Nachtrag!
Ich habe erst in der bebilderten Anleitung von OTL gesehen, dass die LOP- und Purity-Prüfung anzuklicken sind. Hier die Dateien dazu: Code:
OTL logfile created on: 01.01.2013 14:03:49 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\edda\Eigene Dateien\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 1,92 Gb Available Physical Memory | 64,06% Memory free
4,84 Gb Paging File | 3,98 Gb Available in Paging File | 82,21% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Programme
Drive C: | 298,08 Gb Total Space | 183,51 Gb Free Space | 61,56% Space Free | Partition Type: NTFS
Computer Name: BIE | User Name: edda | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Dokumente und Einstellungen\edda\Eigene Dateien\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Programme\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\WINXP\system32\svchospt.exe (FK2)
PRC - C:\WINXP\system32\FsUsbExService.Exe (Teruten)
PRC - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
PRC - C:\Programme\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Programme\Gemeinsame Dateien\Logishrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Programme\FreePDF_XP\fpassist.exe (shbox.de)
PRC - C:\WINXP\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\APC\APC PowerChute Personal Edition\apcsystray.exe (American Power Conversion Corporation)
PRC - C:\Programme\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
========== Modules (No Company Name) ==========
MOD - C:\WINXP\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
MOD - C:\Programme\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINXP\assembly\NativeImages_v2.0.50727_32\System.Web\62e34cfb5a8b233667c7c5a47a32ad93\System.Web.ni.dll ()
MOD - C:\WINXP\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\3c272cad7afb127e2a2bdb8a5a808512\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINXP\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll ()
MOD - C:\WINXP\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINXP\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINXP\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINXP\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINXP\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3195.38441__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3156.17694__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3156.17689__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3156.17698__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3156.17722__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3156.17721__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Foundation\2.0.3156.17682__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3156.17695__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\LOG.Foundation\2.0.3156.17681__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3156.17682__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3156.17747__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\DEM.OS.I0602\2.0.3156.17703__90ba9c70f846762e\DEM.OS.I0602.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3156.17697__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3156.17695__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3156.17689__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\MOM.Foundation\2.0.3156.17699__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\DEM.OS\2.0.3156.17703__90ba9c70f846762e\DEM.OS.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\DEM.Graphics\2.0.3156.17703__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3156.17694__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3156.17695__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\MOM.Implementation\2.0.3195.38593__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3195.38590__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3195.38620__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3156.17689__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3156.17702__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\LOCALIZATION.Foundation.Private\2.0.3156.17686__90ba9c70f846762e\LOCALIZATION.Foundation.Private.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll ()
MOD - C:\WINXP\assembly\GAC\Interop.WBOCXLib\1.0.0.0__90ba9c70f846762e\Interop.WBOCXLib.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\LOCALIZATION.Foundation.Implementation\2.0.3195.38634__90ba9c70f846762e\LOCALIZATION.Foundation.Implementation.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3195.38446__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.3195.38583__90ba9c70f846762e\CLI.Component.Systemtray.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3195.38458__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3195.38438__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3195.38440__90ba9c70f846762e\CLI.Component.SkinFactory.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3156.17698__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3156.17686__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3156.17692__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CCC.Implementation\2.0.3195.38592__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3156.17698__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3156.17702__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\ATIDEMOS\2.0.3195.38439__90ba9c70f846762e\ATIDEMOS.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\AEM.Server\2.0.3195.38435__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\WINXP\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\pdfshell.DEU ()
MOD - C:\WINXP\system32\btwicons.dll ()
MOD - C:\WINXP\system32\CoolXPCombo.ocx ()
MOD - C:\WINXP\system32\CoolXPButton.ocx ()
MOD - C:\WINXP\system32\CoolXPLabel.ocx ()
MOD - C:\WINXP\system32\redmonnt.dll ()
MOD - C:\WINXP\system32\janGraphics.dll ()
========== Services (SafeList) ==========
SRV - (winmgmt) -- C:\DOKUME~1\edda\wgsdgsdgdsgsd.dll File not found
SRV - (JavaQuickStarterService) -- C:\Programme\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (MBAMService) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINXP\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (TuneUp.UtilitiesSvc) -- C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) -- C:\WINXP\system32\uxtuneup.dll (TuneUp Software)
