Hallo Kira,
Dank für Deine schnelle Hilfe.
Ich habe seit dem BLUESCREEN statt firefox nur noch opera benutzt.
1. Run OTL:
OTL.TXT
OTL Logfile: Code:
OTL logfile created on: 27.05.2012 03:31:29 - Run 4
OTL by OldTimer - Version 3.2.43.1 Folder = C:\Users\s\Documents
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,87 Gb Total Physical Memory | 1,20 Gb Available Physical Memory | 41,59% Memory free
3,68 Gb Paging File | 2,07 Gb Available in Paging File | 56,30% Paging File free
Paging file location(s): c:\pagefile.sys 16 1024z:\pagefile.sys 900 920 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 39,11 Gb Total Space | 9,83 Gb Free Space | 25,14% Space Free | Partition Type: NTFS
Drive D: | 7,59 Gb Total Space | 0,65 Gb Free Space | 8,52% Space Free | Partition Type: NTFS
Drive E: | 1,55 Gb Total Space | 1,31 Gb Free Space | 84,21% Space Free | Partition Type: NTFS
Drive G: | 61,52 Gb Total Space | 0,38 Gb Free Space | 0,61% Space Free | Partition Type: NTFS
Drive H: | 39,27 Gb Total Space | 3,42 Gb Free Space | 8,71% Space Free | Partition Type: NTFS
Drive Z: | 1023,00 Mb Total Space | 122,99 Mb Free Space | 12,02% Space Free | Partition Type: FAT32
Computer Name: S-PC | User Name: a | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ==========
PRC - C:\Users\s\Documents\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\dradio-Recorder\phonostarTimer.exe ()
PRC - C:\Program Files\BatteryCare\BatteryCare.exe (Filipe Lourenço)
PRC - C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe (Nitro PDF Software)
PRC - C:\Program Files\Paragon Software\System Backup 2010 Kompakt\program\dbhservice.exe (Paragon Software Group)
PRC - C:\Program Files\Paragon Software\System Backup 2010 Kompakt\program\dbhagent.exe (Paragon Software Group)
PRC - C:\Users\s\progs\AutoHotkey104805\AutoHotkey.exe ()
PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
PRC - C:\Program Files\FRITZ!DSL\StCenter.exe (AVM Berlin)
PRC - \\?\C:\Windows\System32\wbem\WMIADAP.EXE ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\FRITZ!DSL\FwebProt.exe (AVM Berlin)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
PRC - C:\users\s\PROGS\VS\win\VS.EXE () ========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f3d4d5fe5ab848fbfcf91a49960dc8ae\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e4d54640bacd18e047a4573cb4611bd3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5d8696f15e49aedf883dd945806a7049\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll ()
MOD - C:\Program Files\dradio-Recorder\phonostarTimer.exe ()
MOD - C:\Users\s\progs\AutoHotkey104805\AutoHotkey.exe ()
MOD - C:\WINDOWS\System32\atitmmxx.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Configuration.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Configuration.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\users\s\PROGS\VS\win\VS.EXE ()
MOD - C:\users\s\PROGS\VS\win\VCHACK.DLL ()
MOD - C:\users\s\PROGS\VS\win\VSAPI.DLL () ========== Win32 Services (SafeList) ==========
SRV - (ZLMM) -- Z:\Temp\ZLMM.exe File not found
SRV - (VBPYZIXBOQ) -- Z:\Temp\VBPYZIXBOQ.exe File not found
SRV - (TOWPQ) -- Z:\Temp\TOWPQ.exe File not found
SRV - (SBSDWSCService) -- C:\Program Files\Spybot File not found
SRV - (RWSX) -- Z:\Temp\RWSX.exe File not found
SRV - (NHLQNS) -- Z:\Temp\NHLQNS.exe File not found
SRV - (MEXQD) -- Z:\Temp\MEXQD.exe File not found
SRV - (FOJDVGF) -- Z:\Temp\FOJDVGF.exe File not found
SRV - (EEYGQKZIUNYL) -- Z:\Temp\EEYGQKZIUNYL.exe File not found
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AfaService) -- C:\WINDOWS\System32\afasrv32.exe ()
SRV - (NitroReaderDriverReadSpool2) -- C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe (Nitro PDF Software)
SRV - (SbieSvc) -- C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV - (Paragon System Backup Dienst) -- C:\Program Files\Paragon Software\System Backup 2010 Kompakt\program\dbhservice.exe (Paragon Software Group)
SRV - (UI Assistant Service) -- C:\Program Files\Join Air\AssistantServices.exe ()
SRV - (bepldr6PixelPlanetService) -- C:\Program Files\Common Files\BCL Technologies\PixelPlanet6\bepldr.exe ()
SRV - (IGDCTRL) -- C:\Program Files\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (BcmSqlStartupSvc) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (pdfcDispatcher) -- C:\Program Files\PDF Complete\pdfsvc.exe (PDF Complete Inc)
SRV - (AgereModemAudio) -- C:\WINDOWS\System32\agrsmsvc.exe (Agere Systems)
SRV - (AEADIFilters) -- C:\WINDOWS\System32\AEADISRV.EXE (Andrea Electronics Corporation)
SRV - (IviRegMgr) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo) ========== Driver Services (SafeList) ==========
DRV - (VMnetAdapter) -- system32\DRIVERS\vmnetadapter.sys File not found
DRV - (VBoxNetFlt) -- system32\DRIVERS\VBoxNetFlt.sys File not found
DRV - (rootrepeal) -- C:\Windows\system32\drivers\rootrepeal.sys File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (hwdatacard) -- system32\DRIVERS\ewusbmdm.sys File not found
DRV - (blbdrive) -- C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (a9ry7opk) -- File not found
DRV - (avipbb) -- C:\WINDOWS\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\WINDOWS\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (sptd) -- C:\WINDOWS\System32\drivers\sptd.sys ()
DRV - (avkmgr) -- C:\WINDOWS\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (SbieDrv) -- C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV - (MHIKEY10) -- C:\WINDOWS\System32\drivers\MHIKEY10.sys (Generic USB smartcard reader)
DRV - (hotcore3) -- C:\WINDOWS\System32\drivers\hotcore3.sys (Paragon Software Group)
DRV - (CdaC15BA) -- C:\WINDOWS\System32\drivers\CDAC15BA.SYS ()
DRV - (VBoxNetAdp) -- C:\WINDOWS\System32\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV - (HBtnKey) -- C:\WINDOWS\System32\drivers\CPQBTTN.sys (Hewlett-Packard Company)
DRV - (R300) -- C:\WINDOWS\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) -- C:\WINDOWS\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (ZTEusbser6k) -- C:\WINDOWS\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) -- C:\WINDOWS\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) -- C:\WINDOWS\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) -- C:\WINDOWS\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (ssmdrv) -- C:\WINDOWS\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (Ser2pl) -- C:\WINDOWS\System32\drivers\ser2pl.sys (Prolific Technology Inc.)
