Hirnqualle | 15.03.2014 18:33 | also konnte keine Häckchen bei:
Firefox Defaults
Reset IE proxy
System Restore Point
Reset System Restore
Reset Hosts
da diese nicht in den Optionen zu finden war.
zoek-results.txt Code:
Zoek.exe v5.0.0.0 Updated 07-March-2014
Tool run by feuer on 15.03.2014 at 17:32:45,93.
Microsoft Windows XP Home Edition 5.1.2600 Service Pack 3 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Dokumente und Einstellungen\feuer\Eigene Dateien\Downloads\zoek.exe [Scan all users] [Checkboxes used]
==== Older Logs ======================
C:\zoek-results2014-03-15-162648.log 12186 bytes
==== Running Processes ======================
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Programme\Microsoft\BingBar\BBSvc.EXE
C:\Programme\Microsoft\BingBar\SeaPort.EXE
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Programme\Norton Internet Security CBE\Engine\21.1.0.18\NIS.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programme\Google\Update\1.3.22.5\GoogleCrashHandler.exe
C:\Programme\Secunia\PSI\PSIA.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Programme\Virtual CD v9\System\VC9SecS.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Programme\Norton Internet Security CBE\Engine\21.1.0.18\NIS.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Creative\Surround Mixer\CTSysVol.exe
C:\Programme\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe
C:\Programme\DivX\DivX Update\DivXUpdate.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\rmctrl.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programme\Secunia\PSI\psi_tray.exe
C:\Programme\Web Protect\PCProtect.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Programme\Secunia\PSI\sua.exe
C:\Dokumente und Einstellungen\feuer\Eigene Dateien\Downloads\zoek.exe
C:\WINDOWS\system32\msiexec.exe
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Installed Programs ======================
Adiboo und das Geheimnis von Paziral
Adobe Flash Player 12 ActiveX
Adobe Flash Player 12 Plugin
Adobe Reader XI (11.0.06) - Deutsch
Adobe Shockwave Player 12.1
Apple Application Support
AudialsOne
Auslogics Disk Defrag
Auslogics Registry Defrag
AVIVO Codecs
Barbie(tm) Strandurlaub
Bing Bar
Blue Byte Game Channel
Brother MFL-Pro Suite
CCleaner
Compatibility Pack fr 2007 Office System
Creative EAX-Einstellungen
Creative Lautsprechereinstellungen
Creative Software AutoUpdate
Dev-C++ 5 beta 9 release (4.9.9.2)
Die Siedler IV
DivX-Setup
DriveImage XML (Private Edition)
DualCoreCenter
EVGA OC Scanner 1.6.1
EVGA Precision 2.0.1
FaceFilter Studio Brother Edition
Fiesta Online DE 1.04.053
Free Easy Burner V 5.1
Ger„testeuerung
Google Chrome
Google Update Helper
Happy Farm
Hauppauge WinTV Scheduler
Hauppauge WinTV Soft PVR
Hauppauge WinTV Source Selector
Hauppauge WinTV2000
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB976002-v5)
Intel(R) Graphics Media Accelerator Driver
Java Auto Updater
Junk Mail filter update
jv16 PowerTools 2013
KODAK Picture CD
Kodu Game Lab
Langenscheidt Grammatiktrainer 6.0 Englisch
Langenscheidt Kurs 1 6.0 Englisch
Langenscheidt Kurs 2 6.0 Englisch
Langenscheidt Vokabeltrainer 6.0 Englisch
liNear Updater
lingDIALOG
Liveupdate4
Malwarebytes Anti-Malware Version 1.75.0.1300
Meine Tierklinik in Afrika
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile DEU Language Pack
Microsoft .NET Framework 4 Extended
Microsoft .NET Framework 4 Extended DEU Language Pack
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office Live Add-in 1.5
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Word 2002
Microsoft Works 7.0
Microsoft XNA Framework Redistributable 3.1
Microsoft_VC100_CRT_SP1_x86
Minecraft
Minecraft Packages
Mozilla Firefox 27.0.1 (x86 de)
Mozilla Maintenance Service
MSVC80_x86_v2
MSVC90_x86
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB2758694)
MyPhoneExplorer
New PowerCinema
Nokia Connectivity Cable Driver
Nokia Suite
Norton Internet Security CBE
Notepad++
NVIDIA GeForce Experience 1.5
NVIDIA Install Application
NVIDIA nView 140.62
NVIDIA nView Desktop Manager
NVIDIA PhysX-Systemsoftware 9.13.0604
NVIDIA PhysX
NVIDIA Systemsteuerung 320.49
NVIDIA Update 4.11.9
NVIDIA Update Components
Online Manuals for WinTV (German)
Paint.NET v3.5.10
PaperPort Image Printer
Paragon Partition ManagerT 12 Home
PC Connectivity Solution
PixelNet Software 4.12.2
PixiePack Codec Pack
PowerDirector Pro
PowerDVD
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
Revo Uninstaller 1.95
Samsung Kies
SAMSUNG USB Driver for Mobile Phones
ScanSoft PaperPort 11
Secunia PSI (3.0.0.9016)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2861697)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2861188)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2898855v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2901110v2)
Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft .NET Framework 4 Extended (KB2858302v2)
Security Update for Microsoft .NET Framework 4 Extended (KB2901110v2)
Segoe UI
Shotty - Kleines aber eindrucksvolles Screenshot Tool
Sicherheitsupdate fr Windows Internet Explorer 8 (KB2510531)
Sicherheitsupdate fr Windows Internet Explorer 8 (KB2618444)
Sicherheitsupdate fr Windows Internet Explorer 8 (KB2744842)
Sicherheitsupdate fr Windows Internet Explorer 8 (KB2862772)
Sicherheitsupdate fr Windows Internet Explorer 8 (KB2909210)
Sicherheitsupdate fr Windows Internet Explorer 8 (KB2909921)
Sicherheitsupdate fr Windows Internet Explorer 8 (KB2925418)
Sicherheitsupdate fr Windows Internet Explorer 8 (KB982381)
Sicherheitsupdate fr Windows Media Player (KB911564)
Sicherheitsupdate fr Windows XP (KB2916036)
Sicherheitsupdate fr Windows XP (KB2929961)
Sicherheitsupdate fr Windows XP (KB2930275)
Sicherheitsupdate fr Windows XP (KB923789)
SiSoftware Sandra Lite 2011.SP2
Skatpalast Version 1.0
SpeedFan (remove only)
Surround Mixer
swMSM
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3)
Update fr Windows Internet Explorer 8 (KB2598845)
Update fr Windows Internet Explorer 8 (KB2632503)
Update fr Windows XP (KB2808679)
Update fr Windows XP (KB2934207)
Update fr Windows XP (KB961503)
VC80CRTRedist - 8.0.50727.6195
Viega Online-Update
Viptool Assistant 3
Virtual CD v9
VTPlus32 fr WinTV (German)
WebFldrs XP
Windows-Treiberpaket - Nokia pccsmcfd "LegacyDriver" (05/31/2012 7.1.2.0)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live-Uploadtool
Windows Live Anmelde-Assistent
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Fotogalerie
Windows Live Mail
Windows Live Messenger
Windows Live Sync
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Player 11
WinEject
WinRAR 4.20 (32-Bit)
Works Suite-Betriebssystem-Pack
X10 Hardware(TM)
XnView 2.05
==== Deleting Services ======================
==== FireFox Fix ======================
ProfilePath: C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\conkeror.mozdev.org\conkeror\Profiles\nplijwk3.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs__1800_.backup
ProfilePath: C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Mozilla\Firefox\Profiles\qhdllhf9.default-1394709733765
---- Lines buenosearch removed from prefs.js ----
user_pref("extensions.buenosearch.admin", false);
user_pref("extensions.buenosearch.aflt", "babsst");
user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");
user_pref("extensions.buenosearch.autoRvrt", "false");
user_pref("extensions.buenosearch.dfltLng", "en");
user_pref("extensions.buenosearch.excTlbr", false);
user_pref("extensions.buenosearch.ffxUnstlRst", true);
user_pref("extensions.buenosearch.id", "aca8014e000000000000406186fb7153");
user_pref("extensions.buenosearch.instlDay", "16143");
user_pref("extensions.buenosearch.instlRef", "sst");
user_pref("extensions.buenosearch.newTab", false);
user_pref("extensions.buenosearch.prdct", "buenosearch");
user_pref("extensions.buenosearch.prtnrId", "buenosearch");
user_pref("extensions.buenosearch.rvrt", "false");
user_pref("extensions.buenosearch.smplGrp", "none");
user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=ACA8406186FB7153&affID=127690&tsp=5186");
user_pref("extensions.buenosearch.tlbrId", "base");
user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=ACA8406186FB7153&affID=127690&tsp=518
user_pref("extensions.buenosearch.vrsn", "1.8.28.7");
user_pref("extensions.buenosearch.vrsnTs", "1.8.28.714:14:07");
user_pref("extensions.buenosearch.vrsni", "1.8.28.7");
---- Lines buenosearch removed from user.js ----
user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=ACA8406186FB7153&affID=127690&tsp=5186");
user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=ACA8406186FB7153&affID=127690&tsp=5186");
user_pref("extensions.buenosearch.id", "aca8014e000000000000406186fb7153");
user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");
user_pref("extensions.buenosearch.instlDay", "16143");
user_pref("extensions.buenosearch.vrsn", "1.8.28.7");
user_pref("extensions.buenosearch.vrsni", "1.8.28.7");
user_pref("extensions.buenosearch.vrsnTs", "1.8.28.714:14:07");
user_pref("extensions.buenosearch.prtnrId", "buenosearch");
user_pref("extensions.buenosearch.prdct", "buenosearch");
user_pref("extensions.buenosearch.aflt", "babsst");
user_pref("extensions.buenosearch.smplGrp", "none");
user_pref("extensions.buenosearch.tlbrId", "base");
user_pref("extensions.buenosearch.instlRef", "sst");
user_pref("extensions.buenosearch.dfltLng", "en");
user_pref("extensions.buenosearch.excTlbr", false);
user_pref("extensions.buenosearch.ffxUnstlRst", true);
user_pref("extensions.buenosearch.admin", false);
user_pref("extensions.buenosearch.autoRvrt", "false");
user_pref("extensions.buenosearch.rvrt", "false");
user_pref("extensions.buenosearch.newTab", false);
---- FireFox user.js and prefs.js backups ----
user__1800_.backup
prefs__1800_.backup
ProfilePath: C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\Mozilla\Firefox\Profiles\pbu2gtes.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs__1800_.backup
==== Registry Fix Code ======================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\MSN Explorer\shell\open\command]
@="C:\\Programme\\MSN\\MSNCoreFiles\\MSN6.exe"
==== Batch Command(s) Run By Tool======================
Der Winsock-Katalog kann nicht zurckgesetzt werden.
