Paules-PC-Forum.de Anzeige:

Microsoft Windows Intune: PC-Verwaltung und -Sicherheit in der Cloud: Updateverwaltung, Anti-Virus und vieles mehr!


Zurück   Paules-PC-Forum.de > PC-Sicherheit > Viren-Forum

Viren-Forum über Viren, Dialer, Trojaner, Spyware etc.

EM-Tippspiel

Paule bei Facebook


Paule bei Twitter


Letzte Forenthemen
Gehe zum ersten neuen Beitrag PPF - Spiel "Wörter weiter...
Aufrufe: 26918, Antworten: 4218
Gehe zum ersten neuen Beitrag Algorithmen Teil IV...
Aufrufe: 3328, Antworten: 122
Gehe zum ersten neuen Beitrag Von Live CD Windowspfad...
Aufrufe: 314, Antworten: 19
Bundesliga-Tippspiel Saision...
Aufrufe: 7646, Antworten: 185
Gehe zum ersten neuen Beitrag Captur 2.2 (Snow Leo)
Aufrufe: 21, Antworten: 0
Gehe zum ersten neuen Beitrag Captur 2.3 (Lion)
Aufrufe: 24, Antworten: 0
Gehe zum ersten neuen Beitrag Acer Aspire 8745ZG fährt...
Aufrufe: 59, Antworten: 6
Gehe zum ersten neuen Beitrag Rechner fährt herunter,...
Aufrufe: 146, Antworten: 9
Gehe zum ersten neuen Beitrag avs4you_com Lizenz oder Abo?
Aufrufe: 72, Antworten: 4
Gehe zum ersten neuen Beitrag PPF - Shoppingwahn
Aufrufe: 50944, Antworten: 1395
Zeige:





Antwort
 
LinkBack Themen-Optionen Ansicht
Alt 27.04.2011, 09:22   #1 (Direktlink)
War schon mal da
 
Benutzerbild von lillimucki
 
Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
Blinzeln Abgesicherter Modus - automatische Aktivierung deaktivieren?

Guten Tag
ich bin hier neu registriert, war aber schon oft als Gast hier. Nun habe ich eine Frage:
Beim Neustart des Systems kommt automatisch der abgesicherte Modus. Gibt es eine Möglichkeit, diesen abzuschalten und bei Bedarf auf F8 beim Starten zurückzugreifen?
Liebe Grüße
lillimucki

P.S. Windows Vista Home Premium 32bit
lillimucki ist offline   Mit Zitat antworten
Werbung

Windows 7 Tipps und Tricks in Bildern

Alt 27.04.2011, 09:39   #2 (Direktlink)
sea
Super-Moderator
 
Benutzerbild von sea
 
Registriert seit: 31.10.2005
Ort: N51°26'24''E8°22'42''
Beiträge: 10.173
Standard

Hallo

Frage ist wieso kommt es nach dem Neustart dazu das der Rechner abgesichert bootet ? Hast du am System etwas geändert und seit wann hast du das Problem ?

Hast du im Gerätemanager Warneinträge in Form von ? oder !
__________________
viele Grüsse von sea

----------------------------------------------------------------------
SUPPORTER DES MONATS FEBRUAR 2010 von PCVISIT
----------------------------------------------------------------------
meine Homepage: http://www.pcdietmar.info
Biete auf Wunsch kostenlose Fernwartung/Diagnose per PC Visit an
sea ist offline   Mit Zitat antworten
Alt 27.04.2011, 09:52   #3 (Direktlink)
War schon mal da
 
Benutzerbild von lillimucki
 
Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
Standard

Hallo sea
das Problem tritt nur beim Neustart auf. Nicht beim normalen Hochfahren. Es besteht seit ca 3 Wochen. Gestern machte ich einen kompletten Virenscan mit Avast Pro und es wurde 1 infizierte Datei gefunden. Der Versuch über Wiederherstellung vor diesem Zeitraum hat keine Änderung gebracht. Es ist nur lästig, jedesmal den "normalen Start" anzuklicken.
Liebe Grüße
lillimucki
lillimucki ist offline   Mit Zitat antworten
Alt 27.04.2011, 09:56   #4 (Direktlink)
sea
Super-Moderator
 
Benutzerbild von sea
 
Registriert seit: 31.10.2005
Ort: N51°26'24''E8°22'42''
Beiträge: 10.173
Standard

Hallo



Wenn ein Virenverdacht vorliegt sollte das mal genauer unter die Lupe genommen werden.Ich schieb den Beitrag in den Virenbereich. Dort meldet sich dann ein Virenmoderator mit weiteren Anweisungen.
__________________
viele Grüsse von sea

----------------------------------------------------------------------
SUPPORTER DES MONATS FEBRUAR 2010 von PCVISIT
----------------------------------------------------------------------
meine Homepage: http://www.pcdietmar.info
Biete auf Wunsch kostenlose Fernwartung/Diagnose per PC Visit an
sea ist offline   Mit Zitat antworten
Alt 27.04.2011, 13:06   #5 (Direktlink)
Super-Moderator
 
Registriert seit: 08.02.2010
Beiträge: 1.728
Standard

Hallo,


Gehe auf Start --> Gebe unten in der Leiste msconfig ein --> Drücke die Taste Enter --> Wähle im Fenster den Reiter Start aus --> Erstelle ein Screenshot --> "Poste" das Bild.


Außerdem reiche das Log mit der Virenmeldung von Avast nach.
__________________
Gruß Leo

Der Leo ist offline   Mit Zitat antworten
Werbung

Windows 7 Tipps und Tricks in Bildern

Alt 27.04.2011, 14:36   #6 (Direktlink)
War schon mal da
 
Benutzerbild von lillimucki
 
Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
Standard

Hallo Leo
hier sind die Bilder:


Das Avast-Protokoll



und das erschien eben noch obendrein:



Vielen Dank für die Hilfe
Liebe Grüße
lillimucki
lillimucki ist offline   Mit Zitat antworten
Alt 28.04.2011, 17:09   #7 (Direktlink)
Super-Moderator
 
Registriert seit: 08.02.2010
Beiträge: 1.728
Standard

Hm, benutzt du ThreatFire?

Schritt 1
Malwarebytes Anti-Malware
Download (Free Version): Malwarebytes : Malwarebytes Anti-Malware is a free download that removes viruses and malware from your computer
  • Installiere das Programm in den vorgegebenen Pfad.
  • Führe ein Update durch (Reiter Aktualisierungen) solange bis die Datenbank auf dem neusten Stand ist.
  • Klicke auf den Reiter Suchlauf --> wähle dort "Vollständigen Suchlauf durchführen" --> klicke auf Scannen.
  • Wenn der Scan beendet ist, klicke auf "Ergebnisse anzeigen".
  • Versichere Dich, dass alle Funde markiert sind und drücke "Entferne Auswahl".
  • Falls ein Neustart verlangt wird so bitte umgehend nachkommen.
  • Poste das Logfile in deinem Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.

Schritt 2

OTL
Download: http://oldtimer.geekstogo.com/OTL.exe


1. Doppelklick auf die OTL.exe
2. User von Windows 7 und Vista: Rechtsklick als Administrator ausführen
3. Oben findest Du ein Kästchen mit Ausgabe. Wähle bitte Minimal-Ausgabe
4. Setze einen Haken Oben bei Scanne alle Benutzer.
5. Unter "Extra Registrierung wähle "Benutze SafeList"
6. Rechts unten Haken setzen bei "LOP Prüfung" und "Purity Prüfung "
7. Kopiere in die Textbox (ohen das Wort Code: )


Code:
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT



8. Klicke "Scan"
Es werden 2 Reporte erstellt:
OTL.Txt sowie Extras.Txt
Bitte beide Logs Posten!

__________________
Gruß Leo

Der Leo ist offline   Mit Zitat antworten
Alt 28.04.2011, 21:58   #8 (Direktlink)
War schon mal da
 
Benutzerbild von lillimucki
 
Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
Standard

Hallo Leoja, ich nutzeThreatFire. Ist das nicht gut?
Hier sind dann die Logfiles.

OTL.txt


OTL logfile created on: 28.04.2011 20:52:00 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

2,00 Gb Total Physical Memory | 0,00 Gb Available Physical Memory | 20,00% Memory free
6,00 Gb Paging File | 4,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s): c:\pagefile.sys 4092 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 143,19 Gb Total Space | 61,37 Gb Free Space | 42,86% Space Free | Partition Type: NTFS
Drive D: | 5,86 Gb Total Space | 0,82 Gb Free Space | 13,97% Space Free | Partition Type: NTFS
Drive J: | 1,88 Gb Total Space | 0,11 Gb Free Space | 5,58% Space Free | Partition Type: FAT

Computer Name: HEINER-PC | User Name: Heiner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe (Uniblue Systems Limited)
PRC - C:\Program Files\Klebezettel NG\klebez.exe (Hollie-Soft)
PRC - C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
PRC - C:\Program Files\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
PRC - C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (Deutsche Telekom AG)
PRC - C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation)
PRC - C:\Program Files\epson\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe (Speedbit Ltd.)
PRC - C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe (Speedbit Ltd.)
PRC - C:\D - PROGRAMME\AmP\AmP.exe (Mirko Böer)
PRC - C:\Program Files\ThreatFire\TFTray.exe (PC Tools)
PRC - C:\Program Files\ThreatFire\TFService.exe (PC Tools)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe (Blue Onion Software)
PRC - C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe (Prolific Technology Inc.)
PRC - C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe (Jay Elaraj)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\E_FATIEDE.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Windows\System32\iashost.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Windows\System32\PSIService.exe ()


========== Modules (SafeList) ==========

MOD - C:\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Alwil Software\Avast5\snxhk.dll (AVAST Software)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\ThreatFire\TFWAH.dll (PC Tools)


========== Win32 Services (SafeList) ==========

SRV - (WinExit-Service-Launcher) -- File not found
SRV - (TS) -- File not found
SRV - (KWOGC) -- File not found
SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (JetDrive WindowsClosingService) -- C:\Windows\System32\WindowsClosingService.exe ()
SRV - (Application Updater) -- C:\Program Files\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (Netzmanager Service) -- C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (Deutsche Telekom AG)
SRV - (EpsonCustomerResearchParticipation) -- C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
SRV - (MatSvc) -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation)
SRV - (VideoAcceleratorService) -- C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe (Speedbit Ltd.)
SRV - (ThreatFire) -- C:\Program Files\ThreatFire\TFService.exe (PC Tools)
SRV - (nSvcIp) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV - (SBSDWSCService) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (PLFlash DeviceIoControl Service) -- C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe (Prolific Technology Inc.)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (LPDSVC) -- C:\Windows\System32\lpdsvc.dll (Microsoft Corporation)
SRV - (WPEServ) -- C:\Program Files\Common Files\wpe\wpeserv.exe (soft Xpansion)
SRV - (CLTNetCnService) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ProtexisLicensing) -- C:\Windows\System32\PSIService.exe ()


========== Driver Services (SafeList) ==========

DRV - (aswSnx) -- C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) -- C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) -- C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRdr) -- C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMonFlt) -- C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) -- C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (jetdrive) -- C:\Windows\System32\drivers\jddrv.sys (Abelssoft GmbH)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (MBAMSwissArmy) -- C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (TelekomNM3) -- C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
DRV - (MTOnlPktAlyX) -- C:\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\MTOnlPktAlyx.sys (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
DRV - (LUsbFilt) -- C:\Windows\System32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouFilt) -- C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (NVNET) -- C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (Uim_IM) -- C:\Windows\System32\drivers\Uim_IM.sys (Paragon)
DRV - (UimBus) -- C:\Windows\System32\drivers\UimBus.sys (Windows (R) 2000 DDK provider)
DRV - (hotcore3) -- C:\Windows\system32\DRIVERS\hotcore3.sys (Paragon Software Group)
DRV - (TfSysMon) -- C:\Windows\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfNetMon) -- C:\Windows\System32\drivers\TfNetMon.sys (PC Tools)
DRV - (TfFsMon) -- C:\Windows\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (nvstor32) -- C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (RMCAST) RMCAST (Pgm) -- C:\Windows\System32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (kbfiltr) -- C:\Windows\System32\drivers\kbfiltr.sys ( )
DRV - (PSI) -- C:\Windows\System32\drivers\psi_mf.sys (Secunia)
DRV - (SymEvent) -- C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (StarOpen) -- C:\Windows\System32\drivers\StarOpen.sys ()
DRV - (SYMTDI) -- C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIMMP) -- C:\Windows\System32\drivers\SymIM.sys (Symantec Corporation)
DRV - (SymIM) -- C:\Windows\System32\drivers\SymIM.sys (Symantec Corporation)
DRV - (KS-959) -- C:\Windows\System32\drivers\KS-959.sys (Kingsun Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files\Winload\tbWin0.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {73c7d5b0-7b03-444a-84c7-ce1ba03b5573} - C:\Program Files\Foxit\tbFoxi.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA0.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - Reg Error: Key error. File not found


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = Google Toolbar
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = Google
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Miro Start
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://search.conduit.com?SearchSour...ctid=CT2475029
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TF = http://search.conduit.com?SearchSour...ctid=CT2431245
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Google Toolbar
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Google Toolbar
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files\Winload\tbWin0.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA0.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.)
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-153915148-350753066-3938573312-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========


FF - HKLM\software\mozilla\Firefox\Extensions\\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}: C:\Program Files\SpeedBit Video Downloader\SPFireFox
FF - HKLM\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011.04.27 14:02:37 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6b2\extensions\\Components: C:\Program Files\Mozilla Firefox 3.6 Beta 1\components [2010.12.23 11:19:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6b2\extensions\\Plugins: C:\Program Files\Mozilla Firefox 3.6 Beta 1\plugins [2011.04.26 16:23:16 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.22 17:13:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.04.26 16:23:16 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011.04.11 12:56:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2011.04.26 16:23:17 | 000,000,000 | ---D | M]