DRV - (RRamdisk) -- C:\WINDOWS\System32\drivers\rramdisk.sys (gavotte)
DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (AgereSoftModem) -- C:\WINDOWS\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (KMWDFILTER) -- C:\WINDOWS\System32\drivers\KMWDFILTER.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (WinRing0_1_2_0) -- C:\Program Files\BatteryCare\WinRing0.sys (OpenLibSys.org)
DRV - (Ramdisk) -- C:\WINDOWS\System32\drivers\ramdisk.sys (Microsoft Corporation)
DRV - (SCR3XX2K) -- C:\WINDOWS\System32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (ATSWPDRV) (****DEBUG****) AuthenTec TruePrint USB Driver (SwipeSensor) -- C:\WINDOWS\System32\drivers\atswpdrv.sys (AuthenTec, Inc.)
DRV - (SSPORT) -- C:\WINDOWS\System32\drivers\SSPORT.SYS (Samsung Electronics)
DRV - (TPM) -- C:\WINDOWS\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (WimFltr) -- C:\WINDOWS\System32\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (AtiPcie) ATI PCI Express (3GIO) -- C:\WINDOWS\System32\drivers\AtiPcie.sys (ATI Technologies Inc.)
DRV - (DgiVecp) -- C:\WINDOWS\System32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=none&bd=smb&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=none&bd=smb&pf=laptop
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.hp.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.orbitdownloader.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (de)"
FF - prefs.js..browser.startup.homepage: "hxxp://google.de"
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@soft-xpansion/npsxpdf: C:\Program Files\Common Files\soft Xpansion\np-sxpdf.dll (soft Xpansion)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\NitroPDF: C:\Program Files\Nitro PDF\Reader 2\npnitromozilla.dll ( )
FF - HKCU\Software\MozillaPlugins\@phonostar.de/phonostar: C:\Program Files\dradio-Recorder\npphonostarDetectNP.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.05.15 17:50:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.05.14 01:59:32 | 000,000,000 | ---D | M]
[2010.07.22 14:16:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\a\AppData\Roaming\mozilla\Extensions
[2011.11.08 23:06:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\a\AppData\Roaming\mozilla\Firefox\Profiles\09iind3n.Standard-Benutzer\extensions
[2010.11.10 15:44:09 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\a\AppData\Roaming\mozilla\Firefox\Profiles\09iind3n.Standard-Benutzer\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.04.30 17:21:15 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\a\AppData\Roaming\mozilla\Firefox\Profiles\09iind3n.Standard-Benutzer\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.14 03:16:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\a\AppData\Roaming\mozilla\Firefox\Profiles\gdk6r6k0.default\extensions
[2010.08.09 14:01:01 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\a\AppData\Roaming\mozilla\Firefox\Profiles\gdk6r6k0.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.04.24 14:22:37 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\a\AppData\Roaming\mozilla\Firefox\Profiles\gdk6r6k0.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011.04.30 17:21:15 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\a\AppData\Roaming\mozilla\Firefox\Profiles\gdk6r6k0.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.15 17:50:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.05.14 03:16:42 | 000,000,000 | ---D | M] (OneClick YouTube Downloader) -- C:\PROGRAM FILES\ORBITDOWNLOADER\ADDONS\ONECLICKYOUTUBEDOWNLOADER
[2012.04.21 03:18:00 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.07.13 19:38:58 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012.04.21 03:54:08 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.04.21 03:54:08 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.04.21 03:54:08 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.04.21 03:54:08 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.04.21 03:54:08 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.04.21 03:54:08 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DBHAgent] C:\Program Files\Paragon Software\System Backup 2010 Kompakt\program\dbhagent.exe (Paragon Software Group)
O4 - HKCU..\Run: [BatteryCare] C:\Program Files\BatteryCare\BatteryCare.exe (Filipe Lourenço)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [dradio-Recorder] C:\Program Files\dradio-Recorder\phonostarStarter.exe ()
O4 - HKCU..\Run: [dradio-RecorderTimer] C:\Program Files\dradio-Recorder\phonostarTimer.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Users\a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ClipMagic.lnk = C:\Program Files\ClipMagic3.2.3\clipmagic.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 4
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAPower = 0
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Free YouTube Download - C:\Users\a\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\a\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: iMacros V7 - {602AB448-D389-4a54-B6A6-CE57AA0CCFC4} - C:\Program Files\iOpus\iMacros\iMacrosSidebar.dll ()
O9 - Extra 'Tools' menuitem : iMacros Web Automation - {602AB448-D389-4a54-B6A6-CE57AA0CCFC4} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\FRITZ!DSL\\sarah.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\FRITZ!DSL\sarah.dll (AVM Berlin)
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9C0A94B8-C110-4DAB-A31F-5D9A3ED781D1}: DhcpNameServer = 192.168.178.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\img17.jpg
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\img17.jpg
O32 - HKLM CDRom: AutoRun - 0
O32 - Unable to obtain root file information for disk D:\
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ==========
[2012.05.23 01:35:39 | 000,000,000 | ---D | C] -- C:\vslick
[2012.05.20 11:42:57 | 000,000,000 | ---D | C] -- C:\Users\a\AppData\Roaming\Runscanner.net
[2012.05.15 23:50:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012.05.15 17:50:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.05.15 17:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012.05.15 16:32:58 | 000,000,000 | ---D | C] -- C:\Program Files\SumatraPDF
[2012.05.15 16:31:45 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
[2012.05.15 16:27:36 | 000,000,000 | ---D | C] -- C:\Users\a\AppData\Local\Secunia PSI (BETA)