SRV - (FLEXnet Licensing Service) -- C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (FsUsbExService) -- C:\WINXP\system32\FsUsbExService.Exe (Teruten)
SRV - (BcmSqlStartupSvc) -- C:\Programme\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (osppsvc) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (ose) -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (rpcapd) -- C:\Programme\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (LBTServ) -- C:\Programme\Gemeinsame Dateien\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (FirebirdServerMAGIXInstance) -- C:\Programme\Gemeinsame Dateien\MAGIX Services\Database\bin\fbserver.exe (MAGIX®)
SRV - (APC UPS Service) -- C:\Programme\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) -- File not found
DRV - (VDSDK) -- C:\DOKUME~1\edda\LOKALE~1\Temp\vdsdk.sys File not found
DRV - (SetupNTGLM7X) -- D:\NTGLM7X.sys File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (NTACCESS) -- D:\NTACCESS.sys File not found
DRV - (MSICPL) -- D:\install4\MSICPL.sys File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (hwusbfake) -- system32\DRIVERS\ewusbfake.sys File not found
DRV - (hwdatacard) -- system32\DRIVERS\ewusbmdm.sys File not found
DRV - (GMSIPCI) -- D:\INSTALL\GMSIPCI.SYS File not found
DRV - (Changer) -- File not found
DRV - (MBAMProtector) -- C:\WINXP\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (cpuz135) -- C:\Programme\CPUID\PC Wizard 2012\pcwiz_x32.sys (CPUID)
DRV - (ati2mtag) -- C:\WINXP\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (TuneUpUtilitiesDrv) -- C:\Programme\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (ba4037c3) -- C:\WINXP\3275178170 ()
DRV - (LMIRfsClientNP) -- C:\WINXP\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (dgderdrv) -- C:\WINXP\system32\drivers\dgderdrv.sys (Devguru Co., Ltd)
DRV - (FsUsbExDisk) -- C:\WINXP\system32\FsUsbExDisk.Sys ()
DRV - (oreans32) -- C:\WINXP\system32\drivers\oreans32.sys ()
DRV - (ss_mdm) -- C:\WINXP\system32\drivers\ss_mdm.sys (MCCI Corporation)
DRV - (ss_bus) -- C:\WINXP\system32\drivers\ss_bus.sys (MCCI Corporation)
DRV - (ss_mdfl) -- C:\WINXP\system32\drivers\ss_mdfl.sys (MCCI Corporation)
DRV - (LMIRfsDriver) -- C:\WINXP\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) -- C:\Programme\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (NPF) -- C:\WINXP\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (RTL2832U_IRHID) -- C:\WINXP\system32\drivers\RTL2832U_IRHID.sys (Realtek)
DRV - (RTL2832UUSB) -- C:\WINXP\system32\drivers\RTL2832UUSB.sys (REALTEK SEMICONDUCTOR Corp.)
DRV - (RTL2832UBDA) -- C:\WINXP\system32\drivers\RTL2832UBDA.sys (REALTEK SEMICONDUCTOR Corp.)
DRV - (RsFx0103) -- C:\WINXP\system32\drivers\RsFx0103.sys (Microsoft Corporation)
DRV - (tcpipBM) -- C:\WINXP\System32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (BMLoad) -- C:\WINXP\system32\drivers\BMLoad.sys (Bytemobile, Inc.)
DRV - (ZD1211BU(TP-LINK) -- C:\WINXP\system32\drivers\ZD1211BU.sys (Atheros Technology Corporation)
DRV - (BRGSp50) -- C:\WINXP\system32\drivers\BRGSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (ZDPSp50) -- C:\WINXP\system32\drivers\ZDPSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (LMouFilt) -- C:\WINXP\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\WINXP\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LBeepKE) -- C:\WINXP\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (AtiHdmiService) -- C:\WINXP\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (BTKRNL) -- C:\WINXP\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (btaudio) -- C:\WINXP\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTWUSB) -- C:\WINXP\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (btwhid) -- C:\WINXP\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (BTDriver) -- C:\WINXP\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) -- C:\WINXP\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) -- C:\WINXP\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (IntcAzAudAddService) -- C:\WINXP\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) -- C:\WINXP\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Afc) -- C:\WINXP\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (AmdK8) -- C:\WINXP\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (MPE) -- C:\WINXP\system32\drivers\mpe.sys (Microsoft Corporation)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms}
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-507921405-1844823847-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKU\S-1-5-21-507921405-1844823847-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\S-1-5-21-507921405-1844823847-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-507921405-1844823847-682003330-1003\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINXP\system32\ieframe.dll (Microsoft Corporation)
IE - HKU\S-1-5-21-507921405-1844823847-682003330-1003\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-507921405-1844823847-682003330-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-507921405-1844823847-682003330-1003\..\SearchScopes\{34B3644B-28D6-4221-8E36-A52380186490}: "URL" = hxxp://www.google.de/search?q={searchTerms}
IE - HKU\S-1-5-21-507921405-1844823847-682003330-1003\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = hxxp://search.avg.com/route/?d=4b3d2cf0&i=23&tp=chrome&q={searchTerms}&lng={language}&ychte=us&nt=1
IE - HKU\S-1-5-21-507921405-1844823847-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-507921405-1844823847-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google.de"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.fxdirekt.de/de/marktueberblick/news-analysen.html"
FF - prefs.js..extensions.enabledAddons: ffxtlbra%40softonic.com:1.6.0
FF - prefs.js..extensions.enabledAddons: moveplayer%40movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledAddons: sipgateffx%40michael.rotmanov:0.7.4
FF - prefs.js..extensions.enabledAddons: toolbar%40alexa.com:2.17
FF - prefs.js..extensions.enabledAddons: %7B51e18ac0-6522-11da-8cd6-0800200c9a66%7D:0.41
FF - prefs.js..extensions.enabledAddons: %7BE9A4B2C3-9857-4873-BA67-FB4271257B20%7D:1.3.9
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {E9A4B2C3-9857-4873-BA67-FB4271257B20}:1.3.8
FF - prefs.js..extensions.enabledItems: sipgateffx@michael.rotmanov:0.7