Zugriff verweigert
==== Deleting Files \ Folders ======================
C:\DOKUME~1\ALLUSE~1\ANWEND~1\BetterExperience deleted
C:\Dokumente und Einstellungen\feuer\daemonprocess.txt deleted
C:\Dokumente und Einstellungen\feuer\.android deleted
C:\Programme\Registry Dr deleted
C:\Programme\Flowsurf deleted
C:\Programme\Microsoft Research deleted
C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\BabSolution deleted
C:\DOKUME~1\ALLUSE~1\ANWEND~1\lpm.dat deleted
C:\DOKUME~1\ALLUSE~1\ANWEND~1\Updater deleted
C:\DOKUME~1\ALLUSE~1\ANWEND~1\Babylon deleted
C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Anwendungsdaten\RegistryDR deleted
C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Anwendungsdaten\cache deleted
C:\WINDOWS\tasks\EPUpdater.job deleted
C:\WINDOWS\System32\asycfilt.dll.tmp deleted
C:\WINDOWS\System32\OLD1B22.tmp deleted
C:\WINDOWS\System32\OLD1B25.tmp deleted
C:\WINDOWS\System32\OLD1B28.tmp deleted
C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Mozilla\Firefox\Profiles\qhdllhf9.default-1394709733765\searchplugins\buenosearch.xml deleted
C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Mozilla\Firefox\Profiles\qhdllhf9.default-1394709733765\Invalidprefs.js deleted
"C:\WINDOWS\system32\PCProtect.dll" not deleted
==== System Specs ======================
Windows: Windows XP Home Edition Service Pack 3 (Build 2600)
Memory (RAM): 3072 MB
CPU Info: Intel(R) Celeron(R) CPU E3300 @ 2.50GHz
CPU Speed: 2451,5 MHz
Sound Card: SB 5.1 VX |
Realtek HD Audio output |
Display Adapters: NVIDIA GeForce GT 440 | NetMeeting driver | RDPDD Chained DD
Monitors: 1x; SONY GDM-FW900 |
Screen Resolution: 1280 X 1024 - 32 bit
Network: Network Present
Network Adapters: Realtek PCIe FE Family Controller - Paketplaner-Miniport
CD / DVD Drives: 5x (Q: | R: | X: | Y: | Z: | ) Q: SONY DVD-ROM DDU1612 | R: PHILIPS SPD6003P | X: VXDV DVD-ROM DVDR S90 | Y: VXDV DVD-ROM DVDR S90 | Z: VXDV DVD-RAM DVDR S95
Ports: COM1 | COM2 LPT1
Mouse: 3 Button Wheel Mouse Present
Hard Disks: C: 292,1GB | D: 19,9GB | E: 80,1GB | F: 119,8GB | G: 119,4GB | H: 300,4GB | I: 20,0GB | J: 20,0GB | K: 30,0GB | L: 79,0GB
Hard Disks - Free: C: 138,4GB | D: 19,6GB | E: 68,4GB | F: 112,2GB | G: 113,3GB | H: 287,1GB | I: 19,5GB | J: 16,3GB | K: 8,7GB | L: 79,0GB
Manufacturer *: American Megatrends Inc.
BIOS Info: AT/AT COMPATIBLE | 08/16/32 | 7529MS - 20100419
Time Zone: Westeuropäische Normalzeit
Motherboard *: MICRO-STAR INTERNATIONAL CO.,LTD G31TM-P21 (MS-7529)
Country: Deutschland
Language: DEU
==== System Specs (Software) ======================
Anti-Virus: Norton Internet Security CBE On-access scanning disabled (Updated)
Firewall: Norton Internet Security CBE disabled
Default Browser: Firefox 27.0.1
Internet Explorer version: 8.0.6001.18702
Mozilla Firefox version: 27.0.1 (x86 de)
Google Chrome version: 33.0.1750.154
Adobe Reader version: 11.0.06.70
Sun Java version: 1.7.0_51 (32-bit)
Flash Player version: 12.0.0.77
Shockwave Player version: 12.1r150
==== Files Recently Created / Modified ======================
====== C:\WINDOWS ====
2014-03-07 13:53:48 7A8EF968D9312E63A97DD61C1681A52F 1374 ----a-w- C:\WINDOWS\imsins.BAK
2014-02-23 15:43:55 466F8D601D91DDAB6061A72D85D89353 305664 ----a-w- C:\WINDOWS\IsUn0407.exe
2014-02-16 10:51:09 F042EE4C8D66248D9B86DCF52ABAE416 256000 ----a-w- C:\WINDOWS\PEV.exe
2014-02-16 10:51:09 9E05A9C264C8A908A8E79450FCBFF047 80412 ----a-w- C:\WINDOWS\grep.exe
2014-02-16 10:51:09 5E832F4FAF5F481F2EAF3B3A48F603B8 68096 ----a-w- C:\WINDOWS\zip.exe
2014-02-16 10:51:09 0297C72529807322B152F517FDB0A9FC 406528 ----a-w- C:\WINDOWS\SWSC.exe
2014-02-16 10:51:09 0277C027A26428DB64EF4F64F52BB4FD 208896 ----a-w- C:\WINDOWS\MBR.exe
====== C:\DOKUME~1\feuer\LOKALE~1\Temp ====
2014-03-14 13:13:06 0F430302475B9969528C327864FD2E03 3535504 ----a-w- C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\temp\is1242154493\8705182_stp.EXE
2014-03-14 13:12:35 1FBC33A6613EDD3087C2E65D52C9A719 429834 ----a-w- C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\temp\is1242154493\8704949_stp.EXE
2014-03-08 07:37:02 2E0323A94915FAAB10A25F3BABF82584 157696 ----a-w- C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\temp\jrt\erunt\ERUNT.EXE
====== Java Cache =====
====== C:\WINDOWS\system32 =====
2014-03-14 15:23:08 9B10927CFD0F7AD39E40C0E34005B1AD 877480 ----a-w- C:\WINDOWS\System32\npdeployJava1.dll
2014-03-14 15:23:08 4CC1F431910276174B4BC20E306FE742 800168 ----a-w- C:\WINDOWS\System32\deployJava1.dll
2014-03-07 15:26:20 870D609C55F72FF4A622CD0B6233D886 13312 ------w- C:\WINDOWS\System32\xp_eos.exe
====== C:\WINDOWS\system32\drivers =====
2014-03-07 21:46:58 E0087225B137E57239FF40F8AE82059B 54760 ----a-w- C:\WINDOWS\System32\drivers\fssfltr_tdi.sys
2014-02-18 12:49:21 7BA76ED9C7EF33B4C8C6041CE6C91A6E 15271 ----a-w- C:\WINDOWS\System32\drivers\FIDE.SYS
2014-02-17 17:02:45 4470E3C1E0C3378E4CAB137893C12C3A 22856 ----a-w- C:\WINDOWS\System32\drivers\mbam.sys
====== C:\WINDOWS\Tasks ======
2014-03-07 15:42:11 1E300FAB1D3FB9F9A1EF5C31A24AD4AE 222 ----a-w- C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Benachrichtigung – Anmeldung.job
2014-03-07 15:42:10 53478E05C99C1072661939461AB02DC6 216 ----a-w- C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Monatliche Benachrichtigung.job
2014-03-07 14:49:31 8ABF1F0F764ABB06F1EE5B19E2C0C8D3 1088 ----a-w- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-07 14:49:31 39545306C6EE2D07F66166CBA357E26E 1084 ----a-w- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-16 10:43:06 26DC5570DBE6C6BF71B602355F727632 282 ----a-w- C:\WINDOWS\Tasks\RegistryDr_Popup.job
====== C:\WINDOWS\Temp ======
======= C:\Programme =====
2014-03-14 13:13:27 -------- d-----w- C:\Programme\Minecraft
2014-03-07 21:44:49 -------- d-----w- C:\Programme\Microsoft SQL Server Compact Edition
2014-03-07 21:43:06 -------- d-----w- C:\Programme\Windows Live SkyDrive
2014-03-07 21:42:30 -------- d-----w- C:\Programme\Windows Live
2014-03-07 21:37:36 -------- d-----w- C:\Programme\Gemeinsame Dateien\Windows Live
2014-03-07 15:50:48 -------- d-----w- C:\Programme\Microsoft.NET
2014-03-07 14:23:06 -------- d-----w- C:\Programme\Microsoft Silverlight
2014-02-23 15:46:04 -------- d-----w- C:\Programme\Ubi Soft
2014-02-20 15:21:49 -------- d-----w- C:\Programme\Mozilla Maintenance Service
2014-02-18 13:10:02 -------- d-----w- C:\Programme\Gemeinsame Dateien\Apple
2014-02-18 12:50:40 -------- d-----w- C:\Programme\CyberLink
2014-02-17 11:32:34 -------- d-----w- C:\Programme\Gemeinsame Dateien\Wise Installation Wizard
2014-02-15 00:46:03 -------- d-----w- C:\Programme\Secunia
======= C: =====
2014-02-16 10:52:27 BF868D4249196E408EC3F3A615214161 262448 --sha-r- C:\cmldr
====== C:\Dokumente und Einstellungen\feuer\Anwendungsdaten ======
2014-03-14 13:14:21 -------- d-----w- C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\1H1Q
2014-03-07 13:42:51 -------- d-----w- C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Mozilla
2014-03-01 01:59:25 -------- d-----w- C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Dev-Cpp
2014-02-24 07:23:24 -------- d-----w- C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Anwendungsdaten\Deployment
2014-02-22 23:21:39 -------- d-----w- C:\Dokumente und Einstellungen\Gast\Lokale Einstellungen\Anwendungsdaten\Identities
2014-02-22 08:39:30 -------- d-----w- C:\Dokumente und Einstellungen\Gast\Lokale Einstellungen\Anwendungsdaten\Apple Computer
2014-02-20 16:14:51 -------- d-----w- C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\Windows Search
2014-02-20 07:45:06 -------- d-----w- C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Apple
2014-02-19 08:10:30 -------- d-----w- C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Apple Computer
2014-02-19 01:13:10 -------- d-----w- C:\Dokumente und Einstellungen\Gast\Lokale Einstellungen\Anwendungsdaten\Adobe
2014-02-19 01:04:00 -------- d-----w- C:\Dokumente und Einstellungen\Gast\Lokale Einstellungen\Anwendungsdaten\Apple
2014-02-19 01:00:52 -------- d-----w- C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\Apple Computer
2014-02-18 13:10:53 -------- d-----w- C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Anwendungsdaten\Apple Computer
2014-02-18 13:10:41 -------- d-----w- C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Anwendungsdaten\Apple
2014-02-18 10:10:59 -------- d-----w- C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\Adobe
2014-02-18 10:07:13 -------- d-----w- C:\Dokumente und Einstellungen\Gast\Lokale Einstellungen\Anwendungsdaten\Mozilla
2014-02-18 10:07:13 -------- d-----w- C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\Mozilla
2014-02-18 10:04:19 61FDEC9BBA19DE42673CBE320E8E448A 32456 ----a-w- C:\Dokumente und Einstellungen\Gast\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT
2014-02-18 10:03:58 -------- d-----w- C:\Dokumente und Einstellungen\Gast\Lokale Einstellungen\Anwendungsdaten\Scansoft
2014-02-18 10:03:45 -------- d-----w- C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\Identities
2014-02-18 10:03:03 -------- d-----w- C:\Dokumente und Einstellungen\Gast\Lokale Einstellungen\Anwendungsdaten\Microsoft
2014-02-18 10:03:02 88CF0FF92A4A9FA7BD9B7513B2E9E22B 62 --sha-w- C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\desktop.ini
2014-02-18 10:03:02 -------- d-s---w- C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\Microsoft
2014-02-17 22:14:52 -------- d-----w- C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Anwendungsdaten\Google