[2012.05.14 03:16:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Orbit
[2012.05.14 02:00:04 | 000,000,000 | ---D | C] -- C:\Users\a\AppData\Local\Seven Zip
[2012.05.13 20:45:23 | 000,000,000 | ---D | C] -- C:\Program Files\ZZattoo4
[2012.05.09 11:00:14 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2012.05.09 11:00:14 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2012.05.09 11:00:14 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2012.05.09 11:00:14 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2012.05.09 11:00:14 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2012.05.09 11:00:13 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012.05.09 11:00:12 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012.05.09 11:00:12 | 002,044,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[3 C:\*.tmp files -> C:\*.tmp -> ] ========== Files - Modified Within 30 Days ==========
[2012.05.27 03:33:54 | 000,658,316 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.05.27 03:33:54 | 000,614,264 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.05.27 03:33:54 | 000,151,598 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.05.27 03:33:54 | 000,116,030 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.05.27 03:31:15 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.05.27 03:26:21 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.05.27 03:26:21 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.05.27 03:26:15 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.05.27 02:28:31 | 000,001,088 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.05.15 23:50:40 | 000,001,015 | ---- | M] () -- C:\Users\a\Desktop\Spybot - Search & Destroy.lnk
[2012.05.15 17:50:21 | 000,000,806 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.05.15 16:35:06 | 000,000,819 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012.05.15 16:32:11 | 000,000,674 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2012.05.15 15:37:52 | 000,001,683 | ---- | M] () -- C:\Users\Public\Desktop\ClipMagic.lnk
[2012.05.14 12:57:51 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.05.14 12:57:51 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.05.14 12:01:50 | 000,439,064 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.05.14 03:16:43 | 000,000,848 | ---- | M] () -- C:\Users\a\Desktop\Orbit.lnk
[2012.05.08 14:31:09 | 004,140,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerInstaller.exe
[2012.05.08 13:30:00 | 000,137,928 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2012.05.08 13:30:00 | 000,083,392 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[3 C:\*.tmp files -> C:\*.tmp -> ] ========== Files Created - No Company Name ==========
[2012.05.15 23:50:40 | 000,001,015 | ---- | C] () -- C:\Users\a\Desktop\Spybot - Search & Destroy.lnk
[2012.05.15 16:33:01 | 000,001,674 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SumatraPDF.lnk
[2012.05.15 16:32:11 | 000,000,686 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2012.05.15 16:32:11 | 000,000,674 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2012.03.20 01:07:27 | 000,003,474 | ---- | C] () -- C:\Windows\System32\NANSI.SYS
[2012.03.11 22:13:38 | 000,112,128 | RH-- | C] () -- C:\Windows\CdaC14BA.DLL
[2012.03.11 22:13:38 | 000,030,720 | RH-- | C] () -- C:\Windows\CdaC13BA.EXE
[2012.02.24 23:23:17 | 000,017,408 | ---- | C] () -- C:\Users\a\AppData\Local\WebpageIcons.db
[2011.09.25 21:35:38 | 000,065,536 | ---- | C] () -- C:\Windows\System32\afasrv32.exe
[2011.09.19 22:51:16 | 000,821,182 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011.09.19 22:51:16 | 000,251,575 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011.06.28 14:18:31 | 000,006,808 | ---- | C] () -- C:\Windows\System32\HWACCESS.SYS
[2011.04.27 16:14:37 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.04.23 04:12:18 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010.12.19 17:56:19 | 000,004,608 | ---- | C] () -- C:\Users\a\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.11.25 17:15:19 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2010.10.14 02:24:08 | 000,000,880 | ---- | C] () -- C:\Windows\HBCIKRNL.INI
[2010.10.04 07:29:11 | 000,000,035 | ---- | C] () -- C:\Windows\Ulead32.INI
[2010.09.29 15:03:25 | 000,000,043 | ---- | C] () -- C:\Windows\gswin32.ini
[2010.09.23 11:12:36 | 000,029,752 | ---- | C] () -- C:\Windows\System32\oeminfo.ini
[2010.09.18 01:16:00 | 000,000,000 | ---- | C] () -- C:\Windows\PROTOCOL.INI
[2010.08.07 00:38:29 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010.07.16 11:09:05 | 000,000,089 | ---- | C] () -- C:\Users\a\AppData\Local\fusioncache.dat
[2010.07.09 15:49:14 | 002,648,064 | ---- | C] () -- C:\Windows\System32\dvmsg.dll
[2010.07.02 14:29:29 | 000,008,864 | ---- | C] () -- C:\Windows\System32\drivers\CDAC15BA.SYS
[2010.07.02 03:23:33 | 000,285,216 | ---- | C] () -- C:\Windows\System32\drivers\Onsio.sys
[2010.07.02 03:23:33 | 000,007,680 | ---- | C] () -- C:\Windows\System32\drivers\Onsreged.sys
[2010.06.21 03:06:57 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010.06.20 18:06:28 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010.06.20 18:06:28 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010.06.09 17:45:19 | 000,010,414 | ---- | C] () -- C:\Windows\recORDER.DLL
< End of report > --- --- ---
Extras.Txt
OTL Logfile: Code:
OTL logfile created on: 27.05.2012 03:31:29 - Run 4
OTL by OldTimer - Version 3.2.43.1 Folder = C:\Users\s\Documents
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,87 Gb Total Physical Memory | 1,20 Gb Available Physical Memory | 41,59% Memory free
3,68 Gb Paging File | 2,07 Gb Available in Paging File | 56,30% Paging File free
Paging file location(s): c:\pagefile.sys 16 1024z:\pagefile.sys 900 920 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 39,11 Gb Total Space | 9,83 Gb Free Space | 25,14% Space Free | Partition Type: NTFS
Drive D: | 7,59 Gb Total Space | 0,65 Gb Free Space | 8,52% Space Free | Partition Type: NTFS
Drive E: | 1,55 Gb Total Space | 1,31 Gb Free Space | 84,21% Space Free | Partition Type: NTFS
Drive G: | 61,52 Gb Total Space | 0,38 Gb Free Space | 0,61% Space Free | Partition Type: NTFS
Drive H: | 39,27 Gb Total Space | 3,42 Gb Free Space | 8,71% Space Free | Partition Type: NTFS