[2009.12.28 10:49:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Extensions
[2009.12.28 10:49:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.04.28 20:47:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions
[2011.03.11 10:21:27 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2011.01.19 10:56:46 | 000,000,000 | ---D | M] (Resurrect Pages) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{0c8fbd76-bdeb-4c52-9b24-d587ce7b9dc3}
[2011.04.21 12:21:59 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2011.01.14 09:34:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{1280606b-2510-4fe0-97ef-9b5a22eafe80}
[2011.01.06 10:32:28 | 000,000,000 | ---D | M] (Image Zoom) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2009.08.11 08:35:02 | 000,000,000 | ---D | M] (Minimap Addon) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{398e77b8-2304-11dc-8314-0800200c9a66}
[2011.03.22 21:44:44 | 000,000,000 | ---D | M] (Winload Community Toolbar) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{40c3cc16-7269-4b32-9531-17f2950fb06f}
[2009.09.09 08:18:15 | 000,000,000 | ---D | M] ("Picnik") -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{5b1fdac4-a239-4933-9c52-b65a2a720b75}
[2011.03.23 11:34:01 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011.04.07 06:35:21 | 000,000,000 | ---D | M] (iMacros for Firefox) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
[2011.04.18 22:22:28 | 000,000,000 | ---D | M] (Nightly Tester Tools) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29}
[2011.01.06 10:32:29 | 000,000,000 | ---D | M] (Context Search) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{902D2C4A-457A-4EF9-AD43-7014562929FF}
[2011.03.02 23:38:05 | 000,000,000 | ---D | M] (Password Exporter) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
[2011.04.02 22:02:39 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011.03.02 23:38:05 | 000,000,000 | ---D | M] (Bargain Book Mole) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{c7b204cd-707e-4d13-b5c4-8eb3ce6f3f52}
[2010.11.16 21:04:21 | 000,000,000 | ---D | M] (COMPUTERBILD-Abzockschutz) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{d49175b3-3fd8-43b8-b28e-da5d47f3c398}
[2011.03.08 09:31:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{dc572301-7619-498c-a57d-39143191b318}
[2011.04.07 23:01:18 | 000,000,000 | ---D | M] (BitDefender QuickScan) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2011.03.16 09:37:24 | 000,000,000 | ---D | M] (Menu Editor) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{EDA7B1D7-F793-4e03-B074-E6F303317FB0}
[2011.03.23 21:24:24 | 000,000,000 | ---D | M] (FoxLingo) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2011.04.09 16:34:53 | 000,000,000 | ---D | M] (New Tab King) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{FC5BAC7D-D696-4ba6-B913-CF8F000C33DF}
[2010.11.02 11:53:45 | 000,000,000 | ---D | M] (BarTab) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\bartap@philikon.de
[2010.11.19 08:10:01 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\de-DE@dictionaries.addons.mozilla.org
[2011.03.23 11:33:55 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\engine@conduit.com
[2011.03.16 09:46:03 | 000,000,000 | ---D | M] (Mein Gutscheincode Finder) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\finder@meingutscheincode.de
[2010.12.29 08:53:01 | 000,000,000 | ---D | M] (Read It Later) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\isreaditlater@ideashower.com
[2010.12.11 22:23:26 | 000,000,000 | ---D | M] ("It's All Text!") -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\itsalltext@docwhat.gerf.org
[2011.01.12 09:13:20 | 000,000,000 | ---D | M] (NoSquint) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\nosquint@urandom.ca
[2011.03.02 23:38:05 | 000,000,000 | ---D | M] (Puzzle) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\puzzle@internauta1024a.pl
[2011.03.02 23:38:05 | 000,000,000 | ---D | M] (SkipScreen) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\SkipScreen@SkipScreen
[2011.04.28 20:47:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\staged
[2011.04.03 20:06:18 | 000,000,000 | ---D | M] (Foxit PDF Creator Toolbar) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\toolbar@ask.com
[2011.03.08 09:31:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\{dc572301-7619-498c-a57d-39143191b318}\modules\extensions
[2008.04.14 17:57:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heiner\AppData\Roaming\mozilla\Sunbird\Profiles\4j8vuwrs.default\extens ions
[2011.03.21 18:52:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010.05.12 07:54:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011.01.18 11:52:02 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.03.11 09:00:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.03.22 17:13:29 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011.02.02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.10.19 09:17:16 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2007.03.05 14:59:06 | 000,645,504 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
[2007.03.10 01:16:44 | 000,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
[2006.09.26 12:03:14 | 000,098,304 | ---- | M] (Zylom) -- C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
[2011.03.22 17:13:33 | 000,001,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom-de.xml
[2011.03.22 17:13:33 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011.03.22 17:13:33 | 000,001,153 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-de.xml
[2011.03.22 17:13:33 | 000,006,805 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\leo_ende_de.xml
[2011.03.22 17:13:33 | 000,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-de.xml
[2011.03.22 17:13:33 | 000,001,105 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-de.xml

O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (CescrtHlpr Object) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files\Winload\tbWin0.dll (Conduit Ltd.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Foxit Toolbar) - {73c7d5b0-7b03-444a-84c7-ce1ba03b5573} - C:\Program Files\Foxit\tbFoxi.dll (Conduit Ltd.)
O2 - BHO: (MyAshampoo Toolbar) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA0.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll (Google Inc.)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (no name) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - No CLSID value found.
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0744.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (no name) - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - No CLSID value found.
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Program Files\Winload\tbWin0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Foxit Toolbar) - {73c7d5b0-7b03-444a-84c7-ce1ba03b5573} - C:\Program Files\Foxit\tbFoxi.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {77709987-486F-4210-BE78-328303B8691C} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll (Babylon Ltd.)
O3 - HKLM\..\Toolbar: (MyAshampoo Toolbar) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\Toolbar\WebBrowser: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\Toolbar\WebBrowser: (Winload Toolbar) - {40C3CC16-7269-4B32-9531-17F2950FB06F} - C:\Program Files\Winload\tbWin0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\Toolbar\WebBrowser: (Foxit Toolbar) - {73C7D5B0-7B03-444A-84C7-CE1BA03B5573} - C:\Program Files\Foxit\tbFoxi.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\Toolbar\WebBrowser: (MyAshampoo Toolbar) - {A1E75A0E-4397-4BA8-BB50-E19FB66890F4} - C:\Program Files\MyAshampoo\prxtbMyA0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\..\Toolbar\WebBrowser: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alle meine Passworte] C:\D - PROGRAMME\AmP\AmP.exe (Mirko Böer)
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe (PC Tools)
O4 - HKU\.DEFAULT..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\.DEFAULT..\Run: [T-Online_Software_6\WLAN-Access Finder] C:\Program Files\T-Online\WLAN-Access Finder\ToWLaAcF.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
O4 - HKU\S-1-5-18..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-18..\Run: [T-Online_Software_6\WLAN-Access Finder] C:\Program Files\T-Online\WLAN-Access Finder\ToWLaAcF.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
O4 - HKU\S-1-5-19..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-153915148-350753066-3938573312-1000..\Run: [DeskDriveStartup] C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe (Blue Onion Software)
O4 - HKU\S-1-5-21-153915148-350753066-3938573312-1000..\Run: [EPSON SX100 Series (Kopie 1)] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-153915148-350753066-3938573312-1000..\Run: [Klebezettel NG] C:\Program Files\Klebezettel NG\klebez.exe (Hollie-Soft)
O4 - HKU\S-1-5-21-153915148-350753066-3938573312-1000..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe (Jay Elaraj)
O4 - Startup: C:\Users\Heiner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Geburtstagsmahner.lnk = C:\Program Files\ZEHBESOFT\Geburtstagsmahner\GebAlert.exe (ZehbeSoft)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\TabbedBrowsing present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSecurityTab = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStartupSound = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\AdvancedOptions present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\AdvancedOptions present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\AdvancedOptions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\AdvancedOptions present
O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\Software\Policies\Microsoft\Internet Explorer\AdvancedOptions present
O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoShellSearchButton = 0
O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserFolderInStartMenu = 1
O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 67106819
O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67104771
O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O7 - HKU\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayItemsDisplay = 0
O8 - Extra context menu item: Auswahl mit FDM herunterladen - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Datei mit FDM herunterladen - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Videos mit FDM herunterladen - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O9 - Extra Button: WhoisAssistant - {1153C29A-2A1C-12E3-A2A3-00D1A2F21300} - C:\Program Files\WhoisAssistant\WhoisAssistantDirect.exe ()
O9 - Extra 'Tools' menuitem : &WhoisAssistant starten - {1153C29A-2A1C-12E3-A2A3-00D1A2F21300} - C:\Program Files\WhoisAssistant\WhoisAssistantDirect.exe ()
O9 - Extra Button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra 'Tools' menuitem : Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra Button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - Reg Error: Value error. File not found
O9 - Extra Button: Add to Favorites - {9BEF3FB8-E5E0-4494-BC59-7BAC1C9AD503} - Reg Error: Key error. File not found
O9 - Extra Button: Open Tidy Favorites - {E3CB497B-E230-4445-8B34-13476822F867} - Reg Error: Key error. File not found
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/res.../wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} Windows Live OneCare (Windows Live Safety Center Base Module)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Filter\text/html {53B95211-7D77-11D2-9F80-00104B107C96} - Reg Error: Key error. File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Bild006.jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Bild006.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /k:C *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Lexware Info Service.lnk - - File not found
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Quicken 2008 Zahlungserinnerung.lnk - - File not found
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WISO Mein Sparbuch heute.lnk - C:\Program Files\WISO\Sparbuch 2010\meinsparbuchheute.exe - ()
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WISO Urteilsmonitor.lnk - C:\Program Files\WISO\Sparbuch 2008\urteilsmonitor.exe - ()
MsConfig - StartUpFolder: C:^Users^Heiner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Corel Registration.lnk.disabled - - File not found
MsConfig - StartUpFolder: C:^Users^Heiner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^klickTel OEM 2008 - Schnellstarter.lnk - C:\Program Files\klickTel\klickTel OEM 2008\KSTART32.EXE - (klickTel AG)
MsConfig - StartUpFolder: C:^Users^Heiner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Nettalk.lnk - C:\Program Files\Nettalk6\Nettalk.exe - (Nicolas Kruse)
MsConfig - StartUpFolder: C:^Users^Heiner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Secunia PSI (RC4).lnk - C:\Program Files\Secunia\PSI (RC4)\psi.exe - (Secunia)
MsConfig - StartUpFolder: C:^Users^Heiner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Wallpapers from MSN.lnk - - File not found
MsConfig - StartUpReg: Acronis Scheduler2 Service - hkey= - key= - File not found
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - File not found
MsConfig - StartUpReg: AppleSyncNotifier - hkey= - key= - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
MsConfig - StartUpReg: BabylonToolbar - hkey= - key= - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe (Babylon Ltd.)
MsConfig - StartUpReg: BirthdayRemember6 - hkey= - key= - File not found
MsConfig - StartUpReg: ccApp - hkey= - key= - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
MsConfig - StartUpReg: Copernic Desktop Search - Home - hkey= - key= - File not found
MsConfig - StartUpReg: DivXUpdate - hkey= - key= - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MsConfig - StartUpReg: Firefox - hkey= - key= - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
MsConfig - StartUpReg: FreePDF Assistant - hkey= - key= - C:\Program Files\FreePDF_XP\fpassist.exe (shbox.de)
MsConfig - StartUpReg: GMX_GMX MultiMessenger - hkey= - key= - File not found
MsConfig - StartUpReg: ICQ - hkey= - key= - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
MsConfig - StartUpReg: InfoCockpit - hkey= - key= - C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg: MAXA-LockTray - hkey= - key= - C:\Program Files\MAXA-Lock\tray.exe (MAXA Research Int'l Inc.)
MsConfig - StartUpReg: mspwr - hkey= - key= - File not found
MsConfig - StartUpReg: NBKeyScan - hkey= - key= - C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe (Nero AG)
MsConfig - StartUpReg: Ocster Backup - hkey= - key= - File not found
MsConfig - StartUpReg: OpwareSE2 - hkey= - key= - C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
MsConfig - StartUpReg: PikyAgent - hkey= - key= - C:\Program Files\Conceptworld\PikySuite\PikyAgent.exe (Conceptworld Corporation)
MsConfig - StartUpReg: PrintDisp - hkey= - key= - File not found
MsConfig - StartUpReg: PSUNMain - hkey= - key= - File not found
MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
MsConfig - StartUpReg: Skype - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig - StartUpReg: Spiele Post - hkey= - key= - File not found
MsConfig - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
MsConfig - StartUpReg: ToADiMon.exe - hkey= - key= - C:\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
MsConfig - StartUpReg: Trend Micro Browser Guard v2.0 Beta - hkey= - key= - File not found
MsConfig - StartUpReg: TrueImageMonitor.exe - hkey= - key= - File not found
MsConfig - StartUpReg: TVBroadcast - hkey= - key= - File not found
MsConfig - StartUpReg: UnlockerAssistant - hkey= - key= - C:\Program Files\Unlocker\UnlockerAssistant.exe ()
MsConfig - StartUpReg: UVS12 Preload - hkey= - key= - File not found
MsConfig - StartUpReg: Windows Defender - hkey= - key= - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
MsConfig - StartUpReg: WinUhr - hkey= - key= - C:\Users\Heiner\Downloads\Mozilla\winuhr\WinUhr.exe (Walter Hintenaus)
MsConfig - StartUpReg: Yahoo! Pager - hkey= - key= - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
MsConfig - State: "startup" - 2
MsConfig - State: "services" - 2
MsConfig - State: "bootini" - 2

SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - File not found
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX: {0291E591-EA41-4c82-8106-3DC6CE7F7664} - Reg Error: Value error.
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Windows Media Player 5.2
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2F6EFCE6-10DF-49F9-9E64-9AE3775B2588} - Microsoft .NET Framework 1.1 Security Update (KB2416447)
ActiveX: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - Reg Error: Value error.
ActiveX: {347B0667-C7ED-429B-BDE3-CC8D3BACAA31} - Reg Error: Value error.
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {A17E30C4-A9BA-11D4-8673-60DB54C10000} - Reg Error: Value error.
ActiveX: {AA218328-0EA8-4D70-8972-E987A9190FF4} - Reg Error: Value error.
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.
ActiveX: {E78BFA60-5393-4C38-82AB-E8019E464EB4} - .NET Framework
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

Geändert von Tunarus (28.04.2011 um 23:21 Uhr)
lillimucki ist offline   Mit Zitat antworten
Alt 28.04.2011, 22:06   #9 (Direktlink)
War schon mal da
 