FF - prefs.js..extensions.enabledItems: {1acd747e-8470-11db-96a9-00e08161165f}:6.1.2.6
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: toolbar@alexa.com:2.11
FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:7.1.20101113Wb1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: toolbar@web.de:1.5.4
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17
FF - prefs.js..keyword.URL: "hxxp://isearch.avg.com/search?cid=%7B71d1900c-e5bb-4687-94cb-4f730f5296e7%7D&mid=a9c175fca86c2a12b519ccaafc86bf37-06ce4fc639803a2e3563922518183d8e94088cb9&ds=AVG&v=8.0.0.34.1&lang=de&pr=pr&d=2011-09-28%2009%3A12%3A17&sap=ku&q="
FF - prefs.js..network.proxy.type: 4
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINXP\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Programme\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\WINXP\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Programme\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINXP\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Programme\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Programme\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINXP\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2011.11.18 07:48:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\ff-bmboc@bytemobile.com: C:\Programme\3-addons\addon
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Programme\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.07.23 10:39:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Programme\Mozilla Firefox\components [2012.12.08 00:48:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2012.12.20 23:52:19 | 000,000,000 | ---D | M]
[2009.11.26 13:07:02 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Extensions
[2009.06.29 13:26:07 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009.11.26 13:07:02 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Extensions\sz@mast.er
[2012.12.07 13:34:21 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\extensions
[2012.04.16 16:27:42 | 000,000,000 | ---D | M] (Tradesignal Online Chart) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\extensions\{1acd747e-8470-11db-96a9-00e08161165f}
[2010.09.07 08:44:36 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}(2)
[2012.09.27 15:14:50 | 000,000,000 | ---D | M] (softonic.com) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\extensions\ffxtlbra@softonic.com
[2009.07.03 15:23:08 | 000,000,000 | ---D | M] (LogMeIn, Inc. Remote Access Plugin) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\extensions\LogMeInClient@logmein.com
[2010.01.12 23:36:01 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\extensions\moveplayer@movenetworks.com
[2012.09.17 18:38:18 | 000,109,666 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\extensions\sipgateffx@michael.rotmanov.xpi
[2012.10.05 18:38:55 | 000,474,990 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\extensions\toolbar@alexa.com.xpi
[2012.11.16 11:16:13 | 000,566,853 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\extensions\toolbar@web.de.xpi
[2012.04.20 16:48:44 | 000,003,874 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\extensions\{51e18ac0-6522-11da-8cd6-0800200c9a66}.xpi
[2012.09.05 18:11:05 | 001,268,546 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
[2012.12.07 13:34:21 | 000,804,627 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2011.05.08 15:28:18 | 000,038,174 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\extensions\{E9A4B2C3-9857-4873-BA67-FB4271257B20}.xpi
[2011.11.12 19:41:18 | 000,000,933 | ---- | M] () -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\searchplugins\11-suche.xml
[2011.09.28 10:44:16 | 000,003,849 | ---- | M] () -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\searchplugins\avg-secure-search.xml
[2011.11.12 19:41:18 | 000,002,419 | ---- | M] () -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\searchplugins\englische-ergebnisse.xml
[2011.11.12 19:41:18 | 000,010,525 | ---- | M] () -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\searchplugins\gmx-suche.xml
[2012.04.04 07:50:35 | 000,002,101 | ---- | M] () -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\searchplugins\googlede.xml
[2011.11.12 19:41:18 | 000,002,457 | ---- | M] () -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\searchplugins\lastminute.xml
[2012.10.05 18:39:45 | 000,001,492 | ---- | M] () -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\searchplugins\web-search-powered-by-google.xml
[2011.08.15 07:49:54 | 000,005,508 | ---- | M] () -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Mozilla\Firefox\Profiles\a3jq7uvn.default\searchplugins\webde-suche.xml
[2012.12.08 00:48:06 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.12.08 00:48:19 | 000,000,000 | ---D | M] (Default) -- C:\Programme\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2012.12.08 00:48:19 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2008.12.10 12:47:33 | 000,027,976 | ---- | M] (WebEx Communications, Inc) -- C:\Programme\mozilla firefox\plugins\atgpcdec.dll
[2008.12.10 12:47:35 | 000,126,360 | ---- | M] (WebEx Communications, Inc) -- C:\Programme\mozilla firefox\plugins\atgpcext.dll
[2005.04.04 02:45:48 | 000,024,848 | ---- | M] (Citrix Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\cgpcfg.dll
[2005.04.04 02:45:48 | 000,074,000 | ---- | M] () -- C:\Programme\mozilla firefox\plugins\cgpcore.dll
[2005.04.04 02:45:50 | 000,045,328 | ---- | M] (Citrix Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\icalogon.dll
[2008.12.10 12:48:41 | 000,098,712 | ---- | M] (WebEx Communications, Inc) -- C:\Programme\mozilla firefox\plugins\ieatgpc.dll
[2008.08.06 15:22:02 | 000,114,688 | ---- | M] (Adobe Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\np32dsw.dll
[2008.12.10 12:47:28 | 000,060,824 | ---- | M] (WebEx Communications, Inc) -- C:\Programme\mozilla firefox\plugins\npatgpc.dll
[2005.04.04 02:45:50 | 000,315,664 | ---- | M] () -- C:\Programme\mozilla firefox\plugins\npican.dll
[2007.03.22 19:23:30 | 000,017,248 | ---- | M] (Microsoft Corporation) -- C:\Programme\mozilla firefox\plugins\NPOFFICE.DLL
[2012.07.30 22:52:13 | 000,103,904 | ---- | M] (Adobe Systems Inc.) -- C:\Programme\mozilla firefox\plugins\nppdf32.dll
[2006.10.17 09:12:12 | 000,144,872 | ---- | M] (RealNetworks, Inc.) -- C:\Programme\mozilla firefox\plugins\nppl3260.dll