Drive Z: | 1023,00 Mb Total Space | 122,99 Mb Free Space | 12,02% Space Free | Partition Type: FAT32
Computer Name: S-PC | User Name: a | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ==========
PRC - C:\Users\s\Documents\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\dradio-Recorder\phonostarTimer.exe ()
PRC - C:\Program Files\BatteryCare\BatteryCare.exe (Filipe Lourenço)
PRC - C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe (Nitro PDF Software)
PRC - C:\Program Files\Paragon Software\System Backup 2010 Kompakt\program\dbhservice.exe (Paragon Software Group)
PRC - C:\Program Files\Paragon Software\System Backup 2010 Kompakt\program\dbhagent.exe (Paragon Software Group)
PRC - C:\Users\s\progs\AutoHotkey104805\AutoHotkey.exe ()
PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
PRC - C:\Program Files\FRITZ!DSL\StCenter.exe (AVM Berlin)
PRC - \\?\C:\Windows\System32\wbem\WMIADAP.EXE ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\FRITZ!DSL\FwebProt.exe (AVM Berlin)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
PRC - C:\users\s\PROGS\VS\win\VS.EXE () ========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f3d4d5fe5ab848fbfcf91a49960dc8ae\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e4d54640bacd18e047a4573cb4611bd3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5d8696f15e49aedf883dd945806a7049\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll ()
MOD - C:\Program Files\dradio-Recorder\phonostarTimer.exe ()
MOD - C:\Users\s\progs\AutoHotkey104805\AutoHotkey.exe ()
MOD - C:\WINDOWS\System32\atitmmxx.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Configuration.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Configuration.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\users\s\PROGS\VS\win\VS.EXE ()
MOD - C:\users\s\PROGS\VS\win\VCHACK.DLL ()
MOD - C:\users\s\PROGS\VS\win\VSAPI.DLL () ========== Win32 Services (SafeList) ==========
SRV - (ZLMM) -- Z:\Temp\ZLMM.exe File not found
SRV - (VBPYZIXBOQ) -- Z:\Temp\VBPYZIXBOQ.exe File not found
SRV - (TOWPQ) -- Z:\Temp\TOWPQ.exe File not found
SRV - (SBSDWSCService) -- C:\Program Files\Spybot File not found
SRV - (RWSX) -- Z:\Temp\RWSX.exe File not found
SRV - (NHLQNS) -- Z:\Temp\NHLQNS.exe File not found
SRV - (MEXQD) -- Z:\Temp\MEXQD.exe File not found
SRV - (FOJDVGF) -- Z:\Temp\FOJDVGF.exe File not found
SRV - (EEYGQKZIUNYL) -- Z:\Temp\EEYGQKZIUNYL.exe File not found
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AfaService) -- C:\WINDOWS\System32\afasrv32.exe ()
SRV - (NitroReaderDriverReadSpool2) -- C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe (Nitro PDF Software)
SRV - (SbieSvc) -- C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV - (Paragon System Backup Dienst) -- C:\Program Files\Paragon Software\System Backup 2010 Kompakt\program\dbhservice.exe (Paragon Software Group)
SRV - (UI Assistant Service) -- C:\Program Files\Join Air\AssistantServices.exe ()
SRV - (bepldr6PixelPlanetService) -- C:\Program Files\Common Files\BCL Technologies\PixelPlanet6\bepldr.exe ()
SRV - (IGDCTRL) -- C:\Program Files\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (BcmSqlStartupSvc) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (pdfcDispatcher) -- C:\Program Files\PDF Complete\pdfsvc.exe (PDF Complete Inc)
SRV - (AgereModemAudio) -- C:\WINDOWS\System32\agrsmsvc.exe (Agere Systems)
SRV - (AEADIFilters) -- C:\WINDOWS\System32\AEADISRV.EXE (Andrea Electronics Corporation)
SRV - (IviRegMgr) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo) ========== Driver Services (SafeList) ==========
DRV - (VMnetAdapter) -- system32\DRIVERS\vmnetadapter.sys File not found
DRV - (VBoxNetFlt) -- system32\DRIVERS\VBoxNetFlt.sys File not found
DRV - (rootrepeal) -- C:\Windows\system32\drivers\rootrepeal.sys File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (hwdatacard) -- system32\DRIVERS\ewusbmdm.sys File not found
DRV - (blbdrive) -- C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (a9ry7opk) -- File not found
DRV - (avipbb) -- C:\WINDOWS\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\WINDOWS\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (sptd) -- C:\WINDOWS\System32\drivers\sptd.sys ()
DRV - (avkmgr) -- C:\WINDOWS\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (SbieDrv) -- C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV - (MHIKEY10) -- C:\WINDOWS\System32\drivers\MHIKEY10.sys (Generic USB smartcard reader)
DRV - (hotcore3) -- C:\WINDOWS\System32\drivers\hotcore3.sys (Paragon Software Group)
DRV - (CdaC15BA) -- C:\WINDOWS\System32\drivers\CDAC15BA.SYS ()
DRV - (VBoxNetAdp) -- C:\WINDOWS\System32\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV - (HBtnKey) -- C:\WINDOWS\System32\drivers\CPQBTTN.sys (Hewlett-Packard Company)
DRV - (R300) -- C:\WINDOWS\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) -- C:\WINDOWS\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (ZTEusbser6k) -- C:\WINDOWS\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) -- C:\WINDOWS\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) -- C:\WINDOWS\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) -- C:\WINDOWS\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (ssmdrv) -- C:\WINDOWS\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (Ser2pl) -- C:\WINDOWS\System32\drivers\ser2pl.sys (Prolific Technology Inc.)
DRV - (RRamdisk) -- C:\WINDOWS\System32\drivers\rramdisk.sys (gavotte)
DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (AgereSoftModem) -- C:\WINDOWS\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (KMWDFILTER) -- C:\WINDOWS\System32\drivers\KMWDFILTER.sys (Windows (R) Codename Longhorn DDK provider)
DRV - (WinRing0_1_2_0) -- C:\Program Files\BatteryCare\WinRing0.sys (OpenLibSys.org)
DRV - (Ramdisk) -- C:\WINDOWS\System32\drivers\ramdisk.sys (Microsoft Corporation)
DRV - (SCR3XX2K) -- C:\WINDOWS\System32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (ATSWPDRV) (****DEBUG****) AuthenTec TruePrint USB Driver (SwipeSensor) -- C:\WINDOWS\System32\drivers\atswpdrv.sys (AuthenTec, Inc.)
DRV - (SSPORT) -- C:\WINDOWS\System32\drivers\SSPORT.SYS (Samsung Electronics)
DRV - (TPM) -- C:\WINDOWS\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (WimFltr) -- C:\WINDOWS\System32\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (AtiPcie) ATI PCI Express (3GIO) -- C:\WINDOWS\System32\drivers\AtiPcie.sys (ATI Technologies Inc.)