Benutzerbild von lillimucki
 
Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
Standard

hier gehts weiter:
Drivers32: msacm.alf2cd - C:\Windows\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.avis - C:\Windows\System32\ff_acm.acm ()
Drivers32: msacm.divxa32 - C:\Windows\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\Windows\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\Windows\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.voxacm160 - C:\Windows\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.dvsd - C:\Windows\System32\mcdvd_32.dll (MainConcept)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.i420 - C:\Windows\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011.04.28 15:33:54 | 000,000,000 | ---D | C] -- C:\Users\Heiner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2011.04.28 08:32:29 | 000,000,000 | ---D | C] -- C:\UWT
[2011.04.27 12:31:43 | 000,000,000 | ---D | C] -- C:\shexview
[2011.04.27 07:32:31 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
[2011.04.27 07:32:30 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
[2011.04.27 07:32:26 | 000,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2011.04.26 21:22:37 | 000,000,000 | ---D | C] -- C:\DVD-ColdCut
[2011.04.26 14:05:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
[2011.04.26 14:05:20 | 000,000,000 | -H-D | C] -- C:\ProgramData\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A}
[2011.04.26 14:05:19 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue
[2011.04.26 11:14:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.04.26 11:14:17 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.04.24 19:30:09 | 000,000,000 | ---D | C] -- C:\0001 - Druck
[2011.04.21 08:28:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011.04.20 12:29:30 | 000,029,056 | ---- | C] (Abelssoft GmbH) -- C:\Windows\System32\drivers\jddrv.sys
[2011.04.18 09:42:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FontFrenzy
[2011.04.18 09:42:39 | 000,000,000 | ---D | C] -- C:\Program Files\FontFrenzy
[2011.04.15 09:50:10 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2011.04.15 09:50:09 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011.04.15 09:50:08 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2011.04.15 09:50:06 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2011.04.15 09:50:05 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011.04.15 09:50:05 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2011.04.15 09:50:05 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2011.04.15 09:50:05 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2011.04.15 09:49:56 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2011.04.15 09:49:56 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2011.04.15 09:49:55 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2011.04.15 09:49:53 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2011.04.15 09:49:53 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2011.04.15 09:49:53 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2011.04.15 09:49:52 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2011.04.15 09:49:52 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2011.04.15 09:49:51 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2011.04.15 09:49:51 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011.04.15 09:49:50 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2011.04.15 09:49:50 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011.04.15 09:49:50 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2011.04.15 09:49:50 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2011.04.15 09:49:50 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2011.04.15 09:49:50 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2011.04.15 09:49:49 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2011.04.15 09:49:47 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011.04.15 09:49:47 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2011.04.15 09:49:47 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2011.04.15 09:49:46 | 001,797,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011.04.15 09:49:46 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2011.04.15 09:49:46 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2011.04.15 09:49:46 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2011.04.15 09:49:46 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2011.04.15 09:49:45 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2011.04.15 09:49:45 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2011.04.15 09:49:45 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2011.04.15 09:49:45 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2011.04.15 09:49:45 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2011.04.15 09:49:45 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2011.04.15 08:41:48 | 000,000,000 | ---D | C] -- C:\Users\Heiner\SecurityScans
[2011.04.15 08:34:38 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Baseline Security Analyzer 2
[2011.04.13 13:01:58 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe
[2011.04.13 13:01:44 | 001,162,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll
[2011.04.13 13:01:42 | 001,136,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll
[2011.04.13 13:01:40 | 002,041,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011.04.13 13:01:34 | 000,292,864 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2011.04.13 13:01:33 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2011.04.06 12:53:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeOCR
[2011.04.06 12:53:44 | 002,680,320 | ---- | C] (HiComponents) -- C:\Windows\System32\ImageEnXLibrary.ocx
[2011.04.06 12:53:44 | 001,883,136 | ---- | C] (Debenu Pty Ltd) -- C:\Windows\System32\QuickPDFAX0717.dll
[2011.04.06 12:53:44 | 000,000,000 | ---D | C] -- C:\Windows\tessdata
[2011.04.06 12:53:44 | 000,000,000 | ---D | C] -- C:\Program Files\FreeOCR
[2011.04.06 12:53:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer
[2011.04.04 21:32:45 | 000,000,000 | ---D | C] -- C:\OTR_Homeloader
[2011.04.04 21:32:29 | 000,000,000 | ---D | C] -- C:\Users\Heiner\AppData\Roaming\OTRHomeloader
[2011.04.04 21:32:24 | 000,000,000 | ---D | C] -- C:\Users\Heiner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OTRHomeloader
[2011.04.04 21:32:23 | 000,000,000 | ---D | C] -- C:\Program Files\OTRHomeloader
[2011.04.02 21:41:25 | 000,000,000 | -HSD | C] -- C:\found.001
[2010.05.10 15:10:41 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Heiner\AppData\Roaming\pcouffin.sys
[2008.11.03 16:03:28 | 000,013,880 | ---- | C] ( ) -- C:\Windows\System32\drivers\kbfiltr.sys
[1996.11.18 23:15:46 | 000,018,944 | ---- | C] ( ) -- C:\Windows\System32\IMPLODE.DLL
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011.04.28 21:13:42 | 010,747,904 | ---- | M] () -- C:\Users\Heiner\ntuser.dat
[2011.04.28 21:00:05 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.04.28 20:41:56 | 000,000,205 | ---- | M] () -- C:\Users\Heiner\Desktop\READYBOOST (J).lnk
[2011.04.28 20:36:39 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.04.28 20:36:32 | 000,000,334 | ---- | M] () -- C:\Windows\tasks\RegistryBooster.job
[2011.04.28 20:36:31 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2011.04.28 20:36:22 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.04.28 20:36:22 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.04.28 20:36:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.04.28 20:36:00 | 1877,454,848 | -HS- | M] () -- C:\hiberfil.sys
[2011.04.28 20:32:55 | 000,524,288 | -HS- | M] () -- C:\Users\Heiner\ntuser.dat{c73d8214-6e91-11e0-834a-001bfcfaa836}.TMContainer00000000000000000001.regtrans-ms
[2011.04.28 20:32:55 | 000,065,536 | -HS- | M] () -- C:\Users\Heiner\ntuser.dat{c73d8214-6e91-11e0-834a-001bfcfaa836}.TM.blf
[2011.04.28 20:32:39 | 005,604,485 | -H-- | M] () -- C:\Users\Heiner\AppData\Local\IconCache.db
[2011.04.28 17:40:48 | 000,000,793 | ---- | M] () -- C:\Users\Heiner\Desktop\mbam.exe.lnk
[2011.04.28 17:37:54 | 000,001,189 | ---- | M] () -- C:\Users\Heiner\AppData\Roaming\vso_ts_preview.xml
[2011.04.28 17:29:18 | 000,011,145 | ---- | M] () -- C:\Windows\Heiner8.xlb
[2011.04.28 16:05:09 | 000,161,792 | ---- | M] () -- C:\Users\Heiner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.04.28 15:33:54 | 000,001,040 | ---- | M] () -- C:\Users\Heiner\Desktop\Revo Uninstaller.lnk
[2011.04.28 14:14:08 | 000,001,553 | ---- | M] () -- C:\Windows\QUICKEN.INI
[2011.04.28 11:00:00 | 000,000,436 | ---- | M] () -- C:\Windows\tasks\ASOService.job
[2011.04.27 21:38:29 | 000,001,156 | ---- | M] () -- C:\Windows\System32\games.stat
[2011.04.27 14:02:42 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2011.04.27 11:48:30 | 000,002,312 | ---- | M] () -- C:\Windows\Provex.ini
[2011.04.26 21:09:15 | 000,360,208 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.04.26 11:34:22 | 000,100,496 | ---- | M] () -- C:\Users\Heiner\AppData\Local\GDIPFONTCACHEV1.DAT
[2011.04.26 11:20:14 | 000,358,172 | ---- | M] () -- C:\Users\Heiner\Documents\cc_20110426_111944.reg
[2011.04.26 02:31:50 | 000,001,811 | ---- | M] () -- C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
[2011.04.25 18:05:40 | 000,524,288 | -HS- | M] () -- C:\Users\Heiner\ntuser.dat{c73d8214-6e91-11e0-834a-001bfcfaa836}.TMContainer00000000000000000002.regtrans-ms
[2011.04.24 18:54:06 | 000,524,288 | -HS- | M] () -- C:\Users\Heiner\ntuser.dat{92dd0609-586f-11e0-8578-f78160efc769}.TMContainer00000000000000000001.regtrans-ms
[2011.04.24 18:54:06 | 000,065,536 | -HS- | M] () -- C:\Users\Heiner\ntuser.dat{92dd0609-586f-11e0-8578-f78160efc769}.TM.blf
[2011.04.21 08:28:41 | 000,000,824 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2011.04.18 19:25:12 | 000,040,112 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2011.04.18 19:25:10 | 000,199,304 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2011.04.18 19:17:46 | 000,441,176 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2011.04.18 19:17:34 | 000,307,288 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2011.04.18 19:16:18 | 000,049,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2011.04.18 19:13:21 | 000,025,432 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2011.04.18 19:13:09 | 000,053,592 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2011.04.18 19:12:58 | 000,019,544 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2011.04.18 15:25:39 | 000,000,986 | ---- | M] () -- C:\Users\Heiner\Desktop\ConvertXtoDVD 4.lnk
[2011.04.18 13:43:48 | 000,008,704 | ---- | M] () -- C:\Windows\System32\WindowsClosingService.exe
[2011.04.18 13:42:02 | 000,029,056 | ---- | M] (Abelssoft GmbH) -- C:\Windows\System32\drivers\jddrv.sys
[2011.04.18 13:42:02 | 000,016,384 | ---- | M] () -- C:\Windows\System32\jddac.dll
[2011.04.18 13:42:02 | 000,015,360 | ---- | M] () -- C:\Windows\System32\jdnat.dll
[2011.04.18 13:42:02 | 000,006,656 | ---- | M] () -- C:\Windows\System32\jdboot.exe
[2011.04.15 17:00:23 | 000,000,402 | ---- | M] () -- C:\Windows\tasks\WebUpdate.job
[2011.04.15 09:50:37 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat
[2011.04.15 09:50:37 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat
[2011.04.15 09:50:10 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2011.04.15 09:50:09 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011.04.15 09:50:08 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2011.04.15 09:50:06 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2011.04.15 09:50:05 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011.04.15 09:50:05 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2011.04.15 09:50:05 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2011.04.15 09:50:05 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2011.04.15 09:49:57 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2011.04.15 09:49:56 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2011.04.15 09:49:56 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2011.04.15 09:49:54 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2011.04.15 09:49:53 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2011.04.15 09:49:53 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2011.04.15 09:49:53 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2011.04.15 09:49:52 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011.04.15 09:49:52 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2011.04.15 09:49:52 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2011.04.15 09:49:51 | 001,427,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2011.04.15 09:49:51 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2011.04.15 09:49:50 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011.04.15 09:49:50 | 000,420,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2011.04.15 09:49:50 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2011.04.15 09:49:50 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2011.04.15 09:49:50 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2011.04.15 09:49:50 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2011.04.15 09:49:47 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011.04.15 09:49:47 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2011.04.15 09:49:47 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2011.04.15 09:49:46 | 001,797,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011.04.15 09:49:46 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2011.04.15 09:49:46 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2011.04.15 09:49:46 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2011.04.15 09:49:46 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2011.04.15 09:49:45 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2011.04.15 09:49:45 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2011.04.15 09:49:45 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2011.04.15 09:49:45 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2011.04.15 09:49:45 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2011.04.15 09:49:45 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2011.04.13 13:13:42 | 001,494,818 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2011.04.13 13:13:42 | 000,638,510 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.04.13 13:13:42 | 000,604,126 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.04.13 13:13:42 | 000,130,462 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.04.13 13:13:42 | 000,107,562 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.04.08 20:22:55 | 000,000,541 | ---- | M] () -- C:\Users\Heiner\Desktop\speedyfox.exe.lnk
[2011.04.08 13:17:57 | 000,005,434 | -H-- | M] () -- C:\ffastun.ffa
[2011.04.08 13:17:55 | 001,806,336 | -H-- | M] () -- C:\ffastun.ffo
[2011.04.08 13:17:53 | 021,368,832 | -H-- | M] () -- C:\ffastun0.ffx
[2011.04.08 13:17:53 | 005,292,032 | -H-- | M] () -- C:\ffastun.ffl
[2011.04.03 13:31:21 | 000,000,157 | ---- | M] () -- C:\Windows\ktel.ini
[2011.04.01 09:20:04 | 000,524,288 | -HS- | M] () -- C:\Users\Heiner\ntuser.dat{92dd0609-586f-11e0-8578-f78160efc769}.TMContainer00000000000000000002.regtrans-ms
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

lillimucki ist offline   Mit Zitat antworten
Alt 28.04.2011, 22:08   #10 (Direktlink)
War schon mal da
 