[2009.12.14 18:25:02 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Programme\mozilla firefox\plugins\npqtplugin.dll
[2009.12.14 18:25:02 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Programme\mozilla firefox\plugins\npqtplugin2.dll
[2009.12.14 18:25:02 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Programme\mozilla firefox\plugins\npqtplugin3.dll
[2009.12.14 18:25:02 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Programme\mozilla firefox\plugins\npqtplugin4.dll
[2009.12.14 18:25:02 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Programme\mozilla firefox\plugins\npqtplugin5.dll
[2009.12.14 18:25:02 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Programme\mozilla firefox\plugins\npqtplugin6.dll
[2009.12.14 18:25:02 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Programme\mozilla firefox\plugins\npqtplugin7.dll
[2006.10.17 09:12:19 | 000,024,621 | ---- | M] (RealNetworks, Inc.) -- C:\Programme\mozilla firefox\plugins\nprjplug.dll
[2006.10.17 09:12:08 | 000,081,967 | ---- | M] (RealNetworks, Inc.) -- C:\Programme\mozilla firefox\plugins\nprpjplug.dll
[2005.04.04 02:45:50 | 000,028,944 | ---- | M] (Citrix Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\pscript.dll
[2005.04.04 02:45:52 | 000,069,904 | ---- | M] (Citrix Systems, Inc.) -- C:\Programme\mozilla firefox\plugins\sslsdk_b.dll
[2005.04.04 02:45:52 | 000,024,848 | ---- | M] () -- C:\Programme\mozilla firefox\plugins\tcppserv.dll
[2012.02.12 14:46:38 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.09.13 09:00:15 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.02.12 14:46:38 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2012.09.13 09:00:15 | 000,003,581 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\google.xml
[2012.02.12 14:46:38 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.12 14:46:38 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.12 14:46:38 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Programme\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Programme\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINXP\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Programme\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Programme\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Programme\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Programme\Mozilla Firefox\plugins\np32dsw.dll
CHR - plugin: ActiveTouch General Plugin Container (Enabled) = C:\Programme\Mozilla Firefox\plugins\npatgpc.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Programme\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Programme\Real Alternative\browser\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Programme\Real Alternative\browser\plugins\nprpjplug.dll
CHR - plugin: QuickTime Plug-in 7.6.4 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.4 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.4 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.4 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.4 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.4 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.4 (Enabled) = C:\Programme\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Programme\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programme\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programme\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Programme\Windows Media Player\npdsplay.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Programme\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Programme\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Programme\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Zeon Plus (Enabled) = C:\Programme\Nuance\PDF Reader\bin\nppdf.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Programme\Microsoft Silverlight\5.0.61118.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINXP\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: AT_Porsche = C:\Dokumente und Einstellungen\edda\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg\3_0\
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Dokumente und Einstellungen\edda\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.126_0\
O1 HOSTS File: ([2011.06.04 09:42:51 | 000,000,820 | ---- | M]) - C:\WINXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Programme\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Programme\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-507921405-1844823847-682003330-1003\..\Toolbar\ShellBrowser: (&Adresse) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINXP\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-507921405-1844823847-682003330-1003\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Programme\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-21-507921405-1844823847-682003330-1003\..\Toolbar\WebBrowser: (&Links) - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINXP\system32\ieframe.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [FreePDF Assistant] C:\Programme\FreePDF_XP\fpassist.exe (shbox.de)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINXP\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [svchospt] C:\WINXP\system32\svchospt.exe (FK2)
O4 - HKU\S-1-5-21-507921405-1844823847-682003330-1003..\Run: [ctfmon.exe] C:\WINXP\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-507921405-1844823847-682003330-1003..\Run: [H/PC Connection Agent] C:\Programme\Microsoft ActiveSync\Wcescomm.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-507921405-1844823847-682003330-1003..\Run: [ISUSPM] C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINXP\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - HKU\S-1-5-18..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - HKU\S-1-5-19..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - HKU\S-1-5-20..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\APC UPS Status.lnk = C:\Programme\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)
O4 - Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Logitech SetPoint.lnk = C:\Programme\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Dokumente und Einstellungen\edda\Startmenü\Programme\Autostart\Dropbox.lnk = C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-507921405-1844823847-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: address pick-up: Übernehmen in combit address manager (crm.dbf) - C:\Dokumente und Einstellungen\edda\Lokale Einstellungen\Anwendungsdaten\combit\address pick-up\cmbtar1.htm ()