2014-02-17 11:40:32 2D9FB319BD41004E5D42CC41EA3CB5E6 44 ----a-w- C:\Dokumente und Einstellungen\NetworkService\Anwendungsdaten\WB.CFG
2014-02-16 11:41:15 -------- d-----w- C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\0D0S1L2Z1P1B
2014-02-15 13:28:23 -------- d-----w- C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\de.rgerlach.skatpalastdesktop
2014-02-15 00:52:09 -------- d-----w- C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\IObit
2014-02-15 00:46:27 -------- d-----w- C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Anwendungsdaten\Secunia PSI
====== C:\Dokumente und Einstellungen\feuer ======
2014-03-07 21:47:52 -------- d-----w- C:\Dokumente und Einstellungen\feuer\Tracing
2014-02-22 06:21:16 -------- d-sh--w- C:\Dokumente und Einstellungen\Gast\IECompatCache
2014-02-22 06:20:18 -------- d-sh--w- C:\Dokumente und Einstellungen\Gast\PrivacIE
2014-02-20 23:53:21 -------- d--h--r- C:\Dokumente und Einstellungen\feuer\Recent
2014-02-20 16:09:30 -------- d-sh--w- C:\Dokumente und Einstellungen\Gast\IETldCache
2014-02-18 10:03:12 -------- d-sh--w- C:\Dokumente und Einstellungen\Gast\Cookies
2014-02-18 10:03:10 -------- d-----r- C:\Dokumente und Einstellungen\Gast\Eigene Dateien
2014-02-18 10:03:03 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Dokumente und Einstellungen\Gast\ntuser.ini
2014-02-18 10:03:02 -------- d--h--w- C:\Dokumente und Einstellungen\Gast\Netzwerkumgebung
2014-02-18 10:03:02 -------- d--h--w- C:\Dokumente und Einstellungen\Gast\Lokale Einstellungen
2014-02-18 10:03:02 -------- d--h--w- C:\Dokumente und Einstellungen\Gast\Druckumgebung
2014-02-18 10:03:02 -------- d--h--r- C:\Dokumente und Einstellungen\Gast\SendTo
2014-02-18 10:03:02 -------- d--h--r- C:\Dokumente und Einstellungen\Gast\Recent
2014-02-18 10:03:02 -------- d--h--r- C:\Dokumente und Einstellungen\Gast\Anwendungsdaten
2014-02-18 10:03:02 -------- d-----w- C:\Dokumente und Einstellungen\Gast\Desktop
2014-02-18 10:03:02 -------- d-----r- C:\Dokumente und Einstellungen\Gast\Favoriten
2014-02-18 10:03:01 -------- d--h--w- C:\Dokumente und Einstellungen\Gast\Vorlagen
2014-02-18 10:03:01 -------- d-----r- C:\Dokumente und Einstellungen\Gast\Startmenü
2014-02-16 10:50:44 -------- d--h--w- C:\Dokumente und Einstellungen\feuer\Druckumgebung
2014-02-15 22:02:32 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Dokumente und Einstellungen\feuer\defogger_reenable
====== C: exe-files ==
2014-03-15 16:54:26 E677174AA15D1B9D9E0B0F1C8DB8CC56 892120 ----a-w- C:\Programme\Google\Update\Install\{A0D535F1-43BB-4B55-9780-9AC238771C28}\33.0.1750.154_33.0.1750.146_chrome_updater.exe
2014-03-15 16:54:25 E677174AA15D1B9D9E0B0F1C8DB8CC56 892120 ----a-w- C:\Programme\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\33.0.1750.154\33.0.1750.154_33.0.1750.146_chrome_updater.exe
2014-03-14 20:23:49 362223D9DFCA99D26E81A21FAC6669BE 3401168 ----a-w- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NVIDIA\Updatus\Packages\000058f8\DAO.18054780.exe
2014-03-14 15:26:14 C4B3C0EA2E75BEF2C57B2316CC08C04A 2562712 ----a-w- C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Anwendungsdaten\Microsoft\DefaultSetup\DefaultSetup.exe
2014-03-14 15:08:48 3842C46F2FBC7522EF625F1833530804 145408 ----a-w- C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Sun\Java\jre1.7.0_51\lzma.exe
2014-03-14 14:11:33 D6A3D61864E8F9565550548865D7522C 921000 ----a-w- C:\Dokumente und Einstellungen\feuer\Eigene Dateien\Downloads\jxpiinstall(1).exe
2014-03-14 14:09:36 4F0E67CA1C2C18C04BFC16F42AB6F29F 108064 ----a-w- C:\Dokumente und Einstellungen\feuer\Eigene Dateien\Downloads\Java(1).exe
2014-03-14 13:14:21 8C7FB9078A63B7E5E899E7A2DBB0DB53 1114624 ----a-w- C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\1H1Q\Minecraft Packages\uninstaller.exe
2014-03-14 13:13:53 11EFC73CB9D61EEAC2D78245E6C33879 2836568 ----a-w- C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Temporary Internet Files\Content.IE5\97QSJ5C2\Setup[1].exe
2014-03-14 13:13:29 C165143E8367C15883EC2A5344499276 56109 ----a-w- C:\Programme\Minecraft\uninstall.exe
2014-03-14 13:13:06 0F430302475B9969528C327864FD2E03 3535504 ----a-w- C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\temp\is1242154493\8705182_stp.EXE
2014-03-14 13:12:35 1FBC33A6613EDD3087C2E65D52C9A719 429834 ----a-w- C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\temp\is1242154493\8704949_stp.EXE
2014-03-14 13:12:18 34F333910B18E5695E2A29DE6D9AD9CD 698800 ----a-w- C:\Dokumente und Einstellungen\feuer\Eigene Dateien\Downloads\MinecraftSetup.exe
2014-03-14 13:02:57 1AF9E2AA8264B023404A76D3FB6751FE 29141928 ----a-w- C:\Dokumente und Einstellungen\feuer\Eigene Dateien\Downloads\jre-7u51-windows-i586.exe
2014-03-13 04:02:33 200400F735A399A6047010CC60C04D94 234872 -c----w- C:\WINDOWS\ie8updates\KB2925418-IE8\spuninst\spuninst.exe
2014-03-13 04:02:26 9690B079450A711BC1942D0E1FD7AC37 174592 -c----w- C:\WINDOWS\ie8updates\KB2925418-IE8\ie4uinit.exe
2014-03-12 20:20:17 BB502CB9D3D32BA92732D9D647077849 3397024 ----a-w- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NVIDIA\Updatus\Packages\000058db\DAO.18035426.exe
2014-03-11 20:18:11 32E61242DC025873CC2B707EE381D3DF 3384328 ----a-w- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\NVIDIA\Updatus\Packages\000058ce\DAO.18033972.exe
2014-03-11 09:40:08 6CECA89123998DB60A3132B017F1C1F5 150728 ----a-w- C:\WINDOWS\system32\Adobe\Director\SWDNLD.EXE
2014-03-11 09:40:08 1F293FA6E463EF940C140CBB6C177679 1308360 ----a-w- C:\WINDOWS\system32\Adobe\Shockwave 12\SwHelper_1210150.exe
2014-03-11 09:19:34 E7D46C0783F43614108668CC445F89D3 118272 ----a-w- C:\WINDOWS\system32\Adobe\Shockwave 12\SwInit.exe
2014-03-11 07:23:48 723005F05394E2E1AB3056A408E719BB 330 ----a-w- C:\WINDOWS\system32\Adobe\Director\M5drvr32.exe
2014-03-10 07:37:12 5DE078679FFBBD993DA0C3B5E41870EB 251628879 ----a-w- C:\Dokumente und Einstellungen\feuer\Eigene Dateien\Downloads\PDR4_Patch_Retail(Deluxe)_v1515a(1).exe
2014-03-10 07:23:24 39ED3A0C1B696AA5816C8189928E76D4 303104 ----a-w- C:\WINDOWS\Temp\PACAA.tmp.DIR\ID_FLIDR1004.exe
2014-03-10 07:23:09 E701FBAAAFE36C9AE2FA1ECC10ED4516 900717 ----a-w- C:\Dokumente und Einstellungen\feuer\Eigene Dateien\Downloads\drw1004im(1).exe
2014-03-10 07:22:28 F9BC0E9B5879C1B5257A9785D78F355A 8770257 ----a-w- C:\Dokumente und Einstellungen\feuer\Eigene Dateien\Downloads\PDVDxp4_Patch_2417(1).exe
2014-03-10 07:22:06 9111148961D244F19BE221EB25779DD6 1013601 ----a-w- C:\Dokumente und Einstellungen\feuer\Eigene Dateien\Downloads\PDVD4_RemoteControl(1).exe
2014-03-10 07:03:11 82ED9BE3A0E185670CDD31903B54B0DF 24793312 ----a-w- C:\Dokumente und Einstellungen\feuer\Eigene Dateien\Downloads\Windows-KB890830-V5.9(1).exe
2014-03-09 18:48:54 03AD32E37F29E4199A3B745F4CA47744 1145856 ----a-w- C:\Dokumente und Einstellungen\feuer\Eigene Dateien\Downloads\FRST.exe
2014-03-09 06:36:36 A7690639D8FC6F297C0406FB8B8D7E21 186880 ----a-w- C:\Dokumente und Einstellungen\feuer\Eigene Dateien\Downloads\LSPFix.exe
=== C: other files ==
2014-03-14 20:47:00 A7BC9D96BEBAECCF98BB2DE4BAECB4C3 287566 ----a-w- C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Mozilla\Firefox\Profiles\qhdllhf9.default-1394709733765\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
2014-03-10 07:23:24 7BA76ED9C7EF33B4C8C6041CE6C91A6E 15271 ----a-w- C:\WINDOWS\Temp\PACAA.tmp.DIR\Fide.sys
======== System Restore Points ========
RP717: 11.02.2014 08:07:16 - Systemprüfpunkt
RP718: 11.02.2014 08:07:16 - Systemprüfpunkt
RP719: 11.02.2014 08:07:16 - Systemprüfpunkt
RP720: 11.02.2014 08:07:15 - Systemprüfpunkt
RP721: 11.02.2014 08:07:15 - Systemprüfpunkt
RP722: 11.02.2014 08:07:15 - Systemprüfpunkt
RP723: 11.02.2014 08:07:15 - Systemprüfpunkt
RP724: 11.02.2014 08:07:15 - Systemprüfpunkt
RP725: 11.02.2014 08:07:15 - Systemprüfpunkt
RP726: 11.02.2014 08:07:14 - Systemprüfpunkt
RP727: 11.02.2014 08:07:14 - Systemprüfpunkt
RP728: 11.02.2014 08:07:14 - Systemprüfpunkt
RP729: 11.02.2014 08:07:14 - Systemprüfpunkt
RP730: 11.02.2014 08:07:14 - Systemprüfpunkt
RP731: 11.02.2014 08:07:14 - Systemprüfpunkt
RP732: 11.02.2014 08:07:14 - Software Distribution Service 3.0
RP733: 11.02.2014 08:07:13 - Systemprüfpunkt
RP734: 11.02.2014 08:07:13 - Systemprüfpunkt
RP735: 11.02.2014 08:07:13 - Systemprüfpunkt
RP736: 11.02.2014 08:07:13 - Systemprüfpunkt
RP737: 11.02.2014 08:07:13 - Systemprüfpunkt
RP738: 11.02.2014 08:07:13 - Systemprüfpunkt
RP739: 11.02.2014 08:07:12 - Systemprüfpunkt
RP740: 11.02.2014 08:07:12 - Systemprüfpunkt
RP741: 11.02.2014 08:07:12 - Systemprüfpunkt
RP742: 11.02.2014 08:07:12 - Systemprüfpunkt
RP743: 11.02.2014 08:07:12 - Systemprüfpunkt
RP744: 11.02.2014 08:07:12 - Systemprüfpunkt
RP745: 11.02.2014 08:07:12 - Systemprüfpunkt
RP746: 11.02.2014 08:07:12 - Installed Microsoft XNA Framework Redistributable 3.1
RP747: 11.02.2014 08:07:11 - Installed Kodu Game Lab
RP748: 11.02.2014 08:07:11 - Installed Windows KB954550-v5.
RP749: 11.02.2014 08:07:11 - Druckertreiber Microsoft XPS Document Writer installiert
RP750: 11.02.2014 08:07:11 - Druckertreiber Microsoft XPS Document Writer installiert
RP751: 11.02.2014 08:07:11 - Installed %1 %2.
RP752: 11.02.2014 08:07:11 - Windows Internet Explorer 8 wurde installiert.
RP753: 11.02.2014 08:07:11 - Software Distribution Service 3.0
RP754: 11.02.2014 08:07:10 - Software Distribution Service 3.0
RP755: 11.02.2014 08:07:10 - Installed Windows KB954550-v5.
RP756: 11.02.2014 08:07:10 - Druckertreiber Microsoft XPS Document Writer installiert
RP757: 11.02.2014 08:07:10 - Druckertreiber Microsoft XPS Document Writer installiert
RP758: 11.02.2014 08:07:10 - Installed %1 %2.
