Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Windows VISTA aus sicherheisgründen gesperrt (https://www.trojaner-board.de/108003-windows-vista-sicherheisgruenden-gesperrt.html)

cklemm 12.01.2012 17:49

Windows VISTA aus sicherheisgründen gesperrt
 
Hallo,

Heute ist bei mir ein Problem aufgetreten dass antscheinend einige andere auch haben:
Es öffnet sich ein nicht zu schließendes Fenster mit einer zahlaufforderung da sonst Daten verloren gehen. Über mein tablet (damit schreibe ich auch hier, daher leider einige Tippfehler) hab ich dann mal gegooglt und raus gefunden dass das wohl eine betrugsmasche ist. Ich hatte mich auch schon gewundert weil ich heute mittag erst meinen Computer unter www.dns-ok.de getestet habe und raus kam das alles Ok ist.
Nach einem PC neustart ging mein Computer kurz, und ich wollte avira durchlaufen lassen, aber bevor was kam, kam die Meldung wieder und ich musste den PC wieder abschießen.

Ich Post das hier neu, weil in einem anderen Thema geschrieben wurde das zu dem Thema jeder neu Posten soll.

Hoffe mir kann einer helfen, Gruß und Danke.

markusg 12.01.2012 18:12

hi,
pc neustarten, f8 drücken, abgesicherter modus mit netzwerk wählen.
Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
explorer.exe
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs
CREATERESTOREPOINT

  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Kopiere
    nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread

cklemm 12.01.2012 18:41

So habe ein weilchen gebraucht. Da waren jetzt 2 textfelder. Otl.txt und extras.txt:


otl.txt
OTL Logfile:
Code:

OTL logfile created on: 12.01.2012 18:31:58 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Christian\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,18 Gb Available Physical Memory | 72,68% Memory free
6,19 Gb Paging File | 5,61 Gb Available in Paging File | 90,58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287,45 Gb Total Space | 91,52 Gb Free Space | 31,84% Space Free | Partition Type: NTFS
Drive D: | 10,64 Gb Total Space | 1,79 Gb Free Space | 16,84% Space Free | Partition Type: NTFS
 
Computer Name: CHRISTIAN-PC | User Name: Christian | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Christian\Desktop\OTL(1).exe (OldTimer Tools)
PRC - C:\Programme\C2D06\lvvm.exe ()
PRC - C:\Programme\LP\A776\38B.exe ()
PRC - C:\Users\Christian\AppData\Roaming\606C2\B00A7.exe ()
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Windows\HelpPane.exe (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Programme\C2D06\lvvm.exe ()
MOD - C:\Programme\LP\A776\38B.exe ()
MOD - C:\Users\Christian\AppData\Roaming\606C2\B00A7.exe ()
MOD - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f}\components\RadioWMPCoreGecko8.dll ()
MOD - C:\Programme\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (Akamai) -- c:\program files\common files\akamai/netsession_win_b427739.dll ()
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (ICQ Service) -- C:\Programme\ICQ6Toolbar\ICQ Service.exe ()
SRV - (npggsvc) -- C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (TVCapSvc) TV Background Capture Service (TVBCS) -- C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
SRV - (TVSched) TV Task Scheduler (TVTS) -- C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
SRV - (AESTFilters) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c92065b9\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (STacSV) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c92065b9\stacsv.exe (IDT, Inc.)
SRV - (Recovery Service for Windows) -- C:\Programme\SMINST\BLService.exe ()
SRV - (ezSharedSvc) -- C:\Windows\System32\ezsvc7.dll (EasyBits Sofware AS)
SRV - (dlcf_device) -- C:\Windows\System32\dlcfcoms.exe ( )
SRV - (FirebirdServerMAGIXInstance) -- C:\Programme\MAGIX\Common\Database\bin\fbserver.exe (MAGIX®)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (truecrypt) -- C:\Windows\System32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (TKFsFt) -- C:\Windows\System32\TKFsFt2k.sys (Copyright (C) INCA Internet. 2000-2009)
DRV - (TKFsAv) -- C:\Windows\System32\TKFsAv2k.sys (Copyright (C) INCA Internet. 2000-2009)
DRV - (mfesmfk) -- C:\Windows\System32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (hwusbdev) -- C:\Windows\System32\drivers\ewusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (mferkdk) -- C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (hwdatacard) -- C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (TKRgFt) -- C:\Windows\System32\TKRgFtXp.sys (Copyright (C) INCA Internet. 2000-2009)
DRV - (TKRgAc) -- C:\Windows\System32\TKRgAc2k.sys (Copyright (C) INCA Internet. 2000-2009)
DRV - (TKFsAc) -- C:\Windows\System32\TKFsAc2k.sys (Copyright (C) INCA Internet. 2000-2009)
DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (STHDA) -- C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (JMCR) -- C:\Windows\System32\drivers\jmcr.sys (JMicron Technology Corporation)
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) -- C:\Programme\Hewlett-Packard\Media\DVD\000.fcl (CyberLink Corp.)
DRV - (tcpipBM) -- C:\Windows\System32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (enecir) -- C:\Windows\System32\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV - (usbfilter) -- C:\Windows\System32\drivers\usbfilter.sys (Advanced Micro Devices Inc.)
DRV - (AtiPcie) ATI PCI Express (3GIO) -- C:\Windows\system32\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV - (hpdskflt) -- C:\Windows\system32\DRIVERS\hpdskflt.sys (Hewlett-Packard Corporation)
DRV - (Accelerometer) -- C:\Windows\System32\drivers\Accelerometer.sys (Hewlett-Packard Corporation)
DRV - (NETw3v32) Intel(R) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (SLEE_16_DRIVER) -- C:\Windows\System32\drivers\sleen16.sys (Softwareentwicklung Remus - ArchiCrypt )
DRV - (HpqKbFiltr) -- C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (NPPTNT2) -- C:\Windows\System32\npptNT2.sys (INCA Internet Co., Ltd.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\tbWin1.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKLM\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Programme\P2P_Max_DE\tbP2P_.dll (Conduit Ltd.)
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\tbWin1.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Programme\P2P_Max_DE\tbP2P_.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:52667
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "InnoGames Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.1&q="
FF - prefs.js..browser.search.order.1: "Ask"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.5
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.0.0.10
FF - prefs.js..extensions.enabledItems: youtube2mp3@mondayx.de:1.0.7
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:5.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:3.3.3.2
FF - prefs.js..extensions.enabledItems: finder@meingutscheincode.de:2.0
FF - prefs.js..extensions.enabledItems: {40c3cc16-7269-4b32-9531-17f2950fb06f}:3.3.3.2
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2
FF - prefs.js..extensions.enabledItems: {c7478d43-2bd5-4844-98b8-c2a6aa9ed677}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {2458abc0-f443-11dd-87af-0800200c9a66}:3.6.3.1.03.04.10
FF - prefs.js..extensions.enabledItems: nasanightlaunch@example.com:0.6.20110508
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.3&q="
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player:  File not found
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012.01.12 11:34:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.13 09:49:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.01 13:28:30 | 000,000,000 | ---D | M]
 
[2009.08.17 18:20:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\mozilla\Extensions
[2009.08.17 18:20:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org
[2012.01.10 14:10:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions
[2011.12.06 18:35:52 | 000,000,000 | ---D | M] (Winload Community Toolbar) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f}
[2012.01.10 14:10:05 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.09.30 19:18:51 | 000,000,000 | ---D | M] (Tamper Data) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2011.09.29 19:08:54 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.12.25 12:19:52 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.01.10 14:10:19 | 000,000,000 | ---D | M] (InnoGames Community Toolbar) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{c7478d43-2bd5-4844-98b8-c2a6aa9ed677}
[2012.01.10 14:10:33 | 000,000,000 | ---D | M] (softonic-de3 Community Toolbar) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}
[2009.08.17 18:19:52 | 000,000,000 | ---D | M] (P2P Max DE Toolbar) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{e0007d18-baa4-4573-ae78-8bea0958c610}
[2010.03.12 17:35:45 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011.11.12 14:29:03 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011.04.30 09:50:58 | 000,000,000 | ---D | M] (Multirow Bookmarks Toolbar) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2011.11.05 17:58:42 | 000,000,000 | ---D | M] ("bug489729") -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\bug489729@alice0775
[2011.03.30 16:38:52 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\engine@conduit.com
[2009.06.06 19:24:15 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\moveplayer@movenetworks.com
[2011.12.03 18:02:20 | 000,000,000 | ---D | M] (Download Youtube Videos +) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\video.downloader.plugin@ffpimp.com
[2009.06.07 14:11:53 | 000,000,681 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\ask.xml
[2010.12.30 17:22:44 | 000,000,921 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\conduit.xml
[2012.01.08 11:12:19 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-1.xml
[2011.07.03 16:21:08 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-2.xml
[2011.08.22 14:37:54 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-3.xml
[2011.08.31 17:18:15 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-4.xml
[2011.09.01 20:28:01 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-5.xml
[2011.09.08 10:04:22 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-6.xml
[2011.11.06 14:48:47 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-7.xml
[2011.11.13 09:50:47 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-8.xml
[2012.01.04 14:54:58 | 000,000,168 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin.gif
[2012.01.04 14:54:58 | 000,000,618 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin.src
[2010.06.21 16:35:24 | 000,001,042 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin.xml
[2011.07.19 10:00:58 | 000,002,227 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\s-amazon-de.xml
[2009.07.10 21:34:09 | 000,003,915 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\sweetim.xml
[2011.11.13 09:50:03 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.07.03 16:20:20 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011.08.24 23:42:36 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TRJ1LSEZ.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}.XPI
() (No name found) -- C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TRJ1LSEZ.DEFAULT\EXTENSIONS\FINDER@MEINGUTSCHEINCODE.DE.XPI
() (No name found) -- C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TRJ1LSEZ.DEFAULT\EXTENSIONS\YOUTUBE2MP3@MONDAYX.DE.XPI
[2011.11.13 09:49:42 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.07.19 04:05:25 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007.07.25 09:51:06 | 000,164,352 | ---- | M] (Indiepath Ltd) -- C:\Program Files\mozilla firefox\plugins\npigl.dll
[2011.11.06 14:37:30 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.11.06 14:37:30 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.11.06 14:37:30 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.11.06 14:37:30 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.25 10:11:54 | 000,002,027 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2011.11.06 14:37:30 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.11.06 14:37:30 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: igLoader (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npigl.dll
CHR - plugin: getPlusPlus for Adobe 16263 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: SiteAdvisor = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\
 
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
O2 - BHO: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\tbWin1.dll (Conduit Ltd.)
O2 - BHO: (AOL Toolbar BHO) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.)
O2 - BHO: (P2P Max DE Toolbar) - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Programme\P2P_Max_DE\tbP2P_.dll (Conduit Ltd.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
O3 - HKLM\..\Toolbar: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\tbWin1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (P2P Max DE Toolbar) - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Programme\P2P_Max_DE\tbP2P_.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (TextAloud) - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\Programme\TextAloud\TAForIE.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (P2P Max DE Toolbar) - {E0007D18-BAA4-4573-AE78-8BEA0958C610} - C:\Programme\P2P_Max_DE\tbP2P_.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [38B.exe] C:\Programme\LP\A776\38B.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DataCardMonitor] C:\Programme\T-Mobile\T-Mobile Internet Manager\DataCardMonitor.exe (Huawei Technologies Co., Ltd.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [DVDAgent] C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Programme\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [SmartMenu] C:\Programme\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SweetIM] C:\Programme\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TSMAgent] C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TVAgent] C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [38B.exe] C:\Users\Christian\AppData\Roaming\Microsoft\A776\38B.exe ()
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Christian\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [Firefox helper] C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\firefox.exe ()
O4 - HKCU..\Run: [HW_OPENEYE_OUC_T-Mobile Internet Manager] C:\Program Files\T-Mobile\T-Mobile Internet Manager\UpdateDog\ouc.exe (Huawei Technologies Co., Ltd.)
O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background File not found
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Programme\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
F3 - HKCU WinNT: Load - (C:\Users\Christian\AppData\Roaming\C2D06\lvvm.exe) -C:\Users\Christian\AppData\Roaming\C2D06\lvvm.exe ()
O8 - Extra context menu item: &AOL Toolbar-Suche - C:\ProgramData\AOL\ieToolbar\resources\de-DE\local\search.html ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Read By Natural Voice Reader - C:\Programme\Natural Voice Reader Standard\read.html ()
O9 - Extra Button: Natural Reader - {0DF757C4-9999-463C-A4EB-B6BF1D8D8D3D} - C:\Programme\Natural Voice Reader Standard\read.html ()
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: fritz.repeater ([]* in Lokales Intranet)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Lokales Intranet)
O15 - HKCU\..Trusted Ranges: Range2 ([*] in Lokales Intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0DD7E30D-49C5-4558-B73D-BC68CA74671E}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2EE10678-3EEE-404C-AC60-95CDBE17AB4B}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Users\Christian\AppData\Roaming\606C2\B00A7.exe) -C:\Users\Christian\AppData\Roaming\606C2\B00A7.exe ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{57cb71e9-bc65-11e0-b757-00238bb00a77}\Shell - "" = AutoRun
O33 - MountPoints2\{57cb71e9-bc65-11e0-b757-00238bb00a77}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{57cb7201-bc65-11e0-b757-00238bb00a77}\Shell - "" = AutoRun
O33 - MountPoints2\{57cb7201-bc65-11e0-b757-00238bb00a77}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{e320eb30-3088-11e1-8904-00238bb00a77}\Shell - "" = AutoRun
O33 - MountPoints2\{e320eb30-3088-11e1-8904-00238bb00a77}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{f6458d7b-3cac-11de-b779-00238bb00a77}\Shell - "" = AutoRun
O33 - MountPoints2\{f6458d7b-3cac-11de-b779-00238bb00a77}\Shell\AutoRun\command - "" = F:\LaunchU3.exe
O33 - MountPoints2\{fc2cf70e-2141-11df-910f-00238bb00a77}\Shell - "" = AutoRun
O33 - MountPoints2\{fc2cf70e-2141-11df-910f-00238bb00a77}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.01.12 18:28:08 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Christian\Desktop\OTL(1).exe
[2012.01.12 18:17:08 | 000,000,000 | ---D | C] -- C:\Program Files\C2D06
[2012.01.12 16:48:53 | 000,000,000 | ---D | C] -- C:\Program Files\LP
[2012.01.12 16:45:24 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Roaming\C2D06
[2012.01.12 16:44:53 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Roaming\606C2
[2012.01.11 16:24:44 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciseq.dll
[2012.01.11 16:24:41 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll
[2012.01.11 16:24:37 | 000,376,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2012.01.11 16:24:32 | 001,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2012.01.11 16:24:32 | 000,497,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2011.12.24 19:18:05 | 000,000,000 | ---D | C] -- C:\Users\Christian\Musik
[2011.12.22 22:16:25 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Steam
[2011.12.22 22:16:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2011.12.22 22:16:21 | 000,000,000 | ---D | C] -- C:\Program Files\Steam
[2011.12.22 21:59:43 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Local\Ubisoft Game Launcher
[2011.12.22 21:47:18 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll
[2011.12.22 21:47:17 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_43.dll
[2011.12.22 21:47:17 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll
[2011.12.22 21:47:17 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll
[2011.12.22 21:47:17 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll
[2011.12.22 21:47:17 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll
[2011.12.22 21:47:17 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll
[2011.12.22 21:47:17 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll
[2011.12.22 21:47:16 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_6.dll
[2011.12.22 21:47:16 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2011.12.22 21:47:16 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_6.dll
[2011.12.22 21:47:16 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_4.dll
[2011.12.22 21:47:16 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_7.dll
[2011.12.22 21:47:15 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2011.12.22 21:47:14 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2011.12.22 21:47:14 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2011.12.22 21:47:14 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2011.12.22 21:47:14 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2011.12.22 21:47:13 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_41.dll
[2011.12.22 21:47:13 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2011.12.22 21:47:13 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_41.dll
[2011.12.22 21:47:13 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_4.dll
[2011.12.22 21:47:13 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_41.dll
[2011.12.22 21:47:13 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2011.12.22 21:47:12 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_40.dll
[2011.12.22 21:47:12 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_40.dll
[2011.12.22 21:47:12 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2011.12.22 21:47:12 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2011.12.22 21:47:12 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_4.dll
[2011.12.22 21:47:12 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2011.12.22 21:47:12 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_6.dll
[2011.12.22 21:47:11 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll
[2011.12.22 21:47:11 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll
[2011.12.22 21:47:11 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll
[2011.12.22 21:47:11 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll
[2011.12.22 21:47:11 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2011.12.22 21:47:11 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll
[2011.12.22 21:47:11 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2011.12.22 21:47:10 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll
[2011.12.22 21:47:10 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_38.dll
[2011.12.22 21:47:10 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_1.dll
[2011.12.22 21:47:10 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_38.dll
[2011.12.22 21:47:10 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_1.dll
[2011.12.22 21:47:10 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_0.dll
[2011.12.22 21:47:10 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_4.dll
[2011.12.22 21:47:08 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_38.dll
[2011.12.22 21:47:08 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_0.dll
[2011.12.22 21:47:07 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_37.dll
[2011.12.22 21:47:07 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_37.dll
[2011.12.22 21:47:07 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_37.dll
[2011.12.22 21:47:07 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_10.dll
[2011.12.22 21:47:07 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_0.dll
[2011.12.22 21:47:07 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_3.dll
[2011.12.22 21:47:06 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_36.dll
[2011.12.22 21:47:06 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_36.dll
[2011.12.22 21:47:05 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_36.dll
[2011.12.22 21:47:05 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_9.dll
[2011.12.22 21:47:04 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_35.dll
[2011.12.22 21:47:04 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_35.dll
[2011.12.22 21:47:04 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_35.dll
[2011.12.22 21:47:03 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_8.dll
[2011.12.22 21:47:03 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_2.dll
[2011.12.22 21:47:02 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_34.dll
[2011.12.22 21:47:02 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_34.dll
[2011.12.22 21:47:02 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_34.dll
[2011.12.22 21:47:02 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_3.dll
[2011.12.22 21:47:01 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_33.dll
[2011.12.22 21:47:01 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_33.dll
[2011.12.22 21:47:01 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_7.dll
[2011.12.22 21:47:00 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_33.dll
[2011.12.22 21:47:00 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_6.dll
[2011.12.22 21:46:59 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10.dll
[2011.12.22 21:46:59 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_5.dll
[2011.12.22 21:46:58 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_32.dll
[2011.12.22 21:46:58 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_4.dll
[2011.12.22 21:46:58 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_1.dll
[2011.12.22 21:46:57 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_31.dll
[2011.12.22 21:46:57 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_3.dll
[2011.12.22 21:46:57 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_2.dll
[2011.12.22 21:43:17 | 000,000,000 | ---D | C] -- C:\Users\Christian\Documents\Ubisoft
[2011.12.22 21:21:24 | 000,000,000 | ---D | C] -- C:\Program Files\Ubisoft
[2011.12.22 21:20:09 | 000,000,000 | -H-D | C] -- C:\Users\Christian\InstallAnywhere
[2011.12.22 13:56:18 | 000,026,176 | -H-- | C] (LogMeIn, Inc.) -- C:\Windows\System32\hamachi.sys
[2011.12.15 17:15:03 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2011.12.15 17:15:02 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2011.12.15 17:14:59 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2011.12.15 17:14:55 | 000,671,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2011.12.15 17:14:55 | 000,471,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011.12.15 17:14:55 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2011.12.15 17:14:55 | 000,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2011.12.15 17:14:54 | 001,383,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011.12.15 17:14:54 | 000,380,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2011.12.15 17:14:54 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011.12.15 17:14:46 | 002,043,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011.12.15 17:14:34 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2011.12.15 17:14:31 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2006.11.01 21:15:50 | 000,537,480 | ---- | C] ( ) -- C:\Windows\System32\dlcfcoms.exe
[2006.11.01 21:15:50 | 000,385,928 | ---- | C] ( ) -- C:\Windows\System32\dlcfih.exe
[2006.11.01 21:15:48 | 000,381,832 | ---- | C] ( ) -- C:\Windows\System32\dlcfcfg.exe
[2006.10.11 17:01:40 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\dlcfpmui.dll
[2006.10.11 16:59:56 | 001,224,704 | ---- | C] ( ) -- C:\Windows\System32\dlcfserv.dll
[2006.10.11 16:54:10 | 000,421,888 | ---- | C] ( ) -- C:\Windows\System32\dlcfcomm.dll
[2006.10.11 16:52:34 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\dlcflmpm.dll
[2006.10.11 16:51:16 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\dlcfiesc.dll
[2006.10.11 16:48:58 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\dlcfpplc.dll
[2006.10.11 16:48:14 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\dlcfcomc.dll
[2006.10.11 16:47:42 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\dlcfprox.dll
[2006.10.11 16:41:42 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\dlcfinpa.dll
[2006.10.11 16:41:04 | 000,991,232 | ---- | C] ( ) -- C:\Windows\System32\dlcfusb1.dll
[2006.10.11 16:37:14 | 000,696,320 | ---- | C] ( ) -- C:\Windows\System32\dlcfhbn3.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Christian\Desktop\*.tmp files -> C:\Users\Christian\Desktop\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.01.12 18:28:08 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Christian\Desktop\OTL(1).exe
[2012.01.12 18:16:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.01.12 17:18:42 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.01.12 17:18:42 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.01.12 17:15:04 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.01.12 16:59:47 | 000,000,680 | ---- | M] () -- C:\Users\Christian\AppData\Local\d3d9caps.dat
[2012.01.12 16:59:25 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore1cc6e61108ec1c0.job
[2012.01.12 16:49:04 | 000,000,394 | ---- | M] () -- C:\Windows\tasks\At1.job
[2012.01.12 16:48:23 | 000,291,328 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\firefox.exe
[2012.01.12 14:03:19 | 047,626,643 | ---- | M] () -- C:\Users\Christian\Desktop\12-ArbeitenMitRaster.mov
[2012.01.11 16:15:06 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.01.11 16:15:06 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.01.11 16:15:06 | 000,126,454 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.01.11 16:15:06 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.01.08 17:25:15 | 000,059,904 | ---- | M] () -- C:\Users\Christian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.01.08 11:35:01 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.01.05 11:38:12 | 000,000,338 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForChristian.job
[2011.12.22 22:16:23 | 000,001,872 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2011.12.17 12:00:19 | 000,448,496 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Christian\Desktop\*.tmp files -> C:\Users\Christian\Desktop\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.01.12 16:48:54 | 000,000,394 | ---- | C] () -- C:\Windows\tasks\At1.job
[2012.01.12 16:48:23 | 000,291,328 | ---- | C] () -- C:\Users\Christian\AppData\Roaming\firefox.exe
[2012.01.12 14:02:26 | 047,626,643 | ---- | C] () -- C:\Users\Christian\Desktop\12-ArbeitenMitRaster.mov
[2012.01.08 10:53:26 | 000,000,680 | ---- | C] () -- C:\Users\Christian\AppData\Local\d3d9caps.dat
[2011.12.22 22:16:23 | 000,001,872 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2011.06.03 12:29:29 | 000,022,328 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011.06.03 12:29:23 | 000,103,736 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.06.03 12:29:17 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2010.12.23 16:22:48 | 000,525,754 | ---- | C] () -- C:\Users\Christian\AppData\Local\tmpIMG_1922.1
[2010.12.23 16:22:46 | 001,210,568 | ---- | C] () -- C:\Users\Christian\AppData\Local\tmpIMG_1922.0
[2010.12.23 16:22:46 | 000,518,792 | ---- | C] () -- C:\Users\Christian\AppData\Local\tmpIMG_1922.JPG
[2010.06.28 18:53:11 | 000,053,248 | ---- | C] () -- C:\Windows\System32\mgxasio2.dll
[2010.06.28 18:51:07 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2010.06.28 18:50:19 | 000,007,119 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2010.06.15 13:13:07 | 000,000,000 | ---- | C] () -- C:\Users\Christian\AppData\Roaming\wklnhst.dat
[2010.05.08 14:43:22 | 000,000,552 | ---- | C] () -- C:\Users\Christian\AppData\Local\d3d8caps.dat
[2010.03.11 13:45:44 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2009.09.24 13:48:29 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.09.24 13:48:28 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.18 20:35:50 | 001,511,424 | ---- | C] () -- C:\Windows\System32\sn3win.dll
[2009.05.30 19:11:59 | 000,031,007 | ---- | C] () -- C:\Users\Christian\AppData\Roaming\UserTile.png
[2009.05.09 17:49:45 | 000,059,904 | ---- | C] () -- C:\Users\Christian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.05.07 19:02:01 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009.04.25 02:46:20 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009.02.26 17:00:22 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009.02.26 16:56:04 | 000,628,742 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.02.26 16:56:04 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.02.26 16:56:04 | 000,126,454 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.02.26 16:56:04 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.02.26 10:27:50 | 000,000,428 | ---- | C] () -- C:\Windows\System32\ezdigsgn.dat
[2009.01.22 01:34:38 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2009.01.22 00:51:52 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2008.10.29 18:13:34 | 000,180,720 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2008.10.21 13:40:00 | 000,081,920 | ---- | C] () -- C:\Windows\System32\ATIODE.exe
[2008.10.21 13:40:00 | 000,045,056 | ---- | C] () -- C:\Windows\System32\ATIODCLI.exe
[2007.01.26 00:04:12 | 000,138,752 | ---- | C] () -- C:\Windows\System32\mase32.dll
[2007.01.26 00:04:12 | 000,027,648 | ---- | C] () -- C:\Windows\System32\ma32.dll
[2006.12.05 05:08:56 | 000,022,723 | ---- | C] () -- C:\Windows\System32\DELS3L3.DLL
[2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:47:37 | 000,448,496 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 11:33:01 | 000,595,996 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 11:33:01 | 000,104,070 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.10.28 09:31:44 | 000,344,064 | ---- | C] () -- C:\Windows\System32\dlcfcoin.dll
[2006.10.20 12:37:22 | 000,221,184 | ---- | C] () -- C:\Windows\System32\dlcfinsb.dll
[2006.10.20 12:37:16 | 000,086,016 | ---- | C] () -- C:\Windows\System32\dlcfcub.dll
[2006.10.20 12:37:00 | 000,073,728 | ---- | C] () -- C:\Windows\System32\dlcfcu.dll
[2006.10.20 12:36:54 | 000,159,744 | ---- | C] () -- C:\Windows\System32\dlcfins.dll
[2006.10.20 12:35:36 | 000,434,176 | ---- | C] () -- C:\Windows\System32\dlcfutil.dll
[2006.10.20 12:20:46 | 000,114,688 | ---- | C] () -- C:\Windows\System32\dlcfinsr.dll
[2006.10.20 12:20:40 | 000,036,864 | ---- | C] () -- C:\Windows\System32\dlcfcur.dll
[2006.10.20 12:20:20 | 000,135,168 | ---- | C] () -- C:\Windows\System32\dlcfjswr.dll
[2006.09.06 04:27:08 | 000,069,632 | ---- | C] () -- C:\Windows\System32\dlcfcfg.dll
[2005.08.18 05:26:46 | 000,040,960 | ---- | C] () -- C:\Windows\System32\dlcfvs.dll
 