O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: RF - Formular ausfüllen - C:\Programme\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RF - Formular speichern - C:\Programme\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: RF - Menü anpassen - C:\Programme\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: RF - RoboForm-Leiste ein/aus - C:\Programme\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Senden an &Bluetooth-Gerät... - C:\Programme\ANYCOM\Bluetooth-USB\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Senden an Bluetooth - C:\Programme\ANYCOM\Bluetooth-USB\btsendto_ie.htm ()
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Ausfüllen - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Programme\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : RF - Formular ausfüllen - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Programme\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Speichern - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Programme\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : RF - Formular speichern - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Programme\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Programme\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra 'Tools' menuitem : Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Programme\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Programme\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RF - RoboForm-Leiste ein/aus - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Programme\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ANYCOM\Bluetooth-USB\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\ANYCOM\Bluetooth-USB\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINXP\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINXP\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINXP\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Programme\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Programme\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINXP\system32\mswsock.dll (Microsoft Corporation)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C6A2F315-3237-4204-91CB-450AC729E941}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINXP\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINXP\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINXP\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINXP\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINXP\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINXP\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINXP\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINXP\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINXP\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINXP\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINXP\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINXP\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINXP\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINXP\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINXP\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINXP\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINXP\system32\userinit.exe) - C:\WINXP\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINXP\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINXP\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINXP\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINXP\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - C:\WINXP\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - C:\WINXP\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - C:\WINXP\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - (%SystemRoot%\System32\dimsntfy.dll) - C:\WINXP\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\programme\gemeinsame dateien\logishrd\bluetooth\LBTWlgn.dll) - c:\Programme\Gemeinsame Dateien\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINXP\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - C:\WINXP\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - C:\WINXP\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - C:\WINXP\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - C:\WINXP\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - (wlnotify.dll) - C:\WINXP\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - (WgaLogon.dll) - C:\WINXP\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - C:\WINXP\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINXP\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINXP\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINXP\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINXP\system32\upnpui.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINXP\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINXP\system32\wpdshserviceobj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINXP\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINXP\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\WINXP\Web\Wallpaper\Grüne Idylle.bmp
O24 - Desktop BackupWallPaper: C:\WINXP\Web\Wallpaper\Grüne Idylle.bmp
O27 - HKLM IFEO\isuspm.exe: Debugger - C:\Programme\TuneUp Utilities 2012\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\natspeak.exe: Debugger - C:\Programme\TuneUp Utilities 2012\TUAutoReactivator32.exe (TuneUp Software)
O27 - HKLM IFEO\upgrade.exe: Debugger - C:\Programme\TuneUp Utilities 2012\TUAutoReactivator32.exe (TuneUp Software)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINXP\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINXP\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINXP\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINXP\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINXP\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINXP\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINXP\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINXP\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINXP\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.25 13:19:05 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{0d7878cc-ff7d-11de-9916-001d9262b9ed}\Shell - "" = AutoRun