RP759: 11.02.2014 08:07:10 - Systemprüfpunkt
RP760: 11.02.2014 08:07:10 - Systemprüfpunkt
RP761: 11.02.2014 08:07:09 - Systemprüfpunkt
RP762: 11.02.2014 08:07:09 - Systemprüfpunkt
RP763: 11.02.2014 08:07:09 - Systemprüfpunkt
RP764: 11.02.2014 08:07:09 - Systemprüfpunkt
RP765: 11.02.2014 08:07:09 - Systemprüfpunkt
RP766: 11.02.2014 08:07:09 - Systemprüfpunkt
RP767: 11.02.2014 08:07:09 - Systemprüfpunkt
RP768: 11.02.2014 08:07:08 - Systemprüfpunkt
RP769: 11.02.2014 08:07:08 - Software Distribution Service 3.0
RP770: 11.02.2014 08:07:08 - Systemprüfpunkt
RP771: 11.02.2014 08:07:08 - Systemprüfpunkt
RP772: 11.02.2014 08:07:08 - Software Distribution Service 3.0
RP773: 11.02.2014 08:07:08 - Systemprüfpunkt
RP774: 11.02.2014 08:07:08 - Systemprüfpunkt
RP775: 11.02.2014 08:07:08 - Systemprüfpunkt
RP776: 11.02.2014 08:07:07 - Systemprüfpunkt
RP777: 11.02.2014 08:07:07 - Compatibility Pack für 2007 Office System wird installiert
RP778: 11.02.2014 08:07:07 - Software Distribution Service 3.0
RP779: 11.02.2014 08:07:07 - Software Distribution Service 3.0
RP780: 11.02.2014 08:07:07 - Systemprüfpunkt
RP781: 11.02.2014 08:07:07 - Systemprüfpunkt
RP782: 11.02.2014 08:07:07 - Systemprüfpunkt
RP783: 11.02.2014 08:07:07 - Systemprüfpunkt
RP784: 11.02.2014 08:07:06 - Systemprüfpunkt
RP785: 11.02.2014 08:07:06 - Systemprüfpunkt
RP786: 11.02.2014 08:07:06 - Systemprüfpunkt
RP787: 11.02.2014 08:07:06 - Systemprüfpunkt
RP788: 11.02.2014 08:07:06 - Systemprüfpunkt
RP789: 11.02.2014 08:07:06 - Systemprüfpunkt
RP790: 11.02.2014 08:07:06 - Systemprüfpunkt
RP791: 11.02.2014 08:07:05 - Systemprüfpunkt
RP792: 11.02.2014 08:07:05 - Systemprüfpunkt
RP793: 11.02.2014 08:07:05 - Systemprüfpunkt
RP794: 11.02.2014 08:07:05 - Systemprüfpunkt
RP795: 11.02.2014 08:07:05 - Systemprüfpunkt
RP796: 11.02.2014 08:07:05 - Systemprüfpunkt
RP797: 11.02.2014 08:07:05 - Systemprüfpunkt
RP798: 11.02.2014 08:07:05 - Systemprüfpunkt
RP799: 11.02.2014 08:07:04 - Software Distribution Service 3.0
RP800: 11.02.2014 08:07:04 - Software Distribution Service 3.0
RP801: 16.01.2014 10:38:20 - Java 7 Update 51 wird installiert
RP802: 11.02.2014 08:07:04 - Systemprüfpunkt
RP803: 11.02.2014 08:07:04 - Systemprüfpunkt
RP804: 11.02.2014 08:07:04 - Systemprüfpunkt
RP805: 24.01.2014 14:32:03 - Systemprüfpunkt
RP806: 25.01.2014 17:39:20 - Wiederherstellungsvorgang
RP807: 25.01.2014 17:45:31 - Wiederherstellungsvorgang
RP808: 03.02.2014 23:49:30 - Konfiguriert lingDIALOG
RP809: 09.02.2014 23:33:49 - Wiederherstellungsvorgang
RP810: 12.02.2014 00:19:18 - Software Distribution Service 3.0
RP811: 15.02.2014 02:04:52 - Driver Booster : NVIDIA High Definition Audio
RP812: 16.02.2014 12:15:53 - Removed Registry Dr
RP813: 16.02.2014 12:16:33 - Removed Registry Dr
RP814: 16.02.2014 12:17:50 - Removed Registry Dr
RP815: 17.02.2014 12:33:12 - SpyHunter wird installiert
RP816: 17.02.2014 14:58:54 - pc sauber
RP817: 18.02.2014 15:15:58 - Installed MSXML 4.0 SP3 Parser
RP818: 18.02.2014 23:17:04 - Software Distribution Service 3.0
RP819: 19.02.2014 09:11:42 - SpyHunter wird entfernt
RP820: 20.02.2014 15:48:59 - Revo Uninstaller's restore point - Google Chrome
RP821: 20.02.2014 15:54:23 - Revo Uninstaller's restore point - Mozilla Firefox 18.0 (x86 de)
RP822: 20.02.2014 20:25:39 - Microsoft Fix it 50195 wird installiert
RP823: 20.02.2014 20:29:28 - Microsoft Fix it 50195 wird installiert
RP824: 20.02.2014 20:48:45 - Java 7 Update 25 wird entfernt
RP825: 20.02.2014 20:50:59 - Java 7 Update 51 wird installiert
RP826: 21.02.2014 01:22:22 - Microsoft Fix it 50267 wird installiert
RP827: 21.02.2014 01:30:21 - Software Distribution Service 3.0
RP828: 23.02.2014 03:17:07 - Systemprüfpunkt
RP829: 23.02.2014 21:37:40 - Revo Uninstaller's restore point - Mozilla Firefox 27.0.1 (x86 de)
RP830: 23.02.2014 21:51:37 - Revo Uninstaller's restore point - Mozilla Firefox 27.0.1 (x86 de)
RP831: 24.02.2014 08:21:06 - Revo Uninstaller's restore point - Google Chrome
RP832: 24.02.2014 08:31:43 - Revo Uninstaller's restore point - Google Chrome
RP833: 24.02.2014 08:42:12 - Revo Uninstaller's restore point - Google Chrome
RP834: 25.02.2014 17:03:50 - Systemprüfpunkt
RP835: 01.03.2014 04:39:41 - Systemprüfpunkt
RP836: 01.03.2014 09:36:28 - Revo Uninstaller's restore point - 7-Zip 9.20
RP837: 01.03.2014 09:38:46 - Revo Uninstaller's restore point - Apple Software Update
RP838: 01.03.2014 09:39:03 - Apple Software Update wird entfernt
RP839: 01.03.2014 09:43:00 - Revo Uninstaller's restore point - Driver Booster
RP840: 04.03.2014 22:15:58 - Systemprüfpunkt
RP841: 06.03.2014 00:06:41 - Systemprüfpunkt
RP842: 07.03.2014 00:57:30 - Systemprüfpunkt
RP843: 07.03.2014 14:18:21 - Revo Uninstaller's restore point - Mozilla Firefox 27.0.1 (x86 de)
RP844: 07.03.2014 14:49:47 - Revo Uninstaller's restore point - Google Chrome
RP845: 07.03.2014 14:53:37 - Revo Uninstaller's restore point - Windows Internet Explorer 8
RP846: 07.03.2014 15:23:17 - MSN Toolbar wird installiert
RP847: 07.03.2014 15:24:19 - Windows Internet Explorer 8 wurde installiert.
RP848: 07.03.2014 15:24:49 - Software Distribution Service 3.0
RP849: 07.03.2014 15:31:12 - Revo Uninstaller's restore point - Windows Internet Explorer 8
RP850: 07.03.2014 16:09:06 - Windows Internet Explorer 8 wurde installiert.
RP851: 07.03.2014 16:09:45 - Software Distribution Service 3.0
RP852: 07.03.2014 16:26:23 - Software Distribution Service 3.0
RP853: 07.03.2014 16:50:11 - Software Distribution Service 3.0
RP854: 07.03.2014 17:10:23 - Software Distribution Service 3.0
RP855: 07.03.2014 19:08:19 - Software Distribution Service 3.0
RP856: 07.03.2014 20:09:49 - Software Distribution Service 3.0
RP857: 07.03.2014 20:19:52 - Software Distribution Service 3.0
RP858: 07.03.2014 21:07:13 - Software Distribution Service 3.0
RP859: 07.03.2014 22:37:18 - Software Distribution Service 3.0
RP860: 07.03.2014 22:51:42 - Software Distribution Service 3.0
RP861: 07.03.2014 23:37:23 - Software Distribution Service 3.0
RP862: 12.03.2014 19:19:45 - Systemprüfpunkt
RP863: 13.03.2014 05:00:15 - Software Distribution Service 3.0
RP864: 13.03.2014 12:28:52 - Wiederherstellungsvorgang
RP865: 13.03.2014 12:32:26 - Wiederherstellungsvorgang
RP866: 13.03.2014 12:56:47 - Wiederherstellungsvorgang
RP867: 14.03.2014 14:06:02 - Java 7 Update 51 wird installiert
RP868: 14.03.2014 16:11:06 - Java 7 Update 51 wird installiert
RP869: 14.03.2014 16:22:36 - Revo Uninstaller's restore point - Java(TM) 6 Update 33
RP870: 14.03.2014 16:22:59 - Java(TM) 6 Update 33 wird entfernt
RP871: 14.03.2014 16:25:40 - Revo Uninstaller's restore point - Bing-Desktop
RP872: 14.03.2014 16:32:49 - Revo Uninstaller's restore point - Bueno Chrome Toolbar
RP873: 14.03.2014 16:36:19 - Revo Uninstaller's restore point - Mega Browse
RP874: 14.03.2014 16:38:58 - Revo Uninstaller's restore point - MSN Toolbar
RP875: 14.03.2014 16:39:10 - MSN Toolbar wird entfernt
RP876: 14.03.2014 16:41:55 - Revo Uninstaller's restore point - Treiber-Studio 2011 7.0.6.116
RP877: 14.03.2014 16:44:19 - Revo Uninstaller's restore point - QuickTime
RP878: 14.03.2014 16:44:56 - QuickTime wird entfernt
RP879: 15.03.2014 05:00:17 - Software Distribution Service 3.0
RP880: 15.03.2014 17:25:59 - zoek.exe restore point
==== Startup Registry Enabled ======================
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE"
[HKEY_USERS\S-1-5-21-1085031214-790525478-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe"
[HKEY_USERS\S-1-5-21-1085031214-790525478-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE"
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"
"CTSysVol"="C:\Programme\Creative\Surround Mixer\CTSysVol.exe /r"
"Nvtmru"="C:\Programme\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
"SSBkgdUpdate"="C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot"
"Persistence"="C:\WINDOWS\System32\igfxpers.exe"
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe"
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe"
"DelReg"="C:\Programme\MSI\DualCoreCenter\DelReg.exe"
"DivXUpdate"="C:\Programme\DivX\DivX Update\DivXUpdate.exe /CHECKNOW"
"RTHDCPL"="RTHDCPL.EXE"
"RemoteControl"="C:\WINDOWS\system32\rmctrl.exe"
"APSDaemon"="C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe"
"BingDesktop"="C:\Programme\Microsoft\BingDesktop\BingDesktop.exe /fromkey"
"NvCplDaemon"="RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup"
"NvMediaCenter"="RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit"
"KernelFaultCheck"="%systemroot%\system32\dumprep 0 -k"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe"
==== Startup Registry Disabled ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BrMfcWnd]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BrMfcWnd"
"hkey"="HKLM"
"command"="C:\\Programme\\Brother\\Brmfcmon\\BrMfcWnd.exe /AUTORUN"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ControlCenter3]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ControlCenter3"
"hkey"="HKLM"
"command"="C:\\Programme\\Brother\\ControlCenter3\\brctrcen.exe /autorun"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DivXMediaServer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DivXMediaServer"
"hkey"="HKLM"
"command"="C:\\Programme\\DivX\\DivX Media Server\\DivXMediaServer.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IndexSearch.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="IndexSearch.exe"
"hkey"="HKLM"
"command"="\"C:\\Programme\\ScanSoft\\PaperPort\\IndexSearch.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesAirMessage]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="KiesAirMessage"
"hkey"="HKCU"
"command"="J:\\alex\\Kies\\KiesAirMessage.exe -startup"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesPreload]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="KiesPreload"
"hkey"="HKCU"
"command"="J:\\alex\\Kies\\Kies.exe /preload"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesTrayAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="KiesTrayAgent"
"hkey"="HKLM"
"command"="J:\\alex\\Kies\\KiesTrayAgent.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mobilegeni daemon"
"hkey"="HKLM"
"command"="C:\\Programme\\Mobogenie\\DaemonProcess.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NokiaMServer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NokiaMServer"
"hkey"="HKLM"
"command"="C:\\Programme\\Gemeinsame Dateien\\Nokia\\MPlatform\\NokiaMServer /watchfiles startup"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\P17Helper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="P17Helper"
"hkey"="HKLM"
"command"="Rundll32 P17.dll,P17Helper"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PaperPort PTD]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PaperPort PTD"
"hkey"="HKLM"
"command"="\"C:\\Programme\\ScanSoft\\PaperPort\\pptd40nt.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PCMService]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PCMService"
"hkey"="HKLM"
"command"="C:\\Programme\\Medion\\PowerCinema\\PCMService.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PPort11reminder]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PPort11reminder"
"hkey"="HKLM"