Benutzerbild von lillimucki
 
Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
Standard

...und noch weiter:
[2011.04.15 09:49:52 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2011.04.15 08:34:45 | 000,000,999 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Baseline Security Analyzer 2.2.lnk
[2011.04.08 20:22:55 | 000,000,541 | ---- | C] () -- C:\Users\Heiner\Desktop\speedyfox.exe.lnk
[2011.04.06 12:53:43 | 000,962,560 | ---- | C] () -- C:\Windows\tesseract.exe
[2011.03.17 20:23:01 | 000,032,768 | ---- | C] () -- C:\Windows\System32\EcodocLicenceLib.dll
[2011.03.16 12:28:54 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2011.03.16 00:11:39 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011.03.16 00:11:39 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2011.02.21 15:07:11 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2011.02.21 12:15:58 | 000,017,136 | ---- | C] () -- C:\Windows\System32\sasnative32.exe
[2011.01.26 08:34:31 | 000,000,680 | ---- | C] () -- C:\Users\Heiner\AppData\Local\d3d9caps.dat
[2010.08.20 15:07:47 | 000,819,200 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2010.08.20 15:07:38 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010.06.21 11:08:38 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2010.05.31 10:32:57 | 000,110,602 | ---- | C] () -- C:\Windows\System32\xcdsfx32.bin
[2010.05.10 15:21:27 | 000,001,189 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\vso_ts_preview.xml
[2010.05.10 15:10:41 | 000,087,608 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\inst.exe
[2010.05.10 15:10:41 | 000,007,887 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\pcouffin.cat
[2010.05.10 15:10:41 | 000,001,144 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\pcouffin.inf
[2010.04.01 13:52:37 | 000,000,067 | ---- | C] () -- C:\Windows\swf2avi.INI
[2010.03.29 17:31:30 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2010.03.22 13:08:01 | 000,005,115 | ---- | C] () -- C:\ProgramData\kbkwknay.ayh
[2010.01.22 08:52:21 | 000,000,043 | ---- | C] () -- C:\Windows\gswin32.ini
[2010.01.14 10:31:49 | 000,011,164 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin
[2009.12.26 11:50:35 | 000,691,200 | ---- | C] () -- C:\Windows\System32\PrintLog.exe
[2009.12.26 11:50:35 | 000,524,288 | ---- | C] () -- C:\Windows\System32\PrtPass.exe
[2009.12.25 22:35:06 | 001,163,264 | ---- | C] () -- C:\Windows\System32\Ei4rbfL-a77VQ.dll
[2009.12.16 13:02:10 | 000,000,530 | ---- | C] () -- C:\Windows\System32\tx151ic.ini
[2009.11.02 12:11:07 | 000,000,045 | ---- | C] () -- C:\ProgramData\.SimImages
[2009.10.05 14:48:52 | 000,000,705 | ---- | C] () -- C:\Windows\System32\AeroShake.ini
[2009.08.08 20:47:21 | 000,000,659 | ---- | C] () -- C:\Windows\unins000.dat
[2009.08.03 16:40:51 | 000,000,026 | ---- | C] () -- C:\Windows\NeoSetup.INI
[2009.07.21 00:05:16 | 000,000,040 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\lZJoYI4Nl0eqQ3j+wCSiZ5uqvQdWg2FYUxeLS5PJ.trl
[2009.05.29 08:03:20 | 000,000,000 | ---- | C] () -- C:\Windows\PROTOCOL.INI
[2009.05.27 17:02:49 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.05.27 17:01:58 | 000,368,640 | ---- | C] () -- C:\Windows\System32\msjetoledb40.dll
[2009.05.27 17:00:53 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.05.20 12:09:21 | 000,000,024 | ---- | C] () -- C:\Windows\Bombgolf.ini
[2009.02.28 19:17:54 | 000,008,704 | ---- | C] () -- C:\Windows\System32\WindowsClosingService.exe
[2009.02.09 19:56:22 | 000,084,480 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009.02.02 17:54:03 | 000,000,000 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\AVSDVDPlayer.m3u
[2008.12.24 21:12:57 | 000,000,339 | ---- | C] () -- C:\Windows\DesktopSchneeFree.ini
[2008.11.07 17:09:13 | 000,000,025 | ---- | C] () -- C:\Windows\CDESX100DEFGIPS.ini
[2008.11.04 19:46:23 | 000,001,033 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\ShiftN.ini
[2008.10.21 11:12:05 | 000,000,736 | ---- | C] () -- C:\Windows\SamsungMaster.INI
[2008.10.18 19:10:15 | 000,299,008 | ---- | C] () -- C:\Windows\System32\midas.dll
[2008.10.18 19:10:12 | 000,120,320 | ---- | C] () -- C:\Windows\System32\UnzDll.dll
[2008.10.18 16:36:27 | 002,963,456 | ---- | C] () -- C:\Program Files\Common FilesDDBACSetup.msi
[2008.09.28 20:33:22 | 000,000,041 | ---- | C] () -- C:\Windows\crw.ini
[2008.09.22 09:46:15 | 000,000,157 | ---- | C] () -- C:\Windows\ktel.ini
[2008.09.12 15:21:02 | 000,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest
[2008.08.14 10:48:02 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008.07.25 16:49:40 | 000,000,027 | ---- | C] () -- C:\Windows\CDE DX4400DEFGIPS.ini
[2008.07.21 22:33:08 | 000,000,173 | ---- | C] () -- C:\Windows\CWREGIST.INI
[2008.07.11 14:20:09 | 000,230,377 | ---- | C] () -- C:\Windows\System32\XXCOPY16.EXE
[2008.07.05 12:13:19 | 000,008,704 | ---- | C] () -- C:\Windows\System32\vidccleaner.exe
[2008.07.05 12:09:13 | 000,040,960 | ---- | C] () -- C:\Windows\unS385N.dll
[2008.06.28 02:42:44 | 000,013,576 | ---- | C] () -- C:\Windows\System32\wnaspi32.dll
[2008.06.16 11:49:01 | 000,073,728 | ---- | C] () -- C:\Windows\AKDeInstall.exe
[2008.05.28 13:24:00 | 000,233,542 | ---- | C] () -- C:\Windows\System32\vcdll.dll
[2008.05.12 17:12:25 | 000,000,928 | ---- | C] () -- C:\ProgramData\winsys.lng
[2008.05.12 17:11:55 | 000,081,920 | ---- | C] () -- C:\Windows\System32\GkSui20.EXE
[2008.05.08 18:15:03 | 000,101,936 | ---- | C] () -- C:\Windows\System32\GDIPFONTCACHEV1.DAT
[2008.05.08 17:10:40 | 000,162,304 | ---- | C] () -- C:\Windows\System32\ztvunrar36.dll
[2008.05.08 17:10:40 | 000,077,312 | ---- | C] () -- C:\Windows\System32\ztvunace26.dll
[2008.04.15 21:29:19 | 000,163,840 | ---- | C] () -- C:\Windows\System32\PwrUpCid.dll
[2008.03.05 22:53:26 | 000,116,224 | ---- | C] () -- C:\Windows\System32\redmonnt.dll
[2008.03.03 15:12:13 | 000,045,056 | ---- | C] () -- C:\Windows\System32\rWinHook.dll
[2008.03.02 14:46:43 | 000,003,060 | ---- | C] () -- C:\Windows\tm.ini
[2008.02.29 13:03:08 | 000,051,815 | R--- | C] () -- C:\Windows\System32\QPRO200.DLL
[2008.02.29 13:03:05 | 000,100,352 | R--- | C] () -- C:\Windows\System32\JUCALC4.DLL
[2008.02.29 13:03:05 | 000,100,352 | R--- | C] () -- C:\Windows\System32\Jucalc2.dll
[2008.02.29 13:03:05 | 000,100,352 | R--- | C] () -- C:\Windows\System32\Jucalc.dll
[2008.02.29 13:03:03 | 000,282,112 | R--- | C] () -- C:\Windows\System32\ASTR.DLL
[2008.02.29 13:03:03 | 000,112,640 | R--- | C] () -- C:\Windows\System32\AW300.DLL
[2008.02.13 12:37:29 | 000,000,848 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys
[2008.02.13 12:29:39 | 001,136,208 | ---- | C] () -- C:\ProgramData\pswi_preloaded.exe
[2008.02.06 13:04:53 | 000,045,056 | ---- | C] () -- C:\Windows\System32\unredmon.exe
[2008.01.28 19:09:30 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat
[2008.01.28 19:09:30 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat
[2008.01.28 19:09:30 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat
[2008.01.28 19:09:30 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat
[2008.01.28 19:09:30 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
[2008.01.28 19:09:30 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat
[2008.01.28 19:09:30 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat
[2008.01.28 19:09:30 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat
[2008.01.28 19:09:30 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat
[2008.01.28 19:09:30 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat
[2008.01.28 19:09:30 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat
[2008.01.28 19:09:30 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat
[2008.01.28 19:09:30 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat
[2008.01.28 19:09:30 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat
[2008.01.28 19:09:30 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat
[2008.01.28 19:09:30 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat
[2008.01.28 13:47:12 | 000,000,754 | ---- | C] () -- C:\Windows\wiso.ini
[2008.01.18 08:14:05 | 000,000,032 | ---- | C] () -- C:\ProgramData\ezsid.dat
[2008.01.15 08:40:52 | 000,000,030 | ---- | C] () -- C:\Windows\INTURS.DAT
[2008.01.15 08:40:49 | 000,000,024 | ---- | C] () -- C:\Windows\qfnonl.ini
[2008.01.15 08:40:00 | 000,000,028 | ---- | C] () -- C:\Windows\ICOA.INI
[2008.01.15 08:39:34 | 000,000,000 | ---- | C] () -- C:\Windows\QFN.ini
[2008.01.15 08:39:34 | 000,000,000 | ---- | C] () -- C:\Windows\QDQICK.ini
[2008.01.15 04:31:00 | 000,000,530 | ---- | C] () -- C:\Windows\System32\tx14_ic.ini
[2007.12.19 15:46:35 | 000,060,124 | ---- | C] () -- C:\Windows\System32\tcpmon.ini
[2007.12.08 01:40:42 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2007.12.07 22:52:14 | 000,004,246 | ---- | C] () -- C:\Windows\WINAS60.INI
[2007.12.07 22:51:15 | 000,201,984 | ---- | C] () -- C:\Windows\PI.EXE
[2007.12.05 17:32:37 | 000,000,000 | ---- | C] () -- C:\Windows\distlib.ini
[2007.12.03 12:50:03 | 000,003,596 | ---- | C] () -- C:\Windows\System32\buttonstudio.ini
[2007.12.01 19:53:20 | 000,008,395 | ---- | C] () -- C:\Windows\mozver.dat
[2007.11.30 15:51:40 | 000,694,168 | ---- | C] () -- C:\ProgramData\LUUnInstall.LiveUpdate
[2007.11.28 19:59:42 | 003,702,784 | ---- | C] () -- C:\Windows\System32\gsdll32.dll
[2007.11.27 17:19:30 | 000,001,553 | ---- | C] () -- C:\Windows\QUICKEN.INI
[2007.11.27 17:19:30 | 000,000,904 | ---- | C] () -- C:\Windows\Intuprof.ini
[2007.11.27 17:19:25 | 000,005,990 | ---- | C] () -- C:\Windows\icoadb32.dat
[2007.11.26 21:52:07 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2007.11.26 20:38:25 | 000,002,312 | ---- | C] () -- C:\Windows\Provex.ini
[2007.11.26 18:27:30 | 000,000,100 | ---- | C] () -- C:\Windows\HBUser.ini
[2007.11.26 17:36:53 | 000,000,094 | ---- | C] () -- C:\Users\Heiner\AppData\Local\fusioncache.dat
[2007.11.26 16:20:09 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2007.11.26 16:19:28 | 000,006,768 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2007.11.26 12:11:04 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll
[2007.11.26 09:04:09 | 000,000,132 | ---- | C] () -- C:\Windows\winamp.ini
[2007.11.25 18:25:41 | 000,031,028 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\UserTile.png
[2007.11.25 09:26:38 | 000,039,095 | ---- | C] () -- C:\Windows\iccsigs.dat
[2007.11.25 09:26:37 | 000,112,688 | ---- | C] () -- C:\Windows\System32\shw32.dll
[2007.11.25 01:47:28 | 000,161,792 | ---- | C] () -- C:\Users\Heiner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.11.25 00:13:48 | 000,000,216 | ---- | C] () -- C:\Users\Heiner\AppData\Roaming\wklnhst.dat
[2007.11.24 22:59:08 | 000,000,634 | ---- | C] () -- C:\Windows\ODBC.INI
[2007.11.24 22:59:07 | 000,000,967 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2007.11.24 22:34:47 | 000,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
[2007.11.24 22:34:47 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
[2007.11.24 22:34:47 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2007.11.24 22:27:44 | 000,000,027 | ---- | C] () -- C:\Windows\CDE CX3600FGD.ini
[2007.11.24 22:20:25 | 000,000,532 | ---- | C] () -- C:\Windows\MAXLINK.INI
[2007.11.24 20:01:36 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat
[2007.11.24 17:37:57 | 000,100,496 | ---- | C] () -- C:\Users\Heiner\AppData\Local\GDIPFONTCACHEV1.DAT
[2007.10.25 18:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2007.09.04 12:56:10 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2007.03.11 15:10:58 | 006,209,536 | ---- | C] () -- C:\Windows\System32\ImageMagickObject.dll
[2006.11.29 04:30:00 | 000,000,530 | ---- | C] () -- C:\Windows\System32\tx13_ic.ini
[2006.11.02 21:40:12 | 000,174,656 | ---- | C] () -- C:\Windows\System32\PSIService.exe
[2006.11.02 17:33:31 | 000,638,510 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2006.11.02 17:33:31 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2006.11.02 17:33:31 | 000,130,462 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2006.11.02 17:33:31 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:47:37 | 000,360,208 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:33:01 | 001,494,818 | ---- | C] () -- C:\Windows\System32\PerfStringBackup.INI
[2006.11.02 12:33:01 | 000,604,126 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,107,562 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:24:31 | 000,001,405 | ---- | C] () -- C:\Windows\msdfmap.ini
[2006.11.02 12:23:31 | 000,000,432 | ---- | C] () -- C:\Windows\win.ini
[2006.11.02 12:23:31 | 000,000,236 | ---- | C] () -- C:\Windows\system.ini
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.11.02 09:10:37 | 000,053,536 | ---- | C] () -- C:\Windows\System32\dosx.exe
[2006.11.02 09:10:02 | 000,000,718 | ---- | C] () -- C:\Windows\System32\mscdexnt.exe
[2006.11.02 09:10:00 | 000,002,842 | ---- | C] () -- C:\Windows\System32\redir.exe
[2006.11.02 09:09:59 | 000,069,886 | ---- | C] () -- C:\Windows\System32\edit.com
[2006.11.02 09:09:59 | 000,019,694 | ---- | C] () -- C:\Windows\System32\GRAPHICS.COM
[2006.11.02 09:09:59 | 000,000,882 | ---- | C] () -- C:\Windows\System32\share.exe
[2006.11.02 09:09:59 | 000,000,882 | ---- | C] () -- C:\Windows\System32\fastopen.exe
[2006.11.02 09:09:57 | 000,014,710 | ---- | C] () -- C:\Windows\System32\KB16.COM
[2006.11.02 09:09:56 | 000,007,052 | ---- | C] () -- C:\Windows\System32\nlsfunc.exe
[2006.11.02 09:09:55 | 000,039,274 | ---- | C] () -- C:\Windows\System32\mem.exe
[2006.11.02 09:09:55 | 000,001,131 | ---- | C] () -- C:\Windows\System32\LOADFIX.COM
[2006.11.02 09:09:53 | 000,011,753 | ---- | C] () -- C:\Windows\System32\setver.exe
[2006.11.02 09:09:52 | 000,020,634 | ---- | C] () -- C:\Windows\System32\debug.exe
[2006.11.02 09:09:51 | 000,008,424 | ---- | C] () -- C:\Windows\System32\exe2bin.exe
[2006.11.02 09:09:50 | 000,012,642 | ---- | C] () -- C:\Windows\System32\edlin.exe
[2006.11.02 09:09:49 | 000,050,648 | ---- | C] () -- C:\Windows\System32\COMMAND.COM
[2006.11.02 09:09:49 | 000,012,498 | ---- | C] () -- C:\Windows\System32\append.exe
[2006.11.02 09:09:45 | 000,027,097 | ---- | C] () -- C:\Windows\System32\country.sys
[2006.11.02 09:09:44 | 000,042,809 | ---- | C] () -- C:\Windows\System32\KEY01.SYS
[2006.11.02 09:09:44 | 000,042,537 | ---- | C] () -- C:\Windows\System32\KEYBOARD.SYS
[2006.11.02 09:09:42 | 000,009,029 | ---- | C] () -- C:\Windows\System32\ANSI.SYS
[2006.11.02 09:09:41 | 000,004,768 | ---- | C] () -- C:\Windows\System32\HIMEM.SYS
[2006.11.02 09:09:40 | 000,029,274 | ---- | C] () -- C:\Windows\System32\NTDOS412.SYS
[2006.11.02 09:09:38 | 000,029,370 | ---- | C] () -- C:\Windows\System32\NTDOS411.SYS
[2006.11.02 09:09:35 | 000,029,146 | ---- | C] () -- C:\Windows\System32\NTDOS404.SYS
[2006.11.02 09:09:31 | 000,029,146 | ---- | C] () -- C:\Windows\System32\NTDOS804.SYS
[2006.11.02 09:09:29 | 000,027,866 | ---- | C] () -- C:\Windows\System32\NTDOS.SYS
[2006.11.02 09:09:26 | 000,035,536 | ---- | C] () -- C:\Windows\System32\NTIO412.SYS
[2006.11.02 09:09:24 | 000,035,776 | ---- | C] () -- C:\Windows\System32\NTIO411.SYS
[2006.11.02 09:09:23 | 000,034,672 | ---- | C] () -- C:\Windows\System32\NTIO404.SYS
[2006.11.02 09:09:22 | 000,034,672 | ---- | C] () -- C:\Windows\System32\NTIO804.SYS
[2006.11.02 09:09:20 | 000,033,952 | ---- | C] () -- C:\Windows\System32\NTIO.SYS
[2006.11.02 08:25:08 | 000,013,312 | ---- | C] () -- C:\Windows\System32\win87em.dll
[2006.09.29 16:12:12 | 000,303,104 | ---- | C] () -- C:\Windows\System32\dnt27VC8.dll
[2006.09.24 22:04:42 | 000,090,112 | ---- | C] () -- C:\Windows\System32\dntvmc27VC8.dll
[2006.09.24 22:03:32 | 000,086,016 | ---- | C] () -- C:\Windows\System32\dntvm27VC8.dll
[2006.09.21 14:53:28 | 000,282,679 | ---- | C] () -- C:\Windows\System32\dnt27.dll
[2006.09.21 14:52:24 | 000,077,882 | ---- | C] () -- C:\Windows\System32\dntvmc27.dll
[2006.09.21 14:52:14 | 000,077,881 | ---- | C] () -- C:\Windows\System32\dntvm27.dll
[2002.03.17 02:00:00 | 000,007,420 | ---- | C] () -- C:\Windows\UA000107.DLL
[1998.05.11 00:00:00 | 000,748,160 | ---- | C] () -- C:\Windows\System32\CO2C40EN.DLL
[1997.09.14 02:10:28 | 000,000,304 | ---- | C] () -- C:\Windows\KARTVERW.INI
[1996.12.14 01:00:00 | 000,094,208 | ---- | C] () -- C:\Windows\System32\MSENCODE.DLL
[1996.12.14 01:00:00 | 000,022,016 | ---- | C] () -- C:\Windows\System32\ODBCSTF.DLL
[1996.12.14 01:00:00 | 000,022,016 | ---- | C] () -- C:\Windows\System32\DOCOBJ.DLL
[1996.12.14 01:00:00 | 000,012,288 | ---- | C] () -- C:\Windows\System32\HLINKPRX.DLL
[1996.11.18 23:15:52 | 000,131,072 | ---- | C] () -- C:\Windows\System32\P2SODBC.DLL
[1996.11.18 23:15:50 | 000,054,272 | ---- | C] () -- C:\Windows\System32\P2IRDAO.DLL
[1996.11.18 23:15:50 | 000,050,176 | ---- | C] () -- C:\Windows\System32\P2CTDAO.DLL
[1996.11.18 23:15:50 | 000,036,352 | ---- | C] () -- C:\Windows\System32\P2BBND.DLL
lillimucki ist offline   Mit Zitat antworten
Werbung