O33 - MountPoints2\{0d7878cc-ff7d-11de-9916-001d9262b9ed}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0d7878cc-ff7d-11de-9916-001d9262b9ed}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{13453fad-6c8d-11de-98e9-001d9262b9ed}\Shell - "" = AutoRun
O33 - MountPoints2\{13453fad-6c8d-11de-98e9-001d9262b9ed}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{13453fad-6c8d-11de-98e9-001d9262b9ed}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{13453faf-6c8d-11de-98e9-001d9262b9ed}\Shell - "" = AutoRun
O33 - MountPoints2\{13453faf-6c8d-11de-98e9-001d9262b9ed}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{13453faf-6c8d-11de-98e9-001d9262b9ed}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{18c6f092-5828-11df-9947-001d9262b9ed}\Shell - "" = AutoRun
O33 - MountPoints2\{18c6f092-5828-11df-9947-001d9262b9ed}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{18c6f092-5828-11df-9947-001d9262b9ed}\Shell\AutoRun\command - "" = E:\.\Autorun.exe AUTORUN=1
O33 - MountPoints2\{18c6f094-5828-11df-9947-001d9262b9ed}\Shell - "" = AutoRun
O33 - MountPoints2\{18c6f094-5828-11df-9947-001d9262b9ed}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{18c6f094-5828-11df-9947-001d9262b9ed}\Shell\AutoRun\command - "" = G:\.\Autorun.exe AUTORUN=1
O33 - MountPoints2\{18c6f096-5828-11df-9947-001d9262b9ed}\Shell - "" = AutoRun
O33 - MountPoints2\{18c6f096-5828-11df-9947-001d9262b9ed}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{18c6f096-5828-11df-9947-001d9262b9ed}\Shell\AutoRun\command - "" = F:\.\Autorun.exe AUTORUN=1
O33 - MountPoints2\{26eca6b1-6343-11df-9950-001d9262b9ed}\Shell - "" = AutoRun
O33 - MountPoints2\{26eca6b1-6343-11df-9950-001d9262b9ed}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{26eca6b1-6343-11df-9950-001d9262b9ed}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{2e900f64-8eb6-11e0-85f5-000a3a840b52}\Shell - "" = AutoRun
O33 - MountPoints2\{2e900f64-8eb6-11e0-85f5-000a3a840b52}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2e900f64-8eb6-11e0-85f5-000a3a840b52}\Shell\AutoRun\command - "" = E:\.\Autorun.exe AUTORUN=1
O33 - MountPoints2\{5881cc77-5115-11df-9946-001d9262b9ed}\Shell - "" = AutoRun
O33 - MountPoints2\{5881cc77-5115-11df-9946-001d9262b9ed}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5881cc77-5115-11df-9946-001d9262b9ed}\Shell\AutoRun\command - "" = E:\.\Autorun.exe AUTORUN=1
O33 - MountPoints2\{f5ac3a94-6189-11de-98d4-001d9262b9ed}\Shell - "" = AutoRun
O33 - MountPoints2\{f5ac3a94-6189-11de-98d4-001d9262b9ed}\Shell\1\Command - "" = E:\Notepad.exe
O33 - MountPoints2\{f5ac3a94-6189-11de-98d4-001d9262b9ed}\Shell\2\Command - "" = E:\Notepad.exe
O33 - MountPoints2\{f5ac3a94-6189-11de-98d4-001d9262b9ed}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f5ac3a94-6189-11de-98d4-001d9262b9ed}\Shell\AutoRun\command - "" = C:\WINXP\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Notepad.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.01.01 13:36:36 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\edda\Eigene Dateien\Trojaner
[2013.01.01 12:16:26 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\edda\Recent
[2013.01.01 02:42:40 | 000,114,176 | ---- | C] (CPUID) -- C:\WINXP\System32\PCWizard.cpl
[2013.01.01 02:42:40 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\CPUID
[2013.01.01 02:42:39 | 000,000,000 | ---D | C] -- C:\Programme\CPUID
[2012.12.31 11:43:41 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\edda\Eigene Dateien\Dropbox
[2012.12.31 11:39:26 | 000,000,000 | ---D | C] -- C:\Programme\Dropbox
[2012.12.31 11:39:08 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\edda\Startmenü\Programme\Dropbox
[2012.12.31 11:37:59 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Dropbox
[2012.12.26 19:09:30 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Malwarebytes
[2012.12.26 19:09:20 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Malwarebytes' Anti-Malware
[2012.12.26 19:09:20 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
[2012.12.26 19:09:19 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\WINXP\System32\drivers\mbam.sys
[2012.12.26 19:09:19 | 000,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2012.12.20 23:52:38 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\edda\Lokale Einstellungen\Anwendungsdaten\Sun
[2012.12.20 23:52:30 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Java
[2012.12.20 23:52:19 | 000,859,072 | ---- | C] (Oracle Corporation) -- C:\WINXP\System32\npDeployJava1.dll
[2012.12.20 23:52:19 | 000,260,528 | ---- | C] (Oracle Corporation) -- C:\WINXP\System32\javaws.exe
[2012.12.20 23:52:19 | 000,143,872 | ---- | C] (Oracle Corporation) -- C:\WINXP\System32\javacpl.cpl
[2012.12.20 23:52:12 | 000,174,000 | ---- | C] (Oracle Corporation) -- C:\WINXP\System32\javaw.exe
[2012.12.20 23:52:12 | 000,173,992 | ---- | C] (Oracle Corporation) -- C:\WINXP\System32\java.exe
[2012.12.20 23:52:12 | 000,093,640 | ---- | C] (Oracle Corporation) -- C:\WINXP\System32\WindowsAccessBridge.dll
[2012.12.20 18:59:15 | 000,000,000 | ---D | C] -- C:\Programme\Xirrus
[2012.12.20 18:54:37 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\edda\Startmenü\Programme\MetaGeek
[2012.12.20 18:54:36 | 000,000,000 | ---D | C] -- C:\Programme\MetaGeek
[2012.12.08 00:48:05 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox
[3 C:\WINXP\*.tmp files -> C:\WINXP\*.tmp -> ]
[1 C:\WINXP\System32\*.tmp files -> C:\WINXP\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
File not found -- C:\WINXP\System32\
[2013.01.01 14:00:52 | 000,000,473 | ---- | M] () -- C:\WINXP\BRWMARK.INI
[2013.01.01 13:41:15 | 000,000,880 | ---- | M] () -- C:\WINXP\tasks\Adobe Flash Player Updater.job
[2013.01.01 13:32:39 | 000,002,048 | --S- | M] () -- C:\WINXP\bootstat.dat
[2013.01.01 13:32:30 | 3220,557,824 | -HS- | M] () -- C:\hiberfil.sys
[2013.01.01 12:32:34 | 000,000,785 | ---- | M] () -- C:\Dokumente und Einstellungen\edda\Desktop\PC Wizard 2012.lnk
[2013.01.01 02:58:00 | 000,001,086 | ---- | M] () -- C:\WINXP\tasks\GoogleUpdateTaskMachineUA.job
[2012.12.31 23:19:40 | 000,000,654 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\CCleaner.lnk
[2012.12.31 18:49:53 | 000,000,219 | RHS- | M] () -- C:\boot.ini
[2012.12.31 18:41:41 | 000,001,082 | ---- | M] () -- C:\WINXP\tasks\GoogleUpdateTaskMachineCore.job