DRV - (DgiVecp) -- C:\WINDOWS\System32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=none&bd=smb&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=none&bd=smb&pf=laptop
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.hp.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.orbitdownloader.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (de)"
FF - prefs.js..browser.startup.homepage: "hxxp://google.de"
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@soft-xpansion/npsxpdf: C:\Program Files\Common Files\soft Xpansion\np-sxpdf.dll (soft Xpansion)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\NitroPDF: C:\Program Files\Nitro PDF\Reader 2\npnitromozilla.dll ( )
FF - HKCU\Software\MozillaPlugins\@phonostar.de/phonostar: C:\Program Files\dradio-Recorder\npphonostarDetectNP.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.05.15 17:50:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.05.14 01:59:32 | 000,000,000 | ---D | M]
[2010.07.22 14:16:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\a\AppData\Roaming\mozilla\Extensions
[2011.11.08 23:06:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\a\AppData\Roaming\mozilla\Firefox\Profiles\09iind3n.Standard-Benutzer\extensions
[2010.11.10 15:44:09 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\a\AppData\Roaming\mozilla\Firefox\Profiles\09iind3n.Standard-Benutzer\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.04.30 17:21:15 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\a\AppData\Roaming\mozilla\Firefox\Profiles\09iind3n.Standard-Benutzer\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.14 03:16:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\a\AppData\Roaming\mozilla\Firefox\Profiles\gdk6r6k0.default\extensions
[2010.08.09 14:01:01 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\a\AppData\Roaming\mozilla\Firefox\Profiles\gdk6r6k0.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.04.24 14:22:37 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\a\AppData\Roaming\mozilla\Firefox\Profiles\gdk6r6k0.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011.04.30 17:21:15 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Users\a\AppData\Roaming\mozilla\Firefox\Profiles\gdk6r6k0.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.15 17:50:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.05.14 03:16:42 | 000,000,000 | ---D | M] (OneClick YouTube Downloader) -- C:\PROGRAM FILES\ORBITDOWNLOADER\ADDONS\ONECLICKYOUTUBEDOWNLOADER
[2012.04.21 03:18:00 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.07.13 19:38:58 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012.04.21 03:54:08 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.04.21 03:54:08 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.04.21 03:54:08 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.04.21 03:54:08 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.04.21 03:54:08 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.04.21 03:54:08 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DBHAgent] C:\Program Files\Paragon Software\System Backup 2010 Kompakt\program\dbhagent.exe (Paragon Software Group)
O4 - HKCU..\Run: [BatteryCare] C:\Program Files\BatteryCare\BatteryCare.exe (Filipe Lourenço)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [dradio-Recorder] C:\Program Files\dradio-Recorder\phonostarStarter.exe ()
O4 - HKCU..\Run: [dradio-RecorderTimer] C:\Program Files\dradio-Recorder\phonostarTimer.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Users\a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ClipMagic.lnk = C:\Program Files\ClipMagic3.2.3\clipmagic.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 4
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAPower = 0
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Free YouTube Download - C:\Users\a\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\a\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: iMacros V7 - {602AB448-D389-4a54-B6A6-CE57AA0CCFC4} - C:\Program Files\iOpus\iMacros\iMacrosSidebar.dll ()
O9 - Extra 'Tools' menuitem : iMacros Web Automation - {602AB448-D389-4a54-B6A6-CE57AA0CCFC4} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\FRITZ!DSL\\sarah.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\FRITZ!DSL\sarah.dll (AVM Berlin)
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9C0A94B8-C110-4DAB-A31F-5D9A3ED781D1}: DhcpNameServer = 192.168.178.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\img17.jpg
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\img17.jpg
O32 - HKLM CDRom: AutoRun - 0
O32 - Unable to obtain root file information for disk D:\
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ==========
[2012.05.23 01:35:39 | 000,000,000 | ---D | C] -- C:\vslick
[2012.05.20 11:42:57 | 000,000,000 | ---D | C] -- C:\Users\a\AppData\Roaming\Runscanner.net
[2012.05.15 23:50:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012.05.15 17:50:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.05.15 17:50:20 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012.05.15 16:32:58 | 000,000,000 | ---D | C] -- C:\Program Files\SumatraPDF
[2012.05.15 16:31:45 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
[2012.05.15 16:27:36 | 000,000,000 | ---D | C] -- C:\Users\a\AppData\Local\Secunia PSI (BETA)
[2012.05.14 03:16:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Orbit
[2012.05.14 02:00:04 | 000,000,000 | ---D | C] -- C:\Users\a\AppData\Local\Seven Zip
[2012.05.13 20:45:23 | 000,000,000 | ---D | C] -- C:\Program Files\ZZattoo4
[2012.05.09 11:00:14 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2012.05.09 11:00:14 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2012.05.09 11:00:14 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2012.05.09 11:00:14 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2012.05.09 11:00:14 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2012.05.09 11:00:13 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012.05.09 11:00:12 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012.05.09 11:00:12 | 002,044,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[3 C:\*.tmp files -> C:\*.tmp -> ] ========== Files - Modified Within 30 Days ==========