"command"="\"C:\\Programme\\ScanSoft\\PaperPort\\Ereg\\Ereg.exe\" -r \"C:\\Dokumente und Einstellungen\\All Users\\Anwendungsdaten\\ScanSoft\\PaperPort\\11\\Config\\Ereg\\Ereg.ini"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="QuickTime Task"
"hkey"="HKLM"
"command"="\"C:\\Programme\\QuickTime\\qttask.exe\" -atboottime"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Updater]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Updater"
"hkey"="HKCU"
"command"="C:\\Dokumente und Einstellungen\\All Users\\Anwendungsdaten\\Updater\\Updater.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\VC9Player]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VC9Player"
"hkey"="HKLM"
"command"="C:\\Programme\\Virtual CD v9\\System\\VC9Play.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinEjectAutoStart1]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WinEjectAutoStart1"
"hkey"="HKCU"
"command"="E:\\Programme\\WinEject\\WinEject.exe -instance:1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmen^Programme^Autostart^DualCoreCenter.lnk]
"item"="DualCoreCenter"
"path"="C:\\Dokumente und Einstellungen\\All Users\\Startmen\\Programme\\Autostart\\DualCoreCenter.lnk"
"backup"="C:\\WINDOWS\\pss\\DualCoreCenter.lnkCommon Startup"
"command"="C:\\PROGRA~1\\MSI\\DUALCO~1\\STARTU~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmen^Programme^Autostart^Microsoft Office.lnk]
"item"="Microsoft Office"
"path"="C:\\Dokumente und Einstellungen\\All Users\\Startmen\\Programme\\Autostart\\Microsoft Office.lnk"
"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
"command"="C:\\PROGRA~1\\MICROS~4\\Office10\\OSA.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmen^Programme^Autostart^Windows Search.lnk]
"item"="Windows Search"
"path"="C:\\Dokumente und Einstellungen\\All Users\\Startmen\\Programme\\Autostart\\Windows Search.lnk"
"backup"="C:\\WINDOWS\\pss\\Windows Search.lnkCommon Startup"
"command"="C:\\PROGRA~1\\WI459E~1\\WINDOW~1.EXE"
==== Startup Folders ======================
==== Task Scheduler Jobs ======================
C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a------ C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [12.03.2014 10:50]
C:\WINDOWS\tasks\Ende des Supports für Microsoft Windows XP – Benachrichtigung – Anmeldung.job [Undetermined Task]
C:\WINDOWS\tasks\Ende des Supports für Microsoft Windows XP – Monatliche Benachrichtigung.job [Undetermined Task]
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Programme\Google\Update\GoogleUpdate.exe [07.03.2014 15:49]
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Programme\Google\Update\GoogleUpdate.exe [07.03.2014 15:49]
C:\WINDOWS\tasks\RegistryDr_Popup.job --a------ C:\Programme\Registry Dr\Splash.exe []
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}"="C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.0.100\coFFPlgn" [15.03.2014 17:33]
==== Firefox Extensions ======================
ProfilePath: C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Mozilla\Firefox\Profiles\qhdllhf9.default-1394709733765
- Greasemonkey - %ProfilePath%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
ProfilePath: C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\Mozilla\Firefox\Profiles\pbu2gtes.default
- Norton Vulnerability Protection - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.0.100\IPSFF
==== Firefox Plugins ======================
Profilepath: C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Mozilla\Firefox\Profiles\qhdllhf9.default-1394709733765
95812430959AE88CDD0301AB3A71913B - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll - Shockwave Flash
0E8B2D0D9E3415A91EF259CE1112C579 - C:\WINDOWS\system32\Adobe\Director\np32dsw_1210150.dll - Shockwave for Director / Shockwave for Director
A9C86900D2A61728C8326FE7147617C5 - C:\Programme\Google\Update\1.3.22.5\npGoogleUpdate3.dll - Google Update
A9191AE22A8F1287B5E2DF33E3A57253 - C:\Programme\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U51
9B10927CFD0F7AD39E40C0E34005B1AD - C:\WINDOWS\system32\npdeployJava1.dll - Java Deployment Toolkit 7.0.510.13
01D93217A9EE48DD37072B671378CC9C - C:\Programme\Microsoft Silverlight\5.1.30214.0\npctrl.dll - Silverlight Plug-In
4380B55D9167DC87793A97329C6C4059 - C:\Programme\DivX\DivX Web Player\npdivx32.dll - DivX Plus Web Player
AC987EE8037531807C5D7E6217A23501 - C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
EB41064BC07017F5694CF16B4DEF6B10 - C:\Programme\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
D6BCD0765A259DB2481C082DDBD86AD7 - C:\Programme\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll - Nokia Suite Enabler Plugin
86244E1B6D062BBE2B91AA5DA7376806 - C:\Programme\DivX\DivX OVS Helper\npovshelper.dll - DivX VOD Helper Plug-in
24E990B1E6D55428001843CF7217DD81 - C:\Programme\Microsoft\Office Live\npOLW.dll - Microsoft Office Live Plug-in for Firefox / Microsoft Office Live Plug-in for Firefox
1C8124B6A03A620EB0CBCA615666D2AE - C:\Programme\Windows Live\Photo Gallery\NPWLPG.dll - Windows Live® Photo Gallery
AB87EEFFD18F2BAAFC274E7075EA6C67 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
38A1E65626558B8776C3546BE4491993 - C:\Programme\Windows Media Player\npdrmv2.dll - Microsoft® DRM
AE3A029E3DC4EEB5EF5A4C2C997F78F8 - C:\Programme\Windows Media Player\npdsplay.dll - Windows Media Player Plug-in Dynamic Link Library
1D187905079ACC40C420E7C8BD167731 - C:\Programme\Windows Media Player\npwmsdrm.dll - Microsoft® DRM
3CB231F12674D3CB0AC1F5EDE9578E85 - C:\WINDOWS\system32\npwmsdrm.dll - Microsoft® Windows Media Services
F630B4A9D9C1AAF6BBABBB41E9BD45B5 - C:\WINDOWS\system32\npptools.dll - Betriebssystem Microsoft® Windows®
28986F0A2342A033345EF9E70D395E4F - C:\Programme\Microsoft Silverlight\5.1.30214.0\npctrlui.dll - Microsoft® Silverlight
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
acfoobbgoakpihljnfedbcfaipcdlfhk - C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\BabSolution\CR\bueno.crx[]
mkfokfffehpeedafpekjeddnmnjhmcmk - C:\Programme\Norton Internet Security CBE\Engine\21.1.0.18\Exts\Chrome.crx[19.01.2014 18:42]
Google Docs - feuer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - feuer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - feuer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - feuer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Norton Identity Protection - feuer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk
Google Wallet - feuer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - feuer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== Chrome Fix ======================
C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Local Storage\chrome-extension_acfoobbgoakpihljnfedbcfaipcdlfhk_0.localstorage deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.msn.com/?pc=BDT1&ocid=BDT1DHP"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.msn.com/?pc=BDT1&ocid=BDT1DHP"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{E00B0CB1-3424-4B69-8D2C-501D7D864CE7}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} Unknown Url="Not_Found"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
{E00B0CB1-3424-4B69-8D2C-501D7D864CE7} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&form=MS8TDF&pc=MS8TDF&src=IE-SearchBox"
==== Reset Google Chrome ======================
C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1085031214-790525478-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully
HKEY_USERS\S-1-5-21-1085031214-790525478-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully
HKEY_USERS\S-1-5-21-1085031214-790525478-725345543-1004\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully
==== shortcuts on Users Desktops ======================
C:\Dokumente und Einstellungen\feuer\Desktop\Adiboo_Paziral starten.lnk - C:\Dokumente und Einstellungen\All Users\Dokumente\Virtual CD v9\Scripts\Adiboo_Paziral starten.vbs
C:\Dokumente und Einstellungen\feuer\Desktop\Audible Manager.lnk - J:\Audible\Bin\Manager.exe
C:\Dokumente und Einstellungen\feuer\Desktop\Auslogics Disk Defrag.lnk - E:\Programme\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe
C:\Dokumente und Einstellungen\feuer\Desktop\Auslogics Registry Defrag.lnk - E:\Programme\Auslogics Registry Defrag\RegistryDefrag.exe
C:\Dokumente und Einstellungen\feuer\Desktop\DivX Movies.lnk - H:\Eigene Videos\DivX Movies
C:\Dokumente und Einstellungen\feuer\Desktop\DivX Player 2.0 Alpha.lnk - C:\Programme\DivX\DivX Player 2.0 Alpha\DivX Player 2.0 Alpha.exe
C:\Dokumente und Einstellungen\feuer\Desktop\EVGA OC Scanner.lnk - C:\Programme\EVGA\EVGA OC Scanner\EVGA_OC_Scanner.exe
C:\Dokumente und Einstellungen\feuer\Desktop\EVGA Precision.lnk - C:\Programme\EVGA Precision\EVGAPrecision.exe
C:\Dokumente und Einstellungen\feuer\Desktop\Fiesta Online DE.lnk - E:\gamigo\Fiesta Online DE\FiestaOnline.exe
C:\Dokumente und Einstellungen\feuer\Desktop\Free Easy Burner.lnk - C:\Programme\Free Easy CD DVD Burner\FreeEasyBurner.exe
C:\Dokumente und Einstellungen\feuer\Desktop\Frontschweine.lnk - C:\Dokumente und Einstellungen\All Users\Dokumente\Virtual CD v9\Scripts\Frontschweine.vbs
C:\Dokumente und Einstellungen\feuer\Desktop\jv16 PowerTools 2013.lnk - C:\Programme\jv16 PowerTools 2013\jv16PT.exe
C:\Dokumente und Einstellungen\feuer\Desktop\Moorhuhn Kart - Thunder spielen.lnk - E:\Programme\phenomedia\Moorhuhn Kart - Thunder\mhk4.exe
C:\Dokumente und Einstellungen\feuer\Desktop\Notepad++.lnk - E:\Programme\Notepad++\notepad++.exe
C:\Dokumente und Einstellungen\feuer\Desktop\Revo Uninstaller.lnk - E:\Programme\VS Revo Group\Revo Uninstaller\Revouninstaller.exe
C:\Dokumente und Einstellungen\feuer\Desktop\Siedler 4 starten.lnk - C:\Dokumente und Einstellungen\All Users\Dokumente\Virtual CD v9\Scripts\Siedler 4 starten.vbs
C:\Dokumente und Einstellungen\feuer\Desktop\Siedler3 starten.lnk - C:\Dokumente und Einstellungen\All Users\Dokumente\Virtual CD v9\Scripts\Siedler3 starten.vbs
C:\Dokumente und Einstellungen\feuer\Desktop\SpeedFan.lnk - C:\Programme\SpeedFan\speedfan.exe
C:\Dokumente und Einstellungen\feuer\Desktop\Ubi Soft Product Registration.lnk - C:\Programme\Ubi Soft\Register\register.exe
C:\Dokumente und Einstellungen\feuer\Desktop\Verknüpfung mit MinecraftSP.lnk -
C:\Dokumente und Einstellungen\feuer\Desktop\XnView.lnk - E:\Programme\XnView\xnview.exe
C:\Dokumente und Einstellungen\Gast\Desktop\Die Siedler 4 Starten.lnk - C:\Dokumente und Einstellungen\All Users\Dokumente\Virtual CD v9\Scripts\Die Siedler 4 Starten.vbs
==== shortcuts on All Users Desktop ======================
C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Digital Editions.lnk - J:\Adobe\Adobe Digital Editions\digitaleditions.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader XI.lnk - C:\Programme\Adobe\Reader 11.0\Reader\AcroRd32.exe
C:\Dokumente und Einstellungen\All Users\Desktop\audials TV.lnk - C:\Programme\RapidSolution\AudialsTV\bin\audialsTV.exe
C:\Dokumente und Einstellungen\All Users\Desktop\AudialsOne 4.lnk - C:\Programme\RapidSolution\AudialsOne 4\AudialsOne.exe
C:\Dokumente und Einstellungen\All Users\Desktop\CCleaner.lnk - C:\Programme\CCleaner\CCleaner.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Configure Kodu Game Lab.lnk - C:\Programme\Microsoft Research\Kodu Game Lab\BokuPreBoot.exe