========== LOP Check ==========
 
[2011.09.16 11:24:33 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\.minecraft
[2012.01.12 16:45:15 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\606C2
[2011.01.19 21:07:01 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Arduino
[2011.01.28 17:43:07 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Audacity
[2011.11.28 16:38:35 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\BitZipper
[2012.01.12 16:45:48 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\C2D06
[2010.09.22 13:20:26 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Dev-Cpp
[2011.09.29 19:09:30 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DVDVideoSoft
[2011.09.29 19:08:53 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.05.29 09:49:16 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\GHISLER
[2010.10.20 15:01:13 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\gtk-2.0
[2012.01.12 17:18:19 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ICQ
[2011.06.13 15:08:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\JoCar Consulting
[2010.08.29 20:45:05 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\LimeWire
[2010.06.28 18:54:55 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\MAGIX
[2010.06.15 13:14:08 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\OpenOffice.org
[2009.05.30 19:11:58 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\PeerNetworking
[2011.07.11 16:19:12 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Philipp Winterberg
[2009.05.09 18:52:36 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Roni Music
[2011.08.01 18:46:43 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\T-Mobile
[2011.08.01 19:05:29 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\T-Mobile Internet Manager
[2011.08.22 17:21:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\TeamViewer
[2010.06.15 13:13:11 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Template
[2010.07.01 13:26:48 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\TrueCrypt
[2011.07.18 21:00:22 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\TS3Client
[2009.05.10 13:52:36 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\WildTangent
[2012.01.12 16:49:04 | 000,000,394 | ---- | M] () -- C:\Windows\Tasks\At1.job
[2012.01.12 17:18:38 | 000,032,558 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:EEE39B00

< End of report >

--- --- ---


extras.txt:
OTL Logfile:
Code:

OTL Extras logfile created on: 12.01.2012 18:31:58 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Christian\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,18 Gb Available Physical Memory | 72,68% Memory free
6,19 Gb Paging File | 5,61 Gb Available in Paging File | 90,58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287,45 Gb Total Space | 91,52 Gb Free Space | 31,84% Space Free | Partition Type: NTFS
Drive D: | 10,64 Gb Total Space | 1,79 Gb Free Space | 16,84% Space Free | Partition Type: NTFS
 
Computer Name: CHRISTIAN-PC | User Name: Christian | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{3C389DB3-E83E-4229-B3E1-D91C065729C4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{65D5B2A1-298C-4E16-A54D-22CC62F9B522}" = lport=49730 | protocol=6 | dir=in | name=akamai netsession interface |
"{6C0AB25F-8647-4543-A849-FA1392A2D5C4}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{A633C424-504C-4605-A770-0130BED902B9}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{A9C34A91-E054-4141-87D6-6FB1546F11D5}" = lport=2869 | protocol=6 | dir=in | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{010D3B1A-E1E6-4AF6-9201-3A042B258892}" = protocol=6 | dir=in | app=c:\users\christian\appdata\local\akamai\netsession_win.exe |
"{04DFAF47-8268-4AC1-A4B0-830F8CB67BEE}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{101AA672-6CBC-4811-BF84-26790897AB1F}" = protocol=17 | dir=in | app=c:\program files\firefly studios\stronghold 2\stronghold2.exe |
"{1031BAF5-977E-4CE3-9B68-D6BD8EE24A1C}" = dir=in | app=c:\program files\msn messenger\livecall.exe |
"{139E6F97-C971-4E7A-8E7C-00268F6AAD75}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{14352909-BD7C-425E-8415-BDAC2FE8440F}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\rm.exe |
"{16B81A41-00DB-4373-89A7-5476C1F7CEB7}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{16BC2E47-96DD-4BD9-B1E9-BA4D667051AC}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\videospin.exe |
"{18B082EA-74E6-450B-B207-746DCD74214C}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\tsmagent.exe |
"{19DA7B46-92BE-4273-990D-F1A127FDBD49}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\umi.exe |
"{1B79E82C-3E48-436A-B122-7FA29858C65D}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\tsmagent.exe |
"{1CAD9C64-3BC7-46E8-A505-2E6298CCE423}" = protocol=17 | dir=in | app=c:\users\christian\appdata\local\akamai\netsession_win.exe |
"{1FEEC755-5C5C-4196-A8EA-FE3B8B24DD6F}" = protocol=6 | dir=in | app=c:\program files\ubisoft\driver san francisco\driver.exe |
"{2023DC0B-550F-4470-B8AC-73E06B382FDE}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\rm.exe |
"{2506743D-DF7F-4A51-8CFD-BAD011B3B0AA}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{27322EC1-8A8B-43F5-A36E-0353922B1FFA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{279674E2-4D2B-4FAA-BA7E-10783196BEF2}" = dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{2A05C254-2E38-4837-97C8-4F6BBE92C050}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{2D44883D-C871-44DA-85F4-D7C7E2BC4DDD}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{2E2C62E6-646D-4A5C-9E41-C45E61F6E5AD}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe |
"{33B9FE64-5185-453E-85E9-311C24AE06E2}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{357A4848-415F-40FB-9795-E75D372E189F}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{3C103B07-95F0-4E68-BB9D-68E443510210}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{4269A371-5B89-4F42-88EF-A515A8B39A58}" = protocol=17 | dir=in | app=c:\windows\system32\dlcfcoms.exe |
"{51E0114A-515A-43EF-A2B5-67738560C6B2}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{524D9A01-E2F2-4254-89FD-D46971605AD7}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{56627F28-3BBA-4D5F-9E59-8789EBC65B52}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{5D09CE97-C99D-4986-8EB0-6F6568C83335}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\hptouchsmartmusic.exe |
"{6A0529EC-5CB6-48B7-A556-6B69DD827224}" = dir=in | app=c:\program files\hewlett-packard\media\tv\qpservice.exe |
"{76CE4EF8-0437-4979-8A0D-5C5E5FCCB1C0}" = protocol=17 | dir=in | app=c:\program files\ubisoft\driver san francisco\driver.exe |
"{7BD93047-16C0-4921-AEDC-0778E7DB304F}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{816CF110-3B8F-4D48-A7C3-1D4AD5811263}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{82300642-859D-4C0E-A047-49D0CD9F2919}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8681CB43-430D-4882-8320-5F50DD7FA934}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8A8C9A10-BCE9-419A-B5C9-BD1867078B4E}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\videospin.exe |
"{8F80DAB7-3086-4C0B-AC05-B7FA0650A09C}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{96D79059-8043-44C4-8B17-299C0F9331BD}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{9A00201A-FCD0-4EF5-A6D0-C3E7C3DEF64E}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{A06B113F-703E-4FC0-90A6-E60ED66687C4}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{A589287E-9D8A-442A-861B-5449A0E315B9}" = protocol=6 | dir=in | app=c:\program files\logitech touch mouse server\itouch-server-win.exe |
"{A5E51304-3020-4327-ABF0-F9B5AE9B5C66}" = protocol=17 | dir=in | app=c:\program files\logitech touch mouse server\itouch-server-win.exe |
"{BB287FE0-A8BE-4D9E-8576-D291024E7E45}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{BFDEE337-A637-410B-B978-A0107CB83968}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{C06FDC63-36D6-4B51-9089-7B609FA0A361}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
"{C709DCD4-1633-4B6C-B2F1-6C4B362ABFF9}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{CC73667A-B19C-4077-9F11-D3FFB515F603}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{CF0525CD-C1E2-4F83-8F51-9566C7E55020}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D7A53A63-BA99-4EB1-93E1-266DF6A2B1F8}" = protocol=6 | dir=in | app=c:\windows\system32\dlcfcoms.exe |
"{D8D6C0B1-C044-48A6-9D70-A0A23DFBA676}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe |
"{DA6389B6-5933-436F-827C-877710696B6C}" = protocol=6 | dir=in | app=c:\program files\firefly studios\stronghold 2\stronghold2.exe |
"{DA69575C-3ED2-4065-9BF5-BC76732F0E67}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{DC6CFB0A-AF60-4C0D-AD2D-4413BE4B6999}" = dir=in | app=c:\program files\hewlett-packard\media\tv\qp.exe |
"{DDF1340C-F38E-4855-BBB3-A839D2FA9659}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{E2D20AAD-EB1C-4C00-BEEA-3BBAB6CEDED0}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\umi.exe |
"{EB783220-EA58-4A1B-A028-88A734665634}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe |
"TCP Query User{21897EE5-3696-4EC6-9980-F820FDCBC543}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{21E64E27-CE50-4126-8345-9A654204F6E2}C:\users\christian\desktop\spiele\cod 4\iw3mp.exe" = protocol=6 | dir=in | app=c:\users\christian\desktop\spiele\cod 4\iw3mp.exe |
"TCP Query User{28D59AAE-8439-475E-B2BA-EF428DBAB974}C:\users\christian\desktop\spiele\stronghold crusader\stronghold crusader.exe" = protocol=6 | dir=in | app=c:\users\christian\desktop\spiele\stronghold crusader\stronghold crusader.exe |
"TCP Query User{49F3B628-EA83-4BF2-8BD1-8F7A5366D6FA}C:\program files\firefly studios\stronghold 2\stronghold2.exe" = protocol=6 | dir=in | app=c:\program files\firefly studios\stronghold 2\stronghold2.exe |
"TCP Query User{51EF5195-F309-4DB7-8627-41B2234FD329}C:\program files\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{646BFFDD-9458-43EF-A722-A657141FB138}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{7915E5A6-F248-41E8-9CB0-8A90564A026C}C:\users\christian\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\christian\appdata\local\akamai\netsession_win.exe |
"TCP Query User{84D88D70-61C0-4068-A989-EAA85770C47C}C:\program files\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"TCP Query User{9DDD925C-EAB8-48AC-9007-8326A5153C20}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{A177A198-FD21-4DB9-B983-48D1CC81F6AE}C:\program files\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"TCP Query User{A6E0BAFA-8754-42E1-A564-6C7EF38BAFF1}C:\program files\icq7.2\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe |
"TCP Query User{B4C86F1F-C021-4249-84E0-F72E1683C235}C:\users\christian\desktop\cod 4\iw3mp.exe" = protocol=6 | dir=in | app=c:\users\christian\desktop\cod 4\iw3mp.exe |
"TCP Query User{BF166C22-CDA7-42DC-84F3-794DBA54E3BC}C:\users\christian\desktop\spiele\age of empires ii\age2_x1\age2_x1.exe" = protocol=6 | dir=in | app=c:\users\christian\desktop\spiele\age of empires ii\age2_x1\age2_x1.exe |
"TCP Query User{D307411B-0C70-49C8-8DB2-1BD953BE0912}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{1CD4E8AA-37FE-4CC0-AD15-7AACB75717B1}C:\users\christian\desktop\spiele\cod 4\iw3mp.exe" = protocol=17 | dir=in | app=c:\users\christian\desktop\spiele\cod 4\iw3mp.exe |
"UDP Query User{3E7AE464-1435-4547-B2EA-A7C196FD5DA4}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{59F241F6-F910-472D-9F52-B8D8DC8DC2AD}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{6E438FFA-4E03-449E-8A91-39961F307F46}C:\program files\icq7.2\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe |
"UDP Query User{70C946FB-95E6-4BB5-BE9B-EBC7268CF697}C:\users\christian\desktop\cod 4\iw3mp.exe" = protocol=17 | dir=in | app=c:\users\christian\desktop\cod 4\iw3mp.exe |
"UDP Query User{8895A492-7045-4CED-8B59-76C0495ECEB9}C:\users\christian\desktop\spiele\stronghold crusader\stronghold crusader.exe" = protocol=17 | dir=in | app=c:\users\christian\desktop\spiele\stronghold crusader\stronghold crusader.exe |
"UDP Query User{8AE8CE69-069E-45D8-A69B-2896158F48E5}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{96CC401D-E4DD-46A6-AC6F-6F8C4A63EB80}C:\program files\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"UDP Query User{A5116B96-7169-4A78-B907-5368359C2BF4}C:\program files\firefly studios\stronghold 2\stronghold2.exe" = protocol=17 | dir=in | app=c:\program files\firefly studios\stronghold 2\stronghold2.exe |
"UDP Query User{B17B6091-5790-4D28-988E-7E58BD994870}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{C4CE01F2-F928-412E-ABFD-CFEFA7EE2EEF}C:\program files\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"UDP Query User{D33D4CEA-873A-4A1F-BAC3-A5A5CEDAA000}C:\users\christian\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\christian\appdata\local\akamai\netsession_win.exe |
"UDP Query User{DF227F58-6D69-48F2-94CA-CD646F7D215B}C:\users\christian\desktop\spiele\age of empires ii\age2_x1\age2_x1.exe" = protocol=17 | dir=in | app=c:\users\christian\desktop\spiele\age of empires ii\age2_x1\age2_x1.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{00DDD9E0-E95F-4470-8767-26B76164A315}" = LesefixPRO
"{018A980E-99CC-E6E1-1103-460538A91B39}" = CCC Help Dutch
"{01F6C6F6-0D5A-45D0-83DB-38AB421D0BF5}" = Steganos Safe One
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{04758F02-79E9-A64D-6C95-65EF84E435EA}" = ccc-core-static
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0C1EBF39-FB4C-106D-56C6-91F926F5E283}" = Catalyst Control Center Graphics Light
"{0DF757C4-9999-463C-A4EB-B6BF1D8D8D3D}" = Free Natural Voice Text to Speech Reader
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software  1.14.17.1
"{0F2C3198-6FA0-78E7-48CF-82F766D0AD60}" = Catalyst Control Center Core Implementation
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor
"{16D2C649-CBA8-44EE-B730-12584667D487}" = Stronghold 2 Deluxe
"{187817E2-6407-461C-B59B-56CE73363D34}" = Catalyst Control Center - Branding
"{1E7DACA2-C810-40DF-ADAD-BD1C8DB231B9}" = DemonFlyFFv15
"{1E8FDA17-C7AB-4610-1F54-B5A6695E8B6F}" = CCC Help Danish
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F2DF2C6-08F7-40BD-8E85-D16CB436E7F0}" = Free NaturalReader
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{259C0ABB-A3B2-4D70-008F-BF7EE491B70B}" = Need for Speed™ Carbon
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 27
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{2FD8E82F-55A4-358A-D74A-DA017F011200}" = Catalyst Control Center Graphics Previews Vista
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 L1
"{34FB8E02-74B4-8018-A2D3-ADB69E06A24A}" = Catalyst Control Center Graphics Previews Common
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{367BC374-0115-EEF1-8471-6EC87AF0D8C3}" = CCC Help Norwegian
"{36E90C09-EB23-4EAC-8B47-12C0CA5DBD3A}" = HP User Guides 0126
"{37BD3ECA-C926-8CF1-4FFF-BC473CF892E1}" = Catalyst Control Center Graphics Full Existing
"{37D31156-0666-0A8B-1313-6120E0FA40D0}" = CCC Help Italian
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3FA73E2A-50B6-DCAE-0BDD-FAA128934EE8}" = Catalyst Control Center Graphics Full New
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{478FAEA5-00EB-F676-89C1-3822B94B09A7}" = CCC Help Japanese
"{47F36D92-E58E-456D-B73C-3382737E4C42}" = HP Update
"{490951ED-21E8-0B65-0BF5-32F1A3242F28}" = CCC Help English
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{55741CE4-41A5-4247-AB56-AD9DB32A4855}" = nProtect Security Platform 2007
"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5BAB951D-956E-4D20-CCD5-10BB8E1D4AF0}" = CCC Help Czech
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{632240E4-0BC9-704E-D71F-4C5D396D2CCF}" = CCC Help Chinese Standard
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{720FEF0C-7CE6-C8F6-2CF1-41FBB8846700}" = ATI Catalyst Install Manager
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}" = RollerCoaster Tycoon 2
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{732A3F80-008B-4350-BD58-EC5AE98707B8}" = HP Common Access Service Library
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78605EFA-1076-A2B3-AA59-526536BA93E3}" = CCC Help Polish
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{79CB708A-AD4F-A11B-4CA0-713A152C1705}" = CCC Help Portuguese
"{7A9531EF-11A2-D53C-FCB9-8DFCCAD7F2B7}" = CCC Help Spanish
"{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{7BD0D8F8-A13C-48D2-B201-4AD29A48AF34}" = Google SketchUp 7
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{8C13BEE4-E7CE-4E46-BD13-8F41DAD00FEF}" = SweetIM Toolbar for Internet Explorer 3.4
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_PROPLUS_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}_PROPLUS_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}_PROPLUS_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_PROPLUS_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_PROPLUS_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}_PROPLUS_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}_PROPLUS_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}_PROPLUS_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-0044-0407-0000-0000000FF1CE}_PROPLUS_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0407-0000-0000000FF1CE}_PROPLUS_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90EB79E8-6A0F-1660-86C2-9E36A8B01D4A}" = CCC Help Korean
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95A747E0-DF19-46CB-A622-20A0107201BD}" = HP Total Care Setup
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A1D37D8A-876C-5A1E-AC00-454D0C024C9B}" = Skins
"{A3AB35FA-943E-4799-99DC-46EFD59E998F}" = AMD USB Audio Driver Filter
"{A48B9CD8-C2BA-4EC9-0081-7260D238C7CF}" = Need for Speed™ Most Wanted
"{A7AC8E69-01FF-494E-9A2C-423B82CEA604}" = HP MediaSmart SmartMenu
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-A94000000001}" = Adobe Reader 9.4.0 - Deutsch
"{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player
"{AEBBFC67-7A03-4DF3-9E71-BA5C9EB4FBEF}" = MobileMe Control Panel
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2AD681E-6741-AB24-90BC-51B2326F8680}" = CCC Help Russian
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{BA3733E3-CABE-EA21-F351-69BCFC30CF88}" = CCC Help Hungarian
"{BDFA1F29-03E7-C59F-F9A5-E727F6E1A857}" = ccc-utility
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB71A20E-B1B4-4562-81FA-33E1DBD0342F}" = ProtectSmart Hard Drive Protection
"{CD232781-26CA-4E18-BC70-4343A2F0D583}" = Microsoft IntelliPoint 8.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{D0379E71-7CB9-893E-1A20-9581E10999EC}" = Catalyst Control Center InstallProxy
"{D2F31CF3-F83D-6863-4F8A-C8502802E0DD}" = CCC Help Thai
"{D3887E31-A821-9D46-48B2-240E0613EB12}" = CCC Help Chinese Traditional
"{D92F1880-822A-41CA-0090-451FBB89BF4C}" = FIFA Fussball-Weltmeisterschaft 2006 (TM)
"{DB5B22F8-D4C2-A320-5151-B3D4CFEF733C}" = CCC Help German
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}" = muvee Reveal
"{DD74F03D-8DDC-E124-C971-C3217832EE19}" = CCC Help Turkish
"{DFFC0648-BC4B-47D1-93D2-6CA6B9457641}" = OpenOffice.org 3.2
"{E1060959-A299-9D88-60EC-187A55809145}" = CCC Help Swedish
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E551D855-4EE6-852E-5AB8-E9AE95F73B37}" = CCC Help French
"{E5E29403-3D25-40C6-892B-F9FEE2A95585}" = HP Wireless Assistant
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E6B042BC-3F10-609E-CDC1-2DE2AEB2552F}" = CCC Help Greek
"{E848C9C0-E6FF-4A3F-9D67-AE53AC3628FE}" = SweetIM for Messenger 2.7
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition
"{EE656C90-7D67-ECAA-B2E4-F4A768CDA1D0}" = CCC Help Finnish
"{EFB7727F-76AF-43B0-E9AC-3F89181A188B}" = Catalyst Control Center Localization All
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}" = Pinnacle VideoSpin
"7DE39862CC26DCE2446838AAF7CD5C163F835A57" = Windows-Treiberpaket - ENE (enecir) HIDClass  (09/04/2008 2.6.0.0)
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Akamai" = Akamai NetSession Interface Service
"Amazing Slow Downer" = Amazing Slow Downer (remove only)
"AOL Toolbar" = AOL Toolbar 5.0
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.11 (Unicode)
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BitZipper_is1" = BitZipper 2010
"Bricx Command Center" = Bricx Command Center
"CCleaner" = CCleaner
"Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2)
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX-Setup
"Driver San Francisco" = Driver San Francisco
"Firebird SQL Server D" = Firebird SQL Server - MAGIX Edition
"Fraps" = Fraps
"Free iPod Video Converter_is1" = Free iPod Video Converter 1.34
"Free Video to Flash Converter_is1" = Free Video to Flash Converter version 4.1
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.11.923
"Google Chrome" = Google Chrome
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HyperCam 2" = HyperCam 2
"ICQToolbar" = ICQ Toolbar
"igLoader" = igLoader
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1E7DACA2-C810-40DF-ADAD-BD1C8DB231B9}" = DemonFlyFFv15
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"LameACM" = Lame ACM MP3 Codec
"LHTTSGED" = L&H TTS3000 Deutsch
"Logitech Touch Mouse Server" = Logitech Touch Mouse Server 1.0
"LuPO_is1" = LuPO 1.0.2.41
"MAGIX Music Maker for MySpace D" = MAGIX Music Maker for MySpace 15.0.1.8 (D)
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"mIRC" = mIRC
"Mozilla Firefox 8.0 (x86 de)" = Mozilla Firefox 8.0 (x86 de)
"Neffy" = Neffy 1,3,29,0
"P2P_Max_DE Toolbar" = P2P_Max_DE Toolbar
"PROPLUS" = Microsoft Office Professional Plus 2007
"RarZilla Free Unrar" = RarZilla Free Unrar
"softonic-de3 Toolbar" = softonic-de3 Toolbar
"Sweet Home 3D_is1" = Sweet Home 3D version 2.3
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TextAloud MP3_is1" = TextAloud
"TmNationsForever_is1" = TmNationsForever
"T-Mobile Internet Manager" = T-Mobile Internet Manager
"Totalcmd" = Total Commander (Remove or Repair)
"TrueCrypt" = TrueCrypt
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"Uninstall_is1" = Uninstall 1.0.0.1
"WildTangent hp Master Uninstall" = My HP Games
"WinGimp-2.0_is1" = GIMP 2.6.8
"Winload Toolbar" = Winload Toolbar
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"Clash N Slash" = Clash N Slash 1.23
"TeamSpeak 3 Client" = TeamSpeak 3 Client
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 12.01.2012 11:41:29 | Computer Name = Christian-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 12.01.2012 11:41:29 | Computer Name = Christian-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 137312
 
