows Live Toolbar "{79A3E733-3887-4043-8E32-C6A2577CF73C}" = klickTel OEM 2008 "{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}" = OmniPage SE "{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager "{7ff45382-e5a7-4772-b46d-a5c71f3a15d6}" = Nero BackItUp 4 Essentials "{81821BF8-DA20-4F8C-AA87-F70A274828D4}" = Windows Live Writer "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{837B6259-6FF5-4E66-87C1-A5A15ED36FF4}" = Windows Live Messenger "{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}" = Windows Live Anmelde-Assistent "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar "{878B631B-E0F9-41B9-83D9-BC9DFB0B9F2B}" = Ebad "{8944ED10-DBF2-4FA9-8B5D-D7E1B046C761}_is1" = ColdCut "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) "{8B79684C-6DAC-438C-8F30-10DF65C2068F}" = Samsung Digital Camera "{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}" = Camera RAW Plug-In for EPSON Creativity Suite "{8FBC9407-713D-4B8A-98D2-57210DA56049}" = MSN Toolbar "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard "{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System "{90141793-E338-4EEB-B7E8-8CDED19D908D}" = 5CentSMS "{91E04CA7-0B13-4F8C-AA4D-2A573AC96D19}" = Windows Live Essentials "{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{97C82B44-D408-4F14-9252-47FC1636D23E}_is1" = IZArc 3.81 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A0B139A7-E8D5-49E8-A7BF-12421E652208}" = pdfforge Toolbar v4.3 "{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175 "{A1973A71-BC23-4A8C-A0A0-2B0497B7EAF4}" = WISO Sparbuch 2008 "{A306FD29-7D3A-4287-91AC-9A0180931395}_is1" = Roadkil's Unstoppable Copier Version 5.2 "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint "{B1275E23-717A-4D52-997A-1AD1E24BC7F3}" = T-Online 6.0 "{B24E05CC-46FF-4787-BBB8-5CD516AFB118}" = ccCommon "{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center "{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 260.99 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 260.99 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B3C1579F-C9BB-4479-B343-B22C5C283D47}" = Vista Services Optimizer "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B4E4ACA0-79C5-4FC0-818F-ECE4521EBF8D}" = COMPUTERBILD-Abzockschutz "{B4E96960-5F6B-48B9-A5BD-6A5A9BB4F027}" = Avery Wizard 3.1 "{B525BB2C-9338-11D4-8B84-00B0D03E6A83}" = Palm Conduit Support for COM "{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center "{BA165460-FCF7-4D6C-A7A2-F2321700720F}" = MobileMe Control Panel "{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) "{BE4FE60C-A636-4017-B3FF-0EE7C39EAAF2}" = Speak-A-Message "{BFBB91DB-9F0F-4A9C-9669-A97DA3512CF2}" = RealSpeak Solo fur Deutsch - Steffi "{C5C649A8-1D21-4C83-9B08-7B3752E580F4}" = Safari "{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser "{CA9BCD4D-B782-4637-8F1F-F9A328D3C244}" = CanoScan Toolbox Ver4.9 "{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CF25B0C4-A162-49C8-94FA-FFCFC8BD59FE}" = AstroStar 11.0 "{D263A9AE-0B59-4C01-B72B-DD3CA956BA58}" = Favicon-Manager "{D848D140-41C3-4A53-86D8-E866A100B4****" = PC Connectivity Solution "{D980202C-4681-4D9A-848C-875ABAA1870A}" = soft Xpansion PDF Quick Master 4.0 "{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.16.360 "{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader "{DFAA3D2B-7087-464E-823B-738A23C29C27}" = Microsoft Visual J# 2.0 Redistributable Package - SE "{E2DAB18F-D5D4-435A-B033-6B8D0EAE4D7A}" = Desk Drive "{E3723A04-A894-4036-A78E-282E18F43C0A}_is1" = Tinypic 3.14 "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack "{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer "{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}" = ScanToWeb "{ED636101-1959-4360-8BF7-209436E7DEE4}" = Windows Live Sync "{F0312AC6-988B-11DA-9C49-000476F770CC}" = CIB pdf brewer 2.5.26 "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter "{F54B04F8-44B6-4218-82B9-69A28B69A61D}" = DDBAC "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "{F7E345A5-F79B-44EE-BC4A-738899E756C0}" = Lexware online banking 4.90 "{F8013DD1-574B-4921-A473-88A2F7A34D16}" = Paragon Drive Backup™ 9 Personal "{F82C6574-AD88-4B40-A432-970BC77F1BD2}" = DesignPro 5 "{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}" = Vista Codec Package "{FC008FF3-3006-4316-8845-6681379A21BB}" = 5CentSMS "{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "3554AA4B-9B0B-451a-A269-2B5F53982209_is1" = ThreatFire "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "AFPL Ghostscript 8.54" = AFPL Ghostscript 8.54 "AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts "Ashampoo Burning Studio 10_is1" = Ashampoo Burning Studio 10.0.7 "Ashampoo PowerUp 3_is1" = Ashampoo PowerUp 3.10 "Ashampoo PowerUP XP Platinum 2" = Ashampoo PowerUP XP Platinum 2 "Ashampoo WinOptimizer 4_is1" = Ashampoo WinOptimizer 4.51 "avast" = avast! Pro Antivirus "B076073A-5527-4f4f-B46B-B10692277DA2_is1" = DisplayFusion 3.0.6 "BabylonToolbar" = Babylon toolbar "Balabolka" = Balabolka "cayahooantispy" = CA Yahoo! Anti-Spy (remove only) "CCleaner" = CCleaner "CheckDrive_is1" = CheckDrive "Chronik" = Chronik "conduitEngine" = Conduit Engine "Core FTP LE 2.1" = Core FTP LE 2.1 "Corel Applications" = Corel Applications "Debut" = Debut Video Capture Software "DEUTSCHLAND SPIELT Spiele Post" = DEUTSCHLAND SPIELT Spiele Post "DFX for Windows Media Player" = DFX for Windows Media Player "DiceDungeon" = DiceDungeon 0.98.0.29 "DivX Setup.divx.com" = DivX-Setup "Driver Genius Professional Edition_is1" = Driver Genius Professional Edition "DVD Flick_is1" = DVD Flick 1.3.0.7 "DVD Shrink_is1" = DVD Shrink 3.2 "EPSON Scanner" = EPSON Scan "EPSON Stylus SX100_TX100 Benutzerhandbuch" = EPSON Stylus SX100_TX100 Handbuch "EPSON SX100 Series" = EPSON SX100 Series Printer Uninstall "EURO-XL8" = Microsoft Excel Euro Toolbar Addin (Remove only) "EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v4.60 "ffdshow_is1" = ffdshow [rev 2946] [2009-05-15] "FileMenu Tools_is1" = FileMenu Tools "FILEminimizer Pictures_is1" = FILEminimizer Pictures "FileZilla Client" = FileZilla Client 3.2.6.1 "FlashLynx" = FlashLynx Video Download Software "Flickr Uploadr" = Flickr Uploadr 3.0.5 "Folder Guide" = Folder Guide "Foxit Reader" = Foxit Reader "Foxit Toolbar" = Foxit Toolbar "Free Download Manager_is1" = Free Download Manager 3.0 "FreePDF_XP" = FreePDF XP (Remove only) "Google Updater" = Google Updater "GPL Ghostscript 8.63" = GPL Ghostscript 8.63 "Handbrake" = Handbrake 0.9.4 "Hdd Speed Test Tool_is1" = Hdd Speed Test Tool v. 1.0.14 (RC 1) "HDD Thermometer" = HDD Thermometer "HijackThis" = HijackThis 