[2012.05.27 03:33:54 | 000,658,316 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.05.27 03:33:54 | 000,614,264 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.05.27 03:33:54 | 000,151,598 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.05.27 03:33:54 | 000,116,030 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.05.27 03:31:15 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.05.27 03:26:21 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.05.27 03:26:21 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.05.27 03:26:15 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.05.27 02:28:31 | 000,001,088 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.05.15 23:50:40 | 000,001,015 | ---- | M] () -- C:\Users\a\Desktop\Spybot - Search & Destroy.lnk
[2012.05.15 17:50:21 | 000,000,806 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.05.15 16:35:06 | 000,000,819 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012.05.15 16:32:11 | 000,000,674 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2012.05.15 15:37:52 | 000,001,683 | ---- | M] () -- C:\Users\Public\Desktop\ClipMagic.lnk
[2012.05.14 12:57:51 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.05.14 12:57:51 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012.05.14 12:01:50 | 000,439,064 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.05.14 03:16:43 | 000,000,848 | ---- | M] () -- C:\Users\a\Desktop\Orbit.lnk
[2012.05.08 14:31:09 | 004,140,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerInstaller.exe
[2012.05.08 13:30:00 | 000,137,928 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2012.05.08 13:30:00 | 000,083,392 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[3 C:\*.tmp files -> C:\*.tmp -> ] ========== Files Created - No Company Name ==========
[2012.05.15 23:50:40 | 000,001,015 | ---- | C] () -- C:\Users\a\Desktop\Spybot - Search & Destroy.lnk
[2012.05.15 16:33:01 | 000,001,674 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SumatraPDF.lnk
[2012.05.15 16:32:11 | 000,000,686 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2012.05.15 16:32:11 | 000,000,674 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2012.03.20 01:07:27 | 000,003,474 | ---- | C] () -- C:\Windows\System32\NANSI.SYS
[2012.03.11 22:13:38 | 000,112,128 | RH-- | C] () -- C:\Windows\CdaC14BA.DLL
[2012.03.11 22:13:38 | 000,030,720 | RH-- | C] () -- C:\Windows\CdaC13BA.EXE
[2012.02.24 23:23:17 | 000,017,408 | ---- | C] () -- C:\Users\a\AppData\Local\WebpageIcons.db
[2011.09.25 21:35:38 | 000,065,536 | ---- | C] () -- C:\Windows\System32\afasrv32.exe
[2011.09.19 22:51:16 | 000,821,182 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011.09.19 22:51:16 | 000,251,575 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011.06.28 14:18:31 | 000,006,808 | ---- | C] () -- C:\Windows\System32\HWACCESS.SYS
[2011.04.27 16:14:37 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.04.23 04:12:18 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010.12.19 17:56:19 | 000,004,608 | ---- | C] () -- C:\Users\a\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.11.25 17:15:19 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2010.10.14 02:24:08 | 000,000,880 | ---- | C] () -- C:\Windows\HBCIKRNL.INI
[2010.10.04 07:29:11 | 000,000,035 | ---- | C] () -- C:\Windows\Ulead32.INI
[2010.09.29 15:03:25 | 000,000,043 | ---- | C] () -- C:\Windows\gswin32.ini
[2010.09.23 11:12:36 | 000,029,752 | ---- | C] () -- C:\Windows\System32\oeminfo.ini
[2010.09.18 01:16:00 | 000,000,000 | ---- | C] () -- C:\Windows\PROTOCOL.INI
[2010.08.07 00:38:29 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010.07.16 11:09:05 | 000,000,089 | ---- | C] () -- C:\Users\a\AppData\Local\fusioncache.dat
[2010.07.09 15:49:14 | 002,648,064 | ---- | C] () -- C:\Windows\System32\dvmsg.dll
[2010.07.02 14:29:29 | 000,008,864 | ---- | C] () -- C:\Windows\System32\drivers\CDAC15BA.SYS
[2010.07.02 03:23:33 | 000,285,216 | ---- | C] () -- C:\Windows\System32\drivers\Onsio.sys
[2010.07.02 03:23:33 | 000,007,680 | ---- | C] () -- C:\Windows\System32\drivers\Onsreged.sys
[2010.06.21 03:06:57 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010.06.20 18:06:28 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010.06.20 18:06:28 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010.06.09 17:45:19 | 000,010,414 | ---- | C] () -- C:\Windows\recORDER.DLL
< End of report > --- --- ---
2. Run ccleaner Code:
7sDoc-lite 1.3.0 SVA-software 14.03.2012 4,43 MB
ABBYY FineReader 5.0 Pro ABBYY Software House 01.07.2010 151,1 MB 5.0
ABBYY FineReader 5.0 Sprint ABBYY Software House 01.07.2010 294 MB 5.0.0.3347
ABBYY FineReader OCR Engine für Tevion 01.07.2010 272 MB
Adobe Flash Player 11 ActiveX Adobe Systems Incorporated 07.05.2012 11.2.202.235
Adobe Flash Player 11 Plugin Adobe Systems Incorporated 13.05.2012 11.2.202.235
Agere Systems HDA Modem LSI Corporation 14.03.2009 16,00 KB
Application Installer 4.00.B14 Hewlett-Packard Company 02.03.2009 0,89 MB 4.00.B14
ASIO4ALL Michael Tippach 06.09.2010 0,52 MB 2.10
ATI Catalyst Install Manager ATI Technologies, Inc. 26.04.2011 13,8 MB 3.0.715.0
ATI Uninstaller ATI Technologies, Inc. 02.03.2009 13,9 MB
Avanquest update Avanquest Software 04.02.2012 2,79 MB 1.30
Avira Free Antivirus Avira 07.05.2012 99,6 MB 12.0.0.1125
AVM FRITZ!DSL AVM Berlin 12.07.2010 11,2 MB 2.04.03
BatteryCare 0.9.8.10 Filipe Lourenço 13.06.2011 3,10 MB 0.9.8.10
Browser Mouse 22.06.2010 2,01 MB
Business Contact Manager für Outlook 2007 SP2 Microsoft Corporation 01.06.2010 31,4 MB 3.0.8619.1
Cda Product Service - shared component 10.03.2012
CHIPDRIVE Smartcard Commander SCM Microsystems 13.10.2010 21,6 MB
Chipkartenleser 17.09.2010 2,97 MB
ClipMagic 3.2.3 MJT Net Ltd 02.09.2011 1,39 MB 4.1
DAEMON Tools Lite DT Soft Ltd 15.10.2011 24,2 MB 4.41.3.0173
dradio-Recorder Version 3.02.5 03.04.2012 34,7 MB
DSL-Turbo FRANZIS Verlag 07.10.2011 3,36 MB
ESU for Microsoft Vista Hewlett-Packard 29.06.2007 3,78 MB 1.0.10.1
EVEREST Home Edition v2.20 Lavalys Inc 28.03.2012 6,58 MB 2.20
Feedback Tool Microsoft Corporation 19.06.2011 2,28 MB 1.2.0
Flash Memory Toolkit trial 2.01 EFD Software 11.10.2011 3,30 MB
fortePivot LG Soft India 11.08.2010 2,16 MB 3.04