Error - 12.01.2012 11:41:29 | Computer Name = Christian-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 137312
 
Error - 12.01.2012 11:48:25 | Computer Name = Christian-PC | Source = EventSystem | ID = 4621
Description =
 
Error - 12.01.2012 11:52:28 | Computer Name = Christian-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =
 
Error - 12.01.2012 11:52:56 | Computer Name = Christian-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 12.01.2012 11:59:53 | Computer Name = Christian-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 12.01.2012 12:14:45 | Computer Name = Christian-PC | Source = EventSystem | ID = 4621
Description =
 
Error - 12.01.2012 13:16:40 | Computer Name = Christian-PC | Source = EventSystem | ID = 4609
Description =
 
Error - 12.01.2012 13:17:35 | Computer Name = Christian-PC | Source = WinMgmt | ID = 10
Description =
 
[ System Events ]
Error - 12.01.2012 11:59:58 | Computer Name = Christian-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 12.01.2012 12:02:42 | Computer Name = Christian-PC | Source = Service Control Manager | ID = 7009
Description =
 
Error - 12.01.2012 12:02:42 | Computer Name = Christian-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 12.01.2012 13:16:29 | Computer Name = Christian-PC | Source = DCOM | ID = 10005
Description =
 
Error - 12.01.2012 13:16:40 | Computer Name = Christian-PC | Source = DCOM | ID = 10005
Description =
 
Error - 12.01.2012 13:16:43 | Computer Name = Christian-PC | Source = DCOM | ID = 10005
Description =
 
Error - 12.01.2012 13:16:51 | Computer Name = Christian-PC | Source = DCOM | ID = 10005
Description =
 
Error - 12.01.2012 13:17:27 | Computer Name = Christian-PC | Source = DCOM | ID = 10005
Description =
 
Error - 12.01.2012 13:17:36 | Computer Name = Christian-PC | Source = Service Control Manager | ID = 7001
Description =
 
Error - 12.01.2012 13:17:36 | Computer Name = Christian-PC | Source = Service Control Manager | ID = 7026
Description =
 
 
< End of report >

--- --- ---

cklemm 12.01.2012 19:03

Wie ich grade merke hatte ich nicht alle programme geschlossen, also mach ich das schnell nochmal !

markusg 12.01.2012 19:06

wieso wurde der scan nict mit dem von mir benanntem script ausgeführt welches in der code box steht

cklemm 12.01.2012 19:11

oh tut mir Leid, dass hab ich falsch verstanden.

jetzt läuft der San richtig, ich stell das Ergebnis gleich rein !

cklemm 12.01.2012 19:23

oh tut mir Leid, dass hab ich falsch verstanden.

jetzt läuft der San richtig, ich stell das Ergebnis gleich rein !

cklemm 12.01.2012 19:45

Sorry wegen dem doppelpost oben, habe es nicht wegbekommen.

So ich hoffe es ist jetzt richtig :D

OTL:OTL Logfile:
Code:

OTL logfile created on: 12.01.2012 19:09:36 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Christian\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,42 Gb Available Physical Memory | 80,85% Memory free
6,19 Gb Paging File | 5,87 Gb Available in Paging File | 94,76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287,45 Gb Total Space | 91,60 Gb Free Space | 31,87% Space Free | Partition Type: NTFS
Drive D: | 10,64 Gb Total Space | 1,79 Gb Free Space | 16,84% Space Free | Partition Type: NTFS
 
Computer Name: CHRISTIAN-PC | User Name: Christian | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Christian\Desktop\OTL(1).exe (OldTimer Tools)
PRC - C:\Programme\C2D06\lvvm.exe ()
PRC - C:\Programme\LP\A776\38B.exe ()
PRC - C:\Users\Christian\AppData\Roaming\606C2\B00A7.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Programme\C2D06\lvvm.exe ()
MOD - C:\Programme\LP\A776\38B.exe ()
MOD - C:\Users\Christian\AppData\Roaming\606C2\B00A7.exe ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (Akamai) -- c:\program files\common files\akamai/netsession_win_b427739.dll ()
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (ICQ Service) -- C:\Programme\ICQ6Toolbar\ICQ Service.exe ()
SRV - (npggsvc) -- C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (TVCapSvc) TV Background Capture Service (TVBCS) -- C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
SRV - (TVSched) TV Task Scheduler (TVTS) -- C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
SRV - (AESTFilters) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c92065b9\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (STacSV) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c92065b9\stacsv.exe (IDT, Inc.)
SRV - (Recovery Service for Windows) -- C:\Programme\SMINST\BLService.exe ()
SRV - (ezSharedSvc) -- C:\Windows\System32\ezsvc7.dll (EasyBits Sofware AS)
SRV - (dlcf_device) -- C:\Windows\System32\dlcfcoms.exe ( )
SRV - (FirebirdServerMAGIXInstance) -- C:\Programme\MAGIX\Common\Database\bin\fbserver.exe (MAGIX®)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (truecrypt) -- C:\Windows\System32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (TKFsFt) -- C:\Windows\System32\TKFsFt2k.sys (Copyright (C) INCA Internet. 2000-2009)
DRV - (TKFsAv) -- C:\Windows\System32\TKFsAv2k.sys (Copyright (C) INCA Internet. 2000-2009)
DRV - (mfesmfk) -- C:\Windows\System32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (hwusbdev) -- C:\Windows\System32\drivers\ewusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (mferkdk) -- C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (hwdatacard) -- C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (TKRgFt) -- C:\Windows\System32\TKRgFtXp.sys (Copyright (C) INCA Internet. 2000-2009)
DRV - (TKRgAc) -- C:\Windows\System32\TKRgAc2k.sys (Copyright (C) INCA Internet. 2000-2009)
DRV - (TKFsAc) -- C:\Windows\System32\TKFsAc2k.sys (Copyright (C) INCA Internet. 2000-2009)
DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (STHDA) -- C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (JMCR) -- C:\Windows\System32\drivers\jmcr.sys (JMicron Technology Corporation)
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) -- C:\Programme\Hewlett-Packard\Media\DVD\000.fcl (CyberLink Corp.)
DRV - (tcpipBM) -- C:\Windows\System32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (enecir) -- C:\Windows\System32\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV - (usbfilter) -- C:\Windows\System32\drivers\usbfilter.sys (Advanced Micro Devices Inc.)
DRV - (AtiPcie) ATI PCI Express (3GIO) -- C:\Windows\system32\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV - (hpdskflt) -- C:\Windows\system32\DRIVERS\hpdskflt.sys (Hewlett-Packard Corporation)
DRV - (Accelerometer) -- C:\Windows\System32\drivers\Accelerometer.sys (Hewlett-Packard Corporation)
DRV - (NETw3v32) Intel(R) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (SLEE_16_DRIVER) -- C:\Windows\System32\drivers\sleen16.sys (Softwareentwicklung Remus - ArchiCrypt )
DRV - (HpqKbFiltr) -- C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (NPPTNT2) -- C:\Windows\System32\npptNT2.sys (INCA Internet Co., Ltd.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE - HKLM\..\URLSearchHook:  - No CLSID value found
IE - HKLM\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\tbWin1.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKLM\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Programme\P2P_Max_DE\tbP2P_.dll (Conduit Ltd.)
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\tbWin1.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Programme\P2P_Max_DE\tbP2P_.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:52667
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "InnoGames Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.1&q="
FF - prefs.js..browser.search.order.1: "Ask"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.5
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.0.0.10
FF - prefs.js..extensions.enabledItems: youtube2mp3@mondayx.de:1.0.7
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:5.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:3.3.3.2
FF - prefs.js..extensions.enabledItems: finder@meingutscheincode.de:2.0
FF - prefs.js..extensions.enabledItems: {40c3cc16-7269-4b32-9531-17f2950fb06f}:3.3.3.2
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2
FF - prefs.js..extensions.enabledItems: {c7478d43-2bd5-4844-98b8-c2a6aa9ed677}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {2458abc0-f443-11dd-87af-0800200c9a66}:3.6.3.1.03.04.10
FF - prefs.js..extensions.enabledItems: nasanightlaunch@example.com:0.6.20110508
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.3&q="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 52667
FF - prefs.js..network.proxy.type: 1
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player:  File not found
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012.01.12 11:34:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.13 09:49:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.01 13:28:30 | 000,000,000 | ---D | M]
 
[2009.08.17 18:20:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\mozilla\Extensions
[2009.08.17 18:20:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org
[2012.01.10 14:10:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions
[2011.12.06 18:35:52 | 000,000,000 | ---D | M] (Winload Community Toolbar) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f}
[2012.01.10 14:10:05 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.09.30 19:18:51 | 000,000,000 | ---D | M] (Tamper Data) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2011.09.29 19:08:54 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.12.25 12:19:52 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.01.10 14:10:19 | 000,000,000 | ---D | M] (InnoGames Community Toolbar) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{c7478d43-2bd5-4844-98b8-c2a6aa9ed677}
[2012.01.10 14:10:33 | 000,000,000 | ---D | M] (softonic-de3 Community Toolbar) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}
[2009.08.17 18:19:52 | 000,000,000 | ---D | M] (P2P Max DE Toolbar) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{e0007d18-baa4-4573-ae78-8bea0958c610}
[2010.03.12 17:35:45 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011.11.12 14:29:03 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011.04.30 09:50:58 | 000,000,000 | ---D | M] (Multirow Bookmarks Toolbar) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2011.11.05 17:58:42 | 000,000,000 | ---D | M] ("bug489729") -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\bug489729@alice0775
[2011.03.30 16:38:52 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\engine@conduit.com
[2009.06.06 19:24:15 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\moveplayer@movenetworks.com
[2011.12.03 18:02:20 | 000,000,000 | ---D | M] (Download Youtube Videos +) -- C:\Users\Christian\AppData\Roaming\mozilla\Firefox\Profiles\trj1lsez.default\extensions\video.downloader.plugin@ffpimp.com
[2009.06.07 14:11:53 | 000,000,681 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\ask.xml
[2010.12.30 17:22:44 | 000,000,921 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\conduit.xml
[2012.01.08 11:12:19 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-1.xml
[2011.07.03 16:21:08 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-2.xml
[2011.08.22 14:37:54 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-3.xml
[2011.08.31 17:18:15 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-4.xml
[2011.09.01 20:28:01 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-5.xml
[2011.09.08 10:04:22 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-6.xml
[2011.11.06 14:48:47 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-7.xml
[2011.11.13 09:50:47 | 000,000,950 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin-8.xml
[2012.01.04 14:54:58 | 000,000,168 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin.gif
[2012.01.04 14:54:58 | 000,000,618 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin.src
[2010.06.21 16:35:24 | 000,001,042 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\icqplugin.xml
[2011.07.19 10:00:58 | 000,002,227 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\s-amazon-de.xml
[2009.07.10 21:34:09 | 000,003,915 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\searchplugins\sweetim.xml
[2011.11.13 09:50:03 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.07.03 16:20:20 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011.08.24 23:42:36 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TRJ1LSEZ.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}.XPI
() (No name found) -- C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TRJ1LSEZ.DEFAULT\EXTENSIONS\FINDER@MEINGUTSCHEINCODE.DE.XPI
() (No name found) -- C:\USERS\CHRISTIAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TRJ1LSEZ.DEFAULT\EXTENSIONS\YOUTUBE2MP3@MONDAYX.DE.XPI
[2011.11.13 09:49:42 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.07.19 04:05:25 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007.07.25 09:51:06 | 000,164,352 | ---- | M] (Indiepath Ltd) -- C:\Program Files\mozilla firefox\plugins\npigl.dll
[2011.11.06 14:37:30 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.11.06 14:37:30 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.11.06 14:37:30 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.11.06 14:37:30 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.09.25 10:11:54 | 000,002,027 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2011.11.06 14:37:30 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.11.06 14:37:30 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: igLoader (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npigl.dll
CHR - plugin: getPlusPlus for Adobe 16263 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: SiteAdvisor = C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\
 