C:\Dokumente und Einstellungen\All Users\Desktop\DivX Converter.lnk - C:\Programme\DivX\DivX Converter\DivXConverterLauncher.exe
C:\Dokumente und Einstellungen\All Users\Desktop\DivX Player.lnk - C:\Programme\DivX\DivX Player\DivX Player.exe
C:\Dokumente und Einstellungen\All Users\Desktop\DriveImage XML.lnk - C:\Programme\Runtime Software\DriveImage XML\dixml.exe
C:\Dokumente und Einstellungen\All Users\Desktop\FaceFilter Studio.lnk - C:\Programme\Reallusion\FaceFilter Studio\FaceFilterStudio.exe
C:\Dokumente und Einstellungen\All Users\Desktop\GeForce Experience.lnk - C:\Programme\NVIDIA Corporation\NVIDIA GeForce Experience\GFExperience.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Google Chrome.lnk - C:\Programme\Google\Chrome\Application\chrome.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Grammatiktrainer 6.0 Englisch.lnk - E:\Programme\Langenscheidt\Grammatiktrainer 6.0 Englisch\Viewer\Viewer.exe
C:\Dokumente und Einstellungen\All Users\Desktop\KODAK Picture CD.lnk - F:\Programme\Kodak\KODAK Picture CD\PCD\launch1.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Kodu Game Lab.lnk - C:\Programme\Microsoft Research\Kodu Game Lab\Boku.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Kurs 1 6.0 Englisch.lnk - E:\Programme\Langenscheidt\Kurs 1 6.0 Englisch\Viewer\Viewer.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Kurs 2 6.0 Englisch.lnk - E:\Programme\Langenscheidt\Kurs 2 6.0 Englisch\Viewer\Viewer.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk - E:\Programme\Malwarebytes' Anti-Malware\mbam.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Medi@Show.lnk - C:\Programme\Medion\MediaShow\MediaShow.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Minecraft.lnk - C:\Programme\Minecraft\Minecraft.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Mozilla Firefox.lnk - C:\Programme\Mozilla Firefox\firefox.exe
C:\Dokumente und Einstellungen\All Users\Desktop\MyPhoneExplorer.lnk - E:\Programme\MyPhoneExplorer\MyPhoneExplorer.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Nokia Suite.lnk - C:\Programme\Nokia\Nokia Suite\NokiaSuite.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Paint.NET.lnk - C:\Programme\Paint.NET\PaintDotNet.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Paragon Partition Manager™ 12 Home.lnk -
C:\Dokumente und Einstellungen\All Users\Desktop\PixelNet Software.lnk - F:\Programme\PixelNet Software\PixelNet.exe
C:\Dokumente und Einstellungen\All Users\Desktop\PowerCinema.lnk - C:\Programme\Medion\PowerCinema\PCM2.exe
C:\Dokumente und Einstellungen\All Users\Desktop\PowerDirector Pro.lnk - C:\Programme\Medion\PowerDirector\PowerDirector.exe
C:\Dokumente und Einstellungen\All Users\Desktop\PowerDVD.lnk - C:\Programme\Medion\PowerDVD\PowerDVD.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Samsung Kies.lnk - J:\alex\Kies\Kies.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Skatpalast.lnk - E:\Programme\Skatpalast\skatpalast.exe
C:\Dokumente und Einstellungen\All Users\Desktop\VideoLive Mail 4.0.lnk - C:\Programme\Medion\VideoLiveMail\VLM_SKIN_UI.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Virtual CD v9.lnk - C:\Programme\Virtual CD v9\System\vc9start.exe
C:\Dokumente und Einstellungen\All Users\Desktop\Vokabeltrainer 6.0 Englisch.lnk - C:\WINDOWS\Installer\{67F91DB9-1958-4328-869C-032415F04AD1}\_2CDE2A1F231E75E9DE898A.exe
C:\Dokumente und Einstellungen\All Users\Desktop\WinTV2000.lnk - C:\Programme\WinTV\WinTV2K.EXE
C:\Dokumente und Einstellungen\All Users\Desktop\Microsoft\Internet Explorer\Quick Launch\DualCoreCenter.lnk - C:\Programme\MSI\DualCoreCenter\DualCoreCenter.exe
==== shortcuts in Quick Launch ======================
C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Adobe Digital Editions.lnk - J:\Adobe\Adobe Digital Editions\digitaleditions.exe
C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Dev-C++.lnk - E:\Dev-Cpp\devcpp.exe
C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\DriveImage XML.lnk - C:\Programme\Runtime Software\DriveImage XML\dixml.exe
C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\EVGA OC Scanner.lnk - C:\Programme\EVGA\EVGA OC Scanner\EVGA_OC_Scanner.exe
C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Free Easy Burner.lnk - C:\Programme\Free Easy CD DVD Burner\FreeEasyBurner.exe
C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Programme\Google\Chrome\Application\chrome.exe
C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Internet Explorer Browser starten.lnk - C:\Programme\Internet Explorer\iexplore.exe
C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk - C:\Programme\Mozilla Firefox\firefox.exe
C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk - J:\alex\Kies\Kies.exe
C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk - C:\Programme\Windows Media Player\wmplayer.exe /prefetch:1
C:\Dokumente und Einstellungen\feuer\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\XnView.lnk - E:\Programme\XnView\xnview.exe
C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Programme\Google\Chrome\Application\chrome.exe
C:\Dokumente und Einstellungen\Gast\Anwendungsdaten\Microsoft\Internet Explorer\Quick Launch\Internet Explorer Browser starten.lnk - C:\Programme\Internet Explorer\iexplore.exe
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\acfoobbgoakpihljnfedbcfaipcdlfhk deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Updater deleted successfully
==== HijackThis Entries ======================
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://de.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://de.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.msn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <-loopback>
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Programme\Norton Internet Security CBE\Engine\21.1.0.18\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Programme\Norton Internet Security CBE\Engine\21.1.0.18\IPS\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Programme\Norton Internet Security CBE\Engine\21.1.0.18\coIEPlg.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Programme\Creative\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [Nvtmru] "C:\Programme\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DelReg] C:\Programme\MSI\DualCoreCenter\DelReg.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Programme\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [BingDesktop] C:\Programme\Microsoft\BingDesktop\BingDesktop.exe /fromkey
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKUS\S-1-5-21-1085031214-790525478-725345543-1005\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: ubisoft register.lnk = C:\Programme\Ubi Soft\Register\schedule.exe
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Programme\Secunia\PSI\psi_tray.exe
O9 - Extra button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: FlowSurf - {6CA2A4DE-483E-456B-8634-6445460D7097} - C:\Programme\Flowsurf\FlowSurf.dll (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\pcprotect.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\pcprotect.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\pcprotect.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - hxxp://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1304073907390
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1379302733234
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Google Update-Dienst (gupdate) (gupdate) - Google Inc. - C:\Programme\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Programme\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Norton Internet Security CBE (NIS) - Symantec Corporation - C:\Programme\Norton Internet Security CBE\Engine\21.1.0.18\NIS.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PCProtect - Objectify Media Inc - C:\Programme\Web Protect\PCProtect.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Programme\SiSoftware\SiSoftware Sandra Lite 2011.SP2\RpcAgentSrv.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Programme\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Programme\Secunia\PSI\sua.exe
O23 - Service: ServiceLayer - Nokia - C:\Programme\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Virtual CD v9 Management Service (VC9SecS) - H+H Software GmbH - C:\Programme\Virtual CD v9\System\VC9SecS.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
==== Silent Runners ======================
"Silent Runners.vbs", revision 69.2, hxxp://www.silentrunners.org/
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
SetDefaultMIDI = MIDIDef.exe [Creative Technology Ltd]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
Adobe ARM = "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [Adobe Systems Incorporated]
CTSysVol = C:\Programme\Creative\Surround Mixer\CTSysVol.exe /r [Creative Technology Ltd]
Nvtmru = "C:\Programme\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [NVIDIA Corporation]
SSBkgdUpdate = "C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot [Nuance Communications, Inc.]
Persistence = C:\WINDOWS\System32\igfxpers.exe [Intel Corporation]
IgfxTray = C:\WINDOWS\System32\igfxtray.exe [Intel Corporation]
HotKeysCmds = C:\WINDOWS\System32\hkcmd.exe [Intel Corporation]
DelReg = C:\Programme\MSI\DualCoreCenter\DelReg.exe [empty string]
DivXUpdate = "C:\Programme\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [null data]
RTHDCPL = RTHDCPL.EXE [Realtek Semiconductor Corp.]
RemoteControl = C:\WINDOWS\system32\rmctrl.exe [null data]
APSDaemon = "C:\Programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe" [Apple Inc.]
KernelFaultCheck = C:\WINDOWS\system32\dumprep 0 -k
BingDesktop = C:\Programme\Microsoft\BingDesktop\BingDesktop.exe /fromkey [file not found]
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [MS]
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit [MS]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\(Default) = Norton Identity Protection
-> {HKLM...CLSID} = Norton Identity Protection
\InProcServer32\(Default) = C:\Programme\Norton Internet Security CBE\Engine\21.1.0.18\coIEPlg.dll [Symantec Corporation]
{6D53EC84-6AAE-4787-AEEE-F4628F01010C}\(Default) = Norton Vulnerability Protection
-> {HKLM...CLSID} = Norton Vulnerability Protection
\InProcServer32\(Default) = C:\Programme\Norton Internet Security CBE\Engine\21.1.0.18\IPS\IPSBHO.DLL [Symantec Corporation]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
-> {HKLM...CLSID} = Java(tm) Plug-In SSV Helper
\InProcServer32\(Default) = C:\Programme\Java\jre7\bin\ssv.dll [Oracle Corporation]
{9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)
-> {HKLM...CLSID} = Windows Live Anmelde-Hilfsprogramm
\InProcServer32\(Default) = C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [MS]
{DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided)
-> {HKLM...CLSID} = Java(tm) Plug-In 2 SSV Helper
\InProcServer32\(Default) = C:\Programme\Java\jre7\bin\jp2ssv.dll [Oracle Corporation]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
{88895560-9AA2-1069-930E-00AA0030EBC8} = Erweiterung fr HyperTerminal-Icons
-> {HKLM...CLSID} = HyperTerminal Icon Ext
\InProcServer32\(Default) = C:\WINDOWS\System32\hticons.dll [Hilgraeve, Inc.]