[2012.12.31 11:49:30 | 000,000,664 | ---- | M] () -- C:\WINXP\System32\d3d9caps.dat
[2012.12.31 11:39:40 | 000,001,031 | ---- | M] () -- C:\Dokumente und Einstellungen\edda\Startmenü\Programme\Autostart\Dropbox.lnk
[2012.12.29 12:03:09 | 000,002,206 | ---- | M] () -- C:\WINXP\System32\wpa.dbl
[2012.12.24 18:29:47 | 000,002,880 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\dsgsdgdsgdsgw.js
[2012.12.20 23:52:04 | 000,093,640 | ---- | M] (Oracle Corporation) -- C:\WINXP\System32\WindowsAccessBridge.dll
[2012.12.20 23:52:03 | 000,260,528 | ---- | M] (Oracle Corporation) -- C:\WINXP\System32\javaws.exe
[2012.12.20 23:52:03 | 000,174,000 | ---- | M] (Oracle Corporation) -- C:\WINXP\System32\javaw.exe
[2012.12.20 23:52:03 | 000,173,992 | ---- | M] (Oracle Corporation) -- C:\WINXP\System32\java.exe
[2012.12.20 23:52:03 | 000,143,872 | ---- | M] (Oracle Corporation) -- C:\WINXP\System32\javacpl.cpl
[2012.12.20 23:52:02 | 000,859,072 | ---- | M] (Oracle Corporation) -- C:\WINXP\System32\npDeployJava1.dll
[2012.12.20 23:52:02 | 000,779,704 | ---- | M] (Oracle Corporation) -- C:\WINXP\System32\deployJava1.dll
[2012.12.14 16:49:28 | 000,021,104 | ---- | M] (Malwarebytes Corporation) -- C:\WINXP\System32\drivers\mbam.sys
[2012.12.12 09:24:39 | 003,234,593 | ---- | M] () -- C:\Dokumente und Einstellungen\edda\Eigene Dateien\Gigaset_C470IP_Bedienungsanleitung.pdf
[2012.12.11 20:41:07 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\WINXP\System32\FlashPlayerApp.exe
[2012.12.11 20:41:07 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\WINXP\System32\FlashPlayerCPLApp.cpl
[2012.12.06 13:30:55 | 000,610,580 | ---- | M] () -- C:\WINXP\System32\perfh007.dat
[2012.12.06 13:30:55 | 000,561,954 | ---- | M] () -- C:\WINXP\System32\perfh009.dat
[2012.12.06 13:30:55 | 000,136,040 | ---- | M] () -- C:\WINXP\System32\perfc007.dat
[2012.12.06 13:30:55 | 000,109,368 | ---- | M] () -- C:\WINXP\System32\perfc009.dat
[3 C:\WINXP\*.tmp files -> C:\WINXP\*.tmp -> ]
[1 C:\WINXP\System32\*.tmp files -> C:\WINXP\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
File not found -- C:\WINXP\System32\
[2013.01.01 02:42:40 | 000,000,785 | ---- | C] () -- C:\Dokumente und Einstellungen\edda\Desktop\PC Wizard 2012.lnk
[2012.12.31 23:19:40 | 000,000,654 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\CCleaner.lnk
[2012.12.31 11:39:39 | 000,001,031 | ---- | C] () -- C:\Dokumente und Einstellungen\edda\Startmenü\Programme\Autostart\Dropbox.lnk
[2012.12.24 18:29:47 | 000,002,880 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\dsgsdgdsgdsgw.js
[2012.12.24 18:29:47 | 000,000,664 | ---- | C] () -- C:\WINXP\System32\d3d9caps.dat
[2012.12.12 09:24:39 | 003,234,593 | ---- | C] () -- C:\Dokumente und Einstellungen\edda\Eigene Dateien\Gigaset_C470IP_Bedienungsanleitung.pdf
[2012.06.17 11:43:10 | 000,567,328 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2012.05.26 17:46:00 | 000,544,256 | ---- | C] () -- C:\WINXP\System32\janGraphics.dll
[2012.05.26 17:46:00 | 000,124,416 | ---- | C] () -- C:\WINXP\System32\dXCtrls.dll
[2011.11.16 00:13:35 | 000,017,408 | ---- | C] () -- C:\Dokumente und Einstellungen\edda\Lokale Einstellungen\Anwendungsdaten\WebpageIcons.db
[2011.11.03 11:40:57 | 000,000,824 | ---- | C] () -- C:\Dokumente und Einstellungen\edda\.recently-used.xbel
[2011.09.27 23:28:49 | 000,000,036 | ---- | C] () -- C:\Dokumente und Einstellungen\edda\Lokale Einstellungen\Anwendungsdaten\housecall.guid.cache
[2011.06.07 10:13:38 | 000,974,848 | ---- | C] () -- C:\WINXP\System32\cis-2.4.dll
[2011.06.07 10:13:38 | 000,081,920 | ---- | C] () -- C:\WINXP\System32\issacapi_bs-2.3.dll
[2011.06.07 10:13:38 | 000,065,536 | ---- | C] () -- C:\WINXP\System32\issacapi_pe-2.3.dll
[2011.06.07 10:13:38 | 000,057,344 | ---- | C] () -- C:\WINXP\System32\issacapi_se-2.3.dll
[2011.06.07 10:13:38 | 000,030,568 | ---- | C] () -- C:\WINXP\MusiccityDownload.exe
[2011.04.21 10:00:33 | 005,224,000 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-S-1-5-21-507921405-1844823847-682003330-1003-0.dat
[2011.04.21 10:00:32 | 000,367,206 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-System.dat
[2011.04.10 15:29:49 | 000,000,087 | ---- | C] () -- C:\WINXP\NavWin.INI
[2011.04.10 15:22:47 | 000,007,680 | ---- | C] () -- C:\WINXP\System32\free_res.exe
[2011.04.10 15:22:46 | 000,118,784 | ---- | C] () -- C:\WINXP\System32\G32_TICK.DLL
[2011.04.10 15:22:46 | 000,081,920 | ---- | C] () -- C:\WINXP\System32\G32_rkey.dll
[2010.09.12 08:33:30 | 000,002,674 | ---- | C] () -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\SAS7_000.DAT
[2010.04.20 18:31:31 | 000,002,528 | ---- | C] () -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\$_hpcst$.hpc
[2010.01.28 16:27:06 | 000,000,071 | ---- | C] () -- C:\Dokumente und Einstellungen\edda\.gtk-bookmarks
[2010.01.27 09:49:58 | 000,000,760 | ---- | C] () -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\setup_ldm.iss
[2009.06.29 11:26:22 | 000,078,848 | ---- | C] () -- C:\Dokumente und Einstellungen\edda\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2009.06.25 13:57:15 | 000,000,227 | RHS- | M] () -- C:\WINXP\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 10:00:00 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINXP\system32\wbem\fastprox.dll -- [2009.02.09 11:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINXP\system32\wbem\wbemess.dll -- [2008.04.14 10:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011.06.03 13:18:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\1stWorks
[2012.08.25 00:22:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AgenaTrader
[2011.10.03 15:30:52 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AVG2012
[2011.09.28 07:34:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\avg9
[2011.03.15 09:55:05 | 000,000,000 | -H-D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Common Files
[2010.09.12 23:00:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Downloaded Installations
[2009.09.08 14:54:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Electronic Arts
[2010.12.19 12:19:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\espionServerData
[2012.01.27 00:47:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\FXCM
[2011.04.12 18:04:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Gibraltar