Windows 7 Tipps und Tricks in Bildern

Alt 28.04.2011, 22:09   #11 (Direktlink)
War schon mal da
 
Benutzerbild von lillimucki
 
Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
Standard

...und immer weiter bis zum Ende:


========== Files Created - No Company Name ==========

[2011.04.28 20:41:56 | 000,000,205 | ---- | C] () -- C:\Users\Heiner\Desktop\READYBOOST (J).lnk
[2011.04.28 17:40:48 | 000,000,793 | ---- | C] () -- C:\Users\Heiner\Desktop\mbam.exe.lnk
[2011.04.26 21:08:27 | 1877,454,848 | -HS- | C] () -- C:\hiberfil.sys
[2011.04.26 14:05:59 | 000,000,334 | ---- | C] () -- C:\Windows\tasks\RegistryBooster.job
[2011.04.26 11:20:01 | 000,358,172 | ---- | C] () -- C:\Users\Heiner\Documents\cc_20110426_111944.reg
[2011.04.24 19:03:03 | 000,524,288 | -HS- | C] () -- C:\Users\Heiner\ntuser.dat{c73d8214-6e91-11e0-834a-001bfcfaa836}.TMContainer00000000000000000002.regtrans-ms
[2011.04.24 19:03:03 | 000,524,288 | -HS- | C] () -- C:\Users\Heiner\ntuser.dat{c73d8214-6e91-11e0-834a-001bfcfaa836}.TMContainer00000000000000000001.regtrans-ms
[2011.04.24 19:03:03 | 000,065,536 | -HS- | C] () -- C:\Users\Heiner\ntuser.dat{c73d8214-6e91-11e0-834a-001bfcfaa836}.TM.blf
[2011.04.24 18:39:22 | 005,604,485 | -H-- | C] () -- C:\Users\Heiner\AppData\Local\IconCache.db
[2011.04.21 08:28:41 | 000,000,824 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2011.04.20 12:29:30 | 000,016,384 | ---- | C] () -- C:\Windows\System32\jddac.dll
[2011.04.20 12:29:30 | 000,015,360 | ---- | C] () -- C:\Windows\System32\jdnat.dll
[2011.04.20 12:29:30 | 000,006,656 | ---- | C] () -- C:\Windows\System32\jdboot.exe
========== LOP Check ==========

[2008.10.11 20:09:33 | 000,000,000 | -HSD | M] -- C:\Users\Heiner\AppData\Roaming\.#
[2007.11.26 13:03:15 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\1&1
[2010.01.27 14:15:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Acronis
[2008.07.11 14:35:25 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ASCOMP Software
[2010.08.01 11:20:27 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Ashampoo
[2010.08.03 14:11:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\avidemux
[2010.11.11 22:10:27 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Balabolka
[2008.05.12 23:56:00 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\BirthdayRemember
[2008.01.28 13:49:55 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Buhl Data Service
[2010.03.18 20:44:23 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Canneverbe Limited
[2007.11.26 11:37:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Canon
[2008.10.02 20:01:14 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\CDZilla
[2010.11.02 21:55:46 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\COMPUTERBILD-Abzockschutz
[2010.02.17 12:28:50 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Conceptworld
[2009.07.05 20:01:36 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Copernic
[2009.01.29 23:13:05 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\CoreFTP
[2008.10.18 18:48:04 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Daoisoft
[2007.12.03 20:09:54 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DataDesign
[2009.01.01 14:36:45 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DeepBurner
[2011.03.21 17:55:43 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DreamDale
[2008.03.20 22:56:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DTgrafic
[2008.01.28 19:53:37 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\EPSON
[2010.10.08 19:24:16 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FILEminimizerPictures
[2009.08.07 14:06:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FileZilla
[2009.07.20 19:20:07 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FinalBurner Video DVD
[2010.08.04 13:20:09 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FireShot
[2010.02.24 06:32:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FlashGet
[2009.02.02 18:07:50 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Flickr
[2009.12.14 10:46:23 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Foxit
[2010.06.01 15:07:50 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Foxit Software
[2011.04.26 11:17:48 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Free Download Manager
[2010.03.17 19:24:07 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FreeFLVConverter
[2010.04.23 11:01:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\freeTVRadio
[2009.07.20 22:11:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\GetRightToGo
[2011.03.23 11:57:43 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\GlarySoft
[2007.12.22 23:05:33 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\GMX
[2008.05.08 17:20:21 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\gtk-2.0
[2010.05.07 01:14:51 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\HandBrake
[2010.08.30 10:32:38 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\HDD Thermometer
[2010.12.27 09:53:09 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\HTC Home
[2010.11.11 22:10:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Hunspell
[2009.08.06 11:57:11 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ICQ
[2009.08.13 13:57:16 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Intenium
[2011.01.06 20:54:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Inventivio
[2008.01.11 12:00:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\JAM Software
[2010.02.09 09:35:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\JGoodies
[2008.04.10 15:35:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\JoJoThumb
[2009.01.15 23:20:56 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\jpg-Illuminator
[2010.05.12 12:57:32 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\KeePass
[2010.03.11 21:11:58 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Keseling
[2008.09.22 09:54:18 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\klickTel
[2011.01.19 13:16:04 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Leadertech
[2008.10.18 16:40:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Lexware
[2011.03.21 17:50:40 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\MagicBall4
[2008.12.19 14:52:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Map24
[2010.03.22 13:08:25 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\MOVAVI
[2008.12.11 13:08:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\NAVIGON
[2008.07.31 19:18:53 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Nettalk
[2009.02.02 18:02:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Nokia
[2010.04.23 11:05:22 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\OfferBox
[2008.08.26 18:04:05 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Open Source Applications Foundation
[2008.12.14 19:08:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\OpenOffice.org
[2011.04.04 21:32:29 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\OTRHomeloader
[2010.05.27 16:55:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Panda Security
[2010.12.21 10:50:19 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Participatory Culture Foundation
[2009.02.02 18:02:37 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PC Suite
[2010.12.21 10:51:33 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PCF-VLC
[2010.12.02 10:27:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PCToolsFirewallPlus
[2009.08.13 14:06:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Peace Craft
[2010.11.18 11:28:54 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PeaceCraft2
[2008.08.26 18:03:07 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Python-Eggs
[2010.10.19 11:15:18 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\QuickScan
[2010.05.13 21:03:13 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Returnil
[2011.03.16 12:20:44 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Samsung
[2007.11.24 22:20:34 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ScanSoft
[2009.09.12 11:26:34 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ScreenSeven
[2008.02.01 00:59:00 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\SimpleScreenshot
[2010.03.31 12:51:13 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Software Informer
[2010.11.25 21:41:36 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Spamihilator
[2011.01.06 20:52:23 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Speak-A-Message
[2010.09.09 14:14:51 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\SuperEasy
[2010.03.09 09:42:41 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\SuperEasy Software
[2011.02.21 12:14:39 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Systweak
[2007.11.26 17:45:48 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\T-Online
[2007.11.25 00:14:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Template
[2009.12.28 10:49:47 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Thunderbird
[2007.12.07 09:04:40 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\TuneUp Software
[2009.05.21 11:36:21 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\TVcentral-Core
[2010.01.27 10:27:24 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Ulead Systems
[2011.04.26 14:05:55 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Uniblue
[2010.05.10 14:50:41 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Video DVD Maker FREE
[2008.11.04 19:31:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ViewPicXXL
[2010.11.03 09:16:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Vista Start Menu
[2011.04.28 17:38:01 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Vso
[2011.01.01 16:23:57 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\René's Homepage
[2011.04.26 02:24:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ZSGebmahner
[2009.10.11 20:47:49 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Zylom
[2011.04.28 11:00:00 | 000,000,436 | ---- | M] () -- C:\Windows\Tasks\ASOService.job
[2010.11.06 09:01:13 | 000,000,970 | ---- | M] () -- C:\Windows\Tasks\Paragon File Archive name arc_051110075557617.job
[2011.04.28 20:36:32 | 000,000,334 | ---- | M] () -- C:\Windows\Tasks\RegistryBooster.job
[2011.04.28 20:33:33 | 000,032,562 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.04.15 17:00:23 | 000,000,402 | ---- | M] () -- C:\Windows\Tasks\WebUpdate.job