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
O2 - BHO: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\tbWin1.dll (Conduit Ltd.)
O2 - BHO: (AOL Toolbar BHO) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.)
O2 - BHO: (P2P Max DE Toolbar) - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Programme\P2P_Max_DE\tbP2P_.dll (Conduit Ltd.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
O3 - HKLM\..\Toolbar: (Winload Toolbar) - {40c3cc16-7269-4b32-9531-17f2950fb06f} - C:\Programme\Winload\tbWin1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (P2P Max DE Toolbar) - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Programme\P2P_Max_DE\tbP2P_.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (TextAloud) - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\Programme\TextAloud\TAForIE.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Programme\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (P2P Max DE Toolbar) - {E0007D18-BAA4-4573-AE78-8BEA0958C610} - C:\Programme\P2P_Max_DE\tbP2P_.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [38B.exe] C:\Programme\LP\A776\38B.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DataCardMonitor] C:\Programme\T-Mobile\T-Mobile Internet Manager\DataCardMonitor.exe (Huawei Technologies Co., Ltd.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [DVDAgent] C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Programme\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [SmartMenu] C:\Programme\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SweetIM] C:\Programme\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TSMAgent] C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TVAgent] C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [38B.exe] C:\Users\Christian\AppData\Roaming\Microsoft\A776\38B.exe ()
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Christian\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [Firefox helper] C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\firefox.exe ()
O4 - HKCU..\Run: [HW_OPENEYE_OUC_T-Mobile Internet Manager] C:\Program Files\T-Mobile\T-Mobile Internet Manager\UpdateDog\ouc.exe (Huawei Technologies Co., Ltd.)
O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background File not found
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Programme\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
F3 - HKCU WinNT: Load - (C:\Users\Christian\AppData\Roaming\C2D06\lvvm.exe) -C:\Users\Christian\AppData\Roaming\C2D06\lvvm.exe ()
O8 - Extra context menu item: &AOL Toolbar-Suche - C:\ProgramData\AOL\ieToolbar\resources\de-DE\local\search.html ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Read By Natural Voice Reader - C:\Programme\Natural Voice Reader Standard\read.html ()
O9 - Extra Button: Natural Reader - {0DF757C4-9999-463C-A4EB-B6BF1D8D8D3D} - C:\Programme\Natural Voice Reader Standard\read.html ()
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Programme\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: fritz.repeater ([]* in Lokales Intranet)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Lokales Intranet)
O15 - HKCU\..Trusted Ranges: Range2 ([*] in Lokales Intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0DD7E30D-49C5-4558-B73D-BC68CA74671E}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2EE10678-3EEE-404C-AC60-95CDBE17AB4B}: DhcpNameServer = 192.168.178.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Users\Christian\AppData\Roaming\606C2\B00A7.exe) -C:\Users\Christian\AppData\Roaming\606C2\B00A7.exe ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{57cb71e9-bc65-11e0-b757-00238bb00a77}\Shell - "" = AutoRun
O33 - MountPoints2\{57cb71e9-bc65-11e0-b757-00238bb00a77}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{57cb7201-bc65-11e0-b757-00238bb00a77}\Shell - "" = AutoRun
O33 - MountPoints2\{57cb7201-bc65-11e0-b757-00238bb00a77}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{e320eb30-3088-11e1-8904-00238bb00a77}\Shell - "" = AutoRun
O33 - MountPoints2\{e320eb30-3088-11e1-8904-00238bb00a77}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{f6458d7b-3cac-11de-b779-00238bb00a77}\Shell - "" = AutoRun
O33 - MountPoints2\{f6458d7b-3cac-11de-b779-00238bb00a77}\Shell\AutoRun\command - "" = F:\LaunchU3.exe
O33 - MountPoints2\{fc2cf70e-2141-11df-910f-00238bb00a77}\Shell - "" = AutoRun
O33 - MountPoints2\{fc2cf70e-2141-11df-910f-00238bb00a77}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
ActiveX: {166B1BCA-3F9C-11CF-8075-444553540000} - Macromedia Shockwave Director 10.1
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Macromedia Shockwave Director 10.1
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {AF91E5F3-2046-95EC-D312-49B4FD6B6914} - Internet Explorer
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
NetSvcs: ezSharedSvc - C:\Windows\System32\ezsvc7.dll (EasyBits Sofware AS)
 
 
CREATERESTOREPOINT
Error creating restore point.
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.01.12 18:28:08 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Christian\Desktop\OTL(1).exe
[2012.01.12 18:17:08 | 000,000,000 | ---D | C] -- C:\Program Files\C2D06
[2012.01.12 16:48:53 | 000,000,000 | ---D | C] -- C:\Program Files\LP
[2012.01.12 16:45:24 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Roaming\C2D06
[2012.01.12 16:44:53 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Roaming\606C2
[2011.12.24 19:18:05 | 000,000,000 | ---D | C] -- C:\Users\Christian\Musik
[2011.12.22 22:16:25 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Steam
[2011.12.22 22:16:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2011.12.22 22:16:21 | 000,000,000 | ---D | C] -- C:\Program Files\Steam
[2011.12.22 21:59:43 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Local\Ubisoft Game Launcher
[2011.12.22 21:43:17 | 000,000,000 | ---D | C] -- C:\Users\Christian\Documents\Ubisoft
[2011.12.22 21:21:24 | 000,000,000 | ---D | C] -- C:\Program Files\Ubisoft
[2011.12.22 21:20:09 | 000,000,000 | -H-D | C] -- C:\Users\Christian\InstallAnywhere
[2011.12.22 13:56:18 | 000,026,176 | -H-- | C] (LogMeIn, Inc.) -- C:\Windows\System32\hamachi.sys
[2006.11.01 21:15:50 | 000,537,480 | ---- | C] ( ) -- C:\Windows\System32\dlcfcoms.exe
[2006.11.01 21:15:50 | 000,385,928 | ---- | C] ( ) -- C:\Windows\System32\dlcfih.exe
[2006.11.01 21:15:48 | 000,381,832 | ---- | C] ( ) -- C:\Windows\System32\dlcfcfg.exe
[2006.10.11 17:01:40 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\dlcfpmui.dll
[2006.10.11 16:59:56 | 001,224,704 | ---- | C] ( ) -- C:\Windows\System32\dlcfserv.dll
[2006.10.11 16:54:10 | 000,421,888 | ---- | C] ( ) -- C:\Windows\System32\dlcfcomm.dll
[2006.10.11 16:52:34 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\dlcflmpm.dll
[2006.10.11 16:51:16 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\dlcfiesc.dll
[2006.10.11 16:48:58 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\dlcfpplc.dll
[2006.10.11 16:48:14 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\dlcfcomc.dll
[2006.10.11 16:47:42 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\dlcfprox.dll
[2006.10.11 16:41:42 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\dlcfinpa.dll
[2006.10.11 16:41:04 | 000,991,232 | ---- | C] ( ) -- C:\Windows\System32\dlcfusb1.dll
[2006.10.11 16:37:14 | 000,696,320 | ---- | C] ( ) -- C:\Windows\System32\dlcfhbn3.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Christian\Desktop\*.tmp files -> C:\Users\Christian\Desktop\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.01.12 18:28:08 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Christian\Desktop\OTL(1).exe
[2012.01.12 18:16:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.01.12 17:18:42 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.01.12 17:18:42 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.01.12 17:15:04 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.01.12 16:59:47 | 000,000,680 | ---- | M] () -- C:\Users\Christian\AppData\Local\d3d9caps.dat
[2012.01.12 16:59:25 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore1cc6e61108ec1c0.job
[2012.01.12 16:49:04 | 000,000,394 | ---- | M] () -- C:\Windows\tasks\At1.job
[2012.01.12 16:48:23 | 000,291,328 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\firefox.exe
[2012.01.12 14:03:19 | 047,626,643 | ---- | M] () -- C:\Users\Christian\Desktop\12-ArbeitenMitRaster.mov
[2012.01.11 16:15:06 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.01.11 16:15:06 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.01.11 16:15:06 | 000,126,454 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.01.11 16:15:06 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.01.08 17:25:15 | 000,059,904 | ---- | M] () -- C:\Users\Christian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.01.08 11:35:01 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.01.05 11:38:12 | 000,000,338 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForChristian.job
[2011.12.22 22:16:23 | 000,001,872 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2011.12.17 12:00:19 | 000,448,496 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Christian\Desktop\*.tmp files -> C:\Users\Christian\Desktop\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.01.12 16:48:54 | 000,000,394 | ---- | C] () -- C:\Windows\tasks\At1.job
[2012.01.12 16:48:23 | 000,291,328 | ---- | C] () -- C:\Users\Christian\AppData\Roaming\firefox.exe
[2012.01.12 14:02:26 | 047,626,643 | ---- | C] () -- C:\Users\Christian\Desktop\12-ArbeitenMitRaster.mov
[2012.01.08 10:53:26 | 000,000,680 | ---- | C] () -- C:\Users\Christian\AppData\Local\d3d9caps.dat
[2011.12.22 22:16:23 | 000,001,872 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2011.06.03 12:29:29 | 000,022,328 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011.06.03 12:29:23 | 000,103,736 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.06.03 12:29:17 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2010.12.23 16:22:48 | 000,525,754 | ---- | C] () -- C:\Users\Christian\AppData\Local\tmpIMG_1922.1
[2010.12.23 16:22:46 | 001,210,568 | ---- | C] () -- C:\Users\Christian\AppData\Local\tmpIMG_1922.0
[2010.12.23 16:22:46 | 000,518,792 | ---- | C] () -- C:\Users\Christian\AppData\Local\tmpIMG_1922.JPG
[2010.06.28 18:53:11 | 000,053,248 | ---- | C] () -- C:\Windows\System32\mgxasio2.dll
[2010.06.28 18:51:07 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2010.06.28 18:50:19 | 000,007,119 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2010.06.15 13:13:07 | 000,000,000 | ---- | C] () -- C:\Users\Christian\AppData\Roaming\wklnhst.dat
[2010.05.08 14:43:22 | 000,000,552 | ---- | C] () -- C:\Users\Christian\AppData\Local\d3d8caps.dat
[2010.03.11 13:45:44 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2009.09.24 13:48:29 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.09.24 13:48:28 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.09.18 20:35:50 | 001,511,424 | ---- | C] () -- C:\Windows\System32\sn3win.dll
[2009.05.30 19:11:59 | 000,031,007 | ---- | C] () -- C:\Users\Christian\AppData\Roaming\UserTile.png
[2009.05.09 17:49:45 | 000,059,904 | ---- | C] () -- C:\Users\Christian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.05.07 19:02:01 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009.04.25 02:46:20 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009.02.26 17:00:22 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009.02.26 16:56:04 | 000,628,742 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.02.26 16:56:04 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.02.26 16:56:04 | 000,126,454 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.02.26 16:56:04 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.02.26 10:27:50 | 000,000,428 | ---- | C] () -- C:\Windows\System32\ezdigsgn.dat
[2009.01.22 01:34:38 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2009.01.22 00:51:52 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2008.10.29 18:13:34 | 000,180,720 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2008.10.21 13:40:00 | 000,081,920 | ---- | C] () -- C:\Windows\System32\ATIODE.exe
[2008.10.21 13:40:00 | 000,045,056 | ---- | C] () -- C:\Windows\System32\ATIODCLI.exe
[2007.01.26 00:04:12 | 000,138,752 | ---- | C] () -- C:\Windows\System32\mase32.dll
[2007.01.26 00:04:12 | 000,027,648 | ---- | C] () -- C:\Windows\System32\ma32.dll
[2006.12.05 05:08:56 | 000,022,723 | ---- | C] () -- C:\Windows\System32\DELS3L3.DLL
[2006.11.02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:47:37 | 000,448,496 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 11:33:01 | 000,595,996 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 11:33:01 | 000,104,070 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.10.28 09:31:44 | 000,344,064 | ---- | C] () -- C:\Windows\System32\dlcfcoin.dll
[2006.10.20 12:37:22 | 000,221,184 | ---- | C] () -- C:\Windows\System32\dlcfinsb.dll
[2006.10.20 12:37:16 | 000,086,016 | ---- | C] () -- C:\Windows\System32\dlcfcub.dll
[2006.10.20 12:37:00 | 000,073,728 | ---- | C] () -- C:\Windows\System32\dlcfcu.dll
[2006.10.20 12:36:54 | 000,159,744 | ---- | C] () -- C:\Windows\System32\dlcfins.dll
[2006.10.20 12:35:36 | 000,434,176 | ---- | C] () -- C:\Windows\System32\dlcfutil.dll
[2006.10.20 12:20:46 | 000,114,688 | ---- | C] () -- C:\Windows\System32\dlcfinsr.dll
[2006.10.20 12:20:40 | 000,036,864 | ---- | C] () -- C:\Windows\System32\dlcfcur.dll
[2006.10.20 12:20:20 | 000,135,168 | ---- | C] () -- C:\Windows\System32\dlcfjswr.dll
[2006.09.06 04:27:08 | 000,069,632 | ---- | C] () -- C:\Windows\System32\dlcfcfg.dll
[2005.08.18 05:26:46 | 000,040,960 | ---- | C] () -- C:\Windows\System32\dlcfvs.dll
 
========== LOP Check ==========
 
[2011.09.16 11:24:33 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\.minecraft
[2012.01.12 16:45:15 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\606C2
[2011.01.19 21:07:01 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Arduino
[2011.01.28 17:43:07 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Audacity
[2011.11.28 16:38:35 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\BitZipper
[2012.01.12 16:45:48 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\C2D06
[2010.09.22 13:20:26 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Dev-Cpp
[2011.09.29 19:09:30 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DVDVideoSoft
[2011.09.29 19:08:53 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.05.29 09:49:16 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\GHISLER
[2010.10.20 15:01:13 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\gtk-2.0
[2012.01.12 17:18:19 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\ICQ
[2011.06.13 15:08:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\JoCar Consulting
[2010.08.29 20:45:05 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\LimeWire
[2010.06.28 18:54:55 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\MAGIX
[2010.06.15 13:14:08 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\OpenOffice.org
[2009.05.30 19:11:58 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\PeerNetworking
[2011.07.11 16:19:12 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Philipp Winterberg
[2009.05.09 18:52:36 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Roni Music
[2011.08.01 18:46:43 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\T-Mobile
[2011.08.01 19:05:29 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\T-Mobile Internet Manager
[2011.08.22 17:21:54 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\TeamViewer
[2010.06.15 13:13:11 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\Template
[2010.07.01 13:26:48 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\TrueCrypt
[2011.07.18 21:00:22 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\TS3Client
[2009.05.10 13:52:36 | 000,000,000 | ---D | M] -- C:\Users\Christian\AppData\Roaming\WildTangent
[2012.01.12 16:49:04 | 000,000,394 | ---- | M] () -- C:\Windows\Tasks\At1.job
[2012.01.12 17:18:38 | 000,032,558 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*. >
[2009.05.07 14:32:47 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN
[2010.02.17 14:50:08 | 000,000,000 | ---D | M] -- C:\17888c14954ddc0e95029ffae873dae6
[2009.11.16 14:11:11 | 000,000,000 | -HSD | M] -- C:\boot
[2010.09.27 16:30:48 | 000,000,000 | ---D | M] -- C:\Dev-Cpp
[2006.11.02 14:02:03 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2009.05.07 14:22:20 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2009.06.07 14:16:17 | 000,000,000 | ---D | M] -- C:\DVDVideoSoft
[2011.08.25 08:56:57 | 000,000,000 | ---D | M] -- C:\e0e9780eaec1741d76
[2009.05.07 14:24:17 | 000,000,000 | -H-D | M] -- C:\HP
[2011.03.08 15:10:04 | 000,000,000 | ---D | M] -- C:\LuPO
[2009.02.26 10:10:49 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2008.01.21 03:32:31 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2012.01.12 18:17:08 | 000,000,000 | R--D | M] -- C:\Program Files
[2012.01.12 17:00:32 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2009.05.07 14:22:20 | 000,000,000 | -HSD | M] -- C:\Programme
[2009.09.15 13:12:47 | 000,000,000 | ---D | M] -- C:\SWSetup
[2012.01.12 11:44:45 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2009.05.07 14:24:50 | 000,000,000 | -H-D | M] -- C:\System.sav
[2010.05.29 09:49:26 | 000,000,000 | ---D | M] -- C:\totalcmd
[2009.05.07 14:22:29 | 000,000,000 | R--D | M] -- C:\Users
[2012.01.12 18:16:00 | 000,000,000 | ---D | M] -- C:\Windows
 
< %PROGRAMFILES%\*.exe >
 
< %LOCALAPPDATA%\*.exe >
 
< %systemroot%\*. /mp /s >
 
 
< MD5 for: AGP440.SYS  >
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.21 03:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.21 03:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.21 03:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 10:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.08.16 13:03:39 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=66A1A71D66C5235A31C16F30147E7AF6 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_181d523c\atapi.sys
[2008.08.16 13:03:39 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=66A1A71D66C5235A31C16F30147E7AF6 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22245_none_dd9b888d3ac35a04\atapi.sys
[2009.02.26 17:16:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=9C0E70031905ADBF94EDB9EA14AF943B -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7f3e4ed9\atapi.sys
[2009.02.26 17:16:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=9C0E70031905ADBF94EDB9EA14AF943B -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22193_none_dd6376773aedb5e4\atapi.sys
[2009.02.26 17:16:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E26DDFE464B464DAF1C739122978D1D6 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b7393fc6\atapi.sys
[2009.02.26 17:16:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E26DDFE464B464DAF1C739122978D1D6 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20847_none_dbb74a7b3d9afbc1\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2007.05.17 21:34:04 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files\CyberLink\PowerDirector\EventLog.dll
 
< MD5 for: EXPLORER.EXE  >
[2009.02.26 17:33:58 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2009.02.26 17:33:57 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2009.02.26 17:33:57 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2009.02.26 17:33:57 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008.01.21 03:24:24 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 03:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008.01.21 03:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.21 03:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.21 03:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.21 03:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008.01.21 03:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.21 03:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 03:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\Windows\System32\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
[2008.01.21 03:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 03:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.21 03:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008.01.21 03:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 03:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.21 03:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2008.01.21 04:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008.01.21 04:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008.01.21 04:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 11:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 11:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\system32\*.dll /lockedfiles >
 
< %USERPROFILE%\*.* >
[2011.11.09 17:16:48 | 000,001,490 | ---- | M] () -- C:\Users\Christian\.recently-used.xbel
[2012.01.12 19:38:51 | 003,932,160 | -HS- | M] () -- C:\Users\Christian\ntuser.dat
[2012.01.12 19:38:51 | 000,262,144 | -H-- | M] () -- C:\Users\Christian\ntuser.dat.LOG1
[2012.01.12 16:59:23 | 000,262,144 | -H-- | M] () -- C:\Users\Christian\ntuser.dat.LOG2
[2011.02.02 22:33:33 | 000,065,536 | -HS- | M] () -- C:\Users\Christian\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2011.02.02 22:33:33 | 000,524,288 | -HS- | M] () -- C:\Users\Christian\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2009.05.07 14:38:52 | 000,524,288 | -HS- | M] () -- C:\Users\Christian\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2012.01.12 17:18:30 | 000,065,536 | -HS- | M] () -- C:\Users\Christian\ntuser.dat{9d0ad263-2fa5-11e0-bab0-00238bb00a77}.TM.blf
[2012.01.12 17:18:30 | 000,524,288 | -HS- | M] () -- C:\Users\Christian\ntuser.dat{9d0ad263-2fa5-11e0-bab0-00238bb00a77}.TMContainer00000000000000000001.regtrans-ms
[2011.02.03 21:38:52 | 000,524,288 | -HS- | M] () -- C:\Users\Christian\ntuser.dat{9d0ad263-2fa5-11e0-bab0-00238bb00a77}.TMContainer00000000000000000002.regtrans-ms
[2009.05.07 14:22:30 | 000,000,020 | -HS- | M] () -- C:\Users\Christian\ntuser.ini
 
< %USERPROFILE%\Local Settings\Temp\*.exe >
 
< %USERPROFILE%\Local Settings\Temp\*.dll >
 
< %USERPROFILE%\Application Data\*.exe >
 
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
 
<          >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:EEE39B00

< End of report >

--- --- ---

cklemm 12.01.2012 19:46

Extras:OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 12.01.2012 19:09:36 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Christian\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 2,42 Gb Available Physical Memory | 80,85% Memory free
6,19 Gb Paging File | 5,87 Gb Available in Paging File | 94,76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287,45 Gb Total Space | 91,60 Gb Free Space | 31,87% Space Free | Partition Type: NTFS
Drive D: | 10,64 Gb Total Space | 1,79 Gb Free Space | 16,84% Space Free | Partition Type: NTFS
 