[2012.08.25 00:22:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\IsolatedStorage
[2011.09.27 23:01:49 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\LogMeIn
[2010.12.07 10:07:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MAGIX
[2011.08.13 22:47:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MetaQuotes
[2011.10.01 00:05:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MFAData
[2010.09.16 07:31:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Nuance
[2009.07.03 18:47:22 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PixelPlanet
[2009.06.29 09:40:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\RoboForm
[2012.06.16 16:57:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Samsung
[2013.01.01 02:13:33 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ScanSoft
[2012.12.31 12:25:09 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
[2011.11.16 09:20:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TuneUp Software
[2010.01.28 15:49:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\VideoMach
[2009.07.02 14:01:45 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\WinZip
[2011.11.16 09:18:49 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2009.07.03 11:05:27 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{55A29068-F2CE-456C-9148-C869879E2357}
[2009.12.14 18:26:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010.12.12 10:58:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\AceBIT
[2012.08.25 00:22:00 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\AgenaTrader
[2011.11.03 10:46:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Audacity
[2011.09.28 08:12:57 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\AVG2012
[2010.08.14 12:58:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\concept design
[2011.04.12 18:21:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\cTrader
[2011.07.23 10:41:02 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\DDMSettings
[2012.01.27 00:51:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\DFXSignals
[2013.01.01 13:33:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Dropbox
[2010.01.18 13:53:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\eDocPrintPro
[2012.12.28 00:19:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\fxgen
[2012.07.31 18:40:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\FxPro-cAlgo
[2012.07.31 12:50:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\FxPro-cTrader
[2012.09.07 07:53:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\FxPro-cTraderCommon
[2012.02.13 08:50:12 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\FxPro-cTraderUsers
[2012.07.31 09:57:46 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\FxPro-xTrader
[2010.09.12 06:28:06 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\GetRightToGo
[2010.10.15 08:26:35 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\GoPal Assistant
[2010.04.18 12:14:44 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\gtk-2.0
[2012.08.25 00:22:26 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\IsolatedStorage
[2010.04.12 14:45:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\jpg-Illuminator
[2010.01.25 13:59:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Leadertech
[2010.12.07 10:07:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\MAGIX
[2012.07.01 14:31:54 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\MetaQuotes
[2009.07.10 15:56:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Michael Sado
[2011.04.08 08:41:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\MYFX
[2011.06.01 14:00:19 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Netviewer
[2010.09.16 07:31:05 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Nuance
[2009.07.06 17:08:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\PC-FAX TX
[2009.07.03 18:47:11 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\PixelPlanet
[2011.04.28 09:11:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Professional
[2010.05.05 10:16:55 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Programme
[2010.08.14 16:44:03 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\S.A.D
[2012.06.16 16:57:27 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Samsung
[2009.07.16 10:14:53 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\ScanSoft
[2011.11.04 15:48:32 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\SlimBrowser
[2011.08.13 11:27:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\SystemSoft
[2009.11.26 13:06:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\SZMaster
[2011.12.16 12:30:03 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\TeamViewer
[2012.06.16 19:06:14 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Temp
[2009.08.14 11:21:40 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\tradesignal
[2011.11.16 09:20:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\TuneUp Software
[2010.02.06 11:37:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\UDC Profiles
[2011.08.21 09:51:13 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\VoipCheapCom
[2012.09.27 15:25:50 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Windows Desktop Search
[2010.11.24 23:49:48 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Windows Search
[2012.07.31 10:07:04 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\xTrader
[2010.09.12 23:01:18 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\edda\Anwendungsdaten\Zeon
[2011.06.13 17:06:29 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\3DataManager
[2010.01.18 13:53:15 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\eDocPrintPro
[2011.11.23 09:24:20 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\LocalService\Anwendungsdaten\TuneUp Software
[2011.06.09 15:28:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\NetworkService\Anwendungsdaten\3DataManager
[2009.07.06 14:34:37 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\NetworkService\Anwendungsdaten\TuneUp Software
========== Purity Check ==========
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINXP\$NtUninstallKB29308$] -> Error: Cannot create file handle -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 236 bytes -> C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:0FF263E8
< End of report > |