========== Purity Check ==========



========== Custom Scans ==========


< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2008.10.11 20:09:33 | 000,000,000 | -HSD | M] -- C:\Users\Heiner\AppData\Roaming\.#
[2007.11.26 13:03:15 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\1&1
[2010.01.27 14:15:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Acronis
[2011.02.15 08:59:05 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Adobe
[2010.08.11 14:35:55 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Apple Computer
[2008.10.10 11:21:29 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ArcSoft
[2008.07.11 14:35:25 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ASCOMP Software
[2010.08.01 11:20:27 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Ashampoo
[2010.08.03 14:11:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\avidemux
[2010.03.20 18:35:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\AVS4YOU
[2010.11.11 22:10:27 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Balabolka
[2008.05.12 23:56:00 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\BirthdayRemember
[2008.01.28 13:49:55 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Buhl Data Service
[2010.03.18 20:44:23 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Canneverbe Limited
[2007.11.26 11:37:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Canon
[2008.10.02 20:01:14 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\CDZilla
[2010.11.02 21:55:46 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\COMPUTERBILD-Abzockschutz
[2010.02.17 12:28:50 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Conceptworld
[2009.07.05 20:01:36 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Copernic
[2009.01.29 23:13:05 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\CoreFTP
[2008.02.13 14:58:18 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Corel
[2008.10.18 18:48:04 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Daoisoft
[2007.12.03 20:09:54 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DataDesign
[2009.01.01 14:36:45 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DeepBurner
[2010.05.23 17:51:54 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Ditto
[2010.08.23 20:04:14 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DivX
[2011.03.21 17:55:43 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DreamDale
[2008.03.20 22:56:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DTgrafic
[2010.10.26 18:04:36 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DVD Flick
[2009.07.20 20:29:51 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\DVD Shrink
[2010.12.02 10:05:56 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\dvdcss
[2008.01.28 19:53:37 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\EPSON
[2008.01.25 21:48:23 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FastStone
[2010.10.08 19:24:16 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FILEminimizerPictures
[2009.08.07 14:06:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FileZilla
[2009.07.20 19:20:07 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FinalBurner Video DVD
[2010.08.04 13:20:09 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FireShot
[2010.02.24 06:32:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FlashGet
[2009.02.02 18:07:50 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Flickr
[2009.12.14 10:46:23 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Foxit
[2010.06.01 15:07:50 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Foxit Software
[2011.04.26 11:17:48 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Free Download Manager
[2010.03.17 19:24:07 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\FreeFLVConverter
[2010.04.23 11:01:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\freeTVRadio
[2009.07.20 22:11:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\GetRightToGo
[2011.03.23 11:57:43 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\GlarySoft
[2007.12.22 23:05:33 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\GMX
[2007.11.27 12:06:36 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Google
[2008.05.08 17:20:21 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\gtk-2.0
[2010.05.07 01:14:51 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\HandBrake
[2010.08.30 10:32:38 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\HDD Thermometer
[2008.09.18 22:59:31 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Help
[2010.12.27 09:53:09 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\HTC Home
[2010.11.11 22:10:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Hunspell
[2009.08.06 11:57:11 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ICQ
[2009.10.11 20:47:49 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Identities
[2008.01.28 13:37:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\InstallShield
[2009.08.13 13:57:16 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Intenium
[2011.01.06 20:54:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Inventivio
[2008.01.11 12:00:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\JAM Software
[2010.02.09 09:35:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\JGoodies
[2008.04.10 15:35:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\JoJoThumb
[2009.01.15 23:20:56 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\jpg-Illuminator
[2010.05.12 12:57:32 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\KeePass
[2010.03.11 21:11:58 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Keseling
[2008.09.22 09:54:18 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\klickTel
[2007.12.31 00:21:45 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Lavasoft
[2011.01.19 13:16:04 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Leadertech
[2008.10.18 16:40:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Lexware
[2011.01.19 13:13:29 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Logishrd
[2011.01.19 13:16:12 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Logitech
[2007.11.24 17:46:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Macromedia
[2011.03.21 17:50:40 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\MagicBall4
[2009.03.26 19:32:44 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Malwarebytes
[2008.12.19 14:52:02 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Map24
[2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Media Center Programs
[2011.04.26 11:17:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Media Player Classic
[2009.05.26 08:04:44 | 000,000,000 | --SD | M] -- C:\Users\Heiner\AppData\Roaming\Microsoft
[2010.03.22 13:08:25 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\MOVAVI
[2008.04.14 17:57:39 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Mozilla
[2008.12.11 13:08:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\NAVIGON
[2010.06.15 08:28:14 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\NCH Software
[2010.03.17 15:41:16 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Nero
[2008.07.31 19:18:53 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Nettalk
[2009.02.02 18:02:42 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Nokia
[2010.04.23 11:05:22 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\OfferBox
[2008.08.26 18:04:05 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Open Source Applications Foundation
[2008.12.14 19:08:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\OpenOffice.org
[2008.12.14 18:49:28 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\OpenOffice.org2
[2011.04.04 21:32:29 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\OTRHomeloader
[2010.05.27 16:55:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Panda Security
[2010.12.21 10:50:19 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Participatory Culture Foundation
[2009.02.02 18:02:37 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PC Suite
[2010.12.21 10:51:33 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PCF-VLC
[2010.12.02 10:27:03 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PCToolsFirewallPlus
[2009.08.13 14:06:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Peace Craft
[2010.11.18 11:28:54 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\PeaceCraft2
[2008.08.26 18:03:07 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Python-Eggs
[2010.10.19 11:15:18 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\QuickScan
[2010.03.16 15:45:19 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Real
[2010.05.13 21:03:13 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Returnil
[2011.03.16 12:20:44 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Samsung
[2007.11.24 22:20:34 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ScanSoft
[2009.09.12 11:26:34 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ScreenSeven
[2008.02.01 00:59:00 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\SimpleScreenshot
[2010.07.29 11:55:28 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Skype
[2008.08.14 09:23:14 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\skypePM
[2010.03.31 12:51:13 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Software Informer
[2010.11.25 21:41:36 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Spamihilator
[2011.01.06 20:52:23 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Speak-A-Message
[2010.09.09 14:14:51 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\SuperEasy
[2010.03.09 09:42:41 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\SuperEasy Software
[2011.02.21 12:14:39 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Systweak
[2007.11.26 17:45:48 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\T-Online
[2007.12.11 09:05:14 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Talkback
[2007.11.25 00:14:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Template
[2009.12.28 10:49:47 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Thunderbird
[2007.12.07 09:04:40 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\TuneUp Software
[2009.05.21 11:36:21 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\TVcentral-Core
[2010.01.27 10:27:24 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Ulead Systems
[2011.04.26 14:05:55 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Uniblue
[2010.05.10 14:50:41 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Video DVD Maker FREE
[2008.11.04 19:31:10 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ViewPicXXL
[2010.11.03 09:16:08 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Vista Start Menu
[2011.04.26 02:24:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\vlc
[2011.04.28 17:38:01 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Vso
[2011.01.01 16:23:57 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\René's Homepage
[2008.01.18 07:45:54 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Yahoo!
[2011.04.26 02:24:52 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\ZSGebmahner
[2009.10.11 20:47:49 | 000,000,000 | ---D | M] -- C:\Users\Heiner\AppData\Roaming\Zylom

< %APPDATA%\*.exe /s >
[2010.05.10 15:10:41 | 000,087,608 | ---- | M] () -- C:\Users\Heiner\AppData\Roaming\inst.exe
[2010.12.27 09:52:37 | 000,260,096 | ---- | M] (Stealth Software) -- C:\Users\Heiner\AppData\Roaming\HTC Home\HTCHome (x64).exe
[2010.12.27 09:52:37 | 000,261,120 | ---- | M] (Stealth Software) -- C:\Users\Heiner\AppData\Roaming\HTC Home\HTCHome.exe
[2010.12.27 09:52:38 | 000,165,888 | ---- | M] (Stealth Software) -- C:\Users\Heiner\AppData\Roaming\HTC Home\Updater.exe
[2010.12.27 09:51:20 | 000,277,504 | ---- | M] (Stealth Software) -- C:\Users\Heiner\AppData\Roaming\HTC Home\Uninstall\Uninstall.exe
[2010.06.17 19:08:22 | 000,010,134 | R--- | M] () -- C:\Users\Heiner\AppData\Roaming\Microsoft\Installer\{116D1725-3193-49AF-8999-036D385F701E}\_07FC79487A9632D69318B3.exe
[2011.01.19 13:16:03 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Heiner\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2009.02.02 17:32:33 | 000,004,286 | R--- | M] () -- C:\Users\Heiner\AppData\Roaming\Microsoft\Installer\{E2DAB18F-D5D4-435A-B033-6B8D0EAE4D7A}\_497245D8059E20FE841577.exe
[2009.02.02 17:32:33 | 000,004,286 | R--- | M] () -- C:\Users\Heiner\AppData\Roaming\Microsoft\Installer\{E2DAB18F-D5D4-435A-B033-6B8D0EAE4D7A}\_6FEFF9B68218417F98F549.exe
[2010.02.05 00:49:18 | 000,010,134 | R--- | M] () -- C:\Users\Heiner\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
[2011.02.01 19:04:18 | 000,052,616 | ---- | M] () -- C:\Users\Heiner\AppData\Roaming\Mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\toolbar@ask.com\chrome\content\issigned.exe
[2011.03.27 15:04:11 | 003,325,832 | ---- | M] (Ask) -- C:\Users\Heiner\AppData\Roaming\Mozilla\Firefox\Profiles\sopcs2bi.default\extens ions\toolbar@ask.com\chrome\temp\askToolbar.exe
[2011.02.21 12:15:19 | 010,341,040 | ---- | M] (Systweak Inc ) -- C:\Users\Heiner\AppData\Roaming\Systweak\ASO3\Installer\aso3setup.exe

< %SYSTEMDRIVE%\*.exe >
[1997.08.05 01:00:00 | 000,014,123 | ---- | M] () -- C:\DIRSUCHE.EXE
[2008.01.28 15:51:20 | 002,254,848 | ---- | M] (Mirko Böer) -- C:\SimpleScreenshot.exe


< MD5 for: AGP440.SYS >
[2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bb eb0d97a\AGP440.sys
[2008.01.18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647b bd2a4c6\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009.04.10 23:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.10 23:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.10 23:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261ea b99e8\atapi.sys
[2008.01.18 23:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.18 23:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a218 9ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.01.19 07:06:48 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008.01.19 07:06:48 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a44247 9c42c\atapi.sys
[2008.01.19 06:33:23 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da 31a8b\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2008.01.18 23:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.18 23:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af1152788 7c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.18 23:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2007.01.05 21:59:42 | 000,035,920 | ---- | M] (NVIDIA Corporation) MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9 -- C:\Windows\System32\drivers\nvstor.sys
[2007.01.05 21:59:42 | 000,035,920 | ---- | M] (NVIDIA Corporation) MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_45f67928\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.18 23:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.18 23:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327be fea467\nvstor.sys

< MD5 for: NVSTOR32.SYS >
[2008.11.12 17:02:46 | 000,146,464 | ---- | M] (NVIDIA Corporation) MD5=1BEF40FDCA53B43E16E1851FAA3440CC -- C:\NVIDIA\nForceWinVistaInt\15.26\IDE\WinVista\sataraid\nvstor32.sys
[2009.08.04 18:44:14 | 000,213,024 | ---- | M] (NVIDIA Corporation) MD5=269DE658DEAF032564E8B6430B5BD170 -- C:\NVIDIA\nForceWinVista\15.51\English\IDE\Win7\sataraid\nvstor32.sys
[2009.08.04 18:44:14 | 000,213,024 | ---- | M] (NVIDIA Corporation) MD5=269DE658DEAF032564E8B6430B5BD170 -- C:\NVIDIA\nForceWinVista\15.51\English\IDE\WinVista\sataraid\nvstor32.sys
[2009.08.04 18:43:40 | 000,213,024 | ---- | M] (NVIDIA Corporation) MD5=3FF57A9A657C9690ECBC8B1E3B6E3979 -- C:\NVIDIA\nForceWinVista\15.51\English\IDE\Win7\sata_ide\nvstor32.sys
[2009.08.04 18:43:40 | 000,213,024 | ---- | M] (NVIDIA Corporation) MD5=3FF57A9A657C9690ECBC8B1E3B6E3979 -- C:\NVIDIA\nForceWinVista\15.51\English\IDE\WinVista\sata_ide\nvstor32.sys
[2009.08.04 18:43:40 | 000,213,024 | ---- | M] (NVIDIA Corporation) MD5=3FF57A9A657C9690ECBC8B1E3B6E3979 -- C:\Windows\System32\drivers\nvstor32.sys
[2009.08.04 18:43:40 | 000,213,024 | ---- | M] (NVIDIA Corporation) MD5=3FF57A9A657C9690ECBC8B1E3B6E3979 -- C:\Windows\System32\DriverStore\FileRepository\nvstor32.inf_dcdb2e54\nvstor32.sy s
[2007.07.03 01:37:08 | 000,110,112 | ---- | M] (NVIDIA Corporation) MD5=A1CE1A6FD74C046F029448FCFA5E386D -- C:\Windows\System32\DriverStore\FileRepository\nvstor32.inf_efe24208\nvstor32.sy s
[2008.11.12 17:02:18 | 000,146,464 | ---- | M] (NVIDIA Corporation) MD5=BB4DD678706510D9249EED1DA0219900 -- C:\NVIDIA\nForceWinVistaInt\15.26\IDE\WinVista\sata_ide\nvstor32.sys
[2008.11.12 17:02:18 | 000,146,464 | ---- | M] (NVIDIA Corporation) MD5=BB4DD678706510D9249EED1DA0219900 -- C:\Windows\System32\DriverStore\FileRepository\nvstor32.inf_b40e17fb\nvstor32.sy s
[2007.08.09 19:12:30 | 000,110,624 | ---- | M] (NVIDIA Corporation) MD5=DC5F166422BEEBF195E3E4BB8AB4EE22 -- C:\Windows\System32\DriverStore\FileRepository\nvstor32.inf_99d8b088\nvstor32.sy s
[2008.01.26 03:02:02 | 000,140,832 | ---- | M] (NVIDIA Corporation) MD5=FA7B8ECA6E845B244B7E30A9DCD82C6C -- C:\Windows\System32\DriverStore\FileRepository\nvstor32.inf_ef43fd49\nvstor32.sy s

< MD5 for: SCECLI.DLL >
[2008.01.18 23:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\sce cli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\sce cli.dll
[2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\sce cli.dll

< MD5 for: USERINIT.EXE >
[2008.01.18 23:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.18 23:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe

< MD5 for: WS2IFSL.SYS >
[2006.11.02 10:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_4d4fded8cae2956d\ws2ifsl.sys
[2008.01.18 21:56:50 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.18 21:56:50 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2006.11.02 12:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2011.04.15 09:49:56 | 000,353,792 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\dxtmsft.dll
[2011.04.15 09:49:56 | 000,223,232 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\dxtrans.dll
[2006.11.02 09:10:21 | 000,068,992 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\MMSYSTEM.DLL
[2011.04.15 09:49:50 | 000,420,864 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\vbscript.dll
[2006.09.18 23:43:37 | 000,013,312 | ---- | M] () Unable to obtain MD5 -- C:\Windows\System32\win87em.dll
[2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

========== Alternate Data Streams ==========

@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMPFC5A2B2
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:1CA73D29
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:7E95B6FD

< End of report >
lillimucki ist offline   Mit Zitat antworten
Alt 28.04.2011, 22:11   #12 (Direktlink)
Super-Moderator
 
Registriert seit: 08.02.2010
Beiträge: 1.728
Standard

Kurze Info

Ein Moderator wird gleich die Links in deinem Hostfile löschen.
Den es gibt genung neugierige Mitmenschen die gerne auf solche verlockenden Links klicken.