Foxit Creator Foxit Corporation 16.02.2011 3,1,0,1210
Foxit Reader Foxit Corporation 12.07.2011 11,6 MB 4.3.1.323
Free Studio version 5.0.9 DVDVideoSoft Limited. 29.04.2011 173,0 MB
Gadwin PrintScreen Gadwin Systems, Inc. 17.05.2011 3,50 MB 4.6
Google Earth Plug-in Google 16.11.2011 40,9 MB 6.1.0.5001
GPL Ghostscript Artifex Software Inc. 11.06.2011 31,1 MB 9.02
GSview 4.9 11.06.2011 3,23 MB
HD Tune 2.55 EFD Software 04.11.2010 1,27 MB
HP BIOS Configuration for ProtectTools Hewlett-Packard 29.06.2007 2,56 MB 3.00 C1
HP Customer Experience Enhancements Hewlett-Packard 29.06.2007 5.0.0.2258
HP Easy Setup - Core Hewlett-Packard 29.06.2007 1,02 MB 5.0.0.2258
HP Easy Setup - Frontend Hewlett-Packard 29.06.2007 1,44 MB 5.0.0.2258
HP Help and Support Hewlett-Packard 29.06.2007 20,9 MB 1.0.0
HP Help and Support HPQ 22.09.2010 0,35 MB 4.4.0002
HP Notebook Accessories Product Tour Hewlett-Packard 29.06.2007 10,1 MB 13.0.0
HP ProtectTools Security Manager Hewlett-Packard 29.06.2007 7,10 MB 3.00 A10
HP Quick Launch Buttons Hewlett-Packard Company 03.11.2011 32,9 MB 6.50.14.1
HP SoftPaq Download Manager Hewlett-Packard Company 30.06.2010 14,7 MB 3.0.5.0
HP Update Hewlett-Packard 30.06.2010 2,97 MB 5.002.006.003
HP Wireless Assistant Hewlett-Packard 29.06.2007 3,94 MB 3.00 F1
iMacros Version 7.5.1.1734 iOpus 04.11.2011 16,3 MB 7.5.1.1734
InterVideo DVD Check 02.03.2009 0,18 MB
InterVideo WinDVD InterVideo Inc. 02.03.2009 46,1 MB 5.0-B11.1164
Java(TM) 6 Update 26 Oracle 12.07.2011 97,1 MB 6.0.260
Java(TM) SE Runtime Environment 6 Sun Microsystems, Inc. 29.06.2007 115,2 MB 1.6.0.0
Join Air ZTE Corporation 23.12.2010 22,6 MB 1.0.0.2
LightScribe System Software 1.10.16.1 hxxp://www.lightscribe.com 29.07.2010 19,2 MB 1.10.16.1
Malwarebytes' Anti-Malware Version 1.51.2.1300 Malwarebytes Corporation 27.11.2011 3,90 MB 1.51.2.1300
Microsoft .NET Framework 1.1 14.03.2009
Microsoft .NET Framework 1.1 German Language Pack Microsoft 29.06.2007 3,02 MB 1.1.4322
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft Corporation 01.06.2010 37,0 MB
Microsoft .NET Framework 3.5 SP1 Microsoft Corporation 14.03.2009 37,0 MB
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 26.06.2010 120,3 MB 4.0.30319
Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Corporation 26.06.2010 24,5 MB 4.0.30319
Microsoft SQL Server 2005 Microsoft Corporation 03.06.2010 221 MB
Microsoft SQL Server Native Client Microsoft Corporation 30.05.2011 2,63 MB 9.00.5000.00
Microsoft SQL Server VSS Writer Microsoft Corporation 30.05.2011 0,68 MB 9.00.5000.00
Microsoft Tool Web Package:Diruse.exe Microsoft Corporation 31.08.2010 48,00 KB 1.0.0.1
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Corporation 01.06.2010 0,25 MB 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 15.06.2011 0,29 MB 8.0.61001
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Corporation 07.06.2011 0,58 MB 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Corporation 30.05.2011 1,41 MB 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Corporation 12.07.2010 0,23 MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 31.05.2010 0,58 MB 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 15.06.2011 0,58 MB 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 23.10.2011 11,1 MB 10.0.40219
Microsoft Windows Performance Toolkit Microsoft Corporation 06.09.2010 19,7 MB 4.6.0
Mozilla Firefox 12.0 (x86 de) Mozilla 14.05.2012 69,7 MB 12.0
Mozilla Maintenance Service Mozilla 14.05.2012 0,21 MB 12.0
MSCU for Microsoft Vista Hewlett-Packard 29.06.2007 72,9 MB 1.0.1.3
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 14.03.2009 1,28 MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 01.06.2010 1,34 MB 4.20.9876.0
Multimedia keyboard utility 22.06.2010 1,91 MB
MyDefrag v4.3.1 J.C. Kessels 23.06.2010 3,34 MB 4.0.0.0
Nero 8 Essentials Nero AG 29.07.2010 1.632 MB 8.10.135
Nitro PDF Reader 2 Nitro PDF Software 13.09.2011 84,6 MB 2.0.0.29
Opera 10.51 Opera Software ASA 14.05.2012 28,2 MB 10.51
Orbit Downloader www.orbitdownloader.com 13.05.2012 12,8 MB
Paragon Partition Manager™ 11 Free Edition Paragon Software 26.06.2010 45,1 MB 90.00.0003
Paragon System Backup 2010 Kompakt Paragon Software 02.12.2010 111,0 MB 90.00.0003
PDF Complete 02.03.2009 24,8 MB
PdfGrabber 6.0 PixelPlanet 28.09.2010 66,5 MB 6.0.0.0
PL-2303 USB-to-Serial 17.09.2010 1,02 MB
Riot - Radical Image Optimization Tool 10.10.2011 1,25 MB
Roxio Creator Audio Roxio 29.06.2007 1,09 MB 3.3.0
Roxio Creator Basic v9 Roxio 29.06.2007 20,6 MB 3.3.0
Roxio Creator Copy Roxio 29.06.2007 0,63 MB 3.3.0
Roxio Creator Data Roxio 29.06.2007 0,96 MB 3.3.0
Roxio Creator Tools Roxio 29.06.2007 0,34 MB 3.3.0
Roxio Express Labeler 3 Roxio 29.06.2007 16,3 MB 2.1.0
Roxio MyDVD Basic v9 Roxio 29.06.2007 297 MB 9.0.116
Sandboxie 3.54 (32-bit) 17.05.2011 3,14 MB
ScanWizard 5 01.07.2010 3,45 MB
SCR3xxx Smart Card Reader SCM Microsystems 13.10.2010 3,06 MB 8.30
Security Task Manager 1.8d Neuber Software 03.11.2011 2,75 MB 1.8d
SlickEdit 11.0.0 04.07.2010 120,5 MB
soft Xpansion Perfect PDF 7 Reader soft Xpansion 29.04.2011 22,7 MB 7.0.9.6
SoundMAX Analog Devices 29.06.2007 56,00 KB 6.10.1.5180
Spybot - Search & Destroy Safer Networking Limited 14.05.2012 52,5 MB 1.6.2
SSH Secure Shell 20.06.2010 0,84 MB
ST Wiederherstellungs- & Sicherungsprogramme Hewlett-Packard Company 29.06.2007 18.775 MB 4.0.14
Streamripper (Remove only) 01.03.2011 6,30 MB
StreamTransport version: 1.0.2.2171 23.04.2012 5,36 MB
SumatraPDF Krzysztof Kowalczyk 14.05.2012 8,52 MB 1.6
Synaptics Pointing Device Driver Synaptics Incorporated 03.11.2011 32,8 MB 15.0.24.0
Uninstall 1.0.0.1 29.04.2011 62,8 MB
Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) Microsoft Corporation 30.05.2011 30,6 MB 9.00.5000.00
USIM Editor 1.0.25.0 24.09.2011 17,3 MB
Vista Default Settings Hewlett-Packard 29.06.2007 0,27 MB 1.0.5.1
VLC media player 2.0.1 VideoLAN 03.04.2012 75,9 MB 2.0.1
Winamp Nullsoft, Inc 01.03.2011 39,4 MB 5.601
Winamp Erkennungs-Plug-in Nullsoft, Inc 01.03.2011 0,15 MB 1.0.0.1
Windows Installer Clean Up Microsoft Corporation 12.02.2011 0,30 MB 3.00.00.0000
WinFuture xp-Iso-Builder 3.0.7 Tobias Schiek 14.06.2010 3,69 MB
Xvid MPEG-4 Video Codec Xvid Development Team 19.09.2011 3. Run HijackThis (alle Fenster gechlossen)