{97090E2F-3062-4459-855B-014F0D3CDBB1} = Windows Search Deskbar
-> {HKLM...CLSID} = Windows Search Deskbar
\InProcServer32\(Default) = C:\Programme\Windows Desktop Search\deskbar.dll [MS]
{13E7F612-F261-4391-BEA2-39DF4F3FA311} = Windows Desktop Search
-> {HKLM...CLSID} = Windows Desktop Search
\InProcServer32\(Default) = C:\Programme\Windows Desktop Search\msnlExt.dll [MS]
{A70C977A-BF00-412C-90B7-034C51DA2439} = NvCpl DesktopContext Class
-> {HKLM...CLSID} = DesktopContext Class
\InProcServer32\(Default) = C:\WINDOWS\system32\nvcpl.dll [NVIDIA Corporation]
{42042206-2D85-11D3-8CFF-005004838597} = Microsoft Office HTML Icon Handler
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = C:\Programme\Microsoft Office\Office10\msohev.dll [MS]
{16148659-720A-457d-850B-2DBD87BB129D} = Audible Shlell Extension
-> {HKLM...CLSID} = AudibleShlExt Class
\InProcServer32\(Default) = C:\Programme\Audible\Bin\AudibleExt.dll [Audible, Inc.]
{1CDB2949-8F65-4355-8456-263E7C208A5D} = Desktop Explorer
-> {HKLM...CLSID} = Desktop Explorer
\InProcServer32\(Default) = C:\Programme\NVIDIA Corporation\nview\nvshell.dll [NVIDIA Corporation]
{1E9B04FB-F9E5-4718-997B-B8DA88302A47} = Desktop Explorer Menu
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = C:\Programme\NVIDIA Corporation\nview\nvshell.dll [NVIDIA Corporation]
{1E9B04FB-F9E5-4718-997B-B8DA88302A48} = nView Desktop Context Menu
-> {HKLM...CLSID} = nView Desktop Context Menu
\InProcServer32\(Default) = C:\Programme\NVIDIA Corporation\nview\nvshell.dll [NVIDIA Corporation]
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = WinRAR shell extension
-> {HKLM...CLSID} = WinRAR
\InProcServer32\(Default) = C:\Programme\WinRAR\rarext.dll [Alexander Roshal]
{e57ce731-33e8-4c51-8354-bb4de9d215d1} = Universelle Plug & Play-Ger„te
-> {HKLM...CLSID} = Universelle Plug & Play-Ger„te
\InProcServer32\(Default) = C:\WINDOWS\system32\upnpui.dll [MS]
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} = Microsoft Office Metadata Handler
-> {HKLM...CLSID} = Microsoft Office Metadata Handler
\InProcServer32\(Default) = C:\PROGRA~1\GEMEIN~1\MICROS~1\OFFICE12\msoshext.dll [MS]
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} = Microsoft Office Thumbnail Handler
-> {HKLM...CLSID} = Microsoft Office Thumbnail Handler
\InProcServer32\(Default) = C:\PROGRA~1\GEMEIN~1\MICROS~1\OFFICE12\msoshext.dll [MS]
{40CC864B-947A-4e5d-A2E5-DB6777B55D8F} = DivX MKV file icon extension
-> {HKLM...CLSID} = DivX MKV icon handler Class
\InProcServer32\(Default) = C:\Programme\DivX\DivX Player\DPXIconHandler.dll [null data]
{FFB699E0-306A-11d3-8BD1-00104B6F7516} = Play on my TV helper
-> {HKLM...CLSID} = NVIDIA CPL Extension
\InProcServer32\(Default) = C:\WINDOWS\system32\nvcpl.dll [NVIDIA Corporation]
{0563DB41-F538-4B37-A92D-4659049B7766} = WLMD Message Handler
-> {HKLM...CLSID} = CLSID_WLMCMimeFilter
\InProcServer32\(Default) = C:\Programme\Windows Live\Mail\mailcomm.dll [MS]
{00F33137-EE26-412F-8D71-F84E4C2C6625} = (no title provided)
-> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim
\InProcServer32\(Default) = C:\Programme\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS]
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} = Windows Live Photo Gallery Viewer Drop Target Shim
-> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Shim
\InProcServer32\(Default) = C:\Programme\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS]
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} = Windows Live Photo Gallery Editor Drop Target Shim
-> {HKLM...CLSID} = Windows Live Photo Gallery Editor Shim
\InProcServer32\(Default) = C:\Programme\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS]
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} = Windows Live Photo Gallery Autoplay Drop Target Shim
-> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim
\InProcServer32\(Default) = C:\Programme\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<<!>> {56F9679E-7826-4C84-81F3-532071A8BCC5} = (no title provided)
-> {HKLM...CLSID} = Windows Desktop Search Namespace Manager
\InProcServer32\(Default) = C:\Programme\Windows Desktop Search\MSNLNamespaceMgr.dll [MS]
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> igfxcui\DLLName = igfxdev.dll [Intel Corporation]
HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\
<<!>> livecall\CLSID = {828030A1-22C1-4009-854F-8E305202313F}
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL [MS]
<<!>> msnim\CLSID = {828030A1-22C1-4009-854F-8E305202313F}
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL [MS]
<<!>> wlmailhtml\CLSID = {03C514A3-1EFB-4856-9F99-10D7BE1653C0}
-> {HKLM...CLSID} = Windows Live Mail HTML Asynchronous Pluggable Protocol Handler
\InProcServer32\(Default) = C:\Programme\Windows Live\Mail\mailcomm.dll [MS]
HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
ANotepad++\(Default) = {00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}
-> {HKLM...CLSID} = ANotepad++
\InProcServer32\(Default) = e:\Programme\Notepad++\NppShell_05.dll [null data]
Symantec.Norton.Antivirus.IEContextMenu\(Default) = {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}
-> {HKLM...CLSID} = IEContextMenu Class
\InProcServer32\(Default) = "C:\Programme\Norton Internet Security CBE\Engine\21.1.0.18\NavShExt.dll" [Symantec Corporation]
HKLM\SOFTWARE\Classes\*\shellex\PropertySheetHandlers\
{10670A99-FCCC-415C-8127-176332842618}\(Default) = (no title provided)
-> {HKLM...CLSID} = ExFolderView ActiveX Control
\InProcServer32\(Default) = F:\Programme\PixelNet Software\ExFolderView.dll [Exontrol Inc.]
HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
MBAMShlExt\(Default) = {57CE581A-0CB6-4266-9CA0-19364C90A0B3}
-> {HKLM...CLSID} = MBAMShlExt Class
\InProcServer32\(Default) = e:\Programme\Malwarebytes' Anti-Malware\mbamext.dll [Malwarebytes Corporation]
HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\
00nView\(Default) = {1E9B04FB-F9E5-4718-997B-B8DA88302A48}
-> {HKLM...CLSID} = nView Desktop Context Menu
\InProcServer32\(Default) = C:\Programme\NVIDIA Corporation\nview\nvshell.dll [NVIDIA Corporation]
igfxcui\(Default) = {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4}
-> {HKLM...CLSID} = GraphicsShellExt Class
\InProcServer32\(Default) = C:\WINDOWS\System32\igfxpph.dll [Intel Corporation]
NvCplDesktopContext\(Default) = {A70C977A-BF00-412C-90B7-034C51DA2439}
-> {HKLM...CLSID} = DesktopContext Class
\InProcServer32\(Default) = C:\WINDOWS\system32\nvcpl.dll [NVIDIA Corporation]
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\
{16148659-720A-457d-850B-2DBD87BB129D}\(Default) = Audible Column Ext
-> {HKLM...CLSID} = AudibleShlExt Class
\InProcServer32\(Default) = C:\Programme\Audible\Bin\AudibleExt.dll [Audible, Inc.]
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = PDF Column Info
-> {HKLM...CLSID} = PDF Shell Extension
\InProcServer32\(Default) = C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.dll [Adobe Systems, Inc.]
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
MBAMShlExt\(Default) = {57CE581A-0CB6-4266-9CA0-19364C90A0B3}
-> {HKLM...CLSID} = MBAMShlExt Class
\InProcServer32\(Default) = e:\Programme\Malwarebytes' Anti-Malware\mbamext.dll [Malwarebytes Corporation]
Symantec.Norton.Antivirus.IEContextMenu\(Default) = {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}
-> {HKLM...CLSID} = IEContextMenu Class
\InProcServer32\(Default) = "C:\Programme\Norton Internet Security CBE\Engine\21.1.0.18\NavShExt.dll" [Symantec Corporation]
WinRAR\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}
-> {HKLM...CLSID} = WinRAR
\InProcServer32\(Default) = C:\Programme\WinRAR\rarext.dll [Alexander Roshal]
{BB8DFEF6-E2F6-4167-BD4E-F65D882B740F}\(Default) = (no title provided)
-> {HKLM...CLSID} = VcdImage Class
\InProcServer32\(Default) = C:\Programme\Virtual CD v9\System\vc9extse.dll [H+H Software GmbH]
HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\
WinRAR\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}
-> {HKLM...CLSID} = WinRAR
\InProcServer32\(Default) = C:\Programme\WinRAR\rarext.dll [Alexander Roshal]
Group Policies {GPedit.msc branch and setting}:
-----------------------------------------------
Note: detected settings may not have any effect.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\
NoChangingWallpaper = (REG_DWORD) dword:0x00000000
{User Configuration|Administrative Templates|Control Panel|Display|
Prevent changing wallpaper}
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoRecentDocsHistory = (REG_DWORD) dword:0x00000001
{unrecognized setting}
NoDrives = (REG_DWORD) dword:0x00000000
{unrecognized setting}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoDrives = (REG_DWORD) dword:0x00000000
{unrecognized setting}
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
DisableRegistryTools = (REG_DWORD) dword:0x00000000
{User Configuration|Administrative Templates|System|
Prevent access to registry editing tools}
DisableTaskMgr = (REG_DWORD) dword:0x00000000
{unrecognized setting}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\
DisableRegistryTools = (REG_DWORD) dword:0x00000000
{unrecognized setting}
Active Desktop and Wallpaper:
-----------------------------
Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
Wallpaper = C:\WINDOWS\web\wallpaper\Grne Idylle.bmp
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
Wallpaper = C:\WINDOWS\web\wallpaper\Grne Idylle.bmp
Windows Portable Device AutoPlay Handlers
-----------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\
AudialsUseStorageOnArrival\
Provider = Audials
InvokeProgID = Audials.UseStorage
InvokeVerb = open
HKLM\SOFTWARE\Classes\Audials.UseStorage\shell\open\command\(Default) = C:\Programme\RapidSolution\AudialsOne 4\AudialsOne.exe -use_storage:%1 [RapidSolution Software AG]
FreeEasyBurner\
Provider = FreeEasyBurner
InvokeProgID = FreeEasyBurnerOpen
InvokeVerb = Open
HKLM\SOFTWARE\Classes\FreeEasyBurnerOpen\shell\Open\command\(Default) = C:\Programme\Free Easy CD DVD Burner\FreeEasyBurner.exe [Koyote Soft]
MSLivePhotoAcqHWEventHandler\
Provider = @%ProgramFiles%\Windows Live\Photo Gallery\regres.dll,-10
ProgID = Microsoft.LivePhotoAcqHWEventHandler
HKLM\SOFTWARE\Classes\Microsoft.LivePhotoAcqHWEventHandler\CLSID\(Default) = {3BD0ACD1-71CA-4475-92CC-E0AA0AAF843F}
-> {HKLM...CLSID} = (no title provided)
\LocalServer32\(Default) = C:\Programme\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe [MS]
MSLivePhotoAcquireDropHandler\
Provider = @%ProgramFiles%\Windows Live\Photo Gallery\regres.dll,-10
InvokeProgID = Microsoft.LivePhotoAcqDTShim.1
InvokeVerb = open
HKLM\SOFTWARE\Classes\Microsoft.LivePhotoAcqDTShim.1\shell\open\DropTarget\CLSID = {00F33137-EE26-412F-8D71-F84E4C2C6625}
-> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim
\InProcServer32\(Default) = C:\Programme\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS]
MSLiveShowPicturesOnArrival\
Provider = @%ProgramFiles%\Windows Live\Photo Gallery\regres.dll,-10
InvokeProgID = Microsoft.Photos.LiveAutoplayShim.1
InvokeVerb = open
HKLM\SOFTWARE\Classes\Microsoft.Photos.LiveAutoplayShim.1\shell\open\DropTarget\CLSID = {00F30F90-3E96-453B-AFCD-D71989ECC2C7}
-> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim
\InProcServer32\(Default) = C:\Programme\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS]
MSLiveVideoCameraArrivalCaptureWizard\
Provider = @%ProgramFiles%\Windows Live\Photo Gallery\regres.dll,-10
ProgID = WLXAutoPlayMgr.WLXHWEventHandler
InitCmdLine = WLXVideoAcquireWizard
HKLM\SOFTWARE\Classes\WLXAutoPlayMgr.WLXHWEventHandler\CLSID\(Default) = {9B5C97F6-B3A5-4A6D-8B03-993EC7291A22}
-> {HKLM...CLSID} = WLXWEventHandler Class
\LocalServer32\(Default) = "C:\Programme\Windows Live\Photo Gallery\WLXVideoCameraAutoPlayManager.exe" [MS]
MSWPDShellNamespaceHandler\
Provider = @%SystemRoot%\System32\WPDShextRes.dll,-501
CLSID = {A55803CC-4D53-404c-8557-FD63DBA95D24}
InitCmdLine =
-> {HKLM...CLSID} = WPDShextAutoplay
\LocalServer32\(Default) = C:\WINDOWS\system32\WPDShextAutoplay.exe [MS]
NokiaOviSuite\
Provider = Nokia Suite
ProgID = Nokia.Suite
InitCmdLine = -autoplay
HKLM\SOFTWARE\Classes\Nokia.Suite\CLSID\(Default) = {27F341A3-9735-41a3-AC51-75734826845F}
-> {HKLM...CLSID} = Nokia Suite
\LocalServer32\(Default) = C:/Programme/Nokia/Nokia Suite/NokiaSuite.exe [Nokia]
PaperPort11AutoPlay\
Provider = PaperPort 11
InvokeProgID = PaperPort.AutoplayHandler
InvokeVerb = open
HKLM\SOFTWARE\Classes\PaperPort.AutoplayHandler\shell\open\command\(Default) = C:\Programme\ScanSoft\PaperPort\PaprPort.exe /folder %L [Nuance Communications, Inc.]