Das Log von OTL werd ich mir morgen anschauen. Das schaffe ich heute zeitlich nicht mehr.
__________________
Gruß Leo

Der Leo ist offline   Mit Zitat antworten
Alt 28.04.2011, 22:12   #13 (Direktlink)
War schon mal da
 
Benutzerbild von lillimucki
 
Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
Standard

Und nun die Extras:
OTL Extras logfile created on: 28.04.2011 20:52:00 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

2,00 Gb Total Physical Memory | 0,00 Gb Available Physical Memory | 20,00% Memory free
6,00 Gb Paging File | 4,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s): c:\pagefile.sys 4092 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 143,19 Gb Total Space | 61,37 Gb Free Space | 42,86% Space Free | Partition Type: NTFS
Drive D: | 5,86 Gb Total Space | 0,82 Gb Free Space | 13,97% Space Free | Partition Type: NTFS
Drive J: | 1,88 Gb Total Space | 0,11 Gb Free Space | 5,58% Space Free | Partition Type: FAT

Computer Name: HEINER-PC | User Name: Heiner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-153915148-350753066-3938573312-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Browse with &IrfanView] -- "C:\Program Files\iview410g\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Durchsuchen mit &IrfanView] -- "C:\Program Files\iview410g\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Unstopcp] -- "C:\Datenrettung CD-DVD\Roadkil.Net\UnstopCpy_5_2_Win2K_UP.exe" "%1" * (Roadkil.Net)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1"
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\Winamp.exe" /ADD "%1"
Directory [Winamp.Play] -- "C:\Program Files\Winamp\Winamp.exe" "%1"
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 1
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-153915148-350753066-3938573312-1000]
"EnableNotifications" = 1
"EnableNotificationsRef" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir ewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir ewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir ewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir ewallPolicy\FirewallRules]
"{190C5382-2844-46F0-8708-2B9F116B7707}" = lport=445 | protocol=6 | dir=in | app=system |
"{2284A150-AB0D-4665-90F1-864344CC6930}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{2D02807E-472A-4DF8-8008-B526C24FC64C}" = lport=139 | protocol=6 | dir=in | app=system |
"{3CBB23E3-314A-4E14-B1AE-36C89562211E}" = lport=445 | protocol=6 | dir=in | app=system |
"{59CDE329-0052-45F6-9FAB-EA70AB3B0137}" = lport=rpc | protocol=6 | dir=in | app=c:\windows\system32\vdsldr.exe |
"{681A550A-EA2C-4F39-9998-97611FEEE672}" = rport=137 | protocol=17 | dir=out | app=system |
"{688D4605-8574-4087-B64B-4425C3C5D102}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{93FAFAD3-FC9E-4E0D-B0D8-31D622B92F01}" = lport=137 | protocol=17 | dir=in | app=system |
"{9643BA87-279D-4D73-9E86-BC3200623CEA}" = rport=445 | protocol=6 | dir=out | app=system |
"{986EE4AF-86FD-4969-A50D-B517DD12668C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{A4A2EB55-CB10-4B95-AEAD-5A7E7778D2FC}" = lport=rpc | protocol=6 | dir=in | svc=vds | app=c:\windows\system32\vds.exe |
"{C0708B4C-5FBE-482E-AF04-FC89D74BD3F2}" = lport=rpc | protocol=6 | dir=in | app=c:\windows\system32\services.exe |
"{C4F8620C-9343-4075-8181-361547F4C553}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe |
"{C93A236F-E66E-470D-86ED-FE0991914B6E}" = lport=138 | protocol=17 | dir=in | app=system |
"{E4A478F2-D103-45A4-93BD-86ED1B248D58}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E4EC8BC0-DF76-4B7A-B9F9-37874ADB4D34}" = rport=138 | protocol=17 | dir=out | app=system |
"{E7CFE094-BA47-4B0D-9EC9-D9907046D0A0}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=datei- und druckerfreigabe (spoolerdienst - rpc-epmap) |
"{E8E88AC4-C9EB-4F75-9D88-9DAFED44023F}" = rport=139 | protocol=6 | dir=out | app=system |
"{EF722AB7-4831-4356-965D-8F2B437CD3E1}" = lport=rpc | protocol=6 | dir=in | svc=* | app=c:\windows\system32\svchost.exe |
"{F6599DB0-2961-4E31-A512-4D9D8C9365AF}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{F9BA4B07-E70C-4F53-8DE9-6CAC3A1A87CB}" = lport=445 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Fir ewallPolicy\FirewallRules]
"{0A27D42E-19A9-4372-9F10-3C213DF883C6}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) |
"{1A7A76BA-1DFA-4945-9FE2-5FB16D2DB39F}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{32BA0E6C-EB38-4E18-A270-1834E4DBC321}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) |
"{354C188E-F533-4FB9-9DBF-EA80BAF0676B}" = protocol=58 | dir=out | name=datei- und druckerfreigabe (echoanforderung - icmpv6 ausgehend) |
"{39A471AC-D97F-4081-8AF5-DA8C0F09E17F}" = protocol=6 | dir=out | app=%systemroot%\system32\msra.exe |
"{4201C0F6-DF13-458A-AA4B-2CC3E180332D}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{45CDEE4D-6A16-4FEE-8BA7-49A443D9C7B5}" = protocol=6 | dir=in | app=c:\program files\smart pc utilities\vista services optimizer\servicesoptimizer.exe |
"{514EB1A7-E7E6-454E-9814-96519C6E2B02}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) |
"{6C1B1B9A-B644-4836-A3CA-2A0F45D67892}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) |
"{7240C3C1-4C41-44BB-90CE-FD75D86EE57F}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{7BBC6197-3BEF-4A5A-80A9-1276C57C5CA9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{7CCB871C-9F58-4697-8F7E-DD3A87AF2247}" = protocol=6 | dir=in | app=c:\program files\smart pc utilities\vista services optimizer\webupdate.exe |
"{823F4366-5D8E-416C-B01C-E771CAAF9A7D}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) |
"{84936D85-0099-4DC1-8514-8662B834D9AA}" = protocol=17 | dir=in | app=c:\program files\smart pc utilities\vista services optimizer\webupdate.exe |
"{8515CB08-6EB3-46FF-84D4-C25F329D6DC5}" = protocol=1 | dir=out | name=datei- und druckerfreigabe (echoanforderung - icmpv4 ausgehend) |
"{888E331B-FC98-4182-B66F-A9B30ED24BA2}" = protocol=1 | dir=in | name=sisoftware sandra agent service (icmp-in) |
"{94E4F1A8-B91B-41AC-BF71-ECF8263B1ED0}" = protocol=58 | dir=in | name=datei- und druckerfreigabe (echoanforderung - icmpv6 eingehend) |
"{96D565C3-2682-4D6D-A9B5-FF5B7D07DEF7}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{9E3C71D8-8064-4B08-9FAC-CE81C3AEBC9B}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{B6B41BA0-394E-4BE2-A309-8DE2FEA95C9C}" = protocol=1 | dir=in | name=sisoftware deployment agent service (icmp-in) |
"{BF64FB08-07D2-400F-B17D-B51E7C472BE5}" = protocol=1 | dir=in | name=datei- und druckerfreigabe (echoanforderung - icmpv4 eingehend) |
"{BF82C2D6-F950-451D-9540-B0ED13438FED}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{C26DEA38-24DD-46AB-A148-63DE2AB26EF1}" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe |
"{CE66ECFD-1DFF-4C87-901E-381F0E44C19B}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{D43BA01B-F82B-4C6F-8D91-CF371309DD14}" = protocol=6 | dir=in | app=%systemroot%\system32\msra.exe |
"{E1A9991B-53ED-4E7C-B092-95A0337B1D32}" = protocol=17 | dir=in | app=c:\program files\smart pc utilities\vista services optimizer\servicesoptimizer.exe |
"TCP Query User{076D0914-C4DB-45CE-A22E-9E1210CA296F}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{46FBEC16-CA29-4548-A61D-192EB9B2E62C}C:\nof 7\fusion.exe" = protocol=6 | dir=in | app=c:\nof 7\fusion.exe |
"TCP Query User{9FC97A35-8FF4-4F06-B6B4-CF28BC3F57A7}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{BA4F7EBF-EB5A-4F08-870D-578CD550F66B}C:\program files\klebezettel ng\klebez.exe" = protocol=6 | dir=in | app=c:\program files\klebezettel ng\klebez.exe |
"UDP Query User{125FE2CE-D5B6-4EFC-BAEA-7F50C8858CAB}C:\program files\klebezettel ng\klebez.exe" = protocol=17 | dir=in | app=c:\program files\klebezettel ng\klebez.exe |
"UDP Query User{4234D505-5655-4F92-BFF0-2D5ED66D65DB}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{44A435C3-870C-4EBE-831F-5865A887AF44}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{7463C81B-4031-4A4D-9087-C6C54173A476}C:\nof 7\fusion.exe" = protocol=17 | dir=in | app=c:\nof 7\fusion.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00C58EBE-223E-4AB6-8AE9-38F27F4420BD}" = WISO Sparbuch 2009
"{00D0200F-3B4D-4A2F-869E-533ED835A943}" = Hervorhebe-Funktion (Windows Live Toolbar)
"{01CCDA56-6D59-4915-8BE2-752376E80E82}" = Hide-My-Address
"{048DB452-C8B0-4A8D-89AF-84A6B149E1EE}" = Meine Software
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA}" = Uniblue RegistryBooster
"{0EE4030A-8FD4-4798-A21D-17E525B1F7CF}" = Corel Snapfire
"{108A39BF-4ED1-4293-B11A-06BD521FB8F7}" = FreeOCR 3.0
"{116D1725-3193-49AF-8999-036D385F701E}" = Desktop Restore
"{119B7481-0216-40D2-A5CC-C3E1F461ECC1}" = Windows Live Fotogalerie
"{12665B01-3F3A-4433-B179-9D8E352D7547}" = Try Corel Snapfire muvee autoProducer add on
"{13CD417D-F1F1-4AC4-945D-FDDEB884756F}" = Microsoft Baseline Security Analyzer 2.2
"{15AC0C5D-A6FB-4CE2-8CD0-28179EEB5625}" = Nokia Connectivity Cable Driver
"{18A5DFF2-8A95-49F3-873F-743CB5549F3D}" = Canon ScanGear Starter
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{1C63DD23-6554-4A1F-8D0D-B5A6B49D8015}" = Corel Graphics Suite 11
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{2119BCD0-09CA-403B-92A1-35A13C33E179}" = Epson Customer Research Participation
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{218761F6-CBF6-4973-B910-A33E6563A1EA}" = Windows Live Toolbar-Erweiterung (Windows Live Toolbar)
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23B265D4-42E0-405B-B285-1782F629E049}" = 5CentSMS
"{23B72D50-1C7E-491C-8086-9E060051D316}" = Manual CanoScan LiDE 60
"{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = Media Player Classic - Home Cinema v. 1.3.1249.0
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 24
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{295C31E5-3F91-498E-9623-DA24D2FA2B6A}" = T-Online WLAN-Access Finder
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{2DD6C198-FA9A-40B4-8DE5-CE5206E3EB34}" = Smart Menus (Windows Live Toolbar)
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{319786B7-D72F-43B3-99C1-E93724ED17D3}" = Lexware online banking 4.90
"{3744B641-61DE-417F-BCDC-9CCED4224DF8}" = LightScribe System Software
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{43B74FAB-FB58-447D-8D3A-5F638AF36FD1}" = Netzmanager
"{46B70DEB-97B3-4E38-B746-EC16905E6A8F}" = WISO Sparbuch 2010
"{485DF5E7-8379-4BFA-BAE1-9B8DBFE0D6B4}" = Paragon Backup & Recovery™ 10 Home
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B6F67C5-D103-4329-A70A-F80BEEC26B70}" = Marco Polo TravelRouting Europe 2003
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}" = Microsoft Works
"{4F81901F-3655-4340-8227-F687F69A3C79}}_is1" = Klebezettel NG (Version 2.9.9)
"{54B1E5A3-1B29-4582-A226-172A1FC7BA6C}" = Windows Live Family Safety
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A166C0B-9557-4364-A057-F946D674E6AC}" = Windows Live Mail
"{5C474A83-A45F-470C-9AC8-2BD1C251BF9A}" = Skype™ 4.2
"{5C98D841-6392-41F1-A80E-B1A741F32A95}" = DSL-Speedtest
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{65883ddf-2152-4cb7-8e13-b99194b13498}" = Nero BackItUp
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{69097103-1F00-469D-BDE7-CAF50E241647}" = 5CentSMS
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{70B7A167-0B88-445D-A3EA-97C73AA88CAC}" = Windows Live Toolbar
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser und SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{735DEB9C-61BD-4D31-994B-92395BBB4E45}" = Microsoft XML Parser
"{7373184D-8E8F-4308-912A-3901071FA1AD}" = LightScribe Applications
"{738D0F96-2F2A-4650-B7C7-2C724D662091}" = 5CentSMS
"{75c53f52-398b-4d66-b28a-f9ef170b3b34}" = Nero BackItUp
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites für Windows Live Toolbar
"{79A3E733-3887-4043-8E32-C6A2577CF73C}" = klickTel OEM 2008
"{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}" = OmniPage SE
"{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"{7ff45382-e5a7-4772-b46d-a5c71f3a15d6}" = Nero BackItUp 4 Essentials
"{81821BF8-DA20-4F8C-AA87-F70A274828D4}" = Windows Live Writer
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{837B6259-6FF5-4E66-87C1-A5A15ED36FF4}" = Windows Live Messenger
"{83E2CFA9-E0EB-4E08-9F85-43E577FF3D60}" = Windows Live Anmelde-Assistent
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{878B631B-E0F9-41B9-83D9-BC9DFB0B9F2B}" = Ebad
"{8944ED10-DBF2-4FA9-8B5D-D7E1B046C761}_is1" = ColdCut
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8B79684C-6DAC-438C-8F30-10DF65C2068F}" = Samsung Digital Camera
"{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}" = Camera RAW Plug-In for EPSON Creativity Suite
"{8FBC9407-713D-4B8A-98D2-57210DA56049}" = MSN Toolbar
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90141793-E338-4EEB-B7E8-8CDED19D908D}" = 5CentSMS
"{91E04CA7-0B13-4F8C-AA4D-2A573AC96D19}" = Windows Live Essentials
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97C82B44-D408-4F14-9252-47FC1636D23E}_is1" = IZArc 3.81
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A0B139A7-E8D5-49E8-A7BF-12421E652208}" = pdfforge Toolbar v4.3
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1973A71-BC23-4A8C-A0A0-2B0497B7EAF4}" = WISO Sparbuch 2008
"{A306FD29-7D3A-4287-91AC-9A0180931395}_is1" = Roadkil's Unstoppable Copier Version 5.2
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{B1275E23-717A-4D52-997A-1AD1E24BC7F3}" = T-Online 6.0
"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}" = ccCommon
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 260.99
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 260.99
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B3C1579F-C9BB-4479-B343-B22C5C283D47}" = Vista Services Optimizer
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4E4ACA0-79C5-4FC0-818F-ECE4521EBF8D}" = COMPUTERBILD-Abzockschutz
"{B4E96960-5F6B-48B9-A5BD-6A5A9BB4F027}" = Avery Wizard 3.1
"{B525BB2C-9338-11D4-8B84-00B0D03E6A83}" = Palm Conduit Support for COM
"{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center
"{BA165460-FCF7-4D6C-A7A2-F2321700720F}" = MobileMe Control Panel
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BE4FE60C-A636-4017-B3FF-0EE7C39EAAF2}" = Speak-A-Message
"{BFBB91DB-9F0F-4A9C-9669-A97DA3512CF2}" = RealSpeak Solo fur Deutsch - Steffi
"{C5C649A8-1D21-4C83-9B08-7B3752E580F4}" = Safari
"{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser
"{CA9BCD4D-B782-4637-8F1F-F9A328D3C244}" = CanoScan Toolbox Ver4.9
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF25B0C4-A162-49C8-94FA-FFCFC8BD59FE}" = AstroStar 11.0
"{D263A9AE-0B59-4C01-B72B-DD3CA956BA58}" = Favicon-Manager
"{D848D140-41C3-4A53-86D8-E866A100B4****" = PC Connectivity Solution
"{D980202C-4681-4D9A-848C-875ABAA1870A}" = soft Xpansion PDF Quick Master 4.0
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.16.360
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DFAA3D2B-7087-464E-823B-738A23C29C27}" = Microsoft Visual J# 2.0 Redistributable Package - SE
"{E2DAB18F-D5D4-435A-B033-6B8D0EAE4D7A}" = Desk Drive
"{E3723A04-A894-4036-A78E-282E18F43C0A}_is1" = Tinypic 3.14
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}" = ScanToWeb
"{ED636101-1959-4360-8BF7-209436E7DEE4}" = Windows Live Sync
"{F0312AC6-988B-11DA-9C49-000476F770CC}" = CIB pdf brewer 2.5.26
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{F54B04F8-44B6-4218-82B9-69A28B69A61D}" = DDBAC
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F7E345A5-F79B-44EE-BC4A-738899E756C0}" = Lexware online banking 4.90
"{F8013DD1-574B-4921-A473-88A2F7A34D16}" = Paragon Drive Backup™ 9 Personal
"{F82C6574-AD88-4B40-A432-970BC77F1BD2}" = DesignPro 5
"{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}" = Vista Codec Package
"{FC008FF3-3006-4316-8845-6681379A21BB}" = 5CentSMS
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"3554AA4B-9B0B-451a-A269-2B5F53982209_is1" = ThreatFire
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AFPL Ghostscript 8.54" = AFPL Ghostscript 8.54
"AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts
"Ashampoo Burning Studio 10_is1" = Ashampoo Burning Studio 10.0.7
"Ashampoo PowerUp 3_is1" = Ashampoo PowerUp 3.10
"Ashampoo PowerUP XP Platinum 2" = Ashampoo PowerUP XP Platinum 2
"Ashampoo WinOptimizer 4_is1" = Ashampoo WinOptimizer 4.51
"avast" = avast! Pro Antivirus
"B076073A-5527-4f4f-B46B-B10692277DA2_is1" = DisplayFusion 3.0.6
"BabylonToolbar" = Babylon toolbar
"Balabolka" = Balabolka
"cayahooantispy" = CA Yahoo! Anti-Spy (remove only)
"CCleaner" = CCleaner
"CheckDrive_is1" = CheckDrive
"Chronik" = Chronik
"conduitEngine" = Conduit Engine
"Core FTP LE 2.1" = Core FTP LE 2.1
"Corel Applications" = Corel Applications
"Debut" = Debut Video Capture Software
"DEUTSCHLAND SPIELT Spiele Post" = DEUTSCHLAND SPIELT Spiele Post
"DFX for Windows Media Player" = DFX for Windows Media Player
"DiceDungeon" = DiceDungeon 0.98.0.29
"DivX Setup.divx.com" = DivX-Setup
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"DVD Flick_is1" = DVD Flick 1.3.0.7
"DVD Shrink_is1" = DVD Shrink 3.2
"EPSON Scanner" = EPSON Scan
"EPSON Stylus SX100_TX100 Benutzerhandbuch" = EPSON Stylus SX100_TX100 Handbuch
"EPSON SX100 Series" = EPSON SX100 Series Printer Uninstall
"EURO-XL8" = Microsoft Excel Euro Toolbar Addin (Remove only)
"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v4.60
"ffdshow_is1" = ffdshow [rev 2946] [2009-05-15]
"FileMenu Tools_is1" = FileMenu Tools
"FILEminimizer Pictures_is1" = FILEminimizer Pictures
"FileZilla Client" = FileZilla Client 3.2.6.1
"FlashLynx" = FlashLynx Video Download Software
"Flickr Uploadr" = Flickr Uploadr 3.0.5
"Folder Guide" = Folder Guide
"Foxit Reader" = Foxit Reader
"Foxit Toolbar" = Foxit Toolbar
"Free Download Manager_is1" = Free Download Manager 3.0
"FreePDF_XP" = FreePDF XP (Remove only)
"Google Updater" = Google Updater
"GPL Ghostscript 8.63" = GPL Ghostscript 8.63
"Handbrake" = Handbrake 0.9.4
"Hdd Speed Test Tool_is1" = Hdd Speed Test Tool v. 1.0.14 (RC 1)
"HDD Thermometer" = HDD Thermometer
"HijackThis" = HijackThis 2.0.2
"Icon Restore_is1" = Icon Restore 1.0
"ICQToolbar" = ICQ Toolbar
"InstallShield_{1C63DD23-6554-4A1F-8D0D-B5A6B49D8015}" = CorelDRAW Graphics Suite 11
"InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"InstallShield_{CF25B0C4-A162-49C8-94FA-FFCFC8BD59FE}" = AstroStar 11.0
"InstallShield_{F82C6574-AD88-4B40-A432-970BC77F1BD2}" = DesignPro 5
"IrfanView" = IrfanView (remove only)
"JDiskReport 1.3.2" = JGoodies JDiskReport 1.3.2
"JetDrive_is1" = JetDrive
"LHTTSGED" = L&H TTS3000 Deutsch
"MailStore Home_is1" = MailStore Home 4.2.0.5431
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Map24 Desktop_is1" = Map24 Desktop
"MAXA Cookie Manager Lite_is1" = MAXA Cookie Manager Lite 3.01
"MAXA Cookie Manager_is1" = MAXA Cookie Manager Standard 3.3
"MAXA-Lock_is1" = MAXA-Lock Standard
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft Visual J# 2.0 Redistributable Package - SE" = Microsoft Visual J# 2.0 Redistributable Package - SE
"MozBackup_is1" = MozBackup 1.4.7
"Mozilla Firefox (3.6b2)" = Mozilla Firefox (3.6b2)
"Mozilla Firefox 4.0 (x86 de)" = Mozilla Firefox 4.0 (x86 de)
"Mozilla Thunderbird (3.1.9)" = Mozilla Thunderbird (3.1.9)
"MyAshampoo Toolbar" = MyAshampoo Toolbar
"NAVIGON Fresh" = NAVIGON Fresh 3.2.0
"NAVIGON Sync" = NAVIGON Sync 1.0
"NetObjects Fusion 7" = NetObjects Fusion 7
"Nettalk_is1" = Nettalk 6.5
"Netzmanager" = Netzmanager
"NVIDIA Drivers" = NVIDIA Drivers
"Office8.0" = Microsoft Office 97, Professional Edition
"OTR Homeloader" = OTR Homeloader 1.5.8.129
"PC SECURITY TEST 2007_is1" = PC SECURITY TEST 2007
"PikySuite_is1" = PikySuite 3.0
"Prism" = Prism Video Converter
"Quicken 2000" = Quicken 2000
"Recuva" = Recuva
"Redirection Port Monitor" = RedMon - Redirection Port Monitor
"Revo Uninstaller" = Revo Uninstaller 1.92
"Secunia PSI (RC4)" = Secunia PSI (RC4)
"ShiftN_is1" = ShiftN 3.4
"softonic-de3 Toolbar" = softonic-de3 Toolbar
"Software Informer_is1" = Software Informer 1.0 BETA
"SpeedBit Video Accelerator" = SpeedBit Video Accelerator
"SSC Service Utility_is1" = SSC Service Utility v4.30
"ST6UNST #1" = VistawinExit 3 Freeware
"ST6UNST #2" = Zahlen des Lebens
"ST6UNST #3" = Zahlen des Lebens (C:\Program Files\Zahlen des Lebens\)
"SyncBack_is1" = SyncBack
"SystemRequirementsLab" = System Requirements Lab
"Taskbar Shuffle_is1" = Taskbar Shuffle version 2.5
"Thoosje Vista Tweaker" = Thoosje Vista Tweaker
"Tidy Favorites Buttons_is1" = Tidy Favorites Buttons 6.23
"TIPP10_is1" = TIPP10 Version 2.0.3
"TreeSize Free_is1" = TreeSize Free V2.1
"TUGZip_is1" = TUGZip 3.5
"Uniblue RegistryBooster" = Uniblue RegistryBooster
"Uninstall_is1" = Uninstall 1.0.0.1
"Unlocker" = Unlocker 1.9.0
"ViewpointMediaPlayer" = Viewpoint Media Player (Remove Only)
"Vista Start Menu_is1" = Vista Start Menu 3.67
"VLC media player" = VLC media player 1.1.9
"WhoisAssistant_is1" = WhoisAssistant 1.1
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WinHTTrack Website Copier_is1" = WinHTTrack Website Copier 3.42
"WinLiveSuite_Wave3" = Windows Live Essentials
"Winload Toolbar" = Winload Toolbar
"WinSmile WiZi" = WinSmile WiZi
"XMedia Recode" = XMedia Recode 2.2.1.6
"xp-AntiSpy" = xp-AntiSpy 3.96-8
"Xvid_is1" = Xvid 1.2.2 final uninstall
"XXConsole" = XXConsole: Super Console Generator ver 0.93
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Customizations" = Yahoo! Extras
"Yahoo! Messenger" = Yahoo! Messenger
"Z-defragRAM" = Z-defragRAM
"ZehbeSoft Geburtstagsmahner" = ZehbeSoft Geburtstagsmahner