Computer Name: CHRISTIAN-PC | User Name: Christian | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{3C389DB3-E83E-4229-B3E1-D91C065729C4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{65D5B2A1-298C-4E16-A54D-22CC62F9B522}" = lport=49730 | protocol=6 | dir=in | name=akamai netsession interface |
"{6C0AB25F-8647-4543-A849-FA1392A2D5C4}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{A633C424-504C-4605-A770-0130BED902B9}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{A9C34A91-E054-4141-87D6-6FB1546F11D5}" = lport=2869 | protocol=6 | dir=in | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{010D3B1A-E1E6-4AF6-9201-3A042B258892}" = protocol=6 | dir=in | app=c:\users\christian\appdata\local\akamai\netsession_win.exe |
"{04DFAF47-8268-4AC1-A4B0-830F8CB67BEE}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{101AA672-6CBC-4811-BF84-26790897AB1F}" = protocol=17 | dir=in | app=c:\program files\firefly studios\stronghold 2\stronghold2.exe |
"{1031BAF5-977E-4CE3-9B68-D6BD8EE24A1C}" = dir=in | app=c:\program files\msn messenger\livecall.exe |
"{139E6F97-C971-4E7A-8E7C-00268F6AAD75}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{14352909-BD7C-425E-8415-BDAC2FE8440F}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\rm.exe |
"{16B81A41-00DB-4373-89A7-5476C1F7CEB7}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{16BC2E47-96DD-4BD9-B1E9-BA4D667051AC}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\videospin.exe |
"{18B082EA-74E6-450B-B207-746DCD74214C}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\tsmagent.exe |
"{19DA7B46-92BE-4273-990D-F1A127FDBD49}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\umi.exe |
"{1B79E82C-3E48-436A-B122-7FA29858C65D}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\tsmagent.exe |
"{1CAD9C64-3BC7-46E8-A505-2E6298CCE423}" = protocol=17 | dir=in | app=c:\users\christian\appdata\local\akamai\netsession_win.exe |
"{1FEEC755-5C5C-4196-A8EA-FE3B8B24DD6F}" = protocol=6 | dir=in | app=c:\program files\ubisoft\driver san francisco\driver.exe |
"{2023DC0B-550F-4470-B8AC-73E06B382FDE}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\rm.exe |
"{2506743D-DF7F-4A51-8CFD-BAD011B3B0AA}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{27322EC1-8A8B-43F5-A36E-0353922B1FFA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{279674E2-4D2B-4FAA-BA7E-10783196BEF2}" = dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{2A05C254-2E38-4837-97C8-4F6BBE92C050}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{2D44883D-C871-44DA-85F4-D7C7E2BC4DDD}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{2E2C62E6-646D-4A5C-9E41-C45E61F6E5AD}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe |
"{33B9FE64-5185-453E-85E9-311C24AE06E2}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{357A4848-415F-40FB-9795-E75D372E189F}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{3C103B07-95F0-4E68-BB9D-68E443510210}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{4269A371-5B89-4F42-88EF-A515A8B39A58}" = protocol=17 | dir=in | app=c:\windows\system32\dlcfcoms.exe |
"{51E0114A-515A-43EF-A2B5-67738560C6B2}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{524D9A01-E2F2-4254-89FD-D46971605AD7}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{56627F28-3BBA-4D5F-9E59-8789EBC65B52}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{5D09CE97-C99D-4986-8EB0-6F6568C83335}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\hptouchsmartmusic.exe |
"{6A0529EC-5CB6-48B7-A556-6B69DD827224}" = dir=in | app=c:\program files\hewlett-packard\media\tv\qpservice.exe |
"{76CE4EF8-0437-4979-8A0D-5C5E5FCCB1C0}" = protocol=17 | dir=in | app=c:\program files\ubisoft\driver san francisco\driver.exe |
"{7BD93047-16C0-4921-AEDC-0778E7DB304F}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{816CF110-3B8F-4D48-A7C3-1D4AD5811263}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{82300642-859D-4C0E-A047-49D0CD9F2919}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8681CB43-430D-4882-8320-5F50DD7FA934}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8A8C9A10-BCE9-419A-B5C9-BD1867078B4E}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\videospin.exe |
"{8F80DAB7-3086-4C0B-AC05-B7FA0650A09C}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{96D79059-8043-44C4-8B17-299C0F9331BD}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{9A00201A-FCD0-4EF5-A6D0-C3E7C3DEF64E}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{A06B113F-703E-4FC0-90A6-E60ED66687C4}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{A589287E-9D8A-442A-861B-5449A0E315B9}" = protocol=6 | dir=in | app=c:\program files\logitech touch mouse server\itouch-server-win.exe |
"{A5E51304-3020-4327-ABF0-F9B5AE9B5C66}" = protocol=17 | dir=in | app=c:\program files\logitech touch mouse server\itouch-server-win.exe |
"{BB287FE0-A8BE-4D9E-8576-D291024E7E45}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{BFDEE337-A637-410B-B978-A0107CB83968}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{C06FDC63-36D6-4B51-9089-7B609FA0A361}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
"{C709DCD4-1633-4B6C-B2F1-6C4B362ABFF9}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{CC73667A-B19C-4077-9F11-D3FFB515F603}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{CF0525CD-C1E2-4F83-8F51-9566C7E55020}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D7A53A63-BA99-4EB1-93E1-266DF6A2B1F8}" = protocol=6 | dir=in | app=c:\windows\system32\dlcfcoms.exe |
"{D8D6C0B1-C044-48A6-9D70-A0A23DFBA676}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe |
"{DA6389B6-5933-436F-827C-877710696B6C}" = protocol=6 | dir=in | app=c:\program files\firefly studios\stronghold 2\stronghold2.exe |
"{DA69575C-3ED2-4065-9BF5-BC76732F0E67}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{DC6CFB0A-AF60-4C0D-AD2D-4413BE4B6999}" = dir=in | app=c:\program files\hewlett-packard\media\tv\qp.exe |
"{DDF1340C-F38E-4855-BBB3-A839D2FA9659}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{E2D20AAD-EB1C-4C00-BEEA-3BBAB6CEDED0}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\umi.exe |
"{EB783220-EA58-4A1B-A028-88A734665634}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe |
"TCP Query User{21897EE5-3696-4EC6-9980-F820FDCBC543}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{21E64E27-CE50-4126-8345-9A654204F6E2}C:\users\christian\desktop\spiele\cod 4\iw3mp.exe" = protocol=6 | dir=in | app=c:\users\christian\desktop\spiele\cod 4\iw3mp.exe |
"TCP Query User{28D59AAE-8439-475E-B2BA-EF428DBAB974}C:\users\christian\desktop\spiele\stronghold crusader\stronghold crusader.exe" = protocol=6 | dir=in | app=c:\users\christian\desktop\spiele\stronghold crusader\stronghold crusader.exe |
"TCP Query User{49F3B628-EA83-4BF2-8BD1-8F7A5366D6FA}C:\program files\firefly studios\stronghold 2\stronghold2.exe" = protocol=6 | dir=in | app=c:\program files\firefly studios\stronghold 2\stronghold2.exe |
"TCP Query User{51EF5195-F309-4DB7-8627-41B2234FD329}C:\program files\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{646BFFDD-9458-43EF-A722-A657141FB138}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{7915E5A6-F248-41E8-9CB0-8A90564A026C}C:\users\christian\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\christian\appdata\local\akamai\netsession_win.exe |
"TCP Query User{84D88D70-61C0-4068-A989-EAA85770C47C}C:\program files\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"TCP Query User{9DDD925C-EAB8-48AC-9007-8326A5153C20}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{A177A198-FD21-4DB9-B983-48D1CC81F6AE}C:\program files\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"TCP Query User{A6E0BAFA-8754-42E1-A564-6C7EF38BAFF1}C:\program files\icq7.2\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe |
"TCP Query User{B4C86F1F-C021-4249-84E0-F72E1683C235}C:\users\christian\desktop\cod 4\iw3mp.exe" = protocol=6 | dir=in | app=c:\users\christian\desktop\cod 4\iw3mp.exe |
"TCP Query User{BF166C22-CDA7-42DC-84F3-794DBA54E3BC}C:\users\christian\desktop\spiele\age of empires ii\age2_x1\age2_x1.exe" = protocol=6 | dir=in | app=c:\users\christian\desktop\spiele\age of empires ii\age2_x1\age2_x1.exe |
"TCP Query User{D307411B-0C70-49C8-8DB2-1BD953BE0912}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{1CD4E8AA-37FE-4CC0-AD15-7AACB75717B1}C:\users\christian\desktop\spiele\cod 4\iw3mp.exe" = protocol=17 | dir=in | app=c:\users\christian\desktop\spiele\cod 4\iw3mp.exe |
"UDP Query User{3E7AE464-1435-4547-B2EA-A7C196FD5DA4}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{59F241F6-F910-472D-9F52-B8D8DC8DC2AD}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{6E438FFA-4E03-449E-8A91-39961F307F46}C:\program files\icq7.2\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe |
"UDP Query User{70C946FB-95E6-4BB5-BE9B-EBC7268CF697}C:\users\christian\desktop\cod 4\iw3mp.exe" = protocol=17 | dir=in | app=c:\users\christian\desktop\cod 4\iw3mp.exe |
"UDP Query User{8895A492-7045-4CED-8B59-76C0495ECEB9}C:\users\christian\desktop\spiele\stronghold crusader\stronghold crusader.exe" = protocol=17 | dir=in | app=c:\users\christian\desktop\spiele\stronghold crusader\stronghold crusader.exe |
"UDP Query User{8AE8CE69-069E-45D8-A69B-2896158F48E5}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{96CC401D-E4DD-46A6-AC6F-6F8C4A63EB80}C:\program files\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"UDP Query User{A5116B96-7169-4A78-B907-5368359C2BF4}C:\program files\firefly studios\stronghold 2\stronghold2.exe" = protocol=17 | dir=in | app=c:\program files\firefly studios\stronghold 2\stronghold2.exe |
"UDP Query User{B17B6091-5790-4D28-988E-7E58BD994870}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{C4CE01F2-F928-412E-ABFD-CFEFA7EE2EEF}C:\program files\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"UDP Query User{D33D4CEA-873A-4A1F-BAC3-A5A5CEDAA000}C:\users\christian\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\christian\appdata\local\akamai\netsession_win.exe |
"UDP Query User{DF227F58-6D69-48F2-94CA-CD646F7D215B}C:\users\christian\desktop\spiele\age of empires ii\age2_x1\age2_x1.exe" = protocol=17 | dir=in | app=c:\users\christian\desktop\spiele\age of empires ii\age2_x1\age2_x1.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{00DDD9E0-E95F-4470-8767-26B76164A315}" = LesefixPRO
"{018A980E-99CC-E6E1-1103-460538A91B39}" = CCC Help Dutch
"{01F6C6F6-0D5A-45D0-83DB-38AB421D0BF5}" = Steganos Safe One
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{04758F02-79E9-A64D-6C95-65EF84E435EA}" = ccc-core-static
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{0C1EBF39-FB4C-106D-56C6-91F926F5E283}" = Catalyst Control Center Graphics Light
"{0DF757C4-9999-463C-A4EB-B6BF1D8D8D3D}" = Free Natural Voice Text to Speech Reader
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software  1.14.17.1
"{0F2C3198-6FA0-78E7-48CF-82F766D0AD60}" = Catalyst Control Center Core Implementation
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor
"{16D2C649-CBA8-44EE-B730-12584667D487}" = Stronghold 2 Deluxe
"{187817E2-6407-461C-B59B-56CE73363D34}" = Catalyst Control Center - Branding
"{1E7DACA2-C810-40DF-ADAD-BD1C8DB231B9}" = DemonFlyFFv15
"{1E8FDA17-C7AB-4610-1F54-B5A6695E8B6F}" = CCC Help Danish
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F2DF2C6-08F7-40BD-8E85-D16CB436E7F0}" = Free NaturalReader
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{259C0ABB-A3B2-4D70-008F-BF7EE491B70B}" = Need for Speed™ Carbon
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 27
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{2FD8E82F-55A4-358A-D74A-DA017F011200}" = Catalyst Control Center Graphics Previews Vista
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 L1
"{34FB8E02-74B4-8018-A2D3-ADB69E06A24A}" = Catalyst Control Center Graphics Previews Common
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{367BC374-0115-EEF1-8471-6EC87AF0D8C3}" = CCC Help Norwegian
"{36E90C09-EB23-4EAC-8B47-12C0CA5DBD3A}" = HP User Guides 0126
"{37BD3ECA-C926-8CF1-4FFF-BC473CF892E1}" = Catalyst Control Center Graphics Full Existing
"{37D31156-0666-0A8B-1313-6120E0FA40D0}" = CCC Help Italian
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3FA73E2A-50B6-DCAE-0BDD-FAA128934EE8}" = Catalyst Control Center Graphics Full New
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{478FAEA5-00EB-F676-89C1-3822B94B09A7}" = CCC Help Japanese
"{47F36D92-E58E-456D-B73C-3382737E4C42}" = HP Update
"{490951ED-21E8-0B65-0BF5-32F1A3242F28}" = CCC Help English
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{55741CE4-41A5-4247-AB56-AD9DB32A4855}" = nProtect Security Platform 2007
"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5BAB951D-956E-4D20-CCD5-10BB8E1D4AF0}" = CCC Help Czech
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{632240E4-0BC9-704E-D71F-4C5D396D2CCF}" = CCC Help Chinese Standard
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{720FEF0C-7CE6-C8F6-2CF1-41FBB8846700}" = ATI Catalyst Install Manager
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}" = RollerCoaster Tycoon 2
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{732A3F80-008B-4350-BD58-EC5AE98707B8}" = HP Common Access Service Library
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78605EFA-1076-A2B3-AA59-526536BA93E3}" = CCC Help Polish
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{79CB708A-AD4F-A11B-4CA0-713A152C1705}" = CCC Help Portuguese
"{7A9531EF-11A2-D53C-FCB9-8DFCCAD7F2B7}" = CCC Help Spanish
"{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{7BD0D8F8-A13C-48D2-B201-4AD29A48AF34}" = Google SketchUp 7
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{8C13BEE4-E7CE-4E46-BD13-8F41DAD00FEF}" = SweetIM Toolbar for Internet Explorer 3.4
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_PROPLUS_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}_PROPLUS_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}_PROPLUS_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_PROPLUS_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_PROPLUS_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}_PROPLUS_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}_PROPLUS_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}_PROPLUS_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-0044-0407-0000-0000000FF1CE}_PROPLUS_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0407-0000-0000000FF1CE}_PROPLUS_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90EB79E8-6A0F-1660-86C2-9E36A8B01D4A}" = CCC Help Korean
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95A747E0-DF19-46CB-A622-20A0107201BD}" = HP Total Care Setup
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A1D37D8A-876C-5A1E-AC00-454D0C024C9B}" = Skins
"{A3AB35FA-943E-4799-99DC-46EFD59E998F}" = AMD USB Audio Driver Filter
"{A48B9CD8-C2BA-4EC9-0081-7260D238C7CF}" = Need for Speed™ Most Wanted
"{A7AC8E69-01FF-494E-9A2C-423B82CEA604}" = HP MediaSmart SmartMenu
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-A94000000001}" = Adobe Reader 9.4.0 - Deutsch
"{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player
"{AEBBFC67-7A03-4DF3-9E71-BA5C9EB4FBEF}" = MobileMe Control Panel
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2AD681E-6741-AB24-90BC-51B2326F8680}" = CCC Help Russian
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{BA3733E3-CABE-EA21-F351-69BCFC30CF88}" = CCC Help Hungarian
"{BDFA1F29-03E7-C59F-F9A5-E727F6E1A857}" = ccc-utility
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB71A20E-B1B4-4562-81FA-33E1DBD0342F}" = ProtectSmart Hard Drive Protection
"{CD232781-26CA-4E18-BC70-4343A2F0D583}" = Microsoft IntelliPoint 8.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{D0379E71-7CB9-893E-1A20-9581E10999EC}" = Catalyst Control Center InstallProxy
"{D2F31CF3-F83D-6863-4F8A-C8502802E0DD}" = CCC Help Thai
"{D3887E31-A821-9D46-48B2-240E0613EB12}" = CCC Help Chinese Traditional
"{D92F1880-822A-41CA-0090-451FBB89BF4C}" = FIFA Fussball-Weltmeisterschaft 2006 (TM)
"{DB5B22F8-D4C2-A320-5151-B3D4CFEF733C}" = CCC Help German
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}" = muvee Reveal
"{DD74F03D-8DDC-E124-C971-C3217832EE19}" = CCC Help Turkish
"{DFFC0648-BC4B-47D1-93D2-6CA6B9457641}" = OpenOffice.org 3.2
"{E1060959-A299-9D88-60EC-187A55809145}" = CCC Help Swedish
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E551D855-4EE6-852E-5AB8-E9AE95F73B37}" = CCC Help French
"{E5E29403-3D25-40C6-892B-F9FEE2A95585}" = HP Wireless Assistant
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E6B042BC-3F10-609E-CDC1-2DE2AEB2552F}" = CCC Help Greek
"{E848C9C0-E6FF-4A3F-9D67-AE53AC3628FE}" = SweetIM for Messenger 2.7
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition
"{EE656C90-7D67-ECAA-B2E4-F4A768CDA1D0}" = CCC Help Finnish
"{EFB7727F-76AF-43B0-E9AC-3F89181A188B}" = Catalyst Control Center Localization All
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}" = Pinnacle VideoSpin
"7DE39862CC26DCE2446838AAF7CD5C163F835A57" = Windows-Treiberpaket - ENE (enecir) HIDClass  (09/04/2008 2.6.0.0)
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Akamai" = Akamai NetSession Interface Service
"Amazing Slow Downer" = Amazing Slow Downer (remove only)
"AOL Toolbar" = AOL Toolbar 5.0
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.11 (Unicode)
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BitZipper_is1" = BitZipper 2010
"Bricx Command Center" = Bricx Command Center
"CCleaner" = CCleaner
"Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2)
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX-Setup
"Driver San Francisco" = Driver San Francisco
"Firebird SQL Server D" = Firebird SQL Server - MAGIX Edition
"Fraps" = Fraps
"Free iPod Video Converter_is1" = Free iPod Video Converter 1.34
"Free Video to Flash Converter_is1" = Free Video to Flash Converter version 4.1
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.11.923
"Google Chrome" = Google Chrome
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HyperCam 2" = HyperCam 2
"ICQToolbar" = ICQ Toolbar
"igLoader" = igLoader
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1E7DACA2-C810-40DF-ADAD-BD1C8DB231B9}" = DemonFlyFFv15
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"LameACM" = Lame ACM MP3 Codec
"LHTTSGED" = L&H TTS3000 Deutsch
"Logitech Touch Mouse Server" = Logitech Touch Mouse Server 1.0
"LuPO_is1" = LuPO 1.0.2.41
"MAGIX Music Maker for MySpace D" = MAGIX Music Maker for MySpace 15.0.1.8 (D)
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"mIRC" = mIRC
"Mozilla Firefox 8.0 (x86 de)" = Mozilla Firefox 8.0 (x86 de)
"Neffy" = Neffy 1,3,29,0
"P2P_Max_DE Toolbar" = P2P_Max_DE Toolbar
"PROPLUS" = Microsoft Office Professional Plus 2007
"RarZilla Free Unrar" = RarZilla Free Unrar
"softonic-de3 Toolbar" = softonic-de3 Toolbar
"Sweet Home 3D_is1" = Sweet Home 3D version 2.3
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TextAloud MP3_is1" = TextAloud
"TmNationsForever_is1" = TmNationsForever
"T-Mobile Internet Manager" = T-Mobile Internet Manager
"Totalcmd" = Total Commander (Remove or Repair)
"TrueCrypt" = TrueCrypt
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"Uninstall_is1" = Uninstall 1.0.0.1
"WildTangent hp Master Uninstall" = My HP Games
"WinGimp-2.0_is1" = GIMP 2.6.8
"Winload Toolbar" = Winload Toolbar
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"Clash N Slash" = Clash N Slash 1.23
"TeamSpeak 3 Client" = TeamSpeak 3 Client
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 12.01.2012 11:41:29 | Computer Name = Christian-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 137312
 
Error - 12.01.2012 11:41:29 | Computer Name = Christian-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 137312
 
Error - 12.01.2012 11:48:25 | Computer Name = Christian-PC | Source = EventSystem | ID = 4621
Description =
 
Error - 12.01.2012 11:52:28 | Computer Name = Christian-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =
 
Error - 12.01.2012 11:52:56 | Computer Name = Christian-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 12.01.2012 11:59:53 | Computer Name = Christian-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 12.01.2012 12:14:45 | Computer Name = Christian-PC | Source = EventSystem | ID = 4621
Description =
 
Error - 12.01.2012 13:16:40 | Computer Name = Christian-PC | Source = EventSystem | ID = 4609
Description =
 
Error - 12.01.2012 13:17:35 | Computer Name = Christian-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 12.01.2012 14:11:02 | Computer Name = Christian-PC | Source = System Restore | ID = 8193
Description =
 
[ System Events ]
Error - 12.01.2012 11:59:58 | Computer Name = Christian-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 12.01.2012 12:02:42 | Computer Name = Christian-PC | Source = Service Control Manager | ID = 7009
Description =
 
Error - 12.01.2012 12:02:42 | Computer Name = Christian-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 12.01.2012 13:16:29 | Computer Name = Christian-PC | Source = DCOM | ID = 10005
Description =
 
Error - 12.01.2012 13:16:40 | Computer Name = Christian-PC | Source = DCOM | ID = 10005
Description =
 
Error - 12.01.2012 13:16:43 | Computer Name = Christian-PC | Source = DCOM | ID = 10005
Description =
 
Error - 12.01.2012 13:16:51 | Computer Name = Christian-PC | Source = DCOM | ID = 10005
Description =
 
Error - 12.01.2012 13:17:27 | Computer Name = Christian-PC | Source = DCOM | ID = 10005
Description =
 
Error - 12.01.2012 13:17:36 | Computer Name = Christian-PC | Source = Service Control Manager | ID = 7001
Description =
 
Error - 12.01.2012 13:17:36 | Computer Name = Christian-PC | Source = Service Control Manager | ID = 7026
Description =
 
 
< End of report >

--- --- ---

markusg 12.01.2012 20:14

hi

dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user.
wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts.


• Starte bitte die OTL.exe
• Kopiere nun das Folgende in die Textbox.