HijackThis.log
[code]
HiJackthis Logfile: Code:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 03:57:03, on 27.05.2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Paragon Software\System Backup 2010 Kompakt\program\dbhagent.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\BatteryCare\BatteryCare.exe
C:\Program Files\dradio-Recorder\phonostarTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\s\progs\AutoHotkey104805\AutoHotkey.exe
C:\Program Files\FRITZ!DSL\FwebProt.exe
C:\Program Files\FRITZ!DSL\StCenter.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\WINDOWS\System32\cmd.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\Taskmgr.exe
C:\Users\s\Documents\OTL.exe
C:\Users\s\Documents\HiJackThis204.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.hp.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.orbitdownloader.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=none&bd=smb&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=none&bd=smb&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [DBHAgent] C:\Program Files\Paragon Software\System Backup 2010 Kompakt\program\dbhagent.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [dradio-RecorderTimer] C:\Program Files\dradio-Recorder\phonostarTimer.exe
O4 - HKCU\..\Run: [dradio-Recorder] C:\Program Files\dradio-Recorder\phonostarStarter.exe
O4 - HKCU\..\Run: [BatteryCare] C:\Program Files\BatteryCare\BatteryCare.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-21-2902011239-2132124238-3506956372-1006\..\Run: [] (User 's')
O4 - HKUS\S-1-5-18\..\Run: [FRITZ!protect] FwebProt.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [FRITZ!protect] FwebProt.exe (User 'Default user')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 Startup: AutoHotkey1.lnk = C:\Users\s\progs\AutoHotkey104805\AutoHotkey.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 Startup: Blau.lnk = D:\Windows\System32\cmd.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 Startup: Command Prompt.lnk = D:\Windows\System32\cmd.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 Startup: FRITZ!DSL Protect.lnk = C:\Program Files\FRITZ!DSL\FwebProt.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 Startup: FRITZ!DSL Startcenter.lnk = C:\Program Files\FRITZ!DSL\StCenter.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 Startup: Gelb.lnk = D:\Windows\System32\cmd.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 Startup: Grün.lnk = D:\Windows\System32\cmd.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 Startup: Rot.lnk = D:\Windows\System32\cmd.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 User Startup: AutoHotkey1.lnk = C:\Users\s\progs\AutoHotkey104805\AutoHotkey.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 User Startup: Blau.lnk = D:\Windows\System32\cmd.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 User Startup: Command Prompt.lnk = D:\Windows\System32\cmd.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 User Startup: FRITZ!DSL Protect.lnk = C:\Program Files\FRITZ!DSL\FwebProt.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 User Startup: FRITZ!DSL Startcenter.lnk = C:\Program Files\FRITZ!DSL\StCenter.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 User Startup: Gelb.lnk = D:\Windows\System32\cmd.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 User Startup: Grün.lnk = D:\Windows\System32\cmd.exe (User 's')
O4 - S-1-5-21-2902011239-2132124238-3506956372-1006 User Startup: Rot.lnk = D:\Windows\System32\cmd.exe (User 's')
O4 - Startup: ClipMagic.lnk = C:\Program Files\ClipMagic3.2.3\clipmagic.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: Free YouTube Download - C:\Users\a\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\a\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: iMacros V7 - {602AB448-D389-4a54-B6A6-CE57AA0CCFC4} - C:\Program Files\iOpus\iMacros\iMacrosSidebar.dll
O9 - Extra 'Tools' menuitem: iMacros Web Automation - {602AB448-D389-4a54-B6A6-CE57AA0CCFC4} - C:\Program Files\iOpus\iMacros\iMacrosSidebar.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Afa Card Reader Service (AfaService) - Unknown owner - C:\Windows\system32\afasrv32.exe
O23 - Service: Avira Planer (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Echtzeit Scanner (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: AVM IGD CTRL Service (IGDCTRL) - AVM Berlin - C:\Program Files\FRITZ!DSL\IGDCTRL.EXE
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NitroPDFReaderDriverCreatorReadSpool2 (NitroReaderDriverReadSpool2) - Nitro PDF Software - C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe
O23 - Service: Paragon System Backup Dienst - Paragon Software Group - C:\Program Files\Paragon Software\System Backup 2010 Kompakt\program\dbhservice.exe
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
--
End of file - 9408 bytes --- --- ---
Ist viel für Dich zu lesen und zu checken.
PS:
Ist es richtig, dass Trojaner / Viren mit portablen nichts anfangen können
oder es sich für Mafia&Co nicht lohnt, weil viel einfacher
in die Reg raffinierte Einträge zu plazieren?
Habe 1971 mit einer 360/44 (Kernspeicher auf 256 kB erweitert) angefangen, über die 360/165 mit 2MB bis zur 390 (0.05-2Mips) mit einem sagenhaften Adressraum von 16MB:
Hab damals einen Artikel gechrieben, wie man den erweitern konnte - statt dem BALR 15,14 mit BASR ... aber einen BLUESCREEN habe ich noch nie gehabt (wie Bill bei der
Vorführung seines revolutionären XP 2001) - 3 Jahre vorher war ein US-Kreuzer auf offener See wochenlang manövrierunfähig, weil das revolutionäre NT 3.51 abstürzte und niemand in der Lage war, irgend welche Werte zur Steuerung des Schiffes einzugeben. Jedenfalls hatte das Militär die Schnauze gestrichen voll von NT / XP.
Die sind glaube ich auf Ada und ein gehärtetes UNIX (BSD?) umgestiegen.
Na wenn das 1962 bei der Cuba-Krise so gelaufen wäre, würde ich nicht mehr leben und Du wärst gar nicht geboren worden....
vielen Dank nochmal von
Siggi30
PS. Spass muss doch sein nach so vielen öden Seiten Beweismaterial gegen die
russische Mafia... Mafiajäger Giovanni Falcone läst grüßen... 1992 500kg TNT unter der Autobahn bei Palermo... also sieh Dich vor...- |