2.0.2 "Icon Restore_is1" = Icon Restore 1.0 "ICQToolbar" = ICQ Toolbar "InstallShield_{1C63DD23-6554-4A1F-8D0D-B5A6B49D8015}" = CorelDRAW Graphics Suite 11 "InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager "InstallShield_{CF25B0C4-A162-49C8-94FA-FFCFC8BD59FE}" = AstroStar 11.0 "InstallShield_{F82C6574-AD88-4B40-A432-970BC77F1BD2}" = DesignPro 5 "IrfanView" = IrfanView (remove only) "JDiskReport 1.3.2" = JGoodies JDiskReport 1.3.2 "JetDrive_is1" = JetDrive "LHTTSGED" = L&H TTS3000 Deutsch "MailStore Home_is1" = MailStore Home 4.2.0.5431 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Map24 Desktop_is1" = Map24 Desktop "MAXA Cookie Manager Lite_is1" = MAXA Cookie Manager Lite 3.01 "MAXA Cookie Manager_is1" = MAXA Cookie Manager Standard 3.3 "MAXA-Lock_is1" = MAXA-Lock Standard "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Microsoft Visual J# 2.0 Redistributable Package - SE" = Microsoft Visual J# 2.0 Redistributable Package - SE "MozBackup_is1" = MozBackup 1.4.7 "Mozilla Firefox (3.6b2)" = Mozilla Firefox (3.6b2) "Mozilla Firefox 4.0 (x86 de)" = Mozilla Firefox 4.0 (x86 de) "Mozilla Thunderbird (3.1.9)" = Mozilla Thunderbird (3.1.9) "MyAshampoo Toolbar" = MyAshampoo Toolbar "NAVIGON Fresh" = NAVIGON Fresh 3.2.0 "NAVIGON Sync" = NAVIGON Sync 1.0 "NetObjects Fusion 7" = NetObjects Fusion 7 "Nettalk_is1" = Nettalk 6.5 "Netzmanager" = Netzmanager "NVIDIA Drivers" = NVIDIA Drivers "Office8.0" = Microsoft Office 97, Professional Edition "OTR Homeloader" = OTR Homeloader 1.5.8.129 "PC SECURITY TEST 2007_is1" = PC SECURITY TEST 2007 "PikySuite_is1" = PikySuite 3.0 "Prism" = Prism Video Converter "Quicken 2000" = Quicken 2000 "Recuva" = Recuva "Redirection Port Monitor" = RedMon - Redirection Port Monitor "Revo Uninstaller" = Revo Uninstaller 1.92 "Secunia PSI (RC4)" = Secunia PSI (RC4) "ShiftN_is1" = ShiftN 3.4 "softonic-de3 Toolbar" = softonic-de3 Toolbar "Software Informer_is1" = Software Informer 1.0 BETA "SpeedBit Video Accelerator" = SpeedBit Video Accelerator "SSC Service Utility_is1" = SSC Service Utility v4.30 "ST6UNST #1" = VistawinExit 3 Freeware "ST6UNST #2" = Zahlen des Lebens "ST6UNST #3" = Zahlen des Lebens (C:\Program Files\Zahlen des Lebens\) "SyncBack_is1" = SyncBack "SystemRequirementsLab" = System Requirements Lab "Taskbar Shuffle_is1" = Taskbar Shuffle version 2.5 "Thoosje Vista Tweaker" = Thoosje Vista Tweaker "Tidy Favorites Buttons_is1" = Tidy Favorites Buttons 6.23 "TIPP10_is1" = TIPP10 Version 2.0.3 "TreeSize Free_is1" = TreeSize Free V2.1 "TUGZip_is1" = TUGZip 3.5 "Uniblue RegistryBooster" = Uniblue RegistryBooster "Uninstall_is1" = Uninstall 1.0.0.1 "Unlocker" = Unlocker 1.9.0 "ViewpointMediaPlayer" = Viewpoint Media Player (Remove Only) "Vista Start Menu_is1" = Vista Start Menu 3.67 "VLC media player" = VLC media player 1.1.9 "WhoisAssistant_is1" = WhoisAssistant 1.1 "Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner "WinHTTrack Website Copier_is1" = WinHTTrack Website Copier 3.42 "WinLiveSuite_Wave3" = Windows Live Essentials "Winload Toolbar" = Winload Toolbar "WinSmile WiZi" = WinSmile WiZi "XMedia Recode" = XMedia Recode 2.2.1.6 "xp-AntiSpy" = xp-AntiSpy 3.96-8 "Xvid_is1" = Xvid 1.2.2 final uninstall "XXConsole" = XXConsole: Super Console Generator ver 0.93 "Yahoo! Companion" = Yahoo! Toolbar "Yahoo! Customizations" = Yahoo! Extras "Yahoo! Messenger" = Yahoo! Messenger "Z-defragRAM" = Z-defragRAM "ZehbeSoft Geburtstagsmahner" = ZehbeSoft Geburtstagsmahner ========== Last 10 Event Log Errors ========== [ Antivirus Events ] Error - 04.01.2008 04:12:11 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522 Description = Error - 07.04.2008 05:38:54 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522 Description = Error - 07.04.2008 12:10:14 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522 Description = Error - 07.11.2008 11:15:47 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522 Description = Error - 01.01.2009 08:10:18 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522 Description = Error - 20.01.2009 14:19:47 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522 Description = Error - 20.01.2009 14:22:01 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522 Description = Error - 12.11.2009 08:42:31 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522 Description = Error - 09.03.2010 20:29:41 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522 Description = Error - 16.08.2010 12:47:32 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522 Description = ========== Last 10 Event Log Errors ========== Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt! < End of report > |
|
|
|
|
|
#14 (Direktlink) |
|
War schon mal da
![]() Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
|
Und zum Schluß noch "Malwarebytes"
Malwarebytes' Anti-Malware 1.50.1.1100 Malwarebytes : Free anti-malware, anti-virus and spyware removal download Datenbank Version: 6464 Windows 6.0.6002 Service Pack 2 Internet Explorer 9.0.8112.16421 28.04.2011 20:29:50 mbam-log-2011-04-28 (20-28-27).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 413742 Laufzeit: 2 Stunde(n), 47 Minute(n), 36 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 1 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 3 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGR AM FILES\COMMON FILES\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> No action taken. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: c:\program files\Rock XP4\rockxp4.exe.part (PUP.PWDump) -> No action taken. c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> No action taken. c:\program files\vistawinexit\timerv.exe (Trojan.Agent) -> No action taken. Puuuh...das wars. Kannst Du damit etwas anfangen? Liebe Grüße Heiner (lillimucki zieht hier wohl nicht mehr... |
|
|
|
|
|
#15 (Direktlink) |
|
War schon mal da
![]() Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
|
Hallo Leo
jetzt klappt auch die Firewall nicht mehr. Beim Aufruf kommt folgende Mitteilung: ![]() Ein erneuter Suchlauf mit Malwarebytes gab keinen Befund. Als Virenscanner habe ich den Avast Pro. Liebe Grüße lillimucki |
|
|
|
|
![]() |
|
| Lesezeichen |
| Themen-Optionen | |
| Ansicht | |
|
|
Ähnliche Themen
|
||||
| Thema | Autor | Forum | Antworten | Letzter Beitrag |
| Abgesicherter Modus? | AHT | Spezielles | 3 | 16.10.2009 11:26 |
| abgesicherter modus | vollidiot | Windows XP | 3 | 05.02.2009 00:54 |
| Abgesicherter Modus | blaurxs | Windows XP | 2 | 18.01.2008 12:07 |
| Abgesicherter Modus | Jogi | Windows XP | 3 | 02.01.2006 17:57 |
| abgesicherter Modus | Schnitzelbrot | Windows XP | 5 | 15.07.2004 22:16 |