Code:

:OTL
PRC - C:\Programme\C2D06\lvvm.exe ()
PRC - C:\Programme\LP\A776\38B.exe ()
PRC - C:\Users\Christian\AppData\Roaming\606C2\B00A7.exe ()
MOD - C:\Programme\C2D06\lvvm.exe ()
MOD - C:\Programme\LP\A776\38B.exe ()
MOD - C:\Users\Christian\AppData\Roaming\606C2\B00A7.exe ()
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
FF - prefs.js..browser.search.order.1: "Ask"
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "InnoGames Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.icq.com/search/afe_results.php?ch_id=afextb_ver=1.3.1q="
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found
O4 - HKLM..\Run: [38B.exe] C:\Programme\LP\A776\38B.exe ()
O4 - HKCU..\Run: [38B.exe] C:\Users\Christian\AppData\Roaming\Microsoft\A776\38B.exe ()
O4 - HKCU..\Run: [Firefox helper] C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\firefox.exe ()
O4 - HKCU..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background File not found
F3 - HKCU WinNT: Load - (C:\Users\Christian\AppData\Roaming\C2D06\lvvm.exe) -C:\Users\Christian\AppData\Roaming\C2D06\lvvm.exe ()
O20 - HKCU Winlogon: Shell - (C:\Users\Christian\AppData\Roaming\606C2\B00A7.exe) -C:\Users\Christian\AppData\Roaming\606C2\B00A7.exe ()
[2012.01.12 18:17:08 | 000,000,000 | ---D | C] -- C:\Program Files\C2D06
[2012.01.12 16:48:53 | 000,000,000 | ---D | C] -- C:\Program Files\LP
[2012.01.12 16:45:24 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Roaming\C2D06
[2012.01.12 16:44:53 | 000,000,000 | ---D | C] -- C:\Users\Christian\AppData\Roaming\606C2
[2012.01.12 16:49:04 | 000,000,394 | ---- | M] () -- C:\Windows\tasks\At1.job
[2012.01.12 16:48:23 | 000,291,328 | ---- | M] () -- C:\Users\Christian\AppData\Roaming\firefox.exe
 :Files
C:\Programme\LP
C:\Users\Christian\AppData\Roaming\Microsoft\A776
C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\firefox.exe
C:\Users\Christian\AppData\Roaming\C2D06
:Commands
[purity]
[EMPTYFLASH]
[emptytemp]
[Reboot]



• Schliesse bitte nun alle Programme.
• Klicke nun bitte auf den Fix Button.
• OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
• Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren.
starte in den normalen modus.

falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden

öffne internet explorer, extras, internet optionen, dann verbindung, lanverbindung.
eintrag bei proxy und port löschen.
haken bei proxy verwenden raus.
übernehmen ok
internet explorer schließen.
öffne firefox, extras, erweitert, netzwerk.
eintrag bei proxy löschen, keinen proxy verwenden wählen, übernehmen ok
browser schließen, erneut öffnen.
öffne computer, öffne C: dann _OTL
dort rechtsklick auf moved files
wähle zu moved files.rar oder zip hinzufügen.
folge dem link, und lade das archiv im upload channel hoch
http://www.trojaner-board.de/54791-a...ner-board.html

cklemm 12.01.2012 20:46

Habe ich nun gemacht, nur folgendes geht nicht:

Zitat:

Zitat von markusg (Beitrag 753615)
hi
öffne computer, öffne C: dann _OTL
dort rechtsklick auf moved files
wähle zu moved files.rar oder zip hinzufügen.
folge dem link, und lade das archiv im upload channel hoch
http://www.trojaner-board.de/54791-a...ner-board.html



ich habe beim rechtsklick keine solche option.
geht das auch anders? z.B. mit Total Commander?

markusg 12.01.2012 20:52

hi
http://filepony.de/download-7-zip/
7zip instalieren, neustarten, wieder rechtsklick auf moved files, 7zip menü aufklappen, hinzufügen zu moved files.7zip

cklemm 12.01.2012 21:03

Hab ich gemacht !

markusg 12.01.2012 21:07

danke
Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich
ziehen und eine Bereinigung der Infektion noch erschweren.

Bitte downloade dir Combofix.exe und speichere es unbedingt auf deinem Desktop.
  • Besuche folgende Seite für Downloadlinks und Anweisungen für dieses
    Tool

    Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Hinweis:
    Gehe sicher das all deine Anti Virus und Anti Malware Programme abgeschalten sind, damit diese Combofix nicht bei der Arbeit stören.
  • Poste bitte die C:\Combofix.txt in deiner nächsten Antwort.

cklemm 12.01.2012 21:23

Ich bin jetzt ein wenig von den ständigen Warnungen vor combofix eingeschüchtert :D
Nur das ich nichts falsch mache : starten ohne vorher was einzustellen?

markusg 12.01.2012 21:32

ja, einfach doppelklicken, vorher alle aktieven programme aus, und anweisungen folgen.

cklemm 12.01.2012 21:56

Geschafft:

Combofix Logfile:
Code:

ComboFix 12-01-09.03 - Christian 12.01.2012  21:35:22.1.2 - x86 NETWORK
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3068.2536 [GMT 1:00]
ausgeführt von:: c:\users\Christian\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Christian\AppData\Roaming\Mozilla\Firefox\firefox.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\security\Database\tmp.edb
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-12-12 bis 2012-01-12  ))))))))))))))))))))))))))))))
.
.
2012-01-12 20:50 . 2012-01-12 20:50        --------        d-----w-        c:\users\Christian\AppData\Local\temp
2012-01-12 20:50 . 2012-01-12 20:50        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-01-12 19:56 . 2012-01-12 19:56        --------        d-----w-        c:\program files\7-Zip
2012-01-12 19:23 . 2012-01-12 19:57        --------        d-----w-        C:\_OTL
2012-01-12 15:45 . 2012-01-12 15:45        102400        ----a-w-        c:\users\Christian\AppData\Roaming\Microsoft\A776\F0.tmp
2012-01-11 15:24 . 2011-10-14 16:03        189952        ----a-w-        c:\windows\system32\winmm.dll
2012-01-11 15:24 . 2011-10-14 16:00        23552        ----a-w-        c:\windows\system32\mciseq.dll
2012-01-11 15:24 . 2011-11-18 20:23        1205064        ----a-w-        c:\windows\system32\ntdll.dll
2012-01-11 15:24 . 2011-11-18 17:47        66560        ----a-w-        c:\windows\system32\packager.dll
2012-01-11 15:24 . 2011-11-25 15:59        376320        ----a-w-        c:\windows\system32\winsrv.dll
2012-01-11 15:24 . 2011-12-01 15:21        2409784        ----a-w-        c:\program files\Windows Mail\OESpamFilter.dat
2012-01-11 15:24 . 2011-10-25 15:58        1314816        ----a-w-        c:\windows\system32\quartz.dll
2012-01-11 15:24 . 2011-10-25 15:58        497152        ----a-w-        c:\windows\system32\qdvd.dll
2012-01-10 13:22 . 2011-11-21 10:47        6823496        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{DD038849-FEB0-4727-A924-E519FF8285D2}\mpengine.dll
2011-12-24 18:18 . 2011-12-24 18:18        --------        d-----w-        c:\users\Christian\Musik
2011-12-22 21:16 . 2012-01-11 15:00        --------        d-----w-        c:\program files\Common Files\Steam
2011-12-22 21:16 . 2012-01-12 16:00        --------        d-----w-        c:\program files\Steam
2011-12-22 20:59 . 2011-12-22 21:07        --------        d-----w-        c:\users\Christian\AppData\Local\Ubisoft Game Launcher
2011-12-22 20:46 . 2006-12-08 11:02        251672        ----a-w-        c:\windows\system32\xactengine2_5.dll
2011-12-22 20:46 . 2006-11-29 12:06        440080        ----a-w-        c:\windows\system32\d3dx10.dll
2011-12-22 20:46 . 2007-03-05 11:42        15128        ----a-w-        c:\windows\system32\x3daudio1_1.dll
2011-12-22 20:46 . 2006-11-29 12:06        3426072        ----a-w-        c:\windows\system32\d3dx9_32.dll
2011-12-22 20:46 . 2006-09-28 15:05        237848        ----a-w-        c:\windows\system32\xactengine2_4.dll
2011-12-22 20:46 . 2006-09-28 15:05        2414360        ----a-w-        c:\windows\system32\d3dx9_31.dll
2011-12-22 20:46 . 2006-07-28 08:30        236824        ----a-w-        c:\windows\system32\xactengine2_3.dll
2011-12-22 20:46 . 2006-07-28 08:30        62744        ----a-w-        c:\windows\system32\xinput1_2.dll
2011-12-22 20:21 . 2011-12-22 20:44        --------        d-----w-        c:\program files\Ubisoft
2011-12-22 20:20 . 2011-12-22 20:20        --------        d--h--w-        c:\users\Christian\InstallAnywhere
2011-12-22 12:56 . 2009-03-18 16:35        26176        ---ha-w-        c:\windows\system32\hamachi.sys
2011-12-15 16:15 . 2011-10-27 08:01        3602816        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2011-12-15 16:15 . 2011-10-27 08:01        3550080        ----a-w-        c:\windows\system32\ntoskrnl.exe
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-24 13:29 . 2011-10-24 13:29        94208        ----a-w-        c:\windows\system32\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29        69632        ----a-w-        c:\windows\system32\QuickTime.qts
2011-10-22 11:21 . 2011-10-22 11:21        65536        ----a-w-        c:\windows\system32\frapsvid.dll
2011-11-13 08:49 . 2011-11-06 13:37        134104        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2009-05-20 177464]
"{e0007d18-baa4-4573-ae78-8bea0958c610}"= "c:\program files\P2P_Max_DE\tbP2P_.dll" [2009-07-15 2224152]
"{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"= "c:\program files\softonic-de3\tbsoft.dll" [2010-06-03 2736736]
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\tbWin1.dll" [2010-11-04 2735200]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
.
[HKEY_CLASSES_ROOT\clsid\{e0007d18-baa4-4573-ae78-8bea0958c610}]
.
[HKEY_CLASSES_ROOT\clsid\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
2010-11-04 12:06        2735200        ----a-w-        c:\program files\Winload\tbWin1.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}]
2010-06-03 16:24        2736736        ----a-w-        c:\program files\softonic-de3\tbsoft.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e0007d18-baa4-4573-ae78-8bea0958c610}]
2009-07-15 08:09        2224152        ----a-w-        c:\program files\P2P_Max_DE\tbP2P_.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2009-05-20 12:36        1258808        ----a-w-        c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-05-20 1258808]
"{e0007d18-baa4-4573-ae78-8bea0958c610}"= "c:\program files\P2P_Max_DE\tbP2P_.dll" [2009-07-15 2224152]
"{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"= "c:\program files\softonic-de3\tbsoft.dll" [2010-06-03 2736736]
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\tbWin1.dll" [2010-11-04 2735200]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{e0007d18-baa4-4573-ae78-8bea0958c610}]
.
[HKEY_CLASSES_ROOT\clsid\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-05-20 1258808]
"{E0007D18-BAA4-4573-AE78-8BEA0958C610}"= "c:\program files\P2P_Max_DE\tbP2P_.dll" [2009-07-15 2224152]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{e0007d18-baa4-4573-ae78-8bea0958c610}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-10-11 14940040]
"HW_OPENEYE_OUC_T-Mobile Internet Manager"="c:\program files\T-Mobile\T-Mobile Internet Manager\UpdateDog\ouc.exe" [2009-12-31 110592]
"Akamai NetSession Interface"="c:\users\Christian\AppData\Local\Akamai\netsession_win.exe" [2011-12-12 3305760]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Steam"="c:\program files\Steam\Steam.exe" [2011-12-22 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-12-04 1410344]
"DVDAgent"="c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2008-11-28 1148200]
"TSMAgent"="c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2008-12-25 1316136]
"CLMLServer for HP TouchSmart"="c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-12-25 189736]
"UCam_Menu"="c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2008-11-14 218408]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2008-11-18 914224]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-11-26 210216]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-10-10 206128]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-10-30 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-12-08 432432]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-05-20 111928]
"TVAgent"="c:\program files\Hewlett-Packard\Media\TV\TVAgent.exe" [2009-02-09 206120]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-01-08 450663]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-09-21 47904]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-01-07 1797488]
"DataCardMonitor"="c:\program files\T-Mobile\T-Mobile Internet Manager\DataCardMonitor.exe" [2011-08-01 253952]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
"OTL"="c:\users\Christian\Desktop\OTL(1).exe" [2012-01-12 584192]
.
c:\users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_c92065b9\aestsrv.exe [2009-01-13 77824]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - BMLoad
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
Akamai        REG_MULTI_SZ          Akamai
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 08:14        451872        ----a-w-        c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2012-01-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc6e61108ec1c0.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-30 16:54]
.
2012-01-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-30 16:54]
.
2012-01-05 c:\windows\Tasks\HPCeeScheduleForChristian.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2009-02-26 10:34]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://start.icq.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=127.0.0.1:52667
uSearchURL,(Default) = hxxp://de.search.yahoo.com/search?fr=mcafee&p=%s
IE: &AOL Toolbar-Suche - c:\programdata\AOL\ieToolbar\resources\de-DE\local\search.html
IE: Free YouTube to MP3 Converter - c:\users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Read By Natural Voice Reader - c:\program files\Natural Voice Reader Standard\read.html
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.3&q=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 52667
FF - prefs.js: network.proxy.type - 0
pref('extensions.shownSelectionUI',true); pref('extensions.autoDisableScopes',0);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKCU-Run-ICQ - ~c:\program files\ICQ7.2\ICQ.exe
HKCU-Run-Firefox helper - c:\users\Christian\AppData\Roaming\Mozilla\Firefox\firefox.exe
AddRemove-igLoader - c:\program files\igLoader\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-01-12 21:50
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  DataCardMonitor = c:\program files\T-Mobile\T-Mobile Internet Manager\DataCardMonitor.exe?2.tmp?Wi??P;H?????????????Q<A?????#?????????????????????:?P?G????;??????am Files\T-Mobile\T-Mobile Internet Manager\????c:\users????j???c:\Program Files\T-Mobile\T-Mobile Internet Mana
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_b427739.dll"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2012-01-12  21:53:58
ComboFix-quarantined-files.txt  2012-01-12 20:53
.
Vor Suchlauf: 13 Verzeichnis(se), 112.205.828.096 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 112.824.197.120 Bytes frei
.
- - End Of File - - B6B977961350EA8A76CE818DC3F2599F

--- --- ---

cklemm 12.01.2012 22:02

Ist es möglich jetzt eine "Pause" bis morgen zu machen?

Also ich meine:
-kann ich Energiesparmodus machen oder Herunterfahren
-bist du morgen wieder da? :)

markusg 13.01.2012 13:01

ja, war möglich :-)

öffne start programme zubehör editor reinkopieren:

Killall::
Folder::
c:\users\Christian\AppData\Roaming\Microsoft\A776


datei speichern unter, ort wo sich combofix.exe befindet, typ alle dateien, name
cfscript.txt
ziehe cfscript auf combofix, programm startet log posten

cklemm 13.01.2012 18:02

So bin nun wieder da.
Hier das Log:
Combofix Logfile:
Code:

ComboFix 12-01-09.03 - Christian 13.01.2012  15:23:18.1.2 - x86 NETWORK
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3068.2584 [GMT 1:00]
ausgeführt von:: c:\users\Christian\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Christian\Desktop\cfscript.txt
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Christian\AppData\Roaming\Microsoft\A776
c:\users\Christian\AppData\Roaming\Microsoft\A776\363C.tmp
c:\users\Christian\AppData\Roaming\Microsoft\A776\378B.tmp
c:\users\Christian\AppData\Roaming\Microsoft\A776\A30B.tmp
c:\users\Christian\AppData\Roaming\Microsoft\A776\B926.tmp
c:\users\Christian\AppData\Roaming\Microsoft\A776\F0.tmp
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-12-13 bis 2012-01-13  ))))))))))))))))))))))))))))))
.
.
2012-01-13 14:35 . 2012-01-13 14:40        --------        d-----w-        c:\users\Christian\AppData\Local\temp
2012-01-12 19:56 . 2012-01-12 19:56        --------        d-----w-        c:\program files\7-Zip
2012-01-12 19:23 . 2012-01-12 19:57        --------        d-----w-        C:\_OTL
2012-01-11 15:24 . 2011-10-14 16:03        189952        ----a-w-        c:\windows\system32\winmm.dll
2012-01-11 15:24 . 2011-10-14 16:00        23552        ----a-w-        c:\windows\system32\mciseq.dll
2012-01-11 15:24 . 2011-11-18 20:23        1205064        ----a-w-        c:\windows\system32\ntdll.dll
2012-01-11 15:24 . 2011-11-18 17:47        66560        ----a-w-        c:\windows\system32\packager.dll
2012-01-11 15:24 . 2011-11-25 15:59        376320        ----a-w-        c:\windows\system32\winsrv.dll
2012-01-11 15:24 . 2011-12-01 15:21        2409784        ----a-w-        c:\program files\Windows Mail\OESpamFilter.dat
2012-01-11 15:24 . 2011-10-25 15:58        1314816        ----a-w-        c:\windows\system32\quartz.dll
2012-01-11 15:24 . 2011-10-25 15:58        497152        ----a-w-        c:\windows\system32\qdvd.dll
2011-12-24 18:18 . 2011-12-24 18:18        --------        d-----w-        c:\users\Christian\Musik
2011-12-22 21:16 . 2012-01-11 15:00        --------        d-----w-        c:\program files\Common Files\Steam
2011-12-22 21:16 . 2012-01-12 16:00        --------        d-----w-        c:\program files\Steam
2011-12-22 20:59 . 2011-12-22 21:07        --------        d-----w-        c:\users\Christian\AppData\Local\Ubisoft Game Launcher
2011-12-22 20:46 . 2006-12-08 11:02        251672        ----a-w-        c:\windows\system32\xactengine2_5.dll
2011-12-22 20:46 . 2006-11-29 12:06        440080        ----a-w-        c:\windows\system32\d3dx10.dll
2011-12-22 20:46 . 2007-03-05 11:42        15128        ----a-w-        c:\windows\system32\x3daudio1_1.dll
2011-12-22 20:46 . 2006-11-29 12:06        3426072        ----a-w-        c:\windows\system32\d3dx9_32.dll
2011-12-22 20:46 . 2006-09-28 15:05        237848        ----a-w-        c:\windows\system32\xactengine2_4.dll
2011-12-22 20:46 . 2006-09-28 15:05        2414360        ----a-w-        c:\windows\system32\d3dx9_31.dll
2011-12-22 20:46 . 2006-07-28 08:30        236824        ----a-w-        c:\windows\system32\xactengine2_3.dll
2011-12-22 20:46 . 2006-07-28 08:30        62744        ----a-w-        c:\windows\system32\xinput1_2.dll
2011-12-22 20:21 . 2011-12-22 20:44        --------        d-----w-        c:\program files\Ubisoft
2011-12-22 20:20 . 2011-12-22 20:20        --------        d--h--w-        c:\users\Christian\InstallAnywhere
2011-12-22 12:56 . 2009-03-18 16:35        26176        ---ha-w-        c:\windows\system32\hamachi.sys
2011-12-15 16:15 . 2011-10-27 08:01        3602816        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2011-12-15 16:15 . 2011-10-27 08:01        3550080        ----a-w-        c:\windows\system32\ntoskrnl.exe
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:47 . 2012-01-10 13:22        6823496        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{DD038849-FEB0-4727-A924-E519FF8285D2}\mpengine.dll
2011-10-24 13:29 . 2011-10-24 13:29        94208        ----a-w-        c:\windows\system32\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29        69632        ----a-w-        c:\windows\system32\QuickTime.qts
2011-10-22 11:21 . 2011-10-22 11:21        65536        ----a-w-        c:\windows\system32\frapsvid.dll
2011-11-13 08:49 . 2011-11-06 13:37        134104        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2009-05-20 177464]
"{e0007d18-baa4-4573-ae78-8bea0958c610}"= "c:\program files\P2P_Max_DE\tbP2P_.dll" [2009-07-15 2224152]
"{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"= "c:\program files\softonic-de3\tbsoft.dll" [2010-06-03 2736736]
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\tbWin1.dll" [2010-11-04 2735200]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
.
[HKEY_CLASSES_ROOT\clsid\{e0007d18-baa4-4573-ae78-8bea0958c610}]
.
[HKEY_CLASSES_ROOT\clsid\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
2010-11-04 12:06        2735200        ----a-w-        c:\program files\Winload\tbWin1.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}]
2010-06-03 16:24        2736736        ----a-w-        c:\program files\softonic-de3\tbsoft.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e0007d18-baa4-4573-ae78-8bea0958c610}]
2009-07-15 08:09        2224152        ----a-w-        c:\program files\P2P_Max_DE\tbP2P_.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2009-05-20 12:36        1258808        ----a-w-        c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-05-20 1258808]
"{e0007d18-baa4-4573-ae78-8bea0958c610}"= "c:\program files\P2P_Max_DE\tbP2P_.dll" [2009-07-15 2224152]
"{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"= "c:\program files\softonic-de3\tbsoft.dll" [2010-06-03 2736736]
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\tbWin1.dll" [2010-11-04 2735200]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{e0007d18-baa4-4573-ae78-8bea0958c610}]
.
[HKEY_CLASSES_ROOT\clsid\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-05-20 1258808]
"{E0007D18-BAA4-4573-AE78-8BEA0958C610}"= "c:\program files\P2P_Max_DE\tbP2P_.dll" [2009-07-15 2224152]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{e0007d18-baa4-4573-ae78-8bea0958c610}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-10-11 14940040]
"HW_OPENEYE_OUC_T-Mobile Internet Manager"="c:\program files\T-Mobile\T-Mobile Internet Manager\UpdateDog\ouc.exe" [2009-12-31 110592]
"Akamai NetSession Interface"="c:\users\Christian\AppData\Local\Akamai\netsession_win.exe" [2011-12-12 3305760]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Steam"="c:\program files\Steam\Steam.exe" [2011-12-22 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-12-04 1410344]
"DVDAgent"="c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2008-11-28 1148200]
"TSMAgent"="c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2008-12-25 1316136]
"CLMLServer for HP TouchSmart"="c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-12-25 189736]
"UCam_Menu"="c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2008-11-14 218408]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2008-11-18 914224]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-11-26 210216]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-10-10 206128]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-10-30 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-12-08 432432]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-05-20 111928]
"TVAgent"="c:\program files\Hewlett-Packard\Media\TV\TVAgent.exe" [2009-02-09 206120]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-01-08 450663]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-09-21 47904]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-01-07 1797488]
"DataCardMonitor"="c:\program files\T-Mobile\T-Mobile Internet Manager\DataCardMonitor.exe" [2011-08-01 253952]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
"OTL"="c:\users\Christian\Desktop\OTL(1).exe" [2012-01-12 584192]
.
c:\users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_c92065b9\aestsrv.exe [2009-01-13 77824]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - BMLoad
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
Akamai        REG_MULTI_SZ          Akamai
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 08:14        451872        ----a-w-        c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2012-01-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc6e61108ec1c0.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-30 16:54]
.
2012-01-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-30 16:54]
.
2012-01-05 c:\windows\Tasks\HPCeeScheduleForChristian.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2009-02-26 10:34]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://start.icq.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=127.0.0.1:52667
uSearchURL,(Default) = hxxp://de.search.yahoo.com/search?fr=mcafee&p=%s
IE: &AOL Toolbar-Suche - c:\programdata\AOL\ieToolbar\resources\de-DE\local\search.html
IE: Free YouTube to MP3 Converter - c:\users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Read By Natural Voice Reader - c:\program files\Natural Voice Reader Standard\read.html
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.3&q=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 52667
FF - prefs.js: network.proxy.type - 0
pref('extensions.shownSelectionUI',true); pref('extensions.autoDisableScopes',0);
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2012-01-13 15:43
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  DataCardMonitor = c:\program files\T-Mobile\T-Mobile Internet Manager\DataCardMonitor.exe?2.tmp?Wi??P;H?????????????Q<A?????#?????????????????????:?P?G????;??????am Files\T-Mobile\T-Mobile Internet Manager\????c:\users????j???c:\Program Files\T-Mobile\T-Mobile Internet Mana
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_b427739.dll"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\helppane.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-01-13  15:47:32 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-01-13 14:47
ComboFix2.txt  2012-01-12 20:53
.
Vor Suchlauf: 18 Verzeichnis(se), 113.263.697.920 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 113.109.331.968 Bytes frei
.
- - End Of File - - CE260C860927E83106617F6E4F1A74C2

--- --- ---

markusg 13.01.2012 18:30

noch ne kleinigkeit vergessen.
start programme zubehör editor reinkopieren:

Killall::
DDS::
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=127.0.0.1:52667


datei speichern unter, ort, dort wo sich combofix.exe befindet, typ alle dateien, name
cfscript.txt
altes cfscript überschreiben.
wieder auf combofix ziehen, log posten.

cklemm 13.01.2012 19:07

Kann ich inzwischen wieder in den normalen Modus oder immernoch alles über den abgesicherten Modus?