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 04.01.2008 04:12:11 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522
Description =

Error - 07.04.2008 05:38:54 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522
Description =

Error - 07.04.2008 12:10:14 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522
Description =

Error - 07.11.2008 11:15:47 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522
Description =

Error - 01.01.2009 08:10:18 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522
Description =

Error - 20.01.2009 14:19:47 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522
Description =

Error - 20.01.2009 14:22:01 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522
Description =

Error - 12.11.2009 08:42:31 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522
Description =

Error - 09.03.2010 20:29:41 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522
Description =

Error - 16.08.2010 12:47:32 | Computer Name = Heiner-PC | Source = avast! | ID = 33554522
Description =


========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
lillimucki ist offline   Mit Zitat antworten
Alt 28.04.2011, 22:16   #14 (Direktlink)
War schon mal da
 
Benutzerbild von lillimucki
 
Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
Standard

Und zum Schluß noch "Malwarebytes"
Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: 6464

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

28.04.2011 20:29:50
mbam-log-2011-04-28 (20-28-27).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 413742
Laufzeit: 2 Stunde(n), 47 Minute(n), 36 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 3

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGR AM FILES\COMMON FILES\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> No action taken.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
c:\program files\Rock XP4\rockxp4.exe.part (PUP.PWDump) -> No action taken.
c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> No action taken.
c:\program files\vistawinexit\timerv.exe (Trojan.Agent) -> No action taken.


Puuuh...das wars. Kannst Du damit etwas anfangen?
Liebe Grüße
Heiner (lillimucki zieht hier wohl nicht mehr...)
lillimucki ist offline   Mit Zitat antworten
Alt 30.04.2011, 11:06   #15 (Direktlink)
War schon mal da
 
Benutzerbild von lillimucki
 
Registriert seit: 26.04.2011
Ort: 91619 Obernzenn
Beiträge: 27
Standard

Hallo Leo
jetzt klappt auch die Firewall nicht mehr. Beim Aufruf kommt folgende Mitteilung:



Ein erneuter Suchlauf mit Malwarebytes gab keinen Befund. Als Virenscanner habe ich den Avast Pro.
Liebe Grüße
lillimucki
lillimucki ist offline   Mit Zitat antworten
Werbung

Windows 7 Tipps und Tricks in Bildern

Antwort

  Paules-PC-Forum.de > PC-Sicherheit > Viren-Forum

Lesezeichen

Themen-Optionen
Ansicht

Forumregeln
Es ist Ihnen erlaubt, neue Themen zu verfassen.
Es ist Ihnen erlaubt, auf Beiträge zu antworten.
Es ist Ihnen nicht erlaubt, Anhänge hochzuladen.
Es ist Ihnen nicht erlaubt, Ihre Beiträge zu bearbeiten.

BB-Code ist an.
Smileys sind an.
[IMG] Code ist an.
HTML-Code ist aus.
Trackbacks are an
Pingbacks are an
Refbacks are an


Ähnliche Themen
Thema Autor Forum Antworten Letzter Beitrag
Abgesicherter Modus? AHT Spezielles 3 16.10.2009 11:26
abgesicherter modus vollidiot Windows XP 3 05.02.2009 00:54
Abgesicherter Modus blaurxs Windows XP 2 18.01.2008 12:07
Abgesicherter Modus Jogi Windows XP 3 02.01.2006 17:57
abgesicherter Modus Schnitzelbrot Windows XP 5 15.07.2004 22:16



Alle Zeitangaben in WEZ +2. Es ist jetzt 06:58 Uhr.


Powered by vBulletin® Version 3.8.7 (Deutsch)
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Powered by vBCMS® 2.7.0 ©2002 - 2012 vbdesigns.de
(c) Paules-PC-Forum.de

::: Impressum :::

Search Engine Optimization by vBSEO 3.3.2