PCinemaDCameraArrival\
Provider = PowerCinema
InvokeProgID = Picture
InvokeVerb = PlayWithPowerCinema
HKLM\SOFTWARE\Classes\Picture\shell\PlayWithPowerCinema\Command\(Default) = "C:\Programme\Medion\PowerCinema\PCM2.exe" DSC [empty string]
PCinemaDVArrival\
Provider = PowerCinema
ProgID = Shell.HWEventHandlerShellExecute
InitCmdLine = "C:\Programme\Medion\PowerCinema\PCM2.exe" DV
HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}
-> {HKLM...CLSID} = ShellExecute HW Event Handler
\LocalServer32\(Default) = rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} [MS]
PCinemaPlayCDAudioOnArrival\
Provider = PowerCinema
InvokeProgID = AudioCD
InvokeVerb = PlayWithPowerCinema
HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithPowerCinema\Command\(Default) = "C:\Programme\Medion\PowerCinema\PCM2.exe" CD "%L" [empty string]
PCinemaPlayDVDMovieOnArrival\
Provider = PowerCinema
InvokeProgID = DVD
InvokeVerb = PlayWithPowerCinema
HKLM\SOFTWARE\Classes\DVD\shell\PlayWithPowerCinema\Command\(Default) = "C:\Programme\Medion\PowerCinema\PCM2.exe" MOVIE "%L" [empty string]
PDirDVArrival\
Provider = @C:\Programme\Medion\PowerDirector\PDrt.dll,-901
ProgID = Shell.HWEventHandlerShellExecute
InitCmdLine = C:\Programme\Medion\PowerDirector\PowerDirector.exe /DV
HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}
-> {HKLM...CLSID} = ShellExecute HW Event Handler
\LocalServer32\(Default) = rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} [MS]
PDVDPlayDVDMovieOnArrival\
Provider = PowerDVD
InvokeProgID = DVD
InvokeVerb = PlayWithPowerDVD
HKLM\SOFTWARE\Classes\DVD\shell\PlayWithPowerDVD\Command\(Default) = "C:\Programme\Medion\PowerDVD\PowerDVD.exe" "%l" [CyberLink Corp.]
VirtualCD9BurnCD\
Provider = Virtual CD v9 Brenner
InvokeProgID = VirtualCD.9
InvokeVerb = burn
HKLM\SOFTWARE\Classes\VirtualCD.9\shell\burn\command\(Default) = "C:\Programme\Virtual CD v9\System\vc9burn.exe" %L [H+H Software GmbH]
VirtualCD9CreateVCD\
Provider = Virtual CD v9 Containerassistent
InvokeProgID = VirtualCD.9
InvokeVerb = create
HKLM\SOFTWARE\Classes\VirtualCD.9\shell\create\command\(Default) = "C:\Programme\Virtual CD v9\System\vc9build.exe" %L [H+H Software GmbH]
Startup items in "feuer" & "All Users" startup folders:
-------------------------------------------------------
C:\Dokumente und Einstellungen\feuer\Startmen\Programme\Autostart {++}
ubisoft register -> shortcut to: C:\Programme\Ubi Soft\Register\schedule.exe /19.03.2014 06:58:33 /game=Die Siedler IV Gold+ Edition /language=German /country=Germany /url=hxxp://register-it.ubi.com/register.asp [Ubi Soft]
C:\Dokumente und Einstellungen\All Users\Startmen\Programme\Autostart {++}
Secunia PSI Tray -> shortcut to: C:\Programme\Secunia\PSI\psi_tray.exe [Secunia]
Enabled Scheduled Tasks: {++}
------------------------
Adobe Flash Player Updater -> launches: C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [Adobe Systems Incorporated]
Ende des Supports fr Microsoft Windows XP - Benachrichtigung - Anmeldung -> launches: C:\WINDOWS\system32\xp_eos.exe -c [MS]
Ende des Supports fr Microsoft Windows XP - Monatliche Benachrichtigung -> launches: C:\WINDOWS\system32\xp_eos.exe [MS]
GoogleUpdateTaskMachineCore -> launches: C:\Programme\Google\Update\GoogleUpdate.exe /c [Google Inc.]
GoogleUpdateTaskMachineUA -> launches: C:\Programme\Google\Update\GoogleUpdate.exe /ua /installsource scheduler [Google Inc.]
RegistryDr_Popup -> launches: C:\Programme\Registry Dr\Splash.exe true [file not found]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS]
000000000002\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS]
000000000003\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS]
000000000004\LibraryPath = C:\WINDOWS\system32\pnrpnsp.dll [MS]
000000000005\LibraryPath = C:\WINDOWS\system32\pnrpnsp.dll [MS]
000000000006\LibraryPath = %SystemRoot%\System32\nwprovau.dll [MS]
Transport Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
C:\WINDOWS\system32\PCProtect.dll [Objectify Media Inc], 01 - 02, 36
%SystemRoot%\system32\mswsock.dll [MS], 03 - 05, 08 - 35
%SystemRoot%\system32\rsvpsp.dll [MS], 06 - 07
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} = Norton Toolbar
-> {HKLM...CLSID} = Norton Toolbar
\InProcServer32\(Default) = C:\Programme\Norton Internet Security CBE\Engine\21.1.0.18\coIEPlg.dll [Symantec Corporation]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
{219C3416-8CB2-491A-A3C7-D9FCDDC9D600}\
ButtonText = In Blog ver”ffentlichen
MenuText = In Windows Live Writer in Blog ver”ffentliche&n
CLSIDExtension = {5F7B1267-94A9-47F5-98DB-E99415F33AEC}
-> {HKLM...CLSID} = BlogThisToolbarButton Class
\InProcServer32\(Default) = C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll [MS]
{6CA2A4DE-483E-456B-8634-6445460D7097}\
ButtonText = FlowSurf
CLSIDExtension = {6CA2A4DE-483E-456B-8634-6445460D7097}
-> {HKLM...CLSID} = HelloWorldToolbar Class
\InProcServer32\(Default) = C:\Programme\Flowsurf\FlowSurf.dll [file not found]
{E2E2DD38-D088-4134-82B7-F2BA38496583}\
MenuText = @xpsp3res.dll,-20001
Exec = %windir%\Network Diagnostic\xpnetdiag.exe [MS]
{FB5F1910-F110-11D2-BB9E-00C04F795683}\
ButtonText = Messenger
MenuText = Windows Messenger
Exec = C:\Programme\Messenger\msmsgs.exe [MS]
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
BBUpdate, BBUpdate, C:\Programme\Microsoft\BingBar\SeaPort.EXE [MS]
Einfache TCP/IP-Dienste, SimpTcp, C:\WINDOWS\System32\tcpsvcs.exe [MS]
IPv6-Hilfsdienst, 6to4, C:\WINDOWS\system32\svchost.exe -k netsvcs {C:\WINDOWS\System32\6to4svc.dll [MS]}
Norton Internet Security CBE, NIS, "C:\Programme\Norton Internet Security CBE\Engine\21.1.0.18\NIS.exe" /s "NIS" /m "C:\Programme\Norton Internet Security CBE\Engine\21.1.0.18\diMaster.dll" /prefetch:1 [Symantec Corporation]
NVIDIA Driver Helper Service, NVSvc, C:\WINDOWS\system32\nvsvc32.exe [NVIDIA Corporation]
NVIDIA Update Service Daemon, nvUpdatusService, "C:\Programme\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe" [NVIDIA Corporation]
PCProtect, PCProtect, C:\Programme\Web Protect\PCProtect.exe [Objectify Media Inc]
RIP-šberwachung, Iprip, C:\WINDOWS\System32\svchost.exe -k netsvcs {C:\WINDOWS\System32\iprip.dll [MS]}
Secunia PSI Agent, Secunia PSI Agent, C:\Programme\Secunia\PSI\PSIA.exe --start-service [Secunia]
Secunia Update Agent, Secunia Update Agent, C:\Programme\Secunia\PSI\sua.exe --start-service [Secunia]
Virtual CD v9 Management Service, VC9SecS, C:\Programme\Virtual CD v9\System\VC9SecS.exe [H+H Software GmbH]
Windows Search, WSearch, C:\WINDOWS\system32\SearchIndexer.exe /Embedding [MS]
Safe Mode Drivers & Services (subkey name, subkey default value):
-----------------------------------------------------------------
HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\
<<!>> pcwatch.sys, Driver
<<!>> PEVSystemStart, Service
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\
<<!>> PCProtect, service
<<!>> pcwatch.sys, Driver
<<!>> PEVSystemStart, Service
==== Empty IE Cache ======================
C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
C:\Dokumente und Einstellungen\Gast\Lokale Einstellungen\temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
C:\Dokumente und Einstellungen\Gast\Lokale Einstellungen\Temporary Internet Files\Content.IE5 emptied successfully
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5 emptied successfully
C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Dokumente und Einstellungen\UpdatusUser\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\qhdllhf9.default-1394709733765\Cache emptied successfully
C:\Dokumente und Einstellungen\Gast\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\pbu2gtes.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=1873 folders=116 298141634 bytes)
==== Empty Temp Folders ======================
C:\Dokumente und Einstellungen\Default User\Lokale Einstellungen\temp emptied successfully
C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\temp will be emptied at reboot
C:\Dokumente und Einstellungen\Gast\Lokale Einstellungen\temp emptied successfully
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temp emptied successfully
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\temp emptied successfully
C:\Dokumente und Einstellungen\UpdatusUser\Lokale Einstellungen\temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\WINDOWS\Temp successfully emptied
C:\DOKUME~1\feuer\LOKALE~1\Temp successfully emptied
==== Deleting Files / Folders ======================
"C:\WINDOWS\system32\PCProtect.dll" not deleted
"C:\Dokumente und Einstellungen\feuer\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Dokumente und Einstellungen\UpdatusUser\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat" not deleted
==== EOF on 15.03.2014 at 18:19:43,32 ====================== |