Combofix Logfile:
Code:

ComboFix 12-01-09.03 - Christian 13.01.2012  18:41:28.1.2 - x86 NETWORK
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3068.2404 [GMT 1:00]
ausgeführt von:: c:\users\Christian\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Christian\Desktop\cfscript.txt
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-12-13 bis 2012-01-13  ))))))))))))))))))))))))))))))
.
.
2012-01-13 17:53 . 2012-01-13 17:56        --------        d-----w-        c:\users\Christian\AppData\Local\temp
2012-01-13 17:53 . 2012-01-13 17:53        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-01-12 19:56 . 2012-01-12 19:56        --------        d-----w-        c:\program files\7-Zip
2012-01-12 19:23 . 2012-01-12 19:57        --------        d-----w-        C:\_OTL
2012-01-11 15:24 . 2011-10-14 16:03        189952        ----a-w-        c:\windows\system32\winmm.dll
2012-01-11 15:24 . 2011-10-14 16:00        23552        ----a-w-        c:\windows\system32\mciseq.dll
2012-01-11 15:24 . 2011-11-18 20:23        1205064        ----a-w-        c:\windows\system32\ntdll.dll
2012-01-11 15:24 . 2011-11-18 17:47        66560        ----a-w-        c:\windows\system32\packager.dll
2012-01-11 15:24 . 2011-11-25 15:59        376320        ----a-w-        c:\windows\system32\winsrv.dll
2012-01-11 15:24 . 2011-12-01 15:21        2409784        ----a-w-        c:\program files\Windows Mail\OESpamFilter.dat
2012-01-11 15:24 . 2011-10-25 15:58        1314816        ----a-w-        c:\windows\system32\quartz.dll
2012-01-11 15:24 . 2011-10-25 15:58        497152        ----a-w-        c:\windows\system32\qdvd.dll
2011-12-24 18:18 . 2011-12-24 18:18        --------        d-----w-        c:\users\Christian\Musik
2011-12-22 21:16 . 2012-01-11 15:00        --------        d-----w-        c:\program files\Common Files\Steam
2011-12-22 21:16 . 2012-01-12 16:00        --------        d-----w-        c:\program files\Steam
2011-12-22 20:59 . 2011-12-22 21:07        --------        d-----w-        c:\users\Christian\AppData\Local\Ubisoft Game Launcher
2011-12-22 20:46 . 2006-12-08 11:02        251672        ----a-w-        c:\windows\system32\xactengine2_5.dll
2011-12-22 20:46 . 2006-11-29 12:06        440080        ----a-w-        c:\windows\system32\d3dx10.dll
2011-12-22 20:46 . 2007-03-05 11:42        15128        ----a-w-        c:\windows\system32\x3daudio1_1.dll
2011-12-22 20:46 . 2006-11-29 12:06        3426072        ----a-w-        c:\windows\system32\d3dx9_32.dll
2011-12-22 20:46 . 2006-09-28 15:05        237848        ----a-w-        c:\windows\system32\xactengine2_4.dll
2011-12-22 20:46 . 2006-09-28 15:05        2414360        ----a-w-        c:\windows\system32\d3dx9_31.dll
2011-12-22 20:46 . 2006-07-28 08:30        236824        ----a-w-        c:\windows\system32\xactengine2_3.dll
2011-12-22 20:46 . 2006-07-28 08:30        62744        ----a-w-        c:\windows\system32\xinput1_2.dll
2011-12-22 20:21 . 2011-12-22 20:44        --------        d-----w-        c:\program files\Ubisoft
2011-12-22 20:20 . 2011-12-22 20:20        --------        d--h--w-        c:\users\Christian\InstallAnywhere
2011-12-22 12:56 . 2009-03-18 16:35        26176        ---ha-w-        c:\windows\system32\hamachi.sys
2011-12-15 16:15 . 2011-10-27 08:01        3602816        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2011-12-15 16:15 . 2011-10-27 08:01        3550080        ----a-w-        c:\windows\system32\ntoskrnl.exe
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:47 . 2012-01-10 13:22        6823496        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{DD038849-FEB0-4727-A924-E519FF8285D2}\mpengine.dll
2011-10-24 13:29 . 2011-10-24 13:29        94208        ----a-w-        c:\windows\system32\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29        69632        ----a-w-        c:\windows\system32\QuickTime.qts
2011-10-22 11:21 . 2011-10-22 11:21        65536        ----a-w-        c:\windows\system32\frapsvid.dll
2011-11-13 08:49 . 2011-11-06 13:37        134104        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2009-05-20 177464]
"{e0007d18-baa4-4573-ae78-8bea0958c610}"= "c:\program files\P2P_Max_DE\tbP2P_.dll" [2009-07-15 2224152]
"{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"= "c:\program files\softonic-de3\tbsoft.dll" [2010-06-03 2736736]
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\tbWin1.dll" [2010-11-04 2735200]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
.
[HKEY_CLASSES_ROOT\clsid\{e0007d18-baa4-4573-ae78-8bea0958c610}]
.
[HKEY_CLASSES_ROOT\clsid\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
2010-11-04 12:06        2735200        ----a-w-        c:\program files\Winload\tbWin1.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}]
2010-06-03 16:24        2736736        ----a-w-        c:\program files\softonic-de3\tbsoft.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e0007d18-baa4-4573-ae78-8bea0958c610}]
2009-07-15 08:09        2224152        ----a-w-        c:\program files\P2P_Max_DE\tbP2P_.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2009-05-20 12:36        1258808        ----a-w-        c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-05-20 1258808]
"{e0007d18-baa4-4573-ae78-8bea0958c610}"= "c:\program files\P2P_Max_DE\tbP2P_.dll" [2009-07-15 2224152]
"{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}"= "c:\program files\softonic-de3\tbsoft.dll" [2010-06-03 2736736]
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\tbWin1.dll" [2010-11-04 2735200]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{e0007d18-baa4-4573-ae78-8bea0958c610}]
.
[HKEY_CLASSES_ROOT\clsid\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-05-20 1258808]
"{E0007D18-BAA4-4573-AE78-8BEA0958C610}"= "c:\program files\P2P_Max_DE\tbP2P_.dll" [2009-07-15 2224152]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{e0007d18-baa4-4573-ae78-8bea0958c610}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-10-11 14940040]
"HW_OPENEYE_OUC_T-Mobile Internet Manager"="c:\program files\T-Mobile\T-Mobile Internet Manager\UpdateDog\ouc.exe" [2009-12-31 110592]
"Akamai NetSession Interface"="c:\users\Christian\AppData\Local\Akamai\netsession_win.exe" [2011-12-12 3305760]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Steam"="c:\program files\Steam\Steam.exe" [2011-12-22 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-12-04 1410344]
"DVDAgent"="c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2008-11-28 1148200]
"TSMAgent"="c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2008-12-25 1316136]
"CLMLServer for HP TouchSmart"="c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-12-25 189736]
"UCam_Menu"="c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2008-11-14 218408]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2008-11-18 914224]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-11-26 210216]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-10-10 206128]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-10-30 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-12-08 432432]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-05-20 111928]
"TVAgent"="c:\program files\Hewlett-Packard\Media\TV\TVAgent.exe" [2009-02-09 206120]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-01-08 450663]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-09-21 47904]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-01-07 1797488]
"DataCardMonitor"="c:\program files\T-Mobile\T-Mobile Internet Manager\DataCardMonitor.exe" [2011-08-01 253952]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
"OTL"="c:\users\Christian\Desktop\OTL(1).exe" [2012-01-12 584192]
.
c:\users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_c92065b9\aestsrv.exe [2009-01-13 77824]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - BMLoad
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
Akamai        REG_MULTI_SZ          Akamai
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 08:14        451872        ----a-w-        c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2012-01-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc6e61108ec1c0.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-30 16:54]
.
2012-01-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-30 16:54]
.
2012-01-05 c:\windows\Tasks\HPCeeScheduleForChristian.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2009-02-26 10:34]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://start.icq.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
uSearchURL,(Default) = hxxp://de.search.yahoo.com/search?fr=mcafee&p=%s
IE: &AOL Toolbar-Suche - c:\programdata\AOL\ieToolbar\resources\de-DE\local\search.html
IE: Free YouTube to MP3 Converter - c:\users\Christian\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Read By Natural Voice Reader - c:\program files\Natural Voice Reader Standard\read.html
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\trj1lsez.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.3&q=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 52667
FF - prefs.js: network.proxy.type - 0
pref('extensions.shownSelectionUI',true); pref('extensions.autoDisableScopes',0);
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-01-13 18:59
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  DataCardMonitor = c:\program files\T-Mobile\T-Mobile Internet Manager\DataCardMonitor.exe?2.tmp?Wi??P;H?????????????Q<A?????#?????????????????????:?P?G????;??????am Files\T-Mobile\T-Mobile Internet Manager\????c:\users????j???c:\Program Files\T-Mobile\T-Mobile Internet Mana
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_b427739.dll"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2012-01-13  19:03:34 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-01-13 18:03
ComboFix2.txt  2012-01-13 14:47
ComboFix3.txt  2012-01-12 20:53
.
Vor Suchlauf: 18 Verzeichnis(se), 113.109.848.064 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 113.009.938.432 Bytes frei
.
- - End Of File - - 8466D01A1F6FA097285308407ECB0EF3

--- --- ---

markusg 13.01.2012 19:56

sollte gehen.

malwarebytes:
Downloade Dir bitte Malwarebytes
  • Installiere
    das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung --> Suche
    nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere vollständiger Scan durchführen und drücke auf Scannen.
  • Wenn der Scan beendet
    ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste
    das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.

cklemm 14.01.2012 10:18

Hab ich gemacht:

Code:

Malwarebytes Anti-Malware (Test) 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2012.01.13.04

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 7.0.6002.18005
Christian :: CHRISTIAN-PC [Administrator]

Schutz: Aktiviert

13.01.2012 20:10:16
mbam-log-2012-01-13 (20-10-16).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 586463
Laufzeit: 4 Stunde(n), 26 Minute(n), 9 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations|bak_Application (Hijacker.Application) -> Daten: hxxp://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations|Application (Hijacker.Application) -> Bösartig: (hxxp://www.helpmeopen.com/?n=app&ext=%s) Gut: (hxxp://shell.windows.com/fileassoc/%04x/xml/redir.asp?Ext=%s) -> Erfolgreich ersetzt und in Quarantäne gestellt.

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 8
C:\Users\Christian\Programme\wirelesskey\WirelessKeyView.exe (PUP.WirelessKeyView) -> Keine Aktion durchgeführt.
C:\Qoobox\Quarantine\C\Users\Christian\AppData\Roaming\Microsoft\A776\F0.tmp.vir (Trojan.Gbot) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\_OTL\MovedFiles\01122012_202353\C_Program Files\C2D06\lvvm.exe (Trojan.Gbot) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\_OTL\MovedFiles\01122012_202353\C_Programme\LP\A776\38B.exe (Trojan.Gbot) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\_OTL\MovedFiles\01122012_202353\C_Users\Christian\AppData\Roaming\firefox.exe (Trojan.Gbot) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\_OTL\MovedFiles\01122012_202353\C_Users\Christian\AppData\Roaming\606C2\B00A7.exe (Trojan.Gbot) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\_OTL\MovedFiles\01122012_202353\C_Users\Christian\AppData\Roaming\C2D06\lvvm.exe (Trojan.Gbot) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\_OTL\MovedFiles\01122012_202353\C_Users\Christian\AppData\Roaming\Microsoft\A776\38B.exe (Trojan.Gbot) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


markusg 14.01.2012 17:21

hi
lade den CCleaner standard:
CCleaner Download - CCleaner 3.14.1616
falls der CCleaner
bereits instaliert, überspringen.
instalieren, öffnen, extras, liste der instalierten programme, als txt speichern. öffnen.
hinter, jedes von dir benötigte programm, schreibe notwendig.
hinter, jedes, von dir nicht benötigte, unnötig.
hinter, dir unbekannte, unbekannt.
liste posten.

cklemm 14.01.2012 18:02

Ich habe übrigens noch ein kleines Problem:
jedes mal wenn ich firefox starte muss ich die Proxy einstellungen jedesmal neu ändern. Lässt sich das evtl dauerhaft einstellen?

Programmliste:

Code:

7-Zip 9.20                11.01.2012        3,54MB        notwendig
Activation Assistant for the 2007 Microsoft Office suites        Microsoft Corporation        24.04.2009        14,0MB        unbekannt       
Adobe Flash Player 10 ActiveX        Adobe Systems Incorporated        14.03.2010                10.0.45.2 notwendig
Adobe Flash Player 10 Plugin        Adobe Systems Incorporated        28.07.2011                10.3.181.34 notwendig
Adobe Photoshop CS2        Adobe Systems, Inc.        30.03.2011        218MB        9.0 unnötig
Adobe Reader 9.4.0 - Deutsch        Adobe Systems Incorporated        20.10.2010        164,2MB        9.4.0 notwendig
Adobe Shockwave Player 11.5        Adobe Systems, Inc.        14.03.2010        8,79MB        11.5.6.606 unbekannt
Akamai NetSession Interface                19.12.2011        5,68MB        unbekannt
Akamai NetSession Interface Service                09.11.2011        5,68MB        unbekannt
Amazing Slow Downer (remove only)                08.05.2009        2,55MB        notwendig
AMD USB Audio Driver Filter        Advanced Micro Devices, Inc.        24.04.2009        48,00KB        1.0.7.0031 unbekannt
AOL Toolbar 5.0        AOL LLC        24.04.2009        2,83MB        5.2.78.2 unbekannt
Apple Application Support        Apple Inc.        19.10.2011        61,2MB        2.1.5 unbekannt
Apple Mobile Device Support        Apple Inc.        19.10.2011        24,1MB        4.0.0.96 unbekannt
Apple Software Update        Apple Inc.        19.10.2011        2,38MB        2.1.3.127 notwendig
Atheros Driver Installation Program        Atheros        24.04.2009        1,07MB        5.0 unbekannt
ATI Catalyst Install Manager        ATI Technologies, Inc.        24.04.2009        13,7MB        3.0.708.0 unbekannt
Audacity 1.3.11 (Unicode)        Audacity Team        08.03.2010        34,3MB        notwendig
avast! Free Antivirus        AVAST Software        13.01.2012        239MB        6.0.1289.0 notwendig
AVS Update Manager 1.0        Online Media Technologies Ltd.        18.08.2009        9,55MB        unbekannt
AVS Video Converter 6        Online Media Technologies Ltd.        18.08.2009        22,9MB        unbekannt
AVS4YOU Software Navigator 1.3        Online Media Technologies Ltd.        18.08.2009        8,84MB        unbekannt
BitZipper 2010        Bitberry Software        27.11.2011        14,2MB        unnötig
Bonjour        Apple Inc.        19.10.2011        0,73MB        3.0.0.10 unbekannt
Bricx Command Center                12.06.2011        46,3MB        notwendig
CCleaner        Piriform        13.01.2012        4,13MB        3.14 notwendig
Clash N Slash 1.23        Enkord        02.02.2011        15,8MB        1.23 unnötig
Compatibility Pack für 2007 Office System        Microsoft Corporation        15.12.2011        64,0MB        12.0.6425.1000 unbekannt
ConvertHelper 2.2        DownloadHelper        15.02.2010        29,5MB        unbekannt
CyberLink DVD Suite        CyberLink Corp.        25.02.2009        16,6MB        6.0.2326 notwendig
DemonFlyFFv15        Ihr Firmenname        05.07.2010        2.590MB        1.36.0000 unnötig
Dev-C++ 5 beta 9 release (4.9.9.2)                21.09.2010 notwendig               
DivX Converter        DivX, Inc.        23.07.2010        45,3MB        7.1.0 unnötig
DivX Plus DirectShow Filters        DivX, Inc.        23.07.2010        1,58MB unbekannt       
DivX-Setup        DivX, Inc.        27.10.2010        2,09MB        2.1.2.2 unbekannt
Driver San Francisco        Ubisoft        21.12.2011        9.866MB        1.2.0.0 notwendig
FIFA Fussball-Weltmeisterschaft 2006 (TM)                08.11.2009        2.884MB        notwendig
Firebird SQL Server - MAGIX Edition        MAGIX AG        27.06.2010        6,22MB        2.0.1.13 notwendig
Fraps                11.12.2011                notwendig
Free iPod Video Converter 1.34        Jodix Technologies Ltd.        02.02.2010        5,35MB        unnötig
Free Natural Voice Text to Speech Reader        Natural Voices Readers        29.10.2010        11,3MB        2.9 unbekannt
Free NaturalReader        NaturalSoft Limited        29.10.2010        13,3MB        9.0 unbekannt
Free Video to Flash Converter version 4.1        DVDVideoSoft Limited.        06.06.2009        10,5MB        notwendig
Free YouTube to MP3 Converter version 3.10.11.923        DVDVideoSoft Ltd.        28.09.2011        2,21MB        notwendig
GIMP 2.6.8                24.04.2010        98,6MB        unnötig
Google Chrome        Google Inc.        29.07.2009        154,8MB        16.0.912.75 notwendig
Google Earth        Google        12.11.2011        92,8MB        6.1.0.5001 notwendig
Google SketchUp 7        Google, Inc.        24.04.2010        68,1MB        2.1.6863 unbekannt
HP Active Support Library        Hewlett-Packard        25.02.2009        20,5MB        3.1.9.1 unbekannt
HP Customer Experience Enhancements        Hewlett-Packard        25.02.2009        0,98MB        5.7.0.2664 unbekannt
HP Help and Support        Hewlett-Packard Company        25.02.2009        30,7MB        2.1.3.0 unbekannt
HP MediaSmart DVD        Hewlett-Packard        24.04.2009        48,8MB        2.1.2328 unbekannt
HP MediaSmart Music/Photo/Video        Hewlett-Packard        24.04.2009        223MB        2.1.2425 unbekannt
HP MediaSmart SmartMenu        Hewlett-Packard        24.04.2009        11,9MB        2.1.7 unbekannt
HP MediaSmart TV        Hewlett-Packard        14.09.2009        90,2MB        2.1.1409 unbekannt
HP MediaSmart Webcam        Hewlett-Packard        24.04.2009        73,5MB        2.1.1124 notwendig
HP Quick Launch Buttons 6.40 L1        Hewlett-Packard        25.02.2009        15,2MB        6.40 L1 notwendig
HP Total Care Advisor        Hewlett-Packard        25.02.2009        21,7MB        2.4.5479.2842  unbekannt
HP Total Care Setup        Hewlett-Packard Company        25.02.2009                1.1.2413.2876  unbekannt
HP Update        Hewlett-Packard        25.02.2009        3,80MB        4.000.013.003  unbekannt
HP User Guides 0126        Hewlett-Packard        25.02.2009        135,3MB        1.04.0000  unbekannt
HP Wireless Assistant        Hewlett-Packard        25.02.2009        3,43MB        3.50 A6 notwendigg
HyperCam 2                25.07.2009        1,41MB        unnötig
ICQ Toolbar        ICQ        05.07.2010                3.0.0 unnötig
ICQ7.2        ICQ        11.12.2010        47,3MB        7.2 notwendig
IDT Audio        IDT        24.04.2009        31,6MB        1.0.6087.22 unbekannt
iTunes        Apple Inc.        19.10.2011        168,7MB        10.5.0.142 notwendig
Java(TM) 6 Update 27        Sun Microsystems, Inc.        14.06.2010        97,2MB        6.0.270  unbekannt
JMicron Flash Media Controller Driver        JMicron Technology Corp.        24.04.2009        1,54MB        1.00.22.05  unbekannt
L&H TTS3000 Deutsch  unbekannt                29.10.2010               
LabelPrint        CyberLink Corp.        25.02.2009        241MB        2.5.1118  unbekannt
Lame ACM MP3 Codec                29.10.2010                unbekannt
Lernout & Hauspie TruVoice American English TTS Engine                29.10.2010 unbekannt               
LesefixPRO        Dr. Michael Schlesier        29.10.2010        23,5MB        8.00 unnötig
LightScribe System Software  1.14.17.1        LightScribe        24.04.2009        21,0MB        1.14.17.1  unbekannt
Logitech Touch Mouse Server 1.0        Logitech Inc.        27.01.2010        0,27MB        1.0  unbekannt
LuPO 1.0.2.41        Ministerium für Schule, Wissenschaft und Forschung NRW        07.03.2011        15,2MB notwendig       
MAGIX Music Maker for MySpace 15.0.1.8 (D)        MAGIX AG        27.06.2010        206MB        15.0.1.8c notwendig
Malwarebytes Anti-Malware Version 1.60.0.1800        Malwarebytes Corporation        12.01.2012        11,5MB        1.60.0.1800 notwendig
McAfee SiteAdvisor        McAfee, Inc.        10.01.2012        9,30MB        3.4.189 unnötig
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU        Microsoft Corporation        06.05.2009        37,0MB          unbekannt
Microsoft .NET Framework 3.5 SP1        Microsoft Corporation        06.05.2009        37,0MB        unbekannt
Microsoft .NET Framework 4 Client Profile        Microsoft Corporation        25.06.2010        120,3MB        4.0.30319 unbekannt
Microsoft .NET Framework 4 Client Profile DEU Language Pack        Microsoft Corporation        25.06.2010        24,5MB        4.0.30319 unbekannt
Microsoft IntelliPoint 8.0        Microsoft        27.02.2011        32,1MB        8.01.249.0 unbekannt
Microsoft Office Home and Student 2007        Microsoft Corporation        16.06.2010        297MB        12.0.6425.1000 unbekannt
Microsoft Office PowerPoint Viewer 2007 (German)        Microsoft Corporation        15.12.2011        89,0MB        12.0.6425.1000 unbekannt
Microsoft Office Professional Plus 2007        Microsoft Corporation        16.06.2010        561MB        12.0.6425.1000 unbekannt
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053        Microsoft Corporation        15.06.2010        0,24MB        8.0.50727.4053 unbekannt
Microsoft Visual C++ 2005 Redistributable        Microsoft Corporation        17.06.2011        0,29MB        8.0.56336 unbekannt
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570        Microsoft Corporation        26.04.2011        0,58MB        9.0.30729.5570 unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729        Microsoft Corporation        25.02.2009        0,58MB        9.0.30729 unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17        Microsoft Corporation        17.03.2011        0,22MB        9.0.30729 unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148        Microsoft Corporation        11.05.2010        0,58MB        9.0.30729.4148 unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161        Microsoft Corporation        17.06.2011        0,58MB        9.0.30729.6161 unbekannt
Microsoft Works        Microsoft Corporation        15.12.2010        378MB        9.7.0621 unbekannt
MobileMe Control Panel        Apple Inc.        19.10.2010        11,8MB        3.1.3.0 unbekannt
Mozilla Firefox 8.0 (x86 de)        Mozilla        12.11.2011        41,7MB        8.0 notwendig
MSXML 4.0 SP2 (KB954430)        Microsoft Corporation        06.05.2009        1,28MB        4.20.9870.0  unbekannt
MSXML 4.0 SP2 (KB973688)        Microsoft Corporation        25.11.2009        1,34MB        4.20.9876.0 unbekannt
muvee Reveal        muvee Technologies Pte Ltd        24.04.2009        152,9MB        7.0.35.6951 unbekannt
My HP Games        WildTangent        24.04.2009        205MB        1.0.0.62  unbekannt
Need for Speed™ Carbon                28.10.2011        4.995MB        unnötig
Need for Speed™ Most Wanted                06.03.2010        2.820MB unnötig       
Need For Speed™ World        Electronic Arts        23.10.2011        12,6MB        1.0.0.659 unnötig
Neffy 1,3,29,0        CDNetworks        30.05.2010        1,87MB        1,3,29,0  unbekannt
OpenOffice.org 3.2        OpenOffice.org        14.06.2010        379MB        3.2.9502 unnötig
P2P_Max_DE Toolbar                16.08.2009        2,34MB        unbekannt
Pinnacle VideoSpin        Pinnacle Systems        15.06.2010        188,8MB        2.0.0.669 unbekannt
Power2Go        CyberLink Corp.        25.02.2009        164,1MB        6.0.2325 unbekannt
PowerDirector        CyberLink Corp.        25.02.2009        467MB        7.0.2317 unbekannt
ProtectSmart Hard Drive Protection        Hewlett-Packard        24.04.2009        2,04MB        3.10 A7 unbekannt
QuickTime        Apple Inc.        31.10.2011        73,3MB        7.71.80.42 notwendig
RarZilla Free Unrar        Philipp Winterberg        10.07.2011        1,88MB        3.31 unbekannt
Realtek 8169 8168 8101E 8102E Ethernet Driver        Realtek        24.04.2009        2,02MB        1.00.0001 unbekannt
RollerCoaster Tycoon 2                14.07.2010        555MB        notwendig
Skype™ 5.0        Skype Technologies S.A.        07.12.2010        15,2MB        5.0.152 notwendig
softonic-de3 Toolbar        softonic-de3        29.10.2010        2,82MB        5.7.1.1 unnötig
SPORE Creature Creator Trial Edition        Electronic Arts        24.04.2009        1,86MB        1.00.0000 unbekannt
Steam        Valve        21.12.2011        42,1MB        1.0.0.0 unbekannt
Steganos Safe One        Steganos GmbH        30.06.2010        54,3MB        10.0.2 unbekannt
Stronghold 2 Deluxe        Firefly Studios        07.11.2009        1.178MB        1.30 notwendig
Sweet Home 3D version 2.3        eTeks        24.04.2010        99,1MB        unnötig
SweetIM for Messenger 2.7        SweetIM Technologies Ltd.        09.07.2009        3,69MB        2.7.0008 unbekannt
SweetIM Toolbar for Internet Explorer 3.4        SweetIM Technologies Ltd.        09.07.2009        2,98MB        3.4.0010 unnötig
Synaptics Pointing Device Driver        Synaptics        24.04.2009        16,1MB        12.1.0.0  unbekannt
T-Mobile Internet Manager        Huawei Technologies Co.,Ltd        31.07.2011        44,9MB        11.301.05.00.108 notwendig
TeamSpeak 3 Client        TeamSpeak Systems GmbH        06.08.2010        25,8MB        notwendig
TextAloud        NextUp.com        29.10.2010        6,42MB        2.0  unbekannt
TmNationsForever        Nadeo        26.02.2010        717MB        unbekannt
Total Commander (Remove or Repair)        Ghisler Software GmbH        28.05.2010        6,00MB        7.50a notwendig
TrueCrypt        TrueCrypt Foundation        30.06.2010        7,38MB        6.3a  unbekannt
Ubisoft Game Launcher        UBISOFT        21.12.2011        39,3MB        1.0.0.0 unbekannt
Uninstall 1.0.0.1                06.06.2009        15,7MB        unbekannt
Windows-Treiberpaket - ENE (enecir) HIDClass  (09/04/2008 2.6.0.0)        ENE        24.04.2009                09/04/2008 2.6.0.0 unbekannt
Winload Toolbar                29.10.2010        5,07MB        unnötig


markusg 14.01.2012 18:04

öffne mal firefox, dort auf extras einstellungen erweitert, netzwerk, dort eintrag bei proxy löschen, keinen proxy verwenden, übernehmen ok.


hi

dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user.
wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts.


• Starte bitte die OTL.exe
• Kopiere nun das Folgende in die Textbox.



Code:

:OTL
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 52667
FF - prefs.js..network.proxy.type: 1
 :Files
:Commands
[purity]
[EMPTYFLASH]
[emptytemp]
[Reboot]



• Schliesse bitte nun alle Programme.
• Klicke nun bitte auf den Fix Button.
• OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
• Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren.

cklemm 14.01.2012 18:08

Ich gehe auf Einstellungen > Einstellungen > Erweitert > Netzwerk > Einstellungen > lösche die Angeben und haken bei Keine Proxys und übernehme das.

Extras kann ich bei mir nicht finden.

Das mache ich jedesmal wenn ich Firefox neu starte, aber es stellt sich immerwieder zurück.

markusg 14.01.2012 18:09

schau mal, hab noch was editirt, füre das script mal aus.

cklemm 14.01.2012 19:12

Geht leider immernochnicht:

Code:

All processes killed
========== OTL ==========
Prefs.js: "127.0.0.1" removed from network.proxy.http
Prefs.js: 52667 removed from network.proxy.http_port
Prefs.js: 1 removed from network.proxy.type
========== COMMANDS ==========
 
[EMPTYFLASH]
 
User: All Users
 
User: Christian
->Flash cache emptied: 689 bytes
 
User: Default
 
User: Default User
 
User: Public
 
Total Flash Files Cleaned = 0,00 mb
 
 
[EMPTYTEMP]
 
User: All Users
 
User: Christian
->Temp folder emptied: 796843 bytes
->Temporary Internet Files folder emptied: 1323910 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 81542679 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1013234 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 81,00 mb
 
 
OTL by OldTimer - Version 3.2.31.0 log created on 01142012_181223

Files\Folders moved on Reboot...
C:\Users\Christian\AppData\Local\Temp\ehmsas.txt moved successfully.

Registry entries deleted on Reboot...


cklemm 14.01.2012 19:36

Ich habe nun selber eine Lösung für das Proxyproblem gefunden:

Ich habe unter "Kein Proxy verwänden für: ____" folgendes eingegeben: .net,.com,.at,.ch,.de, 127.0.0.1

also muss ich es nur ändern wenn ich auf eine Seite will die nicht auf .net, .com, .at, .ch oder .de endet :D

markusg 15.01.2012 17:28

das ist doch keine lösung. mach das wieder rückgängig damit wir sehen ob wir das problem lösen können.

firefox, extras ad-ons
plugins.
dort deaktiviere unnötigen, java und flash player sollten aktiv bleiben.
deinstaliere bei erweiterungen alle die du nicht benötigst
dann browser schließen, neustarten, proxy wie beschrieben konfigurieren, browser schließen, neustarten und testen was passiert.

cklemm 15.01.2012 17:37

Hat geklappt ! :daumenhoc

markusg 15.01.2012 17:50

endlich :-)
teste jetzt bitte ob alles wie gewünscht läuft, dann sichern wir den pc ab

cklemm 15.01.2012 18:45

Liste der Anhänge anzeigen (Anzahl: 1)
Also mir ist jetzt noch nichts aufgefallen..Also läuft alles wie gewohnt

Edit:
Mir ist gerade etwas aufgefallen: Eine Meldung von Malwarebytes: Sind Malwarebytes und Avast da nur aneinandergeraten, oder ist das bedenklich? (Screenshot im Anhang)

markusg 15.01.2012 20:48

poste mal die fundmeldung, sollte im protection log stehen

cklemm 16.01.2012 14:10

Das ist der von gestern:

Code:

2012/01/15 15:27:54 +0100        CHRISTIAN-PC        Christian        MESSAGE        Starting protection
2012/01/15 15:28:01 +0100        CHRISTIAN-PC        Christian        MESSAGE        Protection started successfully
2012/01/15 15:28:04 +0100        CHRISTIAN-PC        Christian        MESSAGE        Starting IP protection
2012/01/15 15:28:11 +0100        CHRISTIAN-PC        Christian        MESSAGE        IP Protection started successfully
2012/01/15 17:05:05 +0100        CHRISTIAN-PC        Christian        IP-BLOCK        174.120.244.218 (Type: outgoing, Port: 51492, Process: avastsvc.exe)
2012/01/15 17:05:05 +0100        CHRISTIAN-PC        Christian        IP-BLOCK        174.120.244.218 (Type: outgoing, Port: 51493, Process: avastsvc.exe)
2012/01/15 19:29:36 +0100        CHRISTIAN-PC        Christian        IP-BLOCK        212.95.32.106 (Type: outgoing, Port: 55352, Process: avastsvc.exe)
2012/01/15 19:29:36 +0100        CHRISTIAN-PC        Christian        IP-BLOCK        212.95.32.106 (Type: outgoing, Port: 55353, Process: avastsvc.exe)
2012/01/15 22:07:12 +0100        CHRISTIAN-PC        Christian        IP-BLOCK        89.28.2.100 (Type: outgoing, Port: 37531, Process: skype.exe)
2012/01/15 22:07:20 +0100        CHRISTIAN-PC        Christian        IP-BLOCK        89.28.2.100 (Type: outgoing, Port: 37531, Process: skype.exe)


markusg 16.01.2012 15:43

hi, das ist nen fehlalarm, nutzt du die malwarebytes test oder vollversion? falls du die testversion nutzt, solltest du den schutz (protection) im programm beenden können.

cklemm 16.01.2012 16:00

Jo hat geklappt.

markusg 16.01.2012 17:24

ok dann haben wirs

cklemm 16.01.2012 20:00

War jetzt noch was mit der Programm liste zu machen?

markusg 16.01.2012 20:15

ist unter gegangen basorry, hatte ich vergessen
deinstaliere:
Adobe Flash Player alle
Adobe - Adobe Flash Player installieren
neueste version laden
adobe reader:
Adobe - Adobe Reader herunterladen - Alle Versionen
haken bei mcafee security scan raus nehmen

bitte auch mal den adobe reader wie folgt konfigurieren:
adobe reader öffnen, bearbeiten, voreinstellungen.
allgemein:
nur zertifizierte zusatz module verwenden, anhaken.
internet:
hier sollte alles deaktiviert werden, es ist sehr unsicher pdfs automatisch zu öffnen, zu downloaden etc.
es ist immer besser diese direkt abzuspeichern da man nur so die kontrolle hat was auf dem pc vor geht.
bei javascript den haken bei java script verwenden raus nehmen
bei updater, automatisch instalieren wählen.
übernehmen /ok



deinstaliere:
Adobe Photoshop
Adobe Shockwave
Akamai beide
AOL Toolbar
AVS alle
BitZipper
Clash
ConvertHelper
DemonFlyFFv15
DivX alle
Free iPod
Free Natural beide
GIMP
Google SketchUp
HyperCam
ICQ Toolbar
Java
Download der kostenlosen Java-Software
downloade java jre, instalieren.

deinstaliere:
LabelPrint
Lernout
LesefixPRO
LightScribe
McAfee
Need For Speed™ alle
P2P_Max_DE
Pinnacle
RarZilla
softonic
SPORE
Steam
Steganos
Sweet Home
SweetIM beide
TmNationsForever
TrueCrypt
Winload

bereinige mit dem ccleaner, neustarten, testen ob alles läuft

cklemm 17.01.2012 19:25

Habe jetzt noch keine Mängel entdecken können !

markusg 17.01.2012 19:30

ok, pc absichern.
als antimalware programm würde ich emsisoft empfehlen.
diese haben für mich den besten schutz kostet aber etwas.
http://www.trojaner-board.de/103809-...i-malware.html
testversion:
Meine Antivirus-Empfehlung: Emsisoft Anti-Malware

und du kannst vor dem aktivieren der lizenz die 30 tage testzeitraum ausnutzen.

kostenlos, aber eben nicht ganz so gut wäre avast zu empfehlen.
http://www.trojaner-board.de/110895-...antivirus.html
sag mir welches du nutzt, dann gebe ich konfigurationshinweise.
bitte dein bisheriges av deinstalieren
die folgende anleitung ist umfangreich, dass ist mir klar, sie sollte aber umgesetzt werden, da nur dann dein pc sicher ist. stelle so viele fragen wie nötig, ich arbeite gern alles mit dir durch!

http://www.trojaner-board.de/96344-a...-rechners.html
Starte bitte mit der Passage, Windows Vista und Windows 7
Bitte beginne damit, Windows Updates zu instalieren.
Am besten geht dies, wenn du über Start, Suchen gehst, und dort Windows Updates eingibst.
Prüfe unter "Einstellungen ändern" dass folgendes ausgewählt ist:
- Updates automatisch Instalieren,
- Täglich
- Uhrzeit wählen
- Bitte den gesammten rest anhaken, außer:
- detailierte benachichtungen anzeigen, wenn neue Microsoft software verfügbar ist.
Klicke jetzt die Schaltfläche "OK"
Klicke jetzt "nach Updates suchen".
Bitte instaliere zunächst wichtige Updates.
Es wird nötig sein, den PC zwischendurch neu zu starten. falls dies der Fall ist, musst du erneut über Start, Suchen, Windows Update aufrufen, auf Updates suchen klicken und die nächsten instalieren.
Mache das selbe bitte mit den optionalen Updates.
Bitte übernimm den rest so, wie es im Abschnitt windows 7 / Vista zu lesen ist.
aus dem Abschnitt xp, bitte den punkt "datenausführungsverhinderung, dep" übernehmen.
als browser rate ich dir zu chrome:
https://www.google.com/chrome?hl=de
falls du nen andern nutzen willst, sags mir dann muss ich teile der nun folgenden anleitung


Sandboxie
Die devinition einer Sandbox ist hier nachzulesen:
Sandbox
Kurz gesagt, man kann Programme fast 100 %ig isuliert vom System ausführen.

Der Vorteil liegt klar auf der Hand, wenn über den Browser Schadcode eingeschläust wird, kann dieser nicht nach außen dringen.
Download Link:
http://filepony.de/download-sandboxie/
anleitung:
http://www.trojaner-board.de/71542-a...sandboxie.html
ausführliche anleitung als pdf, auch abarbeiten:
Sandbox Einstellungen |

bitte folgende zusatz konfiguration machen:
sandboxie control öffnen, menü sandbox anklicken, defauldbox wählen.
dort klicke auf sandbox einstellungen.
beschrenkungen, bei programm start und internet zugriff schreibe:
chrome.exe
dann gehe auf anwendungen, webbrowser, chrome.
dort aktiviere alles außer gesammten profil ordner freigeben.
Wie du evtl. schon gesehen hast, kannst du einige Funktionen nicht nutzen.
Dies ist nur in der Vollversion nötig, zu deren Kauf ich dir rate.
Du kannst zb unter "Erzwungene Programmstarts" festlegen, dass alle Browser in der Sandbox starten.
Ansonsten musst du immer auf "Sandboxed webbrowser" klicken bzw Rechtsklick, in Sandboxie starten.
Eine lebenslange Lizenz kostet 30 €, und ist auf allen deinen PC's nutzbar.

Weiter mit:
Maßnahmen für ALLE Windows-Versionen
alles komplett durcharbeiten
Backup Programm:
in meiner Anleitung ist bereits ein Backup Programm verlinkt, als Alternative bietet sich auch das Windows eigene Backup Programm an:
Windows 7 Systemabbild erstellen (Backup)
Dies ist aber leider nur für Windows 7 Nutzer vernünftig nutzbar.
Alle Anderen sollten sich aber auf jeden fall auch ein Backup Programm instalieren, denn dies kann unter Umständen sehr wichtig sein, zum Beispiel, wenn die Festplatte einmal kaputt ist.

Zum Schluss, die allgemeinen sicherheitstipps beachten, wenn es dich betrifft, den Tipp zum Onlinebanking beachten und alle Passwörter ändern
bitte auch lesen, wie mache ich programme für alle sichtbar:
Programme für alle Konten nutzbar machen - PCtipp.ch - Praxis & Hilfe
surfe jetzt also nur noch im standard nutzer konto und dort in der sandbox.
wenn du die kostenlose version nutzt, dann mit klick auf sandboxed web browser, wenn du die bezahlversion hast, kannst du erzwungene programm starts festlegen, dann wird sandboxie immer gestartet wenn du nen browser aufrufst.
wenn du mit der maus über den browser fährst sollte der eingerahmt sein, dann bist du im sandboxed web browser


Alle Zeitangaben in WEZ +1. Es ist jetzt 13:38 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129